activity
20192022
most citedDual Manifold Adversarial Robustness: Defense against Lp and non-Lp Adversarial Attacks

21 citations · 42 across the 5 of their papers we have counts for

collaborators

12 papers

cs.CV20222 cited

Invariant Learning via Diffusion Dreamed Distribution Shifts

Priyatham Kattakinda, Alexander Levine, Soheil Feizi

Though the background is an important signal for image classification, over reliance on it can lead to incorrect predictions when spurious correlations between foreground and backg…

cs.LG20223 cited

Provable Adversarial Robustness for Fractional Lp Threat Models

Alexander Levine, Soheil Feizi

In recent years, researchers have extensively studied adversarial robustness in a variety of threat models, including L_0, L_1, L_2, and L_infinity-norm bounded adversarial attacks…

cs.LG2021

Improved, Deterministic Smoothing for L_1 Certified Robustness

Alexander Levine, Soheil Feizi

Randomized smoothing is a general technique for computing sample-dependent robustness guarantees against adversarial attacks for deep classifiers. Prior works on randomized smoothi…

cs.LG2020

Certifying Confidence via Randomized Smoothing

Aounon Kumar, Alexander Levine, Soheil Feizi +1

Randomized smoothing has been shown to provide good certified-robustness guarantees for high-dimensional classification problems. It uses the probabilities of predicting the top tw…

cs.LG2020

Tight Second-Order Certificates for Randomized Smoothing

Alexander Levine, Aounon Kumar, Thomas Goldstein +1

Randomized smoothing is a popular way of providing robustness guarantees against adversarial attacks: randomly-smoothed functions have a universal Lipschitz-like bound, allowing fo…

cs.CV202021 cited

Dual Manifold Adversarial Robustness: Defense against Lp and non-Lp Adversarial Attacks

Wei-An Lin, Chun Pong Lau, Alexander Levine +2

Adversarial training is a popular defense strategy against attack threat models with bounded Lp norms. However, it often degrades the model performance on normal images and the def…