Fetching the paper…
Reading the bibliography…
In this work, we initiate a formal study of probably approximately correct (PAC) learning under evasion attacks, where the adversary's goal is to \emph{misclassify} the adversarially perturbed sample point $\widetilde{x}$, i.e., $h(\widetilde{x})\neq c(\widetilde{x})$, where $c$ is the ground truth concept and $h$ is the learned hypothesis.
A Theory of the Learnable
Valiant, L. G · 1984
Earlier work this paper cites.
Learning disjunctions of conjunctions
Valiant, L. G · 1985
Earlier work this paper cites.
Asymptotic theory of finite dimensional normed spaces , volume 1200
Milman, V. D. and Schechtman, G · 1986
Earlier work this paper cites.
Learning in the Presence of Malicious Errors
Kearns, M. J. and Li, M · 1993
Earlier work this paper cites.
On the sample complexity of pac learning half-spaces against the uniform distribution
Long, P. M · 1995
Earlier work this paper cites.
Euclidean structure in finite dimensional normed spaces
Giannopoulos, A. A. and Milman, V. D · 2001
Earlier work this paper cites.
The Concentration of Measure Phenomenon
Ledoux, M · 2001
Earlier work this paper cites.
PAC learning with nasty noise
Bshouty, N. H., Eiron, N., and Kushilevitz, E · 2002
Earlier work this paper cites.
Poisoning attacks against support vector machines
Biggio, B., Nelson, B., and Laskov, P · 2012
Earlier work this paper cites.
Active and passive learning of linear separators under log-concave distributions
Balcan, M.-F. and Long, P · 2013
Earlier work this paper cites.
Evasion Attacks against Machine Learning at Test Time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Srndic, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Distribution-dependent sample complexity of large margin learning
Sabato, S., Srebro, N., and Tishby, N · 2013
Earlier work this paper cites.
Security evaluation of pattern classifiers under attack
Biggio, B., Fumera, G., and Roli, F · 2014
Cited alongside, same era.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Cited alongside, same era.
Learning and inference in the presence of corrupted inputs
Feige, U., Mansour, Y., and Schapire, R · 2015
Cited alongside, same era.
Explaining and Harnessing Adversarial Examples
Goodfellow, I., Shlens, J., and Szegedy, C · 2015
Cited alongside, same era.
Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks
Papernot, N., McDaniel, P. D., Wu, X., Jha, S., and Swami, A · 2016
Cited alongside, same era.
Robust inference for multiclass classification
Feige, U., Mansour, Y., and Schapire, R. E · 2018
Later among the works it cites.
Gilmer, J., Metz, L., Faghri, F., Schoenholz, S. S., Raghu, M., Wattenberg, M., and Goodfellow, I · 2018
Later among the works it cites.
Adversarial risk bounds for binary classification via function transformation
Khim, J. and Loh, P.-L · 2018
Later among the works it cites.
Adversarially Robust Generalization Requires More Data
Schmidt, L., Santurkar, S., Tsipras, D., Talwar, K., and Madry, A · 2018
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Towards Evaluating the Robustness of Neural Networks
Carlini, N. and Wagner, D. A · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Gu, T., Dolan-Gavitt, B., and Garg, S · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks
Xu, W., Evans, D., and Qi, Y · 2017
Cited alongside, same era.
Improved generalization bounds for robust learning
Attias, I., Kontorovich, A., and Mansour, Y · 2018
Cited alongside, same era.
Pac-learning in the presence of evasion adversaries
Cullina, D., Bhagoji, A. N., and Mittal, P · 2018
Cited alongside, same era.
Adversarial risk and robustness: General definitions and implications for the uniform distribution
Diochnos, D., Mahloujifar, S., and Mahmoody, M · 2018
Cited alongside, same era.
Later among the works it cites.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2018
Later among the works it cites.
Rademacher complexity for adversarially robust generalization
Yin, D., Ramchandran, K., and Bartlett, P · 2018
Later among the works it cites.
Computational limitations in robust classification and win-win results
Degwekar, A. and Vaikuntanathan, V · 2019
Closest in time.
Adversarial examples are a natural consequence of test error in noise
Ford, N., Gilmer, J., Carlini, N., and Cubuk, D · 2019
Closest in time.
Empirically measuring concentration: Fundamental limits on intrinsic robustness
Mahloujifar, S., Zhang, X., Mahmoody, M., and Evans, D · 2019
Closest in time.
Vc classes are adversarially robustly learnable, but only improperly
Montasser, O., Hanneke, S., and Srebro, N · 2019
Closest in time.