{"id":13487497,"url":"https://github.com/RobustBench/robustbench","last_synced_at":"2025-03-27T22:31:26.685Z","repository":{"id":38301167,"uuid":"273564830","full_name":"RobustBench/robustbench","owner":"RobustBench","description":"RobustBench: a standardized adversarial robustness benchmark [NeurIPS 2021 Benchmarks and Datasets Track]","archived":false,"fork":false,"pushed_at":"2024-10-21T11:58:53.000Z","size":6135,"stargazers_count":660,"open_issues_count":9,"forks_count":99,"subscribers_count":9,"default_branch":"master","last_synced_at":"2024-10-21T17:16:21.041Z","etag":null,"topics":["adversarial-machine-learning","adversarial-robustness","benchmark","model-zoo"],"latest_commit_sha":null,"homepage":"https://robustbench.github.io","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/RobustBench.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":"CITATION.bib","codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-06-19T18:48:35.000Z","updated_at":"2024-10-21T04:58:20.000Z","dependencies_parsed_at":"2024-01-21T00:27:00.234Z","dependency_job_id":"167fe293-272a-4f14-a5bc-7ed8e33c136f","html_url":"https://github.com/RobustBench/robustbench","commit_stats":null,"previous_names":[],"tags_count":6,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RobustBench%2Frobustbench","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RobustBench%2Frobustbench/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RobustBench%2Frobustbench/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RobustBench%2Frobustbench/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/RobustBench","download_url":"https://codeload.github.com/RobustBench/robustbench/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":222322034,"owners_count":16966433,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["adversarial-machine-learning","adversarial-robustness","benchmark","model-zoo"],"created_at":"2024-07-31T18:01:00.060Z","updated_at":"2025-03-27T22:31:26.661Z","avatar_url":"https://github.com/RobustBench.png","language":"Python","funding_links":[],"categories":["Robustness Toolboxes","Defenses \u0026 Robustness","Python","Data Stream Processing","\u003ca id=\"tools\"\u003e\u003c/a\u003e🛠️ Tools","Safety \u0026 Robustness"],"sub_categories":["Model Evaluation"],"readme":"# RobustBench: a standardized adversarial robustness benchmark\n\n**Francesco Croce\\* (University of Tübingen), Maksym Andriushchenko\\* (EPFL), Vikash Sehwag\\* (Princeton University), Edoardo Debenedetti\\* (EPFL),\nNicolas Flammarion (EPFL), Mung Chiang (Purdue University), Prateek Mittal (Princeton University), Matthias Hein (University of Tübingen)**\n\n**Leaderboard**: [https://robustbench.github.io/](https://robustbench.github.io/)\n\n**Paper:** [https://arxiv.org/abs/2010.09670](https://arxiv.org/abs/2010.09670)\n\n**❗Note❗: if you experience problems with the automatic downloading of the models from Google Drive, install the latest version of `RobustBench` via `pip install git+https://github.com/RobustBench/robustbench.git`.**\n\n\u003cp align=\"center\"\u003e\u003cimg src=\"images/leaderboard_screenshot_linf.png\" width=\"700\"\u003e\n\u003cp align=\"center\"\u003e\u003cimg src=\"images/leaderboard_screenshot_l2.png\" width=\"700\"\u003e\n\u003cp align=\"center\"\u003e\u003cimg src=\"images/leaderboard_screenshot_corruptions.png\" width=\"700\"\u003e\n\n  \n## News\n- **May 2022**: We have extended the common corruptions leaderboard on ImageNet with [3D Common Corruptions](https://3dcommoncorruptions.epfl.ch/) (ImageNet-3DCC). ImageNet-3DCC evaluation is interesting since (1) it includes more realistic corruptions and (2) it can be used to assess generalization of the existing models which may have overfitted to ImageNet-C. For a quickstart, click [here](#new-evaluating-robustness-of-imagenet-models-against-3d-common-corruptions-imagenet-3dcc). Note that the entries in leaderboard are still sorted according to ImageNet-C performance.\n  \n- **May 2022**: We fixed the preprocessing issue for ImageNet corruption evaluations: previously we used resize to 256x256 and central crop to 224x224 which wasn't necessary since the ImageNet-C images are already 224x224 (see [this issue](https://github.com/RobustBench/robustbench/issues/59)). Note that this changed the ranking between the top-1 and top-2 entries.\n  \n  \n## Main idea\n  \nThe goal of **`RobustBench`** is to systematically track the *real* progress in adversarial robustness. \nThere are already [more than 3'000 papers](https://nicholas.carlini.com/writing/2019/all-adversarial-example-papers.html) \non this topic, but it is still often unclear which approaches really work and which only lead to [overestimated robustness](https://arxiv.org/abs/1802.00420).\nWe start from benchmarking the Linf, L2, and common corruption robustness since these are the most studied settings in the literature. \n\nEvaluation of the robustness to Lp perturbations *in general* is not straightforward and requires adaptive attacks ([Tramer et al., (2020)](https://arxiv.org/abs/2002.08347)).\nThus, in order to establish a reliable *standardized* benchmark, we need to impose some restrictions on the defenses we consider.\nIn particular, **we accept only defenses that are (1) have in general non-zero gradients wrt the inputs, (2) have a fully deterministic forward pass (i.e. no randomness) that\n(3) does not have an optimization loop.** Often, defenses that violate these 3 principles only make gradient-based attacks \nharder but do not substantially improve robustness ([Carlini et al., (2019)](https://arxiv.org/abs/1902.06705)) except those\nthat can present concrete provable guarantees (e.g. [Cohen et al., (2019)](https://arxiv.org/abs/1902.02918)). \n\nTo prevent potential overadaptation of new defenses to AutoAttack, we also welcome external evaluations based on **adaptive attacks**, especially where AutoAttack [flags](https://github.com/fra31/auto-attack/blob/master/flags_doc.md) a potential overestimation of robustness. For each model, we are interested in the best known robust accuracy and see AutoAttack and adaptive attacks as complementary to each other.\n\n**`RobustBench`** consists of two parts: \n- a website [https://robustbench.github.io/](https://robustbench.github.io/) with the leaderboard based on many recent papers (plots below 👇)\n- a collection of the most robust models, **Model Zoo**, which are easy to use for any downstream application (see the tutorial below after FAQ 👇)\n\n\u003c!-- \u003cp align=\"center\"\u003e\u003cimg src=\"images/aa_robustness_vs_venues.png\" height=\"275\"\u003e  \u003cimg src=\"images/aa_robustness_vs_years.png\" height=\"275\"\u003e\u003c/p\u003e --\u003e\n\u003c!-- \u003cp align=\"center\"\u003e\u003cimg src=\"images/aa_robustness_vs_reported.png\" height=\"260\"\u003e  \u003cimg src=\"images/aa_robustness_vs_standard.png\" height=\"260\"\u003e\u003c/p\u003e --\u003e\n\u003cp align=\"center\"\u003e\u003cimg src=\"images/plots_analysis_jsons.png\" width=\"800\"\u003e\u003c/p\u003e\n\n\n## FAQ\n\n**Q**: How does the RobustBench leaderboard differ from the [AutoAttack leaderboard](https://github.com/fra31/auto-attack)? 🤔 \\\n**A**: The [AutoAttack leaderboard](https://github.com/fra31/auto-attack) was the starting point of RobustBench. Now only the [RobustBench leaderboard](https://robustbench.github.io/) is actively maintained.\n\n**Q**: How does the RobustBench leaderboard differ from [robust-ml.org](https://www.robust-ml.org/)? 🤔 \\\n**A**: [robust-ml.org](https://www.robust-ml.org/) focuses on *adaptive* evaluations, but we provide a **standardized benchmark**. Adaptive evaluations\nhave been very useful (e.g., see [Tramer et al., 2020](https://arxiv.org/abs/2002.08347)) but they are also very time-consuming and not standardized by definition. Instead, we argue that one can estimate robustness accurately mostly *without* adaptive attacks but for this one has to introduce some restrictions on the considered models. However, we do welcome adaptive evaluations and we are always interested in showing the best known robust accuracy.\n\n**Q**: How is it related to libraries like `foolbox` / `cleverhans` / `advertorch`? 🤔 \\\n**A**: These libraries provide implementations of different *attacks*. Besides the standardized benchmark, **`RobustBench`** \nadditionally provides a repository of the most robust models. So you can start using the\nrobust models in one line of code (see the tutorial below 👇).\n\n**Q**: Why is Lp-robustness still interesting? 🤔 \\\n**A**: There are numerous interesting applications of Lp-robustness that span \ntransfer learning ([Salman et al. (2020)](https://arxiv.org/abs/2007.08489), [Utrera et al. (2020)](https://arxiv.org/abs/2007.05869)), \ninterpretability ([Tsipras et al. (2018)](https://arxiv.org/abs/1805.12152), [Kaur et al. (2019)](https://arxiv.org/abs/1910.08640), [Engstrom et al. (2019)](https://arxiv.org/abs/1906.00945)),\nsecurity ([Tramèr et al. (2018)](https://arxiv.org/abs/1811.03194), [Saadatpanah et al. (2019)](https://arxiv.org/abs/1906.07153)),\ngeneralization ([Xie et al. (2019)](https://arxiv.org/abs/1911.09665), [Zhu et al. (2019)](https://arxiv.org/abs/1909.11764), [Bochkovskiy et al. (2020)](https://arxiv.org/abs/2004.10934)), \nrobustness to unseen perturbations ([Xie et al. (2019)](https://arxiv.org/abs/1911.09665), [Kang et al. (2019)](https://arxiv.org/abs/1905.01034)),\nstabilization of GAN training ([Zhong et al. (2020)](https://arxiv.org/abs/2008.03364)).\n\n**Q**: What about verified adversarial robustness? 🤔 \\\n**A**: We mostly focus on defenses which improve empirical robustness, given the lack of clarity regarding \nwhich approaches really improve robustness and which only make some particular attacks unsuccessful.\nHowever, we do not restrict submissions of verifiably robust models (e.g., we have [Zhang et al. (2019)](https://arxiv.org/abs/1906.06316) in our CIFAR-10 Linf leaderboard).\nFor methods targeting verified robustness, we encourage the readers to check out [Salman et al. (2019)](https://arxiv.org/abs/1902.08722) \nand [Li et al. (2020)](https://arxiv.org/abs/2009.04131).\n\n**Q**: What if I have a better attack than the one used in this benchmark? 🤔 \\\n**A**: We will be happy to add a better attack or any adaptive evaluation that would complement our default standardized attacks.\n\n\n## Model Zoo: quick tour\n\nThe goal of our **Model Zoo** is to simplify the usage of robust models as much as possible. Check\nout our Colab notebook here\n👉 [RobustBench: quick start](https://colab.research.google.com/drive/1MQY_7O9vj7ixD5ilVRbdQwlNPFvxifHV)\nfor a quick introduction. It is also summarized below 👇.\n\nFirst, install the latest version of **`RobustBench`** (recommended):\n\n```bash\npip install git+https://github.com/RobustBench/robustbench.git\n```\n\nor the latest *stable* version of **`RobustBench`** (it is possible that automatic downloading of the models may not work):\n\n```bash\npip install git+https://github.com/RobustBench/robustbench.git@v1.0\n```\n\nNow let's try to load CIFAR-10 and some quite robust CIFAR-10 models from \n[Carmon2019Unlabeled](https://arxiv.org/abs/1905.13736) that achieves 59.53% robust accuracy evaluated with AA under \n`eps=8/255`:\n\n```python\nfrom robustbench.data import load_cifar10\n\nx_test, y_test = load_cifar10(n_examples=50)\n\nfrom robustbench.utils import load_model\n\nmodel = load_model(model_name='Carmon2019Unlabeled', dataset='cifar10', threat_model='Linf')\n```\n\nLet's try to evaluate the robustness of this model. We can use any favourite library for this. For example, [FoolBox](https://github.com/bethgelab/foolbox)\nimplements many different attacks. We can start from a simple PGD attack:\n```python\n!pip install -q foolbox\nimport foolbox as fb\nfmodel = fb.PyTorchModel(model, bounds=(0, 1))\n\n_, advs, success = fb.attacks.LinfPGD()(fmodel, x_test.to('cuda:0'), y_test.to('cuda:0'), epsilons=[8/255])\nprint('Robust accuracy: {:.1%}'.format(1 - success.float().mean()))\n```\n```\n\u003e\u003e\u003e Robust accuracy: 58.0%\n```\nWonderful! Can we do better with a more accurate attack?\n\nLet's try to evaluate its robustness with a cheap version [AutoAttack](https://arxiv.org/abs/2003.01690) from ICML 2020 with 2/4 attacks (only APGD-CE and APGD-DLR):\n```python\n# autoattack is installed as a dependency of robustbench so there is not need to install it separately\nfrom autoattack import AutoAttack\nadversary = AutoAttack(model, norm='Linf', eps=8/255, version='custom', attacks_to_run=['apgd-ce', 'apgd-dlr'])\nadversary.apgd.n_restarts = 1\nx_adv = adversary.run_standard_evaluation(x_test, y_test)\n```\n```\n\u003e\u003e\u003e initial accuracy: 92.00%\n\u003e\u003e\u003e apgd-ce - 1/1 - 19 out of 46 successfully perturbed\n\u003e\u003e\u003e robust accuracy after APGD-CE: 54.00% (total time 10.3 s)\n\u003e\u003e\u003e apgd-dlr - 1/1 - 1 out of 27 successfully perturbed\n\u003e\u003e\u003e robust accuracy after APGD-DLR: 52.00% (total time 17.0 s)\n\u003e\u003e\u003e max Linf perturbation: 0.03137, nan in tensor: 0, max: 1.00000, min: 0.00000\n\u003e\u003e\u003e robust accuracy: 52.00%\n```\nNote that for our standardized evaluation of Linf-robustness we use the *full* version of AutoAttack which is slower but \nmore accurate (for that just use `adversary = AutoAttack(model, norm='Linf', eps=8/255)`).\n\nWhat about other types of perturbations? Is Lp-robustness useful there? We can evaluate the available models on more general perturbations. \nFor example, let's take images corrupted by fog perturbations from CIFAR-10-C with the highest level of severity (5). \nAre different Linf robust models perform better on them?