Fetching the paper…
Reading the bibliography…
We study the implicit bias of optimization in robust empirical risk minimization (robust ERM) and its connection with robust generalization.
Adversarial robustness may be at odds with simplicity
Nakkiran, P. (2019) · 1901
Earlier work this paper cites.
Rademacher penalties and structural risk minimization
Koltchinskii, V. (2001) · 1914
Earlier work this paper cites.
A simple weight decay can improve generalization
Krogh, A. and Hertz, J. A. (1991) · 1991
Earlier work this paper cites.
Support-vector networks
Cortes, C. and Vapnik, V. (1995) · 1995
Earlier work this paper cites.
Boosting the margin: A new explanation for the effectiveness of voting methods
Schapire, R. E., Freund, Y., Barlett, P., and Lee, W. S. (1997) · 1997
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P. (1998) · 1998
Earlier work this paper cites.
Some pac-bayesian theorems
McAllester, D. A. (1998) · 1998
Earlier work this paper cites.
Statistical learning theory
Vapnik, V. (1998) · 1998
Earlier work this paper cites.
Empirical margin distributions and bounding the generalization error of combined classifiers
Koltchinskii, V. and Panchenko, D. (2002) · 2002
Earlier work this paper cites.
Max-margin markov networks
Taskar, B., Guestrin, C., and Koller, D. (2003) · 2003
Earlier work this paper cites.
Feature selection, l1 vs. l2 regularization, and rotational invariance
Ng, A. Y. (2004) · 2004
Earlier work this paper cites.
Margin-based ranking meets boosting in the middle
Rudin, C., Cortes, C., Mohri, M., and Schapire, R. E. (2005) · 2005
Earlier work this paper cites.
On the complexity of linear prediction: Risk bounds, margin bounds, and regularization
Kakade, S. M., Sridharan, K., and Tewari, A. (2008) · 2008
Earlier work this paper cites.
Foundations of Machine Learning
Mohri, M., Rostamizadeh, A., and Talwalkar, A. (2012) · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Srndic, N., Laskov, P., Giacinto, G., and Roli, F. (2013) · 2013
Earlier work this paper cites.
Margins, shrinkage, and boosting
Telgarsky, M. (2013) · 2013
Earlier work this paper cites.
Convex Optimization
Boyd, S. P. and Vandenberghe, L. (2014) · 2014
Earlier work this paper cites.
Understanding Machine Learning - From Theory to Algorithms
Shalev-Shwartz, S. and Ben-David, S. (2014) · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., and Fergus, R. (2014) · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C. (2015) · 2015
Earlier work this paper cites.
In search of the real inductive bias: On the role of implicit regularization in deep learning
Neyshabur, B., Tomioka, R., and Srebro, N. (2015) · 2015
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P. D., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A. (2016) · 2016
Earlier work this paper cites.
Universal and transferable adversarial attacks on aligned language models
Zou, A., Wang, Z., Kolter, J. Z., and Fredrikson, M. (2023) · 2016
Earlier work this paper cites.
Spectrally-normalized margin bounds for neural networks
Bartlett, P. L., Foster, D. J., and Telgarsky, M. (2017) · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D. A. (2017) · 2017
Cited alongside, same era.
Implicit regularization in matrix factorization
Gunasekar, S., Woodworth, B. E., Bhojanapalli, S., Neyshabur, B., and Srebro, N. (2017) · 2017
Cited alongside, same era.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I. J., and Bengio, S. (2017a) · 2017
Cited alongside, same era.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I. J., and Bengio, S. (2017b) · 2017
Cited alongside, same era.
Understanding deep learning requires rethinking generalization
Zhang, C., Bengio, S., Hardt, M., Recht, B., and Vinyals, O. (2017) · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D. A. (2018) · 2018
You only propagate once: Accelerating adversarial training via maximal principle
Zhang, D., Zhang, T., Lu, Y., Zhu, Z., and Dong, B. (2019a) · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I. (2019b) · 2019
Later among the works it cites.
Adversarial learning guarantees for linear hypotheses and neural networks
Awasthi, P., Frank, N., and Mohri, M. (2020) · 2020
Later among the works it cites.
Implicit bias of gradient descent based adversarial training on separable data
Li, Y., Fang, E. X., Xu, H., and Zhao, T. (2020) · 2020
Later among the works it cites.
