{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/adversarial-robustness/papers/8","list_of":"/task/adversarial-robustness","task":"Adversarial Robustness","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"repositories listed in the archive (most first), then date (newest first), then slug","page":8,"pages_in_order":18,"rows_per_page":100,"rows":[701,800],"of":1746,"counts":{"archive_papers_tagged":1746,"with_a_code_link":788,"where_syntology_ran_a_sample":261,"not_listed_spam_title":0,"listed":1746,"listed_where_code_ran":261,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":205,"every_run_a_failure_of_syntologys_instrument":56,"listed_with_a_run_with_no_instrument_failure":205,"listed_every_run_a_failure_of_syntologys_instrument":56,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/adversarial-robustness","prev":"/task/adversarial-robustness/papers/7","next":"/task/adversarial-robustness/papers/9","papers":[{"url":"/paper/adversarial-feature-desensitization","slug":"adversarial-feature-desensitization","title":"Adversarial Feature Desensitization","date":"2020-06-08","arxiv_id":"2006.04621","repositories_listed":1,"syntology":null},{"url":"/paper/consistency-regularization-for-certified","slug":"consistency-regularization-for-certified","title":"Consistency Regularization for Certified Robustness of Smoothed Classifiers","date":"2020-06-07","arxiv_id":"2006.04062","repositories_listed":1,"syntology":{"n":6,"n_ran":5,"n_constructed":0,"n_ran_checked":4,"n_instrument":1,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":4,"n_pointer_only":2,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 4 with no instrument failure: 0 honoured, 0 violated, 4 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/consistency-regularization-for-certified#ran","syntology_url":"https://syntology.ai/paper/2006.04062","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2006.04062"}},"official":{"repos":["jh-jeong/smoothing-consistency"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":4,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/robust-face-verification-via-disentangled","slug":"robust-face-verification-via-disentangled","title":"Robust Face Verification via Disentangled Representations","date":"2020-06-05","arxiv_id":"2006.03638","repositories_listed":1,"syntology":null},{"url":"/paper/benchmarking-adversarial-robustness-on-image","slug":"benchmarking-adversarial-robustness-on-image","title":"Benchmarking Adversarial Robustness on Image Classification","date":"2020-06-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/rethinking-empirical-evaluation-of","slug":"rethinking-empirical-evaluation-of","title":"Rethinking Empirical Evaluation of Adversarial Robustness Using First-Order Attack Methods","date":"2020-06-01","arxiv_id":"2006.01304","repositories_listed":1,"syntology":null},{"url":"/paper/model-based-robust-deep-learning","slug":"model-based-robust-deep-learning","title":"Model-Based Robust Deep Learning: Generalizing to Natural, Out-of-Distribution Data","date":"2020-05-20","arxiv_id":"2005.10247","repositories_listed":1,"syntology":null},{"url":"/paper/increasing-margin-adversarial-ima-training-to","slug":"increasing-margin-adversarial-ima-training-to","title":"Increasing-Margin Adversarial (IMA) Training to Improve Adversarial Robustness of Neural Networks","date":"2020-05-19","arxiv_id":"2005.09147","repositories_listed":1,"syntology":null},{"url":"/paper/on-intrinsic-dataset-properties-for","slug":"on-intrinsic-dataset-properties-for","title":"On Intrinsic Dataset Properties for Adversarial Machine Learning","date":"2020-05-19","arxiv_id":"2005.09170","repositories_listed":1,"syntology":null},{"url":"/paper/practical-traffic-space-adversarial-attacks","slug":"practical-traffic-space-adversarial-attacks","title":"Evaluating and Improving Adversarial Robustness of Machine Learning-Based Network Intrusion Detectors","date":"2020-05-15","arxiv_id":"2005.07519","repositories_listed":1,"syntology":null},{"url":"/paper/efficient-exact-verification-of-binarized","slug":"efficient-exact-verification-of-binarized","title":"Efficient Exact Verification of Binarized Neural Networks","date":"2020-05-07","arxiv_id":"2005.03597","repositories_listed":1,"syntology":{"n":3,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/efficient-exact-verification-of-binarized#ran","syntology_url":"https://syntology.ai/paper/2005.03597","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2005.03597"}},"official":{"repos":["jia-kai/eevbnn"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/enhancing-intrinsic-adversarial-robustness","slug":"enhancing-intrinsic-adversarial-robustness","title":"Enhancing Intrinsic Adversarial Robustness via Feature Pyramid Decoder","date":"2020-05-06","arxiv_id":"2005.02552","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":0,"n_instrument":3,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 3 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/enhancing-intrinsic-adversarial-robustness#ran","syntology_url":"https://syntology.ai/paper/2005.02552","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2005.02552"}},"official":{"repos":["GuanlinLee/FPD-for-Adversarial-Robustness"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official","unlocated"]}}},{"url":"/paper/proper-measure-for-adversarial-robustness","slug":"proper-measure-for-adversarial-robustness","title":"Measuring Adversarial Robustness using a Voronoi-Epsilon