\n\n```python\nfrom robustbench.data import load_cifar10c\nfrom robustbench.utils import clean_accuracy\n\ncorruptions = ['fog']\nx_test, y_test = load_cifar10c(n_examples=1000, corruptions=corruptions, severity=5)\n\nfor model_name in ['Standard', 'Engstrom2019Robustness', 'Rice2020Overfitting',\n                   'Carmon2019Unlabeled']:\n model = load_model(model_name, dataset='cifar10', threat_model='Linf')\n acc = clean_accuracy(model, x_test, y_test)\n print(f'Model: {model_name}, CIFAR-10-C accuracy: {acc:.1%}')\n``` \n```\n\u003e\u003e\u003e Model: Standard, CIFAR-10-C accuracy: 74.4%\n\u003e\u003e\u003e Model: Engstrom2019Robustness, CIFAR-10-C accuracy: 38.8%\n\u003e\u003e\u003e Model: Rice2020Overfitting, CIFAR-10-C accuracy: 22.0%\n\u003e\u003e\u003e Model: Carmon2019Unlabeled, CIFAR-10-C accuracy: 31.1%\n```\nAs we can see, **all** these Linf robust models perform considerably worse than the standard model on this type of corruptions. \nThis curious phenomenon was first noticed in [Adversarial Examples Are a Natural Consequence of Test Error in Noise](https://arxiv.org/abs/1901.10513) \nand explained from the frequency perspective in [A Fourier Perspective on Model Robustness in Computer Vision](https://arxiv.org/abs/1906.08988). \n\nHowever, on average adversarial training *does* help on CIFAR-10-C. One can check this easily by loading all types of corruptions \nvia `load_cifar10c(n_examples=1000, severity=5)`, and repeating evaluation on them.\n\n\n### **\\*New\\***: Evaluating robustness of ImageNet models against 3D Common Corruptions (ImageNet-3DCC)\n\n3D Common Corruptions (3DCC) is a recent benchmark by [Kar et al. (CVPR 2022)](https://3dcommoncorruptions.epfl.ch/) using scene geometry to generate realistic corruptions. You can evaluate robustness of a standard ResNet-50 against ImageNet-3DCC by following these steps:\n\n1. Download the data from [here](https://github.com/EPFL-VILAB/3DCommonCorruptions#3dcc-data) using the provided tool. The data will be saved into a folder named `ImageNet-3DCC`.\n\n2. Run the sample evaluation script to obtain accuracies and save them in a pickle file:\n```python\nimport torch \nfrom robustbench.data import load_imagenet3dcc\nfrom robustbench.utils import clean_accuracy, load_model\n\ncorruptions_3dcc = ['near_focus', 'far_focus', 'bit_error', 'color_quant', \n                   'flash', 'fog_3d', 'h265_abr', 'h265_crf',\n                   'iso_noise', 'low_light', 'xy_motion_blur', 'z_motion_blur'] # 12 corruptions in ImageNet-3DCC\n\ndevice = torch.device(\"cuda:0\")\nmodel = load_model('Standard_R50', dataset='imagenet', threat_model='corruptions').to(device)\nfor corruption in corruptions_3dcc:\n    for s in [1, 2, 3, 4, 5]:  # 5 severity levels\n        x_test, y_test = load_imagenet3dcc(n_examples=5000, corruptions=[corruption], severity=s, data_dir=$PATH_IMAGENET_3DCC)\n        acc = clean_accuracy(model, x_test.to(device), y_test.to(device), device=device)\n        print(f'Model: {model_name}, ImageNet-3DCC corruption: {corruption} severity: {s} accuracy: {acc:.1%}')\n```\n\n\n\n## Model Zoo\nIn order to use a model, you just need to know its ID, e.g. **Carmon2019Unlabeled**, and to run:\n\n```python\nfrom robustbench import load_model\n\nmodel = load_model(model_name='Carmon2019Unlabeled', dataset='cifar10', threat_model='Linf')\n```\nwhich automatically downloads the model (all models are defined in `model_zoo/models.py`).\n\nReproducing evaluation of models from the Model Zoo can be done directly from the command line. Here is an example of \nan evaluation of `Salman2020Do_R18` model with AutoAttack on ImageNet for `eps=4/255=0.0156862745`:\n```python\npython -m robustbench.eval --n_ex=5000 --dataset=imagenet --threat_model=Linf --model_name=Salman2020Do_R18 --data_dir=/tmldata1/andriush/imagenet --batch_size=128 --eps=0.0156862745\n```\nThe CIFAR-10, CIFAR-10-C, CIFAR-100, and CIFAR-100-C datasets are downloaded automatically. However, the ImageNet datasets should be downloaded manually due to their licensing:\n- ImageNet: Obtain the download link [here](https://image-net.org/download.php) \n(requires just signing up from an academic email, the approval system there is automatic and happens instantly) and then follow\nthe instructions [here](https://github.com/soumith/imagenet-multiGPU.torch#data-processing) to extract the validation \nset in a pytorch-compatible format into folder `val`.\n- ImageNet-C: Please visit [here](https://github.com/hendrycks/robustness#imagenet-c) for the instructions.\n- ImageNet-3DCC: Download the data from [here](https://github.com/EPFL-VILAB/3DCommonCorruptions#3dcc-data) using the provided tool. The data will be saved into a folder named `ImageNet-3DCC`.\n\nIn order to use the models from the Model Zoo, you can find all available model IDs in the tables below. Note that the full [leaderboard](https://robustbench.github.io/) contains a bit more models which we either have not yet added to the Model Zoo or their authors don't want them to appear in the Model Zoo.\n\n\n### CIFAR-10\n\n#### Linf, eps=8/255\n| \u003csub\u003e#\u003c/sub\u003e | \u003csub\u003eModel ID\u003c/sub\u003e | \u003csub\u003ePaper\u003c/sub\u003e | \u003csub\u003eClean accuracy\u003c/sub\u003e | \u003csub\u003eRobust accuracy\u003c/sub\u003e | \u003csub\u003eArchitecture\u003c/sub\u003e | \u003csub\u003eVenue\u003c/sub\u003e |\n|:---:|---|---|:---:|:---:|:---:|:---:|\n| \u003csub\u003e**1**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bartoldson2024Adversarial_WRN-94-16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Robustness Limits via Scaling-Law and Human-Alignment Studies](https://arxiv.org/abs/2404.09349)*\u003c/sub\u003e | \u003csub\u003e93.68%\u003c/sub\u003e | \u003csub\u003e73.71%\u003c/sub\u003e | \u003csub\u003eWideResNet-94-16\u003c/sub\u003e | \u003csub\u003eICML 2024\u003c/sub\u003e |\n| \u003csub\u003e**2**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Amini2024MeanSparse_S-WRN-94-16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MeanSparse: Post-Training Robustness Enhancement Through Mean-Centered Feature Sparsification](https://arxiv.org/abs/2406.05927)*\u003c/sub\u003e | \u003csub\u003e93.60%\u003c/sub\u003e | \u003csub\u003e73.10%\u003c/sub\u003e | \u003csub\u003eMeanSparse WideResNet-94-16\u003c/sub\u003e | \u003csub\u003earXiv, Jun 2024\u003c/sub\u003e |\n| \u003csub\u003e**3**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bartoldson2024Adversarial_WRN-82-8**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Robustness Limits via Scaling-Law and Human-Alignment Studies](https://arxiv.org/abs/2404.09349)*\u003c/sub\u003e | \u003csub\u003e93.11%\u003c/sub\u003e | \u003csub\u003e71.59%\u003c/sub\u003e | \u003csub\u003eWideResNet-82-8\u003c/sub\u003e | \u003csub\u003eICML 2024\u003c/sub\u003e |\n| \u003csub\u003e**4**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Peng2023Robust**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Principles: Architectural Design Principles for Adversarially Robust CNNs](https://arxiv.org/abs/2308.16258)*\u003c/sub\u003e | \u003csub\u003e93.27%\u003c/sub\u003e | \u003csub\u003e71.07%\u003c/sub\u003e | \u003csub\u003eRaWideResNet-70-16\u003c/sub\u003e | \u003csub\u003eBMVC 2023\u003c/sub\u003e |\n| \u003csub\u003e**5**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wang2023Better_WRN-70-16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Better Diffusion Models Further Improve Adversarial Training](https://arxiv.org/abs/2302.04638)*\u003c/sub\u003e | \u003csub\u003e93.25%\u003c/sub\u003e | \u003csub\u003e70.69%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003eICML 2023\u003c/sub\u003e |\n| \u003csub\u003e**6**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bai2024MixedNUTS**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MixedNUTS: Training-Free Accuracy-Robustness Balance via Nonlinearly Mixed Classifiers](https://arxiv.org/abs/2402.02263)*\u003c/sub\u003e | \u003csub\u003e95.19%\u003c/sub\u003e | \u003csub\u003e69.71%\u003c/sub\u003e | \u003csub\u003eResNet-152 + WideResNet-70-16\u003c/sub\u003e | \u003csub\u003eTMLR, Aug 2024\u003c/sub\u003e |\n| \u003csub\u003e**7**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Amini2024MeanSparse_Ra_WRN_70_16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MeanSparse: Post-Training Robustness Enhancement Through Mean-Centered Feature Sparsification](https://arxiv.org/abs/2406.05927)*\u003c/sub\u003e | \u003csub\u003e93.24%\u003c/sub\u003e | \u003csub\u003e68.94%\u003c/sub\u003e | \u003csub\u003eMeanSparse RaWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Jun 2024\u003c/sub\u003e |\n| \u003csub\u003e**8**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bai2023Improving_edm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving the Accuracy-Robustness Trade-off of Classifiers via Adaptive Smoothing](https://arxiv.org/abs/2301.12554)*\u003c/sub\u003e | \u003csub\u003e95.23%\u003c/sub\u003e | \u003csub\u003e68.06%\u003c/sub\u003e | \u003csub\u003eResNet-152 + WideResNet-70-16 + mixing network\u003c/sub\u003e | \u003csub\u003eSIMODS 2024\u003c/sub\u003e |\n| \u003csub\u003e**9**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2023Decoupled_WRN-28-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Decoupled Kullback-Leibler Divergence Loss](https://arxiv.org/abs/2305.13948)*\u003c/sub\u003e | \u003csub\u003e92.16%\u003c/sub\u003e | \u003csub\u003e67.73%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2024\u003c/sub\u003e |\n| \u003csub\u003e**10**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wang2023Better_WRN-28-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Better Diffusion Models Further Improve Adversarial Training](https://arxiv.org/abs/2302.04638)*\u003c/sub\u003e | \u003csub\u003e92.44%\u003c/sub\u003e | \u003csub\u003e67.31%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICML 2023\u003c/sub\u003e |\n| \u003csub\u003e**11**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_70_16_cutmix_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e92.23%\u003c/sub\u003e | \u003csub\u003e66.56%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**12**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2021Improving_70_16_ddpm_100m**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Robustness using Generated Data](https://arxiv.org/abs/2110.09468)*\u003c/sub\u003e | \u003csub\u003e88.74%\u003c/sub\u003e | \u003csub\u003e66.10%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003eNeurIPS 2021\u003c/sub\u003e |\n| \u003csub\u003e**13**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_70_16_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e91.10%\u003c/sub\u003e | \u003csub\u003e65.87%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**14**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Huang2022Revisiting_WRN-A4**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Revisiting Residual Networks for Adversarial Robustness: An Architectural Perspective](https://arxiv.org/abs/2212.11005)*\u003c/sub\u003e | \u003csub\u003e91.58%\u003c/sub\u003e | \u003csub\u003e65.79%\u003c/sub\u003e | \u003csub\u003eWideResNet-A4\u003c/sub\u003e | \u003csub\u003earXiv, Dec. 2022\u003c/sub\u003e |\n| \u003csub\u003e**15**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_106_16_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e88.50%\u003c/sub\u003e | \u003csub\u003e64.58%\u003c/sub\u003e | \u003csub\u003eWideResNet-106-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**16**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_70_16_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e88.54%\u003c/sub\u003e | \u003csub\u003e64.20%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**17**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Kang2021Stable**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Stable Neural ODE with Lyapunov-Stable Equilibrium Points for Defending Against Adversarial Attacks](https://arxiv.org/abs/2110.12976)*\u003c/sub\u003e | \u003csub\u003e93.73%\u003c/sub\u003e | \u003csub\u003e64.20%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16, Neural ODE block\u003c/sub\u003e | \u003csub\u003eNeurIPS 2021\u003c/sub\u003e |\n| \u003csub\u003e**18**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Xu2023Exploring_WRN-28-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Exploring and Exploiting Decision Boundary Dynamics for Adversarial Robustness](https://arxiv.org/abs/2302.03015)*\u003c/sub\u003e | \u003csub\u003e93.69%\u003c/sub\u003e | \u003csub\u003e63.89%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICLR 2023\u003c/sub\u003e |\n| \u003csub\u003e**19**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2021Improving_28_10_ddpm_100m**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Robustness using Generated Data](https://arxiv.org/abs/2110.09468)*\u003c/sub\u003e | \u003csub\u003e87.50%\u003c/sub\u003e | \u003csub\u003e63.38%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2021\u003c/sub\u003e |\n| \u003csub\u003e**20**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Pang2022Robustness_WRN70_16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ Robustness and Accuracy Could Be Reconcilable by (Proper) Definition](https://arxiv.org/pdf/2202.10103.pdf)*\u003c/sub\u003e | \u003csub\u003e89.01%\u003c/sub\u003e | \u003csub\u003e63.35%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003eICML 2022\u003c/sub\u003e |\n| \u003csub\u003e**21**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rade2021Helper_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off](https://openreview.net/forum?id=BuD2LmNaU3a)*\u003c/sub\u003e | \u003csub\u003e91.47%\u003c/sub\u003e | \u003csub\u003e62.83%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**22**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sehwag2021Proxy_ResNest152**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?](https://arxiv.org/abs/2104.09425)*\u003c/sub\u003e | \u003csub\u003e87.30%\u003c/sub\u003e | \u003csub\u003e62.79%\u003c/sub\u003e | \u003csub\u003eResNest152\u003c/sub\u003e | \u003csub\u003eICLR 2022\u003c/sub\u003e |\n| \u003csub\u003e**23**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_28_10_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e89.48%\u003c/sub\u003e | \u003csub\u003e62.76%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**24**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Huang2021Exploring_ema**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Exploring Architectural Ingredients of Adversarially Robust Deep Neural Networks](https://arxiv.org/abs/2110.03825)*\u003c/sub\u003e | \u003csub\u003e91.23%\u003c/sub\u003e | \u003csub\u003e62.54%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-R\u003c/sub\u003e | \u003csub\u003eNeurIPS 2021\u003c/sub\u003e |\n| \u003csub\u003e**25**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Huang2021Exploring**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Exploring Architectural Ingredients of Adversarially Robust Deep Neural Networks](https://arxiv.org/abs/2110.03825)*\u003c/sub\u003e | \u003csub\u003e90.56%\u003c/sub\u003e | \u003csub\u003e61.56%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-R\u003c/sub\u003e | \u003csub\u003eNeurIPS 2021\u003c/sub\u003e |\n| \u003csub\u003e**26**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Dai2021Parameterizing**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Parameterizing Activation Functions for Adversarial Robustness](https://arxiv.org/abs/2110.05626)*\u003c/sub\u003e | \u003csub\u003e87.02%\u003c/sub\u003e | \u003csub\u003e61.55%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10-PSSiLU\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2021\u003c/sub\u003e |\n| \u003csub\u003e**27**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Pang2022Robustness_WRN28_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ Robustness and Accuracy Could Be Reconcilable by (Proper) Definition](https://arxiv.org/pdf/2202.10103.pdf)*\u003c/sub\u003e | \u003csub\u003e88.61%\u003c/sub\u003e | \u003csub\u003e61.04%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICML 2022\u003c/sub\u003e |\n| \u003csub\u003e**28**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rade2021Helper_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off](https://openreview.net/forum?id=BuD2LmNaU3a)*\u003c/sub\u003e | \u003csub\u003e88.16%\u003c/sub\u003e | \u003csub\u003e60.97%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**29**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_28_10_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e87.33%\u003c/sub\u003e | \u003csub\u003e60.73%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**30**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sridhar2021Robust_34_15**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Neural Network Robustness via Persistency of Excitation](https://arxiv.org/abs/2106.02078)*\u003c/sub\u003e | \u003csub\u003e86.53%\u003c/sub\u003e | \u003csub\u003e60.41%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-15\u003c/sub\u003e | \u003csub\u003eACC 2022\u003c/sub\u003e |\n| \u003csub\u003e**31**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sehwag2021Proxy**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?](https://arxiv.org/abs/2104.09425)*\u003c/sub\u003e | \u003csub\u003e86.68%\u003c/sub\u003e | \u003csub\u003e60.27%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICLR 2022\u003c/sub\u003e |\n| \u003csub\u003e**32**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wu2020Adversarial_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Weight Perturbation Helps Robust Generalization](https://arxiv.org/abs/2004.05884)*\u003c/sub\u003e | \u003csub\u003e88.25%\u003c/sub\u003e | \u003csub\u003e60.04%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**33**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sridhar2021Robust**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Neural Network Robustness via Persistency of Excitation](https://arxiv.org/abs/2106.02078)*\u003c/sub\u003e | \u003csub\u003e89.46%\u003c/sub\u003e | \u003csub\u003e59.66%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eACC 2022\u003c/sub\u003e |\n| \u003csub\u003e**34**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Zhang2020Geometry**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Geometry-aware Instance-reweighted Adversarial Training](https://arxiv.org/abs/2010.01736)*\u003c/sub\u003e | \u003csub\u003e89.36%\u003c/sub\u003e | \u003csub\u003e59.64%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICLR 2021\u003c/sub\u003e |\n| \u003csub\u003e**35**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Carmon2019Unlabeled**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Unlabeled Data Improves Adversarial Robustness](https://arxiv.org/abs/1905.13736)*\u003c/sub\u003e | \u003csub\u003e89.69%\u003c/sub\u003e | \u003csub\u003e59.53%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2019\u003c/sub\u003e |\n| \u003csub\u003e**36**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2021Improving_R18_ddpm_100m**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Robustness using Generated Data](https://arxiv.org/abs/2110.09468)*\u003c/sub\u003e | \u003csub\u003e87.35%\u003c/sub\u003e | \u003csub\u003e58.50%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eNeurIPS 2021\u003c/sub\u003e |\n| \u003csub\u003e**37**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2024Data_WRN_34_20**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Data filtering for efficient adversarial training](https://doi.org/10.1016/j.patcog.2024.110394)*\u003c/sub\u003e | \u003csub\u003e86.10%\u003c/sub\u003e | \u003csub\u003e58.09%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003ePattern Recognition 2024\u003c/sub\u003e |\n| \u003csub\u003e**38**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2021Towards_WRN34**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Scaling Adversarial Training to Large Perturbation Bounds](https://arxiv.org/abs/2210.09852)*\u003c/sub\u003e | \u003csub\u003e85.32%\u003c/sub\u003e | \u003csub\u003e58.04%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eECCV 2022\u003c/sub\u003e |\n| \u003csub\u003e**39**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2022Efficient_WRN_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient and Effective Augmentation Strategy for Adversarial Training](https://arxiv.org/abs/2210.15318)*\u003c/sub\u003e | \u003csub\u003e88.71%\u003c/sub\u003e | \u003csub\u003e57.81%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2022\u003c/sub\u003e |\n| \u003csub\u003e**40**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2021LTD_WRN34_20**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[LTD: Low Temperature Distillation for Robust Adversarial Training](https://arxiv.org/abs/2111.02331)*\u003c/sub\u003e | \u003csub\u003e86.03%\u003c/sub\u003e | \u003csub\u003e57.71%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003earXiv, Nov 2021\u003c/sub\u003e |\n| \u003csub\u003e**41**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rade2021Helper_R18_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off](https://openreview.net/forum?id=BuD2LmNaU3a)*\u003c/sub\u003e | \u003csub\u003e89.02%\u003c/sub\u003e | \u003csub\u003e57.67%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**42**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Jia2022LAS-AT_70_16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[LAS-AT: Adversarial Training with Learnable Attack Strategy](https://arxiv.org/abs/2203.06616)*\u003c/sub\u003e | \u003csub\u003e85.66%\u003c/sub\u003e | \u003csub\u003e57.61%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2022\u003c/sub\u003e |\n| \u003csub\u003e**43**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-L12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e91.73%\u003c/sub\u003e | \u003csub\u003e57.58%\u003c/sub\u003e | \u003csub\u003eXCiT-L12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**44**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2024Data_WRN_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Data filtering for efficient adversarial training](https://doi.org/10.1016/j.patcog.2024.110394)*\u003c/sub\u003e | \u003csub\u003e86.54%\u003c/sub\u003e | \u003csub\u003e57.30%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003ePattern Recognition 2024\u003c/sub\u003e |\n| \u003csub\u003e**45**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-M12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e91.30%\u003c/sub\u003e | \u003csub\u003e57.27%\u003c/sub\u003e | \u003csub\u003eXCiT-M12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**46**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sehwag2020Hydra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[HYDRA: Pruning Adversarially Robust Neural Networks](https://arxiv.org/abs/2002.10509)*\u003c/sub\u003e | \u003csub\u003e88.98%\u003c/sub\u003e | \u003csub\u003e57.14%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**47**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_70_16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e85.29%\u003c/sub\u003e | \u003csub\u003e57.14%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**48**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rade2021Helper_R18_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off](https://openreview.net/forum?id=BuD2LmNaU3a)*\u003c/sub\u003e | \u003csub\u003e86.86%\u003c/sub\u003e | \u003csub\u003e57.09%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**49**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2023Decoupled_WRN-34-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Decoupled Kullback-Leibler Divergence Loss](https://arxiv.org/abs/2305.13948)*\u003c/sub\u003e | \u003csub\u003e85.31%\u003c/sub\u003e | \u003csub\u003e57.09%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2024\u003c/sub\u003e |\n| \u003csub\u003e**50**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2021LTD_WRN34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[LTD: Low Temperature Distillation for Robust Adversarial Training](https://arxiv.org/abs/2111.02331)*\u003c/sub\u003e | \u003csub\u003e85.21%\u003c/sub\u003e | \u003csub\u003e56.94%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Nov 2021\u003c/sub\u003e |\n| \u003csub\u003e**51**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_34_20**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e85.64%\u003c/sub\u003e | \u003csub\u003e56.82%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**52**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_R18_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e83.53%\u003c/sub\u003e | \u003csub\u003e56.66%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**53**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wang2020Improving**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Adversarial Robustness Requires Revisiting Misclassified Examples](https://openreview.net/forum?id=rklOg6EFwS)*\u003c/sub\u003e | \u003csub\u003e87.50%\u003c/sub\u003e | \u003csub\u003e56.29%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICLR 2020\u003c/sub\u003e |\n| \u003csub\u003e**54**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Jia2022LAS-AT_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[LAS-AT: Adversarial Training with Learnable Attack Strategy](https://arxiv.org/abs/2203.06616)*\u003c/sub\u003e | \u003csub\u003e84.98%\u003c/sub\u003e | \u003csub\u003e56.26%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2022\u003c/sub\u003e |\n| \u003csub\u003e**55**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wu2020Adversarial**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Weight Perturbation Helps Robust Generalization](https://arxiv.org/abs/2004.05884)*\u003c/sub\u003e | \u003csub\u003e85.36%\u003c/sub\u003e | \u003csub\u003e56.17%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**56**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-S12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e90.06%\u003c/sub\u003e | \u003csub\u003e56.14%\u003c/sub\u003e | \u003csub\u003eXCiT-S12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**57**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sehwag2021Proxy_R18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?](https://arxiv.org/abs/2104.09425)*\u003c/sub\u003e | \u003csub\u003e84.59%\u003c/sub\u003e | \u003csub\u003e55.54%\u003c/sub\u003e | \u003csub\u003eResNet-18\u003c/sub\u003e | \u003csub\u003eICLR 2022\u003c/sub\u003e |\n| \u003csub\u003e**58**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Hendrycks2019Using**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Using Pre-Training Can Improve Model Robustness and Uncertainty](https://arxiv.org/abs/1901.09960)*\u003c/sub\u003e | \u003csub\u003e87.11%\u003c/sub\u003e | \u003csub\u003e54.92%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICML 2019\u003c/sub\u003e |\n| \u003csub\u003e**59**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Pang2020Boosting**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Boosting Adversarial Training with Hypersphere Embedding](https://arxiv.org/abs/2002.08619)*\u003c/sub\u003e | \u003csub\u003e85.14%\u003c/sub\u003e | \u003csub\u003e53.74%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**60**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2020Learnable_34_20**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Learnable Boundary Guided Adversarial Training](https://arxiv.org/abs/2011.11164)*\u003c/sub\u003e | \u003csub\u003e88.70%\u003c/sub\u003e | \u003csub\u003e53.57%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003eICCV 2021\u003c/sub\u003e |\n| \u003csub\u003e**61**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Zhang2020Attacks**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Attacks Which Do Not Kill Training Make Adversarial Learning Stronger](https://arxiv.org/abs/2002.11242)*\u003c/sub\u003e | \u003csub\u003e84.52%\u003c/sub\u003e | \u003csub\u003e53.51%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICML 2020\u003c/sub\u003e |\n| \u003csub\u003e**62**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rice2020Overfitting**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Overfitting in adversarially robust deep learning](https://arxiv.org/abs/2002.11569)*\u003c/sub\u003e | \u003csub\u003e85.34%\u003c/sub\u003e | \u003csub\u003e53.42%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003eICML 2020\u003c/sub\u003e |\n| \u003csub\u003e**63**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Huang2020Self**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Self-Adaptive Training: beyond Empirical Risk