Fetching the paper…
Reading the bibliography…
The current state-of-the-art defense methods against adversarial examples typically focus on improving either empirical or certified robustness.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy et al · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Sergey Ioffe and Christian Szegedy · 2015
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Revisiting batch normalization for practical domain adaptation
Yanghao Li, Naiyan Wang, Jianping Shi, Jiaying Liu, and Xiaodi Hou · 2016
Earlier work this paper cites.
Mitigating evasion attacks to deep neural networks via region-based classification
Xiaoyu Cao and Neil Zhenqiang Gong · 2017
Earlier work this paper cites.
Autodial: Automatic domain alignment layers
Fabio Maria Cariucci, Lorenzo Porzi, Barbara Caputo, Elisa Ricci, and Samuel Rota Bulo · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Self-ensembling for visual domain adaptation
Geoffrey French, Michal Mackiewicz, and Mark Fisher · 2017
Earlier work this paper cites.
Correlation alignment for unsupervised domain adaptation
Baochen Sun, Jiashi Feng, and Kate Saenko · 2017
Earlier work this paper cites.
Evaluating robustness of neural networks with mixed integer programming
Vincent Tjeng, Kai Xiao, and Russ Tedrake · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
A unified view of piecewise linear neural network verification
Rudy Bunel, Ilker Turkaslan, Philip HS Torr, Pushmeet Kohli, and M Pawan Kumar · 2018
Earlier work this paper cites.
A dual approach to scalable verification of deep networks
Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy A Mann, and Pushmeet Kohli · 2018
Earlier work this paper cites.
Ai2: Safety and robustness certification of neural networks with abstract interpretation
Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev · 2018
Earlier work this paper cites.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2018
Earlier work this paper cites.
Decorrelated batch normalization
Lei Huang, Dawei Yang, Bo Lang, and Jia Deng · 2018
Earlier work this paper cites.
Towards robust neural networks via random self-ensemble
Xuanqing Liu, Minhao Cheng, Huan Zhang, and Cho-Jui Hsieh · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin Vechev · 2018
Earlier work this paper cites.
Certified defenses against adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Earlier work this paper cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli · 2018
Cited alongside, same era.
Efficient formal safety analysis of neural networks
Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana · 2018
Cited alongside, same era.
Towards fast computation of certified robustness for relu networks
Lily Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane Boning, and Inderjit Dhillon · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Cited alongside, same era.
Scaling provable adversarial defenses
Eric Wong, Frank R Schmidt, Jan Hendrik Metzen, and J Zico Kolter · 2018
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, Percy Liang, and John C Duchi · 2019
A framework for robustness certification of smoothed classifiers using f-divergences
Krishnamurthy (Dj) Dvijotham, Jamie Hayes, Borja Balle, Zico Kolter, Chongli Qin, Andras Gyorgy, Kai Xiao, Sven Gowal, and Pushmeet Kohli · 2020
Later among the works it cites.
Unering the limits of adversarial training against norm-bounded adversarial examples
Sven Gowal, Chongli Qin, Jonathan Uesato, Timothy Mann, and Pushmeet Kohli · 2020
Later among the works it cites.
Consistency regularization for certified robustness of smoothed classifiers
Jongheon Jeong and Jinwoo Shin · 2020
Later among the works it cites.
Robust pre-training by adversarial contrastive learning
Ziyu Jiang, Tianlong Chen, Ting Chen, and Zhangyang Wang · 2020
Later among the works it cites.
Evaluating prediction-time batch normalization for robustness under covariate shift
Zachary Nado, Shreyas Padhy, D Sculley, Alexander D’Amour, Balaji Lakshminarayanan, and Jasper Snoek · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter · 2019
Cited alongside, same era.
Robustness (python library), 2019
Logan Engstrom, Andrew Ilyas, Hadi Salman, Shibani Santurkar, and Dimitris Tsipras · 2019
Cited alongside, same era.
On the connection between adversarial robustness and saliency map interpretability
Christian Etmann, Sebastian Lunz, Peter Maass, and Carola-Bibiane Schönlieb · 2019
Cited alongside, same era.
Adversarial examples are a natural consequence of test error in noise
Justin Gilmer, Nicolas Ford, Nicholas Carlini, and Ekin Cubuk · 2019
Cited alongside, same era.
Benchmarking neural network robustness to common corruptions and perturbations
Dan Hendrycks and Thomas Dietterich · 2019
Cited alongside, same era.
The robust manifold defense: Adversarial training using generative models
Ajil Jalal, Andrew Ilyas, Constantinos Daskalakis, and Alexandros G Dimakis · 2019
Cited alongside, same era.
Approximate manifold defense against multiple adversarial perturbations
Jay Nandy, Wynne Hsu, and Mong-Li Lee · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and Zico Kolter · 2020
Later among the works it cites.
Denoised smoothing: A provable defense for pretrained classifiers
Hadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor, and J Zico Kolter · 2020
Later among the works it cites.
Improving robustness against common corruptions by covariate shift adaptation
Steffen Schneider, Evgenia Rusak, Luisa Eck, Oliver Bringmann, Wieland Brendel, and Matthias Bethge · 2020
Later among the works it cites.
Test-time training with self-supervision for generalization under distribution shifts
Yu Sun, Xiaolong Wang, Zhuang Liu, John Miller, Alexei Efros, and Moritz Hardt · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J Zico Kolter · 2020
Later among the works it cites.
Intriguing properties of adversarial training at scale
Cihang Xie and Alan Yuille · 2020
Later among the works it cites.
Randomized smoothing of all shapes and sizes
Greg Yang, Tony Duan, Edward Hu, Hadi Salman, Ilya Razenshteyn, and Jerry Li · 2020
Later among the works it cites.
Macer: Attack-free and scalable robust training via maximizing certified radius
Runtian Zhai, Chen Dan, Di He, Huan Zhang, Boqing Gong, Pradeep Ravikumar, Cho-Jui Hsieh, and Liwei Wang · 2020
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2020
Later among the works it cites.
On the effectiveness of adversarial training against common corruptions
Klim Kireev, Maksym Andriushchenko, and Nicolas Flammarion · 2021
Closest in time.
Adversarial attacks are reversible with natural supervision
Chengzhi Mao, Mia Chiquier, Hao Wang, Junfeng Yang, and Carl Vondrick · 2021
Closest in time.
Certify or predict: Boosting certified robustness with compositional architectures
Mark Niklas Mueller, Mislav Balunovic, and Martin Vechev · 2021
Closest in time.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2021
Closest in time.
Provably robust classification of adversarial examples with detection
Fatemeh Sheikholeslami, Ali Lotfi, and J Zico Kolter · 2021
Closest in time.
Augmax: Adversarial composition of random augmentations for robust training
Haotao Wang, Chaowei Xiao, Jean Kossaifi, Zhiding Yu, Anima Anandkumar, and Zhangyang Wang · 2021
Closest in time.
(certified!!) adversarial robustness for free!
Nicholas Carlini, Florian Tramer, J Zico Kolter, et al · 2022
Closest in time.
Boosting randomized smoothing with variance reduced classifiers
Miklós Z Horváth, Mark Niklas Müller, Marc Fischer, and Martin Vechev · 2022
Closest in time.