Adversary","date":"2020-05-06","arxiv_id":"2005.02540","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":2,"n_instrument":1,"n_unverified":0,"n_honours":2,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/proper-measure-for-adversarial-robustness#ran","syntology_url":"https://syntology.ai/paper/2005.02540","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2005.02540"}},"official":{"repos":["hjk92g/proper_measure_robustness"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/evaluating-adversarial-robustness-for-deep","slug":"evaluating-adversarial-robustness-for-deep","title":"Improving the Interpretability of fMRI Decoding using Deep Neural Networks and Adversarial Robustness","date":"2020-04-23","arxiv_id":"2004.11114","repositories_listed":1,"syntology":null},{"url":"/paper/certifying-joint-adversarial-robustness-for","slug":"certifying-joint-adversarial-robustness-for","title":"Certifying Joint Adversarial Robustness for Model Ensembles","date":"2020-04-21","arxiv_id":"2004.10250","repositories_listed":1,"syntology":{"n":2,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"0 ran · 2 unverified","sample_list":"/paper/certifying-joint-adversarial-robustness-for#ran","syntology_url":"https://syntology.ai/paper/2004.10250","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2004.10250"}},"official":{"repos":["jonas-maj/ensemble-adversarial-robustness"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":2,"ran_from_kinds":[]}}},{"url":"/paper/adversarial-attack-on-deep-learning-based","slug":"adversarial-attack-on-deep-learning-based","title":"Adversarial Attack on Deep Learning-Based Splice Localization","date":"2020-04-17","arxiv_id":"2004.08443","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-robustness-guarantees-for-random","slug":"adversarial-robustness-guarantees-for-random","title":"Adversarial Robustness Guarantees for Random Deep Neural Networks","date":"2020-04-13","arxiv_id":"2004.05923","repositories_listed":1,"syntology":{"n":5,"n_ran":3,"n_constructed":0,"n_ran_checked":1,"n_instrument":2,"n_unverified":2,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":5,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/adversarial-robustness-guarantees-for-random#ran","syntology_url":"https://syntology.ai/paper/2004.05923","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2004.05923"}},"official":{"repos":["bkiani/Adversarial-robustness-guarantees-for-random-deep-neural-networks"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/towards-achieving-adversarial-robustness-by","slug":"towards-achieving-adversarial-robustness-by","title":"Towards Achieving Adversarial Robustness by Enforcing Feature Consistency Across Bit Planes","date":"2020-04-01","arxiv_id":"2004.00306","repositories_listed":1,"syntology":null},{"url":"/paper/towards-deep-learning-models-resistant-to-2","slug":"towards-deep-learning-models-resistant-to-2","title":"Towards Deep Learning Models Resistant to Large Perturbations","date":"2020-03-30","arxiv_id":"2003.13370","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-robustness-from-self-supervised","slug":"adversarial-robustness-from-self-supervised","title":"Adversarial Robustness: From Self-Supervised Pre-Training to Fine-Tuning","date":"2020-03-28","arxiv_id":"2003.12862","repositories_listed":1,"syntology":null},{"url":"/paper/inherent-adversarial-robustness-of-deep","slug":"inherent-adversarial-robustness-of-deep","title":"Inherent Adversarial Robustness of Deep Spiking Neural Networks: Effects of Discrete Input Encoding and Non-Linear Activations","date":"2020-03-23","arxiv_id":"2003.10399","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-robustness-on-in-and-out","slug":"adversarial-robustness-on-in-and-out","title":"Adversarial Robustness on In- and Out-Distribution Improves Explainability","date":"2020-03-20","arxiv_id":"2003.09461","repositories_listed":1,"syntology":null},{"url":"/paper/toward-adversarial-robustness-via-semi","slug":"toward-adversarial-robustness-via-semi","title":"Toward Adversarial Robustness via Semi-supervised Robust Training","date":"2020-03-16","arxiv_id":"2003.06974","repositories_listed":1,"syntology":null},{"url":"/paper/arae-adversarially-robust-training-of","slug":"arae-adversarially-robust-training-of","title":"ARAE: Adversarially Robust Training of Autoencoders Improves Novelty Detection","date":"2020-03-12","arxiv_id":"2003.05669","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-machine-learning-perspectives","slug":"adversarial-machine-learning-perspectives","title":"Adversarial Machine Learning: Bayesian Perspectives","date":"2020-03-07","arxiv_id":"2003.03546","repositories_listed":1,"syntology":null},{"url":"/paper/metrics-and-methods-for-robustness-evaluation","slug":"metrics-and-methods-for-robustness-evaluation","title":"Metrics and methods for robustness evaluation of neural networks with generative models","date":"2020-03-04","arxiv_id":"2003.01993","repositories_listed":1,"syntology":null},{"url":"/paper/learn2perturb-an-end-to-end-feature","slug":"learn2perturb-an-end-to-end-feature","title":"Learn2Perturb: an End-to-end Feature Perturbation Learning to Improve Adversarial Robustness","date":"2020-03-02","arxiv_id":"2003.01090","repositories_listed":1,"syntology":{"n":6,"n_ran":6,"n_constructed":0,"n_ran_checked":6,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":6,"n_pointer_only":0,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 6 with no instrument failure: 0 honoured, 0 violated, 6 