Fetching the paper…
Reading the bibliography…
Deep neural networks have achieved impressive experimental results in image classification, but can surprisingly be unstable with respect to adversarial perturbations, that is, minimal changes to the input image that cause the network to misclassify it.
Principles of risk minimization for learning theory
Vladimir Vapnik · 1991
Earlier work this paper cites.
Neural networks for pattern recognition
Christopher M Bishop · 1995
Earlier work this paper cites.
Functions of bounded variation and free discontinuity problems
Luigi Ambrosio, Nicola Fusco, and Diego Pallara · 2000
Earlier work this paper cites.
On the local behavior of spaces of natural images
Gunnar E. Carlsson, Tigran Ishkhanov, Vin de Silva, and Afra Zomorodian · 2008
Earlier work this paper cites.
An abstraction-refinement approach to verification of artificial neural networks
Luca Pulina and Armando Tacchella · 2010
Earlier work this paper cites.
Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Srndic, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Analysis of classifiers’ robustness to adversarial perturbations
Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2015
Cited alongside, same era.
Deep learning
Yann LeCun, Yoshua Bengio, and Geoffrey Hinton · 2015
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2015
Cited alongside, same era.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Anh Nguyen, Jason Yosinski, and Jeff Clune · 2015
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami · 2015
Cited alongside, same era.
Attentive explanations: Justifying decisions and pointing to the evidence
Lisa Anne Hendricks Dong Huk Park, Zeynep Akata, Bernt Schiele, Trevor Darrell, and Marcus Rohrbach · 2016
Closest in time.
Safety verification of deep neural networks
Xiaowei Huang, Marta Kwiatkowska, Sen Wang, and Min Wu · 2016
Closest in time.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Closest in time.
Understanding deep convolutional networks
Stéphane Mallat · 2016
Closest in time.
cleverhans v1.0.0: an adversarial machine learning library
Nicolas Papernot, Ian Goodfellow, Ryan Sheatsley, Reuben Feinman, and Patrick McDaniel · 2016
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Towards verification of artificial neural networks
Karsten Scheibler, Leonore Winterer, Ralf Wimmer, and Bernd Becker · 2015
Cited alongside, same era.
Concrete problems in AI safety
Dario Amodei, Chris Olah, Jacob Steinhardt, Paul Christiano, John Schulman, Dario Amodei, Chris Olah, Jacob Steinhardt, Paul Christiano, John Schulman, and Dan Mané · 2016
Cited alongside, same era.
Unsupervised learning of invariant representations
Fabio Anselmi, Joel Z. Leibo, Lorenzo Rosasco, Jim Mutch, Andrea Tacchetti, and Tomaso Poggio · 2016
Cited alongside, same era.
Measuring neural net robustness with constraints
Osbert Bastani, Yani Ioannou, Leonidas Lampropoulos, Dimitrios Vytiniotis, Aditya Nori, and Antonio Criminisi · 2016
Cited alongside, same era.
End to end learning for self-driving cars
Mariusz Bojarski, Davide Del Testa, Daniel Dworakowski, Bernhard Firner, Beat Flepp, Prasoon Goyal, Lawrence D. Jackel, Mathew Monfort, Urs Muller, Jiakai Zhang, Xin Zhang, Jake Zhao, and Karol Zieba · 2016
Cited alongside, same era.
CIFAR10 model for Keras. https://github.com/fchollet/keras/blob/master/examples/cifar10_cnn.py
Cited in the paper.
DLV. https://github.com/verideep/dlv
Cited in the paper.
Closest in time.
Practical black-box attacks against deep learning systems using adversarial examples
Nicolas Papernot, Patrick Drew McDaniel, Ian J. Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami · 2016
Closest in time.
”why should i trust you?”: Explaining the predictions of any classifier
Marco Tulio Ribeiro, Sameer Singh, and Carlos Guestrin · 2016
Closest in time.
Towards verified artificial intelligence
Sanjit A. Seshia and Dorsa Sadigh · 2016
Closest in time.
Improving the robustness of deep neural networks via stability training
Stephan Zheng, Yang Song, Thomas Leung, and Ian Goodfellow · 2016
Closest in time.
Reluplex: An efficient SMT solver for verifying deep neural networks
Guy Katz, Clark Barrett, David Dill, Kyle Julian, and Mykel Kochenderfer · 2017
Closest in time.