Fetching the paper…
Reading the bibliography…
Deep neural networks (DNNs) are vulnerable to small adversarial perturbations of the inputs, posing a significant challenge to their reliability and robustness.
Y. Brenier, “Polar factorization and monotone rearrangement of vector-valued functions,” Commun. Pure Appl. Math. , vol. 44, no. 4, pp. 375–417, 1991
1991
Earlier work this paper cites.
L. A. Caffarelli, “Some regularity properties of solutions of monge amp re equation,” Commun. Pure Appl. Math. , vol. 44, no. 8-9, pp. 965–969, 1991
1991
Earlier work this paper cites.
H. Drucker and Y. Le Cun, “Improving generalization performance using double backpropagation,” IEEE Trans. Neural Netw. , vol. 3, no. 6, pp. 991–997, 1992
1992
Earlier work this paper cites.
J.-D. Benamou, Y. Brenier, and K. Guittet, “Numerical analysis of a multi-phasic mass transport problem,” Contemporary Math. , vol. 353, pp. 1–18, 2004
2004
Earlier work this paper cites.
S. Chopra, R. Hadsell, and Y. LeCun, “Learning a similarity metric discriminatively, with application to face verification,” in Proc. IEEE Comput. Soc. Conf. Comput. Vis. Pattern Recognit. , vol. 1. IEEE, 2005, pp. 539–546
2005
Earlier work this paper cites.
L. Yang and R. Jin, “Distance metric learning: A comprehensive survey,” Michigan State Universiy , vol. 2, no. 2, p. 4, 2006
2006
Earlier work this paper cites.
C. Villani et al. , Optimal transport: old and new . Springer, 2009, vol. 338
2009
Earlier work this paper cites.
K. Q. Weinberger and L. K. Saul, “Distance metric learning for large margin nearest neighbor classification.” J. Mach. Learn. Res. , vol. 10, no. 2, 2009
2009
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” Technical Report, University of Toronto , 2009
2009
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in Proc. IEEE/CVF Conf. Comput. Vis. Pattern Recognit. , 2009, pp. 248–255
2009
Earlier work this paper cites.
P. Cortez, A. Cerdeira, F. Almeida, T. Matos, and J. Reis, “Modeling wine preferences by data mining from physicochemical properties,” Decis. Support Syst. , vol. 47, no. 4, pp. 547–553, 2009
2009
Earlier work this paper cites.
L. Deng, “The mnist database of handwritten digit images for machine learning research [best of the web],” IEEE Signal Process. Mag. , vol. 29, no. 6, pp. 141–142, 2012
2012
Earlier work this paper cites.
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
N. Tishby and N. Zaslavsky, “Deep learning and the information bottleneck principle,” in Proc. IEEE Inf. Theory Workshop , 2015, pp. 1–5
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
G. De Philippis and A. Figalli, “Partial regularity for optimal transport maps,” Publications mathématiques de l’IHÉS , vol. 121, no. 1, pp. 81–112, 2015
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
N. Carlini and D. Wagner, “Adversarial examples are not easily detected: Bypassing ten detection methods,” in Proc. ACM Workshop Artif. Intell. Secur. , 2017, pp. 3–14
2017
Earlier work this paper cites.
I. Gulrajani, F. Ahmed, M. Arjovsky, V. Dumoulin, and A. Courville, “Improved training of wasserstein gans,” in Proc. Adv. Neural Inf. Process. Syst. , 2017, pp. 5769–5779
2017
Earlier work this paper cites.
J. Sokolić, R. Giryes, G. Sapiro, and M. R. Rodrigues, “Robust large margin deep neural networks,” IEEE Trans. Signal Process. , vol. 65, no. 16, pp. 4265–4280, 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
M. Cisse, P. Bojanowski, E. Grave, Y. Dauphin, and N. Usunier, “Parseval networks: Improving robustness to adversarial examples,” in Proc. Int. Conf. Mach. Learn. , 2017, pp. 854–863
2017
Earlier work this paper cites.