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/learn2perturb-an-end-to-end-feature#ran","syntology_url":"https://syntology.ai/paper/2003.01090","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2003.01090"}},"official":null}},{"url":"/paper/understanding-the-intrinsic-robustness-of","slug":"understanding-the-intrinsic-robustness-of","title":"Understanding the Intrinsic Robustness of Image Distributions using Conditional Generative Models","date":"2020-03-01","arxiv_id":"2003.00378","repositories_listed":1,"syntology":{"n":9,"n_ran":6,"n_constructed":0,"n_ran_checked":5,"n_instrument":1,"n_unverified":3,"n_honours":0,"n_violates":0,"n_no_contract":5,"n_pointer_only":0,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 5 with no instrument failure: 0 honoured, 0 violated, 5 with no contract checked; 1 where Syntology's instrument failed) · 3 unverified","sample_list":"/paper/understanding-the-intrinsic-robustness-of#ran","syntology_url":"https://syntology.ai/paper/2003.00378","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2003.00378"}},"official":{"repos":["xiaozhanguva/Intrinsic-Rob"],"state":"official (archive's flag): 6 ran","n_ran":6,"n_constructed":0,"n_ran_no_instrument_failure":5,"n_unverified":3,"ran_from_kinds":["official"]}}},{"url":"/paper/attacks-which-do-not-kill-training-make","slug":"attacks-which-do-not-kill-training-make","title":"Attacks Which Do Not Kill Training Make Adversarial Learning Stronger","date":"2020-02-26","arxiv_id":"2002.11242","repositories_listed":1,"syntology":null},{"url":"/paper/invariance-vs-robustness-of-neural-networks-1","slug":"invariance-vs-robustness-of-neural-networks-1","title":"Can we have it all? On the Trade-off between Spatial and Adversarial Robustness of Neural Networks","date":"2020-02-26","arxiv_id":"2002.11318","repositories_listed":1,"syntology":{"n":4,"n_ran":3,"n_constructed":0,"n_ran_checked":0,"n_instrument":3,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 3 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/invariance-vs-robustness-of-neural-networks-1#ran","syntology_url":"https://syntology.ai/paper/2002.11318","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2002.11318"}},"official":{"repos":["ksandeshk/spatial-vs-robustness"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/hold-me-tight-influence-of-discriminative","slug":"hold-me-tight-influence-of-discriminative","title":"Hold me tight! Influence of discriminative features on deep network boundaries","date":"2020-02-15","arxiv_id":"2002.06349","repositories_listed":1,"syntology":{"n":11,"n_ran":11,"n_constructed":0,"n_ran_checked":11,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":11,"n_pointer_only":0,"phrase":"11 ran (of which 0 constructed an object rather than computing a result; 11 with no instrument failure: 0 honoured, 0 violated, 11 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/hold-me-tight-influence-of-discriminative#ran","syntology_url":"https://syntology.ai/paper/2002.06349","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2002.06349"}},"official":{"repos":["LTS4/hold-me-tight"],"state":"official (archive's flag): 11 ran","n_ran":11,"n_constructed":0,"n_ran_no_instrument_failure":11,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/ceb-improves-model-robustness-1","slug":"ceb-improves-model-robustness-1","title":"CEB Improves Model Robustness","date":"2020-02-13","arxiv_id":"2002.05380","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-robustness-for-code","slug":"adversarial-robustness-for-code","title":"Adversarial Robustness for Code","date":"2020-02-11","arxiv_id":"2002.04694","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":1,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":1,"n_no_contract":0,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 1 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/adversarial-robustness-for-code#ran","syntology_url":"https://syntology.ai/paper/2002.04694","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2002.04694"}},"official":null}},{"url":"/paper/random-smoothing-might-be-unable-to-certify","slug":"random-smoothing-might-be-unable-to-certify","title":"Random Smoothing Might be Unable to Certify $\\ell_\\infty$ Robustness for High-Dimensional Images","date":"2020-02-10","arxiv_id":"2002.03517","repositories_listed":1,"syntology":{"n":8,"n_ran":7,"n_constructed":0,"n_ran_checked":4,"n_instrument":3,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":4,"n_pointer_only":1,"phrase":"7 ran (of which 0 constructed an object rather than computing a result; 4 with no instrument failure: 0 honoured, 0 violated, 4 with no contract checked; 3 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/random-smoothing-might-be-unable-to-certify#ran","syntology_url":"https://syntology.ai/paper/2002.03517","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2002.03517"}},"official":{"repos":["hongyanz/TRADES-smoothing"],"state":"official (archive's flag): 7 ran","n_ran":7,"n_constructed":0,"n_ran_no_instrument_failure":4,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/improving-the-adversarial-robustness-of","slug":"improving-the-adversarial-robustness-of","title":"Renofeation: A Simple Transfer Learning Method for Improved Adversarial Robustness","date":"2020-02-07","arxiv_id":"2002.02998","repositories_listed":1,"syntology":null},{"url":"/paper/towards-sharper-first-order-adversary-with","slug":"towards-sharper-first-order-adversary-with","title":"Towards Sharper First-Order Adversary with Quantized