Fetching the paper…
Reading the bibliography…
It is commonly believed that networks cannot be both accurate and robust, that gaining robustness means losing accuracy.
Digital selection and analogue amplification coexist in a cortex-inspired silicon circuit
Richard HR Hahnloser, Rahul Sarpeshkar, Misha A Mahowald, Rodney J Douglas, and H Sebastian Seung · 2000
Earlier work this paper cites.
Rectified linear units improve restricted boltzmann machines
Vinod Nair and Geoffrey E Hinton · 2010
Earlier work this paper cites.
Dropout: A simple way to prevent neural networks from overfitting
Nitish Srivastava, Geoffrey Hinton, Alex Krizhevsky, Ilya Sutskever, and Ruslan Salakhutdinov · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Foveation-based mechanisms alleviate adversarial examples
Yan Lou, Xavier Boix, Gemma Roig, Tomaso Poggio, and Qi Zhao · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Olga Russakovsky, Jia Deng, Hao Su, Jonathan Krause, Sanjeev Satheesh, Sean Ma, Zhiheng Huang, Andrej Karpathy, Aditya Khosla, Michael Bernstein, Alexander C. Berg, and Li Fei-Fei · 2015
Earlier work this paper cites.
Fast and accurate deep network learning by exponential linear units (elus)
Djork-Arné Clevert, Thomas Unterthiner, and Sepp Hochreiter · 2016
Earlier work this paper cites.
A study of the effect of jpg compression on adversarial images
Gintare Karolina Dziugaite, Zoubin Ghahramani, and Daniel M Roy · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Gaussian error linear units (gelus)
Dan Hendrycks and Kevin Gimpel · 2016
Earlier work this paper cites.
Deep networks with stochastic depth
Gao Huang, Yu Sun, Zhuang Liu, Daniel Sedra, and Kilian Q Weinberger · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Neural architecture search with reinforcement learning
Barret Zoph and Quoc V Le · 2016
Earlier work this paper cites.
Continuously differentiable exponential linear units
Jonathan T Barron · 2017
Earlier work this paper cites.
Train longer, generalize better: closing the generalization gap in large batch training of neural networks
Elad Hoffer, Itay Hubara, and Daniel Soudry · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Magnet: a two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
Searching for activation functions
Prajit Ramachandran, Barret Zoph, and Quoc V Le · 2017
Earlier work this paper cites.
Ensemble methods as a defense to adversarial perturbations against deep neural networks
Thilo Strauss, Markus Hanselmann, Andrej Junginger, and Holger Ulmer · 2017
Earlier work this paper cites.
Aggregated residual transformations for deep neural networks
Saining Xie, Ross Girshick, Piotr Dollár, Zhuowen Tu, and Kaiming He · 2017
Earlier work this paper cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Enhancing robustness of machine learning systems via data transformations
Arjun Nitin Bhagoji, Daniel Cullina, Chawin Sitawarin, and Prateek Mittal · 2018
Earlier work this paper cites.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Earlier work this paper cites.
Stochastic activation pruning for robust adversarial defense
Guneet S Dhillon, Kamyar Azizzadenesheli, Zachary C Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, and Anima Anandkumar · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Xiaolin Hu, Jianguo Li, and Jun Zhu · 2018
Cited alongside, same era.
Sigmoid-weighted linear units for neural network function approximation in reinforcement learning
Stefan Elfwing, Eiji Uchibe, and Kenji Doya · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten · 2018
Cited alongside, same era.
Averaging weights leads to wider optima and better generalization
Pavel Izmailov, Dmitrii Podoprikhin, Timur Garipov, Dmitry Vetrov, and Andrew Gordon Wilson · 2018
Cited alongside, same era.
Visualizing the loss landscape of neural nets
Hao Li, Zheng Xu, Gavin Taylor, Christoph Studer, and Tom Goldstein · 2018
Cited alongside, same era.
Towards the first adversarially robust neural network model on mnist
Lukas Schott, Jonas Rauber, Matthias Bethge, and Wieland Brendel · 2019
Later among the works it cites.
Adversarial training for free!
Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein · 2019
Later among the works it cites.
Efficientnet: Rethinking model scaling for convolutional neural networks
Mingxing Tan and Quoc Le · 2019
Later among the works it cites.
There is no free lunch in adversarial robustness (but there are unexpected benefits)
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Later among the works it cites.
Protecting neural networks with hierarchical random switching: Towards better robustness-accuracy trade-off for stochastic defenses
Xiao Wang, Siyue Wang, Pin-Yu Chen, Yanzhi Wang, Brian Kulis, Xue Lin, and Peter Chin · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Fangzhou Liao, Ming Liang, Yinpeng Dong, and Tianyu Pang · 2018
Cited alongside, same era.
Towards robust neural networks via random self-ensemble
Xuanqing Liu, Minhao Cheng, Huan Zhang, and Cho-Jui Hsieh · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Deflecting adversarial attacks with pixel deflection
Aaditya Prakash, Nick Moran, Solomon Garber, Antonella DiLillo, and James Storer · 2018
Cited alongside, same era.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Cited alongside, same era.
Certifying some distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2018
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Cited alongside, same era.
On the convergence and robustness of adversarial training
Yisen Wang, Xingjun Ma, James Bailey, Jinfeng Yi, Bowen Zhou, and Quanquan Gu · 2019
Later among the works it cites.
Enhancing adversarial defense by k-winners-take-all
Chang Xiao, Peilin Zhong, and Changxi Zheng · 2019
Later among the works it cites.
Feature denoising for improving adversarial robustness
Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan Yuille, and Kaiming He · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P Xing, Laurent El Ghaoui, and Michael I Jordan · 2019
Later among the works it cites.
Block-wise image transformation with secret key for adversarially robust defense
MaungMaung AprilPyone and Hitoshi Kiya · 2020
Closest in time.
Tanhsoft–a family of activation functions combining tanh and softplus
Koushik Biswas, Sandeep Kumar, Shilpak Banerjee, and Ashish Kumar Pandey · 2020
Closest in time.
Anti-bandit neural architecture search for model defense
Hanlin Chen, Baochang Zhang, Song Xue, Xuan Gong, Hong Liu, Rongrong Ji, and David Doermann · 2020
Closest in time.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Closest in time.
Max-margin adversarial (mma) training: Direct input space margin maximization through adversarial training
Gavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, and Ruitong Huang · 2020
Closest in time.
When nas meets robustness: In search of robust architectures against adversarial attacks
Minghao Guo, Yuzhe Yang, Rui Xu, Ziwei Liu, and Dahua Lin · 2020
Closest in time.
Robust ensemble model training via random layer sampling against adversarial attack
Hakmin Lee, Hong Joo Lee, Seong Tae Kim, and Yong Man Ro · 2020
Closest in time.
Generating accurate pseudo-labels in semi-supervised learning and avoiding overconfident predictions via hermite polynomial activations
Vishnu Suresh Lokhande, Songwong Tasneeyapant, Abhay Venkatesh, Sathya N. Ravi, and Vikas Singh · 2020
Closest in time.
Random mask: Towards robust convolutional neural networks
Tiange Luo, Tianle Cai, Mengxiao Zhang, Siyu Chen, and Liwei Wang · 2020
Closest in time.
Mixup inference: Better exploiting mixup to defend adversarial attacks
Tianyu Pang, Kun Xu, and Jun Zhu · 2020
Closest in time.
Smooth activations and reproducibility in deep networks
Gil Shamir, Dong Lin, and Lorenzo Coviello · 2020
Closest in time.
Improving adversarial robustness requires revisiting misclassified examples
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J Zico Kolter · 2020
Closest in time.
One man’s trash is another man’s treasure: Resisting adversarial examples by adversarial examples
Chang Xiao and Changxi Zheng · 2020
Closest in time.
Intriguing properties of adversarial training at scale
Cihang Xie and Alan Yuille · 2020
Closest in time.
Self-training with noisy student improves imagenet classification
Qizhe Xie, Eduard Hovy, Minh-Thang Luong, and Quoc Le · 2020
Closest in time.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2021
Closest in time.