Fetching the paper…
Reading the bibliography…
Adversarial training (AT) has become the de-facto standard to obtain models robust against adversarial examples.
Maximally fault tolerant neural networks
Chalapathy Neti, Michael H. Schneider, and Eric D. Young · 1992
Earlier work this paper cites.
Training techniques to obtain fault-tolerant neural networks
Ching-Tai Chiu, Kishan Mehrotra, Chilukuri K. Mohan, and Sanjay Ranka · 1994
Earlier work this paper cites.
Flat minima
S. Hochreiter and J. Schmidhuber · 1997
Earlier work this paper cites.
Synthesis of fault-tolerant feedforward neural networks using minimax optimization
Dipti Deodhare, M. Vidyasagar, and S. Sathiya Keerthi · 1998
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Learning with a strong adversary
Ruitong Huang, Bing Xu, Dale Schuurmans, and Csaba Szepesvári · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Sergey Ioffe and Christian Szegedy · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P. Kingma and Jimmy Ba · 2015
Earlier work this paper cites.
Defensive distillation is not robust to adversarial examples
Nicholas Carlini and David A. Wagner · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Bridging nonlinearities and stochastic regularizers with gaussian error linear units
Dan Hendrycks and Kevin Gimpel · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Distributional smoothing with virtual adversarial training
Takeru Miyato, Shin-ichi Maeda, Masanori Koyama, Ken Nakae, and Shin Ishii · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jonathon Shlens, and Zbigniew Wojna · 2016
Earlier work this paper cites.
Learning a probabilistic latent space of object shapes via 3d generative-adversarial modeling
Jiajun Wu, Chengkai Zhang, Tianfan Xue, Bill Freeman, and Josh Tenenbaum · 2016
Earlier work this paper cites.
Wide residual networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
The vulnerability of learning to adversarial perturbation increases with intrinsic dimensionality
Laurent Amsaleg, James Bailey, Dominique Barbe, Sarah M. Erfani, Michael E. Houle, Vinh Nguyen, and Milos Radovanovic · 2017
Earlier work this paper cites.
Dimensionality reduction as a defense against evasion attacks on machine learning classifiers
Arjun Nitin Bhagoji, Daniel Cullina, and Prateek Mittal · 2017
Earlier work this paper cites.
Comment on ”biologically inspired protection of deep networks from adversarial attacks”
Wieland Brendel and Matthias Bethge · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Entropy-sgd: Biasing gradient descent into wide valleys
Pratik Chaudhari, Anna Choromanska, Stefano Soatto, Yann LeCun, Carlo Baldassi, Christian Borgs, Jennifer T. Chayes, Levent Sagun, and Riccardo Zecchina · 2017
Earlier work this paper cites.
ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh · 2017
Earlier work this paper cites.
On the robustness of convolutional neural networks to internal architecture and weight perturbations
Nicholas Cheney, Martin Schrimpf, and Gabriel Kreiman · 2017
Earlier work this paper cites.
Improved regularization of convolutional neural networks with cutout
Terrance Devries and Graham W. Taylor · 2017
Earlier work this paper cites.
Sharp minima can generalize for deep nets
Laurent Dinh, Razvan Pascanu, Samy Bengio, and Yoshua Bengio · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner · 2017
Earlier work this paper cites.
On the (statistical) detection of adversarial examples
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel · 2017
Earlier work this paper cites.
Adversarial example defense: Ensembles of weak defenses are not strong
Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song · 2017
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
Matthias Hein and Maksym Andriushchenko · 2017
Earlier work this paper cites.
The robust manifold defense: Adversarial training using generative models
Andrew Ilyas, Ajil Jalal, Eirini Asteri, Constantinos Daskalakis, and Alexandros G. Dimakis · 2017
Earlier work this paper cites.
On large-batch training for deep learning: Generalization gap and sharp minima
Nitish Shirish Keskar, Dheevatsa Mudigere, Jorge Nocedal, Mikhail Smelyanskiy, and Ping Tak Peter Tang · 2017
Earlier work this paper cites.
Towards robust neural networks via random self-ensemble
Xuanqing Liu, Minhao Cheng, Huan Zhang, and Cho-Jui Hsieh · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Earlier work this paper cites.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Earlier work this paper cites.
Simple black-box adversarial attacks on deep neural networks
Nina Narodytska and Shiva Prasad Kasiviswanathan · 2017
Earlier work this paper cites.
Biologically inspired protection of deep networks from adversarial attacks
Aran Nayebi and Surya Ganguli · 2017
Earlier work this paper cites.
Exploring generalization in deep learning
Behnam Neyshabur, Srinadh Bhojanapalli, David McAllester, and Nati Srebro · 2017
Earlier work this paper cites.
Automatic differentiation in pytorch
Adam Paszke, Sam Gross, Soumith Chintala, Gregory Chanan, Edward Yang, Zachary DeVito, Zeming Lin, Alban Desmaison, Luca Antiga, and Adam Lerer · 2017
Earlier work this paper cites.
