Robustifying $\ell_\infty$ Adversarial Training to the Union of Perturbation Models Article Swipe
YOU?
·
· 2021
· Open Access
·
· DOI: https://doi.org/10.48550/arxiv.2105.14710
Classical adversarial training (AT) frameworks are designed to achieve high adversarial accuracy against a single attack type, typically $\ell_\infty$ norm-bounded perturbations. Recent extensions in AT have focused on defending against the union of multiple perturbations but this benefit is obtained at the expense of a significant (up to $10\times$) increase in training complexity over single-attack $\ell_\infty$ AT. In this work, we expand the capabilities of widely popular single-attack $\ell_\infty$ AT frameworks to provide robustness to the union of ($\ell_\infty, \ell_2, \ell_1$) perturbations while preserving their training efficiency. Our technique, referred to as Shaped Noise Augmented Processing (SNAP), exploits a well-established byproduct of single-attack AT frameworks -- the reduction in the curvature of the decision boundary of networks. SNAP prepends a given deep net with a shaped noise augmentation layer whose distribution is learned along with network parameters using any standard single-attack AT. As a result, SNAP enhances adversarial accuracy of ResNet-18 on CIFAR-10 against the union of ($\ell_\infty, \ell_2, \ell_1$) perturbations by 14%-to-20% for four state-of-the-art (SOTA) single-attack $\ell_\infty$ AT frameworks, and, for the first time, establishes a benchmark for ResNet-50 and ResNet-101 on ImageNet.
Related Topics
- Type
- preprint
- Language
- en
- Landing Page
- http://arxiv.org/abs/2105.14710
- https://arxiv.org/pdf/2105.14710
- OA Status
- green
- References
- 49
- Related Works
- 10
- OpenAlex ID
- https://openalex.org/W3172980906
Raw OpenAlex JSON
- OpenAlex ID
-
https://openalex.org/W3172980906Canonical identifier for this work in OpenAlex
- DOI
-
https://doi.org/10.48550/arxiv.2105.14710Digital Object Identifier
- Title
-
Robustifying $\ell_\infty$ Adversarial Training to the Union of Perturbation ModelsWork title
- Type
-
preprintOpenAlex work type
- Language
-
enPrimary language
- Publication year
-
2021Year of publication
- Publication date
-
2021-05-31Full publication date if available
- Authors
-
Ameya D. Patil, Michael Tuttle, Alexander G. Schwing, Naresh R. ShanbhagList of authors in order
- Landing page
-
https://arxiv.org/abs/2105.14710Publisher landing page
- PDF URL
-
https://arxiv.org/pdf/2105.14710Direct link to full text PDF
- Open access
-
YesWhether a free full text is available
- OA status
-
greenOpen access status per OpenAlex
- OA URL
-
https://arxiv.org/pdf/2105.14710Direct OA link when available
- Concepts
-
Decision boundary, Norm (philosophy), Bounded function, Adversarial system, Mathematics, Perturbation (astronomy), Robustness (evolution), Exploit, Algorithm, Discrete mathematics, Computer science, Topology (electrical circuits), Combinatorics, Artificial intelligence, Mathematical analysis, Physics, Political science, Computer security, Classifier (UML), Biochemistry, Quantum mechanics, Gene, Chemistry, LawTop concepts (fields/topics) attached by OpenAlex
- Cited by
-
0Total citation count in OpenAlex
- References (count)
-
49Number of works referenced by this work
- Related works (count)
-
10Other works algorithmically related by OpenAlex
Full payload
| id | https://openalex.org/W3172980906 |
|---|---|
| doi | https://doi.org/10.48550/arxiv.2105.14710 |
| ids.doi | https://doi.org/10.48550/arxiv.2105.14710 |
| ids.mag | 3172980906 |
| ids.openalex | https://openalex.org/W3172980906 |
| fwci | |
| type | preprint |
| title | Robustifying $\ell_\infty$ Adversarial Training to the Union of Perturbation Models |
| biblio.issue | |
| biblio.volume | |
| biblio.last_page | |
| biblio.first_page | |
| topics[0].id | https://openalex.org/T11689 |
| topics[0].field.id | https://openalex.org/fields/17 |
