Fetching the paper…
Reading the bibliography…
Current neural network-based classifiers are susceptible to adversarial examples even in the black-box setting, where the attacker only has query access to the model.
A concentration theorem for projections
Dasgupta, S., Hsu, D., and Verma, N · 2006
Earlier work this paper cites.
Poisoning attacks against support vector machines
Biggio, B., Nelson, B., and Laskov, P · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Nguyen, A. M., Yosinski, J., and Clune, J · 2014
Earlier work this paper cites.
Natural evolution strategies
Wierstra, D., Schaul, T., Glasmachers, T., Sun, Y., Peters, J., and Schmidhuber, J · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Approximation with random bases
Gorban, A. N., Tyukin, I. Y., Prokhorov, D. V., and Sofeikov, K. I · 2015
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2015
Earlier work this paper cites.
Hidden voice commands
Carlini, N., Mishra, P., Vaidya, T., Zhang, Y., Sherr, M., Shields, C., Wagner, D., and Zhou, W · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Cited alongside, same era.
Automatically evading classifiers: A case study on pdf malware classifiers
Xu, W., Yi, Y., and Evans, D · 2016
Cited alongside, same era.
Synthesizing robust adversarial examples
Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Liu, Y., Chen, X., Liu, C., and Song, D · 2017
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Later among the works it cites.
Universal adversarial perturbations
Moosavi-Dezfooli, S., Fawzi, A., Fawzi, O., and Frossard, P · 2017
Later among the works it cites.
Simple black-box adversarial perturbations for deep networks
Narodytska, N. and Kasiviswanathan, S. P · 2017
Later among the works it cites.
Random gradient-free minimization of convex functions
Nesterov, Y. and Spokoiny, V · 2017
Later among the works it cites.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J · 2017
Cited alongside, same era.
Robust physical-world attacks on machine learning models
Evtimov, I., Eykholt, K., Fernandes, E., Kohno, T., Li, B., Prakash, A., Rahmati, A., and Song, D · 2017
Cited alongside, same era.
Machine learning as an adversarial service: Learning black-box adversarial examples
Hayes, J. and Danezis, G · 2017
Cited alongside, same era.
On the limitation of convolutional neural networks in recognizing negative images
Hosseini, H., Xiao, B., Jaiswal, M., and Poovendran, R · 2017
Cited alongside, same era.
Black-box attacks against RNN based malware detection algorithms
Hu, W. and Tan, Y · 2017
Cited alongside, same era.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Papernot, N., McDaniel, P., and Goodfellow, I
Cited in the paper.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A
Cited in the paper.
Later among the works it cites.
Evolution strategies as a scalable alternative to reinforcement learning
Salimans, T., Ho, J., Chen, X., and Sutskever, I · 2017
Later among the works it cites.
Adversarial generative nets: Neural network attacks on state-of-the-art face recognition
Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M. K · 2017
Later among the works it cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2018
Closest in time.