Gradients","date":"2020-02-01","arxiv_id":"2002.02372","repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-robustness-against-the-union-of-1","slug":"adversarial-robustness-against-the-union-of-1","title":"Adversarial Robustness Against the Union of Multiple Threat Models","date":"2020-01-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/explainability-and-adversarial-robustness-for","slug":"explainability-and-adversarial-robustness-for","title":"Explainability and Adversarial Robustness for RNNs","date":"2019-12-20","arxiv_id":"1912.09855","repositories_listed":1,"syntology":null},{"url":"/paper/apricot-a-dataset-of-physical-adversarial","slug":"apricot-a-dataset-of-physical-adversarial","title":"APRICOT: A Dataset of Physical Adversarial Attacks on Object Detection","date":"2019-12-17","arxiv_id":"1912.08166","repositories_listed":1,"syntology":null},{"url":"/paper/does-interpretability-of-neural-networks","slug":"does-interpretability-of-neural-networks","title":"An Empirical Study on the Relation between Network Interpretability and Adversarial Robustness","date":"2019-12-07","arxiv_id":"1912.03430","repositories_listed":1,"syntology":null},{"url":"/paper/an-adaptive-view-of-adversarial-robustness","slug":"an-adaptive-view-of-adversarial-robustness","title":"An Adaptive View of Adversarial Robustness from Test-time Smoothing Defense","date":"2019-11-26","arxiv_id":"1911.11881","repositories_listed":1,"syntology":null},{"url":"/paper/universal-adversarial-perturbations-to","slug":"universal-adversarial-perturbations-to","title":"Universal Adversarial Robustness of Texture and Shape-Biased Models","date":"2019-11-23","arxiv_id":"1911.10364","repositories_listed":1,"syntology":null},{"url":"/paper/utility-analysis-of-network-architectures-for","slug":"utility-analysis-of-network-architectures-for","title":"Verifiability and Predictability: Interpreting Utilities of Network Architectures for Point Cloud Processing","date":"2019-11-20","arxiv_id":"1911.09053","repositories_listed":1,"syntology":null},{"url":"/paper/advknn-adversarial-attacks-on-k-nearest","slug":"advknn-adversarial-attacks-on-k-nearest","title":"AdvKnn: Adversarial Attacks On K-Nearest Neighbor Classifiers With Approximate Gradients","date":"2019-11-15","arxiv_id":"1911.06591","repositories_listed":1,"syntology":null},{"url":"/paper/preventing-gradient-attenuation-in-lipschitz","slug":"preventing-gradient-attenuation-in-lipschitz","title":"Preventing Gradient Attenuation in Lipschitz Constrained Convolutional Networks","date":"2019-11-03","arxiv_id":"1911.00937","repositories_listed":1,"syntology":{"n":14,"n_ran":10,"n_constructed":0,"n_ran_checked":2,"n_instrument":8,"n_unverified":4,"n_honours":2,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"10 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 8 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/preventing-gradient-attenuation-in-lipschitz#ran","syntology_url":"https://syntology.ai/paper/1911.00937","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1911.00937"}},"official":{"repos":["ColinQiyangLi/LConvNet"],"state":"official (archive's flag): 10 ran","n_ran":10,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-robustness-vs-model-compression","slug":"adversarial-robustness-vs-model-compression","title":"Adversarial Robustness vs. Model Compression, or Both?","date":"2019-10-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/adversarial-patches-exploiting-contextual","slug":"adversarial-patches-exploiting-contextual","title":"Role of Spatial Context in Adversarial Robustness for Object Detection","date":"2019-09-30","arxiv_id":"1910.00068","repositories_listed":1,"syntology":{"n":7,"n_ran":5,"n_constructed":0,"n_ran_checked":5,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":5,"n_pointer_only":0,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 5 with no instrument failure: 0 honoured, 0 violated, 5 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/adversarial-patches-exploiting-contextual#ran","syntology_url":"https://syntology.ai/paper/1910.00068","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1910.00068"}},"official":{"repos":["UMBCvision/Contextual-Adversarial-Patches"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":5,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/lower-bounds-on-adversarial-robustness-from","slug":"lower-bounds-on-adversarial-robustness-from","title":"Lower Bounds on Adversarial Robustness from Optimal Transport","date":"2019-09-26","arxiv_id":"1909.12272","repositories_listed":1,"syntology":null},{"url":"/paper/mixup-inference-better-exploiting-mixup-to","slug":"mixup-inference-better-exploiting-mixup-to","title":"Mixup Inference: Better Exploiting Mixup to Defend Adversarial Attacks","date":"2019-09-25","arxiv_id":"1909.11515","repositories_listed":1,"syntology":{"n":3,"n_ran":2,"n_constructed":0,"n_ran_checked":2,"n_instrument":0,"n_unverified":1,"n_honours":2,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/mixup-inference-better-exploiting-mixup-to#ran","syntology_url":"https://syntology.ai/paper/1909.11515","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1909.11515"}},"official":{"repos":["P2333/Mixup-Inference"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/sign-opt-a-query-efficient-hard-label","slug":"sign-opt-a-query-efficient-hard-label","title":"Sign-OPT: A Query-Efficient Hard-label Adversarial