Fetching the paper…
Reading the bibliography…
While additional training data improves the robustness of deep neural networks against adversarial examples, it presents the challenge of curating a large number of specific real-world samples.
Empirically measuring concentration: Fundamental limits on intrinsic robustness
Saeed Mahloujifar, Xiao Zhang, Mohammad Mahmoody, and David Evans · 1905
Earlier work this paper cites.
The fréchet distance between multivariate normal distributions
DC Dowson and BV Landau · 1982
Earlier work this paper cites.
A class of wasserstein metrics for probability distributions
Clark R Givens, Rae Michael Shortt, et al · 1984
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
MNIST handwritten digit database
Yann LeCun and Corinna Cortes · 2010
Earlier work this paper cites.
Unbiased look at dataset bias
Antonio Torralba and Alexei A Efros · 2011
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Generative adversarial nets
Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
The cifar-10 dataset
Alex Krizhevsky, Vinod Nair, and Geoffrey Hinton · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Deep learning face attributes in the wild
Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
A large dataset to train convolutional networks for disparity, optical flow, and scene flow estimation
Nikolaus Mayer, Eddy Ilg, Philip Hausser, Philipp Fischer, Daniel Cremers, Alexey Dosovitskiy, and Thomas Brox · 2016
Earlier work this paper cites.
Wide Residual Networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Improving the robustness of deep neural networks via stability training
Stephan Zheng, Yang Song, Thomas Leung, and Ian Goodfellow · 2016
Earlier work this paper cites.
Gans trained by a two time-scale update rule converge to a local nash equilibrium
Martin Heusel, Hubert Ramsauer, Thomas Unterthiner, Bernhard Nessler, and Sepp Hochreiter · 2017
Earlier work this paper cites.
The robust manifold defense: Adversarial training using generative models
Ajil Jalal, Andrew Ilyas, Constantinos Daskalakis, and Alexandros G Dimakis · 2017
Earlier work this paper cites.
Revisiting unreasonable effectiveness of data in deep learning era
Chen Sun, Abhinav Shrivastava, Saurabh Singh, and Abhinav Gupta · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Earlier work this paper cites.
Pac-learning in the presence of adversaries
Daniel Cullina, Arjun Nitin Bhagoji, and Prateek Mittal · 2018
Earlier work this paper cites.
Adversarial risk and robustness: general definitions and implications for the uniform distribution
Dimitrios I Diochnos, Saeed Mahloujifar, and Mohammad Mahmoody · 2018
Earlier work this paper cites.
Justin Gilmer, Luke Metz, Fartash Faghri, Samuel S Schoenholz, Maithra Raghu, Martin Wattenberg, and Ian Goodfellow · 2018
Earlier work this paper cites.
Pate-gan: Generating synthetic data with differential privacy guarantees
James Jordon, Jinsung Yoon, and Mihaela Van Der Schaar · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Exploring the limits of weakly supervised pretraining
Dhruv Mahajan, Ross Girshick, Vignesh Ramanathan, Kaiming He, Manohar Paluri, Yixuan Li, Ashwin Bharambe, and Laurens Van Der Maaten · 2018
Earlier work this paper cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Cited alongside, same era.
Scaling provable adversarial defenses
Eric Wong, Frank R. Schmidt, Jan Hendrik Metzen, and J. Zico Kolter · 2018
Cited alongside, same era.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Cited alongside, same era.
Adversarial training and provable defenses: Bridging the gap
Mislav Balunovic and Martin Vechev · 2019
Cited alongside, same era.
Lower bounds on adversarial robustness from optimal transport
Arjun Nitin Bhagoji, Daniel Cullina, and Prateek Mittal · 2019
A review on generative adversarial networks: Algorithms, theory, and applications
Jie Gui, Zhenan Sun, Yonggang Wen, Dacheng Tao, and Jieping Ye · 2020
Later among the works it cites.
Denoising diffusion probabilistic models
Jonathan Ho, Ajay Jain, and Pieter Abbeel · 2020
Later among the works it cites.
Training generative adversarial networks with limited data
Tero Karras, Miika Aittala, Janne Hellsten, Samuli Laine, Jaakko Lehtinen, and Timo Aila · 2020
Later among the works it cites.
Big transfer (bit): General visual representation learning
Alexander Kolesnikov, Lucas Beyer, Xiaohua Zhai, Joan Puigcerver, Jessica Yung, Sylvain Gelly, and Neil Houlsby · 2020
Later among the works it cites.
