activity
20172021
most citedThe Limitations of Adversarial Training and the Blind-Spot Attack

60 citations · 152 across the 6 of their papers we have counts for

collaborators

12 papers

cs.LG202146 cited

Robust Reinforcement Learning on State Observations with Learned Optimal Adversary

Huan Zhang, Hongge Chen, Duane Boning +1

We study the robustness of reinforcement learning (RL) with adversarially perturbed state observations, which aligns with the setting of many adversarial attacks to deep reinforcem…

cs.LG20201 cited

On -norm Robustness of Ensemble Stumps and Trees

Yihan Wang, Huan Zhang, Hongge Chen +2

Recent papers have demonstrated that ensemble stumps and trees could be vulnerable to small input perturbations, so robustness verification and defense for those models have become…

cs.LG20204 cited

Multi-Stage Influence Function

Hongge Chen, Si Si, Yang Li +4

Multi-stage training and knowledge transfer, from a large-scale pretraining task to various finetuning tasks, have revolutionized natural language processing and computer vision re…

cs.CV2019

Adversarial T-shirt! Evading Person Detectors in A Physical World

Kaidi Xu, Gaoyuan Zhang, Sijia Liu +6

It is known that deep neural networks (DNNs) are vulnerable to adversarial attacks. The so-called physical adversarial examples deceive DNN-based decisionmakers by attaching advers…

cs.LG2019

Towards Stable and Efficient Training of Verifiably Robust Neural Networks

Huan Zhang, Hongge Chen, Chaowei Xiao +5

Training neural networks with verifiable robustness guarantees is challenging. Several existing approaches utilize linear relaxation based neural network output bounds under pertur…

cs.LG2019

Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective

Kaidi Xu, Hongge Chen, Sijia Liu +4

Graph neural networks (GNNs) which apply the deep neural networks to graph data have achieved significant performance for the task of semi-supervised node classification. However,…