Minimization](https://arxiv.org/abs/2002.10319)*\u003c/sub\u003e | \u003csub\u003e83.48%\u003c/sub\u003e | \u003csub\u003e53.34%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**64**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Zhang2019Theoretically**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Theoretically Principled Trade-off between Robustness and Accuracy](https://arxiv.org/abs/1901.08573)*\u003c/sub\u003e | \u003csub\u003e84.92%\u003c/sub\u003e | \u003csub\u003e53.08%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICML 2019\u003c/sub\u003e |\n| \u003csub\u003e**65**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2020Learnable_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Learnable Boundary Guided Adversarial Training](https://arxiv.org/abs/2011.11164)*\u003c/sub\u003e | \u003csub\u003e88.22%\u003c/sub\u003e | \u003csub\u003e52.86%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICCV 2021\u003c/sub\u003e |\n| \u003csub\u003e**66**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2022Efficient_RN18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient and Effective Augmentation Strategy for Adversarial Training](https://arxiv.org/abs/2210.15318)*\u003c/sub\u003e | \u003csub\u003e85.71%\u003c/sub\u003e | \u003csub\u003e52.48%\u003c/sub\u003e | \u003csub\u003eResNet-18\u003c/sub\u003e | \u003csub\u003eNeurIPS 2022\u003c/sub\u003e |\n| \u003csub\u003e**67**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2020Adversarial**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Robustness: From Self-Supervised Pre-Training to Fine-Tuning](https://arxiv.org/abs/2003.12862)*\u003c/sub\u003e | \u003csub\u003e86.04%\u003c/sub\u003e | \u003csub\u003e51.56%\u003c/sub\u003e | \u003csub\u003eResNet-50 \u003cbr/\u003e (3x ensemble)\u003c/sub\u003e | \u003csub\u003eCVPR 2020\u003c/sub\u003e |\n| \u003csub\u003e**68**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2020Efficient**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient Robust Training via Backward Smoothing](https://arxiv.org/abs/2010.01278)*\u003c/sub\u003e | \u003csub\u003e85.32%\u003c/sub\u003e | \u003csub\u003e51.12%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**69**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2021Towards_RN18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Scaling Adversarial Training to Large Perturbation Bounds](https://arxiv.org/abs/2210.09852)*\u003c/sub\u003e | \u003csub\u003e80.24%\u003c/sub\u003e | \u003csub\u003e51.06%\u003c/sub\u003e | \u003csub\u003eResNet-18\u003c/sub\u003e | \u003csub\u003eECCV 2022\u003c/sub\u003e |\n| \u003csub\u003e**70**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sitawarin2020Improving**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Adversarial Robustness Through Progressive Hardening](https://arxiv.org/abs/2003.09347)*\u003c/sub\u003e | \u003csub\u003e86.84%\u003c/sub\u003e | \u003csub\u003e50.72%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2020\u003c/sub\u003e |\n| \u003csub\u003e**71**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Engstrom2019Robustness**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robustness library](https://github.com/MadryLab/robustness)*\u003c/sub\u003e | \u003csub\u003e87.03%\u003c/sub\u003e | \u003csub\u003e49.25%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eGitHub,\u003cbr\u003eOct 2019\u003c/sub\u003e |\n| \u003csub\u003e**72**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Zhang2019You**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[You Only Propagate Once: Accelerating Adversarial Training via Maximal Principle](https://arxiv.org/abs/1905.00877)*\u003c/sub\u003e | \u003csub\u003e87.20%\u003c/sub\u003e | \u003csub\u003e44.83%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2019\u003c/sub\u003e |\n| \u003csub\u003e**73**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Andriushchenko2020Understanding**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Understanding and Improving Fast Adversarial Training](https://arxiv.org/abs/2007.02617)*\u003c/sub\u003e | \u003csub\u003e79.84%\u003c/sub\u003e | \u003csub\u003e43.93%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**74**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wong2020Fast**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fast is better than free: Revisiting adversarial training](https://arxiv.org/abs/2001.03994)*\u003c/sub\u003e | \u003csub\u003e83.34%\u003c/sub\u003e | \u003csub\u003e43.21%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eICLR 2020\u003c/sub\u003e |\n| \u003csub\u003e**75**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Ding2020MMA**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MMA Training: Direct Input Space Margin Maximization through Adversarial Training](https://openreview.net/forum?id=HkeryxBtPB)*\u003c/sub\u003e | \u003csub\u003e84.36%\u003c/sub\u003e | \u003csub\u003e41.44%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-4\u003c/sub\u003e | \u003csub\u003eICLR 2020\u003c/sub\u003e |\n| \u003csub\u003e**76**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Standard**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Standardly trained model](https://github.com/RobustBench/robustbench/)*\u003c/sub\u003e | \u003csub\u003e94.78%\u003c/sub\u003e | \u003csub\u003e0.00%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eN/A\u003c/sub\u003e |\n\n\n\n#### L2, eps=0.5\n\n|   \u003csub\u003e#\u003c/sub\u003e    | \u003csub\u003eModel ID\u003c/sub\u003e                                            | \u003csub\u003ePaper\u003c/sub\u003e                                                                                                                                                               | \u003csub\u003eClean accuracy\u003c/sub\u003e | \u003csub\u003eRobust accuracy\u003c/sub\u003e |   \u003csub\u003eArchitecture\u003c/sub\u003e   |        \u003csub\u003eVenue\u003c/sub\u003e         |\n| :---------------: | -------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | :-----------------------: | :------------------------: | :-------------------------: | :-----------------------------: |\n| \u003csub\u003e**1**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Wang2023Better_WRN-70-16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Better Diffusion Models Further Improve Adversarial Training](https://arxiv.org/abs/2302.04638)*\u003c/sub\u003e | \u003csub\u003e95.54%\u003c/sub\u003e | \u003csub\u003e84.97%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Feb 2023\u003c/sub\u003e |\n| \u003csub\u003e**2**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Amini2024MeanSparse_S-WRN-70-16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MeanSparse: Post-Training Robustness Enhancement Through Mean-Centered Feature Sparsification](https://arxiv.org/abs/2406.05927)*\u003c/sub\u003e | \u003csub\u003e95.51%\u003c/sub\u003e | \u003csub\u003e84.33%\u003c/sub\u003e | \u003csub\u003eMeanSparse WideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Jun 2024\u003c/sub\u003e |\n| \u003csub\u003e**3**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wang2023Better_WRN-28-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Better Diffusion Models Further Improve Adversarial Training](https://arxiv.org/abs/2302.04638)*\u003c/sub\u003e | \u003csub\u003e95.16%\u003c/sub\u003e | \u003csub\u003e83.68%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICML 2023\u003c/sub\u003e |\n| \u003csub\u003e**4**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_70_16_cutmix_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e95.74%\u003c/sub\u003e | \u003csub\u003e82.32%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**5**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e94.74%\u003c/sub\u003e | \u003csub\u003e80.53%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**6**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_70_16_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e92.41%\u003c/sub\u003e | \u003csub\u003e80.42%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**7**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_28_10_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e91.79%\u003c/sub\u003e | \u003csub\u003e78.80%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**8**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Augustin2020Adversarial_34_10_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Robustness on In- and Out-Distribution Improves Explainability](https://arxiv.org/abs/2003.09461)*\u003c/sub\u003e | \u003csub\u003e93.96%\u003c/sub\u003e | \u003csub\u003e78.79%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eECCV 2020\u003c/sub\u003e |\n| \u003csub\u003e**9**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sehwag2021Proxy**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?](https://arxiv.org/abs/2104.09425)*\u003c/sub\u003e | \u003csub\u003e90.93%\u003c/sub\u003e | \u003csub\u003e77.24%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICLR 2022\u003c/sub\u003e |\n| \u003csub\u003e**10**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Augustin2020Adversarial_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Robustness on In- and Out-Distribution Improves Explainability](https://arxiv.org/abs/2003.09461)*\u003c/sub\u003e | \u003csub\u003e92.23%\u003c/sub\u003e | \u003csub\u003e76.25%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eECCV 2020\u003c/sub\u003e |\n| \u003csub\u003e**11**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rade2021Helper_R18_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off](https://openreview.net/forum?id=BuD2LmNaU3a)*\u003c/sub\u003e | \u003csub\u003e90.57%\u003c/sub\u003e | \u003csub\u003e76.15%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**12**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_R18_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e90.33%\u003c/sub\u003e | \u003csub\u003e75.86%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**13**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e90.90%\u003c/sub\u003e | \u003csub\u003e74.50%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**14**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sehwag2021Proxy_R18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?](https://arxiv.org/abs/2104.09425)*\u003c/sub\u003e | \u003csub\u003e89.76%\u003c/sub\u003e | \u003csub\u003e74.41%\u003c/sub\u003e | \u003csub\u003eResNet-18\u003c/sub\u003e | \u003csub\u003eICLR 2022\u003c/sub\u003e |\n| \u003csub\u003e**15**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wu2020Adversarial**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Weight Perturbation Helps Robust Generalization](https://arxiv.org/abs/2004.05884)*\u003c/sub\u003e | \u003csub\u003e88.51%\u003c/sub\u003e | \u003csub\u003e73.66%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**16**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Augustin2020Adversarial**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Robustness on In- and Out-Distribution Improves Explainability](https://arxiv.org/abs/2003.09461)*\u003c/sub\u003e | \u003csub\u003e91.08%\u003c/sub\u003e | \u003csub\u003e72.91%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eECCV 2020\u003c/sub\u003e |\n| \u003csub\u003e**17**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Engstrom2019Robustness**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robustness library](https://github.com/MadryLab/robustness)*\u003c/sub\u003e | \u003csub\u003e90.83%\u003c/sub\u003e | \u003csub\u003e69.24%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eGitHub,\u003cbr\u003eSep 2019\u003c/sub\u003e |\n| \u003csub\u003e**18**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rice2020Overfitting**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Overfitting in adversarially robust deep learning](https://arxiv.org/abs/2002.11569)*\u003c/sub\u003e | \u003csub\u003e88.67%\u003c/sub\u003e | \u003csub\u003e67.68%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eICML 2020\u003c/sub\u003e |\n| \u003csub\u003e**19**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rony2019Decoupling**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Decoupling Direction and Norm for Efficient Gradient-Based L2 Adversarial Attacks and Defenses](https://arxiv.org/abs/1811.09600)*\u003c/sub\u003e | \u003csub\u003e89.05%\u003c/sub\u003e | \u003csub\u003e66.44%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eCVPR 2019\u003c/sub\u003e |\n| \u003csub\u003e**20**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Ding2020MMA**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MMA Training: Direct Input Space Margin Maximization through Adversarial Training](https://openreview.net/forum?id=HkeryxBtPB)*\u003c/sub\u003e | \u003csub\u003e88.02%\u003c/sub\u003e | \u003csub\u003e66.09%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-4\u003c/sub\u003e | \u003csub\u003eICLR 2020\u003c/sub\u003e |\n| \u003csub\u003e**21**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Standard**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Standardly trained model](https://github.com/RobustBench/robustbench/)*\u003c/sub\u003e | \u003csub\u003e94.78%\u003c/sub\u003e | \u003csub\u003e0.00%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eN/A\u003c/sub\u003e |\n\n\n\n\n\n#### Common Corruptions\n\n|   \u003csub\u003e#\u003c/sub\u003e    | \u003csub\u003eModel ID\u003c/sub\u003e                                                 | \u003csub\u003ePaper\u003c/sub\u003e                                                                                                                      | \u003csub\u003eClean accuracy\u003c/sub\u003e | \u003csub\u003eRobust accuracy\u003c/sub\u003e |   \u003csub\u003eArchitecture\u003c/sub\u003e   |      \u003csub\u003eVenue\u003c/sub\u003e      |\n| :---------------: | ------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | :-----------------------: | :------------------------: | :-------------------------: | :------------------------: |\n| \u003csub\u003e**1**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_LRR_CARD_Deck**\u003c/sup\u003e\u003c/sub\u003e     | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e |     \u003csub\u003e96.56%\u003c/sub\u003e     |     \u003csub\u003e92.78%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |  \u003csub\u003eNeurIPS 2021\u003c/sub\u003e   |\n| \u003csub\u003e**2**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_LRR**\u003c/sup\u003e\u003c/sub\u003e               | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e |     \u003csub\u003e96.66%\u003c/sub\u003e     |     \u003csub\u003e90.94%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |  \u003csub\u003eNeurIPS 2021\u003c/sub\u003e   |\n| \u003csub\u003e**3**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_Binary_CARD_Deck**\u003c/sup\u003e\u003c/sub\u003e  | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e |     \u003csub\u003e95.09%\u003c/sub\u003e     |     \u003csub\u003e90.15%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |  \u003csub\u003eNeurIPS 2021\u003c/sub\u003e   |\n| \u003csub\u003e**4**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Kireev2021Effectiveness_RLATAugMix**\u003c/sup\u003e\u003c/sub\u003e        | \u003csub\u003e*[On the effectiveness of adversarial training against common corruptions](https://arxiv.org/abs/2103.02325)*\u003c/sub\u003e              |     \u003csub\u003e94.75%\u003c/sub\u003e     |     \u003csub\u003e89.60%\u003c/sub\u003e      |    \u003csub\u003eResNet-18\u003c/sub\u003e     | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**5**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Hendrycks2020AugMix_ResNeXt**\u003c/sup\u003e\u003c/sub\u003e               | \u003csub\u003e*[AugMix: A Simple Data Processing Method to Improve Robustness and Uncertainty](https://arxiv.org/abs/1912.02781)*\u003c/sub\u003e        |     \u003csub\u003e95.83%\u003c/sub\u003e     |     \u003csub\u003e89.09%\u003c/sub\u003e      | \u003csub\u003eResNeXt29_32x4d\u003c/sub\u003e  |    \u003csub\u003eICLR 2020\u003c/sub\u003e    |\n| \u003csub\u003e**6**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Modas2021PRIMEResNet18**\u003c/sup\u003e\u003c/sub\u003e                    | \u003csub\u003e*[PRIME: A Few Primitives Can Boost Robustness to Common Corruptions](https://arxiv.org/abs/2112.13547)*\u003c/sub\u003e                   |     \u003csub\u003e93.06%\u003c/sub\u003e     |     \u003csub\u003e89.05%\u003c/sub\u003e      |    \u003csub\u003eResNet-18\u003c/sub\u003e     | \u003csub\u003earXiv, Dec 2021\u003c/sub\u003e |\n| \u003csub\u003e**7**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Hendrycks2020AugMix_WRN**\u003c/sup\u003e\u003c/sub\u003e                   | \u003csub\u003e*[AugMix: A Simple Data Processing Method to Improve Robustness and Uncertainty](https://arxiv.org/abs/1912.02781)*\u003c/sub\u003e        |     \u003csub\u003e95.08%\u003c/sub\u003e     |     \u003csub\u003e88.82%\u003c/sub\u003e      | \u003csub\u003eWideResNet-40-2\u003c/sub\u003e  |    \u003csub\u003eICLR 2020\u003c/sub\u003e    |\n| \u003csub\u003e**8**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Kireev2021Effectiveness_RLATAugMixNoJSD**\u003c/sup\u003e\u003c/sub\u003e   | \u003csub\u003e*[On the effectiveness of adversarial training against common corruptions](https://arxiv.org/abs/2103.02325)*\u003c/sub\u003e              |     \u003csub\u003e94.77%\u003c/sub\u003e     |     \u003csub\u003e88.53%\u003c/sub\u003e      | \u003csub\u003ePreActResNet-18\u003c/sub\u003e  | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**9**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_Binary**\u003c/sup\u003e\u003c/sub\u003e            | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e |     \u003csub\u003e94.87%\u003c/sub\u003e     |     \u003csub\u003e88.32%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |  \u003csub\u003eNeurIPS 2021\u003c/sub\u003e   |\n| \u003csub\u003e**10**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_70_16_cutmix_extra_L2**\u003c/sup\u003e\u003c/sub\u003e   | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e                           |     \u003csub\u003e95.74%\u003c/sub\u003e     |     \u003csub\u003e88.23%\u003c/sub\u003e      | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**11**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Kireev2021Effectiveness_AugMixNoJSD**\u003c/sup\u003e\u003c/sub\u003e       | \u003csub\u003e*[On the effectiveness of adversarial training against common corruptions](https://arxiv.org/abs/2103.02325)*\u003c/sub\u003e              |     \u003csub\u003e94.97%\u003c/sub\u003e     |     \u003csub\u003e86.60%\u003c/sub\u003e      | \u003csub\u003ePreActResNet-18\u003c/sub\u003e  | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**12**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Kireev2021Effectiveness_Gauss50percent**\u003c/sup\u003e\u003c/sub\u003e    | \u003csub\u003e*[On the effectiveness of adversarial training against common corruptions](https://arxiv.org/abs/2103.02325)*\u003c/sub\u003e              |     \u003csub\u003e93.24%\u003c/sub\u003e     |     \u003csub\u003e85.04%\u003c/sub\u003e      | \u003csub\u003ePreActResNet-18\u003c/sub\u003e  | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**13**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Kireev2021Effectiveness_RLAT**\u003c/sup\u003e\u003c/sub\u003e              | \u003csub\u003e*[On the effectiveness of adversarial training against common corruptions](https://arxiv.org/abs/2103.02325)*\u003c/sub\u003e              |     \u003csub\u003e93.10%\u003c/sub\u003e     |     \u003csub\u003e84.10%\u003c/sub\u003e      | \u003csub\u003ePreActResNet-18\u003c/sub\u003e  | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**14**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_70_16_cutmix_extra_Linf**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e                           |     \u003csub\u003e92.23%\u003c/sub\u003e     |     \u003csub\u003e82.82%\u003c/sub\u003e      | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**15**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2022Efficient_WRN_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient and Effective Augmentation Strategy for Adversarial Training](https://artofrobust.github.io/short_paper/31.pdf)*\u003c/sub\u003e | \u003csub\u003e88.71%\u003c/sub\u003e | \u003csub\u003e80.12%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eCVPRW 2022\u003c/sub\u003e |\n| \u003csub\u003e**16**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2021Towards_WRN34**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Towards Achieving Adversarial Robustness Beyond Perceptual Limits](https://openreview.net/forum?id=SHB_znlW5G7)*\u003c/sub\u003e | \u003csub\u003e85.32%\u003c/sub\u003e | \u003csub\u003e76.78%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Apr 2021\u003c/sub\u003e |\n| \u003csub\u003e**17**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Standard**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Standardly trained model](https://github.com/RobustBench/robustbench/)*\u003c/sub\u003e | \u003csub\u003e94.78%\u003c/sub\u003e | \u003csub\u003e73.46%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eN/A\u003c/sub\u003e |\n\n\n\n### CIFAR-100\n\n#### Linf, eps=8/255 \n\n| \u003csub\u003e#\u003c/sub\u003e | \u003csub\u003eModel ID\u003c/sub\u003e | \u003csub\u003ePaper\u003c/sub\u003e | \u003csub\u003eClean accuracy\u003c/sub\u003e | \u003csub\u003eRobust accuracy\u003c/sub\u003e | \u003csub\u003eArchitecture\u003c/sub\u003e | \u003csub\u003eVenue\u003c/sub\u003e |\n|:---:|---|---|:---:|:---:|:---:|:---:|\n| \u003csub\u003e**1**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wang2023Better_WRN-70-16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Better Diffusion Models Further Improve Adversarial Training](https://arxiv.org/abs/2302.04638)*\u003c/sub\u003e | \u003csub\u003e75.22%\u003c/sub\u003e | \u003csub\u003e42.66%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003eICML 2023\u003c/sub\u003e |\n| \u003csub\u003e**2**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Amini2024MeanSparse_S-WRN-70-16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MeanSparse: Post-Training Robustness Enhancement Through Mean-Centered Feature Sparsification](https://arxiv.org/abs/2406.05927)*\u003c/sub\u003e | \u003csub\u003e75.13%\u003c/sub\u003e | \u003csub\u003e42.25%\u003c/sub\u003e | \u003csub\u003eMeanSparse WideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Jun 2024\u003c/sub\u003e |\n| \u003csub\u003e**3**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bai2024MixedNUTS**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MixedNUTS: Training-Free Accuracy-Robustness Balance via Nonlinearly Mixed Classifiers](https://arxiv.org/abs/2402.02263)*\u003c/sub\u003e | \u003csub\u003e83.08%\u003c/sub\u003e | \u003csub\u003e41.80%\u003c/sub\u003e | \u003csub\u003eResNet-152 + WideResNet-70-16\u003c/sub\u003e | \u003csub\u003eTMLR, Aug 2024\u003c/sub\u003e |\n| \u003csub\u003e**4**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2023Decoupled_WRN-28-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Decoupled Kullback-Leibler Divergence Loss](https://arxiv.org/abs/2305.13948)*\u003c/sub\u003e | \u003csub\u003e73.85%\u003c/sub\u003e | \u003csub\u003e39.18%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2024\u003c/sub\u003e |\n| \u003csub\u003e**5**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wang2023Better_WRN-28-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Better Diffusion Models Further Improve Adversarial Training](https://arxiv.org/abs/2302.04638)*\u003c/sub\u003e | \u003csub\u003e72.58%\u003c/sub\u003e | \u003csub\u003e38.77%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICML 2023\u003c/sub\u003e |\n| \u003csub\u003e**6**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bai2023Improving_edm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving the Accuracy-Robustness Trade-off of Classifiers via Adaptive Smoothing](https://arxiv.org/abs/2301.12554)*\u003c/sub\u003e | \u003csub\u003e85.21%\u003c/sub\u003e | \u003csub\u003e38.72%\u003c/sub\u003e | \u003csub\u003eResNet-152 + WideResNet-70-16 + mixing network\u003c/sub\u003e | \u003csub\u003eSIMODS 2024\u003c/sub\u003e |\n| \u003csub\u003e**7**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_extra**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e69.15%\u003c/sub\u003e | \u003csub\u003e36.88%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**8**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bai2023Improving_trades**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving the Accuracy-Robustness Trade-off of Classifiers via Adaptive Smoothing](https://arxiv.org/abs/2301.12554)*\u003c/sub\u003e | \u003csub\u003e80.18%\u003c/sub\u003e | \u003csub\u003e35.15%\u003c/sub\u003e | \u003csub\u003eResNet-152 + WideResNet-70-16 + mixing network\u003c/sub\u003e | \u003csub\u003eSIMODS 2024\u003c/sub\u003e |\n| \u003csub\u003e**9**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-L12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e70.76%\u003c/sub\u003e | \u003csub\u003e35.08%\u003c/sub\u003e | \u003csub\u003eXCiT-L12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**10**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_70_16_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e63.56%\u003c/sub\u003e | \u003csub\u003e34.64%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**11**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-M12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e69.21%\u003c/sub\u003e | \u003csub\u003e34.21%\u003c/sub\u003e | \u003csub\u003eXCiT-M12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**12**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Pang2022Robustness_WRN70_16**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ Robustness and Accuracy Could Be Reconcilable by (Proper) Definition](https://arxiv.org/pdf/2202.10103.pdf)*\u003c/sub\u003e | \u003csub\u003e65.56%\u003c/sub\u003e | \u003csub\u003e33.05%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003eICML 2022\u003c/sub\u003e |\n| \u003csub\u003e**13**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2023Decoupled_WRN-34-10_autoaug**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Decoupled Kullback-Leibler Divergence Loss](https://arxiv.org/abs/2305.13948)*\u003c/sub\u003e | \u003csub\u003e65.93%\u003c/sub\u003e | \u003csub\u003e32.52%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2024\u003c/sub\u003e |\n| \u003csub\u003e**14**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-S12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e67.34%\u003c/sub\u003e | \u003csub\u003e32.19%\u003c/sub\u003e | \u003csub\u003eXCiT-S12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**15**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_28_10_cutmix_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e62.41%\u003c/sub\u003e | \u003csub\u003e32.06%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**16**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Jia2022LAS-AT_34_20**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[LAS-AT: Adversarial Training with Learnable Attack Strategy](https://arxiv.org/abs/2203.06616)*\u003c/sub\u003e | \u003csub\u003e67.31%\u003c/sub\u003e | \u003csub\u003e31.91%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2022\u003c/sub\u003e |\n| \u003csub\u003e**17**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2023Decoupled_WRN-34-10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Decoupled Kullback-Leibler Divergence Loss](https://arxiv.org/abs/2305.13948)*\u003c/sub\u003e | \u003csub\u003e65.76%\u003c/sub\u003e | \u003csub\u003e31.91%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2024\u003c/sub\u003e |\n| \u003csub\u003e**18**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2022Efficient_WRN_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient and Effective Augmentation Strategy for Adversarial Training](https://arxiv.org/abs/2210.15318)*\u003c/sub\u003e | \u003csub\u003e68.75%\u003c/sub\u003e | \u003csub\u003e31.85%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2022\u003c/sub\u003e |\n| \u003csub\u003e**19**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2020Learnable_34_10_LBGAT9_eps_8_255**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Learnable Boundary Guided Adversarial Training](https://arxiv.org/abs/2011.11164)*\u003c/sub\u003e | \u003csub\u003e62.99%\u003c/sub\u003e | \u003csub\u003e31.20%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICCV 2021\u003c/sub\u003e |\n| \u003csub\u003e**20**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sehwag2021Proxy**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Learning Meets Generative Models: Can Proxy Distributions Improve Adversarial Robustness?](https://arxiv.org/abs/2104.09425)*\u003c/sub\u003e | \u003csub\u003e65.93%\u003c/sub\u003e | \u003csub\u003e31.15%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICLR 2022\u003c/sub\u003e |\n| \u003csub\u003e**21**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2024Data_WRN_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Data filtering for efficient adversarial training](https://doi.org/10.1016/j.patcog.2024.110394)*\u003c/sub\u003e | \u003csub\u003e64.32%\u003c/sub\u003e | \u003csub\u003e31.13%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003ePattern Recognition 2024\u003c/sub\u003e |\n| \u003csub\u003e**22**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Pang2022Robustness_WRN28_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ Robustness and Accuracy Could Be Reconcilable by (Proper) Definition](https://arxiv.org/pdf/2202.10103.pdf)*\u003c/sub\u003e | \u003csub\u003e63.66%\u003c/sub\u003e | \u003csub\u003e31.08%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICML 2022\u003c/sub\u003e |\n| \u003csub\u003e**23**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Jia2022LAS-AT_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[LAS-AT: Adversarial Training with Learnable Attack Strategy](https://arxiv.org/abs/2203.06616)*\u003c/sub\u003e | \u003csub\u003e64.89%\u003c/sub\u003e | \u003csub\u003e30.77%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2022\u003c/sub\u003e |\n| \u003csub\u003e**24**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2021LTD_WRN34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[LTD: Low Temperature Distillation for Robust Adversarial Training](https://arxiv.org/abs/2111.02331)*\u003c/sub\u003e | \u003csub\u003e64.07%\u003c/sub\u003e | \u003csub\u003e30.59%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Nov 2021\u003c/sub\u003e |\n| \u003csub\u003e**25**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2021Towards_WRN34**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Scaling Adversarial Training to Large Perturbation Bounds](https://arxiv.org/abs/2210.09852)*\u003c/sub\u003e | \u003csub\u003e65.73%\u003c/sub\u003e | \u003csub\u003e30.35%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eECCV 2022\u003c/sub\u003e |\n| \u003csub\u003e**26**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2020Learnable_34_20_LBGAT6**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Learnable Boundary Guided Adversarial Training](https://arxiv.org/abs/2011.11164)*\u003c/sub\u003e | \u003csub\u003e62.55%\u003c/sub\u003e | \u003csub\u003e30.20%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-20\u003c/sub\u003e | \u003csub\u003eICCV 2021\u003c/sub\u003e |\n| \u003csub\u003e**27**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e60.86%\u003c/sub\u003e | \u003csub\u003e30.03%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**28**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2020Learnable_34_10_LBGAT6**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Learnable Boundary Guided Adversarial Training](https://arxiv.org/abs/2011.11164)*\u003c/sub\u003e | \u003csub\u003e60.64%\u003c/sub\u003e | \u003csub\u003e29.33%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICCV 2021\u003c/sub\u003e |\n| \u003csub\u003e**29**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rade2021Helper_R18_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Helper-based Adversarial Training: Reducing Excessive Margin to Achieve a Better Accuracy vs. Robustness Trade-off](https://openreview.net/forum?id=BuD2LmNaU3a)*\u003c/sub\u003e | \u003csub\u003e61.50%\u003c/sub\u003e | \u003csub\u003e28.88%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**30**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wu2020Adversarial**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Adversarial Weight Perturbation Helps Robust Generalization](https://arxiv.org/abs/2004.05884)*\u003c/sub\u003e | \u003csub\u003e60.38%\u003c/sub\u003e | \u003csub\u003e28.86%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**31**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rebuffi2021Fixing_R18_ddpm**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fixing Data Augmentation to Improve Adversarial Robustness](https://arxiv.org/abs/2103.01946)*\u003c/sub\u003e | \u003csub\u003e56.87%\u003c/sub\u003e | \u003csub\u003e28.50%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2021\u003c/sub\u003e |\n| \u003csub\u003e**32**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Hendrycks2019Using**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Using Pre-Training Can Improve Model Robustness and Uncertainty](https://arxiv.org/abs/1901.09960)*\u003c/sub\u003e | \u003csub\u003e59.23%\u003c/sub\u003e | \u003csub\u003e28.42%\u003c/sub\u003e | \u003csub\u003eWideResNet-28-10\u003c/sub\u003e | \u003csub\u003eICML 2019\u003c/sub\u003e |\n| \u003csub\u003e**33**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2022Efficient_RN18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient and Effective Augmentation Strategy for Adversarial Training](https://arxiv.org/abs/2210.15318)*\u003c/sub\u003e | \u003csub\u003e65.45%\u003c/sub\u003e | \u003csub\u003e27.67%\u003c/sub\u003e | \u003csub\u003eResNet-18\u003c/sub\u003e | \u003csub\u003eNeurIPS 2022\u003c/sub\u003e |\n| \u003csub\u003e**34**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Cui2020Learnable_34_10_LBGAT0**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Learnable Boundary Guided Adversarial Training](https://arxiv.org/abs/2011.11164)*\u003c/sub\u003e | \u003csub\u003e70.25%\u003c/sub\u003e | \u003csub\u003e27.16%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eICCV 2021\u003c/sub\u003e |\n| \u003csub\u003e**35**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2021Towards_PARN18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Scaling Adversarial Training to Large Perturbation Bounds](https://arxiv.org/abs/2210.09852)*\u003c/sub\u003e | \u003csub\u003e62.02%\u003c/sub\u003e | \u003csub\u003e27.14%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eECCV 2022\u003c/sub\u003e |\n| \u003csub\u003e**36**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2020Efficient**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient Robust Training via Backward Smoothing](https://arxiv.org/abs/2010.01278)*\u003c/sub\u003e | \u003csub\u003e62.15%\u003c/sub\u003e | \u003csub\u003e26.94%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**37**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Sitawarin2020Improving**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Improving Adversarial Robustness Through Progressive Hardening](https://arxiv.org/abs/2003.09347)*\u003c/sub\u003e | \u003csub\u003e62.82%\u003c/sub\u003e | \u003csub\u003e24.57%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003earXiv, Mar 2020\u003c/sub\u003e |\n| \u003csub\u003e**38**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Rice2020Overfitting**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Overfitting in adversarially robust deep learning](https://arxiv.org/abs/2002.11569)*\u003c/sub\u003e | \u003csub\u003e53.83%\u003c/sub\u003e | \u003csub\u003e18.95%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eICML 2020\u003c/sub\u003e |\n\n\n#### Corruptions\n\n|   \u003csub\u003e#\u003c/sub\u003e    | \u003csub\u003eModel ID\u003c/sub\u003e                                                | \u003csub\u003ePaper\u003c/sub\u003e                                                                                                                         | \u003csub\u003eClean accuracy\u003c/sub\u003e | \u003csub\u003eRobust accuracy\u003c/sub\u003e |   \u003csub\u003eArchitecture\u003c/sub\u003e   |        \u003csub\u003eVenue\u003c/sub\u003e         |\n| :---------------: | ------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------- | :-----------------------: | :------------------------: | :-------------------------: | :-----------------------------: |\n| \u003csub\u003e**1**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_LRR_CARD_Deck**\u003c/sup\u003e\u003c/sub\u003e    | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e    |     \u003csub\u003e79.93%\u003c/sub\u003e     |     \u003csub\u003e71.08%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |     \u003csub\u003eNeurIPS 2021\u003c/sub\u003e     |\n| \u003csub\u003e**2**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_Binary_CARD_Deck**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e    |     \u003csub\u003e78.50%\u003c/sub\u003e     |     \u003csub\u003e69.09%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |     \u003csub\u003eNeurIPS 2021\u003c/sub\u003e     |\n| \u003csub\u003e**3**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Modas2021PRIMEResNet18**\u003c/sup\u003e\u003c/sub\u003e                   | \u003csub\u003e*[PRIME: A Few Primitives Can Boost Robustness to Common Corruptions](https://arxiv.org/abs/2112.13547)*\u003c/sub\u003e                      |     \u003csub\u003e77.60%\u003c/sub\u003e     |     \u003csub\u003e68.28%\u003c/sub\u003e      |    \u003csub\u003eResNet-18\u003c/sub\u003e     |   \u003csub\u003earXiv, Dec 2021\u003c/sub\u003e    |\n| \u003csub\u003e**4**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_LRR**\u003c/sup\u003e\u003c/sub\u003e              | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e    |     \u003csub\u003e78.41%\u003c/sub\u003e     |     \u003csub\u003e66.45%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |     \u003csub\u003eNeurIPS 2021\u003c/sub\u003e     |\n| \u003csub\u003e**5**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Diffenderfer2021Winning_Binary**\u003c/sup\u003e\u003c/sub\u003e           | \u003csub\u003e*[A Winning Hand: Compressing Deep Networks Can Improve Out-Of-Distribution Robustness](https://arxiv.org/abs/2106.09129)*\u003c/sub\u003e    |     \u003csub\u003e77.69%\u003c/sub\u003e     |     \u003csub\u003e65.26%\u003c/sub\u003e      | \u003csub\u003eWideResNet-18-2\u003c/sub\u003e  |     \u003csub\u003eNeurIPS 2021\u003c/sub\u003e     |\n| \u003csub\u003e**6**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Hendrycks2020AugMix_ResNeXt**\u003c/sup\u003e\u003c/sub\u003e              | \u003csub\u003e*[AugMix: A Simple Data Processing Method to Improve Robustness and Uncertainty](https://arxiv.org/abs/1912.02781)*\u003c/sub\u003e           |     \u003csub\u003e78.90%\u003c/sub\u003e     |     \u003csub\u003e65.14%\u003c/sub\u003e      | \u003csub\u003eResNeXt29_32x4d\u003c/sub\u003e  |      \u003csub\u003eICLR 2020\u003c/sub\u003e       |\n| \u003csub\u003e**7**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Hendrycks2020AugMix_WRN**\u003c/sup\u003e\u003c/sub\u003e                  | \u003csub\u003e*[AugMix: A Simple Data Processing Method to Improve Robustness and Uncertainty](https://arxiv.org/abs/1912.02781)*\u003c/sub\u003e           |     \u003csub\u003e76.28%\u003c/sub\u003e     |     \u003csub\u003e64.11%\u003c/sub\u003e      | \u003csub\u003eWideResNet-40-2\u003c/sub\u003e  |      \u003csub\u003eICLR 2020\u003c/sub\u003e       |\n| \u003csub\u003e**8**\u003c/sub\u003e  | \u003csub\u003e\u003csup\u003e**Addepalli2022Efficient_WRN_34_10**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Efficient and Effective Augmentation Strategy for Adversarial Training](https://artofrobust.github.io/short_paper/31.pdf)*\u003c/sub\u003e | \u003csub\u003e68.75%\u003c/sub\u003e | \u003csub\u003e56.95%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eCVPRW 2022\u003c/sub\u003e |\n| \u003csub\u003e**9**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_extra_Linf**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e69.15%\u003c/sub\u003e | \u003csub\u003e56.00%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n| \u003csub\u003e**10**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2021Towards_WRN34**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Towards Achieving Adversarial Robustness Beyond Perceptual Limits](https://openreview.net/forum?id=SHB_znlW5G7)*\u003c/sub\u003e | \u003csub\u003e65.73%\u003c/sub\u003e | \u003csub\u003e54.88%\u003c/sub\u003e | \u003csub\u003eWideResNet-34-10\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**11**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Addepalli2021Towards_PARN18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Towards Achieving Adversarial Robustness Beyond Perceptual Limits](https://openreview.net/forum?id=SHB_znlW5G7)*\u003c/sub\u003e | \u003csub\u003e62.02%\u003c/sub\u003e | \u003csub\u003e51.77%\u003c/sub\u003e | \u003csub\u003ePreActResNet-18\u003c/sub\u003e | \u003csub\u003eOpenReview, Jun 2021\u003c/sub\u003e |\n| \u003csub\u003e**12**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Gowal2020Uncovering_Linf**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Uncovering the Limits of Adversarial Training against Norm-Bounded Adversarial Examples](https://arxiv.org/abs/2010.03593)*\u003c/sub\u003e | \u003csub\u003e60.86%\u003c/sub\u003e | \u003csub\u003e49.46%\u003c/sub\u003e | \u003csub\u003eWideResNet-70-16\u003c/sub\u003e | \u003csub\u003earXiv, Oct 2020\u003c/sub\u003e |\n\n\n\n\n### ImageNet\n\n*Note:* the values (even clean accuracy) might have small fluctuations depending on the version of the packages e.g. `torchvision`.