Browse State-of-the-Art › Adversarial Defense
Adversarial Defense
216 papers with code · 10 benchmarks · 5 datasets archive 2025-07-28
Competitions with currently unpublished results:
Description from the archive archive 2025-07-28.
Benchmarks archive 2025-07-28
10 leaderboard tables shown for this task, 10 with rows (a “benchmark” on this site is a table with at least one row, as on /sota), ordered by row count. “Best model” is the first row in the archive's own order at snapshot; nothing is re-ranked here and metric direction is not recorded in the archive. PwC's Trend sparklines are not in the archive, so that column is omitted.
Syntology column: samples harvested from the paper's repositories and executed on synthesized fixtures; “ran” is not a correctness claim and does not order the table. A dash means no Syntology record for that paper, not a recorded non-run. Read from the graph 2026-09-24.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
5 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
2 subtasks in the archive's task tree.
Most implemented papers archive 2025-07-28
30 shown of 216 papers with code (403 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
19 Jun 2017 59 repositories listed Syntology ran 9 of 17 samples · 8 unverified · 13 pointer-only (licence)Its principled nature also enables us to identify methods for both training and attacking neural networks that are reliable and, in a certain sense, universal.
-
28 Mar 2019 14 repositories listed Syntology ran 2 of 3 samples · 1 unverifiedThen we propose a new dataset called ImageNet-P which enables researchers to benchmark a classifier's robustness to common perturbations.
-
3 Oct 2016 13 repositories listed Syntology ran 3 of 26 samples · 23 unverified · 26 pointer-only (licence)An adversarial example library for constructing attacks, building defenses, and benchmarking both
-
8 Feb 2019 12 repositories listedWe show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the ℓ₂ norm.
-
24 Nov 2015 11 repositories listedIn this work, we formalize the space of adversaries against deep neural networks (DNNs) and introduce a novel class of algorithms to craft adversarial samples based on a precise understanding of the mapping between…
-
24 Jan 2019 9 repositories listed Syntology ran 12 of 15 samples · 3 unverified · 4 pointer-only (licence)We identify a trade-off between robustness and accuracy that serves as a guiding principle in the design of defenses against adversarial examples.
-
29 Apr 2019 6 repositories listed Syntology ran 1 of 1 samples · 0 unverified · 1 pointer-only (licence)Adversarial training, in which a network is trained on adversarial examples, is one of the few defenses against adversarial attacks that withstands strong attacks.
-
26 Nov 2018 5 repositories listed Syntology ran 1 of 1 samples · 0 unverified · 1 pointer-only (licence)However, both natural and robust accuracies, in classifying clean and adversarial images, respectively, of the trained robust models are far from satisfactory.
-
17 May 2018 5 repositories listed Syntology ran 2 of 5 samples · 3 unverified · 4 pointer-only (licence)Defense-GAN is trained to model the distribution of unperturbed images.
-
14 Aug 2017 5 repositories listed Syntology ran 1 of 1 samples · 0 unverifiedHowever, different from leveraging attack transferability from substitute models, we propose zeroth order optimization (ZOO) based attacks to directly estimate the gradients of the targeted DNN for generating…
-
23 May 2023 4 repositories listed Syntology ran 7 of 11 samples · 4 unverified · 4 pointer-only (licence)In this paper, we delve deeper into the Kullback-Leibler (KL) Divergence loss and mathematically prove that it is equivalent to the Decoupled Kullback-Leibler (DKL) Divergence loss that consists of 1) a weighted Mean…
-
18 Feb 2019 4 repositories listedCorrectly evaluating defenses against adversarial examples has proven to be extremely difficult.
-
1 Feb 2018 4 repositories listedWe identify obfuscated gradients, a kind of gradient masking, as a phenomenon that leads to a false sense of security in defenses against adversarial examples.
-
29 Jan 2018 4 repositories listedWhile neural networks have achieved high accuracy on standard image classification benchmarks, their accuracy drops to nearly zero in the presence of small adversarial perturbations to test inputs.
-
15 Nov 2017 4 repositories listed Syntology ran 0 of 8 samples · 8 unverified · 1 pointer-only (licence)This paper presents deep compositional grammatical architectures which harness the best of two worlds: grammar models and DNNs.
-
4 Aug 2023 3 repositories listedEnsuring the reliability of face recognition systems against presentation attacks necessitates the deployment of face anti-spoofing techniques.
-
24 May 2023 3 repositories listed Syntology ran 0 of 3 samples · 3 unverified · 3 pointer-only (licence)As RDC does not require training on particular adversarial attacks, we demonstrate that it is more generalizable to defend against multiple unseen threats.
-
23 Nov 2020 3 repositories listedPrevious adversarial training raises model robustness under the compromise of accuracy on natural data.
-
2 Jan 2020 3 repositories listed Syntology ran 0 of 8 samples · 8 unverifiedThere has been extensive research on developing defense techniques against adversarial attacks; however, they have been mainly designed for specific model families or application domains, therefore, they cannot be…
-
21 Aug 2019 3 repositories listed Syntology ran 3 of 18 samples · 15 unverified · 3 pointer-only (licence)To narrow in on this discrepancy between research and reality we introduce ImageNet-UA, a framework for evaluating model robustness against a range of unforeseen adversaries, including eighteen new non-L_p attacks.
-
9 Jun 2019 3 repositories listed Syntology ran 1 of 3 samples · 2 unverifiedIn this paper, we employ adversarial training to improve the performance of randomized smoothing.
-
27 Feb 2019 3 repositories listed Syntology ran 1 of 1 samples · 0 unverified · 1 pointer-only (licence)Although adversarial examples and model robustness have been extensively studied in the context of linear models and neural networks, research on this issue in tree-based models and how to make tree-based models robust…
-
20 Feb 2019 3 repositories listed Syntology ran 0 of 1 samples · 1 unverified · 1 pointer-only (licence)advertorch is a toolbox for adversarial robustness research.
-
30 Dec 2024 2 repositories listedFace recognition has witnessed remarkable advancements in recent years, thanks to the development of deep learning techniques.
-
10 Sep 2023 2 repositories listedWith the increasing deployment of deep neural networks in safety-critical applications such as self-driving cars, medical imaging, anomaly detection, etc., adversarial robustness has become a crucial concern in the…
-
10 Aug 2023 2 repositories listed Syntology ran 15 of 22 samples · 7 unverified · 22 pointer-only (licence)In this study, we develop a general mechanism to increase neural network robustness based on focus analysis.
-
14 Mar 2023 2 repositories listedTo address this problem, we propose a novel image reconstruction framework, termed SMOOTHED UNROLLING (SMUG), which advances a deep unrolling-based MRI reconstruction model using a randomized smoothing (RS)-based robust…
-
12 Oct 2022 2 repositories listed Syntology ran 1 of 1 samples · 0 unverifiedIn this work, we leverage visual prompting (VP) to improve adversarial robustness of a fixed, pre-trained model at testing time.
-
23 Feb 2022 2 repositories listedAlthough 3D point cloud classification has recently been widely deployed in different application scenarios, it is still very vulnerable to adversarial attacks.
-
23 Dec 2021 2 repositories listedWe first show that the commonly-used Fast-AT is equivalent to using a stochastic gradient algorithm to solve a linearized BLO problem involving a sign operation.
Syntology lines on 18 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections