Fetching the paper…
Reading the bibliography…
One prominent approach toward resolving the adversarial vulnerability of deep neural networks is the two-player zero-sum paradigm of adversarial training, in which predictors are trained against adversarially chosen perturbations of data.
Convexity, classification, and risk bounds
Peter L Bartlett, Michael I Jordan, and Jon D McAuliffe · 2006
Earlier work this paper cites.
Cifar datasets (canadian institute for advanced research)
Alex Krizhevsky, Vinod Nair, and Geoffrey Hinton · 2009
Earlier work this paper cites.
Robustbench: a standardized adversarial robustness benchmark
Francesco Croce, Maksym Andriushchenko, Vikash Sehwag, Edoardo Debenedetti, Nicolas Flammarion, Mung Chiang, Prateek Mittal, and Matthias Hein · 2010
Earlier work this paper cites.
Practical bilevel optimization: algorithms and applications , volume 30
Jonathan F Bard · 2013
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Srndic, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Dumitru Erhan Joan Bruna, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P Kingma and Jimmy Ba · 2014
Earlier work this paper cites.
Understanding machine learning: From theory to algorithms
Shai Shalev-Shwartz and Shai Ben-David · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Learning with a strong adversary
Ruitong Huang, Bing Xu, Dale Schuurmans, and Csaba Szepesvari · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Tighter bounds lead to improved classifiers
Nicolas Le Roux · 2017
Earlier work this paper cites.
H. Kannan, A. Kurakin, and I. Goodfellow · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Logit pairing methods can fool gradient-based attacks
Marius Mosbach, Maksym Andriushchenko, Thomas Trost, Matthias Hein, and Dietrich Klakow · 2018
Earlier work this paper cites.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry · 2018
Earlier work this paper cites.
Martin Arjovsky, Léon Bottou, Ishaan Gulrajani, and David Lopez-Paz · 2019
Earlier work this paper cites.
An alternative surrogate loss for pgd-based adversarial testing
Sven Gowal, Jonathan Uesato, Chongli Qin, Po-Sen Huang, Timothy Mann, and Pushmeet Kohli · 2019
Cited alongside, same era.
Benchmarking neural network robustness to common corruptions and perturbations
Dan Hendrycks and Thomas Dietterich · 2019
Cited alongside, same era.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Cited alongside, same era.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P. Xing, Laurent El Ghaoui, and Michael I. Jordan · 2019
Cited alongside, same era.
Calibrated surrogate losses for adversarially robust classification
Han Bao, Clay Scott, and Masashi Sugiyama · 2020
Cited alongside, same era.
Improving robustness using generated data
Sven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg, Dan Andrei Calian, and Timothy Mann · 2021
Later among the works it cites.
Wilds: A benchmark of in-the-wild distribution shifts
Pang Wei Koh, Shiori Sagawa, Henrik Marklund, Sang Michael Xie, Marvin Zhang, Akshay Balsubramani, Weihua Hu, Michihiro Yasunaga, Richard Lanas Phillips, Irena Gao, et al · 2021
Later among the works it cites.
Fixing data augmentation to improve adversarial robustness
Sylvestre-Alvise Rebuffi, Sven Gowal, Dan A. Calian, Florian Stimberg, Olivia Wiles, and Timothy Mann · 2021
Later among the works it cites.
Model-based domain generalization
Alexander Robey, George J Pappas, and Hamed Hassani · 2021
Later among the works it cites.
Breeds: Benchmarks for subpopulation shift
Shibani Santurkar, Dimitris Tsipras, and Aleksander Madry · 2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Alvin Chan, Yi Tay, Yew Soon Ong, and Jie Fu · 2020
Cited alongside, same era.
More data can expand the generalization gap between adversarially robust and standard models
Lin Chen, Yifei Min, Mingrui Zhang, and Amin Karbasi · 2020
Cited alongside, same era.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Cited alongside, same era.
Provable tradeoffs in adversarially robust classification
Edgar Dobriban, Hamed Hassani, David Hong, and Alexander Robey · 2020
Cited alongside, same era.
Perceptual adversarial robustness: Defense against unseen threat models
Cassidy Laidlaw, Sahil Singla, and Soheil Feizi · 2020
Cited alongside, same era.
Adversarial vertex mixup: Toward better adversarially robust generalization
Saehyung Lee, Hyungyu Lee, and Sungroh Yoon · 2020
Cited alongside, same era.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and J Zico Kolter · 2020
Cited alongside, same era.
Xu Sun, Zhiyuan Zhang, Xuancheng Ren, Ruixuan Luo, and Liangyou Li · 2021
Later among the works it cites.
Noise or signal: The role of image backgrounds in object recognition
Kai Xiao, Logan Engstrom, Andrew Ilyas, and Aleksander Madry · 2021
Later among the works it cites.
Exploring memorization in adversarial training
Yinpeng Dong, Ke Xu, Xiao Yang, Tianyu Pang, Zhijie Deng, Hang Su, and Jun Zhu · 2022
Later among the works it cites.
Revisiting Residual Networks for Adversarial Robustness: An Architectural Perspective
Shihua Huang, Zhichao Lu, Kalyanmoy Deb, and Vishnu Naresh Boddeti · 2022
Later among the works it cites.
Towards consistency in adversarial classification
Laurent Meunier, Raphaël Ettedgui, Rafael Pinot, Yann Chevaleyre, and Jamal Atif · 2022
Later among the works it cites.
Robustness and accuracy could be reconcilable by (Proper) definition
Tianyu Pang, Min Lin, Xiao Yang, Jun Zhu, and Shuicheng Yan · 2022
Later among the works it cites.
Understanding robust overfitting of adversarial training and beyond
Chaojian Yu, Bo Han, Li Shen, Jun Yu, Chen Gong, Mingming Gong, and Tongliang Liu · 2022
Later among the works it cites.
Revisiting and advancing fast adversarial training through the lens of bi-level optimization
Yihua Zhang, Guanhua Zhang, Prashant Khanduri, Mingyi Hong, Shiyu Chang, and Sijia Liu · 2022
Later among the works it cites.
The adversarial consistency of surrogate risks for binary classification
Natalie Frank and Jonathan Niles-Weed · 2023
Closest in time.
Finding actual descent directions for adversarial training
Fabian Latorre, Igor Krawczuk, Leello Tadesse Dadi, Thomas Pethick, and Volkan Cevher · 2023
Closest in time.
Better diffusion models further improve adversarial training
Zekai Wang, Tianyu Pang, Chao Du, Min Lin, Weiwei Liu, and Shuicheng Yan · 2023
Closest in time.
Robustness guarantees for adversarially trained neural networks
Poorya Mianjy and Raman Arora · 2024
Closest in time.