A. B. Taylor, “Convex interpolation and performance estimation of first-order methods for convex optimization.” Ph.D. dissertation, Catholic University of Louvain, Louvain-la-Neuve, Belgium, 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Cited alongside, same era.
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman, “Pixeldefend: Leveraging generative models to understand and defend against adversarial examples,” in Proc. Int. Conf. Learn. Representations , 2017
2017
Cited alongside, same era.
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin, “Attention is all you need,” in Proc. Adv. Neural Inf. Process. Syst. , vol. 30, 2017
2017
Cited alongside, same era.
A. Athalye and N. Carlini, “On the robustness of the cvpr 2018 white-box adversarial example defenses,” Comput. Vis.: Challenges Opportunities Privacy Secur. , 2018
2018
Cited alongside, same era.
B. Zhang, T. Cai, Z. Lu, D. He, and L. Wang, “Towards certifying l-infinity robustness using neural networks with l-inf-dist neurons,” in Proc. Int. Conf. Mach. Learn. , 2021, pp. 12 368–12 379
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, X. Zhai, T. Unterthiner, M. Dehghani, M. Minderer, G. Heigold, S. Gelly, J. Uszkoreit, and N. Houlsby, “An image is worth 16x16 words: Transformers for image recognition at scale,” in Proc. Int. Conf. Learn. Representations , 2021
2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
J. Uesato, B. O’donoghue, P. Kohli, and A. Oord, “Adversarial risk and the dangers of evaluating against weak attacks,” in Proc. Int. Conf. Mach. Learn. , 2018, pp. 5025–5034
2018
Cited alongside, same era.
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” in Proc. Int. Conf. Mach. Learn. , 2018, pp. 274–283
2018
Cited alongside, same era.
Y. Tsuzuku, I. Sato, and M. Sugiyama, “Lipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks,” in Proc. Adv. Neural Inf. Process. Syst. , 2018, pp. 6542–6551
2018
Cited alongside, same era.
2018
Cited alongside, same era.
P. Samangouei, M. Kabkab, and R. Chellappa, “Defense-GAN: Protecting classifiers against adversarial attacks using generative models,” in Proc. Int. Conf. Learn. Representations , 2018
2018
Cited alongside, same era.
J. Rapin and O. Teytaud, “Nevergrad - A gradient-free optimization platform,” https://GitHub.com/FacebookResearch/Nevergrad
2018
Cited alongside, same era.
C. Anil, J. Lucas, and R. Grosse, “Sorting out lipschitz function approximation,” in Proc. Int. Conf. Mach. Learn. , 2019, pp. 291–301
2019
Cited alongside, same era.
H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, and M. Jordan, “Theoretically principled trade-off between robustness and accuracy,” in Proc. Int. Conf. Mach. Learn. , 2019, pp. 7472–7482
2019
Cited alongside, same era.
C. Shi, C. Holtz, and G. Mishne, “Online adversarial purification based on self-supervision,” in Proc. Int. Conf. Learn. Representations , 2021
2021
Later among the works it cites.
J. Yoon, S. J. Hwang, and J. Lee, “Adversarial purification with score-based generative models,” in Proc. Int. Conf. Mach. Learn. , 2021, pp. 12 062–12 072
2021
Later among the works it cites.
2021
Later among the works it cites.
Y. Bengio, A. Lodi, and A. Prouvost, “Machine learning for combinatorial optimization: a methodological tour d’horizon,” Eur. J. Oper. Res. , vol. 290, no. 2, pp. 405–421, 2021
2021
Later among the works it cites.
H. Kim, G. Papamakarios, and A. Mnih, “The lipschitz constant of self-attention,” in Proc. Int. Conf. Mach. Learn. , 2021, pp. 5562–5571
2021
Later among the works it cites.
