Fetching the paper…
Reading the bibliography…
Adversarial training is so far the most effective strategy in defending against adversarial examples.
Convex optimization
Boyd, S.; Boyd, S. P.; and Vandenberghe, L. 2004 · 2004
Earlier work this paper cites.
Towards Understanding Fast Adversarial Training
Li, B.; Wang, S.; Jana, S.; and Carin, L. 2020 · 2006
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Deng, J.; Dong, W.; Socher, R.; Li, L.-J.; Li, K.; and Fei-Fei, L. 2009 · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A.; Hinton, G.; et al. 2009 · 2009
Earlier work this paper cites.
Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples
Gowal, S.; Qin, C.; Uesato, J.; Mann, T.; and Kohli, P. 2020 · 2010
Earlier work this paper cites.
Randomized smoothing for stochastic optimization
Duchi, J. C.; Bartlett, P. L.; and Wainwright, M. J. 2012 · 2012
Earlier work this paper cites.
Attacks which do not kill training make adversarial learning stronger
Zhang, J.; Xu, X.; Han, B.; Niu, G.; Cui, L.; Sugiyama, M.; and Kankanhalli, M. 2020 · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C.; Zaremba, W.; Sutskever, I.; Bruna, J.; Erhan, D.; Goodfellow, I.; and Fergus, R. 2013 · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J.; Shlens, J.; and Szegedy, C. 2015 · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K.; Zhang, X.; Ren, S.; and Sun, J. 2016 · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A.; Goodfellow, I.; and Bengio, S. 2016 · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M.; Fawzi, A.; and Frossard, P. 2016 · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N.; McDaniel, P.; Jha, S.; Fredrikson, M.; Celik, Z. B.; and Swami, A. 2016 · 2016
Earlier work this paper cites.
Zagoruyko, S.; and Komodakis, N. 2016 · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N.; and Wagner, D. 2017 · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y.; Zhang, H.; Sharma, Y.; Yi, J.; and Hsieh, C.-J. 2017 · 2017
Earlier work this paper cites.
Cyclical learning rates for training neural networks
Smith, L. N. 2017 · 2017
Earlier work this paper cites.
Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
Athalye, A.; Carlini, N.; and Wagner, D. 2018 · 2018
Earlier work this paper cites.
Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models
Brendel, W.; Rauber, J.; and Bethge, M. 2018 · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Dhillon, G. S.; Azizzadenesheli, K.; Lipton, Z. C.; Bernstein, J.; Kossaifi, J.; Khanna, A.; and Anandkumar, A. 2018 · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Guo, C.; Rana, M.; Cisse, M.; and Van Der Maaten, L. 2018 · 2018
Cited alongside, same era.
Black-box Adversarial Attacks with Limited Queries and Information
Ilyas, A.; Engstrom, L.; Athalye, A.; Lin, J.; Athalye, A.; Engstrom, L.; Ilyas, A.; and Kwok, K. 2018 · 2018
Cited alongside, same era.
Characterizing adversarial subspaces using local intrinsic dimensionality
Ma, X.; Li, B.; Wang, Y.; Erfani, S. M.; Wijewickrema, S.; Schoenebeck, G.; Song, D.; Houle, M. E.; and Bailey, J. 2018 · 2018
Cited alongside, same era.
Adversarial training for free!
Shafahi, A.; Najibi, M.; Ghiasi, M. A.; Xu, Z.; Dickerson, J.; Studer, C.; Davis, L. S.; Taylor, G.; and Goldstein, T. 2019 · 2019
Later among the works it cites.
On the Convergence and Robustness of Adversarial Training
Wang, Y.; Ma, X.; Bailey, J.; Yi, J.; Zhou, B.; and Gu, Q. 2019 · 2019
Later among the works it cites.
Theoretically Principled Trade-off between Robustness and Accuracy
Zhang, H.; Yu, Y.; Jiao, J.; Xing, E.; El Ghaoui, L.; and Jordan, M. 2019 · 2019
Later among the works it cites.
