Fetching the paper…
Reading the bibliography…
We provide a complete characterisation of the phenomenon of adversarial examples - inputs intentionally crafted to fool machine learning models.
Regularization theory and neural networks architectures
F. Girosi, M. Jones, and T. Poggio · 1995
Earlier work this paper cites.
Columbia object image library (coil 100). department of comp
S. Nayar, S. A. Nene, and H. Murase · 1996
Earlier work this paper cites.
Machine learning. 1997
T. M. Mitchell et al · 1997
Earlier work this paper cites.
Differential evolution–a simple and efficient heuristic for global optimization over continuous spaces
R. Storn and K. Price · 1997
Earlier work this paper cites.
Support vector machines
M. A. Hearst, S. T. Dumais, E. Osuna, J. Platt, and B. Scholkopf · 1998
Earlier work this paper cites.
The mnist database of handwritten digits
Y. LeCun · 1998
Earlier work this paper cites.
Object recognition with gradient-based learning
Y. LeCun, P. Haffner, L. Bottou, and Y. Bengio · 1999
Earlier work this paper cites.
Adversarial classification
N. Dalvi, P. Domingos, S. Sanghai, D. Verma, et al · 2004
Earlier work this paper cites.
Adversarial learning
D. Lowd and C. Meek · 2005
Earlier work this paper cites.
Regularization and variable selection via the elastic net
H. Zou and T. Hastie · 2005
Earlier work this paper cites.
Can machine learning be secure?
M. Barreno, B. Nelson, R. Sears, A. D. Joseph, and J. D. Tygar · 2006
Earlier work this paper cites.
Nightmare at test time: robust learning by feature deletion
A. Globerson and S. Roweis · 2006
Earlier work this paper cites.
Robust optimization
A. Ben-Tal, L. El Ghaoui, and A. Nemirovski · 2009
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Feature weighting for improved classifier robustness
A. Kołcz and C. H. Teo · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky and G. Hinton · 2009
Earlier work this paper cites.
Exploring strategies for training deep neural networks
H. Larochelle, Y. Bengio, J. Louradour, and P. Lamblin · 2009
Earlier work this paper cites.
Antidote: understanding and defending against poisoning of anomaly detectors
B. I. Rubinstein, B. Nelson, L. Huang, A. D. Joseph, S.-h. Lau, S. Rao, N. Taft, and J. Tygar · 2009
Earlier work this paper cites.
The security of machine learning
M. Barreno, B. Nelson, A. D. Joseph, and J. Tygar · 2010
Earlier work this paper cites.
Online anomaly detection under adversarial impact
M. Kloft and P. Laskov · 2010
Earlier work this paper cites.
Rectified linear units improve restricted boltzmann machines
V. Nair and G. E. Hinton · 2010
Earlier work this paper cites.
Sensitivity analysis for neural networks
D. S. Yeung, I. Cloete, D. Shi, and W. wY Ng · 2010
Earlier work this paper cites.
Robust statistics
P. J. Huber · 2011
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng · 2011
Earlier work this paper cites.
Higher order contractive auto-encoder
S. Rifai, G. Mesnil, P. Vincent, X. Muller, Y. Bengio, Y. Dauphin, and X. Glorot · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
B. Biggio, B. Nelson, and P. Laskov · 2012
Earlier work this paper cites.
Static prediction games for adversarial learning problems
M. Brückner, C. Kanzow, and T. Scheffer · 2012
Earlier work this paper cites.
A kernel two-sample test
A. Gretton, K. M. Borgwardt, M. J. Rasch, B. Schölkopf, and A. Smola · 2012
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
A. Krizhevsky, I. Sutskever, and G. E. Hinton · 2012
Earlier work this paper cites.
A machine learning approach to android malware detection
J. Sahs and L. Khan · 2012
Earlier work this paper cites.
Generalization bounds for domain adaptation
C. Zhang, L. Zhang, and J. Ye · 2012
Earlier work this paper cites.
