Fetching the paper…
Reading the bibliography…
We introduce the concept of provably robust adversarial examples for deep neural networks - connected input regions constructed from standard adversarial examples which are guaranteed to be robust to a set of real-world perturbations (such as changes in pixel intensity and geometric transformations).
An algorithm for quadratic programming
Marguerite Frank and Philip Wolfe · 1956
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Theory of linear and integer programming
Alexander Schrijver · 1998
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
TensorFlow: Large-scale machine learning on heterogeneous systems, 2015
Martín Abadi, Ashish Agarwal, Paul Barham, Eugene Brevdo, Zhifeng Chen, Craig Citro, Greg S. Corrado, Andy Davis, Jeffrey Dean, Matthieu Devin, Sanjay Ghemawat, Ian Goodfellow, Andrew Harp, Geoffrey Irving, Michael Isard, Yangqing Jia, Rafal Jozefowicz, Lukasz Kaiser, Manjunath Kudlur, Josh Levenberg, Dan Mané, Rajat Monga, Sherry Moore, Derek Murray, Chris Olah, Mike Schuster, Jonathon Shlens, Benoit Steiner, Ilya Sutskever, Kunal Talwar, Paul Tucker, Vincent Vanhoucke, Vijay Vasudevan, Fernanda Viégas, Oriol Vinyals, Pete Warden, Martin Wattenberg, Martin Wicke, Yuan Yu, and Xiaoqiang Zheng · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Max Jaderberg, Karen Simonyan, Andrew Zisserman, and Koray Kavukcuoglu · 2015
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
Formal verification of piece-wise linear feed-forward neural networks
Ruediger Ehlers · 2017
Earlier work this paper cites.
Synthesizing robust adversarial examples
Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok · 2018
Earlier work this paper cites.
Ai2: Safety and robustness certification of neural networks with abstract interpretation
Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin Vechev · 2018
Earlier work this paper cites.
Efficient neural network robustness certification with general activation functions
Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel · 2018
Cited alongside, same era.
Square attack: a query-efficient black-box adversarial attack via random search, 2019
Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion, and Matthias Hein · 2019
Cited alongside, same era.
Certifying geometric robustness of neural networks
Mislav Balunović, Maximilian Baader, Gagandeep Singh, Timon Gehr, and Martin Vechev · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Cited alongside, same era.
Minimally distorted adversarial examples with a fast adaptive boundary attack, 2019
Francesco Croce and Matthias Hein · 2019
Cited alongside, same era.
Exploring the landscape of spatial robustness
Enhancing gradient-based attacks with symbolic intervals, 2019
Shiqi Wang, Yizheng Chen, Ahmed Abdou, and Suman Jana · 2019
Later among the works it cites.
Distributionally adversarial attack
Tianhang Zheng, Changyou Chen, and Kui Ren · 2019
Later among the works it cites.
Adversarial training and provable defenses: Bridging the gap
Mislav Balunovic and Martin Vechev · 2020
Closest in time.
Certified defenses for adversarial patches
Ping-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu, Christoph Studer, and Tom Goldstein · 2020
Closest in time.
Certified defense to image transformations via randomized smoothing
Marc Fischer, Maximilian Baader, and Martin T. Vechev · 2020
Closest in time.
Gurobi optimizer reference manual, 2020
Gurobi Optimization, LLC · 2020
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry · 2019
Cited alongside, same era.
Property inference for deep neural networks
Divya Gopinath, Hayes Converse, Corina Pasareanu, and Ankur Taly · 2019
Cited alongside, same era.
A new defense against adversarial images: Turning a weakness into a strength
Shengyuan Hu, Tao Yu, Chuan Guo, Wei-Lun Chao, and Kilian Q. Weinberger · 2019
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
Mathias Lécuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2019
Cited alongside, same era.
On certifying non-uniform bounds against adversarial attacks
Chen Liu, Ryota Tomioka, and Volkan Cevher · 2019
Cited alongside, same era.
Imperceptible, robust, and targeted adversarial examples for automatic speech recognition
Yao Qin, Nicholas Carlini, Garrison Cottrell, Ian Goodfellow, and Colin Raffel · 2019
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
Hadi Salman, Jerry Li, Ilya P. Razenshteyn, Pengchuan Zhang, Huan Zhang, Sébastien Bubeck, and Greg Yang · 2019
Cited alongside, same era.
Linyi Li, Maurice Weber, Xiaojun Xu, Luka Rimanic, Tao Xie, Ce Zhang, and Bo Li · 2020
Closest in time.
Rethinking softmax cross-entropy loss for adversarial robustness
Tianyu Pang, Kun Xu, Yinpeng Dong, Chao Du, Ning Chen, and Jun Zhu · 2020
Closest in time.
EMPIR: ensembles of mixed precision deep networks for increased robustness against adversarial attacks
Sanchari Sen, Balaraman Ravindran, and Anand Raghunathan · 2020
Closest in time.
Output diversified initialization for adversarial attacks
Yusuke Tashiro, Yang Song, and Stefano Ermon · 2020
Closest in time.
On adaptive attacks to adversarial example defenses
Florian Tramèr, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Closest in time.
Enhancing adversarial defense by k-winners-take-all
Chang Xiao, Peilin Zhong, and Changxi Zheng · 2020
Closest in time.
Certified defenses: Why tighter relaxations may hurt training
Nikola Jovanović, Mislav Balunović, Maximilian Baader, and Martin Vechev · 2021
Closest in time.