Fetching the paper…
Reading the bibliography…
Training machine learning models that are robust against adversarial inputs poses seemingly insurmountable challenges.
Adversarial robustness as a prior for learned representations
Engstrom, L., Ilyas, A., Santurkar, S., Tsipras, D., Tran, B., and Mądry, A · 1906
Earlier work this paper cites.
Asymptotic evaluation of certain markov process expectations for large time, IV
Donsker, M. D. and Varadhan, S. S · 1983
Earlier work this paper cites.
How to generate ordered maps by maximizing the mutual information between input and output signals
Linsker, R · 1989
Earlier work this paper cites.
An information-maximization approach to blind separation and blind deconvolution
Bell, A. J. and Sejnowski, T. J · 1995
Earlier work this paper cites.
Estimation of mutual information using kernel density estimators
Moon, Y.-I., Rajagopalan, B., and Lall, U · 1995
Earlier work this paper cites.
Estimation of the information by an adaptive partitioning of the observation space
Darbellay, G. A. and Vajda, I · 1999
Earlier work this paper cites.
The ∞ \infty -wasserstein distance: Local solutions and existence of optimal transport maps
Champion, T., De Pascale, L., and Juutinen, P · 2008
Earlier work this paper cites.
Approximating mutual information by maximum likelihood density ratio estimation
Suzuki, T., Sugiyama, M., Sese, J., and Kanamori, T · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A., Hinton, G., et al · 2009
Earlier work this paper cites.
MNIST handwritten digit database
LeCun, Y. and Cortes, C · 2010
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., and Ng, A. Y · 2011
Earlier work this paper cites.
Elements of Information Theory
Cover, T. M. and Thomas, J. A · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Nonparametric von mises estimators for entropies, divergences and mutual informations
Kandasamy, K., Krishnamurthy, A., Poczos, B., Wasserman, L., et al · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Simonyan, K. and Zisserman, A · 2015
Cited alongside, same era.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Cited alongside, same era.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M. K · 2016
Cited alongside, same era.
A rotation and a translation suffice: Fooling CNNs with simple transformations
Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., and Mądry, A · 2017
Cited alongside, same era.
Densely connected convolutional networks
Huang, G., Liu, Z., Van Der Maaten, L., and Weinberger, K. Q · 2017
Cited alongside, same era.
Optimal mass transport: Signal processing and machine-learning applications
Towards deep learning models resistant to adversarial attacks
Mądry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Later among the works it cites.
Adversarially robust generalization requires more data
Schmidt, L., Santurkar, S., Tsipras, D., Talwar, K., and Mądry, A · 2018
Later among the works it cites.
Are adversarial examples inevitable?
Shafahi, A., Huang, W. R., Studer, C., Feizi, S., and Goldstein, T · 2018
Later among the works it cites.
Certifying some distributional robustness with principled adversarial training
Sinha, A., Namkoong, H., and Duchi, J · 2018
Later among the works it cites.
Adversarial examples from computational constraints
Bubeck, S., Lee, Y. T., Price, E., and Razenshteyn, I · 2019
Later among the works it cites.
BERT: Pre-training of deep bidirectional transformers for language understanding
Devlin, J., Chang, M.-W., Lee, K., and Toutanova, K · 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Kolouri, S., Park, S. R., Thorpe, M., Slepcev, D., and Rohde, G. K · 2017
Cited alongside, same era.
Ensemble estimation of mutual information
Moon, K. R., Sricharan, K., and Hero, A. O · 2017
Cited alongside, same era.
Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms
Xiao, H., Rasul, K., and Vollgraf, R · 2017
Cited alongside, same era.
Mutual information neural estimation
Belghazi, M. I., Baratin, A., Rajeshwar, S., Ozair, S., Bengio, Y., Hjelm, R. D., and Courville, A. C · 2018
Cited alongside, same era.
Robust physical-world attacks on deep learning visual classification
Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D · 2018
Cited alongside, same era.
Adversarial vulnerability for any classifier
Fawzi, A., Fawzi, H., and Fawzi, O · 2018
Cited alongside, same era.
A spectral view of adversarially robust features
Garg, S., Sharan, V., Zhang, B., and Valiant, G · 2018
Cited alongside, same era.
Later among the works it cites.
On the connection between adversarial robustness and saliency map interpretability
Etmann, C., Lunz, S., Maass, P., and Schoenlieb, C · 2019
Later among the works it cites.
Robust classification using robust feature augmentation
Eykholt, K., Gupta, S., Prakash, A., and Zheng, H · 2019
Later among the works it cites.
Adversarial examples are not bugs, they are features
Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., and Mądry, A · 2019
Later among the works it cites.
The curse of concentration in robust learning: Evasion and poisoning attacks from concentration of measure
Mahloujifar, S., Diochnos, D. I., and Mahmoody, M · 2019
Later among the works it cites.
An introductory guide to Fano’s inequality with applications in statistical estimation
Scarlett, J. and Cevher, V · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E., El Ghaoui, L., and Jordan, M. I · 2019
Later among the works it cites.
Extracting robust and accurate features via a robust information bottleneck
Pensia, A., Jog, V., and Loh, P.-L · 2020
Closest in time.