| topics[0].field.display_name | Computer Science |
| topics[0].score | 0.9998999834060669 |
| topics[0].domain.id | https://openalex.org/domains/3 |
| topics[0].domain.display_name | Physical Sciences |
| topics[0].subfield.id | https://openalex.org/subfields/1702 |
| topics[0].subfield.display_name | Artificial Intelligence |
| topics[0].display_name | Adversarial Robustness in Machine Learning |
| topics[1].id | https://openalex.org/T11515 |
| topics[1].field.id | https://openalex.org/fields/13 |
| topics[1].field.display_name | Biochemistry, Genetics and Molecular Biology |
| topics[1].score | 0.9700000286102295 |
| topics[1].domain.id | https://openalex.org/domains/1 |
| topics[1].domain.display_name | Life Sciences |
| topics[1].subfield.id | https://openalex.org/subfields/1312 |
| topics[1].subfield.display_name | Molecular Biology |
| topics[1].display_name | Bacillus and Francisella bacterial research |
| topics[2].id | https://openalex.org/T11512 |
| topics[2].field.id | https://openalex.org/fields/17 |
| topics[2].field.display_name | Computer Science |
| topics[2].score | 0.9276000261306763 |
| topics[2].domain.id | https://openalex.org/domains/3 |
| topics[2].domain.display_name | Physical Sciences |
| topics[2].subfield.id | https://openalex.org/subfields/1702 |
| topics[2].subfield.display_name | Artificial Intelligence |
| topics[2].display_name | Anomaly Detection Techniques and Applications |
| is_xpac | False |
| apc_list | |
| apc_paid | |
| concepts[0].id | https://openalex.org/C42023084 |
| concepts[0].level | 3 |
| concepts[0].score | 0.5851560235023499 |
| concepts[0].wikidata | https://www.wikidata.org/wiki/Q5249231 |
| concepts[0].display_name | Decision boundary |
| concepts[1].id | https://openalex.org/C191795146 |
| concepts[1].level | 2 |
| concepts[1].score | 0.5363038778305054 |
| concepts[1].wikidata | https://www.wikidata.org/wiki/Q3878446 |
| concepts[1].display_name | Norm (philosophy) |
| concepts[2].id | https://openalex.org/C34388435 |
| concepts[2].level | 2 |
| concepts[2].score | 0.5292890667915344 |
| concepts[2].wikidata | https://www.wikidata.org/wiki/Q2267362 |
| concepts[2].display_name | Bounded function |
| concepts[3].id | https://openalex.org/C37736160 |
| concepts[3].level | 2 |
| concepts[3].score | 0.5248708128929138 |
| concepts[3].wikidata | https://www.wikidata.org/wiki/Q1801315 |
| concepts[3].display_name | Adversarial system |
| concepts[4].id | https://openalex.org/C33923547 |
| concepts[4].level | 0 |
| concepts[4].score | 0.5085660219192505 |
| concepts[4].wikidata | https://www.wikidata.org/wiki/Q395 |
| concepts[4].display_name | Mathematics |
| concepts[5].id | https://openalex.org/C177918212 |
| concepts[5].level | 2 |
| concepts[5].score | 0.4737416207790375 |
| concepts[5].wikidata | https://www.wikidata.org/wiki/Q803623 |
| concepts[5].display_name | Perturbation (astronomy) |
| concepts[6].id | https://openalex.org/C63479239 |
| concepts[6].level | 3 |
| concepts[6].score | 0.46027135848999023 |
| concepts[6].wikidata | https://www.wikidata.org/wiki/Q7353546 |
| concepts[6].display_name | Robustness (evolution) |
| concepts[7].id | https://openalex.org/C165696696 |
| concepts[7].level | 2 |
| concepts[7].score | 0.4527558982372284 |
| concepts[7].wikidata | https://www.wikidata.org/wiki/Q11287 |
| concepts[7].display_name | Exploit |
| concepts[8].id | https://openalex.org/C11413529 |
| concepts[8].level | 1 |
| concepts[8].score | 0.3943597078323364 |
| concepts[8].wikidata | https://www.wikidata.org/wiki/Q8366 |
| concepts[8].display_name | Algorithm |
| concepts[9].id | https://openalex.org/C118615104 |
| concepts[9].level | 1 |
| concepts[9].score | 0.3347669839859009 |
| concepts[9].wikidata | https://www.wikidata.org/wiki/Q121416 |
| concepts[9].display_name | Discrete mathematics |
| concepts[10].id | https://openalex.org/C41008148 |
| concepts[10].level | 0 |
