AI-secure / Certified-Robustness-SoK-Oldver
This repo keeps track of popular provable training and verification approaches towards robust neural networks, including leaderboards on popular datasets and paper categorization.
☆99Updated last year
Related projects: ⓘ
- A united toolbox for running major robustness verification approaches for DNNs. [S&P 2023]☆87Updated last year
- Certified defense to adversarial examples using CROWN and IBP. Also includes GPU implementation of CROWN verification algorithm (in PyTor…☆93Updated 3 years ago
- Blackbox attacks for deep neural network models☆72Updated 6 years ago
- Code for "On Adaptive Attacks to Adversarial Example Defenses"☆84Updated 3 years ago
- Code for paper "Characterizing Adversarial Subspaces Using Local Intrinsic Dimensionality".☆121Updated 3 years ago
- Repository for Certified Defenses for Adversarial Patch ICLR-2020☆32Updated 4 years ago
- Convex Layerwise Adversarial Training (COLT)☆29Updated 3 years ago
- A unified benchmark problem for data poisoning attacks☆148Updated 11 months ago
- ☆76Updated 3 years ago
- Attacking a dog vs fish classification that uses transfer learning inceptionV3☆67Updated 6 years ago
- The code is for our NeurIPS 2019 paper: https://arxiv.org/abs/1910.04749☆31Updated 4 years ago
- Code for "Diversity can be Transferred: Output Diversification for White- and Black-box Attacks"☆52Updated 3 years ago
- Interval attacks (adversarial ML)☆21Updated 5 years ago
- Code of On L-p Robustness of Decision Stumps and Trees, ICML 2020☆10Updated 4 years ago
- Code and data for the ICLR 2021 paper "Perceptual Adversarial Robustness: Defense Against Unseen Threat Models".☆54Updated 2 years ago
- CROWN: A Neural Network Verification Framework for Networks with General Activation Functions☆38Updated 5 years ago
- CLEVER (Cross-Lipschitz Extreme Value for nEtwork Robustness) is a robustness metric for deep neural networks☆60Updated 3 years ago
- Code for Stability Training with Noise (STN)☆21Updated 3 years ago
- RayS: A Ray Searching Method for Hard-label Adversarial Attack (KDD2020)☆54Updated 3 years ago
- Official implementation for paper: A New Defense Against Adversarial Images: Turning a Weakness into a Strength☆37Updated 4 years ago
- ATTA (Efficient Adversarial Training with Transferable Adversarial Examples)☆32Updated 4 years ago
- ☆53Updated last year
- ☆46Updated 3 years ago
- AAAI 2019 oral presentation☆49Updated last month
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks☆165Updated 3 years ago
- [NeurIPS 2021] Fast Certified Robust Training with Short Warmup☆23Updated last year
- Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching☆91Updated last month
- Codes for reproducing query-efficient black-box attacks in “AutoZOOM: Autoencoder-based Zeroth Order Optimization Method for Attacking B…☆56Updated 4 years ago
- ☆57Updated 2 years ago
- A rich-documented PyTorch implementation of Carlini-Wagner's L2 attack.☆59Updated 6 years ago