Attack","date":"2019-09-24","arxiv_id":"1909.10773","repositories_listed":1,"syntology":{"n":4,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/sign-opt-a-query-efficient-hard-label#ran","syntology_url":"https://syntology.ai/paper/1909.10773","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1909.10773"}},"official":{"repos":["cmhcbb/attackbox"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-robustness-against-the-union-of","slug":"adversarial-robustness-against-the-union-of","title":"Adversarial Robustness Against the Union of Multiple Perturbation Models","date":"2019-09-09","arxiv_id":"1909.04068","repositories_listed":1,"syntology":null},{"url":"/paper/metric-learning-for-adversarial-robustness","slug":"metric-learning-for-adversarial-robustness","title":"Metric Learning for Adversarial Robustness","date":"2019-09-03","arxiv_id":"1909.00900","repositories_listed":1,"syntology":null},{"url":"/paper/protecting-neural-networks-with-hierarchical","slug":"protecting-neural-networks-with-hierarchical","title":"Protecting Neural Networks with Hierarchical Random Switching: Towards Better Robustness-Accuracy Trade-off for Stochastic Defenses","date":"2019-08-20","arxiv_id":"1908.07116","repositories_listed":1,"syntology":{"n":2,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":1,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 0 violated, 1 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/protecting-neural-networks-with-hierarchical#ran","syntology_url":"https://syntology.ai/paper/1908.07116","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1908.07116"}},"official":{"repos":["KieranXWang/HRS"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-neural-pruning","slug":"adversarial-neural-pruning","title":"Adversarial Neural Pruning with Latent Vulnerability Suppression","date":"2019-08-12","arxiv_id":"1908.04355","repositories_listed":1,"syntology":null},{"url":"/paper/robustness-properties-of-facebooks-resnext","slug":"robustness-properties-of-facebooks-resnext","title":"Robustness properties of Facebook's ResNeXt WSL models","date":"2019-07-17","arxiv_id":"1907.07640","repositories_listed":1,"syntology":{"n":4,"n_ran":4,"n_constructed":0,"n_ran_checked":1,"n_instrument":3,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":4,"phrase":"4 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 3 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/robustness-properties-of-facebooks-resnext#ran","syntology_url":"https://syntology.ai/paper/1907.07640","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1907.07640"}},"official":{"repos":["eminorhan/resnext-wsl"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/model-agnostic-dual-quality-assessment-for","slug":"model-agnostic-dual-quality-assessment-for","title":"Adversarial Robustness Assessment: Why both $L_0$ and $L_\\infty$ Attacks Are Necessary","date":"2019-06-14","arxiv_id":"1906.06026","repositories_listed":1,"syntology":null},{"url":"/paper/a-stratified-approach-to-robustness-for","slug":"a-stratified-approach-to-robustness-for","title":"Tight Certificates of Adversarial Robustness for Randomly Smoothed Classifiers","date":"2019-06-12","arxiv_id":"1906.04948","repositories_listed":1,"syntology":null},{"url":"/paper/topology-attack-and-defense-for-graph-neural","slug":"topology-attack-and-defense-for-graph-neural","title":"Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective","date":"2019-06-10","arxiv_id":"1906.04214","repositories_listed":1,"syntology":null},{"url":"/paper/beyond-adversarial-training-min-max","slug":"beyond-adversarial-training-min-max","title":"Adversarial Attack Generation Empowered by Min-Max Optimization","date":"2019-06-09","arxiv_id":"1906.03563","repositories_listed":1,"syntology":{"n":25,"n_ran":11,"n_constructed":0,"n_ran_checked":11,"n_instrument":0,"n_unverified":14,"n_honours":0,"n_violates":1,"n_no_contract":10,"n_pointer_only":0,"phrase":"11 ran (of which 0 constructed an object rather than computing a result; 11 with no instrument failure: 0 honoured, 1 violated, 10 with no contract checked; 0 where Syntology's instrument failed) · 14 unverified","sample_list":"/paper/beyond-adversarial-training-min-max#ran","syntology_url":"https://syntology.ai/paper/1906.03563","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1906.03563"}},"official":{"repos":["wangjksjtu/minmax-adv"],"state":"official (archive's flag): 11 ran","n_ran":11,"n_constructed":0,"n_ran_no_instrument_failure":11,"n_unverified":14,"ran_from_kinds":["official"]}}},{"url":"/paper/provably-robust-boosted-decision-stumps-and","slug":"provably-robust-boosted-decision-stumps-and","title":"Provably Robust Boosted Decision Stumps and Trees against Adversarial Attacks","date":"2019-06-08","arxiv_id":"1906.03526","repositories_listed":1,"syntology":{"n":12,"n_ran":10,"n_constructed":0,"n_ran_checked":10,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":10,"n_pointer_only":0,"phrase":"10 ran (of which 0 constructed an object rather than computing a result; 10 with no instrument failure: 0 honoured, 0 violated, 10 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/provably-robust-boosted-decision-stumps-and#ran","syntology_url":"https://syntology.ai/paper/1906.03526","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1906.03526"}},"official":{"repos":["max-andr/provably-robust-boosting"],"state":"official (archive's flag): 10 ran","n_ran":10,"n_constructed":0,"n_ran_no_instrument_failure":10,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/computer-vision-with-a-single-robust","slug":"computer-vision-with-a-single-robust","title":"Image Synthesis with a