| concepts[10].score | 0.324992299079895 |
| concepts[10].wikidata | https://www.wikidata.org/wiki/Q21198 |
| concepts[10].display_name | Computer science |
| concepts[11].id | https://openalex.org/C184720557 |
| concepts[11].level | 2 |
| concepts[11].score | 0.3246137499809265 |
| concepts[11].wikidata | https://www.wikidata.org/wiki/Q7825049 |
| concepts[11].display_name | Topology (electrical circuits) |
| concepts[12].id | https://openalex.org/C114614502 |
| concepts[12].level | 1 |
| concepts[12].score | 0.31662654876708984 |
| concepts[12].wikidata | https://www.wikidata.org/wiki/Q76592 |
| concepts[12].display_name | Combinatorics |
| concepts[13].id | https://openalex.org/C154945302 |
| concepts[13].level | 1 |
| concepts[13].score | 0.2737605571746826 |
| concepts[13].wikidata | https://www.wikidata.org/wiki/Q11660 |
| concepts[13].display_name | Artificial intelligence |
| concepts[14].id | https://openalex.org/C134306372 |
| concepts[14].level | 1 |
| concepts[14].score | 0.2019093632698059 |
| concepts[14].wikidata | https://www.wikidata.org/wiki/Q7754 |
| concepts[14].display_name | Mathematical analysis |
| concepts[15].id | https://openalex.org/C121332964 |
| concepts[15].level | 0 |
| concepts[15].score | 0.15793856978416443 |
| concepts[15].wikidata | https://www.wikidata.org/wiki/Q413 |
| concepts[15].display_name | Physics |
| concepts[16].id | https://openalex.org/C17744445 |
| concepts[16].level | 0 |
| concepts[16].score | 0.09580942988395691 |
| concepts[16].wikidata | https://www.wikidata.org/wiki/Q36442 |
| concepts[16].display_name | Political science |
| concepts[17].id | https://openalex.org/C38652104 |
| concepts[17].level | 1 |
| concepts[17].score | 0.08376297354698181 |
| concepts[17].wikidata | https://www.wikidata.org/wiki/Q3510521 |
| concepts[17].display_name | Computer security |
| concepts[18].id | https://openalex.org/C95623464 |
| concepts[18].level | 2 |
| concepts[18].score | 0.0 |
| concepts[18].wikidata | https://www.wikidata.org/wiki/Q1096149 |
| concepts[18].display_name | Classifier (UML) |
| concepts[19].id | https://openalex.org/C55493867 |
| concepts[19].level | 1 |
| concepts[19].score | 0.0 |
| concepts[19].wikidata | https://www.wikidata.org/wiki/Q7094 |
| concepts[19].display_name | Biochemistry |
| concepts[20].id | https://openalex.org/C62520636 |
| concepts[20].level | 1 |
| concepts[20].score | 0.0 |
| concepts[20].wikidata | https://www.wikidata.org/wiki/Q944 |
| concepts[20].display_name | Quantum mechanics |
| concepts[21].id | https://openalex.org/C104317684 |
| concepts[21].level | 2 |
| concepts[21].score | 0.0 |
| concepts[21].wikidata | https://www.wikidata.org/wiki/Q7187 |
| concepts[21].display_name | Gene |
| concepts[22].id | https://openalex.org/C185592680 |
| concepts[22].level | 0 |
| concepts[22].score | 0.0 |
| concepts[22].wikidata | https://www.wikidata.org/wiki/Q2329 |
| concepts[22].display_name | Chemistry |
| concepts[23].id | https://openalex.org/C199539241 |
| concepts[23].level | 1 |
| concepts[23].score | 0.0 |
| concepts[23].wikidata | https://www.wikidata.org/wiki/Q7748 |
| concepts[23].display_name | Law |
| keywords[0].id | https://openalex.org/keywords/decision-boundary |
| keywords[0].score | 0.5851560235023499 |
| keywords[0].display_name | Decision boundary |
| keywords[1].id | https://openalex.org/keywords/norm |
| keywords[1].score | 0.5363038778305054 |
| keywords[1].display_name | Norm (philosophy) |
| keywords[2].id | https://openalex.org/keywords/bounded-function |
| keywords[2].score | 0.5292890667915344 |
| keywords[2].display_name | Bounded function |
| keywords[3].id | https://openalex.org/keywords/adversarial-system |
| keywords[3].score | 0.5248708128929138 |
| keywords[3].display_name | Adversarial system |
| keywords[4].id | https://openalex.org/keywords/mathematics |
| keywords[4].score | 0.5085660219192505 |
| keywords[4].display_name | Mathematics |