UPSET and ANGRI : Breaking high performance image classifiers
Sayantan Sarkar, Ankan Bansal, Upal Mahbub, and Rama Chellappa · 2017
Earlier work this paper cites.
Ape-gan: Adversarial perturbation elimination with gan
Shiwei Shen, Guoqing Jin, Ke Gao, and Yongdong Zhang · 2017
Earlier work this paper cites.
Ensemble methods as a defense to adversarial perturbations against deep neural networks
Thilo Strauss, Markus Hanselmann, Andrej Junginger, and Holger Ulmer · 2017
Earlier work this paper cites.
One pixel attack for fooling deep neural networks
Jiawei Su, Danilo Vasconcellos Vargas, and Kouichi Sakurai · 2017
Earlier work this paper cites.
Fault and error tolerance in neural networks: A review
César Torres-Huitzil and Bernard Girau · 2017
Earlier work this paper cites.
Adversarial examples: Attacks and defenses for deep learning
Xiaoyong Yuan, Pan He, Qile Zhu, Rajendra Rana Bhat, and Xiaolin Li · 2017
Cited alongside, same era.
Efficient defenses against adversarial attacks
Valentina Zantedeschi, Maria-Irina Nicolae, and Ambrish Rawat · 2017
Cited alongside, same era.
Threat of adversarial attacks on deep learning in computer vision: A survey
Naveed Akhtar and Ajmal S. Mian · 2018
Cited alongside, same era.
On the robustness of the CVPR 2018 white-box adversarial example defenses
Anish Athalye and Nicholas Carlini · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David A. Wagner · 2018
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy M. Cohen, Elan Rosenfeld, and J. Zico Kolter · 2019
Later among the works it cites.
Adversarial fault tolerant training for deep neural networks
Vasisht Duddu, D. Vijay Rao, and Valentina E. Balas · 2019
Later among the works it cites.
Robustness (python library), 2019
Logan Engstrom, Andrew Ilyas, Hadi Salman, Shibani Santurkar, and Dimitris Tsipras · 2019
Later among the works it cites.
Generalizable adversarial training via spectral normalization
Farzan Farnia, Jesse M. Zhang, and David Tse · 2019
Later among the works it cites.
Using self-supervised learning can improve model robustness and uncertainty
Dan Hendrycks, Mantas Mazeika, Saurav Kadavath, and Dawn Song · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Cited alongside, same era.
Understanding batch normalization
Johan Bjorck, Carla P. Gomes, Bart Selman, and Kilian Q. Weinberger · 2018
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Cited alongside, same era.
Provable robustness of relu networks via maximization of linear regions
Francesco Croce, Maksym Andriushchenko, and Matthias Hein · 2018
Cited alongside, same era.
Autoaugment: Learning augmentation policies from data
Ekin Dogus Cubuk, Barret Zoph, Dandelion Mané, Vijay Vasudevan, and Quoc V. Le · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Cited alongside, same era.
Backdooring convolutional neural networks via targeted weight perturbations
Jacob Dumford and Walter J. Scheirer · 2018
Cited alongside, same era.
Cassidy Laidlaw and Soheil Feizi · 2019
Later among the works it cites.
Interpolated adversarial training: Achieving robust neural networks without sacrificing too much accuracy
Alex Lamb, Vikas Verma, Juho Kannala, and Yoshua Bengio · 2019
Later among the works it cites.
Towards robust, locally linear deep networks
Guang-He Lee, David Alvarez-Melis, and Tommi S. Jaakkola · 2019
Later among the works it cites.
Adv-bnn: Improved adversarial defense through robust bayesian neural network
Xuanqing Liu, Yao Li, Chongruo Wu, and Cho-Jui Hsieh · 2019
Later among the works it cites.
Understanding adversarial robustness through loss landscape geometries
Vinay Uday Prabhu, Dian Ang Yap, Joyce Xu, and J. Whaley · 2019
Later among the works it cites.
Adversarial robustness through local linearization
Chongli Qin, James Martens, Sven Gowal, Dilip Krishnan, Krishnamurthy Dvijotham, Alhussein Fawzi, Soham De, Robert Stanforth, and Pushmeet Kohli · 2019
Later among the works it cites.
Adversarial training can hurt generalization
Aditi Raghunathan, Sang Michael Xie, Fanny Yang, John C. Duchi, and Percy Liang · 2019
Later among the works it cites.
Bit-flip attack: Crushing neural network with progressive bit search
Adnan Siraj Rakin, Zhezhi He, and Deliang Fan · 2019
Later among the works it cites.
Disentangling adversarial robustness and generalization
David Stutz, Matthias Hein, and Bernt Schiele · 2019
Later among the works it cites.
