Fetching the paper…
Reading the bibliography…
Multiple intriguing problems are hovering in adversarial training, including robust overfitting, robustness overestimation, and robustness-accuracy trade-off.
Dan Hendrycks, K. Zhao, Steven Basart, J. Steinhardt, and D. Song · 1907
Earlier work this paper cites.
A decision-theoretic generalization of on-line learning and an application to boosting
Y. Freund and R. Schapire · 1995
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Y. LeCun, L. Bottou, Yoshua Bengio, and P. Haffner · 1998
Earlier work this paper cites.
Item response theory for psychologists
S. Embretson and S. Reise · 2000
Earlier work this paper cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, B. Han, Gang Niu, Li zhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2002
Earlier work this paper cites.
Adversarial perturbations prevail in the y-channel of the ycbcr color space
Camilo Pestana, N. Akhtar, W. Liu, David Glance, and A. Mian · 2003
Earlier work this paper cites.
The theory and practice of item response theory
D. Ayala · 2008
Earlier work this paper cites.
Curriculum learning
Yoshua Bengio, J. Louradour, Ronan Collobert, and J. Weston · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky · 2009
Earlier work this paper cites.
Self-paced learning for latent variable models
M. Kumar, Ben Packer, and D. Koller · 2010
Earlier work this paper cites.
Geometry-aware instance-reweighted adversarial training
Jingfeng Zhang, Jianing Zhu, Gang Niu, B. Han, M. Sugiyama, and M. Kankanhalli · 2010
Earlier work this paper cites.
Defense-friendly images in adversarial attacks: Dataset and metrics for perturbation difficulty
Camilo Pestana, Wei Liu, David Glance, and A. Mian · 2011
Earlier work this paper cites.
Improving classification accuracy by identifying and removing instances that should be misclassified
M. Smith and T. Martinez · 2011
Earlier work this paper cites.
An instance level analysis of data complexity
M. Smith, T. Martinez, and C. Giraud-Carrier · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Distilling the knowledge in a neural network
Geoffrey E. Hinton, Oriol Vinyals, and Jeffrey Dean · 2015
Earlier work this paper cites.
Learning with a strong adversary
Ruitong Huang, B. Xu, Dale Schuurmans, and Csaba Szepesvari · 2015
Earlier work this paper cites.
Tiny imagenet visual recognition challenge
Ya Le and Xuan Yang · 2015
Earlier work this paper cites.
Analysis of instance hardness in machine learning using item response theory
R. Prudêncio, J. Hernández-Orallo, and A. Martinez-Usó · 2015
Earlier work this paper cites.
Imagenet large scale visual recognition challenge
Olga Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Zhiheng Huang, A. Karpathy, A. Khosla, Michael S. Bernstein, A. Berg, and Li Fei-Fei · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Identity mappings in deep residual networks
Kaiming He, X. Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Towards the science of security and privacy in machine learning
Nicolas Papernot, P. McDaniel, Arunesh Sinha, and Michael P. Wellman · 2016
Earlier work this paper cites.
Are accuracy and robustness correlated
Andras Rozsa, M. Günther, and T. Boult · 2016
Earlier work this paper cites.
Training region-based object detectors with online hard example mining
Abhinav Shrivastava, Abhinav Gupta, and Ross B. Girshick · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
A closer look at memorization in deep networks
D. Arpit, Stanislaw Jastrzebski, Nicolas Ballas, David Krueger, Emmanuel Bengio, Maxinder S. Kanwal, Tegan Maharaj, Asja Fischer, Aaron C. Courville, Yoshua Bengio, and S. Lacoste-Julien · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and D. Wagner · 2017
Earlier work this paper cites.
Active bias: Training more accurate neural networks by emphasizing high variance samples
Haw-Shiuan Chang, E. Learned-Miller, and A. McCallum · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
G. Katz, C. Barrett, D. Dill, Kyle Julian, and Mykel J. Kochenderfer · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
A. Kurakin, Ian J. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Nicolas Papernot, P. McDaniel, Ian J. Goodfellow, S. Jha, Z. Y. Celik, and A. Swami · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and D. Wagner · 2018
Cited alongside, same era.
Ead: Elastic-net attacks to deep neural networks via adversarial examples
P. Chen, Yash Sharma, Huan Zhang, Jinfeng Yi, and C. Hsieh · 2018
Cited alongside, same era.
Limitations of adversarial robustness: strong no free lunch theorem
Are labels required for improving adversarial robustness?
Jonathan Uesato, Jean-Baptiste Alayrac, Po-Sen Huang, Robert Stanforth, Alhussein Fawzi, and P. Kohli · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, J. Jiao, E. Xing, L. Ghaoui, and Michael I. Jordan · 2019
Later among the works it cites.
Square attack: a query-efficient black-box adversarial attack via random search
Maksym Andriushchenko, F. Croce, Nicolas Flammarion, and M. Hein · 2020
Later among the works it cites.
Rays: A ray searching method for hard-label adversarial attack
J. Chen and Quanquan Gu · 2020
Later among the works it cites.
More data can expand the generalization gap between adversarially robust and standard models
Lin Chen, Yifei Min, Mingrui Zhang, and Amin Karbasi · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Elvis Dohmatob · 2018
Cited alongside, same era.