| keywords[5].id | https://openalex.org/keywords/perturbation |
| keywords[5].score | 0.4737416207790375 |
| keywords[5].display_name | Perturbation (astronomy) |
| keywords[6].id | https://openalex.org/keywords/robustness |
| keywords[6].score | 0.46027135848999023 |
| keywords[6].display_name | Robustness (evolution) |
| keywords[7].id | https://openalex.org/keywords/exploit |
| keywords[7].score | 0.4527558982372284 |
| keywords[7].display_name | Exploit |
| keywords[8].id | https://openalex.org/keywords/algorithm |
| keywords[8].score | 0.3943597078323364 |
| keywords[8].display_name | Algorithm |
| keywords[9].id | https://openalex.org/keywords/discrete-mathematics |
| keywords[9].score | 0.3347669839859009 |
| keywords[9].display_name | Discrete mathematics |
| keywords[10].id | https://openalex.org/keywords/computer-science |
| keywords[10].score | 0.324992299079895 |
| keywords[10].display_name | Computer science |
| keywords[11].id | https://openalex.org/keywords/topology |
| keywords[11].score | 0.3246137499809265 |
| keywords[11].display_name | Topology (electrical circuits) |
| keywords[12].id | https://openalex.org/keywords/combinatorics |
| keywords[12].score | 0.31662654876708984 |
| keywords[12].display_name | Combinatorics |
| keywords[13].id | https://openalex.org/keywords/artificial-intelligence |
| keywords[13].score | 0.2737605571746826 |
| keywords[13].display_name | Artificial intelligence |
| keywords[14].id | https://openalex.org/keywords/mathematical-analysis |
| keywords[14].score | 0.2019093632698059 |
| keywords[14].display_name | Mathematical analysis |
| keywords[15].id | https://openalex.org/keywords/physics |
| keywords[15].score | 0.15793856978416443 |
| keywords[15].display_name | Physics |
| keywords[16].id | https://openalex.org/keywords/political-science |
| keywords[16].score | 0.09580942988395691 |
| keywords[16].display_name | Political science |
| keywords[17].id | https://openalex.org/keywords/computer-security |
| keywords[17].score | 0.08376297354698181 |
| keywords[17].display_name | Computer security |
| language | en |
| locations[0].id | pmh:oai:arXiv.org:2105.14710 |
| locations[0].is_oa | True |
| locations[0].source.id | https://openalex.org/S4306400194 |
| locations[0].source.issn | |
| locations[0].source.type | repository |
| locations[0].source.is_oa | True |
| locations[0].source.issn_l | |
| locations[0].source.is_core | False |
| locations[0].source.is_in_doaj | False |
| locations[0].source.display_name | arXiv (Cornell University) |
| locations[0].source.host_organization | https://openalex.org/I205783295 |
| locations[0].source.host_organization_name | Cornell University |
| locations[0].source.host_organization_lineage | https://openalex.org/I205783295 |
| locations[0].license | |
| locations[0].pdf_url | https://arxiv.org/pdf/2105.14710 |
| locations[0].version | submittedVersion |
| locations[0].raw_type | text |
| locations[0].license_id | |
| locations[0].is_accepted | False |
| locations[0].is_published | False |
| locations[0].raw_source_name | |
| locations[0].landing_page_url | http://arxiv.org/abs/2105.14710 |
| locations[1].id | doi:10.48550/arxiv.2105.14710 |
| locations[1].is_oa | True |
| locations[1].source.id | https://openalex.org/S4306400194 |
| locations[1].source.issn | |
| locations[1].source.type | repository |
| locations[1].source.is_oa | True |
| locations[1].source.issn_l | |
| locations[1].source.is_core | False |
| locations[1].source.is_in_doaj | False |
| locations[1].source.display_name | arXiv (Cornell University) |
| locations[1].source.host_organization | https://openalex.org/I205783295 |
| locations[1].source.host_organization_name | Cornell University |
| locations[1].source.host_organization_lineage | https://openalex.org/I205783295 |
| locations[1].license | cc-by |
| locations[1].pdf_url | |
| locations[1].version | |
