Research map / Adversarial robustness and security
Certified and empirical robustness: research map
1,156 accepted papers on Certified and empirical robustness in Adversarial robustness and security, from ICML, NeurIPS, ICLR, CVPR and AAAI (2016–2026), grouped into 4 clusters and 16 approaches. The busiest year so far is 2023.
Within Adversarial robustness and security, its share shrank from 38.9% in 2023–24 to 23.5% in 2025–26 (303 → 231 papers at ICML, NeurIPS, CVPR and AAAI, the venues with data for all four years).
Explore Certified and empirical robustness in the interactive map
Working on something in this topic? Describe your idea in scime atlas to see which approach it falls under, the closest papers by meaning and how crowded the spot has become.
Approaches and key papers
adversarially · generalization · overfitting · 476 papers
Approaches in this cluster:
- Robustness-accuracy trade-off analysis (148 papers)
Study adversarial training and its evaluation, including trade-offs with accuracy and weak-attack pitfalls. - Attack evaluation and defense critique (103 papers)
Analyze adversarial examples, attack strength and why defenses fail. - Adversarial training refinements (87 papers)
Reweight examples and classes or tune training to improve robustness and convergence. - Robust overfitting and regularization (79 papers)
Explain and reduce robust overfitting and improve generalization of adversarially trained models. - Theory of adversarial risk (59 papers)
Formalize adversarially robust learning, Bayes classifiers and PAC-Bayes bounds.
Most cited and most cited since 2024:
- Towards Deep Learning Models Resistant to Adversarial Attacks (ICLR 2018 · 1,508 citations)
- Theoretically Principled Trade-off between Robustness and Accuracy (ICML 2019 · 1,119 citations)
- Towards Understanding and Improving Adversarial Robustness of Vision Transformers (CVPR 2024 · 19 citations)
- Revisiting Adversarial Training Under Long-Tailed Distributions (CVPR 2024 · 18 citations)
verification · bounds · worst case · 300 papers
Approaches in this cluster:
- Provable robust learning guarantees (120 papers)
Derive worst-case guarantees and relaxations for adversarially robust training. - Neural network robustness verification (87 papers)
Certify robustness with semidefinite, probabilistic or bound-propagation verifiers. - Decision-boundary geometry of robustness (61 papers)
Analyze decision boundaries and universal perturbations to explain adversarial vulnerability. - Robustness to poisoning and multiple attacks (32 papers)
Benchmark and certify defenses against poisoning and multiple threat models.
Most cited and most cited since 2024:
- DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks (CVPR 2016 · 5,359 citations)
- Provable Defenses against Adversarial Examples via the Convex Outer Adversarial Polytope (ICML 2018 · 674 citations)
- Promoting Counterfactual Robustness through Diversity (AAAI 2024 · 8 citations)
- Clarifying the Behavior and the Difficulty of Adversarial Training (AAAI 2024 · 4 citations)
cifar · 10 · imagenet · 273 papers
Approaches in this cluster:
- Adversarial training recipes (68 papers)
Improve robust training through fast training, pretraining, teacher guidance and local features. - Regularized defenses against attacks (40 papers)
Add regularizers, detection or domain adaptation to harden networks against adversarial examples. - Augmentation and diffusion purification (30 papers)
Use mixup, augmentation and diffusion models to purify or robustify inputs. - Adversarial training with feature consistency (135 papers)
Improve robustness via information-theoretic, distillation and consistency regularizers.
Most cited and most cited since 2024:
- mixup: Beyond Empirical Risk Minimization (ICLR 2018 · 4,723 citations)
- Fast is better than free: Revisiting adversarial training (ICLR 2020 · 576 citations)
- Revisiting Adversarial Training at Scale (CVPR 2024 · 27 citations)
- AttackBench: Evaluating Gradient-based Attacks for Adversarial Examples (AAAI 2025 · 18 citations)
smoothing · randomized · certified robustness · 107 papers
Approaches in this cluster:
- Randomized smoothing certification (49 papers)
Certify robustness by smoothing classifiers with noise, extending to new norms and tasks. - Certified training and ensembles (35 papers)
Train models to be certifiably robust, including ensembles and bounded-support settings. - Provable defenses and their limits (23 papers)
Scale, break or extend certified defenses using generated data and partition aggregation.
Most cited and most cited since 2024:
- Certified Adversarial Robustness via Randomized Smoothing (ICML 2019 · 587 citations)
- Provably Robust Deep Learning via Adversarially Trained Smoothed Classifiers (NeurIPS 2019 · 261 citations)
- Diffusion Models are Certifiably Robust Classifiers (NeurIPS 2024 · 14 citations)
- MMCert: Provable Defense against Adversarial Attacks to Multi-modal Models (CVPR 2024 · 7 citations)
Related topics in Adversarial robustness and security
- Backdoor and poisoning (320)
- Black-box and transfer attacks (383)
- Attacks on text and graphs (1,088)