Single (Robust) Classifier","date":"2019-06-06","arxiv_id":"1906.09453","repositories_listed":1,"syntology":null},{"url":"/paper/are-labels-required-for-improving-adversarial","slug":"are-labels-required-for-improving-adversarial","title":"Are Labels Required for Improving Adversarial Robustness?","date":"2019-05-31","arxiv_id":"1905.13725","repositories_listed":1,"syntology":null},{"url":"/paper/reverse-kl-divergence-training-of-prior","slug":"reverse-kl-divergence-training-of-prior","title":"Reverse KL-Divergence Training of Prior Networks: Improved Uncertainty and Adversarial Robustness","date":"2019-05-31","arxiv_id":"1905.13472","repositories_listed":1,"syntology":null},{"url":"/paper/me-net-towards-effective-adversarial","slug":"me-net-towards-effective-adversarial","title":"ME-Net: Towards Effective Adversarial Robustness with Matrix Estimation","date":"2019-05-28","arxiv_id":"1905.11971","repositories_listed":1,"syntology":{"n":5,"n_ran":2,"n_constructed":0,"n_ran_checked":1,"n_instrument":1,"n_unverified":3,"n_honours":0,"n_violates":1,"n_no_contract":0,"n_pointer_only":0,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 1 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 3 unverified","sample_list":"/paper/me-net-towards-effective-adversarial#ran","syntology_url":"https://syntology.ai/paper/1905.11971","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1905.11971"}},"official":{"repos":["YyzHarry/ME-Net"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":3,"ran_from_kinds":["official"]}}},{"url":"/paper/robustness-quantification-for-classification","slug":"robustness-quantification-for-classification","title":"Adversarial Robustness Guarantees for Classification with Gaussian Processes","date":"2019-05-28","arxiv_id":"1905.11876","repositories_listed":1,"syntology":null},{"url":"/paper/scaleable-input-gradient-regularization-for","slug":"scaleable-input-gradient-regularization-for","title":"Scaleable input gradient regularization for adversarial robustness","date":"2019-05-27","arxiv_id":"1905.11468","repositories_listed":1,"syntology":{"n":11,"n_ran":9,"n_constructed":0,"n_ran_checked":8,"n_instrument":1,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":8,"n_pointer_only":1,"phrase":"9 ran (of which 0 constructed an object rather than computing a result; 8 with no instrument failure: 0 honoured, 0 violated, 8 with no contract checked; 1 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/scaleable-input-gradient-regularization-for#ran","syntology_url":"https://syntology.ai/paper/1905.11468","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1905.11468"}},"official":{"repos":["cfinlay/tulip"],"state":"official (archive's flag): 9 ran","n_ran":9,"n_constructed":0,"n_ran_no_instrument_failure":8,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/power-up-robust-graph-convolutional-network","slug":"power-up-robust-graph-convolutional-network","title":"Power up! Robust Graph Convolutional Network via Graph Powering","date":"2019-05-24","arxiv_id":"1905.10029","repositories_listed":1,"syntology":null},{"url":"/paper/what-do-adversarially-robust-models-look-at","slug":"what-do-adversarially-robust-models-look-at","title":"What Do Adversarially Robust Models Look At?","date":"2019-05-19","arxiv_id":"1905.07666","repositories_listed":1,"syntology":null},{"url":"/paper/on-the-connection-between-adversarial","slug":"on-the-connection-between-adversarial","title":"On the Connection Between Adversarial Robustness and Saliency Map Interpretability","date":"2019-05-10","arxiv_id":"1905.04172","repositories_listed":1,"syntology":{"n":16,"n_ran":6,"n_constructed":0,"n_ran_checked":6,"n_instrument":0,"n_unverified":10,"n_honours":0,"n_violates":0,"n_no_contract":6,"n_pointer_only":0,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 6 with no instrument failure: 0 honoured, 0 violated, 6 with no contract checked; 0 where Syntology's instrument failed) · 10 unverified","sample_list":"/paper/on-the-connection-between-adversarial#ran","syntology_url":"https://syntology.ai/paper/1905.04172","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1905.04172"}},"official":{"repos":["cetmann/robustness-interpretability"],"state":"official (archive's flag): 6 ran","n_ran":6,"n_constructed":0,"n_ran_no_instrument_failure":6,"n_unverified":10,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-training-and-robustness-for","slug":"adversarial-training-and-robustness-for","title":"Adversarial Training and Robustness for Multiple Perturbations","date":"2019-04-30","arxiv_id":"1904.13000","repositories_listed":1,"syntology":{"n":5,"n_ran":5,"n_constructed":0,"n_ran_checked":5,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":5,"n_pointer_only":0,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 5 with no instrument failure: 0 honoured, 0 violated, 5 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/adversarial-training-and-robustness-for#ran","syntology_url":"https://syntology.ai/paper/1904.13000","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1904.13000"}},"official":{"repos":["ftramer/MultiRobustness"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":5,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/second-rethinking-of-network-pruning-in-the","slug":"second-rethinking-of-network-pruning-in-the","title":"Adversarial Robustness vs Model Compression, or Both?","date":"2019-03-29","arxiv_id":"1903.12561","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"0 ran · 1 