Fetching the paper…
Reading the bibliography…
Great advances in deep neural networks (DNNs) have led to state-of-the-art performance on a wide range of tasks.
R. Mises and H. Pollaczek-Geiringer, “Praktische verfahren der gleichungsauflösung.” ZAMM-Journal of Applied Mathematics and Mechanics/Zeitschrift für Angewandte Mathematik und Mechanik , vol. 9, no. 1, pp. 58–77, 1929
1929
Earlier work this paper cites.
J. Neyman and E. S. Pearson, “Ix. on the problem of the most efficient tests of statistical hypotheses,” Philosophical Transactions of the Royal Society of London. Series A, Containing Papers of a Mathematical or Physical Character , vol. 231, no. 694-706, pp. 289–337, 1933
1933
Earlier work this paper cites.
P. Cousot and R. Cousot, “Abstract interpretation: a unified lattice model for static analysis of programs by construction or approximation of fixpoints,” in Proceedings of the 4th ACM SIGACT-SIGPLAN symposium on Principles of programming languages , 1977, pp. 238–252
1977
Earlier work this paper cites.
J. P. Ignizio and T. M. Cavalier, Linear programming . Prentice-Hall, Inc., 1994
1994
Earlier work this paper cites.
N. Dalvi, P. Domingos, S. Sanghai, and D. Verma, “Adversarial classification,” in Proceedings of the tenth ACM SIGKDD international conference on Knowledge discovery and data mining , 2004, pp. 99–108
2004
Earlier work this paper cites.
S. Boyd, S. P. Boyd, and L. Vandenberghe, Convex optimization . Cambridge, England: Cambridge university press, 2004
2004
Earlier work this paper cites.
D. Lowd and C. Meek, “Adversarial learning,” in Proceedings of the eleventh ACM SIGKDD international conference on Knowledge discovery in data mining , 2005, pp. 641–647
2005
Earlier work this paper cites.
L. De Moura and N. Bjørner, “Z3: An efficient smt solver,” in International conference on Tools and Algorithms for the Construction and Analysis of Systems . Springer, 2008, pp. 337–340
2008
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” Master’s thesis, Department of Computer Science, University of Toronto , 2009
2009
Earlier work this paper cites.
L. Pulina and A. Tacchella, “An abstraction-refinement approach to verification of artificial neural networks,” in International Conference on Computer Aided Verification . Springer, 2010, pp. 243–257
2010
Earlier work this paper cites.
L. Huang, A. D. Joseph, B. Nelson, B. I. Rubinstein, and J. D. Tygar, “Adversarial machine learning,” in Proceedings of the 4th ACM workshop on Security and artificial intelligence , 2011, pp. 43–58
2011
Earlier work this paper cites.
——, “Challenging smt solvers to verify neural networks,” Ai Communications , vol. 25, no. 2, pp. 117–135, 2012
2012
Earlier work this paper cites.
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli, “Evasion attacks against machine learning at test time,” in Joint European conference on machine learning and knowledge discovery in databases . Springer, 2013, pp. 387–402
2013
Earlier work this paper cites.
2013
Earlier work this paper cites.
I. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, and Y. Bengio, “Generative adversarial nets,” Advances in neural information processing systems , vol. 27, 2014
2014
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in International Conference on Learning Representations , 2015
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 770–778
2016
Earlier work this paper cites.
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 2818–2826
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in 2016 IEEE Symposium on Security and Privacy (SP) . IEEE, 2016, pp. 582–597
2016
Earlier work this paper cites.
K. D. Julian, J. Lopez, J. S. Brush, M. P. Owen, and M. J. Kochenderfer, “Policy compression for aircraft collision avoidance systems,” in 2016 IEEE/AIAA 35th Digital Avionics Systems Conference . IEEE, 2016, pp. 1–10
2016
Earlier work this paper cites.
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, “Attention is all you need,” in Advances in neural information processing systems , 2017, pp. 5998–6008
2017
Earlier work this paper cites.
G. Katz, C. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer, “Reluplex: An efficient smt solver for verifying deep neural networks,” in International Conference on Computer Aided Verification . Springer, 2017, pp. 97–117
2017
Earlier work this paper cites.
