Fetching the paper…
Reading the bibliography…
State of the art computer vision models have been shown to be vulnerable to small adversarial perturbations of the input.
The dimension of almost spherical sections of convex bodies
Tadeusz Figiel, Joram Lindenstrauss, and Vitali D Milman · 1977
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P. Kingma and Jimmy Ba · 2014
Earlier work this paper cites.
Foveation-based mechanisms alleviate adversarial examples
Yan Luo, Xavier Boix, Gemma Roig, Tomaso Poggio, and Qi Zhao · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Sergey Ioffe and Christian Szegedy · 2015
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Deep Learning
Ian Goodfellow, Yoshua Bengio, and Aaron Courville · 2016
Earlier work this paper cites.
Synthesizing robust adversarial examples
Anish Athalye and Ilya Sutskever · 2017
Earlier work this paper cites.
Parseval networks: Improving robustness to adversarial examples
Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial examples
Aleksander Madry, Aleksander Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2017
Cited alongside, same era.
Generative adversarial trainer: Defense to adversarial perturbations with gan
Hyeungill Lee, Sungyeob Han, and Jungwoo Lee · 2017
Cited alongside, same era.
Dense associative memory is robust to adversarial inputs
Dmitry Krotov and John J Hopfield · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Later among the works it cites.
Breaking the madry defense model with l1-based adversarial examples
Yash Sharma and Pin-Yu Chen · 2017
Later among the works it cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Guy Katz, Clark Barrett, David L Dill, Kyle Julian, and Mykel J Kochenderfer · 2017
Later among the works it cites.
Measuring the tendency of cnns to learn surface statistical regularities
Jason Jo and Yoshua Bengio · 2017
Later among the works it cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner · 2017
Cited alongside, same era.
Robustness to adversarial examples through an ensemble of specialists
Mahdieh Abbasi and Christian Gagné · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel · 2017
Cited alongside, same era.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Closest in time.
Robustness of classifiers to uniform lp and gaussian noise
Jean-Yves Franceschi, Alhussein Fawzi, and Omar Fawzi · 2018
Closest in time.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Mądry · 2018
Closest in time.
Adversarial vulnerability for any classifier
Alhussein Fawzi, Hamza Fawzi, and Omar Fawzi · 2018
Closest in time.