Fetching the paper…
Reading the bibliography…
Starting with Gilmer et al.
The Brunn-Minkowski inequality in Gauss space
Borell, C. (1975) · 1975
Earlier work this paper cites.
Extremal properties of half-spaces for spherically invariant measures
Sudakov, V. N. and Tsirelson, B. S. (1978) · 1978
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., Haffner, P., et al. (1998) · 1998
Earlier work this paper cites.
On adaptive attacks to adversarial example defenses
Tramer, F., Carlini, N., Brendel, W., and Madry, A. (2020) · 2002
Earlier work this paper cites.
ImageNet: A Large-Scale Hierarchical Image Database
Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., and Fei-Fei, L. (2009) · 2009
Earlier work this paper cites.
Deep neural networks for acoustic modeling in speech recognition
Hinton, G., Deng, L., Yu, D., Dahl, G., Mohamed, A.-r., Jaitly, N., Senior, A., Vanhoucke, V., Nguyen, P., Kingsbury, B., et al. (2012) · 2012
Earlier work this paper cites.
ImageNet classification with deep convolutional neural networks
Sutskever, I., Hinton, G. E., and Krizhevsky, A. (2012) · 2012
Earlier work this paper cites.
Generative adversarial nets
Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y. (2014) · 2014
Earlier work this paper cites.
Conditional generative adversarial nets
Mirza, M. and Osindero, S. (2014) · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2014) · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I., Shlens, J., and Szegedy, C. (2015) · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J. (2016) · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A. (2016) · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D. (2017) · 2017
Cited alongside, same era.
Reluplex: An efficient SMT solver for verifying deep neural networks
Katz, G., Barrett, C., Dill, D. L., Julian, K., and Kochenderfer, M. J. (2017) · 2017
Cited alongside, same era.
Conditional image synthesis with auxiliary classifier gans
Odena, A., Olah, C., and Shlens, J. (2017) · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D. (2018) · 2018
Cited alongside, same era.
MixTrain: Scalable training of formally robust neural networks
Wang, S., Chen, Y., Abdou, A., and Jana, S. (2018) · 2018
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, Z. (2018) · 2018
Later among the works it cites.
Scaling provable adversarial defenses
Wong, E., Schmidt, F., Metzen, J. H., and Kolter, J. Z. (2018) · 2018
Later among the works it cites.
Lower bounds on adversarial robustness from optimal transport
Bhagoji, A. N., Cullina, D., and Mittal, P. (2019) · 2019
Later among the works it cites.
Large scale GAN training for high fidelity natural image synthesis
Brock, A., Donahue, J., and Simonyan, K. (2019) · 2019
Later among the works it cites.
Generalized no free lunch theorem for adversarial robustness
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Chakraborty, A., Alam, M., Dey, V., Chattopadhyay, A., and Mukhopadhyay, D. (2018) · 2018
Cited alongside, same era.
Adversarial risk and robustness: General definitions and implications for the uniform distribution
Diochnos, D., Mahloujifar, S., and Mahmoody, M. (2018) · 2018
Cited alongside, same era.
Adversarial vulnerability for any classifier
Fawzi, A., Fawzi, H., and Fawzi, O. (2018) · 2018
Cited alongside, same era.
Gilmer, J., Metz, L., Faghri, F., Schoenholz, S. S., Raghu, M., Wattenberg, M., and Goodfellow, I. (2018) · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2018) · 2018
Cited alongside, same era.
Certified defenses against adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P. (2018) · 2018
Cited alongside, same era.
Certifying some distributional robustness with principled adversarial training
Sinha, A., Namkoong, H., and Duchi, J. (2018) · 2018
Cited alongside, same era.
Dohmatob, E. (2019) · 2019
Later among the works it cites.
Scalable verified training for provably robust image classification
Gowal, S., Dvijotham, K., Stanforth, R., Bunel, R., Qin, C., Uesato, J., Mann, T., and Kohli, P. (2019) · 2019
Later among the works it cites.
Are adversarial examples inevitable?
Shafahi, A., Huang, W. R., Studer, C., Feizi, S., and Goldstein, T. (2019) · 2019
Later among the works it cites.
Evaluating robustness of neural networks with mixed integer programming
Tjeng, V., Xiao, K. Y., and Tedrake, R. (2019) · 2019
Later among the works it cites.
On the convergence and robustness of adversarial training
Wang, Y., Ma, X., Bailey, J., Yi, J., Zhou, B., and Gu, Q. (2019) · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E., El Ghaoui, L., and Jordan, M. (2019) · 2019
Later among the works it cites.