Fetching the paper…
Reading the bibliography…
Adversarial attacks optimize against models to defeat defenses.
A mathematical theory of communication
Shannon, C · 1948
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A · 2009
Earlier work this paper cites.
Dataset shift in machine learning
Quionero-Candela, J., Sugiyama, M., Schwaighofer, A., and Lawrence, N. D · 2009
Earlier work this paper cites.
Adapting visual category models to new domains
Saenko, K., Kulis, B., Fritz, M., and Darrell, T · 2010
Earlier work this paper cites.
Effectiveness of moving target defenses
Evans, D., Nguyen-Tuong, A., and Knight, J · 2011
Earlier work this paper cites.
Source data-absent unsupervised domain adaptation through hypothesis transfer and labeling transfer
Liang, J., Hu, D., Wang, Y., He, R., and Feng, J · 2012
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Ioffe, S. and Szegedy, C · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
Kingma, D. and Ba, J · 2015
Earlier work this paper cites.
ImageNet large scale visual recognition challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., et al · 2015
Earlier work this paper cites.
Neural module networks
Andreas, J., Rohrbach, M., Darrell, T., and Klein, D · 2016
Earlier work this paper cites.
Adaptive computation time for recurrent neural networks
Graves, A · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Tensorflow-serving: Flexible, high-performance ml serving
Olston, C., Fiedel, N., Gorovoy, K., Harmsen, J., Lao, L., Li, F., Rajashekhar, V., Ramesh, S., and Soyke, J · 2017
Earlier work this paper cites.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Rauber, J., Brendel, W., and Bethge, M · 2017
Earlier work this paper cites.
Attacking the madry defense model with l _ 1 l\_1 -based adversarial examples
Sharma, Y. and Chen, P.-Y · 2017
Earlier work this paper cites.
Outrageously large neural networks: The sparsely-gated mixture-of-experts layer
Shazeer, N., Mirhoseini, A., Maziarz, K., Davis, A., Le, Q., Hinton, G., and Dean, J · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Earlier work this paper cites.
Neural ordinary differential equations
Chen, R. T., Rubanova, Y., Bettencourt, J., and Duvenaud, D · 2018
Earlier work this paper cites.
Stochastic activation pruning for robust adversarial defense
Dhillon, G. S., Azizzadenesheli, K., Bernstein, J. D., Kossaifi, J., Khanna, A., Lipton, Z. C., and Anandkumar, A · 2018
Earlier work this paper cites.
Countering adversarial images using input transformations
Guo, C., Rana, M., Cisse, M., and van der Maaten, L · 2018
Cited alongside, same era.
Cycada: Cycle-consistent adversarial domain adaptation
Hoffman, J., Tzeng, E., Park, T., Zhu, J.-Y., Isola, P., Saenko, K., Efros, A., and Darrell, T · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Film: Visual reasoning with a general conditioning layer
Perez, E., Strub, F., De Vries, H., Dumoulin, V., and Courville, A · 2018
Cited alongside, same era.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Condconv: Conditionally parameterized convolutions for efficient inference
Yang, B., Bender, G., Le, Q. V., and Ngiam, J · 2019
Later among the works it cites.
Adversarial examples: Attacks and defenses for deep learning
Yuan, X., He, P., Zhu, Q., and Li, X · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E., El Ghaoui, L., and Jordan, M. I · 2019
Later among the works it cites.
Square attack: a query-efficient black-box adversarial attack via random search
Andriushchenko, M., Croce, F., Flammarion, N., and Hein, M · 2020
Later among the works it cites.
Deep equilibrium models
Bai, S., Kolter, J. Z., and Koltun, V · 2020
Later among the works it cites.
Experiment tracking with weights and biases, 2020
Biewald, L · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Song, Y., Kim, T., Nowozin, S., Ermon, S., and Kushman, N · 2018
Cited alongside, same era.
Is robustness the cost of accuracy?–a comprehensive study on the robustness of 18 deep image classification models
Su, D., Zhang, H., Chen, H., Yi, J., Chen, P.-Y., and Gao, Y · 2018
Cited alongside, same era.
Convolutional networks with adaptive inference graphs
Veit, A. and Belongie, S · 2018
Cited alongside, same era.
Skipnet: Learning dynamic routing in convolutional networks
Wang, X., Yu, F., Dou, Z.-Y., Darrell, T., and Gonzalez, J. E · 2018
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Carmon, Y., Raghunathan, A., Schmidt, L., Duchi, J. C., and Liang, P. S · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Cited alongside, same era.
An adaptive and momental bound method for stochastic learning
Ding, J., Ren, X., Luo, R., and Sun, X · 2019
Cited alongside, same era.
Robustbench: a standardized adversarial robustness benchmark
Croce, F., Andriushchenko, M., Sehwag, V., Flammarion, N., Chiang, M., Mittal, P., and Hein, M · 2020
Later among the works it cites.
Mma training: Direct input space margin maximization through adversarial training
Ding, G. W., Sharma, Y., Lui, K. Y. C., and Huang, R · 2020
Later among the works it cites.
Open compound domain adaptation
Liu, Z., Miao, Z., Pan, X., Zhan, X., Lin, D., Yu, S. X., and Gong, B · 2020
Later among the works it cites.
Mixup inference: Better exploiting mixup to defend adversarial attacks
Pang*, T., Xu*, K., and Zhu, J · 2020
Later among the works it cites.
Designing network design spaces
Radosavovic, I., Kosaraju, R. P., Girshick, R., He, K., and Dollár, P · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
Rice, L., Wong, E., and Kolter, Z · 2020
Later among the works it cites.
Improving robustness against common corruptions by covariate shift adaptation
Schneider, S., Rusak, E., Eck, L., Bringmann, O., Brendel, W., and Bethge, M · 2020
Later among the works it cites.
Test-time training for out-of-distribution generalization
Sun, Y., Wang, X., Liu, Z., Miller, J., Efros, A. A., and Hardt, M · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Tramer, F., Carlini, N., Brendel, W., and Madry, A · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
Wu, D., Xia, S.-T., and Wang, Y · 2020
Later among the works it cites.
Towards stable and efficient training of verifiably robust neural networks
Zhang, H., Chen, H., Xiao, C., Gowal, S., Stanforth, R., Li, B., Boning, D., and Hsieh, C.-J · 2020
Later among the works it cites.
Stochastic security: Adversarial defense using long-run dynamics of energy-based models
Hill, M., Mitchell, J. C., and Zhu, S.-C · 2021
Closest in time.
Online adversarial purification based on self-supervised learning
Shi, C., Holtz, C., and Mishne, G · 2021
Closest in time.
Fully test-time adaptation by entropy minimization
Wang, D., Shelhamer, E., Liu, S., Olshausen, B., and Darrell, T · 2021
Closest in time.