Fetching the paper…
Reading the bibliography…
We identify three common cases that lead to overestimation of adversarial accuracy against bounded first-order attack methods, which is popularly used as a proxy for adversarial robustness in empirical studies.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., Haffner, P., et al · 1998
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A., Hinton, G., et al · 2009
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., and Ng, A. Y · 2011
Earlier work this paper cites.
Intriguing properties of neural networks, 2013
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition, 2014
Simonyan, K. and Zisserman, A · 2014
Earlier work this paper cites.
Deep compression: Compressing deep neural networks with pruning, trained quantization and huffman coding, 2015
Han, S., Mao, H., and Dally, W. J · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift, 2015
Ioffe, S. and Szegedy, C · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., and Fei-Fei, L · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Adversarial examples in the physical world, 2016
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Cited alongside, same era.
Zagoruyko, S. and Komodakis, N · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Ead: Elastic-net attacks to deep neural networks via adversarial examples, 2017
Chen, P.-Y., Sharma, Y., Zhang, H., Yi, J., and Hsieh, C.-J · 2017
Cited alongside, same era.
Parseval networks: Improving robustness to adversarial examples, 2017
Cisse, M., Bojanowski, P., Grave, E., Dauphin, Y., and Usunier, N · 2017
Cited alongside, same era.
Boosting adversarial attacks with momentum, 2017
Provable defenses against adversarial examples via the convex outer adversarial polytope, 2017
Wong, E. and Kolter, J. Z · 2017
Later among the works it cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples, 2018
Athalye, A., Carlini, N., and Wagner, D · 2018
Later among the works it cites.
Wild patterns: Ten years after the rise of adversarial machine learning
Biggio, B. and Roli, F · 2018
Later among the works it cites.
Improving dnn robustness to adversarial attacks using jacobian regularization, 2018
Jakubovitz, D. and Giryes, R · 2018
Later among the works it cites.
Spectral normalization for generative adversarial networks
Miyato, T., Kataoka, T., Koyama, M., and Yoshida, Y · 2018
Later among the works it cites.
Virtual adversarial training: A regularization method for supervised and semi-supervised learning
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
Automatic differentiation in PyTorch
Paszke, A., Gross, S., Chintala, S., Chanan, G., Yang, E., DeVito, Z., Lin, Z., Desmaison, A., Antiga, L., and Lerer, A · 2017
Cited alongside, same era.
Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients, 2017
Ross, A. S. and Doshi-Velez, F · 2017
Cited alongside, same era.
Certifying some distributional robustness with principled adversarial training, 2017
Sinha, A., Namkoong, H., and Duchi, J · 2017
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses, 2017
Tramèr, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2017
Cited alongside, same era.
Miyato, T., Maeda, S.-I., Koyama, M., and Ishii, S · 2018
Later among the works it cites.
Certified defenses against adversarial examples, 2018
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Later among the works it cites.
Su, D., Zhang, H., Chen, H., Yi, J., Chen, P.-Y., and Gao, Y · 2018
Later among the works it cites.
Architecture selection via the trade-off between accuracy and robustness, 2019
Deng, Z., Dwork, C., Wang, J., and Zhao, Y · 2019
Later among the works it cites.
AdverTorch v0.1: An adversarial robustness toolbox based on pytorch
Ding, G. W., Wang, L., and Jin, X · 2019
Later among the works it cites.
Defensive quantization: When efficiency meets robustness
Lin, J., Gan, C., and Han, S · 2019
Later among the works it cites.
Evaluating robustness of neural networks with mixed integer programming
Tjeng, V., Xiao, K. Y., and Tedrake, R · 2019
Later among the works it cites.