Fetching the paper…
Reading the bibliography…
Adversarial robustness has proven to be a required property of machine learning algorithms.
Is ami (attacks meet interpretability) robust to adversarial examples?
Carlini, N · 1902
Earlier work this paper cites.
On evaluating adversarial robustness
Carlini, N., Athalye, A., Papernot, N., Brendel, W., Rauber, J., Tsipras, D., Goodfellow, I. J., Madry, A., and Kurakin, A · 1902
Earlier work this paper cites.
Certified adversarial robustness via randomized smoothing
Cohen, J. M., Rosenfeld, E., and Kolter, J. Z · 1902
Earlier work this paper cites.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J. P., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T · 1904
Earlier work this paper cites.
Adversarial examples are not bugs, they are features, 2019
Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., and Madry, A · 1905
Earlier work this paper cites.
Explaining landscape connectivity of low-cost solutions for multilayer nets
Kuditipudi, R., Wang, X., Lee, H., Zhang, Y., Li, Z., Hu, W., Arora, S., and Ge, R · 1906
Earlier work this paper cites.
Adversarially robust generalization just requires more unlabeled data
Zhai, R., Cai, T., He, D., Dan, C., He, K., Hopcroft, J. E., and Wang, L · 1906
Earlier work this paper cites.
Convolutional networks for images, speech, and time-series
Lecun, Y. and Bengio, Y · 1995
Earlier work this paper cites.
A probabilistic theory of pattern recognition
Devroye, L., Gyorfi, L., and Lugosi, G · 1997
Earlier work this paper cites.
Adversarial classification
Dalvi, N., Domingos, P., Sumit, M., and Verma, S. D · 2004
Earlier work this paper cites.
Nightmare at test time: robust learning by feature deletion
Globerson, A. and Roweis, S. T · 2006
Earlier work this paper cites.
Robust Optimization , volume 28 of Princeton Series in Applied Mathematics
Ben-Tal, A., Ghaoui, L. E., and Nemirovski, A · 2009
Earlier work this paper cites.
Feature weighting for improved classifier robustness
Kolcz, A. and Teo, C. H · 2009
Earlier work this paper cites.
Understanding the difficulty of training deep feedforward neural networks
Glorot, X. and Bengio, Y · 2010
Earlier work this paper cites.
MNIST handwritten digit database
LeCun, Y. and Cortes, C · 2010
Earlier work this paper cites.
Speech recognition with deep recurrent neural networks
Graves, A., Mohamed, A., and Hinton, G. E · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization, 2014
Kingma, D. P. and Ba, J · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Qualitatively characterizing neural network optimization problems
Goodfellow, I., Vinyals, O., and Saxe, A · 2015
Earlier work this paper cites.
Explaining nonlinear classification decisions with deep taylor decomposition
Montavon, G., Bach, S., Binder, A., Samek, W., and Müller, K · 2015
Earlier work this paper cites.
Defensive distillation is not robust to adversarial examples
Carlini, N. and Wagner, D. A · 2016
Earlier work this paper cites.
Hidden voice commands
Carlini, N., Mishra, P., Vaidya, T., Zhang, Y., Sherr, M., Shields, C., Wagner, D. A., and Zhou, W · 2016
Earlier work this paper cites.
Topology and geometry of half-rectified network optimization, 2016
Freeman, C. D. and Bruna, J · 2016
Earlier work this paper cites.
Practical black-box attacks against machine learning, 2016
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2016
Cited alongside, same era.
Selvaraju, R. R., Das, A., Vedantam, R., Cogswell, M., Parikh, D., and Batra, D · 2016
Cited alongside, same era.
Achieving human parity in conversational speech recognition
Xiong, W., Droppo, J., Huang, X., Seide, F., Seltzer, M., Stolcke, A., Yu, D., and Zweig, G · 2016
Cited alongside, same era.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Srndic, N., Laskov, P., Giacinto, G., and Roli, F · 2017
Cited alongside, same era.
Magnet and ”efficient defenses against adversarial attacks” are not robust to adversarial examples
Towards the first adversarially robust neural network model on mnist, 2018
Schott, L., Rauber, J., Bethge, M., and Brendel, W · 2018
Later among the works it cites.
Label smoothing and logit squeezing: A replacement for adversarial training?
Shafahi, A., Ghiasi, A., Huang, F., and Goldstein, T · 2018
Later among the works it cites.