C.-H. Cheng, G. Nührenberg, and H. Ruess, “Maximum resilience of artificial neural networks,” in International Symposium on Automated Technology for Verification and Analysis . Springer, 2017, pp. 251–268
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
R. Ehlers, “Formal verification of piece-wise linear feed-forward neural networks,” in International Symposium on Automated Technology for Verification and Analysis . Springer, 2017, pp. 269–286
2017
Earlier work this paper cites.
M. Hein and M. Andriushchenko, “Formal guarantees on the robustness of a classifier against adversarial manipulation,” in Advances in Neural Information Processing Systems , 2017, pp. 2266–2276
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 IEEE Symposium on Security and Privacy (SP) . IEEE, 2017, pp. 39–57
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
K. Pei, Y. Cao, J. Yang, and S. Jana, “Deepxplore: Automated whitebox testing of deep learning systems,” in proceedings of the 26th Symposium on Operating Systems Principles , 2017, pp. 1–18
2017
Earlier work this paper cites.
2018
Earlier work this paper cites.
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” in International Conference on Machine Learning , 2018, pp. 274–283
2018
Earlier work this paper cites.
W. Brendel, J. Rauber, and M. Bethge, “Decision-based adversarial attacks: Reliable attacks against black-box machine learning models,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust physical-world attacks on deep learning visual classification,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2018, pp. 1625–1634
2018
Earlier work this paper cites.
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow, “Thermometer encoding: One hot way to resist adversarial examples,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
C. Guo, M. Rana, M. Cisse, and L. van der Maaten, “Countering adversarial images using input transformations,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
P. Samangouei, M. Kabkab, and R. Chellappa, “Defense-GAN: Protecting classifiers against adversarial attacks using generative models,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
S. Wang, K. Pei, J. Whitehouse, J. Yang, and S. Jana, “Efficient formal safety analysis of neural networks,” in Advances in Neural Information Processing Systems , 2018, pp. 6367–6377
2018
Earlier work this paper cites.
E. Wong and Z. Kolter, “Provable defenses against adversarial examples via the convex outer adversarial polytope,” in International Conference on Machine Learning , 2018, pp. 5286–5295
2018
Earlier work this paper cites.
B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning,” Pattern Recognition , vol. 84, pp. 317–331, 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
N. Papernot, P. McDaniel, A. Sinha, and M. P. Wellman, “Sok: Security and privacy in machine learning,” in 2018 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 2018, pp. 399–414
2018
Earlier work this paper cites.
T. Gehr, M. Mirman, D. Drachsler-Cohen, P. Tsankov, S. Chaudhuri, and M. Vechev, “AI 2 : Safety and robustness certification of neural networks with abstract interpretation,” in 2018 IEEE Symposium on Security and Privacy (SP) . IEEE, 2018, pp. 3–18
2018
Earlier work this paper cites.
H. Zhang, T.-W. Weng, P.-Y. Chen, C.-J. Hsieh, and L. Daniel, “Efficient neural network robustness certification with general activation functions,” in Advances in neural information processing systems , 2018, pp. 4939–4948
2018
Earlier work this paper cites.
L. Weng, H. Zhang, H. Chen, Z. Song, C.-J. Hsieh, L. Daniel, D. Boning, and I. Dhillon, “Towards fast computation of certified robustness for relu networks,” in International Conference on Machine Learning , 2018, pp. 5276–5285
2018
Earlier work this paper cites.
S. Dutta, S. Jha, S. Sankaranarayanan, and A. Tiwari, “Output range analysis for deep feedforward neural networks,” in NASA Formal Methods - 10th International Symposium , vol. 10811, 2018, pp. 121–138
2018
Earlier work this paper cites.
R. R. Bunel, I. Turkaslan, P. Torr, P. Kohli, and P. K. Mudigonda, “A unified view of piecewise linear neural network verification,” in Advances in Neural Information Processing Systems , 2018, pp. 4790–4799
2018
Earlier work this paper cites.
S. Wang, K. Pei, J. Whitehouse, J. Yang, and S. Jana, “Formal security analysis of neural networks using symbolic intervals,” in 27th USENIX Security Symposium (USENIX) Security 18) , 2018, pp. 1599–1614
2018
Earlier work this paper cites.
M. Mirman, T. Gehr, and M. Vechev, “Differentiable abstract interpretation for provably robust neural networks,” in International Conference on Machine Learning , 2018, pp. 3575–3583
2018
Earlier work this paper cites.
