Fetching the paper…
Reading the bibliography…
Adversarial training yields robust models against a specific threat model, e.g., $L_\infty$ adversarial examples.
Benchmarking neural network robustness to common corruptions and perturbations
Hendrycks, D. and Dietterich, T. G · 1903
Earlier work this paper cites.
Exploiting excessive invariance caused by norm-bounded adversarial robustness
Jacobsen, J., Behrmann, J., Carlini, N., Tramèr, F., and Papernot, N · 1903
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
Efficient projections onto the l 1 {}_{\mbox{1}} -ball for learning in high dimensions
Duchi, J. C., Shalev-Shwartz, S., Singer, Y., and Chandra, T · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A · 2009
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., and Ng, A. Y · 2011
Earlier work this paper cites.
Scikit-learn: Machine learning in Python
Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., Vanderplas, J., Passos, A., Cournapeau, D., Brucher, M., Perrot, M., and Duchesnay, E · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Learning with a strong adversary
Huang, R., Xu, B., Schuurmans, D., and Szepesvári, C · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Ioffe, S. and Szegedy, C · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Distributional smoothing with virtual adversarial training
Miyato, T., Maeda, S.-i., Koyama, M., Nakae, K., and Ishii, S · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Earlier work this paper cites.
Wide residual networks
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
The vulnerability of learning to adversarial perturbation increases with intrinsic dimensionality
Amsaleg, L., Bailey, J., Barbe, D., Erfani, S. M., Houle, M. E., Nguyen, V., and Radovanovic, M · 2017
Earlier work this paper cites.
Dimensionality reduction as a defense against evasion attacks on machine learning classifiers
Bhagoji, A. N., Cullina, D., and Mittal, P · 2017
Earlier work this paper cites.
Brown, T. B., Mané, D., Roy, A., Abadi, M., and Gilmer, J · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Feinman, R., Curtin, R. R., Shintre, S., and Gardner, A. B · 2017
Earlier work this paper cites.
Adversarial and clean data are not twins
Gong, Z., Wang, W., and Ku, W · 2017
Earlier work this paper cites.
On the (statistical) detection of adversarial examples
Grosse, K., Manoharan, P., Papernot, N., Backes, M., and McDaniel, P · 2017
Earlier work this paper cites.
Early methods for detecting adversarial images
Hendrycks, D. and Gimpel, K · 2017
Earlier work this paper cites.
Adversarial examples detection in deep networks with convolutional filter statistics
Li, X. and Li, F · 2017
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Liu, Y., Chen, X., Liu, C., and Song, D · 2017
Earlier work this paper cites.
On detecting adversarial perturbations
Metzen, J. H., Genewein, T., Fischer, V., and Bischoff, B · 2017
Cited alongside, same era.
Simple black-box adversarial attacks on deep neural networks
Narodytska, N. and Kasiviswanathan, S. P · 2017
Cited alongside, same era.
Automatic differentiation in pytorch
Paszke, A., Gross, S., Chintala, S., Chanan, G., Yang, E., DeVito, Z., Lin, Z., Desmaison, A., Antiga, L., and Lerer, A · 2017
Cited alongside, same era.
On the robustness of the CVPR 2018 white-box adversarial example defenses
Athalye, A. and Carlini, N · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D. A · 2018
Cited alongside, same era.
Curriculum adversarial training
On evaluating adversarial robustness
Carlini, N., Athalye, A., Brendel, N. P. W., Rauber, J., Tsipras, D., Goodfellow, I., Madry, A., and Kurakin, A · 2019
Closest in time.
Unlabeled data improves adversarial robustness
Carmon, Y., Raghunathan, A., Schmidt, L., Duchi, J. C., and Liang, P · 2019
Closest in time.
Sparse and imperceivable adversarial attacks
Croce, F. and Hein, M · 2019
Closest in time.
Exploring the landscape of spatial robustness
Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., and Madry, A · 2019
Closest in time.
Evaluation methodology for attacks against confidence thresholding models, 2019
Goodfellow, I., Qin, Y., and Berthelot, D · 2019
Closest in time.
Why relu networks yield high-confidence predictions far away from the training data and how to mitigate the problem
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cai, Q., Liu, C., and Song, D · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J · 2018
Cited alongside, same era.
Strength in numbers: Trading-off robustness and computation via adversarially-trained ensembles
Grefenstette, E., Stanforth, R., O’Donoghue, B., Uesato, J., Swirszcz, G., and Kohli, P · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J · 2018
Cited alongside, same era.
On the geometry of adversarial examples
Khoury, M. and Hadfield-Menell, D · 2018
Cited alongside, same era.
A simple unified framework for detecting out-of-distribution samples and adversarial attacks
Lee, K., Lee, K., Lee, H., and Shin, J · 2018
Cited alongside, same era.
Defense against adversarial attacks using high-level representation guided denoiser
Liao, F., Liang, M., Dong, Y., Pang, T., Hu, X., and Zhu, J · 2018
Cited alongside, same era.
Hein, M., Andriushchenko, M., and Bitterwolf, J · 2019
Closest in time.
Using self-supervised learning can improve model robustness and uncertainty
Hendrycks, D., Mazeika, M., Kadavath, S., and Song, D · 2019
Closest in time.
Testing robustness against unforeseen adversaries
Kang, D., Sun, Y., Hendrycks, D., Brown, T., and Steinhardt, J · 2019
Closest in time.
Playing it safe: Adversarial robustness with an abstain option
Laidlaw, C. and Feizi, S · 2019
Closest in time.
Interpolated adversarial training: Achieving robust neural networks without sacrificing too much accuracy
Lamb, A., Verma, V., Kannala, J., and Bengio, Y · 2019
Closest in time.
On norm-agnostic robustness of adversarial training
Li, B., Chen, C., Wang, W., and Carin, L · 2019
Closest in time.
Mnist-c: A robustness benchmark for computer vision
Mu, N. and Gilmer, J · 2019
Closest in time.
Adversarial training can hurt generalization
Raghunathan, A., Xie, S. M., Yang, F., Duchi, J. C., and Liang, P · 2019
Closest in time.
Towards the first adversarially robust neural network model on MNIST
Schott, L., Rauber, J., Bethge, M., and Brendel, W · 2019
Closest in time.
Disentangling adversarial robustness and generalization
Stutz, D., Hein, M., and Schiele, B · 2019
Closest in time.
Adversarial training and robustness for multiple perturbations
Tramèr, F. and Boneh, D · 2019
Closest in time.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Closest in time.
Improving transferability of adversarial examples with input diversity
Xie, C., Zhang, Z., Zhou, Y., Bai, S., Wang, J., Ren, Z., and Yuille, A. L · 2019
Closest in time.
Adversarial framing for image and video classification
Zajac, M., Zolna, K., Rostamzadeh, N., and Pinheiro, P. O · 2019
Closest in time.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 2019
Closest in time.
CAT: customized adversarial training for improved robustness
Cheng, M., Lei, Q., Chen, P., Dhillon, I. S., and Hsieh, C · 2020
Closest in time.
Adversarial robustness against the union of multiple perturbation models
Maini, P., Wong, E., and Kolter, J. Z · 2020
Closest in time.
Universal adversarial training
Shafahi, A., Najibi, M., Xu, Z., Dickerson, J. P., Davis, L. S., and Goldstein, T · 2020
Closest in time.