Fetching the paper…
Reading the bibliography…
Adversarial purification refers to a class of defense methods that remove adversarial perturbations using a generative model.
Entropy and the central limit theorem
Barron, A. R · 1986
Earlier work this paper cites.
Stochastic differential equations
Kloeden, P. E. and Platen, E · 1992
Earlier work this paper cites.
A tutorial on energy-based learning
LeCun, Y., Chopra, S., Hadsell, R., Ranzato, M., and Huang, F · 2006
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., and Fei-Fei, L · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A · 2009
Earlier work this paper cites.
Interpretation and generalization of score matching
Lyu, S · 2009
Earlier work this paper cites.
A connection between score matching and denoising autoencoders
Vincent, P · 2011
Earlier work this paper cites.
Concentration inequalities: A nonasymptotic theory of independence
Boucheron, S., Lugosi, G., and Massart, P · 2013
Earlier work this paper cites.
Generative adversarial nets
Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., and Bengio, Y · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Wide residual networks
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Earlier work this paper cites.
Progressive growing of gans for improved quality, stability, and variation
Karras, T., Aila, T., Laine, S., and Lehtinen, J · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Earlier work this paper cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Earlier work this paper cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Song, Y., Kim, T., Nowozin, S., Ermon, S., and Kushman, N · 2018
Earlier work this paper cites.
Spatially transformed adversarial examples
Xiao, C., Zhu, J.-Y., Li, B., He, W., Liu, M., and Song, D · 2018
Earlier work this paper cites.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Earlier work this paper cites.
Implicit generation and modeling with energy based models
Du, Y. and Mordatch, I · 2019
Earlier work this paper cites.
Robustness (python library), 2019
Engstrom, L., Ilyas, A., Salman, H., Santurkar, S., and Tsipras, D · 2019
Earlier work this paper cites.
Parametric noise injection: Trainable randomness to improve deep neural network robustness against adversarial attack
He, Z., Rakin, A. S., and Fan, D · 2019
Earlier work this paper cites.
Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses
Rony, J., Hafemann, L. G., Oliveira, L. S., Ayed, I. B., Sabourin, R., and Granger, E · 2019
Cited alongside, same era.
Applied stochastic differential equations , volume 10
Särkkä, S. and Solin, A · 2019
Cited alongside, same era.
Generative modeling by estimating gradients of the data distribution
Song, Y. and Ermon, S · 2019
Cited alongside, same era.
Me-net: Towards effective adversarial robustness with matrix estimation
Yang, Y., Zhang, G., Katabi, D., and Xu, Z · 2019
Cited alongside, same era.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E., El Ghaoui, L., and Jordan, M · 2019
Cited alongside, same era.
Adversarial robustness on in-and out-distribution improves explainability
Augustin, M., Meinke, A., and Hein, M · 2020
Ensembling with deep generative views
Chai, L., Zhu, J.-Y., Shechtman, E., Isola, P., and Zhang, R · 2021
Later among the works it cites.
Ilvr: Conditioning method for denoising diffusion probabilistic models
Choi, J., Kim, S., Jeong, Y., Gwon, Y., and Yoon, S · 2021
Later among the works it cites.
Diffusion models beat gans on image synthesis
Dhariwal, P. and Nichol, A · 2021
Later among the works it cites.
ℓ ∞ \ell_{\infty} -robustness and beyond: Unleashing efficient adversarial training
Dolatabadi, H. M., Erfani, S., and Leckie, C · 2021
Later among the works it cites.
An image is worth 16x16 words: Transformers for image recognition at scale
Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., Gelly, S., et al · 2021
Later among the works it cites.
Improving robustness using generated data
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Croce, F. and Hein, M · 2020
Cited alongside, same era.
Robustbench: a standardized adversarial robustness benchmark
Croce, F., Andriushchenko, M., Sehwag, V., Debenedetti, E., Flammarion, N., Chiang, M., Mittal, P., and Hein, M · 2020
Cited alongside, same era.
