Fetching the paper…
Reading the bibliography…
Machine learning models are often susceptible to adversarial perturbations of their inputs.
“Statistical decision functions which minimize the maximum risk”
Abraham Wald · 1945
Earlier work this paper cites.
“Robust Statistics”
Peter. Huber · 1981
Earlier work this paper cites.
“Learning in the Presence of Malicious Errors”
Michael Kearns and Ming Li · 1993
Earlier work this paper cites.
“Toward Efficient Agnostic Learning”
Michael. Kearns, Robert. Schapire and Linda. Sellie · 1994
Earlier work this paper cites.
“The MNIST database of handwritten digits” Website, 1998
Yann LeCun, Corinna Cortes and Christopher.C. Burges · 1998
Earlier work this paper cites.
“PAC Learning with Nasty Noise”
Nader. Bshouty, Nadav Eiron and Eyal Kushilevitz · 1999
Earlier work this paper cites.
“Adversarial Classification”
Nilesh Dalvi, Pedro Domingos, Mausam, Sumit Sanghai and Deepak Verma · 2004
Earlier work this paper cites.
“Adversarial Learning”
Daniel Lowd and Christopher Meek · 2005
Earlier work this paper cites.
“Robust optimization”
Aharon Ben-Tal, Laurent El and Arkadi Nemirovski · 2009
Earlier work this paper cites.
“Learning Multiple Layers of Features from Tiny Images” Technical report, 2009
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
“Robustness and Regularization of Support Vector Machines”
Huan Xu, Constantine Caramanis and Shie Mannor · 2009
Earlier work this paper cites.
“Reading Digits in Natural Images with Unsupervised Feature Learning”
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu and Andrew. Ng · 2011
Earlier work this paper cites.
“Concentration Inequalities: A Nonasymptotic Theory of Independence”
Stéphane Boucheron, Gábor Lugosi and Pascal Massart · 2013
Earlier work this paper cites.
“Explaining and Harnessing Adversarial Examples” arXiv, 2014
Ian. Goodfellow, Jonathon Shlens and Christian Szegedy · 2014
Earlier work this paper cites.
“Understanding Machine Learning: From Theory to Algorithms”
Shai Shalev-Shwartz and Shai Ben-David · 2014
Earlier work this paper cites.
“Intriguing properties of neural networks”
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian. Goodfellow and Rob Fergus · 2014
Earlier work this paper cites.
“Hidden Voice Commands”
Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David Wagner and Wenchao Zhou · 2016
Earlier work this paper cites.
“Defensive Distillation is Not Robust to Adversarial Examples”
Nicholas Carlini and David Wagner · 2016
Earlier work this paper cites.
“Towards Evaluating the Robustness of Neural Networks”
Nicholas Carlini and David Wagner · 2016
Earlier work this paper cites.
“Robustness of classifiers: from adversarial to random noise”
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli and Pascal Frossard · 2016
Earlier work this paper cites.
“Adversarial Perturbations Against Deep Neural Networks for Malware Classification”
Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes and Patrick. McDaniel · 2016
Cited alongside, same era.
“Deep Residual Learning for Image Recognition”
Kaiming He, Xiangyu Zhang, Shaoqing Ren and Jian Sun · 2016
Cited alongside, same era.
“DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks”
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi and Pascal Frossard · 2016
Cited alongside, same era.
“The Limitations of Deep Learning in Adversarial Settings”
Nicolas Papernot, Patrick. McDaniel, Somesh Jha, Matt Fredrikson, Z. Celik and Ananthram Swami · 2016
Cited alongside, same era.
“Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks”
Liwei Song and Prateek Mittal · 2017
Later among the works it cites.
“One pixel attack for fooling deep neural networks” arXiv, 2017
Jiawei Su, Danilo Vargas and Kouichi Sakurai · 2017
Later among the works it cites.
“Tensor Flow Models Repository”, https://www.tensorflow.org/tutorials/layers , 2017
2017
Later among the works it cites.