Attacking the madry defense model with $l_1$-based adversarial examples
Sharma, Y. and Chen, P · 2018
Later among the works it cites.
First-order adversarial vulnerability of neural networks and input dimension, 2018
Simon-Gabriel, C.-J., Ollivier, Y., Bottou, L., Schölkopf, B., and Lopez-Paz, D · 2018
Later among the works it cites.
Improving the generalization of adversarial training with domain adaptation
Song, C., He, K., Wang, L., and Hopcroft, J. E · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Carlini, N. and Wagner, D. A · 2017
Cited alongside, same era.
A rotation and a translation suffice: Fooling cnns with simple transformations
Engstrom, L., Tsipras, D., Schmidt, L., and Madry, A · 2017
Cited alongside, same era.
Learning TensorFlow: A Guide to Building Deep Learning Systems
Hope, T., Resheff, Y. S., and Lieder, I · 2017
Cited alongside, same era.
Visualizing the loss landscape of neural nets
Li, H., Xu, Z., Taylor, G., and Goldstein, T · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Analyzing the robustness of nearest neighbors to adversarial examples
Wang, Y., Jha, S., and Chaudhuri, K · 2017
Cited alongside, same era.
On the robustness of the CVPR 2018 white-box adversarial example defenses
Athalye, A. and Carlini, N · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D. A · 2018
Cited alongside, same era.
Robustness may be at odds with accuracy, 2018
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks, 2018
Uesato, J., O’Donoghue, B., van den Oord, A., and Kohli, P · 2018
Later among the works it cites.
Rademacher complexity for adversarially robust generalization, 2018
Yin, D., Ramchandran, K., and Bartlett, P · 2018
Later among the works it cites.
Lower bounds for adversarially robust pac learning, 2019
Diochnos, D. I., Mahloujifar, S., and Mahmoody, M · 2019
Later among the works it cites.
A discussion of ’adversarial examples are not bugs, they are features’: Discussion and author responses
Engstrom, L., Ilyas, A., Madry, A., Santurkar, S., Tran, B., and Tsipras, D · 2019
Later among the works it cites.
Adversarial examples are a natural consequence of test error in noise, 2019
Ford, N., Gilmer, J., Carlini, N., and Cubuk, D · 2019
Later among the works it cites.
Convergence of adversarial training in overparametrized neural networks, 2019
Gao, R., Cai, T., Li, H., Wang, L., Hsieh, C.-J., and Lee, J. D · 2019
Later among the works it cites.
Adversarially robust learning could leverage computational hardness, 2019
Garg, S., Jha, S., Mahloujifar, S., and Mahmoody, M · 2019
Later among the works it cites.
On the hardness of robust classification, 2019
Gourdeau, P., Kanade, V., Kwiatkowska, M., and Worrell, J · 2019
Later among the works it cites.
An alternative surrogate loss for pgd-based adversarial testing, 2019
Gowal, S., Uesato, J., Qin, C., Huang, P.-S., Mann, T., and Kohli, P · 2019
Later among the works it cites.
Are perceptually-aligned gradients a general property of robust classifiers?
Kaur, S., Cohen, J., and Lipton, Z. C · 2019
Later among the works it cites.
Adversarial music: Real world audio adversary against wake-word detection system
Li, J., Qu, S., Li, X., Szurley, J., Kolter, J. Z., and Metze, F · 2019
Later among the works it cites.
Adversarial robustness against the union of multiple perturbation models, 2019
Maini, P., Wong, E., and Kolter, J. Z · 2019
Later among the works it cites.
Vc classes are adversarially robustly learnable, but only improperly, 2019
Montasser, O., Hanneke, S., and Srebro, N · 2019
Later among the works it cites.
Provably robust deep learning via adversarially trained smoothed classifiers, 2019
Salman, H., Yang, G., Li, J., Zhang, P., Zhang, H., Razenshteyn, I., and Bubeck, S · 2019
Later among the works it cites.
Competitive gradient descent
Schäfer, F. and Anandkumar, A · 2019
Later among the works it cites.
Adversarial training and robustness for multiple perturbations
Tramer, F. and Boneh, D · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy, 2019
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 2019
Later among the works it cites.
More data can expand the generalization gap between adversarially robust and standard models, 2020
Chen, L., Min, Y., Zhang, M., and Karbasi, A · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z · 2020
Closest in time.