Fetching the paper…
Reading the bibliography…
Much research effort has been devoted to better understanding adversarial examples, which are specially crafted inputs to machine-learning models that are perceptually similar to benign inputs, but are classified differently (i.e., misclassified).
Untersuchungen über systeme integrierbarer funktionen
F. Riesz · 1910
Earlier work this paper cites.
Standardizing auditory tests
W. Munson and M. B. Gardner · 1950
Earlier work this paper cites.
Features of similarity
A. Tversky · 1977
Earlier work this paper cites.
Spatiotemporal sensitivity and visual attention for efficient rendering of dynamic environments
H. Yee, S. Pattanaik, and D. P. Greenberg · 2001
Earlier work this paper cites.
A universal image quality index
Z. Wang and A. C. Bovik · 2002
Earlier work this paper cites.
Image quality assessment: from error visibility to structural similarity
Z. Wang, A. C. Bovik, H. R. Sheikh, and E. P. Simoncelli · 2004
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky and G. Hinton · 2009
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
A. M. Nguyen, J. Yosinski, and J. Clune · 2015
Earlier work this paper cites.
Evasion and hardening of tree ensemble classifiers
A. Kantchelian, J. Tygar, and A. D. Joseph · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami · 2016
Cited alongside, same era.
Distillation as a defense to adversarial perturbations against deep neural networks
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami · 2016
Cited alongside, same era.
Adversarial diversity and hard positive generation
A. Rozsa, E. M. Rudd, and T. E. Boult · 2016
Cited alongside, same era.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
A rotation and a translation suffice: Fooling CNNs with simple transformations
Adversarial machine learning at scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2017
Later among the works it cites.
MagNet: a two-pronged defense against adversarial examples
D. Meng and H. Chen · 2017
Later among the works it cites.
On detecting adversarial perturbations
J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff · 2017
Later among the works it cites.
Cleverhans v2.0.0: an adversarial machine learning library
N. Papernot, N. Carlini, I. Goodfellow, R. Feinman, F. Faghri, A. Matyasko, K. Hambardzumyan, Y.-L. Juang, A. Kurakin, R. Sheatsley, A. Garg, and Y.-C. Lin · 2017
Later among the works it cites.
A theoretical framework for robustness of (deep) classifiers under adversarial noise
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
L. Engstrom, D. Tsipras, L. Schmidt, and A. Madry · 2017
Cited alongside, same era.
Robust physical-world attacks on machine learning models
I. Evtimov, K. Eykholt, E. Fernandes, T. Kohno, B. Li, A. Prakash, A. Rahmati, and D. Song · 2017
Cited alongside, same era.
Detecting adversarial samples from artifacts
R. Feinman, R. R. Curtin, S. Shintre, and A. B. Gardner · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
K. Grosse, P. Manoharan, N. Papernot, M. Backes, and P. McDaniel · 2017
Cited alongside, same era.
Objective metrics and gradient descent algorithms for adversarial examples in machine learning
U. Jang, X. Wu, and S. Jha · 2017
Cited alongside, same era.
Geometric robustness of deep networks: analysis and improvement
C. Kanbak, S.-M. Moosavi-Dezfooli, and P. Frossard · 2017
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
J. Z. Kolter and E. Wong · 2017
Cited alongside, same era.
B. Wang, J. Gao, and Y. Qi · 2017
Later among the works it cites.
Adversarial examples that fool both human and computer vision
G. F. Elsayed, S. Shankar, B. Cheung, N. Papernot, A. Kurakin, I. Goodfellow, and J. Sohl-Dickstein · 2018
Closest in time.
Trojaning attack on neural networks
Y. Liu, S. Ma, Y. Aafer, W. Lee, J. Zhai, W. Wang, and X. Zhang · 2018
Closest in time.
Darts: Deceiving autonomous cars with toxic signs
C. Sitawarin, A. N. Bhagoji, A. Mosenia, M. Chiang, and P. Mittal · 2018
Closest in time.
Spatially transformed adversarial examples
C. Xiao, J.-Y. Zhu, B. Li, W. He, M. Liu, and D. Song · 2018
Closest in time.
Feature squeezing: Detecting adversarial examples in deep neural networks
W. Xu, D. Evans, and Y. Qi · 2018
Closest in time.