Fetching the paper…
Reading the bibliography…
Adversarial training (AT) is one of the most effective defenses against adversarial attacks for deep learning models.
On the momentum term in gradient descent learning algorithms
Ning Qian · 1999
Earlier work this paper cites.
Convex optimization
Stephen Boyd and Lieven Vandenberghe · 2004
Earlier work this paper cites.
Analysis 2 springer verlag, 2004
Konrad Königsberger · 2004
Earlier work this paper cites.
Curriculum learning
Yoshua Bengio, Jérôme Louradour, Ronan Collobert, and Jason Weston · 2009
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2010
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep metric learning using triplet network
Elad Hoffer and Nir Ailon · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik Kingma and Jimmy Ba · 2015
Earlier work this paper cites.
Deep face recognition
Omkar M Parkhi, Andrea Vedaldi, Andrew Zisserman, et al · 2015
Earlier work this paper cites.
Facenet: A unified embedding for face recognition and clustering
Florian Schroff, Dmitry Kalenichenko, and James Philbin · 2015
Earlier work this paper cites.
Deep Learning
Ian Goodfellow, Yoshua Bengio, and Aaron Courville · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
Weight normalization: A simple reparameterization to accelerate training of deep neural networks
Tim Salimans and Durk P Kingma · 2016
Earlier work this paper cites.
Wide residual networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh · 2017
Earlier work this paper cites.
Dawnbench: An end-to-end deep learning benchmark and competition
Cody Coleman, Deepak Narayanan, Daniel Kang, Tian Zhao, Jian Zhang, Luigi Nardi, Peter Bailis, Kunle Olukotun, Chris Ré, and Matei Zaharia · 2017
Earlier work this paper cites.
L2-constrained softmax loss for discriminative face verification
Rajeev Ranjan, Carlos D Castillo, and Rama Chellappa · 2017
Earlier work this paper cites.
Normface: l 2 hypersphere embedding for face verification
Feng Wang, Xiang Xiang, Jian Cheng, and Alan Loddon Yuille · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Earlier work this paper cites.
Large margin deep networks for classification
Gamaleldin Elsayed, Dilip Krishnan, Hossein Mobahi, Kevin Regan, and Samy Bengio · 2018
Earlier work this paper cites.
Evaluating and understanding the robustness of adversarial logit pairing
Logan Engstrom, Andrew Ilyas, and Anish Athalye · 2018
Earlier work this paper cites.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Cited alongside, same era.
Harini Kannan, Alexey Kurakin, and Ian Goodfellow · 2018
Cited alongside, same era.
Adversarial attacks and defences competition
Alexey Kurakin, Ian Goodfellow, Samy Bengio, Yinpeng Dong, Fangzhou Liao, Ming Liang, Tianyu Pang, Jun Zhu, Xiaolin Hu, Cihang Xie, et al · 2018
Cited alongside, same era.
Deep hyperspherical defense against adversarial perturbations
Weiyang Liu, Zhen Liu, Zhehui Chen, Bo Dai, Tuo Zhao, and Le Song · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
Hadi Salman, Jerry Li, Ilya Razenshteyn, Pengchuan Zhang, Huan Zhang, Sebastien Bubeck, and Greg Yang · 2019
Later among the works it cites.
Image synthesis with a single (robust) classifier
Shibani Santurkar, Andrew Ilyas, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Later among the works it cites.
Adversarial training for free!
Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein · 2019
Later among the works it cites.
First-order adversarial vulnerability of neural networks and input dimension
Carl-Johann Simon-Gabriel, Yann Ollivier, Leon Bottou, Bernhard Schölkopf, and David Lopez-Paz · 2019
Later among the works it cites.