| locations[1].raw_type | article |
| locations[1].license_id | https://openalex.org/licenses/cc-by |
| locations[1].is_accepted | False |
| locations[1].is_published | |
| locations[1].raw_source_name | |
| locations[1].landing_page_url | https://doi.org/10.48550/arxiv.2105.14710 |
| indexed_in | arxiv, datacite |
| authorships[0].author.id | https://openalex.org/A5076493969 |
| authorships[0].author.orcid | https://orcid.org/0000-0003-3718-3026 |
| authorships[0].author.display_name | Ameya D. Patil |
| authorships[0].countries | US |
| authorships[0].affiliations[0].institution_ids | https://openalex.org/I157725225 |
| authorships[0].affiliations[0].raw_affiliation_string | ***University of Illinois at Urbana-Champaign |
| authorships[0].institutions[0].id | https://openalex.org/I157725225 |
| authorships[0].institutions[0].ror | https://ror.org/047426m28 |
| authorships[0].institutions[0].type | education |
| authorships[0].institutions[0].lineage | https://openalex.org/I157725225 |
| authorships[0].institutions[0].country_code | US |
| authorships[0].institutions[0].display_name | University of Illinois Urbana-Champaign |
| authorships[0].author_position | first |
| authorships[0].raw_author_name | Ameya D. Patil |
| authorships[0].is_corresponding | False |
| authorships[0].raw_affiliation_strings | ***University of Illinois at Urbana-Champaign |
| authorships[1].author.id | https://openalex.org/A5005723037 |
| authorships[1].author.orcid | |
| authorships[1].author.display_name | Michael Tuttle |
| authorships[1].countries | US |
| authorships[1].affiliations[0].institution_ids | https://openalex.org/I157725225 |
| authorships[1].affiliations[0].raw_affiliation_string | ***University of Illinois at Urbana-Champaign |
| authorships[1].institutions[0].id | https://openalex.org/I157725225 |
| authorships[1].institutions[0].ror | https://ror.org/047426m28 |
| authorships[1].institutions[0].type | education |
| authorships[1].institutions[0].lineage | https://openalex.org/I157725225 |
| authorships[1].institutions[0].country_code | US |
| authorships[1].institutions[0].display_name | University of Illinois Urbana-Champaign |
| authorships[1].author_position | middle |
| authorships[1].raw_author_name | Michael Tuttle |
| authorships[1].is_corresponding | False |
| authorships[1].raw_affiliation_strings | ***University of Illinois at Urbana-Champaign |
| authorships[2].author.id | https://openalex.org/A5049638480 |
| authorships[2].author.orcid | |
| authorships[2].author.display_name | Alexander G. Schwing |
| authorships[2].countries | US |
| authorships[2].affiliations[0].institution_ids | https://openalex.org/I157725225 |
| authorships[2].affiliations[0].raw_affiliation_string | ***University of Illinois at Urbana-Champaign |
| authorships[2].institutions[0].id | https://openalex.org/I157725225 |
| authorships[2].institutions[0].ror | https://ror.org/047426m28 |
| authorships[2].institutions[0].type | education |
| authorships[2].institutions[0].lineage | https://openalex.org/I157725225 |
| authorships[2].institutions[0].country_code | US |
| authorships[2].institutions[0].display_name | University of Illinois Urbana-Champaign |
| authorships[2].author_position | middle |
| authorships[2].raw_author_name | Alexander G. Schwing |
| authorships[2].is_corresponding | False |
| authorships[2].raw_affiliation_strings | ***University of Illinois at Urbana-Champaign |
| authorships[3].author.id | https://openalex.org/A5057014407 |
| authorships[3].author.orcid | https://orcid.org/0000-0002-4323-9164 |
| authorships[3].author.display_name | Naresh R. Shanbhag |
| authorships[3].countries | US |
| authorships[3].affiliations[0].institution_ids | https://openalex.org/I157725225 |
| authorships[3].affiliations[0].raw_affiliation_string | ***University of Illinois at Urbana-Champaign |
| authorships[3].institutions[0].id | https://openalex.org/I157725225 |
