Fetching the paper…
Reading the bibliography…
Adversarial examples that fool machine learning models, particularly deep neural networks, have been a topic of intense research interest, with attacks and defenses being developed in a tight back-and-forth.
Probability inequalities for sums of bounded random variables
W. Hoeffding · 1963
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Differential privacy and robust statistics
C. Dwork and J. Lei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky · 2009
Earlier work this paper cites.
Empirical bernstein bounds and sample-variance penalization
A. Maurer and M. Pontil · 2009
Earlier work this paper cites.
Differentially private recommender systems: Building privacy into the netflix prize contenders
F. McSherry and I. Mironov · 2009
Earlier work this paper cites.
Stacked denoising autoencoders: Learning useful representations in a deep network with a local denoising criterion
P. Vincent, H. Larochelle, I. Lajoie, Y. Bengio, and P.-A. Manzagol · 2010
Earlier work this paper cites.
Differentially private empirical risk minimization
K. Chaudhuri, C. Monteleoni, and A. D. Sarwate · 2011
Earlier work this paper cites.
Broadening the scope of differential privacy using metrics
K. Chatzikokolakis, M. E. Andrés, N. E. Bordenabe, and C. Palamidessi · 2013
Earlier work this paper cites.
The algorithmic foundations of differential privacy
C. Dwork, A. Roth, et al · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
S. Ioffe and C. Szegedy · 2015
Earlier work this paper cites.
Malware classification with recurrent networks
R. Pascanu, J. W. Stokes, H. Sanossian, M. Marinescu, and A. Thomas · 2015
Earlier work this paper cites.
Deep Learning with Differential Privacy
M. Abadi, A. Chu, I. Goodfellow, H. Brendan McMahan, I. Mironov, K. Talwar, and L. Zhang · 2016
Earlier work this paper cites.
Algorithmic stability for adaptive data analysis
R. Bassily, K. Nissim, A. Smith, T. Steinke, U. Stemmer, and J. Ullman · 2016
Earlier work this paper cites.
End to end learning for self-driving cars
M. Bojarski, D. D. Testa, D. Dworakowski, B. Firner, B. Flepp, P. Goyal, L. D. Jackel, M. Monfort, U. Muller, J. Zhang, X. Zhang, J. Zhao, and K. Zieba · 2016
Earlier work this paper cites.
Bayesian Differential Privacy through Posterior Sampling
C. Dimitrakakis, B. Nelson, A. Mitrokotsa, and B. Rubinstein · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
A. Kurakin, I. J. Goodfellow, and S. Bengio · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami · 2016
Earlier work this paper cites.
Towards the science of security and privacy in machine learning
N. Papernot, P. D. McDaniel, A. Sinha, and M. P. Wellman · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna · 2016
Earlier work this paper cites.
Wide residual networks
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Synthesizing robust adversarial examples
A. Athalye and I. Sutskever · 2017
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
N. Carlini and D. A. Wagner · 2017
Cited alongside, same era.
Parseval networks: Improving robustness to adversarial examples
M. Cisse, P. Bojanowski, E. Grave, Y. Dauphin, and N. Usunier · 2017
Cited alongside, same era.
Robust physical-world attacks on machine learning models
I. Evtimov, K. Eykholt, E. Fernandes, T. Kohno, B. Li, A. Prakash, A. Rahmati, and D. Song · 2017
Cited alongside, same era.
Operator norm
Wikipedia · 2017
Later among the works it cites.
The mnist database of handwritten digits, Accessed in 2017
Yann LeCun, Corinna Cortes, Christopher J.C. Burges · 2017
Later among the works it cites.
Deep learning based forecasting of critical infrastructure data
Z. Zohrevand, U. Glässer, M. A. Tayebi, H. Y. Shahir, M. Shirmaleki, and A. Y. Shahir · 2017
Later among the works it cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Closest in time.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, Laurens van der Maaten · 2018
Closest in time.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, Alan Yuille · 2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
D. Hendrycks and K. Gimpel · 2017
Cited alongside, same era.
Safety verification of deep neural networks
X. Huang, M. Kwiatkowska, S. Wang, and M. Wu · 2017
Cited alongside, same era.
The robust manifold defense: Adversarial training using generative models
A. Ilyas, A. Jalal, E. Asteri, C. Daskalakis, and A. G. Dimakis · 2017
Cited alongside, same era.
Reluplex: An efficient SMT solver for verifying deep neural networks
G. Katz, C. W. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer · 2017
Cited alongside, same era.
Adversarial examples for generative models
J. Kos, I. Fischer, and D. Song · 2017
Cited alongside, same era.
Delving into adversarial attacks on deep policies
Kos, Jernej and Song, Dawn · 2017
Cited alongside, same era.
Towards robust neural networks via random self-ensemble
X. Liu, M. Cheng, H. Zhang, and C. Hsieh · 2017
Cited alongside, same era.
Output range analysis for deep feedforward neural networks
S. Dutta, S. Jha, S. Sankaranarayanan, and A. Tiwari · 2018
Closest in time.
Training verified learners with learned verifiers
K. Dvijotham, S. Gowal, R. Stanforth, R. Arandjelovic, B. O’Donoghue, J. Uesato, and P. Kohli · 2018
Closest in time.
Ai 2: Safety and robustness certification of neural networks with abstract interpretation
T. Gehr, M. Mirman, D. Drachsler-Cohen, P. Tsankov, S. Chaudhuri, and M. Vechev · 2018
Closest in time.
Inception v3
Google · 2018
Closest in time.
Stochastic activation pruning for robust adversarial defense
Guneet S. Dhillon, Kamyar Azizzadenesheli, Jeremy D. Bernstein, Jean Kossaifi, Aran Khanna, Zachary C. Lipton, Animashree Anandkumar · 2018
Closest in time.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, Ian Goodfellow · 2018
Closest in time.
Differentiable abstract interpretation for provably robust neural networks
M. Mirman, T. Gehr, and M. Vechev · 2018
Closest in time.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, Rama Chellappa · 2018
Closest in time.
Certified defenses against adversarial examples
A. Raghunathan, J. Steinhardt, and P. Liang · 2018
Closest in time.
Generative adversarial examples
Y. Song, R. Shu, N. Kushman, and S. Ermon · 2018
Closest in time.
Efficient formal safety analysis of neural networks
S. Wang, K. Pei, W. Justin, J. Yang, and S. Jana · 2018
Closest in time.
Formal security analysis of neural networks using symbolic intervals
S. Wang, K. Pei, W. Justin, J. Yang, and S. Jana · 2018
Closest in time.
Evaluating the robustness of neural networks: An extreme value theory approach
T.-W. Weng, H. Zhang, P.-Y. Chen, J. Yi, D. Su, Y. Gao, C.-J. Hsieh, and L. Daniel · 2018
Closest in time.
Provable defenses against adversarial examples via the convex outer adversarial polytope
E. Wong and Z. Kolter · 2018
Closest in time.
Generating adversarial examples with adversarial networks
C. Xiao, B. Li, J. Zhu, W. He, M. Liu, and D. Song · 2018
Closest in time.
Spatially transformed adversarial examples
C. Xiao, J. Zhu, B. Li, W. He, M. Liu, and D. Song · 2018
Closest in time.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, Nate Kushman · 2018
Closest in time.