Fetching the paper…
Reading the bibliography…
Many machine learning algorithms are vulnerable to almost imperceptible perturbations of their inputs.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Adversarial classification
Nilesh Dalvi, Pedro Domingos, Mausam, Sumit Sanghai, and Deepak Verma · 2004
Earlier work this paper cites.
Adversarial learning
Daniel Lowd and Christopher Meek · 2005
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Query strategies for evading convex-inducing classifiers
Blaine Nelson, Benjamin I. P. Rubinstein, Ling Huang, Anthony D. Joseph, Steven J. Lee, Satish Rao, and J. D. Tygar · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2015
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2015
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami · 2015
Cited alongside, same era.
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jonathon Shlens, and Zbigniew Wojna · 2015
Cited alongside, same era.
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh · 2017
Closest in time.
Houdini: Fooling deep structured prediction models
Moustapha Cisse, Yossi Adi, Natalia Neverova, and Joseph Keshet · 2017
Closest in time.
Machine learning as an adversarial service: Learning black-box adversarial examples
Jamie Hayes and George Danezis · 2017
Closest in time.
Safetynet: Detecting and rejecting adversarial examples robustly
Jiajun Lu, Theerasit Issaranon, and David A. Forsyth · 2017
Closest in time.
Biologically inspired protection of deep networks from adversarial attacks
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio · 2016
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2016
Cited alongside, same era.
Simple black-box adversarial perturbations for deep networks
Nina Narodytska and Shiva Prasad Kasiviswanathan · 2016
Cited alongside, same era.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Cited alongside, same era.
Comment on “biologically inspired protection of deep networks from adversarial attacks”
Wieland Brendel and Matthias Bethge · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner
Cited in the paper.
Defensive distillation is not robust to adversarial examples
Nicholas Carlini and David A. Wagner
Cited in the paper.
Aran Nayebi and Surya Ganguli · 2017
Closest in time.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Closest in time.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami · 2017
Closest in time.
Foolbox v0.8.0: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2017
Closest in time.
Ensemble adversarial training: Attacks and defenses
Florian Tramer, Alexey Kurakin, Nicolas Papernot, Dan Boneh, and Patrick McDaniel · 2017
Closest in time.