| authorships[3].institutions[0].ror | https://ror.org/047426m28 |
| authorships[3].institutions[0].type | education |
| authorships[3].institutions[0].lineage | https://openalex.org/I157725225 |
| authorships[3].institutions[0].country_code | US |
| authorships[3].institutions[0].display_name | University of Illinois Urbana-Champaign |
| authorships[3].author_position | last |
| authorships[3].raw_author_name | Naresh R. Shanbhag |
| authorships[3].is_corresponding | False |
| authorships[3].raw_affiliation_strings | ***University of Illinois at Urbana-Champaign |
| has_content.pdf | False |
| has_content.grobid_xml | False |
| is_paratext | False |
| open_access.is_oa | True |
| open_access.oa_url | https://arxiv.org/pdf/2105.14710 |
| open_access.oa_status | green |
| open_access.any_repository_has_fulltext | False |
| created_date | 2025-10-10T00:00:00 |
| display_name | Robustifying $\ell_\infty$ Adversarial Training to the Union of Perturbation Models |
| has_fulltext | False |
| is_retracted | False |
| updated_date | 2025-11-06T06:51:31.235846 |
| primary_topic.id | https://openalex.org/T11689 |
| primary_topic.field.id | https://openalex.org/fields/17 |
| primary_topic.field.display_name | Computer Science |
| primary_topic.score | 0.9998999834060669 |
| primary_topic.domain.id | https://openalex.org/domains/3 |
| primary_topic.domain.display_name | Physical Sciences |
| primary_topic.subfield.id | https://openalex.org/subfields/1702 |
| primary_topic.subfield.display_name | Artificial Intelligence |
| primary_topic.display_name | Adversarial Robustness in Machine Learning |
| related_works | https://openalex.org/W17155033, https://openalex.org/W3207760230, https://openalex.org/W1496222301, https://openalex.org/W1590307681, https://openalex.org/W2536018345, https://openalex.org/W4312814274, https://openalex.org/W4285370786, https://openalex.org/W2296488620, https://openalex.org/W4286235935, https://openalex.org/W4385154961 |
| cited_by_count | 0 |
| locations_count | 2 |
| best_oa_location.id | pmh:oai:arXiv.org:2105.14710 |
| best_oa_location.is_oa | True |
| best_oa_location.source.id | https://openalex.org/S4306400194 |
| best_oa_location.source.issn | |
| best_oa_location.source.type | repository |
| best_oa_location.source.is_oa | True |
| best_oa_location.source.issn_l | |
| best_oa_location.source.is_core | False |
| best_oa_location.source.is_in_doaj | False |
| best_oa_location.source.display_name | arXiv (Cornell University) |
| best_oa_location.source.host_organization | https://openalex.org/I205783295 |
| best_oa_location.source.host_organization_name | Cornell University |
| best_oa_location.source.host_organization_lineage | https://openalex.org/I205783295 |
| best_oa_location.license | |
| best_oa_location.pdf_url | https://arxiv.org/pdf/2105.14710 |
| best_oa_location.version | submittedVersion |
| best_oa_location.raw_type | text |
| best_oa_location.license_id | |
| best_oa_location.is_accepted | False |
| best_oa_location.is_published | False |
| best_oa_location.raw_source_name | |
| best_oa_location.landing_page_url | http://arxiv.org/abs/2105.14710 |
| primary_location.id | pmh:oai:arXiv.org:2105.14710 |
| primary_location.is_oa | True |
| primary_location.source.id | https://openalex.org/S4306400194 |
| primary_location.source.issn | |
| primary_location.source.type | repository |
| primary_location.source.is_oa | True |
| primary_location.source.issn_l | |
| primary_location.source.is_core | False |
| primary_location.source.is_in_doaj | False |
| primary_location.source.display_name | arXiv (Cornell University) |
| primary_location.source.host_organization | https://openalex.org/I205783295 |
| primary_location.source.host_organization_name | Cornell University |
| primary_location.source.host_organization_lineage | https://openalex.org/I205783295 |
| primary_location.license | |
