Fetching the paper…
Reading the bibliography…
Randomized smoothing is currently considered the state-of-the-art method to obtain certifiably robust classifiers.
On some accurate bounds for the quantiles of a non-central chi squared distribution
Robert, C · 1990
Earlier work this paper cites.
The mnist database of handwritten digits, 1999
LeCun, Y., Cortes, C., and Burges, C. J · 1999
Earlier work this paper cites.
Rethinking randomized smoothing for adversarial robustness
Mohapatra, J., Ko, C.-Y., Liu, S., Chen, P.-Y., Daniel, L., et al · 2003
Earlier work this paper cites.
Learning multiple layers of features from tiny images, 2009
Krizhevsky, A · 2009
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Rényi divergence and kullback-leibler divergence
Van Erven, T. and Harremos, P · 2014
Earlier work this paper cites.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
Hein, M. and Andriushchenko, M · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Earlier work this paper cites.
On the robustness of the cvpr 2018 white-box adversarial example defenses
Athalye, A. and Carlini, N · 2018
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Cited alongside, same era.
Robust physical-world attacks on deep learning visual classification
Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Mirman, M., Gehr, T., and Vechev, M · 2018
Cited alongside, same era.
Certified defenses against adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Cited alongside, same era.
Lipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks
Tsuzuku, Y., Sato, I., and Sugiyama, M · 2018
Cited alongside, same era.
Towards fast computation of certified robustness for ReLU networks
Data dependent randomized smoothing
Alfarra, M., Bibi, A., Torr, P. H., and Ghanem, B · 2020
Later among the works it cites.
Analyzing accuracy loss in randomized smoothing defenses
Gao, Y., Rosenberg, H., Fawaz, K., Jha, S., and Hsu, J · 2020
Later among the works it cites.
Expressivity of deep neural networks
Gühring, I., Raslan, M., and Kutyniok, G · 2020
Later among the works it cites.
Extensions and limitations of randomized smoothing for robustness guarantees
Hayes, J · 2020
Later among the works it cites.
Curse of dimensionality on randomized smoothing for certifiable robustness
Kumar, A., Levine, A., Goldstein, T., and Feizi, S · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Weng, L., Zhang, H., Chen, H., Song, Z., Hsieh, C.-J., Daniel, L., Boning, D., and Dhillon, I · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Wong, E. and Kolter, Z · 2018
Cited alongside, same era.
Sorting out Lipschitz function approximation
Anil, C., Lucas, J., and Grosse, R · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
Lecuyer, M., Atlidakis, V., Geambasu, R., Hsu, D., and Jana, S · 2019
Cited alongside, same era.
Certified adversarial robustness with additive noise
Li, B., Chen, C., Wang, W., and Carin, L · 2019
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
Salman, H., Li, J., Razenshteyn, I. P., Zhang, P., Zhang, H., Bubeck, S., and Yang, G · 2019
Cited alongside, same era.
Randomized smoothing of all shapes and sizes
Yang, G., Duan, T., Hu, J. E., Salman, H., Razenshteyn, I., and Li, J · 2020
Later among the works it cites.
Macer: Attack-free and scalable robust training via maximizing certified radius
Zhai, R., Dan, C., He, D., Zhang, H., Gong, B., Ravikumar, P., Hsieh, C.-J., and Wang, L · 2020
Later among the works it cites.
Deep learning through the lens of example difficulty
Baldock, R., Maennel, H., and Neyshabur, B · 2021
Closest in time.
Insta-rs: Instance-wise randomized smoothing for improved robustness and accuracy
Chen, C., Kong, K., Yu, P., Luque, J., Goldstein, T., and Huang, F · 2021
Closest in time.
Ancer: Anisotropic certification via sample-wise volume maximization
Eiras, F., Alfarra, M., Kumar, M. P., Torr, P. H., Dokania, P. K., Ghanem, B., and Bibi, A · 2021
Closest in time.
Pretrain-to-finetune adversarial training via sample-wise randomized smoothing
Wang, L., Zhai, R., He, D., Wang, L., and Jian, L · 2021
Closest in time.
Completing the picture: Randomized smoothing suffers from the curse of dimensionality for a large family of distributions
Wu, Y., Bojchevski, A., Kuvshinov, A., and Günnemann, S · 2021
Closest in time.