Fetching the paper…
Reading the bibliography…
Classifier evasion consists in finding for a given instance $x$ the nearest instance $x'$ such that the classifier predictions of $x$ and $x'$ are different.
Symbolic execution and program testing
King, James C · 1976
Earlier work this paper cites.
MNIST dataset, 1998
LeCun, Yann, Cortes, Corinna, and Burges, Christopher J.C · 1998
Earlier work this paper cites.
Adversarial classification
Dalvi, N., Domingos, P., Mausam, Sanghai, S., and Verma, D · 2004
Earlier work this paper cites.
Good word attacks on statistical spam filters
L., Daniel · 2005
Earlier work this paper cites.
Adversarial learning
Lowd, D. and Meek, C · 2005
Earlier work this paper cites.
Can machine learning be secure?
Barreno, M., Nelson, B., Sears, R., Joseph, A. D., and Tygar, J. D · 2006
Earlier work this paper cites.
LIBLINEAR: A library for large linear classification
Fan, R.E., Chang, K.W., Hsieh, C.J., Wang, X.R., and Lin, C.J · 2008
Earlier work this paper cites.
Linear and Nonlinear Optimization (2nd edition)
Griva, I., Nash, S. G., and Sofer, A · 2008
Earlier work this paper cites.
Theano: a CPU and GPU math expression compiler
Bergstra, J., Breuleux, O., Bastien, F., Lamblin, P., Pascanu, R., Desjardins, G., Turian, J., Warde-Farley, D., and Bengio, Y · 2010
Earlier work this paper cites.
LIBSVM: A library for support vector machines
Chang, C.C. and Lin, C.J · 2011
Cited alongside, same era.
Static prediction games for adversarial learning problems
Brückner, M., Kanzow, C., and Scheffer, T · 2012
Cited alongside, same era.
Query strategies for evading convex-inducing classifiers
Nelson, B., Rubinstein, B. I. P., Huang, L., Joseph, A. D., Lee, S. J., Rao, S., and Tygar, J. D · 2012
Cited alongside, same era.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Cited alongside, same era.
API design for machine learning software: experiences from the scikit-learn project
Buitinck, L., Louppe, G., Blondel, M., Pedregosa, F., Mueller, A., Grisel, O., Niculae, V., Prettenhofer, P., Gramfort, A., Grobler, J., Layton, R., VanderPlas, J., Joly, A., Holt, B., and Varoquaux, G · 2013
Cited alongside, same era.
On the hardness of evading combinations of linear classifiers
Large-margin convex polytope machine
Kantchelian, A., Tschantz, M. C., Huang, L., Bartlett, P. L., Joseph, A. D., and Tygar, J. D · 2014
Later among the works it cites.
Practical evasion of a learning-based classifier: A case study
Srndic, N. and Laskov, P · 2014
Later among the works it cites.
XGBoost: eXtreme Gradient Boosting
Chen, T. and He, T · 2015
Closest in time.
Towards deep neural network architectures robust to adversarial examples
Gu, S. and Rigazio, L · 2015
Closest in time.
Gurobi optimizer reference manual, 2015
Gurobi Optimization, Inc · 2015
Closest in time.
Efficient non-greedy optimization of decision trees
Norouzi, M., Collins, M., Johnson, M. A, Fleet, D. J., and Kohli, P · 2015
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Stevens, D. and Lowd, D · 2013
Cited alongside, same era.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Cited alongside, same era.
Analysis of classifiers’ robustness to adversarial perturbations
Fawzi, A., Fawzi, O., and Frossard, P · 2014
Cited alongside, same era.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Cited alongside, same era.
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2015
Closest in time.
Automatically evading classifiers: A case study on PDF malware classifiers
Xu, W., Qi, Y., and Evans, D · 2016
Closest in time.