Fetching the paper…
Reading the bibliography…
Certified robustness in machine learning has primarily focused on adversarial perturbations of the input with a fixed attack budget for each point in the data distribution.
The use of confidence or fiducial limits illustrated in the case of the binomial
C. J. Clopper and E. S. Pearson · 1934
Earlier work this paper cites.
The aurora experimental framework for the performance evaluation of speech recognition systems under noisy conditions
David J. B. Pearce and Hans-Günter Hirsch · 2000
Earlier work this paper cites.
Analysis of representations for domain adaptation
Shai Ben-David, John Blitzer, Koby Crammer, and Fernando Pereira · 2006
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Srndic, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Manitest: Are classifiers really invariant?
Alhussein Fawzi and Pascal Frossard · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Understanding how image quality affects deep neural networks
Samuel F. Dodge and Lina J. Karam · 2016
Earlier work this paper cites.
Examining the impact of blur on recognition by convolutional networks
Igor Vasiljevic, Ayan Chakrabarti, and Gregory Shakhnarovich · 2016
Earlier work this paper cites.
On classification of distorted images with deep convolutional neural networks
Yiren Zhou, Sibo Song, and Ngai-Man Cheung · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
Joint distribution optimal transportation for domain adaptation
Nicolas Courty, Rémi Flamary, Amaury Habrard, and Alain Rakotomamonjy · 2017
Earlier work this paper cites.
Generalisation in humans and deep neural networks
Robert Geirhos, Carlos R. Medina Temme, Jonas Rauber, Heiko H. Schütt, Matthias Bethge, and Felix A. Wichmann · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Pushmeet Kohli, and Aäron van den Oord · 2018
Earlier work this paper cites.
On the effectiveness of interval bound propagation for training verifiably robust models, 2018
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2018
Earlier work this paper cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and J. Zico Kolter · 2018
Earlier work this paper cites.
Semidefinite relaxations for certifying robustness to adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Earlier work this paper cites.
Deepjdot: Deep joint distribution optimal transport for unsupervised domain adaptation
Bharath Bhushan Damodaran, Benjamin Kellenberger, Rémi Flamary, Devis Tuia, and Nicolas Courty · 2018
Earlier work this paper cites.
Minimax statistical learning with wasserstein distances
Jaeho Lee and Maxim Raginsky · 2018
Cited alongside, same era.
Wasserstein distance guided representation learning for domain adaptation
Jian Shen, Yanru Qu, Weinan Zhang, and Yong Yu · 2018
Cited alongside, same era.
Certifying some distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John C. Duchi · 2018
Cited alongside, same era.
Adversarial robustness toolbox v1.2.0
Maria-Irina Nicolae, Mathieu Sinn, Minh Ngoc Tran, Beat Buesser, Ambrish Rawat, Martin Wistuba, Valentina Zantedeschi, Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, Ian Molloy, and Ben Edwards · 2018
Cited alongside, same era.
Why do deep convolutional networks generalize so poorly to small image transformations?
Aharon Azulay and Yair Weiss · 2019
Cited alongside, same era.
Wasserstein smoothing: Certified robustness against wasserstein adversarial attacks, 2019
Alexander Levine and Soheil Feizi · 2019
Later among the works it cites.
On learning invariant representations for domain adaptation
Han Zhao, Remi Tachet des Combes, Kun Zhang, and Geoffrey J. Gordon · 2019
Later among the works it cites.
Measuring robustness to natural distribution shifts in image classification
Rohan Taori, Achal Dave, Vaishaal Shankar, Nicholas Carlini, Benjamin Recht, and Ludwig Schmidt · 2020
Later among the works it cites.
Adversarial self-supervised contrastive learning
Minseon Kim, Jihoon Tack, and Sung Ju Hwang · 2020
Later among the works it cites.
Adversarial robustness against the union of multiple perturbation models
Pratyush Maini, Eric Wong, and J. Zico Kolter · 2020
Later among the works it cites.
Second-order provable defenses against adversarial attacks
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Exploring the landscape of spatial robustness
Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry · 2019
Cited alongside, same era.
Strike (with) a pose: Neural networks are easily fooled by strange poses of familiar objects
Michael A. Alcorn, Qi Li, Zhitao Gong, Chengfei Wang, Long Mai, Wei-Shinn Ku, and Anh Nguyen · 2019
Cited alongside, same era.
Benchmarking neural network robustness to common corruptions and perturbations
Dan Hendrycks and Thomas G. Dietterich · 2019
Cited alongside, same era.
Invariance-inducing regularization using worst-case transformations suffices to boost accuracy and spatial robustness
Fanny Yang, Zuowen Wang, and Christina Heinze-Deml · 2019
Cited alongside, same era.
Adversarial training and robustness for multiple perturbations
Florian Tramèr and Dan Boneh · 2019
Cited alongside, same era.
Adversarial training for free!
Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John P. Dickerson, Christoph Studer, Larry S. Davis, Gavin Taylor, and Tom Goldstein · 2019
Cited alongside, same era.
Functional adversarial attacks
Cassidy Laidlaw and Soheil Feizi · 2019
Cited alongside, same era.
Sahil Singla and Soheil Feizi · 2020
Later among the works it cites.
(de)randomized smoothing for certifiable defense against patch attacks
Alexander Levine and Soheil Feizi · 2020
Later among the works it cites.
Robustness certificates for sparse adversarial attacks by randomized ablation
Alexander Levine and Soheil Feizi · 2020
Later among the works it cites.
Certified defense to image transformations via randomized smoothing
Marc Fischer, Maximilian Baader, and Martin T. Vechev · 2020
Later among the works it cites.
Learning transferable visual models from natural language supervision
Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever · 2021
Later among the works it cites.
Robust contrastive learning using negative samples with diminished semantics
Songwei Ge, Shlok Mishra, Haohan Wang, Chun-Liang Li, and David W. Jacobs · 2021
Later among the works it cites.
Perceptual adversarial robustness: Defense against unseen threat models
Cassidy Laidlaw, Sahil Singla, and Soheil Feizi · 2021
Later among the works it cites.
Improved, deterministic smoothing for L1 certified robustness
Alexander Levine and Soheil Feizi · 2021
Later among the works it cites.
Policy smoothing for provably robust reinforcement learning
Aounon Kumar, Alexander Levine, and Soheil Feizi · 2021
Later among the works it cites.
CROP: certifying robust policies for reinforcement learning through functional smoothing
Fan Wu, Linyi Li, Zijian Huang, Yevgeniy Vorobeychik, Ding Zhao, and Bo Li · 2021
Later among the works it cites.
Center smoothing: Certified robustness for networks with structured outputs
Aounon Kumar and Tom Goldstein · 2021
Later among the works it cites.
Unlearnable examples: Making personal data unexploitable
Hanxun Huang, Xingjun Ma, Sarah Monazam Erfani, James Bailey, and Yisen Wang · 2021
Later among the works it cites.
On the robustness of randomized classifiers to adversarial examples
Rafael Pinot, Laurent Meunier, Florian Yger, Cédric Gouy-Pailler, Yann Chevaleyre, and Jamal Atif · 2021
Later among the works it cites.
Understanding the limits of unsupervised domain adaptation via data poisoning
Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, and Jihun Hamm · 2021
Later among the works it cites.