Fetching the paper…
Reading the bibliography…
We identify obfuscated gradients, a kind of gradient masking, as a phenomenon that leads to a false sense of security in defenses against adversarial examples.
Learning representations by back-propagating errors
Rumelhart, D. E., Hinton, G. E., and Williams, R. J · 1986
Earlier work this paper cites.
Estimating or propagating gradients through stochastic neurons for conditional computation
Bengio, Y., Léonard, N., and Courville, A · 2013
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Estimating local intrinsic dimensionality
Amsaleg, L., Chelly, O., Furon, T., Girard, S., Houle, M. E., Kawarabayashi, K.-i., and Nett, M · 2015
Earlier work this paper cites.
Zagoruyko, S. and Komodakis, N · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Earlier work this paper cites.
Synthesizing robust adversarial examples
Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K · 2017
Earlier work this paper cites.
Improved training of wasserstein gans
Gulrajani, I., Ahmed, F., Arjovsky, M., Dumoulin, V., and Courville, A · 2017
Cited alongside, same era.
Adversarial example defenses: Ensembles of weak defenses are not strong
He, W., Wei, J., Chen, X., Carlini, N., and Song, D · 2017
Cited alongside, same era.
The robust manifold defense: Adversarial training using generative models
Ilyas, A., Jalal, A., Asteri, E., Daskalakis, C., and Dimakis, A. G · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
Pixelcnn++: A pixelcnn implementation with discretized logistic mixture likelihood and other modifications
Salimans, T., Karpathy, A., Chen, X., and Kingma, D. P · 2017
Characterizing adversarial subspaces using local intrinsic dimensionality
Ma, X., Li, B., Wang, Y., Erfani, S. M., Wijewickrema, S., Schoenebeck, G., Houle, M. E., Song, D., and Bailey, J · 2018
Closest in time.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Closest in time.
Cascade adversarial machine learning regularized with a unified embedding
Na, T., Ko, J. H., and Mukhopadhyay, S · 2018
Closest in time.
Certified defenses against adversarial examples
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Closest in time.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Closest in time.
Certifiable distributional robustness with principled adversarial training
Sinha, A., Namkoong, H., and Duchi, J · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Attacking the madry defense model with L 1 {L}_{1} -based adversarial examples
Sharma, Y. and Chen, P.-Y · 2017
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
Buckman, J., Roy, A., Raffel, C., and Goodfellow, I · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Dhillon, G. S., Azizzadenesheli, K., Bernstein, J. D., Kossaifi, J., Khanna, A., Lipton, Z. C., and Anandkumar, A · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Guo, C., Rana, M., Cisse, M., and van der Maaten, L · 2018
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D
Cited in the paper.
Magnet and “efficient defenses against adversarial attacks” are not robust to adversarial examples
Carlini, N. and Wagner, D
Cited in the paper.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D
Cited in the paper.
Closest in time.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Song, Y., Kim, T., Nowozin, S., Ermon, S., and Kushman, N · 2018
Closest in time.
Ensemble adversarial training: Attacks and defenses
Tramèr, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2018
Closest in time.
Mitigating adversarial effects through randomization
Xie, C., Wang, J., Zhang, Z., Ren, Z., and Yuille, A · 2018
Closest in time.