Fetching the paper…
Reading the bibliography…
Randomized smoothing has been shown to provide good certified-robustness guarantees for high-dimensional classification problems.
Asymptotic minimax character of the sample distribution function and of the classical multinomial estimator
A. Dvoretzky, J. Kiefer, and J. Wolfowitz · 1956
Earlier work this paper cites.
Curse of dimensionality on randomized smoothing for certifiable robustness
Aounon Kumar, Alexander Levine, Tom Goldstein, and Soheil Feizi · 2002
Earlier work this paper cites.
(de)randomized smoothing for certifiable defense against patch attacks
Alexander Levine and Soheil Feizi · 2002
Earlier work this paper cites.
Calibrating predictive model estimates to support personalized medicine
Xiaoqian Jiang, Melanie Osl, Jihoon Kim, and Lucila Ohno-Machado · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
End to end learning for self-driving cars, 2016
Mariusz Bojarski, Davide Del Testa, Daniel Dworakowski, Bernhard Firner, Beat Flepp, Prasoon Goyal, Lawrence D. Jackel, Mathew Monfort, Urs Muller, Jiakai Zhang, Xin Zhang, Jake Zhao, and Karol Zieba · 2016
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
Adversarial and clean data are not twins
Zhitao Gong, Wenlu Wang, and Wei-Shinn Ku · 2017
Earlier work this paper cites.
On the (statistical) detection of adversarial examples
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick D. McDaniel · 2017
Earlier work this paper cites.
On calibration of modern neural networks
Chuan Guo, Geoff Pleiss, Yu Sun, and Kilian Q Weinberger · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Adversarial examples detection in deep networks with convolutional filter statistics
Xin Li and Fuxin Li · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian J. Goodfellow · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Guneet S. Dhillon, Kamyar Azizzadenesheli, Zachary C. Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, and Animashree Anandkumar · 2018
Cited alongside, same era.
Training verified learners with learned verifiers, 2018
Krishnamurthy Dvijotham, Sven Gowal, Robert Stanforth, Relja Arandjelovic, Brendan O’Donoghue, Jonathan Uesato, and Pushmeet Kohli · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models, 2018
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cissé, and Laurens van der Maaten · 2018
Cited alongside, same era.
Tight certificates of adversarial robustness for randomly smoothed classifiers
Guang-He Lee, Yang Yuan, Shiyu Chang, and Tommi S. Jaakkola · 2019
Later among the works it cites.
Wasserstein smoothing: Certified robustness against wasserstein adversarial attacks, 2019
Alexander Levine and Soheil Feizi · 2019
Later among the works it cites.
Certified adversarial robustness with additive noise
Bai Li, Changyou Chen, Wenlin Wang, and Lawrence Carin · 2019
Later among the works it cites.
Provably robust deep learning via adversarially trained smoothed classifiers
Hadi Salman, Jerry Li, Ilya P. Razenshteyn, Pengchuan Zhang, Huan Zhang, Sébastien Bubeck, and Greg Yang · 2019
Later among the works it cites.
Robustness certificates against adversarial examples for relu networks
Sahil Singla and Soheil Feizi · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin Vechev · 2018
Cited alongside, same era.
Semidefinite relaxations for certifying robustness to adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Pushmeet Kohli, and Aäron van den Oord · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and J. Zico Kolter · 2018
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Cited alongside, same era.
Achieving verified robustness to symbol substitutions via interval bound propagation
Po-Sen Huang, Robert Stanforth, Johannes Welbl, Chris Dyer, Dani Yogatama, Sven Gowal, Krishnamurthy Dvijotham, and Pushmeet Kohli · 2019
Cited alongside, same era.
Random smoothing might be unable to certify ℓ ∞ \ell_{\infty} robustness for high-dimensional images, 2020
Avrim Blum, Travis Dick, Naren Manoj, and Hongyang Zhang · 2020
Closest in time.
Certified defenses for adversarial patches
Ping-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu, Christoph Studer, and Tom Goldstein · 2020
Closest in time.
Robustness certificates for sparse adversarial attacks by randomized ablation
Alexander Levine and Soheil Feizi · 2020
Closest in time.
Tight second-order certificates for randomized smoothing, 2020
Alexander Levine, Aounon Kumar, Thomas Goldstein, and Soheil Feizi · 2020
Closest in time.
Second-order provable defenses against adversarial attacks, 2020
Sahil Singla and Soheil Feizi · 2020
Closest in time.
ℓ 1 \ell_{1} adversarial robustness certificates: a randomized smoothing approach, 2020
Jiaye Teng, Guang-He Lee, and Yang Yuan · 2020
Closest in time.
On adaptive attacks to adversarial example defenses, 2020
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Closest in time.
Randomized smoothing of all shapes and sizes, 2020
Greg Yang, Tony Duan, J. Edward Hu, Hadi Salman, Ilya Razenshteyn, and Jerry Li · 2020
Closest in time.
Detection as regression: Certified object detection by median smoothing, 2020
Ping yeh Chiang, Michael J. Curry, Ahmed Abdelkader, Aounon Kumar, John Dickerson, and Tom Goldstein · 2020
Closest in time.