Sign Bits Are All You Need for Black-Box Attacks
Al-Dujaili, A.; and O’Reilly, U.-M. 2020 · 2020
Closest in time.
Square attack: a query-efficient black-box adversarial attack via random search
Andriushchenko, M.; Croce, F.; Flammarion, N.; and Hein, M. 2020 · 2020
Closest in time.
Understanding and Improving Fast Adversarial Training
Andriushchenko, M.; and Flammarion, N. 2020 · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Madry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; and Vladu, A. 2018 · 2018
Cited alongside, same era.
Mixed Precision Training
Micikevicius, P.; Narang, S.; Alben, J.; Diamos, G.; Elsen, E.; Garcia, D.; Ginsburg, B.; Houston, M.; Kuchaiev, O.; Venkatesh, G.; and Wu, H. 2018 · 2018
Cited alongside, same era.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Samangouei, P.; Kabkab, M.; and Chellappa, R. 2018 · 2018
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Song, Y.; Kim, T.; Nowozin, S.; Ermon, S.; and Kushman, N. 2018 · 2018
Cited alongside, same era.
Mitigating adversarial effects through randomization
Xie, C.; Wang, J.; Zhang, Z.; Ren, Z.; and Yuille, A. 2018 · 2018
Cited alongside, same era.
Are Labels Required for Improving Adversarial Robustness?
Alayrac, J.-B.; Uesato, J.; Huang, P.-S.; Fawzi, A.; Stanforth, R.; and Kohli, P. 2019 · 2019
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Carmon, Y.; Raghunathan, A.; Schmidt, L.; Duchi, J. C.; and Liang, P. S. 2019 · 2019
Cited alongside, same era.
Closest in time.
RayS: A Ray Searching Method for Hard-label Adversarial Attack
Chen, J.; and Gu, Q. 2020 · 2020
Closest in time.
A Frank-Wolfe framework for efficient and effective adversarial attacks
Chen, J.; Zhou, D.; Yi, J.; and Gu, Q. 2020 · 2020
Closest in time.
Sign-OPT: A Query-Efficient Hard-label Adversarial Attack
Cheng, M.; Singh, S.; Chen, P. H.; Chen, P.-Y.; Liu, S.; and Hsieh, C.-J. 2020 · 2020
Closest in time.
On the Loss Landscape of Adversarial Training: Identifying Challenges and How to Overcome Them
Liu, C.; Salzmann, M.; Lin, T.; Tomioka, R.; and Süsstrunk, S. 2020 · 2020
Closest in time.
Overfitting in adversarially robust deep learning
Rice, L.; Wong, E.; and Kolter, J. Z. 2020 · 2020
Closest in time.
Guided Adversarial Attack for Evaluating and Enhancing Adversarial Defenses
Sriramanan, G.; Addepalli, S.; Baburaj, A.; et al. 2020 · 2020
Closest in time.
Diversity can be Transferred: Output Diversification for White-and Black-box Attacks
Tashiro, Y.; Song, Y.; and Ermon, S. 2020 · 2020
Closest in time.
Improving Adversarial Robustness Requires Revisiting Misclassified Examples
Wang, Y.; Zou, D.; Yi, J.; Bailey, J.; Ma, X.; and Gu, Q. 2020 · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
Wong, E.; Rice, L.; and Kolter, J. Z. 2020 · 2020
Closest in time.
Adversarial weight perturbation helps robust generalization
Wu, D.; Xia, S.-T.; and Wang, Y. 2020 · 2020
Closest in time.
Bag of Tricks for Adversarial Training
Pang, T.; Yang, X.; Dong, Y.; Su, H.; and Zhu, J. 2021 · 2021
Closest in time.
Do Wider Neural Networks Really Help Adversarial Robustness?
Wu, B.; Chen, J.; Cai, D.; He, X.; and Gu, Q. 2021 · 2021
Closest in time.