Fetching the paper…
Reading the bibliography…
The phenomenon of adversarial examples illustrates one of the most basic vulnerabilities of deep neural networks.
You only propagate once: Accelerating adversarial training via maximal principle
Dinghuai Zhang, Tianyuan Zhang, Yiping Lu, Zhanxing Zhu, and Bin Dong · 1905
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Boosting adversarial training with hypersphere embedding
Tianyu Pang, Xiao Yang, Yinpeng Dong, Kun Xu, Jun Zhu, and Hang Su · 2002
Earlier work this paper cites.
Integrating structured biological data by kernel maximum mean discrepancy
Karsten M Borgwardt, Arthur Gretton, Malte J Rasch, Hans-Peter Kriegel, Bernhard Schölkopf, and Alex J Smola · 2006
Earlier work this paper cites.
Visualizing data using t-sne
Laurens Van der Maaten and Geoffrey Hinton · 2008
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
Domain adaptation: Learning bounds and algorithms
Yishay Mansour, Mehryar Mohri, and Afshin Rostamizadeh · 2009
Earlier work this paper cites.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2010
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y Ng · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Unsupervised domain adaptation by backpropagation
Yaroslav Ganin and Victor Lempitsky · 2015
Earlier work this paper cites.
Domain-adversarial training of neural networks
Yaroslav Ganin, Evgeniya Ustinova, Hana Ajakan, Pascal Germain, Hugo Larochelle, François Laviolette, Mario Marchand, and Victor Lempitsky · 2016
Earlier work this paper cites.
Identity mappings in deep residual networks
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
Deep coral: Correlation alignment for deep domain adaptation
Baochen Sun and Kate Saenko · 2016
Earlier work this paper cites.
Exploring the space of adversarial images
Pedro Tabacof and Eduardo Valle · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Earlier work this paper cites.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2017
Earlier work this paper cites.
Certifiable distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2017
Earlier work this paper cites.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel · 2017
Earlier work this paper cites.
Adef: an iterative algorithm to construct adversarial deformations
Rima Alaifari, Giovanni S Alberti, and Tandri Gauksson · 2018
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Unrestricted adversarial examples
Tom B Brown, Nicholas Carlini, Chiyuan Zhang, Catherine Olsson, Paul Christiano, and Ian Goodfellow · 2018
Earlier work this paper cites.
Curriculum adversarial training
Qi-Zhi Cai, Min Du, Chang Liu, and Dawn Song · 2018
Earlier work this paper cites.
Pac-learning in the presence of adversaries
Daniel Cullina, Arjun Nitin Bhagoji, and Prateek Mittal · 2018
Cited alongside, same era.
Mma training: Direct input space margin maximization through adversarial training
Gavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, and Ruitong Huang · 2018
Cited alongside, same era.
Adversarial risk and robustness: General definitions and implications for the uniform distribution
Dimitrios Diochnos, Saeed Mahloujifar, and Mohammad Mahmoody · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Cited alongside, same era.
A rotation and a translation suffice: Fooling cnns with simple transformations
Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry · 2018
Cited alongside, same era.
Adversarially robust generalization just requires more unlabeled data
Runtian Zhai, Tianle Cai, Di He, Chen Dan, Kun He, John Hopcroft, and Liwei Wang · 2019
Later among the works it cites.
Defense against adversarial attacks using feature scattering-based adversarial training
Haichao Zhang and Jianyu Wang · 2019
Later among the works it cites.
Understanding and improving fast adversarial training
Maksym Andriushchenko and Nicolas Flammarion · 2020
Later among the works it cites.
On the rademacher complexity of linear hypothesis sets
Pranjal Awasthi, Natalie Frank, and Mehryar Mohri · 2020
Later among the works it cites.
Adversarial robustness: From self-supervised pre-training to fine-tuning
Tianlong Chen, Sijia Liu, Shiyu Chang, Yu Cheng, Lisa Amini, and Zhangyang Wang · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Justin Gilmer, Ryan P Adams, Ian Goodfellow, David Andersen, and George E Dahl · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2018
Cited alongside, same era.
Benchmarking neural network robustness to common corruptions and surface variations
Dan Hendrycks and Thomas G Dietterich · 2018
Cited alongside, same era.
