Fetching the paper…
Reading the bibliography…
Randomized smoothing is sound when using infinite precision.
Evading the drift in floating-point addition
John F. Reiser and Donald E. Knuth · 1975
Earlier work this paper cites.
Theory and application of trapdoor functions
Andrew C. Yao · 1982
Earlier work this paper cites.
The discrete gaussian for differential privacy, 2020
Clément L. Canonne, Gautam Kamath, and Thomas Steinke · 2004
Earlier work this paper cites.
IEEE Std 754-2008 , Aug 2008
IEEE standard for floating-point arithmetic · 2008
Earlier work this paper cites.
On significance of the least significant bits for differential privacy
Ilya Mironov · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
M. Hein and M. Andriushchenko · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Guy Katz, Clark Barrett, David L Dill, Kyle Julian, and Mykel J Kochenderfer · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Earlier work this paper cites.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Valdu · 2018
Earlier work this paper cites.
Scaling provable adversarial defenses
Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J. Zico Kolter · 2018
Earlier work this paper cites.
On evaluating adversarial robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin · 2019
Earlier work this paper cites.
Certified adversarial robustness via randomized smoothing
Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter · 2019
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2019
Cited alongside, same era.
Preventing gradient attenuation in lipschitz constrained convolutional networks
Qiyang Li, Saminul Haque, Cem Anil, James Lucas, Roger B Grosse, and Jörn-Henrik Jacobsen · 2019
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
Hadi Salman, Jerry Li, Ilya Razenshteyn, Pengchuan Zhang, Huan Zhang, Sebastien Bubeck, and Greg Yang · 2019
Cited alongside, same era.
An abstract domain for certifying neural networks
Gagandeep Singh, Timon Gehr, Markus Püschel, and Martin Vechev · 2019
Cited alongside, same era.
Wasserstein adversarial examples via projected sinkhorn iterations
Regulation for laying down harmonised rules on AI
European Commission · 2021
Later among the works it cites.
Exploiting verified neural networks via floating point numerical error
Kai Jia and Martin Rinard · 2021
Later among the works it cites.
Are we there yet? timing and floating-point attacks on differential privacy systems
Jiankai Jin, Eleanor McMurtry, Benjamin IP Rubinstein, and Olga Ohrimenko · 2021
Later among the works it cites.
Perceptual adversarial robustness: Defense against unseen threat models
Cassidy Laidlaw, Sahil Singla, and Soheil Feizi · 2021
Later among the works it cites.
Globally-robust neural networks
Klas Leino, Zifan Wang, and Matt Fredrikson · 2021
Later among the works it cites.
Improved, deterministic smoothing for L 1 L_{1} certified robustness
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Eric Wong, Frank Schmidt, and Zico Kolter · 2019
Cited alongside, same era.
Fooling a complete neural network verifier
Dániel Zombori, Balázs Bánhelyi, Tibor Csendes, István Megyeri, and Márk Jelasity · 2019
Cited alongside, same era.
Adversarial training and provable defenses: Bridging the gap
Mislav Balunovic and Martin Vechev · 2020
Cited alongside, same era.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Cited alongside, same era.
A programming framework for opendp
Marco Gaboardi, Michael Hay, and Salil Vadhan · 2020
Cited alongside, same era.
Wasserstein smoothing: Certified robustness against wasserstein adversarial attacks
Alexander Levine and Soheil Feizi · 2020
Cited alongside, same era.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Cited alongside, same era.
Alexander J Levine and Soheil Feizi · 2021
Later among the works it cites.
Integer-arithmetic-only certified robustness for quantized neural networks
Haowen Lin, Jian Lou, Li Xiong, and Cyrus Shahabi · 2021
Later among the works it cites.
Orthogonalizing convolutional layers with the cayley transform
Asher Trockman and J Zico Kolter · 2021
Later among the works it cites.
Sílvia Casacuberta, Michael Shoemate, Salil Vadhan, and Connor Wagaman · 2022
Closest in time.
Getting a-round guarantees: Floating-point attacks on certified robustness
Jiankai Jin, Olga Ohrimenko, and Benjamin IP Rubinstein · 2022
Closest in time.
Improved deterministic l 2 l_{2} robustness on CIFAR-10 and CIFAR-100
Sahil Singla, Surbhi Singla, and Soheil Feizi · 2022
Closest in time.
Provably adversarially robust nearest prototype classifiers
Václav Voráček and Matthias Hein · 2022
Closest in time.
Boosting the certified robustness of l-infinity distance nets
Bohang Zhang, Du Jiang, Di He, and Liwei Wang · 2022
Closest in time.