Fetching the paper…
Reading the bibliography…
Several existing works study either adversarial or natural distributional robustness of deep neural networks separately.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky · 2009
Earlier work this paper cites.
Caltech-UCSD Birds 200
P. Welinder, S. Branson, T. Mita, C. Wah, F. Schroff, S. Belongie, and P. Perona · 2010
Earlier work this paper cites.
Sun database: Large-scale scene recognition from abbey to zoo
J. Xiao, J. Hays, K. A. Ehinger, A. Oliva, and A. Torralba · 2010
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Causal inference by using invariant prediction: identification and confidence intervals
J. Peters, P. Buhlmann, and N. Meinshausen · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and A. Zisserman · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Improving weakly-supervised object localization by micro-annotation
A. Kolesnikov and C. H. Lampert · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
N. Papernot, P. Mcdaniel, X. Wu, S. Jha, and A. Swami · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. A. Wagner · 2017
Earlier work this paper cites.
Fair prediction with disparate impact: A study of bias in recidivism prediction instruments
A. Chouldechova · 2017
Earlier work this paper cites.
Densely connected convolutional networks
G. Huang, Z. Liu, and K. Q. Weinberger · 2017
Earlier work this paper cites.
Aggregated residual transformations for deep neural networks
S. Xie, R. B. Girshick, P. Dollár, Z. Tu, and K. He · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. A. Wagner · 2018
Earlier work this paper cites.
Recognition in terra incognita
S. Beery, G. V. Horn, and P. Perona · 2018
Earlier work this paper cites.
Gender shades: Intersectional accuracy disparities in commercial gender classification
J. Buolamwini and T. Gebru · 2018
Earlier work this paper cites.
Imagenet-trained cnns are biased towards texture; increasing shape bias improves accuracy and robustness, 2018
R. Geirhos, P. Rubisch, C. Michaelis, M. Bethge, F. A. Wichmann, and W. Brendel · 2018
Earlier work this paper cites.
Fairness without demographics in repeated loss minimization
T. B. Hashimoto, M. Srivastava, H. Namkoong, and P. Liang · 2018
Earlier work this paper cites.
Does distributionally robust supervised learning give robust classifiers?
W. Hu, G. Niu, I. Sato, and M. Sugiyama · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Earlier work this paper cites.
Learning to reweight examples for robust deep learning
M. Ren, W. Zeng, B. Yang, and R. Urtasun · 2018
Earlier work this paper cites.
A. Rosenfeld, R. S. Zemel, and J. K. Tsotsos · 2018
Earlier work this paper cites.
Mobilenetv2: Inverted residuals and linear bottlenecks
M. Sandler, A. G. Howard, M. Zhu, A. Zhmoginov, and L.-C. Chen · 2018
Earlier work this paper cites.
Variable generalization performance of a deep learning model to detect pneumonia in chest radiographs: A cross-sectional study
J. R. Zech, M. A. Badgeley, M. Liu, A. B. Costa, J. J. Titano, and E. K. Oermann · 2018
Cited alongside, same era.
Shufflenet: An extremely efficient convolutional neural network for mobile devices
X. Zhang, X. Zhou, M. Lin, and J. Sun · 2018
Cited alongside, same era.
Strike (with) a pose: Neural networks are easily fooled by strange poses of familiar objects
M. A. Alcorn, Q. Li, Z. Gong, C. Wang, L. Mai, W.-S. Ku, and A. M. Nguyen · 2019
Cited alongside, same era.
Objectnet: A large-scale bias-controlled dataset for pushing the limits of object recognition models
A. Barbu, D. Mayo, J. Alverio, W. Luo, C. Wang, D. Gutfreund, J. B. Tenenbaum, and B. Katz · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
J. M. Cohen, E. Rosenfeld, and J. Z. Kolter · 2019
Cited alongside, same era.
Fast is better than free: Revisiting adversarial training
E. Wong, L. Rice, and J. Z. Kolter · 2020
Later among the works it cites.
A causal view on robustness of neural networks
C. H. Zhang, K. Zhang, and Y. Li · 2020
Later among the works it cites.
Linear unit-tests for invariance discovery
B. Aubin, A. Slowik, M. Arjovsky, L. Bottou, and D. Lopez-Paz · 2021
Later among the works it cites.
Ai for radiographic covid-19 detection selects shortcuts over signal
A. J. DeGrave, J. D. Janizek, and S.-I. Lee · 2021
Later among the works it cites.
On robustness and transferability of convolutional neural networks
J. Djolonga, J. Yung, M. Tschannen, R. Romijnders, L. Beyer, A. Kolesnikov, J. Puigcerver, M. Minderer, A. D’Amour, D. I. Moldovan, S. Gelly, N. Houlsby, X. Zhai, and M. Lucic · 2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Exploring the landscape of spatial robustness
L. Engstrom, B. Tran, D. Tsipras, L. Schmidt, and A. Madry · 2019
Cited alongside, same era.
