Fetching the paper…
Reading the bibliography…
Existing defenses against adversarial examples such as adversarial training typically assume that the adversary will conform to a specific or known threat model, such as $\ell_p$ perturbations within a fixed budget.
Adversarial training and robustness for multiple perturbations
Tramèr, F. and Boneh, D · 1904
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., and Fei-Fei, L · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A., Hinton, G., et al · 2009
Earlier work this paper cites.
The pascal visual object classes (VOC) challenge
Everingham, M., Gool, L. V., Williams, C. K. I., Winn, J. M., and Zisserman, A · 2010
Earlier work this paper cites.
Understanding the difficulty of training deep feedforward neural networks
Glorot, X. and Bengio, Y · 2010
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., and Fergus, R · 2014
Earlier work this paper cites.
Delving deep into rectifiers: Surpassing human-level performance on imagenet classification
He, K., Zhang, X., Ren, S., and Sun, J · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Simonyan, K. and Zisserman, A · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Wide residual networks
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A., Sutskever, I., and Hinton, G. E · 2017
Earlier work this paper cites.
Pac-learning in the presence of evasion adversaries
Cullina, D., Bhagoji, A. N., and Mittal, P · 2018
Earlier work this paper cites.
Kannan, H., Kurakin, A., and Goodfellow, I · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Spatially transformed adversarial examples
Xiao, C., Zhu, J., Li, B., He, W., Liu, M., and Song, D · 2018
Cited alongside, same era.
The unreasonable effectiveness of deep features as a perceptual metric
Zhang, R., Isola, P., Efros, A. A., Shechtman, E., and Wang, O · 2018
Cited alongside, same era.
Generalizing to unseen domains via distribution matching
Albuquerque, I., Monteiro, J., Darvishi, M., Falk, T. H., and Mitliagkas, I · 2019
Cited alongside, same era.
Improved generalization bounds for robust learning
Attias, I., Kontorovich, A., and Mansour, Y · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
More data can expand the generalization gap between adversarially robust and standard models
Chen, L., Min, Y., Zhang, M., and Karbasi, A · 2020
Later among the works it cites.
Provable robustness against all adversarial $l_p$-perturbations for $p\geq 1$
Croce, F. and Hein, M · 2020
Later among the works it cites.
Manifold regularization for locally stable deep neural networks
Jin, C. and Rinard, M · 2020
Later among the works it cites.
Adversarial robustness against the union of multiple perturbation models
Maini, P., Wong, E., and Kolter, J. Z · 2020
Later among the works it cites.
Mockingbird: Defending against deep-learning-based website fingerprinting attacks with adversarial traces
Rahman, M. S., Imani, M., Mathews, N., and Wright, M · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cohen, J. M., Rosenfeld, E., and Kolter, J. Z · 2019
Cited alongside, same era.
Nearly tight bounds for robust proper learning of halfspaces with a margin
Diakonikolas, I., Kane, D. M., and Manurangsi, P · 2019
Cited alongside, same era.
Lower bounds for adversarially robust pac learning
Diochnos, D. I., Mahloujifar, S., and Mahmoody, M · 2019
Cited alongside, same era.
Adversarial examples are not bugs, they are features
Ilyas, A., Santurkar, S., Engstrom, L., Tran, B., and Madry, A · 2019
Cited alongside, same era.
Testing robustness against unforeseen adversaries
Kang, D., Sun, Y., Hendrycks, D., Brown, T., and Steinhardt, J · 2019
Cited alongside, same era.
Functional adversarial attacks
Laidlaw, C. and Feizi, S · 2019
Cited alongside, same era.
Vc classes are adversarially robustly learnable, but only improperly
Montasser, O., Hanneke, S., and Srebro, N · 2019
Cited alongside, same era.
Fawkes: Protecting privacy against unauthorized deep learning models
Shan, S., Wenger, E., Zhang, J., Li, H., Zheng, H., and Zhao, B. Y · 2020
Later among the works it cites.
Confidence-calibrated adversarial training: Generalizing to unseen attacks
Stutz, D., Hein, M., and Schiele, B · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
Wu, D., Xia, S., and Wang, Y · 2020
Later among the works it cites.
Randomized smoothing of all shapes and sizes
Yang, G., Duan, T., Hu, J. E., Salman, H., Razenshteyn, I., and Li, J · 2020
Later among the works it cites.
Towards stable and efficient training of verifiably robust neural networks
Zhang, H., Chen, H., Xiao, C., Gowal, S., Stanforth, R., Li, B., Boning, D. S., and Hsieh, C · 2020
Later among the works it cites.
Perceptual adversarial robustness: Defense against unseen threat models
Laidlaw, C., Singla, S., and Feizi, S · 2021
Later among the works it cites.
Adversarially robust learning with unknown perturbation sets
Montasser, O., Hanneke, S., and Srebro, N · 2021
Later among the works it cites.
Towards a theoretical framework of out-of-distribution generalization
Ye, H., Xie, C., Cai, T., Li, R., Li, Z., and Wang, L · 2021
Later among the works it cites.
Understanding generalization in adversarial training via the bias-variance decomposition
Yu, Y., Yang, Z., Dobriban, E., Steinhardt, J., and Ma, Y · 2021
Later among the works it cites.
Revisiting adversarial robustness of classifiers with a reject option
Chen, J., Raghuram, J., Choi, J., Wu, X., Liang, Y., and Jha, S · 2022
Closest in time.