Fetching the paper…
Reading the bibliography…
Certified defenses against small-norm adversarial examples have received growing attention in recent years; though certified accuracies of state-of-the-art methods remain far below their non-robust counterparts, despite the fact that benchmark datasets have been shown to be well-separated at far larger radii than the literature generally attempts to certify.
Approximation capabilities of multilayer feedforward networks
Kurt Hornik · 1991
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Reluplex: An efficient SMT solver for verifying deep neural networks
Guy Katz, Clark W. Barrett, David L. Dill, Kyle Julian, and Mykel J. Kochenderfer · 2017
Earlier work this paper cites.
Understanding deep learning requires rethinking generalization
Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals · 2017
Earlier work this paper cites.
On the optimization of deep networks: Implicit acceleration by overparameterization
Sanjeev Arora, Nadav Cohen, and Elad Hazan · 2018
Earlier work this paper cites.
Limitations of the lipschitz constant as a defense against adversarial examples
Todd Huster, Cho-Yu Jason Chiang, and Ritu Chadha · 2018
Earlier work this paper cites.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Certifiable distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2018
Earlier work this paper cites.
Towards fast computation of certified robustness for ReLU networks
Lily Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Luca Daniel, Duane Boning, and Inderjit Dhillon · 2018
Earlier work this paper cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Earlier work this paper cites.
Scaling provable adversarial defenses
Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J. Zico Kolter · 2018
Cited alongside, same era.
Efficient neural network robustness certification with general activation functions
Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel · 2018
Cited alongside, same era.
Sorting out Lipschitz function approximation
Cem Anil, James Lucas, and Roger Gross · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Cited alongside, same era.
Provable robustness of ReLU networks via maximization of linear regions
Francesco Croce, Maksym Andriushchenko, and Matthias Hein · 2019
Cited alongside, same era.
Gradient descent provably optimizes over-parameterized neural networks
Simon S. Du, Xiyu Zhai, Barnabás Póczos, and Aarti Singh · 2019
Lipschitz-certifiable training with a tight outer bound
Sungyoon Lee, Jaewook Lee, and Saerom Park · 2020
Later among the works it cites.
Overfitting, robustness, and malicious algorithms: A study of potential causes of privacy risk in machine learning
Samuel Yeom, Irene Giacomelli, Alan Menaged, Matt Fredrikson, and Somesh Jha · 2020
Later among the works it cites.
A universal law of robustness via isoperimetry
Sebastien Bubeck and Mark Sellke · 2021
Later among the works it cites.
Fast geometric projections for local robustness certification
Aymeric Fromherz, Klas Leino, Matt Fredrikson, Bryan Parno, and Corina Păsăreanu · 2021
Later among the works it cites.
Training certifiably robust neural networks with efficient local lipschitz bounds
Yujia Huang, Huan Zhang, Yuanyuan Shi, J. Zico Kolter, and Anima Anandkumar · 2021
Later among the works it cites.
Relaxing local robustness
Klas Leino and Matt Fredrikson · 2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Provable certificates for adversarial examples: Fitting a ball in the union of polytopes
Matt Jordan, Justin Lewis, and Alexandros G. Dimakis · 2019
Cited alongside, same era.
Preventing gradient attenuation in lipschitz constrained convolutional networks
Qiyang Li, Saminul Haque, Cem Anil, James Lucas, Roger B Grosse, and Joern-Henrik Jacobsen · 2019
Cited alongside, same era.
A convex relaxation barrier to tight robustness verification of neural networks
Hadi Salman, Greg Yang, Huan Zhang, Cho-Jui Hsieh, and Pengchuan Zhang · 2019
Cited alongside, same era.
Evaluating robustness of neural networks with mixed integer programming
Vincent Tjeng, Kai Y. Xiao, and Russ Tedrake · 2019
Cited alongside, same era.
Training for faster adversarial robustness verification via inducing relu stability
Kai Xiao, Vincent Tjeng, Nur Muhammad Shafiullah, and Aleksander Madry · 2019
Cited alongside, same era.
Randomized smoothing of all shapes and sizes
Greg Yang, Tony Duan, J. Edward Hu, Hadi Salman, Ilya P. Razenshteyn, and Jerry Li
Cited in the paper.
Later among the works it cites.
Globally-robust neural networks
Klas Leino, Zifan Wang, and Matt Fredrikson · 2021
Later among the works it cites.
Orthogonalizing convolutional layers with the cayley transform
Asher Trockman and J Zico Kolter · 2021
Later among the works it cites.
Overparameterized (robust) models from computational constraints, 2022
Sanjam Garg, Somesh Jha, Saeed Mahloujifar, Mohammad Mahmoody, and Mingyuan Wang · 2022
Later among the works it cites.
Improved deterministic l2 robustness on cifar-10 and cifar-100
Sahil Singla, Surbhi Singla, and Soheil Feizi · 2022
Later among the works it cites.