Fetching the paper…
Reading the bibliography…
Recent work argues that robust training requires substantially larger datasets than those required for standard classification.
An Alternative Surrogate Loss for PGD-based Adversarial Testing
S. Gowal, J. Uesato, C. Qin, P.-S. Huang, T. Mann, and P. Kohli · 1910
Earlier work this paper cites.
Achieving Robustness in the Wild via Adversarial Mixing with Disentangled Representations
S. Gowal, C. Qin, P.-S. Huang, T. Cemgil, K. Dvijotham, T. Mann, and P. Kohli · 1912
Earlier work this paper cites.
Some methods of speeding up the convergence of iteration methods
B. T. Polyak · 1964
Earlier work this paper cites.
A method of solving a convex programming problem with convergence rate o ( 1 / k 2 ) o(1/k^{2})
Y. Nesterov · 1983
Earlier work this paper cites.
The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution Generalization
D. Hendrycks, S. Basart, N. Mu, S. Kadavath, F. Wang, E. Dorundo, R. Desai, T. Zhu, S. Parajuli, M. Guo, D. Song, J. Steinhardt, and J. Gilmer · 2006
Earlier work this paper cites.
80 million tiny images: a large dataset for non-parametric object and scene recognition
A. Torralba, R. Fergus, and W. T. Freeman · 2008
Earlier work this paper cites.
Bag of tricks for adversarial training
T. Pang, X. Yang, Y. Dong, H. Su, and J. Zhu · 2010
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng · 2011
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
A. Krizhevsky, I. Sutskever, and G. E. Hinton · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
The CIFAR-10 dataset
A. Krizhevsky, V. Nair, and G. Hinton · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
D. P. Kingma and J. Ba · 2015
Earlier work this paper cites.
End to end learning for self-driving cars
M. Bojarski, D. Del Testa, D. Dworakowski, B. Firner, B. Flepp, P. Goyal, L. D. Jackel, M. Monfort, U. Muller, J. Zhang, X. Zhang, J. Zhao, and K. Zieba · 2016
Earlier work this paper cites.
Deep neural networks for YouTube recommendations
P. Covington, J. Adams, and E. Sargin · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Gaussian error linear units (gelus)
D. Hendrycks and K. Gimpel · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
A. Kurakin, I. Goodfellow, and S. Bengio · 2016
Earlier work this paper cites.
Wide residual networks
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Improved regularization of convolutional neural networks with cutout
T. DeVries and G. W. Taylor · 2017
Earlier work this paper cites.
The Tiny ImageNet dataset
A. K. Fei-Fei Li and J. Johnson · 2017
Earlier work this paper cites.
SGDR: stochastic gradient descent with warm restarts
I. Loshchilov and F. Hutter · 2017
Earlier work this paper cites.
Ensemble Adversarial Training: Attacks and Defenses
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2017
Earlier work this paper cites.
Synthesizing robust adversarial examples
A. Athalye and I. Sutskever · 2018
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Earlier work this paper cites.
JAX: composable transformations of Python+NumPy programs, 2018
J. Bradbury, R. Frostig, P. Hawkins, M. J. Johnson, C. Leary, D. Maclaurin, and S. Wanderman-Milne · 2018
Earlier work this paper cites.
Large scale gan training for high fidelity natural image synthesis
A. Brock, J. Donahue, and K. Simonyan · 2018
Cited alongside, same era.
Pac-learning in the presence of adversaries
D. Cullina, A. N. Bhagoji, and P. Mittal · 2018
Cited alongside, same era.
Clinically applicable deep learning for diagnosis and referral in retinal disease
J. De Fauw, J. R. Ledsam, B. Romera-Paredes, S. Nikolov, N. Tomasev, S. Blackwell, H. Askham, X. Glorot, B. O’Donoghue, D. Visentin, G. v. d. Driessche, B. Lakshminarayanan, C. Meyer, F. Mackinder, S. Bouton, K. Ayoub, R. Chopra, D. King, A. Karthikesalingam, C. O. Hughes, R. Raine, J. Hughes, D. A. Sim, C. Egan, A. Tufail, H. Montgomery, D. Hassabis, G. Rees, T. Back, P. T. Khaw, M. Suleyman, J. Cornebise, P. A. Keane, and O. Ronneberger · 2018
Cited alongside, same era.
Boosting Adversarial Attacks with Momentum
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li · 2018
Cited alongside, same era.
Benchmarking neural network robustness to common corruptions and perturbations
D. Hendrycks and T. Dietterich · 2018
Cited alongside, same era.
Adversarially Robust Generalization Just Requires More Unlabeled Data
R. Zhai, T. Cai, D. He, C. Dan, K. He, J. Hopcroft, and L. Wang · 2019
Later among the works it cites.
