Fetching the paper…
Reading the bibliography…
Owing to the susceptibility of deep learning systems to adversarial attacks, there has been a great deal of work in developing (both empirically and certifiably) robust classifiers.
Provable robustness against all adversarial l p {}_{\mbox{p}} -perturbations for p ≥ \geq 1
Croce, F. and Hein, M · 1905
Earlier work this paper cites.
The theory of max-min and its application to weapons allocation problems , volume 5
Danskin, J. M · 1967
Earlier work this paper cites.
Efficient projections onto the l1-ball for learning in high dimensions
Duchi, J., Shalev-Shwartz, S., Singer, Y., and Chandra, T · 2008
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Identity mappings in deep residual networks
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Earlier work this paper cites.
Wide residual networks, 2016
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Ead: Elastic-net attacks to deep neural networks via adversarial examples, 2017
Chen, P.-Y., Sharma, Y., Zhang, H., Yi, J., and Hsieh, C.-J · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Katz, G., Barrett, C., Dill, D., Julian, K., and Kochenderfer, M · 2017
Cited alongside, same era.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2017
Cited alongside, same era.
No need to worry about adversarial examples in object detection in autonomous vehicles
Lu, J., Sibai, H., Fabry, E., and Forsyth, D · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Logit pairing methods can fool gradient-based attacks
Mosbach, M., Andriushchenko, M., Trost, T., Hein, M., and Klakow, D · 2018
Later among the works it cites.
Decoupling direction and norm for efficient gradient-based L2 adversarial attacks and defenses
Rony, J., Hafemann, L. G., Oliveira, L. S., Ayed, I. B., Sabourin, R., and Granger, E · 2018
Later among the works it cites.
Smith, L. N · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
Uesato, J., O’Donoghue, B., Kohli, P., and van den Oord, A · 2018
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Rauber, J., Brendel, W., and Bethge, M · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J · 2018
Cited alongside, same era.
Evaluating and understanding the robustness of adversarial logit pairing
Engstrom, L., Ilyas, A., and Athalye, A · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
Gowal, S., Dvijotham, K., Stanforth, R., Bunel, R., Qin, C., Uesato, J., Arandjelovic, R., Mann, T. A., and Kohli, P · 2018
Cited alongside, same era.
Kannan, H., Kurakin, A., and Goodfellow, I. J · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Mirman, M., Gehr, T., and Vechev, M · 2018
Cited alongside, same era.
Wong, E. and Kolter, Z · 2018
Later among the works it cites.
Scaling provable adversarial defenses
Wong, E., Schmidt, F., Metzen, J. H., and Kolter, J. Z · 2018
Later among the works it cites.
Quantifying perceptual distortion of adversarial examples
Jordan, M., Manoj, N., Goel, S., and Dimakis, A. G · 2019
Closest in time.
Transfer of adversarial robustness between perturbation types
Kang, D., Sun, Y., Brown, T., Hendrycks, D., and Steinhardt, J · 2019
Closest in time.
Towards the first adversarially robust neural network model on MNIST
Schott, L., Rauber, J., Bethge, M., and Brendel, W · 2019
Closest in time.
Evaluating robustness of neural networks with mixed integer programming
Tjeng, V., Xiao, K. Y., and Tedrake, R · 2019
Closest in time.
Adversarial training and robustness for multiple perturbations
Tramèr, F. and Boneh, D · 2019
Closest in time.