“The Space of Transferable Adversarial Examples” arXiv, 2017
Florian Tramèr, Nicolas Papernot, Ian. Goodfellow, Dan Boneh and Patrick. McDaniel · 2017
Later among the works it cites.
“Analyzing the Robustness of Nearest Neighbors to Adversarial Examples” arXiv, 2017
Yizhen Wang, Somesh Jha and Kamalika Chaudhuri · 2017
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha and Ananthram Swami · 2016
Cited alongside, same era.
“Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition”
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer and Michael. Reiter · 2016
Cited alongside, same era.
Sergey Zagoruyko and Nikos Komodakis · 2016
Cited alongside, same era.
“On the Robustness of Semantic Segmentation Models to Adversarial Attacks” arXiv, 2017
Anurag Arnab, Ondrej Miksik and Philip.. Torr · 2017
Cited alongside, same era.
“Vulnerability of Deep Reinforcement Learning to Policy Induction Attacks”
Vahid Behzadan and Arslan Munir · 2017
Cited alongside, same era.
“Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning” arXiv, 2017
Battista Biggio and Fabio Roli · 2017
Cited alongside, same era.
“Houdini: Fooling Deep Structured Visual and Speech Recognition Models with Adversarial Examples”
Moustapha Cisse, Yossi Adi, Natalia Neverova and Joseph Keshet · 2017
Cited alongside, same era.
“Intriguing Properties of Adversarial Examples”
Ekin. Cubuk, Barret Zoph, Samuel. Schoenholz and Quoc. Le · 2017
Cited alongside, same era.
Later among the works it cites.
“Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks”
Weilin Xu, David Evans and Yanjun Qi · 2017
Later among the works it cites.
“Can you fool AI with adversarial examples on a visual Turing test?” arXiv, 2017
Xiaojun Xu, Xinyun Chen, Chang Liu, Anna Rohrbach, Trevor Darell and Dawn Song · 2017
Later among the works it cites.
“DolphinAtack: Inaudible Voice Commands”
Guoming Zhang, Chen Yan, Xiaoyu Ji, Taimin Zhang, Tianchen Zhang and Wenyuan Xu · 2017
Later among the works it cites.
Anish Athalye, Nicholas Carlini and David Wagner · 2018
Closest in time.
“Audio Adversarial Examples: Targeted Attacks on Speech-to-Text” arXiv, 2018
Nicholas Carlini and David Wagner · 2018
Closest in time.
“Adversarial vulnerability for any classifier” arXiv, 2018
Alhussein Fawzi, Hamza Fawzi and Omar Fawzi · 2018
Closest in time.
“Adversarial Spheres” arXiv, 2018
Justin Gilmer, Luke Metz, Fartash Faghri, Samuel. Schoenholz, Maithra Raghu, Martin Wattenberg and Ian Goodfellow · 2018
Closest in time.
“Adversarial Deep Learning for Robust Detection of Binary Encoded Malware” arXiv, 2018
Alex Huang, Abdullah Al-Dujaili, Erik Hemberg and Una-May O’Reilly · 2018
Closest in time.
“Provable defenses against adversarial examples via the convex outer adversarial polytope”
J Kolter and Eric Wong · 2018
Closest in time.
“Towards Deep Learning Models Resistant to Adversarial Attacks”
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras and Adrian Vladu · 2018
Closest in time.
“Towards the Science of Security and Privacy in Machine Learning”
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha and Michael Wellman · 2018
Closest in time.
“Certified Defenses against Adversarial Examples”
Aditi Raghunathan, Jacob Steinhardt and Percy Liang · 2018
Closest in time.
“Certifying Some Distributional Robustness with Principled Adversarial Training”
Aman Sinha, Hongseok Namkoong and John Duchi · 2018
Closest in time.
“Ensemble Adversarial Training: Attacks and Defenses”
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Dan Boneh and Patrick. McDaniel · 2018
Closest in time.
“Spatially Transformed Adversarial Examples”
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu and Dawn Song · 2018
Closest in time.