Fetching the paper…
Reading the bibliography…
Certified patch defenses can guarantee robustness of an image classifier to arbitrary changes within a bounded contiguous region.
“Imagenet: A large-scale hierarchical image database”
Jia Deng et al · 2009
Earlier work this paper cites.
“Learning Multiple Layers of Features from Tiny Images”
Alex Krizhevsky · 2009
Earlier work this paper cites.
“ImageNet Large Scale Visual Recognition Challenge”
Olga Russakovsky et al · 2015
Earlier work this paper cites.
“Deep Residual Learning for Image Recognition”
Kaiming He, Xiangyu Zhang, Shaoqing Ren and Jian Sun · 2016
Earlier work this paper cites.
“Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition”
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer and Michael. Reiter · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
“Formal Verification of Piece-Wise Linear Feed-Forward Neural Networks”
R\"udiger Ehlers · 2017
Earlier work this paper cites.
“Reluplex: An Efficient SMT Solver for Verifying Deep Neural Networks”
Guy Katz et al · 2017
Earlier work this paper cites.
“An approach to reachability analysis for feed-forward ReLU neural networks”
Alessio Lomuscio and Lalit Maganti · 2017
Earlier work this paper cites.
“Attention is All you Need”
Ashish Vaswani et al · 2017
Earlier work this paper cites.
“Adversarial attacks on face detectors using neural net based constrained optimization”
Avishek Bose and Parham Aarabi · 2018
Earlier work this paper cites.
“Thwarting Adversarial Examples: An
Mitali Bafna, Jack Murtagh and Nikhil Vyas · 2018
Earlier work this paper cites.
Tom. Brown et al · 2018
Earlier work this paper cites.
“Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector”
Shang-Tse Chen, Cory Cornelius, Jason Martin and Duen Horng Chau · 2018
Earlier work this paper cites.
“Robust Physical-World Attacks on Machine Learning Models”
Ivan Evtimov et al · 2018
Earlier work this paper cites.
“Physical Adversarial Examples for Object Detectors”
Kevin Eykholt et al · 2018
Earlier work this paper cites.
“On the Effectiveness of Interval Bound Propagation for Training Verifiably Robust Models”, 2018
Sven Gowal et al · 2018
Earlier work this paper cites.
“On visible adversarial perturbations & digital watermarking”
Jamie Hayes · 2018
Earlier work this paper cites.
“Lavan: Localized and visible adversarial noise”
Danny Karmon, Daniel Zoran and Yoav Goldberg · 2018
Earlier work this paper cites.
“Certified adversarial robustness with additive noise”
Bai Li, Changyou Chen, Wenlin Wang and Lawrence Carin · 2018
Cited alongside, same era.
“Dpatch: An adversarial patch attack on object detectors”
Xin Liu et al · 2018
Cited alongside, same era.
“Differentiable abstract interpretation for provably robust neural networks”
Matthew Mirman, Timon Gehr and Martin Vechev · 2018
Cited alongside, same era.
“Certified defenses against adversarial examples”
Aditi Raghunathan, Jacob Steinhardt and Percy Liang · 2018
Cited alongside, same era.
“Towards fast computation of certified robustness for ReLU networks”
Tsui-Wei Weng et al · 2018
Cited alongside, same era.
“Evaluating Robustness of Neural Networks with Mixed Integer Programming”
Vincent Tjeng, Kai Xiao and Russ Tedrake · 2019
Later among the works it cites.
“PyTorch Image Models”
Ross Wightman · 2019
Later among the works it cites.
“Training for Faster Adversarial Robustness Verification via Inducing ReLU Stability”
Kai. Xiao, Vincent Tjeng, Nur Shafiullah and Aleksander Madry · 2019
Later among the works it cites.
“Certified defenses for adversarial patches”
Ping-yeh Chiang et al · 2020
Later among the works it cites.
“Dynamic Adversarial Patch for Evading Object Detection Models”
Shahar Hoory, Tzvika Shapira, Asaf Shabtai and Yuval Elovici · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Eric Wong and J Kolter · 2018
Cited alongside, same era.
“Scaling provable adversarial defenses”
Eric Wong, Frank Schmidt, Jan Metzen and Zico Kolter · 2018
Cited alongside, same era.
“Efficient neural network robustness certification with general activation functions”
Huan Zhang et al · 2018
Cited alongside, same era.
“Certified adversarial robustness via randomized smoothing”
Jeremy Cohen, Elan Rosenfeld and J Kolter · 2019
Cited alongside, same era.
“Scalable verified training for provably robust image classification”
Sven Gowal et al · 2019
Cited alongside, same era.
“Guaranteeing safety for neural network-based aircraft collision avoidance systems”
Kyle Julian and Mykel Kochenderfer · 2019
Cited alongside, same era.
“Certified robustness to adversarial examples with differential privacy”
Mathias Lecuyer et al · 2019
Cited alongside, same era.
Alexander Levine and Soheil Feizi · 2020
Later among the works it cites.
“Robustness certificates for sparse adversarial attacks by randomized ablation”
Alexander Levine and Soheil Feizi · 2020
Later among the works it cites.
“Wasserstein smoothing: Certified robustness against wasserstein adversarial attacks”
Alexander Levine and Soheil Feizi · 2020
Later among the works it cites.
“Adversarial training against location-optimized adversarial patches”
Sukrut Rao, David Stutz and Bernt Schiele · 2020
Later among the works it cites.
“Denoised smoothing: A provable defense for pretrained classifiers”
Hadi Salman et al · 2020
Later among the works it cites.
“Training data-efficient image transformers & distillation through attention”
Hugo Touvron et al · 2020
Later among the works it cites.
“On adaptive attacks to adversarial example defenses”
Florian Tramer, Nicholas Carlini, Wieland Brendel and Aleksander Madry · 2020
Later among the works it cites.
“Neural network virtual sensors for fuel injection quantities with provable performance specifications”
Eric Wong et al · 2020
Later among the works it cites.
“Making an invisibility cloak: Real world adversarial attacks on object detectors”
Zuxuan Wu, Ser-Nam Lim, Larry Davis and Tom Goldstein · 2020
Later among the works it cites.
“Randomized Smoothing of All Shapes and Sizes”
Greg Yang et al · 2020
Later among the works it cites.
“Clipped BagNet: defending against sticker attacks with clipped bag-of-features”
Zhanyuan Zhang, Benson Yuan, Michael McCoyd and David Wagner · 2020
Later among the works it cites.
“An image is worth 16x16 words: Transformers for image recognition at scale”
Alexey Dosovitskiy et al · 2021
Closest in time.
“Certified robustness against adversarial patch attacks via randomized cropping”
Wan-Yi Lin et al · 2021
Closest in time.