Harini Kannan, Alexey Kurakin, and Ian Goodfellow · 2018
Cited alongside, same era.
Adversarial risk bounds for binary classification via function transformation
Justin Khim and Po-Ling Loh · 2018
Cited alongside, same era.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Mądry · 2018
Cited alongside, same era.
Improving the generalization of adversarial training with domain adaptation
Chuanbiao Song, Kun He, Liwei Wang, and John E Hopcroft · 2018
Cited alongside, same era.
Later among the works it cites.
Cat: Customized adversarial training for improved robustness
Minhao Cheng, Qi Lei, Pin-Yu Chen, Inderjit Dhillon, and Cho-Jui Hsieh · 2020
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Later among the works it cites.
Adversarially robust distillation
Micah Goldblum, Liam Fowl, Soheil Feizi, and Tom Goldstein · 2020
Later among the works it cites.
When nas meets robustness: In search of robust architectures against adversarial attacks
Minghao Guo, Yuzhe Yang, Rui Xu, Ziwei Liu, and Dahua Lin · 2020
Later among the works it cites.
Robust pre-training by adversarial contrastive learning
Ziyu Jiang, Tianlong Chen, Ting Chen, and Zhangyang Wang · 2020
Later among the works it cites.
Adversarial vertex mixup: Toward better adversarially robust generalization
Saehyung Lee, Hyungyu Lee, and Sungroh Yoon · 2020
Later among the works it cites.
Towards defending multiple adversarial perturbations via gated batch normalization
Aishan Liu, Shiyu Tang, Xianglong Liu, Xinyun Chen, Lei Huang, Zhuozhuo Tu, Dawn Song, and Dacheng Tao · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and Zico Kolter · 2020
Later among the works it cites.
Do adversarially robust imagenet models transfer better?
Hadi Salman, Andrew Ilyas, Logan Engstrom, Ashish Kapoor, and Aleksander Madry · 2020
Later among the works it cites.
Adversarially-trained deep nets transfer better
Francisco Utrera, Evan Kravitz, N Benjamin Erichson, Rajiv Khanna, and Michael W Mahoney · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J Zico Kolter · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
Dongxian Wu, Shu-Tao Xia, and Yisen Wang · 2020
Later among the works it cites.
Dverge: diversifying vulnerabilities for enhanced robust generation of ensembles
Huanrui Yang, Jingyang Zhang, Hongliang Dong, Nathan Inkawhich, Andrew Gardner, Andrew Touchet, Wesley Wilkes, Heath Berry, and Hai Li · 2020
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2020
Later among the works it cites.
Recent advances in adversarial training for adversarial robustness
Tao Bai, Jinqi Luo, Jun Zhao, Bihan Wen, and Qian Wang · 2021
Closest in time.
Equivariant self-supervised learning: Encouraging equivariance in representations
Rumen Dangovski, Li Jing, Charlotte Loh, Seungwook Han, Akash Srivastava, Brian Cheung, Pulkit Agrawal, and Marin Soljacic · 2021
Closest in time.
Removing undesirable feature contributions using out-of-distribution data
Saehyung Lee, Changhwa Park, Hyungyu Lee, Jihun Yi, Jonghyun Lee, and Sungroh Yoon · 2021
Closest in time.
Improving model robustness with latent distribution locally and globally
Zhuang Qian, Shufei Zhang, Kaizhu Huang, Qiufeng Wang, Rui Zhang, and Xinping Yi · 2021
Closest in time.
Formalizing generalization and robustness of neural networks to weight perturbations
Yu-Lin Tsai, Chia-Yi Hsu, Chia-Mu Yu, and Pin-Yu Chen · 2021
Closest in time.
Residual relaxation for multi-view representation learning
Yifei Wang, Zhengyang Geng, Feng Jiang, Chuming Li, Yisen Wang, Jiansheng Yang, and Zhouchen Lin · 2021
Closest in time.
Adversarially robust learning of real-valued functions
Idan Attias and Steve Hanneke · 2022
Closest in time.
A characterization of semi-supervised adversarially-robust pac learnability
Idan Attias, Steve Hanneke, and Yishay Mansour · 2022
Closest in time.
Enhancing adversarial training with second-order statistics of weights
Gaojie Jin, Xinping Yi, Wei Huang, Sven Schewe, and Xiaowei Huang · 2022
Closest in time.