Benchmarking neural network robustness to common corruptions and perturbations
D. Hendrycks and T. G. Dietterich · 2019
Cited alongside, same era.
Adversarial examples are not bugs, they are features
A. Ilyas, S. Santurkar, D. Tsipras, L. Engstrom, B. Tran, and A. Madry · 2019
Cited alongside, same era.
Functional adversarial attacks
C. Laidlaw and S. Feizi · 2019
Cited alongside, same era.
S. Sagawa, P. W. Koh, T. B. Hashimoto, and P. Liang · 2019
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
H. Salman, G. Yang, J. Li, P. Zhang, H. Zhang, I. P. Razenshteyn, and S. Bubeck · 2019
Cited alongside, same era.
Image synthesis with a single (robust) classifier
S. Santurkar, A. Ilyas, D. Tsipras, L. Engstrom, B. Tran, and A. Madry · 2019
Cited alongside, same era.
Later among the works it cites.
The many faces of robustness: A critical analysis of out-of-distribution generalization
D. Hendrycks, S. Basart, N. Mu, S. Kadavath, F. Wang, E. Dorundo, R. Desai, T. L. Zhu, S. Parajuli, M. Guo, D. X. Song, J. Steinhardt, and J. Gilmer · 2021
Later among the works it cites.
Focus: Familiar objects in common and uncommon settings
P. Kattakinda and S. Feizi · 2021
Later among the works it cites.
Removing spurious features can hurt accuracy and affect groups disproportionately
F. Khani and P. Liang · 2021
Later among the works it cites.
Wilds: A benchmark of in-the-wild distribution shifts
P. W. Koh, S. Sagawa, H. Marklund, S. M. Xie, M. Zhang, A. Balsubramani, W. Hu, M. Yasunaga, R. L. Phillips, S. Beery, J. Leskovec, A. Kundaje, E. Pierson, S. Levine, C. Finn, and P. Liang · 2021
Later among the works it cites.
Out-of-distribution generalization via risk extrapolation (rex)
D. Krueger, E. Caballero, J.-H. Jacobsen, A. Zhang, J. Binas, R. L. Priol, and A. C. Courville · 2021
Later among the works it cites.
Perceptual adversarial robustness: Defense against unseen threat models
C. Laidlaw, S. Singla, and S. Feizi · 2021
Later among the works it cites.
Improved, deterministic smoothing for l1 certified robustness
A. Levine and S. Feizi · 2021
Later among the works it cites.
Just train twice: Improving group robustness without training group information
E. Z. Liu, B. Haghgoo, A. S. Chen, A. Raghunathan, P. W. Koh, S. Sagawa, P. Liang, and C. Finn · 2021
Later among the works it cites.
Sample efficient detection and classification of adversarial attacks via self-supervised embeddings
M. Moayeri and S. Feizi · 2021
Later among the works it cites.
Model-based domain generalization
A. Robey, G. J. Pappas, and H. Hassani · 2021
Later among the works it cites.
Salient imagenet: How to discover spurious features in deep learning?, 2021
S. Singla and S. Feizi · 2021
Later among the works it cites.
Understanding failures of deep networks via robust feature extraction
S. Singla, B. Nushi, S. Shah, E. Kamar, and E. Horvitz · 2021
Later among the works it cites.
Leveraging sparse linear layers for debuggable deep networks
E. Wong, S. Santurkar, and A. Madry · 2021
Later among the works it cites.
Noise or signal: The role of image backgrounds in object recognition
K. Y. Xiao, L. Engstrom, A. Ilyas, and A. Madry · 2021
Later among the works it cites.
Ood-bench: Quantifying and understanding two dimensions of out-of-distribution generalization
N. Ye, K. Li, H. Bai, R. Yu, L. Hong, F. Zhou, Z. Li, and J. Zhu · 2021
Later among the works it cites.
Coping with label shift via distributionally robust optimisation
J. Zhang, A. K. Menon, A. Veit, S. Bhojanapalli, S. Kumar, and S. Sra · 2021
Later among the works it cites.
Last layer re-training is sufficient for robustness to spurious correlations, 2022
P. Kirichenko, P. Izmailov, and A. G. Wilson · 2022
Closest in time.
A comprehensive study of image classification model sensitivity to foregrounds, backgrounds, and visual attributes, 2022
M. Moayeri, P. Pope, Y. Balaji, and S. Feizi · 2022
Closest in time.
Core risk minimization using salient imagenet, 2022
S. Singla, M. Moayeri, and S. Feizi · 2022
Closest in time.
Causaladv: Adversarial robustness through the lens of causality
Y. Zhang, M. Gong, T. Liu, G. Niu, X. Tian, B. Han, B. Scholkopf, and K. Zhung · 2022
Closest in time.