G. Singh, T. Gehr, M. Mirman, M. Püschel, and M. Vechev, “Fast and effective robustness certification,” in Advances in Neural Information Processing Systems , 2018, pp. 10 802–10 813
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
K. Dvijotham, R. Stanforth, S. Gowal, T. A. Mann, and P. Kohli, “A dual approach to scalable verification of deep networks.” in Proceedings of the Thirty-Fourth Conference on Uncertainty in Artificial Intelligence , vol. 1, 2018, pp. 550–559
2018
Earlier work this paper cites.
E. Wong, F. Schmidt, J. H. Metzen, and J. Z. Kolter, “Scaling provable adversarial defenses,” in Advances in Neural Information Processing Systems , 2018, pp. 8400–8409
2018
Earlier work this paper cites.
A. Raghunathan, J. Steinhardt, and P. Liang, “Certified defenses against adversarial examples,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
A. Raghunathan, J. Steinhardt, and P. S. Liang, “Semidefinite relaxations for certifying robustness to adversarial examples,” in Advances in Neural Information Processing Systems , 2018, pp. 10 877–10 887
2018
Earlier work this paper cites.
Y. Tsuzuku, I. Sato, and M. Sugiyama, “Lipschitz-margin training: scalable certification of perturbation invariance for deep neural networks,” in Advances in Neural Information Processing Systems , 2018
2018
Earlier work this paper cites.
N. Bansal, X. Chen, and Z. Wang, “Can we gain more from orthogonality regularizations in training deep networks?” in Advances in Neural Information Processing Systems , vol. 31, 2018
2018
Earlier work this paper cites.
C. Xiao, J.-Y. Zhu, B. Li, W. He, M. Liu, and D. Song, “Spatially transformed adversarial examples,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
A. Sinha, H. Namkoong, and J. Duchi, “Certifying some distributional robustness with principled adversarial training,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
J. Cohen, E. Rosenfeld, and Z. Kolter, “Certified adversarial robustness via randomized smoothing,” in International Conference on Machine Learning , 2019
2019
Earlier work this paper cites.
G. Singh, R. Ganvir, M. Püschel, and M. Vechev, “Beyond the single neuron convex barrier for neural network certification,” in Advances in Neural Information Processing Systems , 2019, pp. 15 072–15 083
2019
Earlier work this paper cites.
G. Singh, T. Gehr, M. Püschel, and M. Vechev, “Boosting robustness certification of neural networks,” in International Conference on Learning Representations , 2019
2019
Earlier work this paper cites.
H. Salman, G. Yang, H. Zhang, C.-J. Hsieh, and P. Zhang, “A convex relaxation barrier to tight robustness verification of neural networks,” in Advances in Neural Information Processing Systems , 2019, pp. 9832–9842
2019
Earlier work this paper cites.
V. Tjeng, K. Y. Xiao, and R. Tedrake, “Evaluating robustness of neural networks with mixed integer programming,” in International Conference on Learning Representations , 2019
2019
Earlier work this paper cites.
G. Katz, D. A. Huang, D. Ibeling, K. Julian, C. Lazarus, R. Lim, P. Shah, S. Thakoor, H. Wu, A. Zeljić et al. , “The marabou framework for verification and analysis of deep neural networks,” in International Conference on Computer Aided Verification . Springer, 2019, pp. 443–452
2019
Earlier work this paper cites.
M. Jordan, J. Lewis, and A. G. Dimakis, “Provable certificates for adversarial examples: Fitting a ball in the union of polytopes,” in Advances in Neural Information Processing Systems , 2019, pp. 14 059–14 069
2019
Earlier work this paper cites.
S. Gowal, K. D. Dvijotham, R. Stanforth, R. Bunel, C. Qin, J. Uesato, R. Arandjelovic, T. Mann, and P. Kohli, “Scalable verified training for provably robust image classification,” in Proceedings of the IEEE International Conference on Computer Vision , 2019, pp. 4842–4851
2019
Earlier work this paper cites.
G. Singh, T. Gehr, M. Püschel, and M. Vechev, “An abstract domain for certifying neural networks,” Proceedings of the ACM on Programming Languages , vol. 3, no. POPL, p. 41, 2019
2019
Earlier work this paper cites.
