Fetching the paper…
Reading the bibliography…
Adversarial training (AT) is the de facto method for building robust neural networks, but it can be computationally expensive.
Discrete Cosine Transform
N. Ahmed, T. Natarajan, and K. R. Rao · 1974
Earlier work this paper cites.
The expressive power of voting polynomials
James Aspnes, Richard Beigel, Merrick Furst, and Steven Rudich · 1994
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y Ng · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Identity mappings in deep residual networks
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Wide residual networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
A closer look at memorization in deep networks
Devansh Arpit, Stanisław Jastrzębski, Nicolas Ballas, David Krueger, Emmanuel Bengio, Maxinder S Kanwal, Tegan Maharaj, Asja Fischer, Aaron Courville, Yoshua Bengio, and Simon Lacoste-Julien · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Empirical study of the topology and geometry of deep networks
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, and Stefano Soatto · 2018
Earlier work this paper cites.
With friends like these, who needs adversaries?
Saumya Jetley, Nicholas Lord, and Philip Torr · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel · 2018
Cited alongside, same era.
Towards fast computation of certified robustness for relu networks
Lily Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane Boning, and Inderjit Dhillon · 2018
Cited alongside, same era.
Adversarial examples are not bugs, they are features
Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Cited alongside, same era.
Robustness via curvature regularization, and vice versa
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Jonathan Uesato, and Pascal Frossard · 2019
Cited alongside, same era.
Adversarial robustness through local linearization
Chongli Qin, James Martens, Sven Gowal, Dilip Krishnan, Krishnamurthy Dvijotham, Alhussein Fawzi, Soham De, Robert Stanforth, and Pushmeet Kohli · 2019
Cited alongside, same era.
Adversarial training for free!
The pitfalls of simplicity bias in neural networks
Harshay Shah, Kaustav Tamuly, Aditi Raghunathan, Prateek Jain, and Praneeth Netrapalli · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Later among the works it cites.
Kendra Albert, Maggie K. Delano, Bogdan Kulynych, and Ram Shankar Siva Kumar · 2021
Later among the works it cites.
Zerograd: Mitigating and explaining catastrophic overfitting in FGSM adversarial training
Zeinab Golgooni, Mehrdad Saberi, Masih Eskandar, and Mohammad Hossein Rohban · 2021
Later among the works it cites.
Understanding catastrophic overfitting in adversarial training
Peilin Kang and Seyed-Mohsen Moosavi-Dezfooli · 2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Ali Shafahi, Mahyar Najibi, Mohammad Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein · 2019
Cited alongside, same era.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan · 2019
Cited alongside, same era.
Making convolutionall neural networks shift-invariant again
Richard Zhang · 2019
Cited alongside, same era.
Politics of adversarial machine learning
Kendra Albert, Jonathon Penney, Bruce Schneier, and Ram Shankar Siva Kumar · 2020
Cited alongside, same era.
Understanding and improving fast adversarial training
Maksym Andriushchenko and Nicolas Flammarion · 2020
Cited alongside, same era.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Cited alongside, same era.
Towards understanding fast adversarial training
Bai Li, Shiqi Wang, Suman Jana, and Lawrence Carin · 2020
Cited alongside, same era.
Later among the works it cites.
Understanding catastrophic overfitting in single-step adversarial training
Hoki Kim, Woojin Lee, and Jaewook Lee · 2021
Later among the works it cites.
Optimism in the face of adversity: Understanding and improving deep learning through adversarial robustness
Guillermo Ortiz-Jiménez, Apostolos Modas, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2021
Later among the works it cites.
How benign is benign overfitting ?
Amartya Sanyal, Puneet K. Dokania, Varun Kanade, and Philip Torr · 2021
Later among the works it cites.
Make some noise: Reliable and efficient single-step adversarial training
Pau de Jorge, Adel Bibi, Riccardo Volpi, Amartya Sanyal, Philip H. S. Torr, Grégory Rogez, and Puneet K. Dokania · 2022
Closest in time.
FrequencyLowCut Pooling - Plug & Play against Catastrophic Overfitting
Julia Grabinski, Steffen Jung, Janis Keuper, and Margret Keuper · 2022
Closest in time.
On the effectiveness of adversarial training against common corruptions
Klim Kireev, Maksym Andriushchenko, and Nicolas Flammarion · 2022
Closest in time.
How robust are pre-trained models to distribution shift?
Yuge Shi, Imant Daunhawer, Julia E Vogt, Philip HS Torr, and Amartya Sanyal · 2022
Closest in time.