H. Touvron, M. Cord, M. Douze, F. Massa, A. Sablayrolles, and H. Jegou, “Training data-efficient image transformers distillation through attention,” in Proc. Int. Conf. Mach. Learn. , 2021, pp. 10 347–10 357
2021
Later among the works it cites.
K. Gupta, B. Pesquet-Popescu, F. Kaakai, J.-C. Pesquet, and F. D. Malliaros, “An adversarial attacker for neural networks in regression problems,” in Proc. Int. Joint Conf. Artif. Intell. Workshop Artif. Intell. Safety , 2021
2021
Later among the works it cites.
L. Xie, Y. Wang, J.-L. Yin, and X. Liu, “Robust single-step adversarial training with regularizer,” in Pattern Recognition and Computer Vision . Springer International Publishing, 2021, pp. 29–41
2021
Later among the works it cites.
R. Zhang and S. Zhang, “Rethinking influence functions of neural networks in the over-parameterized regime,” in Proc. AAAI Conf. Artif. Intell. , vol. 36, no. 8, 2022, pp. 9082–9090
2022
Later among the works it cites.
W. Nie, B. Guo, Y. Huang, C. Xiao, A. Vahdat, and A. Anandkumar, “Diffusion models for adversarial purification,” in Proc. Int. Conf. Mach. Learn. , 2022, pp. 16 805–16 827
2022
Later among the works it cites.
T. Chen, X. Chen, W. Chen, H. Heaton, J. Liu, Z. Wang, and W. Yin, “Learning to optimize: A primer and a benchmark,” J. Mach. Learn. Res. , vol. 23, no. 189, pp. 1–59, 2022
2022
Later among the works it cites.
M. Zhou and V. M. Patel, “Enhancing adversarial robustness for deep metric learning,” in Proc. IEEE/CVF Conf. Comput. Vis. Pattern Recognit. , 2022, pp. 15 325–15 334
2022
Later among the works it cites.
J. Pomponi, S. Scardapane, and A. Uncini, “Pixle: a fast and effective black-box attack based on rearranging pixels,” in 2022 International Joint Conference on Neural Networks (IJCNN) . IEEE, 2022
2022
Later among the works it cites.
Y. Wang, T. Sun, S. Li, X. Yuan, W. Ni, E. Hossain, and H. Vincent Poor, “Adversarial attacks and defenses in machine learning-empowered communication systems and networks: A contemporary survey,” IEEE Commun. Surv. Tutor. , vol. 25, no. 4, pp. 2245–2298, 2023
2023
Later among the works it cites.
H. P. Silva, L. Seidenari, and A. Del Bimbo, “Diffdefense: Defending against adversarial attacks via diffusion models,” in Proc. Int. Conf. Image Anal. Process. , 2023, pp. 430–442
2023
Later among the works it cites.
J. Choi, J. Li, S. Ferdous, Q. Liang, J. R. Moffitt, and R. Chen, “Spatial organization of the mouse retina at single cell resolution by merfish,” Nat. Commun. , vol. 14, no. 1, p. 4929, 2023
2023
Later among the works it cites.
2024
Closest in time.
T. Ruan and S. Zhang, “Towards understanding how the attention mechanism works in deep learning,” 2024
2024
Closest in time.
P. Zhai and S. Zhang, “Adversarial information bottleneck,” IEEE Trans. Neural Netw. Learn. Syst. , vol. 35, no. 1, pp. 221–230, 2024
2024
Closest in time.
K. Gai and S. Zhang, “Tessellating the latent space for non-adversarial generative auto-encoders,” IEEE Trans. Pattern Anal. Mach. Intell. , vol. 46, no. 2, pp. 780–792, 2024
2024
Closest in time.
M. ApS, The MOSEK optimization toolbox for Python manual. Version 10.2. , 2024. [Online]. Available: https://docs.mosek.com/10.2/pythonapi/index.html
2024
Closest in time.