Fetching the paper…
Reading the bibliography…
Adversarial training has become one of the most effective methods for improving robustness of neural networks.
Imagenet: A large-scale hierarchical image database
Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., and Fei-Fei, L · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Simonyan, K. and Zisserman, A · 2015
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I., and Bengio, S · 2017
Earlier work this paper cites.
Efficient defenses against adversarial attacks
Zantedeschi, V., Nicolae, M.-I., and Rawat, A · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Earlier work this paper cites.
Query-efficient hard-label black-box attack: An optimization-based approach
Cheng, M., Le, T., Chen, P.-Y., Yi, J., Zhang, H., and Hsieh, C.-J · 2018
Earlier work this paper cites.
Ding, G. W., Sharma, Y., Lui, K. Y. C., and Huang, R · 2018
Earlier work this paper cites.
Evaluating and understanding the robustness of adversarial logit pairing
Engstrom, L., Ilyas, A., and Athalye, A · 2018
Cited alongside, same era.
Robust physical-world attacks on deep learning visual classification
Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J · 2018
Cited alongside, same era.
Towards robust neural networks via random self-ensemble
Liu, X., Cheng, M., Zhang, H., and Hsieh, C.-J · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Convergence of adversarial training in overparametrized neural networks
Gao, R., Cai, T., Li, H., Hsieh, C.-J., Wang, L., and Lee, J. D · 2019
Later among the works it cites.
Adversarial robustness via adversarial label-smoothing
Goibert, M. and Dohmatob, E · 2019
Later among the works it cites.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T · 2019
Later among the works it cites.
On mixup training: Improved calibration and predictive uncertainty for deep neural networks
Thulasidasan, S., Chennupati, G., Bilmes, J., Bhattacharya, T., and Michalak, S · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Label smoothing and logit squeezing: A replacement for adversarial training?
Shafahi, A., Ghiasi, A., Huang, F., and Goldstein, T · 2018
Cited alongside, same era.
Is robustness the cost of accuracy?–a comprehensive study on the robustness of 18 deep image classification models
Su, D., Zhang, H., Chen, H., Yi, J., Chen, P.-Y., and Gao, Y · 2018
Cited alongside, same era.
Manifold mixup: Better representations by interpolating hidden states
Verma, V., Lamb, A., Beckham, C., Najafi, A., Mitliagkas, I., Courville, A., Lopez-Paz, D., and Bengio, Y · 2018
Cited alongside, same era.
Rademacher complexity for adversarially robust generalization
Yin, D., Ramchandran, K., and Bartlett, P · 2018
Cited alongside, same era.
mixup: Beyond empirical risk minimization
Zhang, H., Cisse, M., Dauphin, Y. N., and Lopez-Paz, D · 2018
Cited alongside, same era.
Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets
Balaji, Y., Goldstein, T., and Hoffman, J · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Cohen, J. M., Rosenfeld, E., and Kolter, J. Z · 2019
Cited alongside, same era.
Wang, J · 2019
Later among the works it cites.
On the convergence and robustness of adversarial training
Wang, Y., Ma, X., Bailey, J., Yi, J., Zhou, B., and Gu, Q · 2019
Later among the works it cites.
Improved sample complexities for deep networks and robust classification via an all-layer margin
Wei, C. and Ma, T · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 2019
Later among the works it cites.
Sign-opt: A query-efficient hard-label adversarial attack
Cheng, M., Singh, S., Chen, P., Chen, P.-Y., Liu, S., and Hsieh, C.-J · 2020
Closest in time.
Improving adversarial robustness requires revisiting misclassified examples
Wang, Zou, Y. B. M. G · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z · 2020
Closest in time.