Fetching the paper…
Reading the bibliography…
Recently, Zhang et al.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P. Kingma and Jimmy Ba · 2015
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Parseval networks: Improving robustness to adversarial examples
Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Earlier work this paper cites.
Spectral norm regularization for improving the generalizability of deep learning
Yuichi Yoshida and Takeru Miyato · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
A dual approach to scalable verification of deep networks
Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy Mann, and Pushmeet Kohli · 2018
Earlier work this paper cites.
Ai2: Safety and robustness certification of neural networks with abstract interpretation
Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev · 2018
Earlier work this paper cites.
Regularisation of neural networks by enforcing lipschitz continuity
Henry Gouk, Eibe Frank, Bernhard Pfahringer, and Michael Cree · 2018
Earlier work this paper cites.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2018
Earlier work this paper cites.
Limitations of the lipschitz constant as a defense against adversarial examples
Todd Huster, Cho-Yu Jason Chiang, and Ritu Chadha · 2018
Earlier work this paper cites.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin Vechev · 2018
Earlier work this paper cites.
Fast and effective robustness certification
Gagandeep Singh, Timon Gehr, Matthew Mirman, Markus Püschel, and Martin Vechev · 2018
Earlier work this paper cites.
Lipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks
Yusuke Tsuzuku, Issei Sato, and Masashi Sugiyama · 2018
Earlier work this paper cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’donoghue, Pushmeet Kohli, and Aaron Oord · 2018
Earlier work this paper cites.
Efficient formal safety analysis of neural networks
Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana · 2018
Earlier work this paper cites.
Towards fast computation of certified robustness for relu networks
Lily Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane Boning, and Inderjit Dhillon · 2018
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Cited alongside, same era.
Scaling provable adversarial defenses
Eric Wong, Frank R Schmidt, Jan Hendrik Metzen, and J Zico Kolter · 2018
Cited alongside, same era.
Efficient neural network robustness certification with general activation functions
Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel · 2018
Cited alongside, same era.
Sorting out lipschitz function approximation
Cem Anil, James Lucas, and Roger Grosse · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Curse of dimensionality on randomized smoothing for certifiable robustness
Aounon Kumar, Alexander Levine, Tom Goldstein, and Soheil Feizi · 2020
Later among the works it cites.
Lipschitz-certifiable training with a tight outer bound
Sungyoon Lee, Jaewook Lee, and Saerom Park · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Later among the works it cites.
Improving adversarial robustness requires revisiting misclassified examples
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu · 2020
Later among the works it cites.
Automatic perturbation analysis for scalable certified robustness and beyond
Kaidi Xu, Zhouxing Shi, Huan Zhang, Yihan Wang, Kai-Wei Chang, Minlie Huang, Bhavya Kailkhura, Xue Lin, and Cho-Jui Hsieh · 2020
Later among the works it cites.
Macer: Attack-free and scalable robust training via maximizing certified radius
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Provable robustness of relu networks via maximization of linear regions
Francesco Croce, Maksym Andriushchenko, and Matthias Hein · 2019
Cited alongside, same era.
Generalizable adversarial training via spectral normalization
Farzan Farnia, Jesse Zhang, and David Tse · 2019
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2019
Cited alongside, same era.
L2-nonexpansive neural networks
Haifeng Qian and Mark N. Wegman · 2019
Cited alongside, same era.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Cited alongside, same era.
Training for faster adversarial robustness verification via inducing relu stability
Kai Y Xiao, Vincent Tjeng, Nur Muhammad Mahi Shafiullah, and Aleksander Madry · 2019
Cited alongside, same era.
Runtian Zhai, Chen Dan, Di He, Huan Zhang, Boqing Gong, Pradeep Ravikumar, Cho-Jui Hsieh, and Liwei Wang · 2020
Later among the works it cites.
Globally-robust neural networks
Klas Leino, Zifan Wang, and Matt Fredrikson · 2021
Closest in time.
Towards evaluating and training verifiably robust neural networks
Zhaoyang Lyu, Minghao Guo, Tong Wu, Guodong Xu, Kehuan Zhang, and Dahua Lin · 2021
Closest in time.
The fundamental limits of interval arithmetic for neural networks
Matthew Mirman, Maximilian Baader, and Martin Vechev · 2021
Closest in time.
Training robust neural networks using lipschitz bounds
Patricia Pauli, Anne Koch, Julian Berberich, Paul Kohler, and Frank Allgower · 2021
Closest in time.
Fast certified robust training with short warmup
Zhouxing Shi, Yihan Wang, Huan Zhang, Jinfeng Yi, and Cho-Jui Hsieh · 2021
Closest in time.
Skew orthogonal convolutions
Sahil Singla and Soheil Feizi · 2021
Closest in time.
Orthogonalizing convolutional layers with the cayley transform
Asher Trockman and J Zico Kolter · 2021
Closest in time.
Beta-crown: Efficient bound propagation with per-neuron split constraints for neural network robustness verification
Shiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin, Suman Jana, Cho-Jui Hsieh, and J Zico Kolter · 2021
Closest in time.
Completing the picture: Randomized smoothing suffers from the curse of dimensionality for a large family of distributions
Yihan Wu, Aleksandar Bojchevski, Aleksei Kuvshinov, and Stephan Günnemann · 2021
Closest in time.
Towards certifying l-infinity robustness using neural networks with l-inf-dist neurons
Bohang Zhang, Tianle Cai, Zhou Lu, Di He, and Liwei Wang · 2021
Closest in time.
Boosting randomized smoothing with variance reduced classifiers
Miklós Z. Horváth, Mark Niklas Mueller, Marc Fischer, and Martin Vechev · 2022
Closest in time.
Improved deterministic l2 robustness on CIFAR-10 and CIFAR-100
Sahil Singla, Surbhi Singla, and Soheil Feizi · 2022
Closest in time.
On the certified robustness for ensemble models and beyond
Zhuolin Yang, Linyi Li, Xiaojun Xu, Bhavya Kailkhura, Tao Xie, and Bo Li · 2022
Closest in time.