Fetching the paper…
Reading the bibliography…
Adversarial attacks on deep learning models have compromised their performance considerably.
Exponential convergence of langevin distributions and their discrete approximations
Gareth O Roberts, Richard L Tweedie, et al · 1996
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Optimal scaling of discrete approximations to langevin diffusions
Gareth O Roberts and Jeffrey S Rosenthal · 1998
Earlier work this paper cites.
Extracting and composing robust features with denoising autoencoders
Pascal Vincent, Hugo Larochelle, Yoshua Bengio, and Pierre-Antoine Manzagol · 2008
Earlier work this paper cites.
Riemann manifold langevin and hamiltonian monte carlo methods
Mark Girolami and Ben Calderhead · 2011
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Shixiang Gu and Luca Rigazio · 2014
Earlier work this paper cites.
What regularized auto-encoders learn from the data-generating distribution
Guillaume Alain and Yoshua Bengio · 2014
Earlier work this paper cites.
Going deeper with convolutions
C. Szegedy, Wei Liu, Yangqing Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
A. Nguyen, J. Yosinski, and J. Clune · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow · 2016
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Plug & play generative networks: Conditional iterative generation of images in latent space
Anh Nguyen, Jason Yosinski, Yoshua Bengio, Alexey Dosovitskiy, and Jeff Clune · 2016
Earlier work this paper cites.
Learning by denoising part 2. connection between data distribution and denoising function, 2016
Unknown · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
Communication-efficient learning of deep networks from decentralized data
H Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, et al · 2016
Earlier work this paper cites.
Tensorflow: a system for large-scale machine learning
Martín Abadi, Paul Barham, Jianmin Chen, Zhifeng Chen, Andy Davis, Jeffrey Dean, Matthieu Devin, Sanjay Ghemawat, Geoffrey Irving, Michael Isard, et al · 2016
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
Robust physical-world attacks on machine learning models
Ivan Evtimov, Kevin Eykholt, Earlence Fernandes, Tadayoshi Kohno, Bo Li, Atul Prakash, Amir Rahmati, and Dawn Song · 2017
Cited alongside, same era.
Synthesizing robust adversarial examples
Anish Athalye and Ilya Sutskever · 2017
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Dan Boneh, and Patrick McDaniel · 2017
Cited alongside, same era.
Ensemble methods as a defense to adversarial perturbations against deep neural networks
Query-efficient black-box adversarial examples
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2017
Later among the works it cites.
Alex Lamb, Jonathan Binas, Anirudh Goyal, Dmitriy Serdyuk, Sandeep Subramanian, Ioannis Mitliagkas, and Yoshua Bengio · 2018
Closest in time.
Harini Kannan, Alexey Kurakin, and Ian Goodfellow · 2018
Closest in time.
Adv-bnn: Improved adversarial defense through robust bayesian neural network
Xuanqing Liu, Yao Li, Chongruo Wu, and Cho-Jui Hsieh · 2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Thilo Strauss, Markus Hanselmann, Andrej Junginger, and Holger Ulmer · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2017
Cited alongside, same era.
The robust manifold defense: Adversarial training using generative models
Andrew Ilyas, Ajil Jalal, Eirini Asteri, Constantinos Daskalakis, and Alexandros G Dimakis · 2017
Cited alongside, same era.
Ape-gan: Adversarial perturbation elimination with gan
Shiwei Shen, Guoqing Jin, Ke Gao, and Yongdong Zhang · 2017
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cissé, and Laurens van der Maaten · 2017
Cited alongside, same era.
Defense against adversarial attacks using high-level representation guided denoiser
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Jun Zhu, and Xiaolin Hu · 2017
Cited alongside, same era.
Magnet: a two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Cited alongside, same era.
Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan Yuille, and Kaiming He · 2018
Closest in time.
Robust perception through analysis by synthesis
Lukas Schott, Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2018
Closest in time.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Closest in time.
Scaling provable adversarial defenses
Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J Zico Kolter · 2018
Closest in time.
Certified defenses against adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Closest in time.
A dual approach to scalable verification of deep networks
Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy Mann, and Pushmeet Kohli · 2018
Closest in time.
Evaluating and understanding the robustness of adversarial logit pairing
Logan Engstrom, Andrew Ilyas, and Anish Athalye · 2018
Closest in time.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Closest in time.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli · 2018
Closest in time.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Closest in time.
Darccc: Detecting adversaries by reconstruction from class conditional capsules
Nicholas Frosst, Sara Sabour, and Geoffrey Hinton · 2018
Closest in time.
Benchmarking neural network robustness to common corruptions and surface variations
Dan Hendrycks and Thomas G Dietterich · 2018
Closest in time.
An admm-based universal framework for adversarial attacks on deep neural networks
Pu Zhao, Sijia Liu, Yanzhi Wang, and Xue Lin · 2018
Closest in time.
Methods for interpreting and understanding deep neural networks
Grégoire Montavon, Wojciech Samek, and Klaus-Robert Müller · 2018
Closest in time.
Sparse binary compression: Towards distributed deep learning with minimal communication
Felix Sattler, Simon Wiedemann, Klaus-Robert Müller, and Wojciech Samek · 2018
Closest in time.
On evaluating adversarial robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, and Aleksander Madry · 2019
Closest in time.
Unmasking clever hans predictors and assessing what machines really learn
Sebastian Lapuschkin, Stephan Wäldchen, Alexander Binder, Grégoire Montavon, Wojciech Samek, and Klaus-Robert Müller · 2019
Closest in time.