G. Anderson, S. Pailoor, I. Dillig, and S. Chaudhuri, “Optimization and abstraction: a synergistic approach for analyzing neural network robustness,” in Proceedings of the 40th ACM SIGPLAN Conference on Programming Language Design and Implementation , 2019, pp. 731–744
2019
Earlier work this paper cites.
K. D. Dvijotham, R. Stanforth, S. Gowal, C. Qin, S. De, and P. Kohli, “Efficient neural network verification with exactness characterization,” in Proc. Uncertainty in Artificial Intelligence, UAI , 2019, p. 164
2019
Earlier work this paper cites.
H. Zhang, P. Zhang, and C.-J. Hsieh, “Recurjac: An efficient recursive algorithm for bounding jacobian matrix of neural networks and its applications,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 33, 2019, pp. 5757–5764
2019
Earlier work this paper cites.
Q. Li, S. Haque, C. Anil, J. Lucas, R. B. Grosse, and J.-H. Jacobsen, “Preventing gradient attenuation in lipschitz constrained convolutional networks,” Advances in neural information processing systems , vol. 32, pp. 15 390–15 402, 2019
2019
Earlier work this paper cites.
M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, and S. Jana, “Certified robustness to adversarial examples with differential privacy,” in 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 2019, pp. 656–672
2019
Earlier work this paper cites.
B. Li, C. Chen, W. Wang, and L. Carin, “Certified adversarial robustness with additive noise,” in Advances in Neural Information Processing Systems , 2019, pp. 9459–9469
2019
Earlier work this paper cites.
H. Salman, J. Li, I. Razenshteyn, P. Zhang, H. Zhang, S. Bubeck, and G. Yang, “Provably robust deep learning via adversarially trained smoothed classifiers,” in Advances in Neural Information Processing Systems , 2019, pp. 11 289–11 300
2019
Earlier work this paper cites.
A. Boopathy, T.-W. Weng, P.-Y. Chen, S. Liu, and L. Daniel, “Cnn-cert: An efficient framework for certifying robustness of convolutional neural networks,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 33, 2019, pp. 3240–3247
2019
Cited alongside, same era.
H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, and M. Jordan, “Theoretically principled trade-off between robustness and accuracy,” in International conference on machine learning . PMLR, 2019, pp. 7472–7482
2019
Cited alongside, same era.
M. Fazlyab, A. Robey, H. Hassani, M. Morari, and G. Pappas, “Efficient and accurate estimation of lipschitz constants for deep neural networks,” in Advances in Neural Information Processing Systems , 2019, pp. 11 423–11 434
2019
Cited alongside, same era.
K. Hung, W. Fithian et al. , “Rank verification for exponential families,” The Annals of Statistics , vol. 47, no. 2, pp. 758–782, 2019
2019
Cited alongside, same era.
C. Ferrari, M. N. Mueller, N. Jovanović, and M. Vechev, “Complete verification via multi-neuron relaxation guided branch-and-bound,” in International Conference on Learning Representations , 2021
2021
Closest in time.
A. Fromherz, K. Leino, M. Fredrikson, B. Parno, and C. Pasareanu, “Fast geometric projections for local robustness certification,” in International Conference on Learning Representations , 2021
2021
Closest in time.
S. Wang, H. Zhang, K. Xu, X. Lin, S. Jana, C.-J. Hsieh, and J. Z. Kolter, “Beta-crown: Efficient bound propagation with per-neuron split constraints for neural network robustness verification,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Closest in time.
K. Xu, H. Zhang, S. Wang, Y. Wang, S. Jana, X. Lin, and C.-J. Hsieh, “Fast and complete: Enabling complete neural network verification with rapid and massively parallel incomplete verifiers,” in International Conference on Learning Representations , 2021
2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
G.-H. Lee, Y. Yuan, S. Chang, and T. Jaakkola, “Tight certificates of adversarial robustness for randomly smoothed classifiers,” in Advances in Neural Information Processing Systems , 2019, pp. 4911–4922
2019
Cited alongside, same era.
L. Li, Z. Zhong, B. Li, and T. Xie, “Robustra: training provable robust neural networks over reference adversarial space,” in Proceedings of the 28th International Joint Conference on Artificial Intelligence . AAAI Press, 2019, pp. 4711–4717
2019
Cited alongside, same era.