Generalization bounds for deep convolutional neural networks
Long, P. M. and Sedghi, H. (2020) · 2020
Later among the works it cites.
Gradient descent maximizes the margin of homogeneous neural networks
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Adversarial vulnerability for any classifier
Fawzi, A., Fawzi, H., and Fawzi, O. (2018) · 2018
Cited alongside, same era.
Adversarial spheres
Gilmer, J., Metz, L., Faghri, F., Schoenholz, S. S., Raghu, M., Wattenberg, M., and Goodfellow, I. J. (2018) · 2018
Cited alongside, same era.
Characterizing implicit bias in terms of optimization geometry
Gunasekar, S., Lee, J. D., Soudry, D., and Srebro, N. (2018a) · 2018
Cited alongside, same era.
Implicit bias of gradient descent on linear convolutional networks
Gunasekar, S., Lee, J. D., Soudry, D., and Srebro, N. (2018b) · 2018
Cited alongside, same era.
Towards Deep Learning Models Resistant to Adversarial Attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2018) · 2018
Cited alongside, same era.
A pac-bayesian approach to spectrally-normalized margin bounds for neural networks
Neyshabur, B., Bhojanapalli, S., and Srebro, N. (2018) · 2018
Cited alongside, same era.
Lyu, K. and Li, J. (2020) · 2020
Later among the works it cites.
Implicit bias in deep linear classification: Initialization scale vs training accuracy
Moroshko, E., Woodworth, B. E., Gunasekar, S., Lee, J. D., Srebro, N., and Soudry, D. (2020) · 2020
Later among the works it cites.
Overfitting in adversarially robust deep learning
Rice, L., Wong, E., and Kolter, J. Z. (2020) · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z. (2020) · 2020
Later among the works it cites.
Kernel and rich regimes in overparametrized models
Woodworth, B. E., Gunasekar, S., Lee, J. D., Moroshko, E., Savarese, P., Golan, I., Soudry, D., and Srebro, N. (2020) · 2020
Later among the works it cites.
Fit without fear: remarkable mathematical phenomena of deep learning through the prism of interpolation
Belkin, M. (2021) · 2021
Later among the works it cites.
Relative deviation margin bounds
Cortes, C., Mohri, M., and Suresh, A. T. (2021) · 2021
Later among the works it cites.
RobustBench: a standardized adversarial robustness benchmark
Croce, F., Andriushchenko, M., Sehwag, V., Debenedetti, E., Flammarion, N., Chiang, M., Mittal, P., and Hein, M. (2021) · 2021
Later among the works it cites.
Bridging the gap between adversarial robustness and optimization bias
Faghri, F., Vasconcelos, C. N., Fleet, D. J., Pedregosa, F., and Roux, N. L. (2021) · 2021
Later among the works it cites.
Implicit bias of adversarial training for deep neural networks
Lyu, B. and Zhu, Z. (2022) · 2022
Later among the works it cites.
On the generalization analysis of adversarial learning
Mustafa, W., Lei, Y., and Kloft, M. (2022) · 2022
Later among the works it cites.
What can the neural tangent kernel tell us about adversarial robustness?
Tsilivis, N. and Kempe, J. (2022) · 2022
Later among the works it cites.
Gradient methods provably converge to non-robust networks
Vardi, G., Yehudai, G., and Shamir, O. (2022) · 2022
Later among the works it cites.
Theoretically grounded loss functions and algorithms for adversarial robustness
Awasthi, P., Mao, A., Mohri, M., and Zhong, Y. (2023) · 2023
Later among the works it cites.
Scaling compute is not all you need for adversarial robustness
Debenedetti, E., Wan, Z., Andriushchenko, M., Sehwag, V., Bhardwaj, K., and Kailkhura, B. (2023) · 2023
Later among the works it cites.
The double-edged sword of implicit bias: Generalization vs. robustness in relu networks
Frei, S., Vardi, G., Bartlett, P. L., and Srebro, N. (2023) · 2023
Later among the works it cites.
On the implicit bias in deep-learning algorithms
Vardi, G. (2023) · 2023
Later among the works it cites.
Better diffusion models further improve adversarial training
Wang, Z., Pang, T., Du, C., Lin, M., Liu, W., and Yan, S. (2023) · 2023
Later among the works it cites.
Adversarial examples for evaluating reading comprehension systems
Jia, R. and Liang, P. (2017) · 2031
Closest in time.