Adversarial training and robustness for multiple perturbations
Florian Tramèr and Dan Boneh · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Later among the works it cites.
Adversarial attacks and defenses in images, graphs and text: A review
Han Xu, Yao Ma, Haochen Liu, Debayan Deb, Hui Liu, Jiliang Tang, and Anil K. Jain · 2019
Later among the works it cites.
Towards stable and efficient training of verifiably robust neural networks
Huan Zhang, Hongge Chen, Chaowei Xiao, Bo Li, Duane S. Boning, and Cho-Jui Hsieh · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P. Xing, Laurent El Ghaoui, and Michael I. Jordan · 2019
Later among the works it cites.
Understanding and improving fast adversarial training
Maksym Andriushchenko and Nicolas Flammarion · 2020
Later among the works it cites.
Robustbench: a standardized adversarial robustness benchmark
Francesco Croce, Maksym Andriushchenko, Vikash Sehwag, Nicolas Flammarion, Mung Chiang, Prateek Mittal, and Matthias Hein · 2020
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Later among the works it cites.
MMA training: Direct input space margin maximization through adversarial training
Gavin Weiguang Ding, Yash Sharma, Kry Yik Chau Lui, and Ruitong Huang · 2020
Later among the works it cites.
Uncovering the limits of adversarial training against norm-bounded adversarial examples
Sven Gowal, Chongli Qin, Jonathan Uesato, Timothy A. Mann, and Pushmeet Kohli · 2020
Later among the works it cites.
Defending and harnessing the bit-flip based adversarial weight attack
Zhezhi He, Adnan Siraj Rakin, Jingtao Li, Chaitali Chakrabarti, and Deliang Fan · 2020
Later among the works it cites.
Adversarial training with stochastic weight average
J. Hwang, Youngwan Lee, Sungchan Oh, and Yu-Seok Bae · 2020
Later among the works it cites.
Fantastic generalization measures and where to find them
Yiding Jiang, Behnam Neyshabur, Hossein Mobahi, Dilip Krishnan, and Samy Bengio · 2020
Later among the works it cites.
Certifying confidence via randomized smoothing
Aounon Kumar, A. Levine, S. Feizi, and T. Goldstein · 2020
Later among the works it cites.
Don’t use large mini-batches, use local SGD
Tao Lin, Sebastian U. Stich, Kumar Kshitij Patel, and Martin Jaggi · 2020
Later among the works it cites.
Adversarial robustness against the union of multiple perturbation models
Pratyush Maini, Eric Wong, and J. Zico Kolter · 2020
Later among the works it cites.
Mish: A self regularized non-monotonic activation function
Diganta Misra · 2020
Later among the works it cites.
Bag of tricks for adversarial training
Tianyu Pang, Xian Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2020
Later among the works it cites.
Boosting adversarial training with hypersphere embedding
Tianyu Pang, Xiao Yang, Yinpeng Dong, Taufik Xu, Jun Zhu, and Hang Su · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and J. Zico Kolter · 2020
Later among the works it cites.
Single-step adversarial training with dropout scheduling
Vivek B. S. and R. Venkatesh Babu · 2020
Later among the works it cites.
Opportunities and challenges in deep learning adversarial robustness: A survey
Samuel Henrique Silva and Peyman Najafirad · 2020
Later among the works it cites.
Fixmatch: Simplifying semi-supervised learning with consistency and confidence
Kihyuk Sohn, David Berthelot, C. Li, Zizhao Zhang, N. Carlini, E. D. Cubuk, Alex Kurakin, Han Zhang, and Colin Raffel · 2020
Later among the works it cites.
Confidence-calibrated adversarial training: Generalizing to unseen attacks
David Stutz, Matthias Hein, and Bernt Schiele · 2020
Later among the works it cites.
Improving adversarial robustness requires revisiting misclassified examples
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu · 2020
Later among the works it cites.
Towards certificated model robustness against weight perturbations
Tsui-Wei Weng, Pu Zhao, Sijia Liu, Pin-Yu Chen, Xue Lin, and Luca Daniel · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
Dongxian Wu, Shu-Tao Xia, and Yisen Wang · 2020
Later among the works it cites.
Randomized smoothing of all shapes and sizes
Greg Yang, Tony Duan, Edward Hu, Hadi Salman, Ilya P. Razenshteyn, and Jerry Li · 2020
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan S. Kankanhalli · 2020
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Li zhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2020
Later among the works it cites.
Regularizing neural networks via adversarial model perturbation
Yaowei Zheng, Richong Zhang, and Yongyi Mao · 2020
Later among the works it cites.
Low curvature activations reduce overfitting in adversarial training
Vasu Singla, Sahil Singla, David Jacobs, and Soheil Feizi · 2021
Closest in time.
Bit error robustness for energy-efficient dnn accelerators
David Stutz, Nandhini Chandramoorthy, Matthias Hein, and Bernt Schiele · 2021
Closest in time.