Theoretically Principled Trade-off between Robustness and Accuracy
H. Zhang, Y. Yu, J. Jiao, E. P. Xing, L. E. Ghaoui, and M. I. Jordan · 2019
Later among the works it cites.
Towards Robust Image Classification Using Sequential Attention Models
D. Zoran, M. Chrzanowski, P.-S. Huang, S. Gowal, A. Mott, and P. Kohl · 2019
Later among the works it cites.
On adversarial bias and the robustness of fair machine learning
H. Chang, T. D. Nguyen, S. K. Murakonda, E. Kazemi, and R. Shokri · 2020
Later among the works it cites.
Gan-leaks: A taxonomy of membership inference attacks against generative models
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Averaging Weights Leads to Wider Optima and Better Generalization
P. Izmailov, D. Podoprikhin, T. Garipov, D. Vetrov, and A. G. Wilson · 2018
Cited alongside, same era.
Minimax statistical learning with wasserstein distances
J. Lee and M. Raginsky · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Cited alongside, same era.
Logit Pairing Methods Can Fool Gradient-Based Attacks
M. Mosbach, M. Andriushchenko, T. Trost, M. Hein, and D. Klakow · 2018
Cited alongside, same era.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Cited alongside, same era.
Adversarially Robust Generalization Requires More Data
L. Schmidt, S. Santurkar, D. Tsipras, K. Talwar, and A. Madry · 2018
Cited alongside, same era.
Robustness may be at odds with accuracy
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry · 2018
Cited alongside, same era.
D. Chen, N. Yu, Y. Zhang, and M. Fritz · 2020
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
F. Croce and M. Hein · 2020
Later among the works it cites.
Robustbench: a standardized adversarial robustness benchmark
F. Croce, M. Andriushchenko, V. Sehwag, N. Flammarion, M. Chiang, P. Mittal, and M. Hein · 2020
Later among the works it cites.
Randaugment: Practical automated data augmentation with a reduced search space
E. D. Cubuk, B. Zoph, J. Shlens, and Q. V. Le · 2020
Later among the works it cites.
Learnable boundary guided adversarial training
J. Cui, S. Liu, L. Wang, and J. Jia · 2020
Later among the works it cites.
Uncovering the limits of adversarial training against norm-bounded adversarial examples
S. Gowal, C. Qin, J. Uesato, T. Mann, and P. Kohli · 2020
Later among the works it cites.
Haiku: Sonnet for JAX, 2020
T. Hennigan, T. Cai, T. Norman, and I. Babuschkin · 2020
Later among the works it cites.
GANSpace: Discovering Interpretable GAN Controls
E. Härkönen, A. Hertzmann, J. Lehtinen, and S. Paris · 2020
Later among the works it cites.
Analyzing and improving the image quality of stylegan
T. Karras, S. Laine, M. Aittala, J. Hellsten, J. Lehtinen, and T. Aila · 2020
Later among the works it cites.
Learning to generate noise for robustness against multiple perturbations
D. Madaan, J. Shin, and S. J. Hwang · 2020
Later among the works it cites.
Controlling generative models with continuous factors of variations
A. Plumerault, H. L. Borgne, and C. Hudelot · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
L. Rice, E. Wong, and J. Z. Kolter · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
F. Tramer, N. Carlini, W. Brendel, and A. Madry · 2020
Later among the works it cites.
Fundamental Tradeoffs between Invariance and Sensitivity to Adversarial Perturbations
F. Tramèr, J. Behrmann, N. Carlini, N. Papernot, and J.-H. Jacobsen · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
D. Wu, S.-t. Xia, and Y. Wang · 2020
Later among the works it cites.
Very deep vaes generalize autoregressive models and can outperform them on images
R. Child · 2021
Closest in time.
Diffusion models beat GANs on image synthesis
P. Dhariwal and A. Nichol · 2021
Closest in time.
Denoising diffusion probabilistic models
J. Ho, A. Jain, and P. Abbeel · 2021
Closest in time.
Perceptual adversarial robustness: Defense against unseen threat models
C. Laidlaw, S. Singla, and S. Feizi · 2021
Closest in time.
Dall-e: Creating images from text, 2021
OpenAI · 2021
Closest in time.
Learning perturbation sets for robust machine learning
E. Wong and J. Z. Kolter · 2021
Closest in time.
Do wider neural networks really help adversarial robustness?
B. Wu, J. Chen, D. Cai, X. He, and Q. Gu · 2021
Closest in time.
Geometry-aware instance-reweighted adversarial training
J. Zhang, J. Zhu, G. Niu, B. Han, M. Sugiyama, and M. Kankanhalli · 2021
Closest in time.