Fetching the paper…
Reading the bibliography…
Despite their success, deep networks have been shown to be highly susceptible to perturbations, often causing significant drops in accuracy.
LeCun, Y., Boser, B., Denker, J.S., Henderson, D., Howard, R.E., Hubbard, W., Jackel, L.D.: Backpropagation applied to handwritten zip code recognition. Neural Computation 1
1989
Earlier work this paper cites.
Barreno, M., Nelson, B., Sears, R., Joseph, A.D., Tygar, J.D.: Can machine learning be secure? In: AsiaCCS (2006)
2006
Earlier work this paper cites.
Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: Imagenet: A large-scale hierarchical image database. In: CVPR. pp. 248–255 (2009)
2009
Earlier work this paper cites.
Krizhevsky, A., Hinton, G.: Learning multiple layers of features from tiny images (2009)
2009
Earlier work this paper cites.
Graves, A.: Long short-term memory. In: Supervised sequence labelling with recurrent neural networks, pp. 37–45. Springer (2012)
2012
Earlier work this paper cites.
Krizhevsky, A., Sutskever, I., Hinton, G.E.: Imagenet classification with deep convolutional neural networks. In: NeurIPS. pp. 1097–1105 (2012)
2012
Earlier work this paper cites.
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
Hinton, G., Vinyals, O., Dean, J.: Distilling the knowledge in a neural network. In: NeurIPS Deep Learning and Representation Learning Workshop (2014)
2014
Earlier work this paper cites.
Srivastava, N., Hinton, G.E., Krizhevsky, A., Sutskever, I., Salakhutdinov, R.: Dropout: a simple way to prevent neural networks from overfitting. JMLR 15
2014
Earlier work this paper cites.
Lee, C.Y., Xie, S., Gallagher, P., Zhang, Z., Tu, Z.: Deeply-supervised nets. In: AISTATS (2015)
2015
Earlier work this paper cites.
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., et al.: Imagenet large scale visual recognition challenge. IJCV 115
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: CVPR. pp. 770–778 (2016)
2016
Earlier work this paper cites.
He, K., Zhang, X., Ren, S., Sun, J.: Identity mappings in deep residual networks. In: ECCV. pp. 630–645. Springer (2016)
2016
Earlier work this paper cites.
Zagoruyko, S., Komodakis, N.: Wide residual networks. In: BMVC (2016)
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
Xie, S., Girshick, R., Dollár, P., Tu, Z., He, K.: Aggregated residual transformations for deep neural networks. In: CVPR. pp. 1492–1500 (2017)
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
Zoph, B., Le, Q.V.: Neural architecture search with reinforcement learning. In: ICLR (2017)
2017
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Cai, Q., Liu, C., Song, D.: Curriculum adversarial training. In: IJCAI. pp. 3740–3747 (2018)
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: ICLR (2018)
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Pham, H., Guan, M.Y., Zoph, B., Le, Q.V., Dean, J.: Efficient neural architecture search via parameter sharing. In: ICML. pp. 4092–4101 (2018)
2018
Earlier work this paper cites.
Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., Chen, L.C.: Mobilenetv2: Inverted residuals and linear bottlenecks. In: CVPR. pp. 4510–4520 (2018)
2018
Cited alongside, same era.
Alayrac, J., Uesato, J., Huang, P., Fawzi, A., Stanforth, R., Kohli, P.: Are labels required for improving adversarial robustness? In: NeurIPS (2019)
2019
Cited alongside, same era.
2019
Cited alongside, same era.
Cai, H., Zhu, L., Han, S.: ProxylessNAS: Direct neural architecture search on target task and hardware. In: ICLR (2019)
2019
Cited alongside, same era.
2020
Later among the works it cites.
2020
Later among the works it cites.
Pang, T., Yang, X., Dong, Y., Xu, T., Zhu, J., Su, H.: Boosting adversarial training with hypersphere embedding. In: NeurIPS (2020)
2020
Later among the works it cites.
Rice, L., Wong, E., Kolter, J.Z.: Overfitting in adversarially robust deep learning. In: ICML (2020)
2020
Later among the works it cites.
Rusak, E., Schott, L., Zimmermann, R.S., Bitterwolf, J., Bringmann, O., Bethge, M., Brendel, W.: A simple way to make neural networks robust against diverse image corruptions. In: ECCV (2020)
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2019
Cited alongside, same era.
Carmon, Y., Raghunathan, A., Schmidt, L., Duchi, J.C., Liang, P.: Unlabeled data improves adversarial robustness. In: NeurIPS (2019)
2019
Cited alongside, same era.
Cubuk, E.D., Zoph, B., Mane, D., Vasudevan, V., Le, Q.V.: Autoaugment: Learning augmentation policies from data. In: CVPR (2019)
2019
Cited alongside, same era.