A public domain dataset for human activity recognition using smartphones
D. Anguita, A. Ghio, L. Oneto, X. Parra, and J. L. Reyes-Ortiz · 2013
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Backpropagation: theory, architectures, and applications
Y. Chauvin and D. E. Rumelhart · 2013
Earlier work this paper cites.
I. J. Goodfellow, D. Warde-Farley, M. Mirza, A. Courville, and Y. Bengio · 2013
Earlier work this paper cites.
R. Goroshin and Y. LeCun · 2013
Earlier work this paper cites.
Auto-encoding variational bayes
D. P. Kingma and M. Welling · 2013
Earlier work this paper cites.
On the difficulty of training recurrent neural networks
R. Pascanu, T. Mikolov, and Y. Bengio · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Drebin: Effective and explainable detection of android malware in your pocket
D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon, K. Rieck, and C. Siemens · 2014
Earlier work this paper cites.
Security evaluation of pattern classifiers under attack
B. Biggio, G. Fumera, and F. Roli · 2014
Earlier work this paper cites.
Robots that can adapt like natural animals
A. Cully, J. Clune, and J.-B. Mouret · 2014
Earlier work this paper cites.
Generative adversarial nets
I. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, and Y. Bengio · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
S. Gu and L. Rigazio · 2014
Earlier work this paper cites.
The cifar-10 dataset
A. Krizhevsky, V. Nair, and G. Hinton · 2014
Earlier work this paper cites.
Practical evasion of a learning-based classifier: A case study
P. Laskov et al · 2014
Earlier work this paper cites.
Stochastic backpropagation and approximate inference in deep generative models
S. M. Rezende, Danilo Jimenez and D. Wierstra · 2014
Earlier work this paper cites.
A tutorial on principal component analysis
J. Shlens · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and A. Zisserman · 2014
Earlier work this paper cites.
Sequence to sequence learning with neural networks
I. Sutskever, O. Vinyals, and Q. V. Le · 2014
Earlier work this paper cites.
Mxnet: A flexible and efficient machine learning library for heterogeneous distributed systems
T. Chen, M. Li, Y. Li, M. Lin, N. Wang, M. Wang, T. Xiao, B. Xu, C. Zhang, and Z. Zhang · 2015
Earlier work this paper cites.
Fundamental limits on adversarial robustness
A. Fawzi, O. Fawzi, and P. Frossard · 2015
Earlier work this paper cites.
Delving deep into rectifiers: Surpassing human-level performance on imagenet classification
K. He, X. Zhang, S. Ren, and J. Sun · 2015
Earlier work this paper cites.
Distilling the knowledge in a neural network
G. Hinton, O. Vinyals, and J. Dean · 2015
Earlier work this paper cites.
Learning with a strong adversary
R. Huang, B. Xu, D. Schuurmans, and C. Szepesvári · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
S. Ioffe and C. Szegedy · 2015
Earlier work this paper cites.
Foveation-based mechanisms alleviate adversarial examples
Y. Luo, X. Boix, G. Roig, T. Poggio, and Q. Zhao · 2015
Earlier work this paper cites.
A unified gradient regularization family for adversarial examples
C. Lyu, K. Huang, and H.-N. Liang · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
A. Nguyen, J. Yosinski, and J. Clune · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein, A. C. Berg, and L. Fei-Fei · 2015
Earlier work this paper cites.
U. Shaham, Y. Yamada, and S. Negahban · 2015
Earlier work this paper cites.
Going deeper with convolutions
C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, A. Rabinovich, et al · 2015
Earlier work this paper cites.
Exploring the space of adversarial images
P. Tabacof and E. Valle · 2015
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
H. Xiao, B. Biggio, G. Brown, G. Fumera, C. Eckert, and F. Roli · 2015
Earlier work this paper cites.
Measuring neural net robustness with constraints
O. Bastani, Y. Ioannou, L. Lampropoulos, D. Vytiniotis, A. Nori, and A. Criminisi · 2016
Earlier work this paper cites.
End to end learning for self-driving cars
M. Bojarski, D. Del Testa, D. Dworakowski, B. Firner, B. Flepp, P. Goyal, L. D. Jackel, M. Monfort, U. Muller, J. Zhang, et al · 2016
Earlier work this paper cites.
