Fetching the paper…
Reading the bibliography…
Randomized smoothing, using just a simple isotropic Gaussian distribution, has been shown to produce good robustness guarantees against $\ell_2$-norm bounded adversaries.
(de)randomized smoothing for certifiable defense against patch attacks
Levine, A. and Feizi, S · 2002
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D. A · 2017
Earlier work this paper cites.
Adversarial and clean data are not twins
Gong, Z., Wang, W., and Ku, W · 2017
Earlier work this paper cites.
On the (statistical) detection of adversarial examples
Grosse, K., Manoharan, P., Papernot, N., Backes, M., and McDaniel, P. D · 2017
Earlier work this paper cites.
Adversarial examples detection in deep networks with convolutional filter statistics
Li, X. and Li, F · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Earlier work this paper cites.
Thermometer encoding: One hot way to resist adversarial examples
Buckman, J., Roy, A., Raffel, C., and Goodfellow, I. J · 2018
Earlier work this paper cites.
Stochastic activation pruning for robust adversarial defense
Dhillon, G. S., Azizzadenesheli, K., Lipton, Z. C., Bernstein, J., Kossaifi, J., Khanna, A., and Anandkumar, A · 2018
Earlier work this paper cites.
Countering adversarial images using input transformations
Guo, C., Rana, M., Cissé, M., and van der Maaten, L · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Semidefinite relaxations for certifying robustness to adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
Uesato, J., O’Donoghue, B., Kohli, P., and van den Oord, A · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, J. Z · 2018
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Cited alongside, same era.
Functional adversarial attacks
Laidlaw, C. and Feizi, S · 2019
Cited alongside, same era.
Are adversarial examples inevitable?
Shafahi, A., Huang, W. R., Studer, C., Feizi, S., and Goldstein, T · 2019
Later among the works it cites.
Robustness certificates against adversarial examples for relu networks
Singla, S. and Feizi, S · 2019
Later among the works it cites.
Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, 8-14 December 2019, Vancouver, BC, Canada , 2019
Wallach, H. M., Larochelle, H., Beygelzimer, A., d’Alché-Buc, F., Fox, E. B., and Garnett, R. (eds.) · 2019
Later among the works it cites.
Random smoothing might be unable to certify ℓ ∞ \ell_{\infty} robustness for high-dimensional images
Blum, A., Dick, T., Manoj, N., and Zhang, H · 2020
Closest in time.
Certified defenses for adversarial patches
Chiang, P.-y., Ni, R., Abdelkader, A., Zhu, C., Studer, C., and Goldstein, T · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Certified robustness to adversarial examples with differential privacy
Lécuyer, M., Atlidakis, V., Geambasu, R., Hsu, D., and Jana, S · 2019
Cited alongside, same era.
Tight certificates of adversarial robustness for randomly smoothed classifiers
Lee, G., Yuan, Y., Chang, S., and Jaakkola, T. S · 2019
Cited alongside, same era.
Certified adversarial robustness with additive noise
Li, B., Chen, C., Wang, W., and Carin, L · 2019
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
Salman, H., Li, J., Razenshteyn, I. P., Zhang, P., Zhang, H., Bubeck, S., and Yang, G · 2019
Cited alongside, same era.
Closest in time.
Wasserstein smoothing: Certified robustness against wasserstein adversarial attacks
Levine, A. and Feizi, S · 2020
Closest in time.
Robustness certificates for sparse adversarial attacks by randomized ablation
Levine, A. and Feizi, S · 2020
Closest in time.
Second-order provable defenses against adversarial attacks
Singla, S. and Feizi, S · 2020
Closest in time.
ℓ 1 \ell_{1} adversarial robustness certificates: a randomized smoothing approach, 2020
Teng, J., Lee, G.-H., and Yuan, Y · 2020
Closest in time.
Black-box certification with randomized smoothing: A functional optimization based framework
Zhang, D., Ye, M., Gong, C., Zhu, Z., and Liu, Q · 2020
Closest in time.