Geirhos, R., Rubisch, P., Michaelis, C., Bethge, M., Wichmann, F.A., Brendel, W.: Imagenet-trained cnns are biased towards texture; increasing shape bias improves accuracy and robustness. ICLR (2019)
2019
Cited alongside, same era.
Hendrycks, D., Dietterich, T.G.: Benchmarking neural network robustness to common corruptions and perturbations. In: ICLR (2019)
2019
Cited alongside, same era.
Hendrycks, D., Mazeika, M., Kadavath, S., Song, D.: Using self-supervised learning can improve model robustness and uncertainty. In: NeurIPS (2019)
2019
Cited alongside, same era.
Lamb, A., Verma, V., Kannala, J., Bengio, Y.: Interpolated adversarial training: Achieving robust neural networks without sacrificing too much accuracy. In: AISec (2019)
2019
Cited alongside, same era.
Liu, H., Simonyan, K., Yang, Y.: Darts: Differentiable architecture search. In: ICLR (2019)
2019
Cited alongside, same era.
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
Sehwag, V., Wang, S., Mittal, P., Jana, S.: HYDRA: pruning adversarially robust neural networks. In: NeurIPS (2020)
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
Singla, S., Feizi, S.: Second-order provable defenses against adversarial attacks. In: ICML (2020)
2020
Later among the works it cites.
Wag, W., Chen, J., Yang, M.H.: Adversarial training with bi-directional likelihood regularization for visual classification. In: ECCV (2020)
2020
Later among the works it cites.
Wang, H., Chen, T., Gui, S., Hu, T., Liu, J., Wang, Z.: Once-for-all adversarial training: In-situ tradeoff between robustness and accuracy for free. In: NeurIPS (2020)
2020
Later among the works it cites.
Wu, D., Xia, S.T., Wang, Y.: Adversarial weight perturbation helps robust generalization. NeurIPS (2020)
2020
Later among the works it cites.
Zhang, J., Xu, X., Han, B., Niu, G., Cui, L., Sugiyama, M., Kankanhalli, M.S.: Attacks which do not kill training make adversarial learning stronger. In: ICML (2020)
2020
Later among the works it cites.
2021
Later among the works it cites.
Chen, Y., Guo, Y., Chen, Q., Li, M., Zeng, W., Wang, Y., Tan, M.: Contrastive neural architecture search with neural architecture comparators. In: CVPR. pp. 9502–9511 (2021)
2021
Later among the works it cites.
Cui, J., Liu, S., Wang, L., Jia, J.: Learnable boundary guided adversarial training. In: ICCV. pp. 15721–15730 (2021)
2021
Later among the works it cites.
Diffenderfer, J., Bartoldson, B., Chaganti, S., Zhang, J., Kailkhura, B.: A winning hand: Compressing deep networks can improve out-of-distribution robustness. NeurIPS 34
2021
Later among the works it cites.
Gou, J., Yu, B., Maybank, S.J., Tao, D.: Knowledge distillation: A survey 129
2021
Later among the works it cites.
Guo, Y., Zheng, Y., Tan, M., Chen, Q., Li, Z., Chen, J., Zhao, P., Huang, J.: Towards accurate and compact architectures via neural architecture transformer. PAMI (2021)
2021
Later among the works it cites.
Hendrycks, D., Basart, S., Mu, N., Kadavath, S., Wang, F., Dorundo, E., Desai, R., Zhu, T., Parajuli, S., Guo, M., et al.: The many faces of robustness: A critical analysis of out-of-distribution generalization. In: ICCV. pp. 8340–8349 (2021)
2021
Later among the works it cites.
2021
Later among the works it cites.
Li, Y., Min, M.R., Lee, T., Yu, W., Kruus, E., Wang, W., Hsieh, C.J.: Towards robustness of deep neural networks via regularization. In: ICCV (2021)
2021
Later among the works it cites.
2021
Later among the works it cites.
Pang, T., Yang, X., Dong, Y., Su, H., Zhu, J.: Bag of tricks for adversarial training. In: ICLR (2021)
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
Stutz, D., Hein, M., Schiele, B.: Relating adversarially robust generalization to flat minima. In: ICCV (2021)
2021
Later among the works it cites.
Zi, B., Zhao, S., Ma, X., Jiang, Y.: Revisiting adversarial robustness distillation: Robust soft labels make student better. In: ICCV (2021)
2021
Later among the works it cites.
Zi, B., Zhao, S., Ma, X., Jiang, Y.G.: Revisiting adversarial robustness distillation: Robust soft labels make student better. CVPR (2021)
2021
Later among the works it cites.