Fetching the paper…
Reading the bibliography…
Convex relaxations are effective for training and certifying neural networks against norm-bounded adversarial attacks, but they leave a large gap between certifiable and empirical robustness.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
Kingma, D. P. and Ba, J · 2014
Earlier work this paper cites.
Distilling the knowledge in a neural network
Hinton, G., Vinyals, O., and Dean, J · 2015
Earlier work this paper cites.
Towards verification of artificial neural networks
Scheibler, K., Winterer, L., Wimmer, R., and Becker, B · 2015
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Provably minimally-distorted adversarial examples
Carlini, N., Katz, G., Barrett, C., and Dill, D. L · 2017
Earlier work this paper cites.
Maximum resilience of artificial neural networks
Cheng, C.-H., Nührenberg, G., and Ruess, H · 2017
Earlier work this paper cites.
Formal verification of piece-wise linear feed-forward neural networks
Ehlers, R · 2017
Earlier work this paper cites.
Deep neural networks as 0-1 mixed integer linear programs: A feasibility study
Fischetti, M. and Jo, J · 2017
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
Hein, M. and Andriushchenko, M · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Katz, G., Barrett, C., Dill, D. L., Julian, K., and Kochenderfer, M. J · 2017
Earlier work this paper cites.
An approach to reachability analysis for feed-forward relu neural networks
Lomuscio, A. and Maganti, L · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Evaluating robustness of neural networks with mixed integer programming
Tjeng, V., Xiao, K., and Tedrake, R · 2017
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, J. Z · 2017
Cited alongside, same era.
Output range analysis for deep feedforward neural networks
Dutta, S., Jha, S., Sankaranarayanan, S., and Tiwari, A · 2018
Adversarial risk and the dangers of evaluating against weak attacks
Uesato, J., O’Donoghue, B., Oord, A. v. d., and Kohli, P · 2018
Later among the works it cites.
Towards fast computation of certified robustness for relu networks
Weng, T.-W., Zhang, H., Chen, H., Song, Z., Hsieh, C.-J., Boning, D., Dhillon, I. S., and Daniel, L · 2018
Later among the works it cites.
Scaling provable adversarial defenses
Wong, E., Schmidt, F., Metzen, J. H., and Kolter, J. Z · 2018
Later among the works it cites.
Training for faster adversarial robustness verification via inducing relu stability
Xiao, K. Y., Tjeng, V., Shafiullah, N. M., and Madry, A · 2018
Later among the works it cites.
Efficient neural network robustness certification with general activation functions
Zhang, H., Weng, T.-W., Chen, P.-Y., Hsieh, C.-J., and Daniel, L · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Ai2: Safety and robustness certification of neural networks with abstract interpretation
Gehr, T., Mirman, M., Drachsler-Cohen, D., Tsankov, P., Chaudhuri, S., and Vechev, M · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
Gowal, S., Dvijotham, K., Stanforth, R., Bunel, R., Qin, C., Uesato, J., Mann, T., and Kohli, P · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Mirman, M., Gehr, T., and Vechev, M · 2018
Cited alongside, same era.
Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning
Papernot, N. and McDaniel, P · 2018
Cited alongside, same era.
Certified defenses against adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Cited alongside, same era.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Cited alongside, same era.
Fast and effective robustness certification
Singh, G., Gehr, T., Mirman, M., Püschel, M., and Vechev, M · 2018
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Cohen, J. M., Rosenfeld, E., and Kolter, J. Z · 2019
Later among the works it cites.
Puvae: A variational autoencoder to purify adversarial examples
Hwang, U., Park, J., Jang, H., Yoon, S., and Cho, N. I · 2019
Later among the works it cites.
A convex relaxation barrier to tight robust verification of neural networks
Salman, H., Yang, G., Zhang, H., Hsieh, C.-J., and Zhang, P · 2019
Later among the works it cites.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T · 2019
Later among the works it cites.
Gotta catch ’em all: Using concealed trapdoors to detect adversarial attacks on neural networks, 2019
Shan, S., Willson, E., Wang, B., Li, B., Zheng, H., and Zhao, B. Y · 2019
Later among the works it cites.
You only propagate once: Painless adversarial training using maximal principle
Zhang, D., Zhang, T., Lu, Y., Zhu, Z., and Dong, B · 2019
Later among the works it cites.
Towards stable and efficient training of verifiably robust neural networks
Zhang, H., Chen, H., Xiao, C., Li, B., Boning, D., and Hsieh, C.-J · 2020
Closest in time.