Y. Carmon, A. Raghunathan, L. Schmidt, J. C. Duchi, and P. S. Liang, “Unlabeled data improves adversarial robustness,” in Advances in Neural Information Processing Systems , 2019, pp. 11 190–11 201
2019
Cited alongside, same era.
C.-Y. Ko, Z. Lyu, L. Weng, L. Daniel, N. Wong, and D. Lin, “Popqorn: Quantifying robustness of recurrent neural networks,” in International Conference on Machine Learning . PMLR, 2019, pp. 3468–3477
2019
Cited alongside, same era.
2019
Cited alongside, same era.
M. Andriushchenko and M. Hein, “Provably robust boosted decision stumps and trees against adversarial attacks,” in Advances in Neural Information Processing Systems , 2019, pp. 12 997–13 008
2019
Cited alongside, same era.
H. Chen, H. Zhang, S. Si, Y. Li, D. Boning, and C.-J. Hsieh, “Robustness verification of tree-based models,” in Advances in Neural Information Processing Systems , 2019, pp. 12 317–12 328
2019
Cited alongside, same era.
R. Jia, A. Raghunathan, K. Göksel, and P. Liang, “Certified robustness to adversarial word substitutions,” in Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing , 2019, pp. 4127–4140
2019
Cited alongside, same era.
Closest in time.
Z. Lyu, M. Guo, T. Wu, G. Xu, K. Zhang, and D. Lin, “Towards evaluating and training verifiably robust neural networks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2021, pp. 4308–4317
2021
Closest in time.
A. D. Palma, H. Behl, R. R. Bunel, P. Torr, and M. P. Kumar, “Scaling the convex barrier with active sets,” in International Conference on Learning Representations , 2021
2021
Closest in time.
K. Leino, Z. Wang, and M. Fredrikson, “Globally-robust neural networks,” in Proceedings of the 38th International Conference on Machine Learning , ser. Proceedings of Machine Learning Research, M. Meila and T. Zhang, Eds., vol. 139. PMLR, 18–24 Jul 2021, pp. 6212–6222
2021
Closest in time.
S. Singla and S. Feizi, “Fantastic four: Differentiable and efficient bounds on singular values of convolution layers,” in International Conference on Learning Representations , 2021
2021
Closest in time.
A. Trockman and J. Z. Kolter, “Orthogonalizing convolutional layers with the cayley transform,” in International Conference on Learning Representations , 2021
2021
Closest in time.
B. Zhang, T. Cai, Z. Lu, D. He, and L. Wang, “Towards certifying l-infinity robustness using neural networks with l-inf-dist neurons,” in International Conference on Machine Learning , ser. Proceedings of Machine Learning Research, M. Meila and T. Zhang, Eds., vol. 139. PMLR, 18–24 Jul 2021, pp. 12 368–12 379
2021
Closest in time.
A. J. Levine and S. Feizi, “Improved, deterministic smoothing for l 1 l_{1} certified robustness,” in Proceedings of the 38th International Conference on Machine Learning , ser. Proceedings of Machine Learning Research, M. Meila and T. Zhang, Eds., vol. 139. PMLR, 18–24 Jul 2021, pp. 6254–6264
2021
Closest in time.
Z. Yang, L. Li, X. Xu, S. Zuo, Q. Chen, P. Zhou, B. I. P. Rubinstein, C. Zhang, and B. Li, “Trs: Transferability reduced ensemble via promoting gradient diversity and model smoothness,” in Advances in Neural Information Processing Systems 34 (NeurIPS 2021) , 2021
2021
Closest in time.
S. Gowal, S.-A. Rebuffi, O. Wiles, F. Stimberg, D. A. Calian, and T. A. Mann, “Improving robustness using generated data,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Closest in time.
M. König, H. H. Hoos, and J. N. van Rijn, “Speeding up neural network verification via automated algorithm configuration,” in ICLR 2021 Workshop on Security and Safety in Machine Learning Systems , 2021
2021
Closest in time.
2021
Closest in time.
D. Shriver, S. Elbaum, and M. B. Dwyer, “Dnnv: A framework for deep neural network verification,” in International Conference on Computer Aided Verification . Springer, 2021, pp. 137–150
2021
Closest in time.
