Fetching the paper…
Reading the bibliography…
Neural networks trained on visual data are well-known to be vulnerable to often imperceptible adversarial perturbations.
Adversarial robustness as a prior for learned representations
Engstrom, L., Ilyas, A., Santurkar, S., Tsipras, D., Tran, B., and Madry, A · 1906
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A., Hinton, G., et al · 2009
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A., Sutskever, I., and Hinton, G. E · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Deep inside convolutional networks: Visualising image classification models and saliency maps
Simonyan, K., Vedaldi, A., and Zisserman, A · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
Kingma, D. P. and Ba, J · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Simonyan, K. and Zisserman, A · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
TensorFlow: Large-scale machine learning on heterogeneous systems, 2015
Abadi, M., Agarwal, A., Barham, P., Brevdo, E., Chen, Z., Citro, C., Corrado, G. S., Davis, A., Dean, J., Devin, M., Ghemawat, S., Goodfellow, I., Harp, A., Irving, G., Isard, M., Jia, Y., Jozefowicz, R., Kaiser, L., Kudlur, M., Levenberg, J., Mané, D., Monga, R., Moore, S., Murray, D., Olah, C., Schuster, M., Shlens, J., Steiner, B., Sutskever, I., Talwar, K., Tucker, P., Vanhoucke, V., Vasudevan, V., Viégas, F., Vinyals, O., Warden, P., Wattenberg, M., Wicke, M., Yu, Y., and Zheng, X · 2015
Earlier work this paper cites.
Understanding deep features with computer-generated imagery
Aubry, M. and Russell, B. C · 2015
Earlier work this paper cites.
Convergent learning: Do different neural networks learn the same representations?
Li, Y., Yosinski, J., Clune, J., Lipson, H., and Hopcroft, J. E · 2015
Earlier work this paper cites.
Understanding deep image representations by inverting them
Mahendran, A. and Vedaldi, A · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., and Fei-Fei, L · 2015
Earlier work this paper cites.
Inverting visual representations with convolutional networks
Dosovitskiy, A. and Brox, T · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Liu, Y., Chen, X., Liu, C., and Song, D · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Earlier work this paper cites.
Adversarial perturbations of deep neural networks
Warde-Farley, D. and Goodfellow, I · 2016
Earlier work this paper cites.
A closer look at memorization in deep networks
Arpit, D., Jastrzębski, S., Ballas, N., Krueger, D., Bengio, E., Kanwal, M. S., Maharaj, T., Fischer, A., Courville, A., Bengio, Y., et al · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Xception: Deep learning with depthwise separable convolutions
Chollet, F · 2017
Earlier work this paper cites.
A downsampled variant of imagenet as an alternative to the cifar datasets
Chrabaszcz, P., Loshchilov, I., and Hutter, F · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Feinman, R., Curtin, R. R., Shintre, S., and Gardner, A. B · 2017
Cited alongside, same era.
Mobilenets: Efficient convolutional neural networks for mobile vision applications
Howard, A. G., Zhu, M., Chen, B., Kalenichenko, D., Wang, W., Weyand, T., Andreetto, M., and Adam, H · 2017
Cited alongside, same era.
Densely connected convolutional networks
Huang, G., Liu, Z., Van Der Maaten, L., and Weinberger, K. Q · 2017
Cited alongside, same era.
Measuring the tendency of cnns to learn surface statistical regularities
Jo, J. and Bengio, Y · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Are perceptually-aligned gradients a general property of robust classifiers?
Kaur, S., Cohen, J., and Lipton, Z. C · 2019
Later among the works it cites.
Similarity of neural network representations revisited
Kornblith, S., Norouzi, M., Lee, H., and Hinton, G · 2019
Later among the works it cites.
Right for the wrong reasons: Diagnosing syntactic heuristics in natural language inference
McCoy, R. T., Pavlick, E., and Linzen, T · 2019
Later among the works it cites.
