Fetching the paper…
Reading the bibliography…
Recent studies show that deep neural networks (DNN) are vulnerable to adversarial examples, which aim to mislead DNNs by adding perturbations with small magnitude.
Ix. on the problem of the most efficient tests of statistical hypotheses
Jerzy Neyman and Egon Sharpe Pearson · 1933
Earlier work this paper cites.
The use of confidence or fiducial limits illustrated in the case of the binomial
Charles J Clopper and Egon S Pearson · 1934
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Popular ensemble methods: An empirical study
David Opitz and Richard Maclin · 1999
Earlier work this paper cites.
Maxi–min margin machine: learning large margin classifiers locally and globally
Kaizhu Huang, Haiqin Yang, Irwin King, and Michael R Lyu · 2008
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Sok: Certified robustness for deep neural networks
Linyi Li, Tao Xie, and Bo Li · 2009
Earlier work this paper cites.
Mnist handwritten digit database
Yann LeCun, Corinna Cortes, and CJ Burges · 2010
Earlier work this paper cites.
Ensemble-based classifiers
Lior Rokach · 2010
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Deep learning face representation from predicting 10,000 classes
Yi Sun, Xiaogang Wang, and Xiaoou Tang · 2014
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Attention is all you need
Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, Łukasz Kaiser, and Illia Polosukhin · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Limitations of the lipschitz constant as a defense against adversarial examples
Todd Huster, Cho-Yu Jason Chiang, and Ritu Chadha · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Certifying some distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2018
Cited alongside, same era.
Towards fast computation of certified robustness for relu networks
Lily Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane Boning, and Inderjit Dhillon · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Cited alongside, same era.
Efficient neural network robustness certification with general activation functions
Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel · 2018
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Unrestricted adversarial examples via semantic manipulation
Anand Bhattad, Min Jin Chong, Kaizhao Liang, Bo Li, and David A Forsyth · 2020
Later among the works it cites.
Anomalous example detection in deep learning: A survey
Saikiran Bulusu, Bhavya Kailkhura, Bo Li, Pramod K Varshney, and Dawn Song · 2020
Later among the works it cites.
Consistency regularization for certified robustness of smoothed classifiers
Jongheon Jeong and Jinwoo Shin · 2020
Later among the works it cites.
Certifying confidence via randomized smoothing
Aounon Kumar, Alexander Levine, Soheil Feizi, and Tom Goldstein · 2020
Later among the works it cites.
Boosting the robustness of capsule networks with diverse ensemble
Yueqiao Li, Hang Su, Jun Zhu, and Jun Zhou · 2020
Later among the works it cites.
Enhancing certified robustness of smoothed classifiers via weighted model ensembling
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, John C Duchi, and Percy S Liang · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Cited alongside, same era.
Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks
Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli · 2019
Cited alongside, same era.
Bert: Pre-training of deep bidirectional transformers for language understanding
Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova · 2019
Cited alongside, same era.
A framework for robustness certification of smoothed classifiers using f-divergences
Krishnamurthy Dj Dvijotham, Jamie Hayes, Borja Balle, Zico Kolter, Chongli Qin, Andras Gyorgy, Kai Xiao, Sven Gowal, and Pushmeet Kohli · 2019
Cited alongside, same era.
Improving adversarial robustness of ensembles with diversity training
Sanjay Kariyappa and Moinuddin K Qureshi · 2019
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2019
Cited alongside, same era.
Chizhou Liu, Yunzhen Feng, Ranran Wang, and Bin Dong · 2020
Later among the works it cites.
Higher-order certification for randomized smoothing
Jeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu, and Luca Daniel · 2020
Later among the works it cites.
Black-box smoothing: A provable defense for pretrained classifiers
Hadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor, and J Zico Kolter · 2020
Later among the works it cites.
Provable robust classification via learned smoothed densities
Saeed Saremi and Rupesh Srivastava · 2020
Later among the works it cites.
Second-order provable defenses against adversarial attacks
Sahil Singla and Soheil Feizi · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Later among the works it cites.
Automatic perturbation analysis for scalable certified robustness and beyond
Kaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang, Kai-Wei Chang, Minlie Huang, Bhavya Kailkhura, Xue Lin, and Cho-Jui Hsieh · 2020
Later among the works it cites.
Black-box certification with randomized smoothing: A functional optimization based framework
Dinghuai Zhang, Mao Ye, Chengyue Gong, Zhanxing Zhu, and Qiang Liu · 2020
Later among the works it cites.
Mixture of robust experts (more): A flexible defense against multiple perturbations
Hao Cheng, Kaidi Xu, Chenan Wang, Xue Lin, Bhavya Kailkhura, and Ryan Goldhahn · 2021
Closest in time.
Improved, deterministic smoothing for l 1 l_{1} certified robustness
Alexander J Levine and Soheil Feizi · 2021
Closest in time.
Trs: Transferability reduced ensemble via promoting gradient diversity and model smoothness
Zhuolin Yang, Linyi Li, Xiaojun Xu, Shiliang Zuo, Qian Chen, Pan Zhou, Benjamin I. P. Rubinstein, Ce Zhang, and Bo Li · 2021
Closest in time.
Boosting the certified robustness of l-infinity distance nets
Bohang Zhang, Du Jiang, Di He, and Liwei Wang · 2022
Closest in time.