| primary_location.pdf_url | https://arxiv.org/pdf/2105.14710 |
| primary_location.version | submittedVersion |
| primary_location.raw_type | text |
| primary_location.license_id | |
| primary_location.is_accepted | False |
| primary_location.is_published | False |
| primary_location.raw_source_name | |
| primary_location.landing_page_url | http://arxiv.org/abs/2105.14710 |
| publication_date | 2021-05-31 |
| publication_year | 2021 |
| referenced_works | https://openalex.org/W2962729158, https://openalex.org/W2945033152, https://openalex.org/W3113477609, https://openalex.org/W3008117795, https://openalex.org/W3034842981, https://openalex.org/W2906186365, https://openalex.org/W3036304200, https://openalex.org/W3168115700, https://openalex.org/W2963297642, https://openalex.org/W2963026800, https://openalex.org/W2963060032, https://openalex.org/W2946498182, https://openalex.org/W2911634294, https://openalex.org/W2243397390, https://openalex.org/W3035467354, https://openalex.org/W2964253222, https://openalex.org/W2934654846, https://openalex.org/W3101700548, https://openalex.org/W2943657790, https://openalex.org/W2963070423, https://openalex.org/W3034758058, https://openalex.org/W2970390122, https://openalex.org/W2963693747, https://openalex.org/W3088909400, https://openalex.org/W3107235539, https://openalex.org/W3012909934, https://openalex.org/W2996568780, https://openalex.org/W3034608990, https://openalex.org/W2913189540, https://openalex.org/W3035005405, https://openalex.org/W2998835636, https://openalex.org/W2963612069, https://openalex.org/W2963485691, https://openalex.org/W2970567221, https://openalex.org/W3034204786, https://openalex.org/W2949769151, https://openalex.org/W3124238039, https://openalex.org/W3007305010, https://openalex.org/W2942630857, https://openalex.org/W3116074996, https://openalex.org/W2971109239, https://openalex.org/W3035032188, https://openalex.org/W3092171228, https://openalex.org/W3034488700, https://openalex.org/W3134621603, https://openalex.org/W2971229607, https://openalex.org/W2982561504, https://openalex.org/W2989576588, https://openalex.org/W2970317235 |
| referenced_works_count | 49 |
| abstract_inverted_index.a | 13, 44, 98, 119, 124, 143, 177 |
| abstract_inverted_index.-- | 105 |
| abstract_inverted_index.AT | 24, 69, 103, 169 |
| abstract_inverted_index.As | 142 |
| abstract_inverted_index.In | 57 |
| abstract_inverted_index.as | 91 |
| abstract_inverted_index.at | 40 |
| abstract_inverted_index.by | 161 |
| abstract_inverted_index.in | 23, 50, 108 |
| abstract_inverted_index.is | 38, 131 |
| abstract_inverted_index.of | 32, 43, 64, 77, 101, 111, 115, 149, 156 |
| abstract_inverted_index.on | 27, 151, 183 |
| abstract_inverted_index.to | 7, 47, 71, 74, 90 |
| abstract_inverted_index.we | 60 |
| abstract_inverted_index.(up | 46 |
| abstract_inverted_index.AT. | 56, 141 |
| abstract_inverted_index.Our | 87 |
| abstract_inverted_index.and | 181 |
| abstract_inverted_index.any | 138 |
| abstract_inverted_index.are | 5 |
| abstract_inverted_index.but | 35 |
| abstract_inverted_index.for | 163, 172, 179 |
| abstract_inverted_index.net | 122 |
| abstract_inverted_index.the | 30, 41, 62, 75, 106, 109, 112, 154, 173 |
| abstract_inverted_index.(AT) | 3 |
| abstract_inverted_index.SNAP | 117, 145 |
| abstract_inverted_index.and, | 171 |
| abstract_inverted_index.deep | 121 |
| abstract_inverted_index.four | 164 |
| abstract_inverted_index.have | 25 |
| abstract_inverted_index.high | 9 |
| abstract_inverted_index.over | 53 |
| abstract_inverted_index.this | 36, 58 |
| abstract_inverted_index.with | 123, 134 |
| abstract_inverted_index.Noise | 93 |
| abstract_inverted_index.along | 133 |
| abstract_inverted_index.first | 174 |
| abstract_inverted_index.given | 120 |
| abstract_inverted_index.layer | 128 |
| abstract_inverted_index.noise | 126 |
| abstract_inverted_index.their | 84 |
| abstract_inverted_index.time, | 175 |