K. Jia and M. Rinard, “Exploiting verified neural networks via floating point numerical error,” in International Static Analysis Symposium . Springer, 2021, pp. 191–205
2021
Closest in time.
2021
Closest in time.
Z. Shi, Y. Wang, H. Zhang, J. Yi, and C.-J. Hsieh, “Fast certified robust training with short warmup,” in Thirty-Fifth Conference on Neural Information Processing Systems , 2021
2021
Closest in time.
B. Batten, P. Kouvaros, A. Lomuscio, and Y. Zheng, “Efficient neural network verification via layer-based semidefinite relaxations and linear cuts,” in International Joint Conference on Artificial Intelligence , 2021, pp. 2184–2190
2021
Closest in time.
J. Mohapatra, C.-Y. Ko, L. Weng, P.-Y. Chen, S. Liu, and L. Daniel, “Hidden cost of randomized smoothing,” in International Conference on Artificial Intelligence and Statistics . PMLR, 2021, pp. 4033–4041
2021
Closest in time.
J. Jeong, S. Park, M. Kim, H.-C. Lee, D. Kim, and J. Shin, “Smoothmix: Training confidence-calibrated smoothed classifiers for certified robustness,” in Thirty-Fifth Conference on Neural Information Processing Systems , 2021
2021
Closest in time.
F. Croce, M. Andriushchenko, V. Sehwag, E. Debenedetti, N. Flammarion, M. Chiang, P. Mittal, and M. Hein, “RobustBench: a standardized adversarial robustness benchmark,” in Proceedings of the Neural Information Processing Systems Track on Datasets and Benchmarks 1 , J. Vanschoren and S. Yeung, Eds., 2021
2021
Closest in time.
L. Li, M. Weber, X. Xu, L. Rimanic, B. Kailkhura, T. Xie, C. Zhang, and B. Li, “TSS: Transformation-specific smoothing for robustness certification,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security , 2021, p. 535–557
2021
Closest in time.
M. Mirman, A. Hägele, P. Bielik, T. Gehr, and M. Vechev, “Robustness certification with generative models,” in Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation , 2021, pp. 1141–1154
2021
Closest in time.
C. Xiang, A. N. Bhagoji, V. Sehwag, and P. Mittal, “PatchGuard: A provably robust defense against adversarial patches via small receptive fields and masking,” in 30th USENIX Security Symposium (USENIX Security 21) , 2021, pp. 2237–2254
2021
Closest in time.
H. Han, K. Xu, X. Hu, X. Chen, L. Liang, Z. Du, Q. Guo, Y. Wang, and Y. Chen, “Scalecert: Scalable certified defense against adversarial patches with sparse superficial layers,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Closest in time.
2021
Closest in time.
Y. Chen, S. Wang, Y. Qin, X. Liao, S. Jana, and D. Wagner, “Learning security classifiers with verified global robustness properties,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security , 2021, p. 477–494
2021
Closest in time.
A. Levine and S. Feizi, “Deep partition aggregation: Provable defenses against general poisoning attacks,” in International Conference on Learning Representations , 2021
2021
Closest in time.
T. Du, S. Ji, L. Shen, Y. Zhang, J. Li, J. Shi, C. Fang, J. Yin, R. Beyah, and T. Wang, “Cert-rnn: Towards certifying the robustness of recurrent neural networks,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security , 2021, pp. 516–534
2021
Closest in time.
W. Ryou, J. Chen, M. Balunovic, G. Singh, A. Dan, and M. Vechev, “Scalable polyhedral verification of recurrent neural networks,” in International Conference on Computer Aided Verification . Springer, 2021, pp. 225–248
2021
Closest in time.
G. Bonaert, D. I. Dimitrov, M. Baader, and M. Vechev, “Fast and precise certification of transformers,” in Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation , 2021, pp. 466–481
2021
Closest in time.
M. Mirman, A. Hägele, P. Bielik, T. Gehr, and M. Vechev, “Robustness certification with generative models,” in Proceedings of the 42nd ACM SIGPLAN International Conference on Programming Language Design and Implementation , 2021, pp. 1141–1154
2021
Closest in time.
Y. Zhang, A. Albarghouthi, and L. D’Antoni, “Certified robustness to programmable transformations in LSTMs,” in Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing . Online and Punta Cana, Dominican Republic: Association for Computational Linguistics, Nov. 2021, pp. 1068–1083
2021
Closest in time.
