Fetching the paper…
Reading the bibliography…
The vulnerability of deep networks to adversarial attacks is a central problem for deep learning from the perspective of both cognition and security.
Kolmogorov entropy and numerical experiments
Giancarlo Benettin, Luigi Galgani, and Jean-Marie Streclyn · 1976
Earlier work this paper cites.
Filters, random fields and maximum entropy (FRAME): towards a unified theory for texture modeling
Song-Chun Zhu, Ying Nian Wu, and David Mumford · 1998
Earlier work this paper cites.
Training products of experts by minimizing contrastive divergence
Geoffrey E. Hinton · 2002
Earlier work this paper cites.
Modeling visual patterns by integrating descriptive and generative methods
Cheng-En Guo, Song-Chun Zhu, and Ying Nian Wu · 2003
Earlier work this paper cites.
Noise-induced unstable dimension variability and transition to chaos in random dynamical systems
Ying-Cheng Lai, Zonghua Liu, Lora Billiings, and Ira B. Schartz · 2003
Earlier work this paper cites.
Statistical modeling and conceptualization of visual patterns
Song-Chun Zhu · 2003
Earlier work this paper cites.
Metastability: A potential theoretic approach
Anton Bovier and Frank den Hollander · 2006
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P. Kingma and Jimmy Ba · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, X. Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
A theory of generative convnet
Jianwen Xie, Yang Lu, Song-Chun Zhu, and Yingnian Wu · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Gans trained by a two time-scale update rule converge to a local nash equilibrium
Martin Heusel, Hubert Ramsauer, Thomas Unterthiner, Bernhard Nessler, and Sepp Hochreiter · 2017
Earlier work this paper cites.
Improving generalization by switching from adam to sgd
Nitish Shirish Keskar and Richard Socher · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Guneet S. Dhillon, Kamyar Azizzadenesheli, Jeremy D. Bernstein, Jean Kossaifi, Aran Khanna, Zachary C. Lipton, and Animashree Anandkumar · 2018
Cited alongside, same era.
Learning generative convnets via multi-grid modeling and sampling
Ruiqi Gao, Yang Lu, Junpei Zhou, Song-Chun Zhu, and Ying Nian Wu · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Implicit generation and modeling with energy based models
Yilun Du and Igor Mordatch · 2019
Later among the works it cites.
Parametric noise injection: Trainable randomness to improve deep neural network robustness against adversarial attack
Zhezhi He, Adnan Siraj Rakin, and Deliang Fan · 2019
Later among the works it cites.
Learning non-convergent non-persistent short-run MCMC toward energy-based model
Erik Nijkamp, Mitch Hill, Song-Chun Zhu, and Ying Nian Wu · 2019
Later among the works it cites.
Barrage of random transforms for adversarially robust defense
Edward Raff, Jared Sylvester, Steven Forsyth, and Mark McLean · 2019
Later among the works it cites.
Defense against adversarial attacks by langevin dynamics
Vignesh Srinivasan, Arturo Marban, Klaus-Robert Muller, Wojciech Samek, and Shinichi Nakajima · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Cited alongside, same era.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Cited alongside, same era.
Are labels required for improving adversarial robustness?
Jean-Baptiste Alayrac, Jonathan Uesato, Po-Sen Huang, Alhussein Fawzi, Robert Stanforth, and Pushmeet Kohli · 2019
Cited alongside, same era.
Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets
Yogesh Balaji, Tom Goldstein, and Judy Hoffman · 2019
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, John C Duchi, and Percy S Liang · 2019
Cited alongside, same era.
Me-net: Towards effective adversarial robustness with matrix estimation
Yuzhe Yang, Guo Zhang, Dina Katabi, and Zhi Xu · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan · 2019
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Closest in time.
Flow contrastive estimation of energy-based models
Ruiqi Gao, Erik Nijkamp, Diederik P Kingma, Zhen Xu, Andrew M Dai, and Ying Nian Wu · 2020
Closest in time.
Your classifier is secretly an energy based model and you should treat it like one
Will Grathwohl, Kuan-Chieh Wang, Joern-Henrik Jacobsen, David Duvenaud, Mohammad Norouzi, and Kevin Swersky · 2020
Closest in time.
On the anatomy of MCMC-based maximum likelihood learning of energy-based models
Erik Nijkamp, Mitch Hill, Tian Han, Song-Chun Zhu, and Ying Nian Wu · 2020
Closest in time.
Denoised smoothing: A provable defense for pretrained classifiers
Hadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor, and J. Zico Kolter · 2020
Closest in time.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Closest in time.