Fetching the paper…
Reading the bibliography…
Existing works have made great progress in improving adversarial robustness, but typically test their method only on data from the same distribution as the training data, i.e.
80 Million Tiny Images: A Large Data Set for Nonparametric Object and Scene Recognition
Torralba, A., Fergus, R., and Freeman, W. T · 2008
Earlier work this paper cites.
Very Deep Convolutional Networks for Large-Scale Image Recognition
Simonyan, K. and Zisserman, A · 2015
Earlier work this paper cites.
Going deeper with convolutions
Szegedy, C., Wei Liu, Yangqing Jia, Sermanet, P., Reed, S., Anguelov, D., Erhan, D., Vanhoucke, V., and Rabinovich, A · 2015
Earlier work this paper cites.
Deep Residual Learning for Image Recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Rethinking the Inception Architecture for Computer Vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Earlier work this paper cites.
Densely Connected Convolutional Networks
Huang, G., Liu, Z., Van Der Maaten, L., and Weinberger, K. Q · 2017
Earlier work this paper cites.
Aggregated Residual Transformations for Deep Neural Networks
Xie, S., Girshick, R., Dollar, P., Tu, Z., and He, K · 2017
Earlier work this paper cites.
Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Earlier work this paper cites.
CINIC-10 is not ImageNet or CIFAR-10, October 2018
Darlow, L. N., Crowley, E. J., Antoniou, A., and Storkey, A. J · 2018
Earlier work this paper cites.
Countering Adversarial Images using Input Transformations
Guo, C., Rana, M., Cisse, M., and Maaten, L. v. d · 2018
Earlier work this paper cites.
Squeeze-and-Excitation Networks
Hu, J., Shen, L., and Sun, G · 2018
Earlier work this paper cites.
Towards Deep Learning Models Resistant to Adversarial Attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Earlier work this paper cites.
Do CIFAR-10 Classifiers Generalize to CIFAR-10?
Recht, B., Roelofs, R., Schmidt, L., and Shankar, V · 2018
Earlier work this paper cites.
Defense-GAN: Protecting Classifiers Against Adversarial Attacks Using Generative Models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Earlier work this paper cites.
Mobilenetv2: Inverted residuals and linear bottlenecks
Sandler, M., Howard, A. G., Zhu, M., Zhmoginov, A., and Chen, L.-C · 2018
Earlier work this paper cites.
Spatially Transformed Adversarial Examples
Xiao, C., Zhu, J.-Y., Li, B., He, W., Liu, M., and Song, D · 2018
Earlier work this paper cites.
Deep layer aggregation
Yu, F., Wang, D., Shelhamer, E., and Darrell, T · 2018
Earlier work this paper cites.
The unreasonable effectiveness of deep features as a perceptual metric
Zhang, R., Isola, P., Efros, A. A., Shechtman, E., and Wang, O · 2018
Earlier work this paper cites.
ObjectNet: A large-scale bias-controlled dataset for pushing the limits of object recognition models
Barbu, A., Mayo, D., Alverio, J., Luo, W., Wang, C., Gutfreund, D., Tenenbaum, J., and Katz, B · 2019
Earlier work this paper cites.
Unlabeled Data Improves Adversarial Robustness
Carmon, Y., Raghunathan, A., Schmidt, L., Duchi, J. C., and Liang, P. S · 2019
Earlier work this paper cites.
AutoAugment: Learning Augmentation Strategies From Data
Cubuk, E. D., Zoph, B., Mane, D., Vasudevan, V., and Le, Q. V · 2019
Earlier work this paper cites.
Robustness (python library), 2019
Engstrom, L., Ilyas, A., Salman, H., Santurkar, S., and Tsipras, D · 2019
Earlier work this paper cites.
ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness
Geirhos, R., Rubisch, P., Michaelis, C., Bethge, M., Wichmann, F. A., and Brendel, W · 2019
Earlier work this paper cites.
Adversarial Examples Are a Natural Consequence of Test Error in Noise
Gilmer, J., Ford, N., Carlini, N., and Cubuk, E · 2019
Earlier work this paper cites.
Benchmarking Neural Network Robustness to Common Corruptions and Perturbations
Hendrycks, D. and Dietterich, T · 2019
Earlier work this paper cites.
Functional Adversarial Attacks
Laidlaw, C. and Feizi, S · 2019
Earlier work this paper cites.
Do ImageNet Classifiers Generalize to ImageNet?
Recht, B., Roelofs, R., Schmidt, L., and Shankar, V · 2019
Earlier work this paper cites.
