I'm a PhD student in the machine learning department at CMU, co-advised by Zico Kolter and Ameet Talwalkar. My main research interest is turning the practice of deep leaning into a mature engineering discipline.Google Scholar
Email spam is known to be a big problem these days, so like other academics I obfuscate my email address.
My email address is email@example.com
Extending recent work, we show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is provably robust to perturbations in L2 norm. This method is the only provable adversarial defense that scales to ImageNet. It also outperforms all other provable L2 adversarial defenses on CIFAR-10 by a wide margin. Best of all, the method is extremely simple to implement and to understand.