Adversarial robustness may be at odds with simplicity
Nakkiran, P · 2019
Later among the works it cites.
Sgd on neural networks learns functions of increasing complexity
Nakkiran, P., Kalimeris, D., Kaplun, G., Edelman, B., Yang, T., Barak, B., and Zhang, H · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
On detecting adversarial perturbations
Metzen, J. H., Genewein, T., Fischer, V., and Bischoff, B · 2017
Cited alongside, same era.
Universal adversarial perturbations
Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., and Frossard, P · 2017
Cited alongside, same era.
Feature visualization
Olah, C., Mordvintsev, A., and Schubert, L · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
Raghu, M., Gilmer, J., Yosinski, J., and Sohl-Dickstein, J · 2017
Cited alongside, same era.
The space of transferable adversarial examples
Tramèr, F., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2017
Cited alongside, same era.
Towards understanding generalization of deep learning: Perspective of loss landscapes
Wu, L., Zhu, Z., et al · 2017
Cited alongside, same era.
Image synthesis with a single (robust) classifier
Santurkar, S., Ilyas, A., Tsipras, D., Engstrom, L., Tran, B., and Madry, A · 2019
Later among the works it cites.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T · 2019
Later among the works it cites.
Disentangling adversarial robustness and generalization
Stutz, D., Hein, M., and Schiele, B · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E., El Ghaoui, L., and Jordan, M · 2019
Later among the works it cites.
Feature purification: How adversarial training performs robust deep learning
Allen-Zhu, Z. and Li, Y · 2020
Later among the works it cites.
Exemplary natural images explain cnn activations better than feature visualizations
Borowski, J., Zimmermann, R. S., Schepers, J., Geirhos, R., Wallis, T. S., Bethge, M., and Brendel, W · 2020
Later among the works it cites.
Shortcut learning in deep neural networks
Geirhos, R., Jacobsen, J.-H., Michaelis, C., Zemel, R., Brendel, W., Bethge, M., and Wichmann, F. A · 2020
Later among the works it cites.
The origins and prevalence of texture bias in convolutional neural networks
Hermann, K., Chen, T., and Kornblith, S · 2020
Later among the works it cites.
A simple fine-tuning is all you need: Towards robust deep learning via adversarial fine-tuning
Jeddi, A., Shafiee, M. J., and Wong, A · 2020
Later among the works it cites.
Does adversarial transferability indicate knowledge transferability?
Liang, K., Zhang, J. Y., Koyejo, O., and Li, B · 2020
Later among the works it cites.
Zoom in: An introduction to circuits
Olah, C., Cammarata, N., Schubert, L., Goh, G., Petrov, M., and Carter, S · 2020
Later among the works it cites.
Gradient starvation: A learning proclivity in neural networks
Pezeshki, M., Kaba, S.-O., Bengio, Y., Courville, A., Precup, D., and Lajoie, G · 2020
Later among the works it cites.
Do adversarially robust imagenet models transfer better?
Salman, H., Ilyas, A., Engstrom, L., Kapoor, A., and Madry, A · 2020
Later among the works it cites.
The pitfalls of simplicity bias in neural networks
Shah, H., Tamuly, K., Raghunathan, A., Jain, P., and Netrapalli, P · 2020
Later among the works it cites.
Adversarial training reduces information and improves transferability
Terzi, M., Achille, A., Maggipinto, M., and Susto, G. A · 2020
Later among the works it cites.
Adversarially-trained deep nets transfer better
Utrera, F., Kravitz, E., Erichson, N. B., Khanna, R., and Mahoney, M. W · 2020
Later among the works it cites.
High-frequency component helps explain the generalization of convolutional neural networks
Wang, H., Wu, X., Huang, Z., and Xing, E. P · 2020
Later among the works it cites.
Understanding non-robust features in image classification
Wei, K.-A. A · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z · 2020
Later among the works it cites.