Theoretically principled trade-off between robustness and accuracy
Original
H. Zhang, Y. Yu, J. Jiao, E. P. Xing, L. E. Ghaoui, and M. I. Jordan · 1901
Earlier work this paper cites.
Asymptotic minimax character of the sample distribution function and of the classical multinomial estimator
A. Dvoretzky, J. Kiefer, and J. Wolfowitz · 1956
Earlier work this paper cites.
The brunn-minkowski inequality in gauss space
C. Borell · 1975
Earlier work this paper cites.
Extremal properties of half-spaces for spherically invariant measures
V. N. Sudakov and B. S. Tsirel’son · 1978
Earlier work this paper cites.
The curious case of adversarially robust models: More data can help, double descend, or hurt generalization, 2020
Original
Y. Min, L. Chen, and A. Karbasi · 2002
Earlier work this paper cites.
An Introduction to Multivariate Statistical Analysis
T. W. Anderson · 2003
Earlier work this paper cites.
A closer look at accuracy vs. robustness
Original
Y.-Y. Yang, C. Rashtchian, H. Zhang, R. Salakhutdinov, and K. Chaudhuri · 2003
Earlier work this paper cites.
Convexity, classification, and risk bounds
P. L. Bartlett, M. I. Jordan, and J. D. McAuliffe · 2006
Earlier work this paper cites.
Pattern recognition and machine learning
C. M. Bishop · 2006
Earlier work this paper cites.
Introduction to empirical processes and semiparametric inference
M. R. Kosorok · 2007
Earlier work this paper cites.
How to compare different loss functions and their risks
I. Steinwart · 2007
Earlier work this paper cites.
The elements of statistical learning: data mining, inference, and prediction
T. Hastie, R. Tibshirani, and J. Friedman · 2009
Earlier work this paper cites.
Empirical processes with applications to statistics
G. R. Shorack and J. A. Wellner · 2009
Earlier work this paper cites.
On the isoperimetric deficit in gauss space
A. Cianchi, N. Fusco, F. Maggi, and A. Pratelli · 2011
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Concentration inequalities: A nonasymptotic theory of independence
S. Boucheron, G. Lugosi, and P. Massart · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Original
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Original
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Deep learning
Y. LeCun, Y. Bengio, and G. Hinton · 2015
Earlier work this paper cites.
Robust dimension free isoperimetry in gaussian space
E. Mossel and J. Neeman · 2015
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Understanding deep learning requires rethinking generalization
Original
C. Zhang, S. Bengio, M. Hardt, B. Recht, and O. Vinyals · 2016
Earlier work this paper cites.
A closer look at memorization in deep networks
D. Arpit, S. Jastrzębski, N. Ballas, D. Krueger, E. Bengio, M. S. Kanwal, T. Maharaj, A. Fischer, A. Courville, and Y. Bengio · 2017
Earlier work this paper cites.
Synthesizing robust adversarial examples
Original
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok · 2017
Earlier work this paper cites.