Hidden voice commands
N. Carlini, P. Mishra, T. Vaidya, Y. Zhang, M. Sherr, C. Shields, D. Wagner, and W. Zhou · 2016
Earlier work this paper cites.
Group equivariant convolutional networks
T. Cohen and M. Welling · 2016
Earlier work this paper cites.
Tutorial on variational autoencoders
C. Doersch · 2016
Earlier work this paper cites.
J. Donahue, P. Krähenbühl, and T. Darrell · 2016
Earlier work this paper cites.
Adversarially learned inference
V. Dumoulin, I. Belghazi, B. Poole, O. Mastropietro, A. Lamb, M. Arjovsky, and A. Courville · 2016
Earlier work this paper cites.
A study of the effect of jpg compression on adversarial images
G. K. Dziugaite, Z. Ghahramani, and D. M. Roy · 2016
Cited alongside, same era.
Robustness of classifiers: from adversarial to random noise
A. Fawzi, S.-M. Moosavi-Dezfooli, and P. Frossard · 2016
Cited alongside, same era.
Deep learning
I. Goodfellow, Y. Bengio, A. Courville, and Y. Bengio · 2016
Cited alongside, same era.
Adversarial perturbations against deep neural networks for malware classification
K. Grosse, N. Papernot, P. Manoharan, M. Backes, and P. McDaniel · 2016
Cited alongside, same era.
D. Ha, A. Dai, and Q. V. Le · 2016
Cited alongside, same era.
Analysis of universal adversarial perturbations
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, P. Frossard, and S. Soatto · 2017
Later among the works it cites.
Simple black-box adversarial perturbations on deep neural networks
N. Narodytska and S. P. Kasiviswanathan · 2017
Later among the works it cites.
Biologically inspired protection of deep networks from adversarial attacks
A. Nayebi and S. Ganguli · 2017
Later among the works it cites.
Practical black-box attacks against machine learning
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Later among the works it cites.
Lower bounds on the robustness to adversarial perturbations
J. Peck, J. Roels, B. Goossens, and Y. Saeys · 2017
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Cited alongside, same era.
Early methods for detecting adversarial images
D. Hendrycks and K. Gimpel · 2016
Cited alongside, same era.
Dense associative memory for pattern recognition
D. Krotov and J. J. Hopfield · 2016
Cited alongside, same era.
Adversarial examples in the physical world
A. Kurakin, I. Goodfellow, and S. Bengio · 2016
Cited alongside, same era.
Adversarial machine learning at scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2016
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2016
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
S. M. Moosavi Dezfooli, A. Fawzi, and P. Frossard · 2016
Cited alongside, same era.
J. Rauber, W. Brendel, and M. Bethge · 2017
Later among the works it cites.
Generic black-box end-to-end attack against rnns and other api calls based malware classifiers
I. Rosenberg, A. Shabtai, L. Rokach, and Y. Elovici · 2017
Later among the works it cites.
T. Salimans, A. Karpathy, X. Chen, and D. P. Kingma · 2017
Later among the works it cites.
Breaking the madry defense model with l1-based adversarial examples
Y. Sharma and P.-Y. Chen · 2017
Later among the works it cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman · 2017
Later among the works it cites.
One pixel attack for fooling deep neural networks
J. Su, D. V. Vargas, and S. Kouichi · 2017
Later among the works it cites.
Hypernetworks with statistical filtering for defending adversarial examples
Z. Sun, M. Ozay, and T. Okatani · 2017
Later among the works it cites.
Inception-v4, inception-resnet and the impact of residual connections on learning
C. Szegedy, S. Ioffe, V. Vanhoucke, and A. A. Alemi · 2017
Later among the works it cites.
Ensemble adversarial training: Attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2017
Later among the works it cites.
The space of transferable adversarial examples
F. Tramèr, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2017
Later among the works it cites.
Attention is all you need
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, Ł. Kaiser, and I. Polosukhin · 2017
Later among the works it cites.