Mockingbird: Defending against deep-learning-based website fingerprinting attacks with adversarial traces
Mohammad Saidur Rahman, Mohsen Imani, Nate Mathews, and Matthew Wright · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Large scale gan training for high fidelity natural image synthesis
Andrew Brock, Jeff Donahue, and Karen Simonyan · 2019
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, John C Duchi, and Percy S Liang · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Cited alongside, same era.
Benchmarking neural network robustness to common corruptions and perturbations
Dan Hendrycks and Thomas G. Dietterich · 2019
Cited alongside, same era.
Vc classes are adversarially robustly learnable, but only improperly
Omar Montasser, Steve Hanneke, and Nathan Srebro · 2019
Cited alongside, same era.
Robustness to adversarial perturbations in learning from incomplete data
Amir Najafi, Shin-ichi Maeda, Masanori Koyama, and Takeru Miyato · 2019
Cited alongside, same era.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and Zico Kolter · 2020
Later among the works it cites.
Hydra: Pruning adversarially robust neural networks
Vikash Sehwag, Shiqi Wang, Prateek Mittal, and Suman Jana · 2020
Later among the works it cites.
Adversarially robust transfer learning
Ali Shafahi, Parsa Saadatpanah, Chen Zhu, Amin Ghiasi, Christoph Studer, David W. Jacobs, and Tom Goldstein · 2020
Later among the works it cites.
Fawkes: Protecting privacy against unauthorized deep learning models
Shawn Shan, Emily Wenger, Jiayun Zhang, Huiying Li, Haitao Zheng, and Ben Y Zhao · 2020
Later among the works it cites.
Denoising diffusion implicit models
Jiaming Song, Chenlin Meng, and Stefano Ermon · 2020
Later among the works it cites.
Measuring robustness to natural distribution shifts in image classification
Rohan Taori, Achal Dave, Vaishaal Shankar, Nicholas Carlini, Benjamin Recht, and Ludwig Schmidt · 2020
Later among the works it cites.
Off-policy reinforcement learning for efficient and effective gan architecture search
Yuan Tian, Qin Wang, Zhiwu Huang, Wen Li, Dengxin Dai, Minghao Yang, Jun Wang, and Olga Fink · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Florian Tramèr, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Later among the works it cites.
Towards stable and efficient training of verifiably robust neural networks
Huan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal, Robert Stanforth, Bo Li, Duane S. Boning, and Cho-Jui Hsieh · 2020
Later among the works it cites.
Differentiable augmentation for data-efficient gan training
Shengyu Zhao, Zhijian Liu, Ji Lin, Jun-Yan Zhu, and Song Han · 2020
Later among the works it cites.
Towards Better Accuracy-efficiency Trade-offs: Divide and Co-training
Shuai Zhao, Liguang Zhou, Wenxiao Wang, Deng Cai, Tin Lun Lam, and Yangsheng Xu · 2020
Later among the works it cites.
Learnable boundary guided adversarial training
Jiequan Cui, Shu Liu, Liwei Wang, and Jiaya Jia · 2021
Closest in time.
Improving adversarial robustness via unlabeled out-of-domain data
Zhun Deng, Linjun Zhang, Amirata Ghorbani, and James Zou · 2021
Closest in time.
The bootstrap framework: Generalization through the lens of online optimization
Preetum Nakkiran, Behnam Neyshabur, and Hanie Sedghi · 2021
Closest in time.
Improved denoising diffusion probabilistic models
Alexander Quinn Nichol and Prafulla Dhariwal · 2021
Closest in time.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2021
Closest in time.
Styleformer: Transformer based generative adversarial networks with style vector
Jeeseung Park and Younggeun Kim · 2021
Closest in time.
Helper-based adversarial training: Reducing excessive margin to achieve a better accuracy vs. robustness trade-off
Rahul Rade and Seyed-Mohsen Moosavi-Dezfooli · 2021
Closest in time.
Fixing data augmentation to improve adversarial robustness
Sylvestre-Alvise Rebuffi, Sven Gowal, Dan A Calian, Florian Stimberg, Olivia Wiles, and Timothy Mann · 2021
Closest in time.
Negative data augmentation
Abhishek Sinha, Kumar Ayush, Jiaming Song, Burak Uzkent, Hongxia Jin, and Stefano Ermon · 2021
Closest in time.