Fetching the paper…
Reading the bibliography…
It is common practice in deep learning to use overparameterized networks and train for as long as possible; there are numerous studies that show, both theoretically and empirically, that such practices surprisingly do not unduly harm the generalization performance of the classifier.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 1901
Earlier work this paper cites.
You only propagate once: Painless adversarial training using maximal principle
Zhang, D., Zhang, T., Lu, Y., Zhu, Z., and Dong, B · 1905
Earlier work this paper cites.
Provably robust deep learning via adversarially trained smoothed classifiers
Salman, H., Yang, G., Li, J., Zhang, P., Zhang, H., Razenshteyn, I., and Bubeck, S · 1906
Earlier work this paper cites.
Towards stable and efficient training of verifiably robust neural networks
Zhang, H., Chen, H., Xiao, C., Li, B., Boning, D., and Hsieh, C.-J · 1906
Earlier work this paper cites.
Theory and methods related to the singular-function expansion and landweber’s iteration for integral equations of the first kind
Strand, O. N · 1974
Earlier work this paper cites.
Generalization and parameter estimation in feedforward nets: Some experiments
Morgan, N. and Bourlard, H · 1990
Earlier work this paper cites.
A simple weight decay can improve generalization
Krogh, A. and Hertz, J. A · 1992
Earlier work this paper cites.
The elements of statistical learning , volume 1
Friedman, J., Hastie, T., and Tibshirani, R · 2001
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
Srivastava, N., Hinton, G., Krizhevsky, A., Sutskever, I., and Salakhutdinov, R · 2014
Earlier work this paper cites.
Identity mappings in deep residual networks
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Earlier work this paper cites.
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Understanding deep learning requires rethinking generalization
Zhang, C., Bengio, S., Hardt, M., Recht, B., and Vinyals, O · 2016
Earlier work this paper cites.
Synthesizing robust adversarial examples
Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Improved regularization of convolutional neural networks with cutout
DeVries, T. and Taylor, G. W · 2017
Earlier work this paper cites.
Formal verification of piece-wise linear feed-forward neural networks
Ehlers, R · 2017
Earlier work this paper cites.
A rotation and a translation suffice: Fooling cnns with simple transformations
Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., and Madry, A · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Feinman, R., Curtin, R. R., Shintre, S., and Gardner, A. B · 2017
Earlier work this paper cites.
Countering adversarial images using input transformations
Guo, C., Rana, M., Cisse, M., and Van Der Maaten, L · 2017
Earlier work this paper cites.
Safety verification of deep neural networks
Huang, X., Kwiatkowska, M., Wang, S., and Wu, M · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Katz, G., Barrett, C., Dill, D. L., Julian, K., and Kochenderfer, M. J · 2017
Cited alongside, same era.
No need to worry about adversarial examples in object detection in autonomous vehicles
Lu, J., Sibai, H., Fabry, E., and Forsyth, D · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
On detecting adversarial perturbations
Metzen, J. H., Genewein, T., Fischer, V., and Bischoff, B · 2017
Cited alongside, same era.
Exploring generalization in deep learning
Neyshabur, B., Bhojanapalli, S., McAllester, D., and Srebro, N · 2017
Cited alongside, same era.
Connecting optimization and regularization paths
Suggala, A., Prasad, A., and Ravikumar, P. K · 2018
Later among the works it cites.
Attacks meet interpretability: Attribute-steered detection of adversarial samples
Tao, G., Ma, S., Liu, Y., and Zhang, X · 2018
Later among the works it cites.
Scaling provable adversarial defenses
Wong, E., Schmidt, F., Metzen, J. H., and Kolter, J. Z · 2018
Later among the works it cites.
Rademacher complexity for adversarially robust generalization
Yin, D., Ramchandran, K., and Bartlett, P · 2018
Later among the works it cites.
Are labels required for improving adversarial robustness?
Alayrac, J.-B., Uesato, J., Huang, P.-S., Fawzi, A., Stanforth, R., and Kohli, P · 2019
Later among the works it cites.
Reconciling modern machine-learning practice and the classical bias–variance trade-off
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Certifying some distributional robustness with principled adversarial training
Sinha, A., Namkoong, H., and Duchi, J · 2017
Cited alongside, same era.
Cyclical learning rates for training neural networks
Smith, L. N · 2017
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Song, Y., Kim, T., Nowozin, S., Ermon, S., and Kushman, N · 2017
Cited alongside, same era.
Early stopping for kernel boosting algorithms: A general analysis with localized complexities
Wei, Y., Yang, F., and Wainwright, M. J · 2017
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, J. Z · 2017
Cited alongside, same era.
mixup: Beyond empirical risk minimization
Zhang, H., Cisse, M., Dauphin, Y. N., and Lopez-Paz, D · 2017
Cited alongside, same era.
A continuous-time view of early stopping for least squares regression
Ali, A., Kolter, J. Z., and Tibshirani, R. J · 2018
Cited alongside, same era.
Belkin, M., Hsu, D., Ma, S., and Mandal, S · 2019
Later among the works it cites.
Is ami (attacks meet interpretability) robust to adversarial examples?
Carlini, N · 2019
Later among the works it cites.
Unlabeled data improves adversarial robustness
Carmon, Y., Raghunathan, A., Schmidt, L., Liang, P., and Duchi, J. C · 2019
Later among the works it cites.
Certified adversarial robustness via randomized smoothing
Cohen, J. M., Rosenfeld, E., and Kolter, J. Z · 2019
Later among the works it cites.
Robustness (python library), 2019
Engstrom, L., Ilyas, A., Santurkar, S., and Tsipras, D · 2019
Later among the works it cites.
Fazlyab, M., Morari, M., and Pappas, G. J · 2019
Later among the works it cites.
Certified robustness to adversarial examples with differential privacy
Lecuyer, M., Atlidakis, V., Geambasu, R., Hsu, D., and Jana, S · 2019
Later among the works it cites.
Adversarial robustness against the union of multiple perturbation models
Maini, P., Wong, E., and Kolter, J. Z · 2019
Later among the works it cites.
Deep double descent: Where bigger models and more data hurt
Nakkiran, P., Kaplun, G., Bansal, Y., Yang, T., Barak, B., and Sutskever, I · 2019
Later among the works it cites.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T · 2019
Later among the works it cites.
Evaluating robustness of neural networks with mixed integer programming
Tjeng, V., Xiao, K. Y., and Tedrake, R · 2019
Later among the works it cites.
Adversarial training and robustness for multiple perturbations
Tramèr, F. and Boneh, D · 2019
Later among the works it cites.
Wasserstein adversarial examples via projected sinkhorn iterations
Wong, E., Schmidt, F. R., and Kolter, J. Z · 2019
Later among the works it cites.
Feature denoising for improving adversarial robustness
Xie, C., Wu, Y., Maaten, L. v. d., Yuille, A. L., and He, K · 2019
Later among the works it cites.
Me-net: Towards effective adversarial robustness with matrix estimation
Yang, Y., Zhang, G., Katabi, D., and Xu, Z · 2019
Later among the works it cites.
Adversarially robust generalization just requires more unlabeled data
Zhai, R., Cai, T., He, D., Dan, C., He, K., Hopcroft, J., and Wang, L · 2019
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z · 2020
Closest in time.