Evaluating and understanding the robustness of adversarial logit pairing
L. Engstrom, Andrew Ilyas, and Anish Athalye · 2018
Cited alongside, same era.
Averaging weights leads to wider optima and better generalization
Pavel Izmailov, Dmitrii Podoprikhin, T. Garipov, Dmitry P. Vetrov, and Andrew Gordon Wilson · 2018
Cited alongside, same era.
Harini Kannan, A. Kurakin, and Ian J. Goodfellow · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
A. Madry, Aleksandar Makelov, L. Schmidt, D. Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Logit pairing methods can fool gradient-based attacks
Marius Mosbach, Maksym Andriushchenko, T. A. Trost, M. Hein, and D. Klakow · 2018
Cited alongside, same era.
Adversarial robustness toolbox v1.2.0
Maria-Irina Nicolae, Mathieu Sinn, Minh Ngoc Tran, Beat Buesser, Ambrish Rawat, Martin Wistuba, Valentina Zantedeschi, Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, Ian Molloy, and Ben Edwards · 2018
Cited alongside, same era.
Adversarially robust generalization requires more data
L. Schmidt, Shibani Santurkar, D. Tsipras, Kunal Talwar, and A. Madry · 2018
Cited alongside, same era.
Later among the works it cites.
Cat: Customized adversarial training for improved robustness
Minhao Cheng, Qi Lei, Pin-Yu Chen, I. Dhillon, and C. Hsieh · 2020
Later among the works it cites.
Learnable boundary guided adversarial training
Jiequan Cui, Shu Liu, L. Wang, and J. Jia · 2020
Later among the works it cites.
G. W. Ding, Yash Sharma, Kry Yik Chau Lui, and Ruitong Huang · 2020
Later among the works it cites.
Uncovering the limits of adversarial training against norm-bounded adversarial examples
Sven Gowal, Chongli Qin, Jonathan Uesato, Timothy A. Mann, and P. Kohli · 2020
Later among the works it cites.
Self-adaptive training: beyond empirical risk minimization
Lang Huang, C. Zhang, and Hongyang Zhang · 2020
Later among the works it cites.
Precise tradeoffs in adversarial training for linear regression
A. Javanmard, M. Soltanolkotabi, and H. Hassani · 2020
Later among the works it cites.
Mingchen Li, M. Soltanolkotabi, and S. Oymak · 2020
Later among the works it cites.
Confidence-aware learning for deep neural networks
Jooyoung Moon, Jihyo Kim, Younghak Shin, and Sangheum Hwang · 2020
Later among the works it cites.
Understanding and mitigating the tradeoff between robustness and accuracy
Aditi Raghunathan, Sang Michael Xie, F. Yang, John C. Duchi, and P. Liang · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and J. Z. Kolter · 2020
Later among the works it cites.
Adversarial training is a form of data-dependent operator norm regularization
Kevin Roth, Yannic Kilcher, and T. Hofmann · 2020
Later among the works it cites.
How benign is benign overfitting?
Amartya Sanyal, P. Dokania, Varun Kanade, and P. Torr · 2020
Later among the works it cites.
Guided adversarial attack for evaluating and enhancing adversarial defenses
Gaurang Sriramanan, Sravanti Addepalli, Arya Baburaj, and R. Venkatesh Babu · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Florian Tramèr, N. Carlini, W. Brendel, and A. Madry · 2020
Later among the works it cites.
Improving adversarial robustness requires revisiting misclassified examples
Yisen Wang, Difan Zou, Jinfeng Yi, J. Bailey, Xingjun Ma, and Quanquan Gu · 2020
Later among the works it cites.
Towards understanding the regularization of adversarial robustness on neural networks
Yuxin Wen, Shuai Li, and Kui Jia · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
Dongxian Wu, Shutao Xia, and Yisen Wang · 2020
Later among the works it cites.
Adversarial examples improve image recognition
Cihang Xie, Mingxing Tan, Boqing Gong, Jiang Wang, A. Yuille, and Quoc V. Le · 2020
Later among the works it cites.
Curriculum learning by dynamic instance hardness
Tianyi Zhou, S. Wang, and J. Bilmes · 2020
Later among the works it cites.
Robust overfitting may be mitigated by properly learned smoothening
Tianlong Chen, Zhenyu (Allen) Zhang, Sijia Liu, Shiyu Chang, and Zhangyang Wang · 2021
Closest in time.
Evaluating the robustness of geometry-aware instance-reweighted adversarial training
Dorjan Hitaj, Giulio Pagnotta, Iacopo Masi, and L. Mancini · 2021
Closest in time.
Pervasive label errors in test sets destabilize machine learning benchmarks
Curtis G. Northcutt, Anish Athalye, and Jonas Mueller · 2021
Closest in time.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2021
Closest in time.
Low curvature activations reduce overfitting in adversarial training
Vasu Singla, Sahil Singla, David Jacobs, and Soheil Feizi · 2021
Closest in time.
Relating adversarially robust generalization to flat minima
David Stutz, Matthias Hein, and B. Schiele · 2021
Closest in time.