Fetching the paper…
Reading the bibliography…
While neural networks have achieved high accuracy on standard image classification benchmarks, their accuracy drops to nearly zero in the presence of small adversarial perturbations to test inputs.
Classes of recursively enumerable sets and their decision problems
H. G. Rice · 1953
Earlier work this paper cites.
The general problem of the stability of motion
A. M. Lyapunov · 1992
Earlier work this paper cites.
Improved approximation algorithms for maximum cut and satisfiability problems using semidefinite programming
M. Goemans and D. Williamson · 1995
Earlier work this paper cites.
Controllers for reachability specifications for hybrid systems
J. Lygeros, C. Tomlin, and S. Sastry · 1999
Earlier work this paper cites.
Using SeDuMi 1.02, a MATLAB toolbox for optimization over symmetric cones
J. F. Sturm · 1999
Earlier work this paper cites.
On the construction of lyapunov functions using the sum of squares decomposition
A. Papachristodoulou and S. Prajna · 2002
Earlier work this paper cites.
Semidefinite programming relaxations for semialgebraic problems
P. A. Parrilo · 2003
Earlier work this paper cites.
YALMIP: A toolbox for modeling and optimization in MATLAB
J. Löfberg · 2004
Earlier work this paper cites.
A time-dependent Hamilton-Jacobi formulation of reachable sets for continuous dynamic games
I. M. Mitchell, A. M. Bayen, and C. J. Tomlin · 2005
Earlier work this paper cites.
Analysis of non-polynomial systems using the sum of squares decomposition
A. Papachristodoulou and S. Prajna · 2005
Earlier work this paper cites.
Paragraph: Thwarting signature learning by training maliciously
J. Newsome, B. Karp, and D. Song · 2006
Earlier work this paper cites.
H-infinity optimal control and related minimax design problems: a dynamic game approach
T. Başar and P. Bernhard · 2008
Earlier work this paper cites.
The security of machine learning
M. Barreno, B. Nelson, A. D. Joseph, and J. D. Tygar · 2010
Earlier work this paper cites.
LQR-trees: Feedback motion planning via sums of squares verification
R. Tedrake, I. R. Manchester, M. M. Tobenkin, and J. W. Roberts · 2010
Earlier work this paper cites.
Theory and applications of robust optimization
D. Bertsimas, D. B. Brown, and C. Caramanis · 2011
Earlier work this paper cites.
Invariant funnels around trajectories using sum-of-squares programming
M. M. Tobenkin, I. R. Manchester, and R. Tedrake · 2011
Earlier work this paper cites.
TCP ex machina: Computer-generated congestion control
K. Winstein and H. Balakrishnan · 2013
Cited alongside, same era.
Adam: A method for stochastic optimization
D. Kingma and J. Ba · 2014
Cited alongside, same era.
Practical evasion of a learning-based classifier: A case study
P. Laskov and N. Šrndic̀ · 2014
Cited alongside, same era.
An experimental study of the learnability of congestion control
A. Sivaraman, K. Winstein, P. Thaker, and H. Balakrishnan · 2014
Cited alongside, same era.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Cited alongside, same era.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter · 2016
Later among the works it cites.
Mastering the game of go with deep neural networks and tree search
D. Silver, A. Huang, C. J. Maddison, A. Guez, L. Sifre, G. V. D. Driessche, J. Schrittwieser, I. Antonoglou, V. Panneershelvam, M. Lanctot, et al · 2016
Later among the works it cites.
Achieving human parity in conversational speech recognition
W. Xiong, J. Droppo, X. Huang, F. Seide, M. Seltzer, A. Stolcke, D. Yu, and G. Zweig · 2016
Later among the works it cites.
Ground-truth adversarial examples
N. Carlini, G. Katz, C. Barrett, and D. L. Dill · 2017
Later among the works it cites.
EAD: Elastic-net attacks to deep neural networks via adversarial examples
P. Chen, Y. Sharma, H. Zhang, J. Yi, and C. Hsieh · 2017
Later among the works it cites.
Parseval networks: Improving robustness to adversarial examples
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Delving deep into rectifiers: Surpassing human-level performance on imagenet classification
K. He, X. Zhang, S. Ren, and J. Sun · 2015
Cited alongside, same era.
Distributional smoothing with virtual adversarial training
T. Miyato, S. Maeda, M. Koyama, K. Nakae, and S. Ishii · 2015
Cited alongside, same era.
Measuring neural net robustness with constraints
O. Bastani, Y. Ioannou, L. Lampropoulos, D. Vytiniotis, A. Nori, and A. Criminisi · 2016
Cited alongside, same era.
Defensive distillation is not robust to adversarial examples
N. Carlini and D. Wagner · 2016
Cited alongside, same era.
Hidden voice commands
N. Carlini, P. Mishra, T. Vaidya, Y. Zhang, M. Sherr, C. Shields, D. Wagner, and W. Zhou · 2016
Cited alongside, same era.
On the security of machine learning in malware c&c detection: A survey
J. Gardiner and S. Nagaraja · 2016
Cited alongside, same era.
M. Cisse, P. Bojanowski, E. Grave, Y. Dauphin, and N. Usunier · 2017
Later among the works it cites.
Robust physical-world attacks on machine learning models
I. Evtimov, K. Eykholt, E. Fernandes, T. Kohno, B. Li, A. Prakash, A. Rahmati, and D. Song · 2017
Later among the works it cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
M. Hein and M. Andriushchenko · 2017
Later among the works it cites.
Safety verification of deep neural networks
X. Huang, M. Kwiatkowska, S. Wang, and M. Wu · 2017
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
J. Z. Kolter and E. Wong · 2017
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2017
Later among the works it cites.
Biologically inspired protection of deep networks from adversarial attacks
A. Nayebi and S. Ganguli · 2017
Later among the works it cites.
Computer-aided design for safe autonomous vehicles
M. O’Kelly, H. Abbas, and R. Mangharam · 2017
Later among the works it cites.
Certified defenses for data poisoning attacks
J. Steinhardt, P. W. Koh, and P. Liang · 2017
Later among the works it cites.
Ensemble adversarial training: Attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, D. Boneh, and P. McDaniel · 2017
Later among the works it cites.