Fetching the paper…
Reading the bibliography…
We investigate two causes for adversarial vulnerability in deep neural networks: bad data and (poorly) trained models.
Two models of double descent for weak features
M. Belkin, D. Hsu, and J. Xu · 1903
Earlier work this paper cites.
M. Li, M. Soltanolkotabi, and S. Oymak · 1903
Earlier work this paper cites.
D. Hendrycks, K. Zhao, S. Basart, J. Steinhardt, and D. Song · 1907
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner · 1998
Earlier work this paper cites.
Adversarial classification
N. Dalvi, P. Domingos, Mausam, S. Sanghai, and D. Verma · 2004
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky and G. Hinton · 2009
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
A. Krizhevsky, I. Sutskever, and G. E. Hinton · 2012
Earlier work this paper cites.
Speech recognition with deep recurrent neural networks
A. Graves, A.-r. Mohamed, and G. Hinton · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Explaining and Harnessing Adversarial Examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Delving deep into rectifiers: Surpassing human-level performance on imagenet classification
K. He, X. Zhang, S. Ren, and J. Sun · 2015
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami · 2015
Earlier work this paper cites.
Faster r-cnn: Towards real-time object detection with region proposal networks
S. Ren, K. He, R. Girshick, and J. Sun · 2015
Earlier work this paper cites.
Deep Residual Learning for Image Recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
A. Kurakin, I. Goodfellow, and S. Bengio · 2016
Earlier work this paper cites.
DeepFool: {A} Simple and Accurate Method to Fool Deep Neural Networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
N. Papernot, P. McDaniel, and I. Goodfellow · 2016
Earlier work this paper cites.
Wide residual networks
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Understanding deep learning requires rethinking generalization
C. Zhang, S. Bengio, M. Hardt, B. Recht, and O. Vinyals · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
Parseval networks: Improving robustness to adversarial examples
M. Cisse, P. Bojanowski, E. Grave, Y. Dauphin, and N. Usunier · 2017
Cited alongside, same era.
Adversarial example defenses: Ensembles of weak defenses are not strong
W. He, J. Wei, X. Chen, N. Carlini, and D. Song · 2017
Cited alongside, same era.
Adversarial machine learning at scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Complexity of linear regions in deep networks
B. Hanin and D. Rolnick · 2019
Later among the works it cites.
Surprises in high-dimensional ridgeless least squares interpolation
T. Hastie, A. Montanari, S. Rosset, and R. J. Tibshirani · 2019
Later among the works it cites.
Excessive invariance causes adversarial vulnerability
J.-H. Jacobsen, J. Behrmann, R. Zemel, and M. Bethge · 2019
Later among the works it cites.
Vc classes are adversarially robustly learnable, but only improperly
O. Montasser, S. Hanneke, and N. Srebro · 2019
Later among the works it cites.
Adversarial robustness may be at odds with simplicity
P. Nakkiran · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Attention is all you need
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Cited alongside, same era.
Wild patterns
B. Biggio and F. Roli · 2018
Cited alongside, same era.
Just interpolate: Kernel ”ridgeless” regression can generalize
T. Liang and A. Rakhlin · 2018
Cited alongside, same era.
An intriguing failing of convolutional neural networks and the coordconv solution
R. Liu, J. Lehman, P. Molino, F. P. Such, E. Frank, A. Sergeev, and J. Yosinski · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Cited alongside, same era.
A. Raghunathan, S. M. Xie, F. Yang, J. C. Duchi, and P. Liang · 2019
Later among the works it cites.
Learning with bad training data via iterative trimmed loss minimization
Y. Shen and S. Sanghavi · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry · 2019
Later among the works it cites.
Rademacher complexity for adversarially robust generalization
D. Yin, R. Kannan, and P. Bartlett · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
H. Zhang, Y. Yu, J. Jiao, E. P. Xing, L. E. Ghaoui, and M. I. Jordan · 2019
Later among the works it cites.
Benign overfitting in linear regression
P. L. Bartlett, P. M. Long, G. Lugosi, and A. Tsigler · 2020
Closest in time.
Finite-sample analysis of interpolating linear classifiers in the overparameterized regime
N. S. Chatterji and P. M. Long · 2020
Closest in time.
Invariance vs robustness of neural networks
S. Kamath, A. Deshpande, and K. V. Subrahmanyam · 2020
Closest in time.
Harmless interpolation of noisy data in regression
V. Muthukumar, K. Vodrahalli, V. Subramanian, and A. Sahai · 2020
Closest in time.
On adaptive attacks to adversarial example defenses
F. Tramer, N. Carlini, W. Brendel, and A. Madry · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
E. Wong, L. Rice, and J. Z. Kolter · 2020
Closest in time.
Adversarial robustness through local lipschitzness
Y.-Y. Yang, C. Rashtchian, H. Zhang, R. Salakhutdinov, and K. Chaudhuri · 2020
Closest in time.
What neural networks memorize and why: Discovering the long tail via influence estimation
C. Zhang and V. Feldman · 2020
Closest in time.