Harmonic networks: Deep translation and rotation equivariance
D. E. Worrall, S. J. Garbin, D. Turmukhambetov, and G. J. Brostow · 2017
Later among the works it cites.
Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms
H. Xiao, K. Rasul, and R. Vollgraf · 2017
Later among the works it cites.
Mitigating adversarial effects through randomization
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille · 2017
Later among the works it cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
W. Xu, D. Evans, and Y. Qi · 2017
Later among the works it cites.
Generating natural adversarial examples
Z. Zhao, D. Dua, and S. Singh · 2017
Later among the works it cites.
Oriented response networks
Y. Zhou, Q. Ye, Q. Qiu, and J. Jiao · 2017
Later among the works it cites.
Threat of adversarial attacks on deep learning in computer vision: A survey
N. Akhtar and A. Mian · 2018
Closest in time.
Genattack: Practical black-box attacks with gradient-free optimization
M. Alzantot, Y. Sharma, S. Chakraborty, and M. Srivastava · 2018
Closest in time.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Closest in time.
Featurized bidirectional gan: Adversarial defense via adversarially learned semantic inference
R. Bao, S. Liang, and Q. Wang · 2018
Closest in time.
Enhancing robustness of machine learning systems via data transformations
A. N. Bhagoji, D. Cullina, C. Sitawarin, and P. Mittal · 2018
Closest in time.
Thermometer encoding: One hot way to resist adversarial examples
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow · 2018
Closest in time.
Provably minimally-distorted adversarial examples
N. Carlini, G. Katz, C. berret, and D. Dill · 2018
Closest in time.
Audio adversarial examples: Targeted attacks on speech-to-text
N. Carlini and D. Wagner · 2018
Closest in time.
Improving adversarial robustness by data-specific discretization
J. Chen, X. Wu, Y. Liang, and S. Jha · 2018
Closest in time.
The best of both worlds: Combining recent advances in neural machine translation
M. X. Chen, O. Firat, A. Bapna, M. Johnson, W. Macherey, G. Foster, L. Jones, N. Parmar, M. Schuster, Z. Chen, et al · 2018
Closest in time.
Pac-learning in the presence of evasion adversaries
D. Cullina, A. N. Bhagoji, and P. Mittal · 2018
Closest in time.
Stochastic activation pruning for robust adversarial defense
G. S. Dhillon, K. Azizzadenesheli, Z. C. Lipton, J. Bernstein, J. Kossaifi, A. Khanna, and A. Anandkumar · 2018
Closest in time.
Robustness of rotation-equivariant networks to adversarial perturbations
B. Dumont, S. Maggio, and P. Montalvo · 2018
Closest in time.
Robust physical-world attacks on deep learning visual classification
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song · 2018
Closest in time.
Adversarial vulnerability for any classifier
A. Fawzi, H. Fawzi, and O. Fawzi · 2018
Closest in time.
Analysis of classifiers’ robustness to adversarial perturbations
A. Fawzi, O. Fawzi, and P. Frossard · 2018
Closest in time.
Ai 2: Safety and robustness certification of neural networks with abstract interpretation
T. Gehr, M. Mirman, D. Drachsler-Cohen, P. Tsankov, S. Chaudhuri, and M. Vechev · 2018
Closest in time.
Resisting adversarial attacks using gaussian mixture variational autoencoders
P. Ghosh, A. Losalka, and M. J. Black · 2018
Closest in time.
Motivating the rules of the game for adversarial example research
J. Gilmer, R. P. Adams, I. Goodfellow, D. Andersen, and G. E. Dahl · 2018
Closest in time.
J. Gilmer, L. Metz, F. Faghri, S. S. Schoenholz, M. Raghu, M. Wattenberg, and I. Goodfellow · 2018
Closest in time.
Combating adversarial attacks using sparse representations
S. Gopalakrishnan, Z. Marzi, U. Madhow, and R. Pedarsani · 2018
Closest in time.
Black-box adversarial attacks with limited queries and information
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin · 2018
Closest in time.
