Fetching the paper…
Reading the bibliography…
Adversarial training augments the training set with perturbations to improve the robust error (over worst-case perturbations), but it often leads to an increase in the standard error (on unperturbed test inputs).
Effective training of a neural network character classifier for word recognition
Yaeger, L., Lyon, R., and Webb, B · 1996
Earlier work this paper cites.
The elements of statistical learning , volume 1
Friedman, J., Hastie, T., and Tibshirani, R · 2001
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A., Sutskever, I., and Hinton, G. E · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
CVXPY: A Python-embedded modeling language for convex optimization
Diamond, S. and Boyd, S · 2016
Earlier work this paper cites.
Regularization with stochastic transformations and perturbations for deep semi-supervised learning
Sajjadi, M., Javanmardi, M., and Tasdizen, T · 2016
Earlier work this paper cites.
Wide residual networks
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Intriguing properties of adversarial examples
Cubuk, E. D., Zoph, B., Schoenholz, S. S., and Le, Q. V · 2017
Earlier work this paper cites.
Adversarial examples for evaluating reading comprehension systems
Jia, R. and Liang, P · 2017
Earlier work this paper cites.
Temporal ensembling for semi-supervised learning
Laine, S. and Aila, T · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks (published at ICLR 2018)
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Earlier work this paper cites.
Understanding deep learning requires rethinking generalization
Zhang, C., Bengio, S., Hardt, M., Recht, B., and Vinyals, O · 2017
Cited alongside, same era.
Generating natural language adversarial examples
Alzantot, M., Sharma, Y., Elgohary, A., Ho, B., Srivastava, M., and Chang, K · 2018
Cited alongside, same era.
To understand deep learning we need to understand kernel learning
Belkin, M., Ma, S., and Mandal, S · 2018
Cited alongside, same era.
Analysis of classifiers’ robustness to adversarial perturbations
Fawzi, A., Fawzi, O., and Frossard, P · 2018
Cited alongside, same era.
Just interpolate: Kernel” ridgeless” regression can generalize
Liang, T. and Rakhlin, A · 2018
Cited alongside, same era.
The power of interpolation: Understanding the effectiveness of SGD in modern over-parametrized learning
Surprises in high-dimensional ridgeless least squares interpolation
Hastie, T., Montanari, A., Rosset, S., and Tibshirani, R. J · 2019
Later among the works it cites.
Interpolated adversarial training: Achieving robust neural networks without sacrificing too much accuracy
Lamb, A., Verma, V., Kannala, J., and Bengio, Y · 2019
Later among the works it cites.
Robustness to adversarial perturbations in learning from incomplete data
Najafi, A., Maeda, S., Koyama, M., and Miyato, T · 2019
Later among the works it cites.
Adversarial robustness may be at odds with simplicity
Nakkiran, P · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Ma, S., Bassily, R., and Belkin, M · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Virtual adversarial training: a regularization method for supervised and semi-supervised learning
Miyato, T., Maeda, S., Ishii, S., and Koyama, M · 2018
Cited alongside, same era.
Adversarially robust generalization requires more data
Schmidt, L., Santurkar, S., Tsipras, D., Talwar, K., and Madry, A · 2018
Cited alongside, same era.
Benign overfitting in linear regression
Bartlett, P. L., Long, P. M., Lugosi, G., and Tsigler, A · 2019
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Carmon, Y., Raghunathan, A., Schmidt, L., Liang, P., and Duchi, J. C · 2019
Cited alongside, same era.
Exploring the landscape of spatial robustness
Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., and Madry, A · 2019
Cited alongside, same era.
Are labels required for improving adversarial robustness?
Uesato, J., Alayrac, J., Huang, P., Stanforth, R., Fawzi, A., and Kohli, P · 2019
Later among the works it cites.
Unsupervised data augmentation
Xie, Q., Dai, Z., Hovy, E., Luong, M., and Le, Q. V · 2019
Later among the works it cites.
Invariance-inducing regularization using worst-case transformations suffices to boost accuracy and spatial robustness
Yang, F., Wang, Z., and Heinze-Deml, C · 2019
Later among the works it cites.
A fourier perspective on model robustness in computer vision
Yin, D., Lopes, R. G., Shlens, J., Cubuk, E. D., and Gilmer, J · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 2019
Later among the works it cites.
Min, Y., Chen, L., and Karbasi, A · 2020
Closest in time.
Adversarial examples improve image recognition
Xie, C., Tan, M., Gong, B., Wang, J., Yuille, A. L., and Le, Q. V · 2020
Closest in time.