Fetching the paper…
Reading the bibliography…
Recently, there is an emerging interest in adversarially training a classifier with a rejection option (also known as a selective classifier) for boosting adversarial robustness.
Playing it safe: Adversarial robustness with an abstain option
Laidlaw, C. and Feizi, S · 1911
Earlier work this paper cites.
Handwritten digit recognition with a back-propagation network
LeCun, Y., Boser, B. E., Denker, J. S., Henderson, D., Howard, R. E., Hubbard, W. E., and Jackel, L. D · 1989
Earlier work this paper cites.
The MNIST database of handwritten digits
LeCun, Y · 1998
Earlier work this paper cites.
Growing a multi-class classifier with a reject option
Tax, D. M. J. and Duin, R. P. W · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A., Hinton, G., et al · 2009
Earlier work this paper cites.
Robustbench: a standardized adversarial robustness benchmark
Croce, F., Andriushchenko, M., Sehwag, V., Flammarion, N., Chiang, M., Mittal, P., and Hein, M · 2010
Earlier work this paper cites.
ATRO: adversarial training with a rejection option
Kato, M., Cui, Z., and Fukuhara, Y · 2010
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., and Ng, A. Y · 2011
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Srndic, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., and Fergus, R · 2014
Earlier work this paper cites.
Autonomous vehicles: human factors issues and future research
Cunningham, M. and Regan, M. A · 2015
Earlier work this paper cites.
Learning with rejection
Cortes, C., DeSalvo, G., and Mohri, M · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
For now, self-driving cars still need humans
Markoff, J · 2016
Cited alongside, same era.
Blocking transferability of adversarial examples in black-box learning systems
Hosseini, H., Chen, Y., Kannan, S., Zhang, B., and Poovendran, R · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D. A · 2018
Cited alongside, same era.
Wild patterns: Ten years after the rise of adversarial machine learning
Biggio, B. and Roli, F · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
SelectiveNet: A deep neural network with an integrated reject option
On adaptive attacks to adversarial example defenses
Tramèr, F., Carlini, N., Brendel, W., and Madry, A · 2020
Later among the works it cites.
Improving adversarial robustness requires revisiting misclassified examples
Wang, Y., Zou, D., Yi, J., Bailey, J., Ma, X., and Gu, Q · 2020
Later among the works it cites.
GAT: generative adversarial training for adversarial example detection and robust classification
Yin, X., Kolouri, S., and Rohde, G. K · 2020
Later among the works it cites.
Classification with rejection based on cost-sensitive classification
Charoenphakdee, N., Cui, Z., Zhang, Y., and Sugiyama, M · 2021
Later among the works it cites.
Perceptual adversarial robustness: Defense against unseen threat models
Laidlaw, C., Singla, S., and Feizi, S · 2021
Later among the works it cites.
Bag of tricks for adversarial training
Pang, T., Yang, X., Dong, Y., Su, H., and Zhu, J · 2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Geifman, Y. and El-Yaniv, R · 2019
Cited alongside, same era.
Scalable verified training for provably robust image classification
Gowal, S., Dvijotham, K., Stanforth, R., Bunel, R., Qin, C., Uesato, J., Arandjelovic, R., Mann, T. A., and Kohli, P · 2019
Cited alongside, same era.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 2019
Cited alongside, same era.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Croce, F. and Hein, M · 2020
Cited alongside, same era.
Beyond perturbations: Learning guarantees with arbitrary adversarial test examples
Goldwasser, S., Kalai, A. T., Kalai, Y., and Montasser, O · 2020
Cited alongside, same era.
Consistent estimators for learning to defer to an expert
Mozannar, H. and Sontag, D · 2020
Cited alongside, same era.
Confidence-calibrated adversarial training: Generalizing to unseen attacks
Stutz, D., Hein, M., and Schiele, B · 2020
Cited alongside, same era.
Later among the works it cites.
Provably robust classification of adversarial examples with detection
Sheikholeslami, F., Lotfi, A., and Kolter, J. Z · 2021
Later among the works it cites.
Robustly-reliable learners under poisoning attacks
Balcan, M.-F., Blum, A., Hanneke, S., and Sharma, D · 2022
Later among the works it cites.
Two coupled rejection metrics can tell adversarial examples apart
Pang, T., Zhang, H., He, D., Dong, Y., Su, H., Chen, W., Zhu, J., and Liu, T.-Y · 2022
Later among the works it cites.
Detecting adversarial examples is (nearly) as hard as classifying them
Tramèr, F · 2022
Later among the works it cites.
An analysis of robustness of non-lipschitz networks
Balcan, M.-F., Blum, A., Sharma, D., and Zhang, H · 2023
Closest in time.
ASPEST: bridging the gap between active learning and selective prediction
Chen, J., Yoon, J., Ebrahimi, S., Arik, S. Ö., Jha, S., and Pfister, T · 2023
Closest in time.