| abstract_inverted_index.type, | 16 |
| abstract_inverted_index.union | 31, 76, 155 |
| abstract_inverted_index.using | 137 |
| abstract_inverted_index.while | 82 |
| abstract_inverted_index.whose | 129 |
| abstract_inverted_index.work, | 59 |
| abstract_inverted_index.(SOTA) | 166 |
| abstract_inverted_index.Recent | 21 |
| abstract_inverted_index.Shaped | 92 |
| abstract_inverted_index.attack | 15 |
| abstract_inverted_index.expand | 61 |
| abstract_inverted_index.shaped | 125 |
| abstract_inverted_index.single | 14 |
| abstract_inverted_index.widely | 65 |
| abstract_inverted_index.(SNAP), | 96 |
| abstract_inverted_index.\ell_2, | 79, 158 |
| abstract_inverted_index.achieve | 8 |
| abstract_inverted_index.against | 12, 29, 153 |
| abstract_inverted_index.benefit | 37 |
| abstract_inverted_index.expense | 42 |
| abstract_inverted_index.focused | 26 |
| abstract_inverted_index.learned | 132 |
| abstract_inverted_index.network | 135 |
| abstract_inverted_index.popular | 66 |
| abstract_inverted_index.provide | 72 |
| abstract_inverted_index.result, | 144 |
| abstract_inverted_index.CIFAR-10 | 152 |
| abstract_inverted_index.\ell_1$) | 80, 159 |
| abstract_inverted_index.accuracy | 11, 148 |
| abstract_inverted_index.boundary | 114 |
| abstract_inverted_index.decision | 113 |
| abstract_inverted_index.designed | 6 |
| abstract_inverted_index.enhances | 146 |
| abstract_inverted_index.exploits | 97 |
| abstract_inverted_index.increase | 49 |
| abstract_inverted_index.multiple | 33 |
| abstract_inverted_index.obtained | 39 |
| abstract_inverted_index.prepends | 118 |
| abstract_inverted_index.referred | 89 |
| abstract_inverted_index.standard | 139 |
| abstract_inverted_index.training | 2, 51, 85 |
| abstract_inverted_index.Augmented | 94 |
| abstract_inverted_index.Classical | 0 |
| abstract_inverted_index.ImageNet. | 184 |
| abstract_inverted_index.ResNet-18 | 150 |
| abstract_inverted_index.ResNet-50 | 180 |
| abstract_inverted_index.benchmark | 178 |
| abstract_inverted_index.byproduct | 100 |
| abstract_inverted_index.curvature | 110 |
| abstract_inverted_index.defending | 28 |
| abstract_inverted_index.networks. | 116 |
| abstract_inverted_index.reduction | 107 |
| abstract_inverted_index.typically | 17 |
| abstract_inverted_index.14%-to-20% | 162 |
| abstract_inverted_index.Processing | 95 |
| abstract_inverted_index.ResNet-101 | 182 |
| abstract_inverted_index.complexity | 52 |
| abstract_inverted_index.extensions | 22 |
| abstract_inverted_index.frameworks | 4, 70, 104 |
| abstract_inverted_index.parameters | 136 |
| abstract_inverted_index.preserving | 83 |
| abstract_inverted_index.robustness | 73 |
| abstract_inverted_index.technique, | 88 |
| abstract_inverted_index.$10\times$) | 48 |
| abstract_inverted_index.adversarial | 1, 10, 147 |
| abstract_inverted_index.efficiency. | 86 |
| abstract_inverted_index.establishes | 176 |
| abstract_inverted_index.frameworks, | 170 |
| abstract_inverted_index.significant | 45 |
| abstract_inverted_index.augmentation | 127 |
| abstract_inverted_index.capabilities | 63 |
| abstract_inverted_index.distribution | 130 |
| abstract_inverted_index.norm-bounded | 19 |
| abstract_inverted_index.$\ell_\infty$ | 18, 55, 68, 168 |
| abstract_inverted_index.perturbations | 34, 81, 160 |
| abstract_inverted_index.single-attack | 54, 67, 102, 140, 167 |
| abstract_inverted_index.($\ell_\infty, | 78, 157 |
| abstract_inverted_index.perturbations. | 20 |
| abstract_inverted_index.state-of-the-art | 165 |
| abstract_inverted_index.well-established | 99 |
| cited_by_percentile_year | |
| countries_distinct_count | 1 |
| institutions_distinct_count | 4 |
| sustainable_development_goals[0].id | https://metadata.un.org/sdg/16 |
| sustainable_development_goals[0].score | 0.8100000023841858 |
| sustainable_development_goals[0].display_name | Peace, Justice and strong institutions |
| citation_normalized_percentile |