Decoupling Direction and Norm for Efficient Gradient-Based L2 Adversarial Attacks and Defenses
Rony, J., Hafemann, L. G., Oliveira, L. S., Ben Ayed, I., Sabourin, R., and Granger, E · 2019
Earlier work this paper cites.
Analyzing the Robustness of Open-World Machine Learning
Sehwag, V., Bhagoji, A. N., Song, L., Sitawarin, C., Cullina, D., Chiang, M., and Mittal, P · 2019
Earlier work this paper cites.
EfficientNet: Rethinking Model Scaling for Convolutional Neural Networks
Tan, M. and Le, Q · 2019
Earlier work this paper cites.
Adversarial Training and Robustness for Multiple Perturbations
Tramer, F. and Boneh, D · 2019
Earlier work this paper cites.
Robustness May Be at Odds with Accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Cited alongside, same era.
Learning Robust Global Representations by Penalizing Local Predictive Power
Wang, H., Ge, S., Lipton, Z., and Xing, E. P · 2019
Cited alongside, same era.
Theoretically Principled Trade-off between Robustness and Accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E., Ghaoui, L. E., and Jordan, M · 2019
Cited alongside, same era.
Adversarial Robustness on In- and Out-Distribution Improves Explainability
Augustin, M., Meinke, A., and Hein, M · 2020
Cited alongside, same era.
Reliable Evaluation of Adversarial Robustness with an Ensemble of Diverse Parameter-free Attacks
Croce, F. and Hein, M · 2020
Cited alongside, same era.
MMA Training: Direct Input Space Margin Maximization through Adversarial Training
Agreement-on-the-line: Predicting the performance of neural networks under distribution shift
Baek, C., Jiang, Y., Raghunathan, A., and Kolter, J. Z · 2022
Later among the works it cites.
Adversarial robustness against multiple and single l _ p l\_p -threat models via quick fine-tuning of robust classifiers
Croce, F. and Hein, M · 2022
Later among the works it cites.
Evaluating the adversarial robustness of adaptive test-time defenses
Croce, F., Gowal, S., Brunner, T., Shelhamer, E., Hein, M., and Cemgil, T · 2022
Later among the works it cites.
Formulating Robustness Against Unforeseen Attacks
Dai, S., Mahloujifar, S., and Mittal, P · 2022
Later among the works it cites.
ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial Viewpoints
Dong, Y., Ruan, S., Su, H., Kang, C., Wei, X., and Zhu, J · 2022
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Ding, G. W., Sharma, Y., Lui, K. Y. C., and Huang, R · 2020
Cited alongside, same era.
Benchmarking Adversarial Robustness on Image Classification
Dong, Y., Fu, Q.-A., Yang, X., Pang, T., Su, H., Xiao, Z., and Zhu, J · 2020
Cited alongside, same era.
Shortcut learning in deep neural networks
Geirhos, R., Jacobsen, J.-H., Michaelis, C., Zemel, R., Brendel, W., Bethge, M., and Wichmann, F. A · 2020
Cited alongside, same era.
Robust Pre-Training by Adversarial Contrastive Learning
Jiang, Z., Chen, T., Chen, T., and Wang, Z · 2020
Cited alongside, same era.
Harder or Different?A Closer Look at Distribution Shift in Dataset Reproduction
Lu, S., Nott, B., Olson, A., Todeschini, A., Vahabi, H., Carmon, Y., and Schmidt, L · 2020
Cited alongside, same era.
Adversarial Robustness Against the Union of Multiple Perturbation Models
Maini, P., Wong, E., and Kolter, Z · 2020
Cited alongside, same era.
Boosting Adversarial Training with Hypersphere Embedding
Pang, T., Yang, X., Dong, Y., Xu, K., Zhu, J., and Su, H · 2020
Cited alongside, same era.
Gao, R., Wang, J., Zhou, K., Liu, F., Xie, B., Niu, G., Han, B., and Cheng, J · 2022
Later among the works it cites.
Leveraging unlabeled data to predict out-of-distribution performance
Garg, S., Balakrishnan, S., Lipton, Z. C., Neyshabur, B., and Sedghi, H · 2022
Later among the works it cites.
On the effectiveness of adversarial training against common corruptions
Kireev, K., Andriushchenko, M., and Flammarion, N · 2022
Later among the works it cites.
Easyrobust: A comprehensive and easy-to-use toolkit for robust computer vision, 2022
Mao, X., Chen, Y., Li, X., Qi, G., Duan, R., Zhang, R., and Xue, H · 2022
Later among the works it cites.