unverified","sample_list":"/paper/second-rethinking-of-network-pruning-in-the#ran","syntology_url":"https://syntology.ai/paper/1903.12561","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1903.12561"}},"official":{"repos":["yeshaokai/Robustness-Aware-Pruning-ADMM"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/bridging-adversarial-robustness-and-gradient","slug":"bridging-adversarial-robustness-and-gradient","title":"Bridging Adversarial Robustness and Gradient Interpretability","date":"2019-03-27","arxiv_id":"1903.11626","repositories_listed":1,"syntology":null},{"url":"/paper/on-evaluation-of-adversarial-perturbations","slug":"on-evaluation-of-adversarial-perturbations","title":"On Evaluation of Adversarial Perturbations for Sequence-to-Sequence Models","date":"2019-03-15","arxiv_id":"1903.06620","repositories_listed":1,"syntology":{"n":5,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/on-evaluation-of-adversarial-perturbations#ran","syntology_url":"https://syntology.ai/paper/1903.06620","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1903.06620"}},"official":{"repos":["pmichel31415/teapot-nlp"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/theoretical-evidence-for-adversarial","slug":"theoretical-evidence-for-adversarial","title":"Theoretical evidence for adversarial robustness through randomization","date":"2019-02-04","arxiv_id":"1902.01148","repositories_listed":1,"syntology":null},{"url":"/paper/improving-adversarial-robustness-of-ensembles","slug":"improving-adversarial-robustness-of-ensembles","title":"Improving Adversarial Robustness of Ensembles with Diversity Training","date":"2019-01-28","arxiv_id":"1901.09981","repositories_listed":1,"syntology":null},{"url":"/paper/using-pre-training-can-improve-model","slug":"using-pre-training-can-improve-model","title":"Using Pre-Training Can Improve Model Robustness and Uncertainty","date":"2019-01-28","arxiv_id":"1901.09960","repositories_listed":1,"syntology":{"n":7,"n_ran":7,"n_constructed":0,"n_ran_checked":4,"n_instrument":3,"n_unverified":0,"n_honours":0,"n_violates":1,"n_no_contract":3,"n_pointer_only":3,"phrase":"7 ran (of which 0 constructed an object rather than computing a result; 4 with no instrument failure: 0 honoured, 1 violated, 3 with no contract checked; 3 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/using-pre-training-can-improve-model#ran","syntology_url":"https://syntology.ai/paper/1901.09960","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1901.09960"}},"official":{"repos":["hendrycks/pre-training"],"state":"official (archive's flag): 7 ran","n_ran":7,"n_constructed":0,"n_ran_no_instrument_failure":4,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/training-deep-capsule-networks","slug":"training-deep-capsule-networks","title":"Increasing the adversarial robustness and explainability of capsule networks with $γ$-capsules","date":"2018-12-23","arxiv_id":"1812.09707","repositories_listed":1,"syntology":null},{"url":"/paper/max-margin-adversarial-mma-training-direct","slug":"max-margin-adversarial-mma-training-direct","title":"MMA Training: Direct Input Space Margin Maximization through Adversarial Training","date":"2018-12-06","arxiv_id":"1812.02637","repositories_listed":1,"syntology":null},{"url":"/paper/sorting-out-lipschitz-function-approximation","slug":"sorting-out-lipschitz-function-approximation","title":"Sorting out Lipschitz function approximation","date":"2018-11-13","arxiv_id":"1811.05381","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":0,"n_instrument":3,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 3 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/sorting-out-lipschitz-function-approximation#ran","syntology_url":"https://syntology.ai/paper/1811.05381","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1811.05381"}},"official":null}},{"url":"/paper/logit-pairing-methods-can-fool-gradient-based","slug":"logit-pairing-methods-can-fool-gradient-based","title":"Logit Pairing Methods Can Fool Gradient-Based Attacks","date":"2018-10-29","arxiv_id":"1810.12042","repositories_listed":1,"syntology":{"n":24,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":21,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 21 unverified","sample_list":"/paper/logit-pairing-methods-can-fool-gradient-based#ran","syntology_url":"https://syntology.ai/paper/1810.12042","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1810.12042"}},"official":{"repos":["uds-lsv/evaluating-logit-pairing-methods"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":21,"ran_from_kinds":["official"]}}},{"url":"/paper/improving-document-binarization-via","slug":"improving-document-binarization-via","title":"Improving Document Binarization via Adversarial Noise-Texture Augmentation","date":"2018-10-25","arxiv_id":"1810.11120","repositories_listed":1,"syntology":null},{"url":"/paper/improved-robustness-to-adversarial-examples","slug":"improved-robustness-to-adversarial-examples","title":"Improved robustness to adversarial examples using Lipschitz regularization of the loss","date":"2018-10-01","arxiv_id":"1810.00953","repositories_listed":1,"syntology":null},{"url":"/paper/caad-2018-generating-transferable-adversarial","slug":"caad-2018-generating-transferable-adversarial","title":"CAAD 2018: Generating Transferable Adversarial Examples","date":"2018-09-29","arxiv_id":"1810.01268","repositories_listed":1,"syntology":null},{"url":"/paper/training-for-faster-adversarial-robustness","slug":"training-for-faster-adversarial-robustness","title":"Training