M. Fischer, M. Baader, and M. Vechev, “Scalable certified segmentation via randomized smoothing,” in International Conference on Machine Learning . PMLR, 2021, pp. 3340–3351
2021
Closest in time.
H. Liu, J. Jia, and N. Z. Gong, “Pointguard: Provably robust 3d point cloud classification,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2021, pp. 6186–6195
2021
Closest in time.
R. Olivier and B. Raj, “Sequential randomized smoothing for adversarially robust speech recognition,” in Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing , 2021, pp. 6372–6386
2021
Closest in time.
A. Mehra, B. Kailkhura, P.-Y. Chen, and J. Hamm, “How robust are randomized smoothing based defenses to data poisoning?” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2021, pp. 13 244–13 253
2021
Closest in time.
L. Bourtoule, V. Chandrasekaran, C. A. Choquette-Choo, H. Jia, A. Travers, B. Zhang, D. Lie, and N. Papernot, “Machine unlearning,” in 2021 IEEE Symposium on Security and Privacy (SP) . IEEE, 2021, pp. 141–159
2021
Closest in time.
D. Wakabayashi, “Self-driving uber car kills pedestrian in arizona, where robots roam,” https://www.nytimes.com/2018/03/19/technology/uber-driverless-fatality.html , accessed: 2021-12-02
2021
Closest in time.
S. Lee, W. Lee, J. Park, and J. Lee, “Towards better understanding of training certifiably robust models against adversarial examples,” in Thirty-Fifth Conference on Neural Information Processing Systems , 2021
2021
Closest in time.
Y. Song, J. Sohl-Dickstein, D. P. Kingma, A. Kumar, S. Ermon, and B. Poole, “Score-based generative modeling through stochastic differential equations,” in International Conference on Learning Representations , 2021
2021
Closest in time.
2022
Closest in time.
M. N. Müller, G. Makarchuk, G. Singh, M. Püschel, and M. Vechev, “PRIMA: Precise and general neural network certification via multi-neuron convex relaxations,” Proceedings of the ACM on Programming Languages , vol. 6, no. POPL, pp. 1–33, 2022
2022
Closest in time.
S. Singla, S. Singla, and S. Feizi, “Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100,” in International Conference on Learning Representations , 2022
2022
Closest in time.
2022
Closest in time.
B. Paulsen and C. Wang, “Linsyn: Synthesizing tight linear bounds for arbitrary neural network activation functions,” in 28th International Conference on Tools and Algorithms for the Construction and Analysis of Systems , 2022
2022
Closest in time.
B. Zhang, D. Jiang, D. He, and L. Wang, “Boosting the certified robustness of l-infinity distance nets,” in International Conference on Learning Representations , 2022
2022
Closest in time.
L. Li, J. Zhang, T. Xie, and B. Li, “Double sampling randomized smoothing,” in International Conference on Machine Learning , 2022
2022
Closest in time.
B. Zhang, D. Jiang, D. He, and L. Wang, “Rethinking lipschitz neural networks and certified robustness: A boolean function perspective,” in Advances in Neural Information Processing Systems , 2022
2022
Closest in time.
X. Xu, L. Li, and B. Li, “Lot: Layer-wise orthogonal training on improving l2 certified robustness,” in Advances in Neural Information Processing Systems , 2022
2022
Closest in time.
Z. Yang, L. Li, X. Xu, B. Kailkhura, T. Xie, and B. Li, “On the certified robustness for ensemble models and beyond,” in International Conference on Learning Representations , 2022
2022
Closest in time.
M. Z. Horváth, M. N. Mueller, M. Fischer, and M. Vechev, “Boosting randomized smoothing with variance reduced classifiers,” in International Conference on Learning Representations , 2022
2022
Closest in time.
F. Wu, L. Li, Z. Huang, Y. Vorobeychik, D. Zhao, and B. Li, “CROP: Certifying robust policies for reinforcement learning through functional smoothing,” in International Conference on Learning Representations , 2022
2022
Closest in time.
M. Pautov, N. Tursynbek, M. Munkhoeva, N. Muravev, A. Petiushko, and I. Oseledets, “CC-Cert: A probabilistic approach to certify general robustness of neural networks,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 36, no. 7, 2022, pp. 7975–7983
2022
Closest in time.
Z. Hao, C. Ying, Y. Dong, H. Su, J. Song, and J. Zhu, “GSmooth: Certified robustness against semantic transformations via generalized randomized smoothing,” in Proceedings of the 39th International Conference on Machine Learning , ser. Proceedings of Machine Learning Research, vol. 162. PMLR, 2022, pp. 8465–8483
2022
Closest in time.
J. Jia, B. Wang, X. Cao, H. Liu, and N. Z. Gong, “Almost tight l0-norm certified robustness of top-k predictions against adversarial perturbations,” in International Conference on Learning Representations , 2022
2022
Closest in time.
H. Salman, S. Jain, E. Wong, and A. Madry, “Certified patch robustness via smoothed vision transformers,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2022, pp. 15 137–15 147
2022
Closest in time.
C. Xiang, S. Mahloujifar, and P. Mittal, “PatchCleanser: Certifiably robust defense against adversarial patches for any image classifier,” in 31st USENIX Security Symposium (USENIX Security) , 2022
2022
Closest in time.
2022
Closest in time.
M. G. Weber, L. Li, B. Wang, Z. Zhao, B. Li, and C. Zhang, “Certifying out-of-domain generalization for blackbox functions,” in International Conference on Machine Learning . PMLR, 2022, pp. 23 527–23 548
2022
Closest in time.
F. Wu, L. Li, C. Xu, H. Zhang, B. Kailkhura, K. Kenthapadi, D. Zhao, and B. Li, “COPA: Certifying robust policies for offline reinforcement learning against poisoning attacks,” in International Conference on Learning Representations , 2022
2022
Closest in time.
V. Voráček and M. Hein, “Provably adversarially robust nearest prototype classifiers,” in International Conference on Machine Learning . PMLR, 2022, pp. 22 361–22 383
2022
Closest in time.
W. Chu, L. Li, and B. Li, “TPC: Transformation-specific smoothing for point cloud models,” in Proceedings of the 39th International Conference on Machine Learning , 2022, pp. 4035–4056
2022
Closest in time.
A. Kumar, A. Levine, and S. Feizi, “Policy smoothing for provably robust reinforcement learning,” in International Conference on Learning Representations , 2022
2022
Closest in time.
2022
Closest in time.
Z. Wang, A. Albarghouthi, G. Prakriya, and S. Jha, “Interval universal approximation for neural networks,” Proceedings of the ACM on Programming Languages , vol. 6, no. POPL, pp. 1–29, 2022
2022
Closest in time.
Y. Wang, Z. Shi, Q. Gu, and C.-J. Hsieh, “On the convergence of certified robust training with interval bound propagation,” in International Conference on Learning Representations , 2022
2022
Closest in time.
2022
Closest in time.
R. S. Hallyburton, Y. Liu, Y. Cao, Z. M. Mao, and M. Pajic, “Security analysis of camera-lidar fusion against black-box attacks on autonomous vehicles,” in 31st USENIX Security Symposium (USENIX Security 22) , 2022
2022
Closest in time.
M. N. Mueller, F. Eckert, M. Fischer, and M. Vechev, “Certified training: Small boxes are all you need,” in International Conference on Learning Representations , 2023
2023
Closest in time.
N. Carlini, F. Tramer, K. D. Dvijotham, L. Rice, M. Sun, and J. Z. Kolter, “(certified!!) adversarial robustness for free!” in International Conference on Learning Representations , 2023
2023
Closest in time.
C. Xiao, Z. Chen, K. Jin, J. Wang, W. Nie, M. Liu, A. Anandkumar, B. Li, and D. Song, “Densepure: Understanding diffusion models for adversarial robustness,” in International Conference on Learning Representations , 2023
2023
Closest in time.
M. Weber, X. Xu, B. Karlas, C. Zhang, and B. Li, “Rab: Provable robustness against backdoor attacks,” in 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, 22-26 May 2023 . IEEE, 2023
2023
Closest in time.
F. Croce, M. Andriushchenko, and M. Hein, “Provable robustness of relu networks via maximization of linear regions,” in the 22nd International Conference on Artificial Intelligence and Statistics . PMLR, 2019, pp. 2057–2066
2066
Closest in time.