activity
20192025
most citedLabel Smoothing and Logit Squeezing: A Replacement for Adversarial Training?

34 citations · 55 across the 5 of their papers we have counts for

collaborators

9 papers

cs.CV2025

Stable Diffusion Models are Secretly Good at Visual In-Context Learning

Trevine Oorloff, Vishwanath Sindagi, Wele Gedara Chaminda Bandara +4

Large language models (LLM) in natural language processing (NLP) have demonstrated great potential for in-context learning (ICL) -- the ability to leverage a few sets of example pr…

cs.CV20223 cited

Plug-In Inversion: Model-Agnostic Inversion for Vision with Data Augmentations

Amin Ghiasi, Hamid Kazemi, Steven Reich +3

Existing techniques for model inversion typically rely on hard-to-tune regularizers, such as total variation or feature regularization, which must be individually calibrated for ea…

cs.LG202117 cited

DP-InstaHide: Provably Defusing Poisoning and Backdoor Attacks with Differentially Private Data Augmentations

Eitan Borgnia, Jonas Geiping, Valeriia Cherepanova +6

Data poisoning and backdoor attacks manipulate training data to induce security breaches in a victim model. These attacks can be provably deflected using differentially private (DP…

cs.CR20201 cited

Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy Tradeoff

Eitan Borgnia, Valeriia Cherepanova, Liam Fowl +5

Data poisoning and backdoor attacks manipulate victim models by maliciously modifying training data. In light of this growing threat, a recent survey of industry professionals reve…

cs.LG2020

Towards Accurate Quantization and Pruning via Data-free Knowledge Transfer

Chen Zhu, Zheng Xu, Ali Shafahi +3

When large scale training data is available, one can obtain compact and accurate networks to be deployed in resource-constrained environments effectively through quantization and p…

cs.LG2020

Breaking certified defenses: Semantic adversarial examples with spoofed robustness certificates

Amin Ghiasi, Ali Shafahi, Tom Goldstein

To deflect adversarial attacks, a range of "certified" classifiers have been proposed. In addition to labeling an image, certified classifiers produce (when possible) a certificate…