Mma training: Direct input space margin maximization through adversarial training
Ding, G. W., Sharma, Y., Lui, K. Y. C., and Huang, R · 2020
Cited alongside, same era.
Uncovering the limits of adversarial training against norm-bounded adversarial examples
Gowal, S., Qin, C., Uesato, J., Mann, T., and Kohli, P · 2020
Cited alongside, same era.
Your classifier is secretly an energy based model and you should treat it like one
Grathwohl, W., Wang, K.-C., Jacobsen, J.-H., Duvenaud, D., Norouzi, M., and Swersky, K · 2020
Cited alongside, same era.
Denoising diffusion probabilistic models
Ho, J., Jain, A., and Abbeel, P · 2020
Cited alongside, same era.
Gowal, S., Rebuffi, S.-A., Wiles, O., Stimberg, F., Calian, D. A., and Mann, T. A · 2021
Later among the works it cites.
Stochastic security: Adversarial defense using long-run dynamics of energy-based models
Hill, M., Mitchell, J. C., and Zhu, S.-C · 2021
Later among the works it cites.
Stable neural ode with lyapunov-stable equilibrium points for defending against adversarial attacks
Kang, Q., Song, Y., Ding, Q., and Tay, W. P · 2021
Later among the works it cites.
Diffusionclip: Text-guided image manipulation using diffusion models
Kim, G. and Ye, J. C · 2021
Later among the works it cites.
Variational diffusion models
Kingma, D. P., Salimans, T., Poole, B., and Ho, J · 2021
Later among the works it cites.
Perceptual adversarial robustness: Defense against unseen threat models
Laidlaw, C., Singla, S., and Feizi, S · 2021
Later among the works it cites.
Sdedit: Image synthesis and editing with stochastic differential equations, 2021
Meng, C., Song, Y., Song, J., Wu, J., Zhu, J.-Y., and Ermon, S · 2021
Later among the works it cites.
Glide: Towards photorealistic image generation and editing with text-guided diffusion models
Nichol, A., Dhariwal, P., Ramesh, A., Shyam, P., Mishkin, P., McGrew, B., Sutskever, I., and Chen, M · 2021
Later among the works it cites.
Fixing data augmentation to improve adversarial robustness
Rebuffi, S.-A., Gowal, S., Calian, D. A., Stimberg, F., Wiles, O., and Mann, T · 2021
Later among the works it cites.
Encoding in style: a stylegan encoder for image-to-image translation
Richardson, E., Alaluf, Y., Patashnik, O., Nitzan, Y., Azar, Y., Shapiro, S., and Cohen-Or, D · 2021
Later among the works it cites.
Palette: Image-to-image diffusion models
Saharia, C., Chan, W., Chang, H., Lee, C. A., Ho, J., Salimans, T., Fleet, D. J., and Norouzi, M · 2021
Later among the works it cites.
Robust learning meets generative models: Can proxy distributions improve adversarial robustness?
Sehwag, V., Mahloujifar, S., Handina, T., Dai, S., Xiang, C., Chiang, M., and Mittal, P · 2021
Later among the works it cites.
Online adversarial purification based on self-supervised learning
Shi, C., Holtz, C., and Mishne, G · 2021
Later among the works it cites.
Training data-efficient image transformers & distillation through attention
Touvron, H., Cord, M., Douze, M., Massa, F., Sablayrolles, A., and Jegou, H · 2021
Later among the works it cites.
Score-based generative modeling in latent space
Vahdat, A., Kreis, K., and Kautz, J · 2021
Later among the works it cites.
Adversarial purification with score-based generative models
Yoon, J., Hwang, S. J., and Lee, J · 2021
Later among the works it cites.
Evaluating the adversarial robustness of adaptive test-time defenses
Croce, F., Gowal, S., Brunner, T., Shelhamer, E., Hein, M., and Cemgil, T · 2022
Closest in time.