Robustness and Accuracy Could Be Reconcilable by (Proper) Definition
Pang, T., Lin, M., Yang, X., Zhu, J., and Yan, S · 2022
Later among the works it cites.
Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off
Rade, R. and Moosavi-Dezfooli, S.-M · 2022
Later among the works it cites.
Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?
Sehwag, V., Mahloujifar, S., Handina, T., Dai, S., Xiang, C., Chiang, M., and Mittal, P · 2022
Later among the works it cites.
RobustART: Benchmarking Robustness on Architecture Design and Training Techniques, January 2022
Tang, S., Gong, R., Wang, Y., Liu, A., Wang, J., Chen, X., Yu, F., Liu, X., Song, D., Yuille, A., Torr, P. H. S., and Tao, D · 2022
Later among the works it cites.
OpenOOD: Benchmarking generalized out-of-distribution detection, October 2022
Yang, J., Wang, P., Zou, D., Zhou, Z., Ding, K., Peng, W., Wang, H., Chen, G., Li, B., Sun, Y., Du, X., Zhou, K., Zhang, W., Hendrycks, D., Li, Y., and Liu, Z · 2022
Later among the works it cites.
OOD-CV: A benchmark for robustness to out-of-distribution shifts of individual nuisances in natural images
Zhao, B., Yu, S., Ma, W., Yu, M., Mei, S., Wang, A., He, J., Yuille, A., and Kortylewski, A · 2022
Later among the works it cites.
Generalizability of Adversarial Robustness Under Distribution Shifts
Alhamoud, K., Hammoud, H. A. A. K., Alfarra, M., and Ghanem, B · 2023
Closest in time.
Improving the Accuracy-Robustness Trade-Off of Classifiers via Adaptive Smoothing, May 2023
Bai, Y., Anderson, B. G., Kim, A., and Sojoudi, S · 2023
Closest in time.
Decoupled Kullback-Leibler Divergence Loss, May 2023
Cui, J., Tian, Z., Zhong, Z., Qi, X., Yu, B., and Zhang, H · 2023
Closest in time.
MultiRobustBench: Benchmarking Robustness Against Multiple Attacks
Dai, S., Mahloujifar, S., Xiang, C., Sehwag, V., Chen, P.-Y., and Mittal, P · 2023
Closest in time.
A Light Recipe to Train Robust Vision Transformers
Debenedetti, E., Sehwag, V., and Mittal, P · 2023
Closest in time.
Towards Compositional Adversarial Robustness: Generalizing Adversarial Training to Composite Semantic Perturbations
Hsiung, L., Tsai, Y.-Y., Chen, P.-Y., and Ho, T.-Y · 2023
Closest in time.
Towards Out-of-Distribution Adversarial Robustness, February 2023
Ibrahim, A., Guille-Escuret, C., Mitliagkas, I., Rish, I., Krueger, D., and Bashivan, P · 2023
Closest in time.
Testing Robustness Against Unforeseen Adversaries, July 2023
Kaufmann, M., Kang, D., Sun, Y., Basart, S., Yin, X., Mazeika, M., Arora, A., Dziedzic, A., Boenisch, F., Brown, T., Steinhardt, J., and Hendrycks, D · 2023
Closest in time.
AROID: Improving Adversarial Robustness through Online Instance-wise Data Augmentation, June 2023
Li, L., Qiu, J., and Spratling, M · 2023
Closest in time.
A Comprehensive Study on Robustness of Image Classification Models: Benchmarking and Rethinking, February 2023
Liu, C., Dong, Y., Xiang, W., Yang, X., Su, H., Zhu, J., Chen, Y., He, Y., Xue, H., and Zheng, S · 2023
Closest in time.
How robust is unsupervised representation learning to distribution shift?
Shi, Y., Daunhawer, I., Vogt, J. E., Torr, P. H., and Sanyal, A · 2023
Closest in time.
Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat Models
Singh, N. D., Croce, F., and Hein, M · 2023
Closest in time.
Patches are all you need?
Trockman, A. and Kolter, J. Z · 2023
Closest in time.
Better Diffusion Models Further Improve Adversarial Training
Wang, Z., Pang, T., Du, C., Lin, M., Liu, W., and Yan, S · 2023
Closest in time.
Exploring and Exploiting Decision Boundary Dynamics for Adversarial Robustness
Xu, Y., Sun, Y., Goldblum, M., Goldstein, T., and Huang, F · 2023
Closest in time.