Fetching the paper…
Reading the bibliography…
Wide adoption of artificial neural networks in various domains has led to an increasing interest in defending adversarial attacks against them.
R. Perdisci, D. Dagon, W. Lee, P. Fogla, and M. Sharif, “Misleading worm signature generators using deliberate noise injection,” in Security and Privacy, 2006 IEEE Symposium on . IEEE, 2006, pp. 15–pp
2006
Earlier work this paper cites.
A. Krizhevsky and G. Hinton, “Learning multiple layers of features from tiny images,” University of Toronto, Tech. Rep., 2009
2009
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “ImageNet: A Large-Scale Hierarchical Image Database,” in CVPR09 , 2009
2009
Earlier work this paper cites.
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, “Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition,” Neural Networks , no. 0, pp. –, 2012. [Online]. Available: http://www.sciencedirect.com/science/article/pii/S0893608012000457
2012
Earlier work this paper cites.
2013
Earlier work this paper cites.
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Srndic, P. Laskov, G. Giacinto, and F. Roli, “Evasion attacks against machine learning at test time,” in 6th European Machine Learning and Data Mining Conference (ECML/PKDD) , 2013
2013
Earlier work this paper cites.
S. Boucheron, G. Lugosi, and P. Massart, Concentration Inequalities: A Nonasymptotic Theory of Independence . Oxford University Press, 2013
2013
Earlier work this paper cites.
M. Fredrikson, E. Lantz, S. Jha, S. Lin, D. Page, and T. Ristenpart, “Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing.” in USENIX Security Symposium , 2014, pp. 17–32
2014
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security . ACM, 2015, pp. 1322–1333
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
X. Wu, M. Fredrikson, S. Jha, and J. F. Naughton, “A methodology for formalizing model-inversion attacks,” in Computer Security Foundations Symposium (CSF), 2016 IEEE 29th . IEEE, 2016, pp. 355–370
2016
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction apis.” in USENIX Security Symposium , 2016, pp. 601–618
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in Security and Privacy (EuroS&P), 2016 IEEE European Symposium on . IEEE, 2016, pp. 372–387
2016
Cited alongside, same era.
2016
Cited alongside, same era.
S. M. Moosavi Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: a simple and accurate method to fool deep neural networks,” in Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , no. EPFL-CONF-218057, 2016
2016
Cited alongside, same era.
2017
Cited alongside, same era.
C. Szegedy, S. Ioffe, V. Vanhoucke, and A. A. Alemi, “Inception-v4, inception-resnet and the impact of residual connections on learning.” in AAAI , vol. 4, 2017, p. 12
2017
Later among the works it cites.
2017
Later among the works it cites.
G. Katz, C. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer, “Reluplex: An efficient smt solver for verifying deep neural networks,” in International Conference on Computer Aided Verification . Springer, 2017, pp. 97–117
2017
Later among the works it cites.
2017
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
D. Meng and H. Chen, “Magnet: a two-pronged defense against adversarial examples,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security . ACM, 2017, pp. 135–147
2017
Cited alongside, same era.
2017
Cited alongside, same era.
2017
Cited alongside, same era.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in Security and Privacy (SP), 2017 IEEE Symposium on . IEEE, 2017, pp. 39–57
2017
Cited alongside, same era.
2017
Cited alongside, same era.
2017
Cited alongside, same era.
A. Kurakin, I. Goodfellow, and S. Bengio, “Nips 2017: Defense against adversarial attack,” https://www.kaggle.com/c/nips-2017-defense-against-adversarial-attack , 2017
2017
Cited alongside, same era.
Y. LeCun, C. Cortes, and C. J. Burges, “The mnist database of handwritten digits,” http://yann.lecun.com/exdb/mnist/
Cited in the paper.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in Security and Privacy (SP), 2017 IEEE Symposium on . IEEE, 2017, pp. 3–18
2017
Later among the works it cites.
W. Xu, D. Evans, and Y. Qi, “Feature squeezing: Detecting adversarial examples in deep neural networks,” in Proceedings of the 2018 Network and Distributed Systems Security Symposium (NDSS) , 2018
2018
Closest in time.
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow, “Thermometer encoding: One hot way to resist adversarial examples,” in Submissions to International Conference on Learning Representations , 2018
2018
Closest in time.
P. Samangouei, M. Kabkab, and R. Chellappa, “Defense-gan: Protecting classifiers against adversarial attacks using generative models,” in International Conference on Learning Representations , vol. 9, 2018
2018
Closest in time.
2018
Closest in time.
2018
Closest in time.