Fetching the paper…
Reading the bibliography…
Randomized smoothing is a general technique for computing sample-dependent robustness guarantees against adversarial attacks for deep classifiers.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Ead: elastic-net attacks to deep neural networks via adversarial examples
Chen, P.-Y., Sharma, Y., Zhang, H., Yi, J., and Hsieh, C.-J · 2018
Earlier work this paper cites.
On the effectiveness of interval bound propagation for training verifiably robust models
Gowal, S., Dvijotham, K., Stanforth, R., Bunel, R., Qin, C., Uesato, J., Mann, T., and Kohli, P · 2018
Earlier work this paper cites.
Semidefinite relaxations for certifying robustness to adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Earlier work this paper cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, Z · 2018
Earlier work this paper cites.
Efficient neural network robustness certification with general activation functions
Zhang, H., Weng, T.-W., Chen, P.-Y., Hsieh, C.-J., and Daniel, L · 2018
Earlier work this paper cites.
Sorting out Lipschitz function approximation
Anil, C., Lucas, J., and Grosse, R · 2019
Earlier work this paper cites.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Earlier work this paper cites.
Certified robustness to adversarial examples with differential privacy
Lecuyer, M., Atlidakis, V., Geambasu, R., Hsu, D., and Jana, S · 2019
Earlier work this paper cites.
Tight certificates of adversarial robustness for randomly smoothed classifiers
Lee, G.-H., Yuan, Y., Chang, S., and Jaakkola, T · 2019
Cited alongside, same era.
Certifiably robust interpretation in deep learning
Levine, A., Singla, S., and Feizi, S · 2019
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
Salman, H., Li, J., Razenshteyn, I., Zhang, P., Zhang, H., Bubeck, S., and Yang, G · 2019
Cited alongside, same era.
Evaluating robustness of neural networks with mixed integer programming
Tjeng, V., Xiao, K. Y., and Tedrake, R · 2019
Cited alongside, same era.
Clipped bagnet: Defending against sticker attacks with clipped bag-of-features
Zhang, Z., Yuan, B., McCoyd, M., and Wagner, D · 2019
Cited alongside, same era.
Higher-order certification for randomized smoothing
Mohapatra, J., Ko, C.-Y., Weng, T.-W., Chen, P.-Y., Liu, S., and Daniel, L · 2020
Later among the works it cites.
Certified robustness to label-flipping attacks via randomized smoothing
Rosenfeld, E., Winston, E., Ravikumar, P., and Kolter, Z · 2020
Later among the works it cites.
Denoised smoothing: A provable defense for pretrained classifiers
Salman, H., Sun, M., Yang, G., Kapoor, A., and Kolter, J. Z · 2020
Later among the works it cites.
Second-order provable defenses against adversarial attacks
Singla, S. and Feizi, S · 2020
Later among the works it cites.
$\ell_1$ adversarial robustness certificates: a randomized smoothing approach, 2020
Teng, J., Lee, G.-H., and Yuan, Y · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Chiang, P., Ni, R., Abdelkader, A., Zhu, C., Studor, C., and Goldstein, T · 2020
Cited alongside, same era.
Certified defense to image transformations via randomized smoothing
Fischer, M., Baader, M., and Vechev, M · 2020
Cited alongside, same era.
Consistency regularization for certified robustness of smoothed classifiers
Jeong, J. and Shin, J · 2020
Cited alongside, same era.
Deterministic certification to adversarial attacks via bernstein polynomial approximation, 2020
Kao, C.-C., Ko, J.-B., and Lu, C.-S · 2020
Cited alongside, same era.
(de)randomized smoothing for certifiable defense against patch attacks
Levine, A. and Feizi, S · 2020
Cited alongside, same era.
Sok: Certified robustness for deep neural networks
Li, L., Qi, X., Xie, T., and Li, B · 2020
Cited alongside, same era.
Robustness certificates for sparse adversarial attacks by randomized ablation
Levine, A. and Feizi, S
Cited in the paper.
Weber, M., Xu, X., Karlas, B., Zhang, C., and Li, B · 2020
Later among the works it cites.
Patchguard: Provable defense against adversarial patches using masks on small receptive fields
Xiang, C., Bhagoji, A., Sehwag, V., and Mittal, P · 2020
Later among the works it cites.
Randomized smoothing of all shapes and sizes
Yang, G., Duan, T., Hu, J. E., Salman, H., Razenshteyn, I., and Li, J · 2020
Later among the works it cites.
Macer: Attack-free and scalable robust training via maximizing certified radius
Zhai, R., Dan, C., He, D., Zhang, H., Gong, B., Ravikumar, P., Hsieh, C.-J., and Wang, L · 2020
Later among the works it cites.
Deep partition aggregation: Provable defenses against general poisoning attacks
Levine, A. and Feizi, S · 2021
Closest in time.