for Faster Adversarial Robustness Verification via Inducing ReLU Stability","date":"2018-09-09","arxiv_id":"1809.03008","repositories_listed":1,"syntology":null},{"url":"/paper/implicit-generative-modeling-of-random-noise","slug":"implicit-generative-modeling-of-random-noise","title":"Implicit Generative Modeling of Random Noise during Training for Adversarial Robustness","date":"2018-07-05","arxiv_id":"1807.02188","repositories_listed":1,"syntology":null},{"url":"/paper/autozoom-autoencoder-based-zeroth-order","slug":"autozoom-autoencoder-based-zeroth-order","title":"AutoZOOM: Autoencoder-based Zeroth Order Optimization Method for Attacking Black-box Neural Networks","date":"2018-05-30","arxiv_id":"1805.11770","repositories_listed":1,"syntology":{"n":6,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":3,"n_honours":2,"n_violates":0,"n_no_contract":1,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 2 honoured, 0 violated, 1 with no contract checked; 0 where Syntology's instrument failed) · 3 unverified","sample_list":"/paper/autozoom-autoencoder-based-zeroth-order#ran","syntology_url":"https://syntology.ai/paper/1805.11770","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1805.11770"}},"official":{"repos":["IBM/Autozoom-Attack"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":3,"ran_from_kinds":["official"]}}},{"url":"/paper/deep-defense-training-dnns-with-improved","slug":"deep-defense-training-dnns-with-improved","title":"Deep Defense: Training DNNs with Improved Adversarial Robustness","date":"2018-02-23","arxiv_id":"1803.00404","repositories_listed":1,"syntology":null},{"url":"/paper/are-generative-classifiers-more-robust-to","slug":"are-generative-classifiers-more-robust-to","title":"Are Generative Classifiers More Robust to Adversarial Attacks?","date":"2018-02-19","arxiv_id":"1802.06552","repositories_listed":1,"syntology":{"n":2,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"0 ran · 2 unverified","sample_list":"/paper/are-generative-classifiers-more-robust-to#ran","syntology_url":"https://syntology.ai/paper/1802.06552","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1802.06552"}},"official":{"repos":["deepgenerativeclassifier/DeepBayes"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":2,"ran_from_kinds":[]}}},{"url":"/paper/improving-the-adversarial-robustness-and","slug":"improving-the-adversarial-robustness-and","title":"Improving the Adversarial Robustness and Interpretability of Deep Neural Networks by Regularizing their Input Gradients","date":"2017-11-26","arxiv_id":"1711.09404","repositories_listed":1,"syntology":null},{"url":null,"slug":"tail-aware-adversarial-attacks-a","title":"Tail-aware Adversarial Attacks: A Distributional Approach to Efficient LLM Jailbreaking","date":"2025-07-06","arxiv_id":"2507.04446","repositories_listed":0,"syntology":null},{"url":null,"slug":"evaluating-the-evaluators-trust-in","title":"Evaluating the Evaluators: Trust in Adversarial Robustness Tests","date":"2025-07-04","arxiv_id":"2507.03450","repositories_listed":0,"syntology":null},{"url":null,"slug":"rectifying-adversarial-sample-with-low","title":"Rectifying Adversarial Sample with Low Entropy Prior for Test-Time Defense","date":"2025-07-04","arxiv_id":"2507.03427","repositories_listed":0,"syntology":null},{"url":null,"slug":"is-reasoning-all-you-need-probing-bias-in-the","title":"Is Reasoning All You Need? Probing Bias in the Age of Reasoning Language Models","date":"2025-07-03","arxiv_id":"2507.02799","repositories_listed":0,"syntology":null},{"url":null,"slug":"prison-unmasking-the-criminal-potential-of","title":"PRISON: Unmasking the Criminal Potential of Large Language Models","date":"2025-06-19","arxiv_id":"2506.16150","repositories_listed":0,"syntology":null},{"url":null,"slug":"intriguing-frequency-interpretation-of","title":"Intriguing Frequency Interpretation of Adversarial Robustness for CNNs and ViTs","date":"2025-06-15","arxiv_id":"2506.12875","repositories_listed":0,"syntology":null},{"url":null,"slug":"nap-tuning-neural-augmented-prompt-tuning-for","title":"NAP-Tuning: Neural Augmented Prompt Tuning for Adversarially Robust Vision-Language Models","date":"2025-06-15","arxiv_id":"2506.12706","repositories_listed":0,"syntology":null},{"url":null,"slug":"canonical-latent-representations-in","title":"Canonical Latent Representations in Conditional Diffusion Models","date":"2025-06-11","arxiv_id":"2506.09955","repositories_listed":0,"syntology":null},{"url":null,"slug":"sylva-tailoring-personalized-adversarial","title":"Sylva: Tailoring Personalized Adversarial Defense in Pre-trained Models via Collaborative Fine-tuning","date":"2025-06-04","arxiv_id":"2506.05402","repositories_listed":0,"syntology":null},{"url":null,"slug":"dynamic-epsilon-scheduling-a-multi-factor","title":"Dynamic Epsilon Scheduling: A Multi-Factor Adaptive Perturbation Budget for Adversarial Training","date":"2025-06-03","arxiv_id":"2506.04263","repositories_listed":0,"syntology":null},{"url":null,"slug":"safegenes-evaluating-the-adversarial","title":"SafeGenes: Evaluating the Adversarial Robustness of Genomic Foundation Models","date":"2025-06-01","arxiv_id":"2506.00821","repositories_listed":0,"syntology":null},{"url":null,"slug":"speech-unlearning","title":"Speech Unlearning","date":"2025-06-01","arxiv_id":"2506.00848","repositories_listed":0,"syntology":null}],"record_sha256":"a0785c93ba6574a278c91d8dc1a9f21ecae48cf72ad0c9a7686a0095007abfbd","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}