\n\n#### Linf, eps=4/255\n\n| \u003csub\u003e#\u003c/sub\u003e | \u003csub\u003eModel ID\u003c/sub\u003e | \u003csub\u003ePaper\u003c/sub\u003e | \u003csub\u003eClean accuracy\u003c/sub\u003e | \u003csub\u003eRobust accuracy\u003c/sub\u003e | \u003csub\u003eArchitecture\u003c/sub\u003e | \u003csub\u003eVenue\u003c/sub\u003e |\n|:---:|---|---|:---:|:---:|:---:|:---:|\n| \u003csub\u003e**1**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Xu2024MIMIR_Swin-L**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MIMIR: Masked Image Modeling for Mutual Information-based Adversarial Robustness](https://arxiv.org/abs/2312.04960)*\u003c/sub\u003e | \u003csub\u003e78.62%\u003c/sub\u003e | \u003csub\u003e59.68%\u003c/sub\u003e | \u003csub\u003eSwin-L\u003c/sub\u003e | \u003csub\u003earXiv, Dec 2023\u003c/sub\u003e |\n| \u003csub\u003e**2**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Liu2023Comprehensive_Swin-L**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Comprehensive Study on Robustness of Image Classification Models: Benchmarking and Rethinking](https://arxiv.org/abs/2302.14301)*\u003c/sub\u003e | \u003csub\u003e78.92%\u003c/sub\u003e | \u003csub\u003e59.56%\u003c/sub\u003e | \u003csub\u003eSwin-L\u003c/sub\u003e | \u003csub\u003earXiv, Feb 2023\u003c/sub\u003e |\n| \u003csub\u003e**3**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Amini2024MeanSparse_Swin-L**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MeanSparse: Post-Training Robustness Enhancement Through Mean-Centered Feature Sparsification](https://arxiv.org/abs/2406.05927)*\u003c/sub\u003e | \u003csub\u003e78.80%\u003c/sub\u003e | \u003csub\u003e58.92%\u003c/sub\u003e | \u003csub\u003eMeanSparse Swin-L\u003c/sub\u003e | \u003csub\u003earXiv, Jun 2024\u003c/sub\u003e |\n| \u003csub\u003e**4**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Bai2024MixedNUTS**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MixedNUTS: Training-Free Accuracy-Robustness Balance via Nonlinearly Mixed Classifiers](https://arxiv.org/abs/2402.02263)*\u003c/sub\u003e | \u003csub\u003e81.48%\u003c/sub\u003e | \u003csub\u003e58.50%\u003c/sub\u003e | \u003csub\u003eConvNeXtV2-L + Swin-L\u003c/sub\u003e | \u003csub\u003eTMLR, Aug 2024\u003c/sub\u003e |\n| \u003csub\u003e**5**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Liu2023Comprehensive_ConvNeXt-L**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Comprehensive Study on Robustness of Image Classification Models: Benchmarking and Rethinking](https://arxiv.org/abs/2302.14301)*\u003c/sub\u003e | \u003csub\u003e78.02%\u003c/sub\u003e | \u003csub\u003e58.48%\u003c/sub\u003e | \u003csub\u003eConvNeXt-L\u003c/sub\u003e | \u003csub\u003earXiv, Feb 2023\u003c/sub\u003e |\n| \u003csub\u003e**6**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Amini2024MeanSparse_ConvNeXt-L**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MeanSparse: Post-Training Robustness Enhancement Through Mean-Centered Feature Sparsification](https://arxiv.org/abs/2406.05927)*\u003c/sub\u003e | \u003csub\u003e77.92%\u003c/sub\u003e | \u003csub\u003e58.22%\u003c/sub\u003e | \u003csub\u003eMeanSparse ConvNeXt-L\u003c/sub\u003e | \u003csub\u003earXiv, Jun 2024\u003c/sub\u003e |\n| \u003csub\u003e**7**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Singh2023Revisiting_ConvNeXt-L-ConvStem**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat Models](https://arxiv.org/abs/2303.01870)*\u003c/sub\u003e | \u003csub\u003e77.00%\u003c/sub\u003e | \u003csub\u003e57.70%\u003c/sub\u003e | \u003csub\u003eConvNeXt-L + ConvStem\u003c/sub\u003e | \u003csub\u003eNeurIPS 2023\u003c/sub\u003e |\n| \u003csub\u003e**8**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Liu2023Comprehensive_Swin-B**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Comprehensive Study on Robustness of Image Classification Models: Benchmarking and Rethinking](https://arxiv.org/abs/2302.14301)*\u003c/sub\u003e | \u003csub\u003e76.16%\u003c/sub\u003e | \u003csub\u003e56.16%\u003c/sub\u003e | \u003csub\u003eSwin-B\u003c/sub\u003e | \u003csub\u003earXiv, Feb 2023\u003c/sub\u003e |\n| \u003csub\u003e**9**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Singh2023Revisiting_ConvNeXt-B-ConvStem**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat Models](https://arxiv.org/abs/2303.01870)*\u003c/sub\u003e | \u003csub\u003e75.90%\u003c/sub\u003e | \u003csub\u003e56.14%\u003c/sub\u003e | \u003csub\u003eConvNeXt-B + ConvStem\u003c/sub\u003e | \u003csub\u003eNeurIPS 2023\u003c/sub\u003e |\n| \u003csub\u003e**10**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Xu2024MIMIR_Swin-B**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[MIMIR: Masked Image Modeling for Mutual Information-based Adversarial Robustness](https://arxiv.org/abs/2312.04960)*\u003c/sub\u003e | \u003csub\u003e76.62%\u003c/sub\u003e | \u003csub\u003e55.90%\u003c/sub\u003e | \u003csub\u003eSwin-B\u003c/sub\u003e | \u003csub\u003earXiv, Dec 2023\u003c/sub\u003e |\n| \u003csub\u003e**11**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Liu2023Comprehensive_ConvNeXt-B**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Comprehensive Study on Robustness of Image Classification Models: Benchmarking and Rethinking](https://arxiv.org/abs/2302.14301)*\u003c/sub\u003e | \u003csub\u003e76.02%\u003c/sub\u003e | \u003csub\u003e55.82%\u003c/sub\u003e | \u003csub\u003eConvNeXt-B\u003c/sub\u003e | \u003csub\u003earXiv, Feb 2023\u003c/sub\u003e |\n| \u003csub\u003e**12**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Singh2023Revisiting_ViT-B-ConvStem**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat Models](https://arxiv.org/abs/2303.01870)*\u003c/sub\u003e | \u003csub\u003e76.30%\u003c/sub\u003e | \u003csub\u003e54.66%\u003c/sub\u003e | \u003csub\u003eViT-B + ConvStem\u003c/sub\u003e | \u003csub\u003eNeurIPS 2023\u003c/sub\u003e |\n| \u003csub\u003e**13**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**RodriguezMunoz2024Characterizing_Swin-L**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Characterizing Model Robustness via Natural Input Gradients](https://arxiv.org/abs/2409.20139)*\u003c/sub\u003e | \u003csub\u003e79.36%\u003c/sub\u003e | \u003csub\u003e53.82%\u003c/sub\u003e | \u003csub\u003eSwin-L\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2024\u003c/sub\u003e |\n| \u003csub\u003e**14**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Singh2023Revisiting_ConvNeXt-S-ConvStem**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat Models](https://arxiv.org/abs/2303.01870)*\u003c/sub\u003e | \u003csub\u003e74.10%\u003c/sub\u003e | \u003csub\u003e52.42%\u003c/sub\u003e | \u003csub\u003eConvNeXt-S + ConvStem\u003c/sub\u003e | \u003csub\u003eNeurIPS 2023\u003c/sub\u003e |\n| \u003csub\u003e**15**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**RodriguezMunoz2024Characterizing_Swin-B**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Characterizing Model Robustness via Natural Input Gradients](https://arxiv.org/abs/2409.20139)*\u003c/sub\u003e | \u003csub\u003e77.76%\u003c/sub\u003e | \u003csub\u003e51.56%\u003c/sub\u003e | \u003csub\u003eSwin-B\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2024\u003c/sub\u003e |\n| \u003csub\u003e**16**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Singh2023Revisiting_ConvNeXt-T-ConvStem**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat Models](https://arxiv.org/abs/2303.01870)*\u003c/sub\u003e | \u003csub\u003e72.72%\u003c/sub\u003e | \u003csub\u003e49.46%\u003c/sub\u003e | \u003csub\u003eConvNeXt-T + ConvStem\u003c/sub\u003e | \u003csub\u003eNeurIPS 2023\u003c/sub\u003e |\n| \u003csub\u003e**17**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Peng2023Robust**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robust Principles: Architectural Design Principles for Adversarially Robust CNNs](https://arxiv.org/abs/2308.16258)*\u003c/sub\u003e | \u003csub\u003e73.44%\u003c/sub\u003e | \u003csub\u003e48.94%\u003c/sub\u003e | \u003csub\u003eRaWideResNet-101-2\u003c/sub\u003e | \u003csub\u003eBMVC 2023\u003c/sub\u003e |\n| \u003csub\u003e**18**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Singh2023Revisiting_ViT-S-ConvStem**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Revisiting Adversarial Training for ImageNet: Architectures, Training and Generalization across Threat Models](https://arxiv.org/abs/2303.01870)*\u003c/sub\u003e | \u003csub\u003e72.56%\u003c/sub\u003e | \u003csub\u003e48.08%\u003c/sub\u003e | \u003csub\u003eViT-S + ConvStem\u003c/sub\u003e | \u003csub\u003eNeurIPS 2023\u003c/sub\u003e |\n| \u003csub\u003e**19**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-L12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e73.76%\u003c/sub\u003e | \u003csub\u003e47.60%\u003c/sub\u003e | \u003csub\u003eXCiT-L12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**20**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-M12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e74.04%\u003c/sub\u003e | \u003csub\u003e45.24%\u003c/sub\u003e | \u003csub\u003eXCiT-M12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**21**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Debenedetti2022Light_XCiT-S12**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[A Light Recipe to Train Robust Vision Transformers](https://arxiv.org/abs/2209.07399)*\u003c/sub\u003e | \u003csub\u003e72.34%\u003c/sub\u003e | \u003csub\u003e41.78%\u003c/sub\u003e | \u003csub\u003eXCiT-S12\u003c/sub\u003e | \u003csub\u003earXiv, Sep 2022\u003c/sub\u003e |\n| \u003csub\u003e**22**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Chen2024Data_WRN_50_2**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Data filtering for efficient adversarial training](https://doi.org/10.1016/j.patcog.2024.110394)*\u003c/sub\u003e | \u003csub\u003e68.76%\u003c/sub\u003e | \u003csub\u003e40.60%\u003c/sub\u003e | \u003csub\u003eWideResNet-50-2\u003c/sub\u003e | \u003csub\u003ePattern Recognition 2024\u003c/sub\u003e |\n| \u003csub\u003e**23**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Mo2022When_Swin-B**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[When Adversarial Training Meets Vision Transformers: Recipes from Training to Architecture](https://arxiv.org/abs/2210.07540)*\u003c/sub\u003e | \u003csub\u003e74.66%\u003c/sub\u003e | \u003csub\u003e38.30%\u003c/sub\u003e | \u003csub\u003eSwin-B\u003c/sub\u003e | \u003csub\u003eNeurIPS 2022\u003c/sub\u003e |\n| \u003csub\u003e**24**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Salman2020Do_50_2**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Do Adversarially Robust ImageNet Models Transfer Better?](https://arxiv.org/abs/2007.08489)*\u003c/sub\u003e | \u003csub\u003e68.46%\u003c/sub\u003e | \u003csub\u003e38.14%\u003c/sub\u003e | \u003csub\u003eWideResNet-50-2\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**25**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Salman2020Do_R50**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Do Adversarially Robust ImageNet Models Transfer Better?](https://arxiv.org/abs/2007.08489)*\u003c/sub\u003e | \u003csub\u003e64.02%\u003c/sub\u003e | \u003csub\u003e34.96%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**26**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Mo2022When_ViT-B**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[When Adversarial Training Meets Vision Transformers: Recipes from Training to Architecture](https://arxiv.org/abs/2210.07540)*\u003c/sub\u003e | \u003csub\u003e68.38%\u003c/sub\u003e | \u003csub\u003e34.40%\u003c/sub\u003e | \u003csub\u003eViT-B\u003c/sub\u003e | \u003csub\u003eNeurIPS 2022\u003c/sub\u003e |\n| \u003csub\u003e**27**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Engstrom2019Robustness**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Robustness library](https://github.com/MadryLab/robustness)*\u003c/sub\u003e | \u003csub\u003e62.56%\u003c/sub\u003e | \u003csub\u003e29.22%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eGitHub,\u003cbr\u003eOct 2019\u003c/sub\u003e |\n| \u003csub\u003e**28**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Wong2020Fast**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Fast is better than free: Revisiting adversarial training](https://arxiv.org/abs/2001.03994)*\u003c/sub\u003e | \u003csub\u003e55.62%\u003c/sub\u003e | \u003csub\u003e26.24%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eICLR 2020\u003c/sub\u003e |\n| \u003csub\u003e**29**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Salman2020Do_R18**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Do Adversarially Robust ImageNet Models Transfer Better?](https://arxiv.org/abs/2007.08489)*\u003c/sub\u003e | \u003csub\u003e52.92%\u003c/sub\u003e | \u003csub\u003e25.32%\u003c/sub\u003e | \u003csub\u003eResNet-18\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**30**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Standard_R50**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Standardly trained model](https://github.com/RobustBench/robustbench/)*\u003c/sub\u003e | \u003csub\u003e76.52%\u003c/sub\u003e | \u003csub\u003e0.00%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eN/A\u003c/sub\u003e |\n\n#### Corruptions (ImageNet-C \u0026 ImageNet-3DCC)\n\n| \u003csub\u003e#\u003c/sub\u003e | \u003csub\u003eModel ID\u003c/sub\u003e | \u003csub\u003ePaper\u003c/sub\u003e | \u003csub\u003eClean accuracy\u003c/sub\u003e | \u003csub\u003eRobust accuracy\u003c/sub\u003e | \u003csub\u003eArchitecture\u003c/sub\u003e | \u003csub\u003eVenue\u003c/sub\u003e |\n|:---:|---|---|:---:|:---:|:---:|:---:|\n| \u003csub\u003e**1**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Tian2022Deeper_DeiT-B**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Deeper Insights into the Robustness of ViTs towards Common Corruptions](https://arxiv.org/abs/2204.12143)*\u003c/sub\u003e | \u003csub\u003e81.38%\u003c/sub\u003e | \u003csub\u003e67.55%\u003c/sub\u003e | \u003csub\u003eDeiT Base\u003c/sub\u003e | \u003csub\u003earXiv, Apr 2022\u003c/sub\u003e |\n| \u003csub\u003e**2**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Tian2022Deeper_DeiT-S**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Deeper Insights into the Robustness of ViTs towards Common Corruptions](https://arxiv.org/abs/2204.12143)*\u003c/sub\u003e | \u003csub\u003e79.76%\u003c/sub\u003e | \u003csub\u003e62.91%\u003c/sub\u003e | \u003csub\u003eDeiT Small\u003c/sub\u003e | \u003csub\u003earXiv, Apr 2022\u003c/sub\u003e |\n| \u003csub\u003e**3**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Erichson2022NoisyMix_new**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[NoisyMix: Boosting Robustness by Combining Data Augmentations, Stability Training, and Noise Injections](https://arxiv.org/pdf/2202.01263.pdf)*\u003c/sub\u003e | \u003csub\u003e76.90%\u003c/sub\u003e | \u003csub\u003e53.28%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003earXiv, Feb 2022\u003c/sub\u003e |\n| \u003csub\u003e**4**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Hendrycks2020Many**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution Generalization](https://arxiv.org/abs/2006.16241)*\u003c/sub\u003e | \u003csub\u003e76.86%\u003c/sub\u003e | \u003csub\u003e52.90%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eICCV 2021\u003c/sub\u003e |\n| \u003csub\u003e**5**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Erichson2022NoisyMix**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[NoisyMix: Boosting Robustness by Combining Data Augmentations, Stability Training, and Noise Injections](https://arxiv.org/pdf/2202.01263.pdf)*\u003c/sub\u003e | \u003csub\u003e76.98%\u003c/sub\u003e | \u003csub\u003e52.47%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003earXiv, Feb 2022\u003c/sub\u003e |\n| \u003csub\u003e**6**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Hendrycks2020AugMix**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[AugMix: A Simple Data Processing Method to Improve Robustness and Uncertainty](https://arxiv.org/abs/1912.02781)*\u003c/sub\u003e | \u003csub\u003e77.34%\u003c/sub\u003e | \u003csub\u003e49.33%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eICLR 2020\u003c/sub\u003e |\n| \u003csub\u003e**7**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Geirhos2018_SIN_IN**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness](https://arxiv.org/abs/1811.12231)*\u003c/sub\u003e | \u003csub\u003e74.98%\u003c/sub\u003e | \u003csub\u003e45.76%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eICLR 2019\u003c/sub\u003e |\n| \u003csub\u003e**8**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Geirhos2018_SIN_IN_IN**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness](https://arxiv.org/abs/1811.12231)*\u003c/sub\u003e | \u003csub\u003e77.56%\u003c/sub\u003e | \u003csub\u003e42.00%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eICLR 2019\u003c/sub\u003e |\n| \u003csub\u003e**9**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Geirhos2018_SIN**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness](https://arxiv.org/abs/1811.12231)*\u003c/sub\u003e | \u003csub\u003e60.08%\u003c/sub\u003e | \u003csub\u003e39.92%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eICLR 2019\u003c/sub\u003e |\n| \u003csub\u003e**10**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Standard_R50**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Standardly trained model](https://github.com/RobustBench/robustbench/)*\u003c/sub\u003e | \u003csub\u003e76.72%\u003c/sub\u003e | \u003csub\u003e39.48%\u003c/sub\u003e | \u003csub\u003eResNet-50\u003c/sub\u003e | \u003csub\u003eN/A\u003c/sub\u003e |\n| \u003csub\u003e**11**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**Salman2020Do_50_2_Linf**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[Do Adversarially Robust ImageNet Models Transfer Better?](https://arxiv.org/abs/2007.08489)*\u003c/sub\u003e | \u003csub\u003e68.64%\u003c/sub\u003e | \u003csub\u003e36.09%\u003c/sub\u003e | \u003csub\u003eWideResNet-50-2\u003c/sub\u003e | \u003csub\u003eNeurIPS 2020\u003c/sub\u003e |\n| \u003csub\u003e**12**\u003c/sub\u003e | \u003csub\u003e\u003csup\u003e**AlexNet**\u003c/sup\u003e\u003c/sub\u003e | \u003csub\u003e*[ImageNet Classification with Deep Convolutional Neural Networks](https://papers.nips.cc/paper/2012/hash/c399862d3b9d6b76c8436e924a68c45b-Abstract.html)*\u003c/sub\u003e | \u003csub\u003e56.24%\u003c/sub\u003e | \u003csub\u003e21.12%\u003c/sub\u003e | \u003csub\u003eAlexNet\u003c/sub\u003e | \u003csub\u003eNeurIPS 2012\u003c/sub\u003e |\n\n\n## Notebooks\n\nWe host all the notebooks at Google Colab:\n\n- [RobustBench: quick start](https://colab.research.google.com/drive/1MQY_7O9vj7ixD5ilVRbdQwlNPFvxifHV):\n  a quick tutorial to get started that illustrates the main features of **`RobustBench`**.\n- [RobustBench: json stats](https://colab.research.google.com/drive/19tgblr13SvaCpG8hoOTv6QCULVJbCec6):\n  various plots based on the jsons from `model_info` (robustness over venues, robustness vs\n  accuracy, etc).\n\nFeel free to suggest a new notebook based on the **Model Zoo** or the jsons from `model_info`. We\nare very interested in collecting new insights about benefits and tradeoffs between different\nperturbation types.\n\n\n## How to contribute\n\nContributions to **`RobustBench`** are very welcome! You can help to improve **`RobustBench`**:\n\n- Are you an author of a recent paper focusing on improving adversarial robustness? Consider adding\n  new models (see the instructions below 👇).\n- Do you have in mind some better *standardized* attack? Do you want to\n  extend **`RobustBench`** to other threat models? We'll be glad to discuss that!\n- Do you have an idea how to make the existing codebase better? Just open a pull request or create\n  an issue and we'll be happy to discuss potential changes.\n\n\n## Adding a new evaluation\n\nIn case you have some new (potentially, adaptive) evaluation that leads to a _lower_ robust accuracy than AutoAttack, we will be happy to add it to the leaderboard.\nThe easiest way is to **open an issue with the \"New external evaluation(s)\" template** and fill in all the fields.\n\n\n## Adding a new model\n\n#### Public model submission (Leaderboard + Model Zoo)\n\nThe easiest way to add new models to the leaderboard and/or to the model zoo, is by **opening an issue\nwith the \"New Model(s)\" template** and fill in all the fields.\n\nIn the following sections there are some tips on how to prepare the claim.\n\n##### Claim\n\nThe claim can be computed in the following way (example for `cifar10`, `Linf` threat model):\n\n```python\nimport torch\n\nfrom robustbench import benchmark\nfrom myrobust model import MyRobustModel\n\nthreat_model = \"Linf\"  # one of {\"Linf\", \"L2\", \"corruptions\"}\ndataset = \"cifar10\"  # one of {\"cifar10\", \"cifar100\", \"imagenet\"}\n\nmodel = MyRobustModel()\nmodel_name = \"\u003cName\u003e\u003cYear\u003e\u003cFirstWordOfTheTitle\u003e\"\ndevice = torch.device(\"cuda:0\")\n\nclean_acc, robust_acc = benchmark(model, model_name=model_name, n_examples=10000, dataset=dataset,\n                                  threat_model=threat_model, eps=8/255, device=device,\n                                  to_disk=True)\n```\n\nIn particular, the `to_disk` argument, if `True`, generates a json file at the path\n`model_info/\u003cdataset\u003e/\u003cthreat_model\u003e/\u003cName\u003e\u003cYear\u003e\u003cFirstWordOfTheTitle\u003e.json` which is structured\nin the following way (example from `model_info/cifar10/Linf/Rice2020Overfitting.json`):\n\n```json\n{\n  \"link\": \"https://arxiv.org/abs/2002.11569\",\n  \"name\": \"Overfitting in adversarially robust deep learning\",\n  \"authors\": \"Leslie Rice, Eric Wong, J. Zico Kolter\",\n  \"additional_data\": false,\n  \"number_forward_passes\": 1,\n  \"dataset\": \"cifar10\",\n  \"venue\": \"ICML 2020\",\n  \"architecture\": \"WideResNet-34-20\",\n  \"eps\": \"8/255\",\n  \"clean_acc\": \"85.34\",\n  \"reported\": \"58\",\n  \"autoattack_acc\": \"53.42\"\n}\n```\n\nThe only difference is that the generated json will have only the fields `\"clean_acc\"` and\n`\"autoattack_acc\"` (for `\"Linf\"` and `\"L2\"` threat models) or `\"corruptions_acc\"` (for the\n`\"corruptions\"` threat model) already specified. The other fields have to be filled manually.\n\nIf the given `threat_model` is `corruptions`, we also save unaggregated results on the different\ncombinations of corruption types and severities in\n[this csv file](model_info/cifar10/corruptions/unaggregated_results.csv) (for CIFAR-10).\n\nFor ImageNet benchmarks, the users should specify what preprocessing should be used (e.g. resize and crop to the needed resolution). There are some preprocessings already defined in [`robustbench.data.PREPROCESSINGS`](https://github.com/RobustBench/robustbench/blob/imagenet-preprocessing/robustbench/data.py#L18), which can be used by specifying the key as the `preprocessing` parameter of `benchmark`. Otherwise, it's possible to pass an arbitrary torchvision transform (or torchvision-compatible transform), e.g.:\n\n```python\ntransform = transforms.Compose([\n        transforms.Resize(256),\n        transforms.CenterCrop(224),\n        transforms.ToTensor()\n    ])\nclean_acc, robust_acc = benchmark(model, model_name=model_name, n_examples=10000, dataset=dataset,\n                                  threat_model=threat_model, eps=8/255, device=device,\n                                  to_disk=True, preprocessing=transform)\n```\n\n##### Model definition\n\nIn case you want to add a model in the Model Zoo by yourself, then you should also open a PR with\nthe new model(s) you would like to add. All the models of each `\u003cdataset\u003e` are saved\nin `robustbench/model_zoo/\u003cdataset\u003e.py`. Each file contains a dictionary for every threat model,\nwhere the keys are the identifiers of each model, and the values are either class constructors, for\nmodels that have to change standard architectures, or `lambda` functions that return the constructed\nmodel.\n\nIf your model is a standard architecture (e.g., `WideResNet`), does not apply any normalization to\nthe input nor has to do things differently from the standard architecture, consider adding your\nmodel as a lambda function, e.g.\n\n```python\n('Cui2020Learnable_34_10', {\n    'model': lambda: WideResNet(depth=34, widen_factor=10, sub_block1=True),\n    'gdrive_id': '16s9pi_1QgMbFLISVvaVUiNfCzah6g2YV'\n})\n```\n\nIf your model is a standard architecture, but you need to do something differently (e.g. applying\nnormalization), consider inheriting the class defined in `wide_resnet.py` or `resnet.py`. For\nexample:\n\n```python\nclass Rice2020OverfittingNet(WideResNet):\n    def __init__(self, depth, widen_factor):\n        super(Rice2020OverfittingNet, self).__init__(depth=depth, widen_factor=widen_factor,\n                                                     sub_block1=False)\n        self.mu = torch.Tensor([0.4914, 0.4822, 0.4465]).float().view(3, 1, 1).cuda()\n        self.sigma = torch.Tensor([0.2471, 0.2435, 0.2616]).float().view(3, 1, 1).cuda()\n\n    def forward(self, x):\n        x = (x - self.mu) / self.sigma\n        return super(Rice2020OverfittingNet, self).forward(x)\n```\n\nIf instead you need to create a new architecture, please put it in\n`robustbench/model_zoo/archietectures/\u003cmy_architecture\u003e.py`.\n\n##### Model checkpoint\n\nYou should also add your model entry in the corresponding `\u003cthreat_model\u003e` dict in the file\n`robustbench/model_zoo/\u003cdataset\u003e.py`. For instance, let's say your model is robust against common\ncorruptions in CIFAR-10 (i.e. CIFAR-10-C), then you should add your model to the\n`common_corruptions` dict in [`robustbench/model_zoo/cifar10.py`](robustbench/model_zoo/cifar10.py).\n\nThe model should also contain the *Google Drive ID* with your PyTorch model so that it can be\ndownloaded automatically from Google Drive:\n\n```python\n    ('Rice2020Overfitting', {\n        'model': Rice2020OverfittingNet(34, 20),\n        'gdrive_id': '1vC_Twazji7lBjeMQvAD9uEQxi9Nx2oG-',\n})\n```\n\n#### Private model submission (leaderboard only)\n\nIn case you want to keep your checkpoints private for some reasons, you can also submit your claim\nby opening an issue with the same \"New Model(s)\" template, specifying that the submission is\nprivate, and sharing the checkpoints with the email address `adversarial.benchmark@gmail.com`. In\nthis case, we will add your model to the leaderboard but not to the Model Zoo and will not share\nyour checkpoints publicly.\n\n#### License of the models\n\nBy default, the models are released under the MIT license, but you can also tell us if you want to\nrelease your model under a customized license.\n\n## Automatic tests\n\nIn order to run the tests, run:\n\n- `python -m unittest discover tests -t . -v` for fast testing\n- `RUN_SLOW=true python -m unittest discover tests -t . -v` for slower testing\n\nFor example, one can test if the clean accuracy on 200 examples exceeds some threshold (70%) or if clean accuracy on \n10'000 examples for each model matches the ones from the jsons located at `robustbench/model_info`.\n\nNote that one can specify some configurations like `batch_size`, `data_dir`, `model_dir` in `tests/config.py` for \nrunning the tests.\n\n## Citation\n\nWould you like to reference the **`RobustBench`** leaderboard or you are using models from the **Model Zoo**? \\\nThen consider citing our [whitepaper](https://arxiv.org/abs/2010.09670):\n\n```bibtex\n@inproceedings{croce2021robustbench,\n  title     = {RobustBench: a standardized adversarial robustness benchmark},\n  author    = {Croce, Francesco and Andriushchenko, Maksym and Sehwag, Vikash and Debenedetti, Edoardo and Flammarion, Nicolas and Chiang, Mung and Mittal, Prateek and Matthias Hein},\n  booktitle = {Thirty-fifth Conference on Neural Information Processing Systems Datasets and Benchmarks Track},\n  year      = {2021},\n  url       = {https://openreview.net/forum?id=SSKZPJCt7B}\n}\n```\n\n## Contact \nFeel free to contact us about anything related to **`RobustBench`** by creating an issue, a pull request or \nby email at `adversarial.benchmark@gmail.com`.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FRobustBench%2Frobustbench","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FRobustBench%2Frobustbench","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FRobustBench%2Frobustbench/lists"}