Fetching the paper…
Reading the bibliography…
An adversarial example is an example that has been adjusted to produce a wrong label when presented to a system at test time.
A morphable model for the synthesis of 3D faces
V. Blanz and T. Vetter · 1999
Earlier work this paper cites.
Traffic sign recognition with multi-scale convolutional networks
P. Sermanet and Y. LeCun · 2011
Earlier work this paper cites.
Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Facewarehouse: A 3d facial expression database for visual computing
C. Cao, Y. Weng, S. Zhou, Y. Tong, and K. Zhou · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
S. Gu and L. Rigazio · 2014
Earlier work this paper cites.
Analysis of classifiers’ robustness to adversarial perturbations
A. Fawzi, O. Fawzi, and P. Frossard · 2015
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
S. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
A. Nguyen, J. Yosinski, and J. Clune · 2015
Earlier work this paper cites.
Faster r-cnn: Towards real-time object detection with region proposal networks
S. Ren, K. He, R. Girshick, and J. Sun · 2015
Cited alongside, same era.
U. Shaham, Y. Yamada, and S. Negahban · 2015
Cited alongside, same era.
Robustness of classifiers: from adversarial to random noise
A. Fawzi, S. Moosavi-Dezfooli, and P. Frossard · 2016
Cited alongside, same era.
Adversarial examples in the physical world
A. Kurakin, I. J. Goodfellow, and S. Bengio · 2016
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2016
Synthesizing robust adversarial examples
A. Athalye and I. Sutskever · 2017
Closest in time.
An implementation of faster rcnn with study for region sampling
X. Chen and A. Gupta · 2017
Closest in time.
Robust physical-world attacks on machine learning models
I. Evtimov, K. Eykholt, E. Fernandes, T. Kohno, B. Li, A. Prakash, A. Rahmati, and D. Song · 2017
Closest in time.
Countering adversarial images using input transformations
C. Guo, M. Rana, M. Cisse, and L. van der Maaten · 2017
Closest in time.
Face detection with the faster r-cnn
H. Jiang and E. Learned-Miller · 2017
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Universal adversarial perturbations
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard · 2016
Cited alongside, same era.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
N. Papernot, P. D. McDaniel, and I. J. Goodfellow · 2016
Cited alongside, same era.
Yolo9000: better, faster, stronger
J. Redmon and A. Farhadi · 2016
Cited alongside, same era.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter · 2016
Cited alongside, same era.
Defensive distillation is not robust to adversarial examples
N. Carlini and D. Wagner
Cited in the paper.
Facetracker
J. Saragih and K. McDonald
Cited in the paper.
Safetynet: Detecting and rejecting adversarial examples robustly
J. Lu, T. Issaranon, and D. Forsyth · 2017
Closest in time.
No need to worry about adversarial examples in object detection in autonomous vehicles
J. Lu, H. Sibai, E. Fabry, and D. Forsyth · 2017
Closest in time.
Standard detectors aren’t (currently) fooled by physical adversarial stop signs
J. Lu, H. Sibai, E. Fabry, and D. Forsyth · 2017
Closest in time.
On detecting adversarial perturbations
J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff · 2017
Closest in time.