Improving the generalization of adversarial training with domain adaptation
Chuanbiao Song, Kun He, Liwei Wang, and John E Hopcroft · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Attacks meet interpretability: Attribute-steered detection of adversarial samples
Guanhong Tao, Shiqing Ma, Yingqi Liu, and Xiangyu Zhang · 2018
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Dan Boneh, and Patrick McDaniel · 2018
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli · 2018
Cited alongside, same era.
Cosface: Large margin cosine loss for deep face recognition
Hao Wang, Yitong Wang, Zheng Zhou, Xing Ji, Dihong Gong, Jingchao Zhou, Zhifeng Li, and Wei Liu · 2018
Cited alongside, same era.
Unsupervised feature learning via non-parametric instance discrimination
Zhirong Wu, Yuanjun Xiong, Stella X Yu, and Dahua Lin · 2018
Cited alongside, same era.
Deep defense: Training dnns with improved adversarial robustness
Ziang Yan, Yiwen Guo, and Changshui Zhang · 2018
Cited alongside, same era.
Are labels required for improving adversarial robustness?
Jean-Baptiste Alayrac, Jonathan Uesato, Po-Sen Huang, Alhussein Fawzi, Robert Stanforth, and Pushmeet Kohli · 2019
Cited alongside, same era.
Florian Tramèr and Dan Boneh · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Later among the works it cites.
On the convergence and robustness of adversarial training
Yisen Wang, Xingjun Ma, James Bailey, Jinfeng Yi, Bowen Zhou, and Quanquan Gu · 2019
Later among the works it cites.
Feature denoising for improving adversarial robustness
Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan Yuille, and Kaiming He · 2019
Later among the works it cites.
Improving machine reading comprehension via adversarial training
Ziqing Yang, Yiming Cui, Wanxiang Che, Ting Liu, Shijin Wang, and Guoping Hu · 2019
Later among the works it cites.
Adversarially robust generalization just requires more unlabeled data
Runtian Zhai, Tianle Cai, Di He, Chen Dan, Kun He, John Hopcroft, and Liwei Wang · 2019
Later among the works it cites.
Defense against adversarial attacks using feature scattering-based adversarial training
Haichao Zhang and Jianyu Wang · 2019
Later among the works it cites.
Making convolutional networks shift-invariant again
Richard Zhang · 2019
Later among the works it cites.
Interpreting adversarially trained convolutional neural networks
Tianyuan Zhang and Zhanxing Zhu · 2019
Later among the works it cites.
Adversarial vision challenge
Wieland Brendel, Jonas Rauber, Alexey Kurakin, Nicolas Papernot, Behar Veliqi, Sharada P Mohanty, Florian Laurent, Marcel Salathé, Matthias Bethge, Yaodong Yu, et al · 2020
Closest in time.
Rays: A ray searching method for hard-label adversarial attack
Jinghui Chen and Quanquan Gu · 2020
Closest in time.
Using single-step adversarial training to defend iterative adversarial examples
Guanxiong Liu, Issa Khalil, and Abdallah Khreishah · 2020
Closest in time.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and J Zico Kolter · 2020
Closest in time.
Fast and stable adversarial training through noise injection
Leo Schwinn and Björn Eskofier · 2020
Closest in time.
Regularizers for single-step adversarial training
BS Vivek and R Venkatesh Babu · 2020
Closest in time.
Single-step adversarial training with dropout scheduling
S Vivek B and R Venkatesh Babu · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Closest in time.
Defending against physically realizable attacks on image classification
Tong Wu, Liang Tong, and Yevgeniy Vorobeychik · 2020
Closest in time.
Intriguing properties of adversarial training at scale
Cihang Xie and Alan Yuille · 2020
Closest in time.
Dynamic divide-and-conquer adversarial training for robust semantic segmentation
Xiaogang Xu, Hengshuang Zhao, and Jiaya Jia · 2020
Closest in time.
Freelb: Enhanced adversarial training for language understanding
Chen Zhu, Yu Cheng, Zhe Gan, Siqi Sun, Thomas Goldstein, and Jingjing Liu · 2020
Closest in time.