Fetching the paper…
Reading the bibliography…
Deep neural networks are vulnerable to adversarial examples, which dramatically alter model output using small input changes.
Communication theory of secrecy systems
C. E. Shannon · 1949
Earlier work this paper cites.
Mimicry attacks on host-based intrusion detection systems
David Wagner and Paolo Soto · 2002
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D. Joseph, Benjamin I. P. Rubinstein, Udam Saini, Charles Sutton, J. D. Tygar, and Kai Xia · 2008
Earlier work this paper cites.
A comparative study of white box, black box and grey box testing techniques
Mohd Ehmer and Farmeena Khan · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Delving deep into rectifiers: Surpassing human-level performance on imagenet classification
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Anh Mai Nguyen, Jason Yosinski, and Jeff Clune · 2015
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami · 2015
Earlier work this paper cites.
Achieving human parity in conversational speech recognition
Wayne Xiong, Jasha Droppo, Xuedong Huang, Frank Seide, Mike Seltzer, Andreas Stolcke, Dong Yu, and Geoffrey Zweig · 2016
Earlier work this paper cites.
Mastering the game of Go with deep neural networks and tree search
David Silver, Aja Huang, Chris J. Maddison, Arthur Guez, Laurent Sifre, George van den Driessche, Julian Schrittwieser, Ioannis Antonoglou, Veda Panneershelvam, Marc Lanctot, Sander Dieleman, Dominik Grewe, John Nham, Nal Kalchbrenner, Ilya Sutskever, Timothy Lillicrap, Madeleine Leach, Koray Kavukcuoglu, Thore Graepel, and Demis Hassabis · 2016
Earlier work this paper cites.
Security testing: A survey
Michael Felderer, Matthias Büchler, Martin Johns, Achim D. Brucker, Ruth Breu, and Alexander Pretschner · 2016
Earlier work this paper cites.
Data poisoning attacks against autoregressive models
Scott Alfeld, Xiaojin Zhu, and Paul Barford · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Towards Evaluating the Robustness of Neural Networks
N. Carlini and D. Wagner · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick D. McDaniel, and Ian J. Goodfellow · 2016
Earlier work this paper cites.
Matching networks for one shot learning
Oriol Vinyals, Charles Blundell, Tim Lillicrap, koray kavukcuoglu, and Daan Wierstra · 2016
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
J. Zico Kolter and Eric Wong · 2017
Cited alongside, same era.
Towards Deep Learning Models Resistant to Adversarial Attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2017
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David A. Wagner · 2017
Cited alongside, same era.
Magnet: a two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Cited alongside, same era.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille · 2018
Closest in time.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Closest in time.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Closest in time.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
Rama Chellappa Pouya Samangouei, Maya Kabkab · 2018
Closest in time.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Closest in time.
Adversarial risk and the dangers of evaluating against weak attacks
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Magnet and "efficient defenses against adversarial attacks" are not robust to adversarial examples
Nicholas Carlini and David A. Wagner · 2017
Cited alongside, same era.
Detecting Adversarial Samples from Artifacts
R. Feinman, R. R. Curtin, S. Shintre, and A. B. Gardner · 2017
Cited alongside, same era.
Adversarial examples for evaluating reading comprehension systems
R. Jia and P. Liang · 2017
Cited alongside, same era.
Adversarial examples for malware detection
Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes, and Patrick McDaniel · 2017
Cited alongside, same era.
Defense against adversarial attacks using high-level representation guided denoiser
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Jun Zhu, and Xiaolin Hu · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
Nips 2017: Non-targeted adversarial attack, 2017
Google Brain · 2017
Cited alongside, same era.
Jonathan Uesato, Brendan O’Donoghue, Pushmeet Kohli, and Aaron van den Oord · 2018
Closest in time.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten · 2018
Closest in time.
Characterizing adversarial subspaces using local intrinsic dimensionality
Xingjun Ma, Bo Li, Yisen Wang, Sarah M. Erfani, Sudanthi Wijewickrema, Grant Schoenebeck, Michael E. Houle, Dawn Song, and James Bailey · 2018
Closest in time.
A Simple Unified Framework for Detecting Out-of-Distribution Samples and Adversarial Attacks
K. Lee, K. Lee, H. Lee, and J. Shin · 2018
Closest in time.
Audio adversarial examples: Targeted attacks on speech-to-text
Nicholas Carlini and David A. Wagner · 2018
Closest in time.
Threat of adversarial attacks on deep learning in computer vision: A survey
N. Akhtar and A. Mian · 2018
Closest in time.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Closest in time.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2018
Closest in time.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Closest in time.
Wasserstein adversarial examples via projected sinkhorn iterations
Eric Wong, Frank R. Schmidt, and J. Zico Kolter · 2019
Closest in time.