Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami · 2016
Cited alongside, same era.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Cited alongside, same era.
Adversarial diversity and hard positive generation
Andras Rozsa, Ethan M Rudd, and Terrance E Boult · 2016
Cited alongside, same era.
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna · 2016
Cited alongside, same era.
Improving the robustness of deep neural networks via stability training
Stephan Zheng, Yang Song, Thomas Leung, and Ian Goodfellow · 2016
Cited alongside, same era.
Dimensionality reduction as a defense against evasion attacks on machine learning classifiers
Original
Arjun Nitin Bhagoji, Daniel Cullina, and Prateek Mittal · 2017
Cited alongside, same era.
Detecting adversarial samples from artifacts
Original
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner · 2017
Cited alongside, same era.
Adversarial and clean data are not twins
Original
Zhitao Gong, Wenlu Wang, and Wei-Shinn Ku · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner
Cited in the paper.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner
Cited in the paper.
Training verified learners with learned verifiers
Original
Krishnamurthy Dvijotham, Sven Gowal, Robert Stanforth, Relja Arandjelovic, Brendan O’Donoghue, Jonathan Uesato, and Pushmeet Kohli
Cited in the paper.