Fetching the paper…
Reading the bibliography…
Randomized smoothing has achieved great success for certified robustness against adversarial perturbations.
Ix. on the problem of the most efficient tests of statistical hypotheses
Neyman, J. and Pearson, E. S · 1933
Earlier work this paper cites.
Differential privacy
Dwork, C · 2006
Earlier work this paper cites.
Differential privacy: A survey of results
Dwork, C · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A., Hinton, G., et al · 2009
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., and Fei-Fei, L · 2015
Earlier work this paper cites.
Empirical evaluation of rectified activations in convolutional network
Xu, B., Wang, N., Chen, T., and Li, M · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Provably minimally-distorted adversarial examples
Carlini, N., Katz, G., Barrett, C., and Dill, D. L · 2017
Earlier work this paper cites.
Maximum resilience of artificial neural networks
Cheng, C.-H., Nührenberg, G., and Ruess, H · 2017
Earlier work this paper cites.
Parseval networks: Improving robustness to adversarial examples
Cissé, M., Bojanowski, P., Grave, E., Dauphin, Y. N., and Usunier, N · 2017
Earlier work this paper cites.
Formal verification of piece-wise linear feed-forward neural networks
Ehlers, R · 2017
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
Hein, M. and Andriushchenko, M · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Katz, G., Barrett, C., Dill, D. L., Julian, K., and Kochenderfer, M. J · 2017
Earlier work this paper cites.
An approach to reachability analysis for feed-forward relu neural networks
Lomuscio, A. and Maganti, L · 2017
Earlier work this paper cites.
Safetynet: Detecting and rejecting adversarial examples robustly
Lu, J., Issaranon, T., and Forsyth, D · 2017
Earlier work this paper cites.
On detecting adversarial perturbations
Metzen, J. H., Genewein, T., Fischer, V., and Bischoff, B · 2017
Earlier work this paper cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Xu, W., Evans, D., and Qi, Y · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Cited alongside, same era.
A unified view of piecewise linear neural network verification
Bunel, R. R., Turkaslan, I., Torr, P. H., Kohli, P., and Mudigonda, P. K · 2018
Cited alongside, same era.
A dual approach to scalable verification of deep networks
Dvijotham, K., Stanforth, R., Gowal, S., Mann, T. A., and Kohli, P · 2018
Cited alongside, same era.
Deep neural networks and mixed integer linear optimization
Fischetti, M. and Jo, J · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
Gowal, S., Dvijotham, K., Stanforth, R., Bunel, R., Qin, C., Uesato, J., Arandjelovic, R., Mann, T. A., and Kohli, P · 2018
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Later among the works it cites.
Efficient decision-based black-box adversarial attacks on face recognition
Dong, Y., Su, H., Wu, B., Li, Z., Liu, W., Zhang, T., and Zhu, J · 2019
Later among the works it cites.
Certified robustness to adversarial examples with differential privacy
Lecuyer, M., Atlidakis, V., Geambasu, R., Hsu, D., and Jana, S · 2019
Later among the works it cites.
Tight certificates of adversarial robustness for randomly smoothed classifiers
Lee, G., Yuan, Y., Chang, S., and Jaakkola, T. S · 2019
Later among the works it cites.
Feature distillation: Dnn-oriented jpeg compression against adversarial examples
Liu, Z., Liu, Q., Liu, T., Xu, N., Lin, X., Wang, Y., and Wen, W · 2019
Later among the works it cites.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T · 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A simple unified framework for detecting out-of-distribution samples and adversarial attacks
Lee, K., Lee, K., Lee, H., and Shin, J · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Mirman, M., Gehr, T., and Vechev, M · 2018
Cited alongside, same era.
Certified defenses against adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Cited alongside, same era.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Cited alongside, same era.
Fast and effective robustness certification
Singh, G., Gehr, T., Mirman, M., Püschel, M., and Vechev, M · 2018
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Tramer, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2018
Cited alongside, same era.
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z · 2019
Later among the works it cites.
Data dependent randomized smoothing
Alfarra, M., Bibi, A., Torr, P. H., and Ghanem, B · 2020
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Croce, F. and Hein, M · 2020
Later among the works it cites.
Lessons learned from the chameleon testbed
Keahey, K., Anderson, J., Zhen, Z., Riteau, P., Ruth, P., Stanzione, D., Cevik, M., Colleran, J., Gunawi, H. S., Hammock, C., Mambretti, J., Barnes, A., Halbach, F., Rocha, A., and Stubbs, J · 2020
Later among the works it cites.
Towards robust lidar-based perception in autonomous driving: General black-box adversarial sensor attack and countermeasures
Sun, J., Cao, Y., Chen, Q. A., and Mao, Z. M · 2020
Later among the works it cites.
$\ell_1$ adversarial robustness certificates: a randomized smoothing approach, 2020
Teng, J., Lee, G.-H., and Yuan, Y · 2020
Later among the works it cites.
Randomized smoothing of all shapes and sizes
Yang, G., Duan, T., Hu, J. E., Salman, H., Razenshteyn, I., and Li, J · 2020
Later among the works it cites.
Black-box certification with randomized smoothing: A functional optimization based framework
Zhang, D., Ye, M., Gong, C., Zhu, Z., and Liu, Q · 2020
Later among the works it cites.
Ancer: Anisotropic certification via sample-wise volume maximization
Eiras, F., Alfarra, M., Kumar, M. P., Torr, P. H., Dokania, P. K., Ghanem, B., and Bibi, A · 2021
Later among the works it cites.
Regularisation of neural networks by enforcing lipschitz continuity
Gouk, H., Frank, E., Pfahringer, B., and Cree, M. J · 2021
Later among the works it cites.
Understanding adversarial attacks on deep learning based medical image analysis systems
Ma, X., Niu, Y., Gu, L., Wang, Y., Zhao, Y., Bailey, J., and Lu, F · 2021
Later among the works it cites.
Adversarial robustness through disentangled representations
Yang, S., Guo, T., Wang, Y., and Xu, C · 2021
Later among the works it cites.