Adversarial examples on discrete sequences for beating whole-binary malware detection
F. Kreuk, A. Barak, S. Aviv-Reuven, M. Baruch, B. Pinkas, and J. Keshet · 2018
Closest in time.
A. Lamb, J. Binas, A. Goyal, D. Serdyuk, S. Subramanian, I. Mitliagkas, and Y. Bengio · 2018
Closest in time.
Accelerating recurrent neural network language model based online speech recognition system
K. Lee, C. Park, N. Kim, and J. Lee · 2018
Closest in time.
A survey on security threats and defensive techniques of machine learning: A data driven view
Q. Liu, P. Li, W. Zhao, W. Cai, S. Yu, and V. C. Leung · 2018
Closest in time.
Differentiable abstract interpretation for provably robust neural networks
M. Mirman, T. Gehr, and M. Vechev · 2018
Closest in time.
Robustness of classifiers to universal perturbations: A geometric perspective
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, P. Frossard, and S. Soatto · 2018
Closest in time.
Adversarial robustness toolbox v0. 2.2
M.-I. Nicolae, M. Sinn, M. N. Tran, A. Rawat, M. Wistuba, V. Zantedeschi, I. M. Molloy, and B. Edwards · 2018
Closest in time.
Bidirectional learning for robust neural networks
S. Pontes-Filho and M. Liwicki · 2018
Closest in time.
Certified defenses against adversarial examples
A. Raghunathan, J. Steinhardt, and P. Liang · 2018
Closest in time.
Blind pre-processing: A robust defense method against adversarial examples
A. S. Rakin, Z. He, B. Gong, and D. Fan · 2018
Closest in time.
Adversarially robust training through structured gradient regularization
K. Roth, A. Lucchi, S. Nowozin, and T. Hofmann · 2018
Closest in time.
Reachability analysis of deep neural networks with provable guarantees
W. Ruan, X. Huang, and M. Kwiatkowska · 2018
Closest in time.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Closest in time.
Defending against adversarial attacks by leveraging an entire gan
G. K. Santhanam and P. Grnarova · 2018
Closest in time.
Adversarially robust generalization requires more data
L. Schmidt, S. Santurkar, D. Tsipras, K. Talwar, and A. Madry · 2018
Closest in time.
Defending against adversarial images using basis functions transformations
U. Shaham, J. Garritano, Y. Yamada, E. Weinberger, A. Cloninger, X. Cheng, K. Stanton, and Y. Kluger · 2018
Closest in time.
Gradient adversarial training of neural networks
A. Sinha, Z. Chen, V. Badrinarayanan, and A. Rabinovich · 2018
Closest in time.
Certifying some distributional robustness with principled adversarial training
A. Sinha, H. Namkoong, and J. Duchi · 2018
Closest in time.
There is no free lunch in adversarial robustness (but there are unexpected benefits)
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry · 2018
Closest in time.
Y. Tsuzuku, I. Sato, and M. Sugiyama · 2018
Closest in time.
Evaluating the robustness of neural networks: An extreme value theory approach
T.-W. Weng, H. Zhang, P.-Y. Chen, J. Yi, D. Su, Y. Gao, C.-J. Hsieh, and L. Daniel · 2018
Closest in time.
Scaling provable adversarial defenses
E. Wong, F. Schmidt, J. H. Metzen, and J. Z. Kolter · 2018
Closest in time.
The manifold assumption and defenses against adversarial perturbations
W. Xi, J. Uyeong, C. Lingjiao, and J. Somesh · 2018
Closest in time.
Spatially transformed adversarial examples
C. Xiao, J.-Y. Zhu, B. Li, W. He, M. Liu, and D. Song · 2018
Closest in time.
Detecting adversarial perturbations with saliency
C. Zhang, Z. Yang, and Z. Ye · 2018
Closest in time.
Deep learning for environmentally robust speech recognition: An overview of recent developments
Z. Zhang, J. Geiger, J. Pohjalainen, A. E.-D. Mousa, W. Jin, and B. Schuller · 2018
Closest in time.
Detecting adversarial examples via key-based network
P. Zhao, Z. Fu, Q. Hu, J. Wang, et al · 2018
Closest in time.