921 citations · 1k across the 13 of their papers we have counts for
16 papers
Unrestricted Adversarial Attacks on ImageNet Competition
Yuefeng Chen, Xiaofeng Mao, Yuan He +34
Many works have investigated the adversarial attacks or defenses under the settings where a bounded and imperceptible perturbation can be added to the input. However in the real-wo…
Learning Over-Parametrized Two-Layer ReLU Neural Networks beyond NTK
Yuanzhi Li, Tengyu Ma, Hongyang R. Zhang
We consider the dynamic of gradient descent for learning a two-layer neural network. We assume the input is drawn from a Gaussian distribution and the label of $…
Understanding and Improving Information Transfer in Multi-Task Learning
Sen Wu, Hongyang R. Zhang, Christopher Ré
We investigate multi-task learning approaches that use a shared feature representation for all tasks. To better understand the transfer of task information, we study an architectur…
Random Smoothing Might be Unable to Certify Robustness for High-Dimensional Images
Avrim Blum, Travis Dick, Naren Manoj +1
We show a hardness result for random smoothing to achieve certified adversarial robustness against attacks in the ball of radius when . Although random smoothing…
A Closer Look at Accuracy vs. Robustness
Yao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang +2
Current methods for training robust networks lead to a drop in test accuracy, which has led prior works to posit that a robustness-accuracy tradeoff may be inevitable in deep learn…
Self-Adaptive Training: beyond Empirical Risk Minimization
Lang Huang, Chao Zhang, Hongyang Zhang
We propose self-adaptive training---a new training algorithm that dynamically corrects problematic training labels by model predictions without incurring extra computational cost--…