Fetching the paper…
Reading the bibliography…
Recent works have shown the effectiveness of randomized smoothing as a scalable technique for building neural network-based classifiers that are provably robust to $\ell_2$-norm adversarial perturbations.
Estimation of the mean of a multivariate normal distribution
Charles M Stein · 1981
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Mitigating evasion attacks to deep neural networks via region-based classification
Xiaoyu Cao and Neil Zhenqiang Gong · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Formal verification of piece-wise linear feed-forward neural networks
Ruediger Ehlers · 2017
Earlier work this paper cites.
Deep neural networks as 0-1 mixed integer linear programs: A feasibility study
Matteo Fischetti and Jason Jo · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Guy Katz, Clark Barrett, David L Dill, Kyle Julian, and Mykel J Kochenderfer · 2017
Earlier work this paper cites.
An approach to reachability analysis for feed-forward relu neural networks
Alessio Lomuscio and Lalit Maganti · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Cited alongside, same era.
On the robustness of the cvpr 2018 white-box adversarial example defenses
Anish Athalye and Nicholas Carlini · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
Provable robustness of relu networks via maximization of linear regions
Fast and effective robustness certification
Gagandeep Singh, Timon Gehr, Matthew Mirman, Markus Püschel, and Martin Vechev · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli · 2018
Later among the works it cites.
Towards fast computation of certified robustness for ReLU networks
Tsui-Wei Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Duane Boning, Inderjit S Dhillon, and Luca Daniel · 2018
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Later among the works it cites.
Scaling provable adversarial defenses
Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J Zico Kolter · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Francesco Croce, Maksym Andriushchenko, and Matthias Hein · 2018
Cited alongside, same era.
Ai2: Safety and robustness certification of neural networks with abstract interpretation
Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Timothy Mann, and Pushmeet Kohli · 2018
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2018
Cited alongside, same era.
Second-order adversarial attack and certifiable robustness
Bai Li, Changyou Chen, Wenlin Wang, and Lawrence Carin · 2018
Cited alongside, same era.
Towards robust neural networks via random self-ensemble
Xuanqing Liu, Minhao Cheng, Huan Zhang, and Cho-Jui Hsieh · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin Vechev · 2018
Cited alongside, same era.
Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses
Jérôme Rony, Luiz G Hafemann, Luis S Oliveira, Ismail Ben Ayed, Robert Sabourin, and Eric Granger · 2018
Cited alongside, same era.
Efficient neural network robustness certification with general activation functions
Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel · 2018
Later among the works it cites.
Unlabeled data improves adversarial robustness
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, Percy Liang, and John C Duchi · 2019
Closest in time.
Certified adversarial robustness via randomized smoothing
Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter · 2019
Closest in time.
Using pre-training can improve model robustness and uncertainty
Dan Hendrycks, Kimin Lee, and Mantas Mazeika · 2019
Closest in time.
A convex relaxation barrier to tight robustness verification of neural networks
Hadi Salman, Greg Yang, Huan Zhang, Cho-Jui Hsieh, and Pengchuan Zhang · 2019
Closest in time.
Evaluating robustness of neural networks with mixed integer programming
Vincent Tjeng, Kai Y. Xiao, and Russ Tedrake · 2019
Closest in time.