Fetching the paper…
Reading the bibliography…
Making classifiers robust to adversarial examples is hard.
Ten signs a claimed mathematical breakthrough is wrong
Aaronson, S · 2008
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Brown, T. B., Mané, D., Roy, A., Abadi, M., and Gilmer, J · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Feinman, R., Curtin, R. R., Shintre, S., and Gardner, A. B · 2017
Earlier work this paper cites.
On the (statistical) detection of adversarial examples
Grosse, K., Manoharan, P., Papernot, N., Backes, M., and McDaniel, P · 2017
Earlier work this paper cites.
Adversarial example defenses: Ensembles of weak defenses are not strong
He, W., Wei, J., Chen, X., Carlini, N., and Song, D · 2017
Earlier work this paper cites.
Early methods for detecting adversarial images
Hendrycks, D. and Gimpel, K · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Earlier work this paper cites.
Adversarial examples from cryptographic pseudo-random generators
Bubeck, S., Lee, Y. T., Price, E., and Razenshteyn, I · 2018
Earlier work this paper cites.
On visible adversarial perturbations & digital watermarking
Hayes, J · 2018
Earlier work this paper cites.
A simple unified framework for detecting out-of-distribution samples and adversarial attacks
Lee, K., Lee, K., Lee, H., and Shin, J · 2018
Earlier work this paper cites.
Characterizing adversarial subspaces using local intrinsic dimensionality
Ma, X., Li, B., Wang, Y., Erfani, S. M., Wijewickrema, S., Schoenebeck, G., Song, D., Houle, M. E., and Bailey, J · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Earlier work this paper cites.
Certified defenses against adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Earlier work this paper cites.
Adversarially robust generalization requires more data
Schmidt, L., Santurkar, S., Tsipras, D., Talwar, K., and Madry, A · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, Z · 2018
Cited alongside, same era.
Feature squeezing: Detecting adversarial examples in deep neural networks
Xu, W., Evans, D., and Qi, Y · 2018
Cited alongside, same era.
On evaluating adversarial robustness
Carlini, N., Athalye, A., Papernot, N., Brendel, W., Rauber, J., Tsipras, D., Goodfellow, I., and Madry, A · 2019
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Carmon, Y., Raghunathan, A., Schmidt, L., Duchi, J. C., and Liang, P. S · 2019
Cited alongside, same era.
Robustness (python library), 2019
Adversarially robust generalization just requires more unlabeled data
Zhai, R., Cai, T., He, D., Dan, C., He, K., Hopcroft, J., and Wang, L · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 2019
Later among the works it cites.
Square attack: a query-efficient black-box adversarial attack via random search
Andriushchenko, M., Croce, F., Flammarion, N., and Hein, M · 2020
Later among the works it cites.
Certified defenses for adversarial patches
Chiang, P.-y., Ni, R., Abdelkader, A., Zhu, C., Studer, C., and Goldstein, T · 2020
Later among the works it cites.
Sentinet: Detecting physical attacks against deep learning systems
Chou, E., Tramèr, F., and Pellegrino, G · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Engstrom, L., Ilyas, A., Salman, H., Santurkar, S., and Tsipras, D · 2019
Cited alongside, same era.
Attribution-driven causal analysis for detection of adversarial examples
Jha, S., Raj, S., Fernandes, S. L., Jha, S. K., Jha, S., Verma, G., Jalaian, B., and Swami, A · 2019
Cited alongside, same era.
Are generative classifiers more robust to adversarial attacks?
Li, Y., Bradshaw, J., and Sharma, Y · 2019
Cited alongside, same era.
Nic: Detecting adversarial samples with neural network invariant checking
Ma, S. and Liu, Y · 2019
Cited alongside, same era.
When not to classify: Anomaly detection of attacks (ada) on dnn classifiers at test time
Miller, D., Wang, Y., and Kesidis, G · 2019
Cited alongside, same era.
Local gradients smoothing: Defense against localized adversarial attacks
Naseer, M., Khan, S., and Porikli, F · 2019
Cited alongside, same era.
The odds are odd: A statistical test for detecting adversarial examples
Roth, K., Kilcher, Y., and Hofmann, T · 2019
Cited alongside, same era.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Croce, F. and Hein, M · 2020
Later among the works it cites.
Robustbench: a standardized adversarial robustness benchmark
Croce, F., Andriushchenko, M., Sehwag, V., Flammarion, N., Chiang, M., Mittal, P., and Hein, M · 2020
Later among the works it cites.
Adversarially robust learning could leverage computational hardness
Garg, S., Jha, S., Mahloujifar, S., and Mohammad, M · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Tramèr, F., Carlini, N., Brendel, W., and Madry, A · 2020
Later among the works it cites.
Gat: Generative adversarial training for adversarial example detection and robust classification
Yin, X., Kolouri, S., and Rohde, G. K · 2020
Later among the works it cites.
Clipped bagnet: Defending against sticker attacks with clipped bag-of-features
Zhang, Z., Yuan, B., McCoyd, M., and Wagner, D · 2020
Later among the works it cites.
Adversarial training with rectified rejection
Pang, T., Zhang, H., He, D., Dong, Y., Su, H., Chen, W., Zhu, J., and Liu, T.-Y · 2021
Closest in time.
A general framework for detecting anomalous inputs to dnn classifiers
Raghuram, J., Chandrasekaran, V., Jha, S., and Banerjee, S · 2021
Closest in time.
Fixing data augmentation to improve adversarial robustness
Rebuffi, S.-A., Gowal, S., Calian, D. A., Stimberg, F., Wiles, O., and Mann, T · 2021
Closest in time.
Provably robust classification of adversarial examples with detection
Sheikholeslami, F., Lotfi, A., and Kolter, J. Z · 2021
Closest in time.
Patchguard: A provably robust defense against adversarial patches via small receptive fields and masking
Xiang, C., Bhagoji, A. N., Sehwag, V., and Mittal, P · 2021
Closest in time.