Fetching the paper…
Reading the bibliography…
Adversarial training is one of the most effective defenses against adversarial attacks.
ImageNet: A Large-Scale Hierarchical Image Database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Gaussian error linear units (gelus)
Dan Hendrycks and Kevin Gimpel · 2016
Earlier work this paper cites.
Safety verification of deep neural networks
Xiaowei Huang, Marta Kwiatkowska, Sen Wang, and Min Wu · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick D. McDaniel, and Ian J. Goodfellow · 2016
Earlier work this paper cites.
Wide residual networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Improved regularization of convolutional neural networks with cutout
Terrance DeVries and Graham W Taylor · 2017
Earlier work this paper cites.
Formal verification of piece-wise linear feed-forward neural networks
Rüdiger Ehlers · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner · 2017
Earlier work this paper cites.
Deep neural networks as 0-1 mixed integer linear programs: A feasibility study
Matteo Fischetti and Jason Jo · 2017
Earlier work this paper cites.
Train longer, generalize better: Closing the generalization gap in large batch training of neural networks
Elad Hoffer, Itay Hubara, and Daniel Soudry · 2017
Earlier work this paper cites.
Reluplex: An efficient SMT solver for verifying deep neural networks
Guy Katz, Clark W. Barrett, David L. Dill, Kyle Julian, and Mykel J. Kochenderfer · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
An approach to reachability analysis for feed-forward relu neural networks
Alessio Lomuscio and Lalit Maganti · 2017
Earlier work this paper cites.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Earlier work this paper cites.
Exploring generalization in deep learning
Behnam Neyshabur, Srinadh Bhojanapalli, David McAllester, and Nathan Srebro · 2017
Earlier work this paper cites.
Searching for activation functions
Prajit Ramachandran, Barret Zoph, and Quoc V Le · 2017
Earlier work this paper cites.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan L. Yuille · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Earlier work this paper cites.
A unified view of piecewise linear neural network verification
Rudy Bunel, Ilker Turkaslan, Philip H.S. Torr, Pushmeet Kohli, and M. Pawan Kumar · 2018
Earlier work this paper cites.
Stochastic activation pruning for robust adversarial defense
Guneet S Dhillon, Kamyar Azizzadenesheli, Zachary C Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, and Anima Anandkumar · 2018
Cited alongside, same era.
Ai2: Safety and robustness certification of neural networks with abstract interpretation
T. Gehr, M. Mirman, D. Drachsler-Cohen, P. Tsankov, S. Chaudhuri, and M. Vechev · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten · 2018
Cited alongside, same era.
Averaging weights leads to wider optima and better generalization
Pavel Izmailov, Dmitrii Podoprikhin, Timur Garipov, Dmitry Vetrov, and Andrew Gordon Wilson · 2018
Cited alongside, same era.
Towards robust neural networks via random self-ensemble
Xuanqing Liu, Minhao Cheng, Huan Zhang, and Cho-Jui Hsieh · 2018
Cited alongside, same era.
Feature denoising for improving adversarial robustness
Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan L Yuille, and Kaiming He · 2019
Later among the works it cites.
You only propagate once: Accelerating adversarial training via maximal principle
Dinghuai Zhang, Tianyuan Zhang, Yiping Lu, Zhanxing Zhu, and Bin Dong · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan · 2019
Later among the works it cites.
(de)randomized smoothing for certifiable defense against patch attacks
Alexander Levine 0001 and Soheil Feizi · 2020
Later among the works it cites.
Discovering parametric activation functions
Garrett Bingham and Risto Miikkulainen · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin Vechev · 2018
Cited alongside, same era.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry · 2018
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and J. Zico Kolter · 2018
Cited alongside, same era.
Scaling provable adversarial defenses
Eric Wong, Frank R. Schmidt, Jan Hendrik Metzen, and J. Zico Kolter · 2018
Cited alongside, same era.
mixup: Beyond empirical risk minimization
Hongyi Zhang, Moustapha Cisse, Yann N. Dauphin, and David Lopez-Paz · 2018
Cited alongside, same era.
Adversarial robustness: From self-supervised pre-training to fine-tuning
Tianlong Chen, Sijia Liu, Shiyu Chang, Yu Cheng, Lisa Amini, and Zhangyang Wang · 2020
Later among the works it cites.
Uncovering the limits of adversarial training against norm-bounded adversarial examples
Sven Gowal, Chongli Qin, Jonathan Uesato, Timothy Mann, and Pushmeet Kohli · 2020
Later among the works it cites.
Adversarial vertex mixup: Toward better adversarially robust generalization
Saehyung Lee, Hyungyu Lee, and Sungroh Yoon · 2020
Later among the works it cites.
Deep double descent: Where bigger models and more data hurt
Preetum Nakkiran, Gal Kaplun, Yamini Bansal, Tristan Yang, Boaz Barak, and Ilya Sutskever · 2020
Later among the works it cites.
Boosting adversarial training with hypersphere embedding
Tianyu Pang, Xiao Yang, Yinpeng Dong, Taufik Xu, Jun Zhu, and Hang Su · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and Zico Kolter · 2020
Later among the works it cites.
Universal adversarial training
Ali Shafahi, Mahyar Najibi, Zheng Xu, John Dickerson, Larry S Davis, and Tom Goldstein · 2020
Later among the works it cites.
Second-order provable defenses against adversarial attacks
Sahil Singla and Soheil Feizi · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
Dongxian Wu, Shu-Tao Xia, and Yisen Wang · 2020
Later among the works it cites.
Cihang Xie, Mingxing Tan, Boqing Gong, Alan L. Yuille, and Quoc V. Le · 2020
Later among the works it cites.
Revisiting knowledge distillation via label smoothing regularization
Li Yuan, Francis EH Tay, Guilin Li, Tao Wang, and Jiashi Feng · 2020
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2020
Later among the works it cites.
Universal adversarial training with class-wise perturbations
Philipp Benz, Chaoning Zhang, Adil Karjauv, and In So Kweon · 2021
Closest in time.
Robust overfitting may be mitigated by properly learned smoothening
Tianlong Chen, Zhenyu Zhang, Sijia Liu, Shiyu Chang, and Zhangyang Wang · 2021
Closest in time.
Shift invariance can reduce adversarial robustness
Songwei Ge, Vasu Singla, Ronen Basri, and David W. Jacobs · 2021
Closest in time.
Regularisation of neural networks by enforcing lipschitz continuity
Henry Gouk, Eibe Frank, Bernhard Pfahringer, and Michael J Cree · 2021
Closest in time.
Perceptual adversarial robustness: Defense against unseen threat models
Cassidy Laidlaw, Sahil Singla, and Soheil Feizi · 2021
Closest in time.
Optimal regularization can mitigate double descent
Preetum Nakkiran, Prayaag Venkat, Sham M. Kakade, and Tengyu Ma · 2021
Closest in time.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2021
Closest in time.
Understanding deep learning (still) requires rethinking generalization
Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals · 2021
Closest in time.