Fetching the paper…
Reading the bibliography…
Adversarial machine learning is a fast growing research area, which considers the scenarios when machine learning systems may face potential adversarial attackers, who intentionally synthesize input data to make a well-trained model to make mistake.
Statistical decision functions which minimize the maximum risk
Abraham Wald · 1945
Earlier work this paper cites.
Multilayer feedforward networks are universal approximators
Kurt Hornik, Maxwell Stinchcombe, and Halbert White · 1989
Earlier work this paper cites.
On the optimality of the simple bayesian classifier under zero-one loss
Pedro Domingos and Michael Pazzani · 1997
Earlier work this paper cites.
A robust minimax approach to classification
Gert R G Lanckriet, Laurent El Ghaoui, Chiranjib Bhattacharyya, and Michael I Jordan · 2003
Earlier work this paper cites.
Adversarial classification
Nilesh Dalvi, Pedro Domingos, Sumit Sanghai, Deepak Verma, et al · 2004
Earlier work this paper cites.
Adversarial learning
Daniel Lowd and Christopher Meek · 2005
Earlier work this paper cites.
Good word attacks on statistical spam filters
Daniel Lowd and Christopher Meek · 2005
Earlier work this paper cites.
Nightmare at test time: robust learning by feature deletion
Amir Globerson and Sam Roweis · 2006
Earlier work this paper cites.
Can machine learning be secure?
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D Joseph, and J Doug Tygar · 2006
Earlier work this paper cites.
Model compression
Cristian Buciluǎ, Rich Caruana, and Alexandru Niculescu-Mizil · 2006
Earlier work this paper cites.
Nash equilibria of static prediction games
Michael Brückner and Tobias Scheffer · 2009
Earlier work this paper cites.
Satisfiability modulo theories
Clark W Barrett, Roberto Sebastiani, Sanjit A Seshia, Cesare Tinelli, et al · 2009
Earlier work this paper cites.
What is the best multi-stage architecture for object recognition?
Kevin Jarrett, Koray Kavukcuoglu, Yann LeCun, et al · 2009
Earlier work this paper cites.
An abstraction-refinement approach to verification of artificial neural networks
Luca Pulina and Armando Tacchella · 2010
Earlier work this paper cites.
Rectified linear units improve restricted boltzmann machines
Vinod Nair and Geoffrey E Hinton · 2010
Earlier work this paper cites.
Adversarial machine learning
Ling Huang, Anthony D Joseph, Blaine Nelson, Benjamin IP Rubinstein, and JD Tygar · 2011
Earlier work this paper cites.
Contractive auto-encoders: Explicit invariance during feature extraction
Salah Rifai, Pascal Vincent, Xavier Muller, Xavier Glorot, and Yoshua Bengio · 2011
Earlier work this paper cites.
Deep sparse rectifier neural networks
Xavier Glorot, Antoine Bordes, and Yoshua Bengio · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Challenging smt solvers to verify neural networks
Luca Pulina and Armando Tacchella · 2012
Earlier work this paper cites.
Large-scale malware classification using random projections and neural networks
George E Dahl, Jack W Stokes, Li Deng, and Dong Yu · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Deep inside convolutional networks: Visualising image classification models and saliency maps
Karen Simonyan, Andrea Vedaldi, and Andrew Zisserman · 2013
Earlier work this paper cites.
Playing atari with deep reinforcement learning
Volodymyr Mnih, Koray Kavukcuoglu, David Silver, Alex Graves, Ioannis Antonoglou, Daan Wierstra, and Martin A Riedmiller · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Generative adversarial nets
Ian J Goodfellow, Jean Pougetabadie, Mehdi Mirza, Bing Xu, David Wardefarley, Sherjil Ozair, Aaron C Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Shixiang Gu and Luca Rigazio · 2014
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Sergey Ioffe and Christian Szegedy · 2015
Cited alongside, same era.
Distilling the knowledge in a neural network
Geoffrey Hinton, Oriol Vinyals, and Jeff Dean · 2015
Cited alongside, same era.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Anh Nguyen, Jason Yosinski, and Jeff Clune · 2015
Cited alongside, same era.
Trust region policy optimization
John Schulman, Sergey Levine, Pieter Abbeel, Michael I Jordan, and Philipp Moritz · 2015
Cited alongside, same era.
Adversarial perturbations against deep neural networks for malware classification
Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes, and Patrick McDaniel · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Later among the works it cites.
Ensemble Adversarial Training: Attacks and Defenses
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2017
Later among the works it cites.
Adversarial examples for evaluating reading comprehension systems
Robin Jia and Percy Liang · 2017
Later among the works it cites.
Generating natural adversarial examples
Zhengli Zhao, Dheeru Dua, and Sameer Singh · 2017
Later among the works it cites.
Adversarial examples for generative models
Jernej Kos, Ian Fischer, and Dawn Song · 2017
Later among the works it cites.
On the (statistical) detection of adversarial examples
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Adversarial feature selection against evasion attacks
Fei Zhang, Patrick PK Chan, Battista Biggio, Daniel S Yeung, and Fabio Roli · 2016
Cited alongside, same era.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow · 2016
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami · 2016
Cited alongside, same era.
Practical black-box attacks against deep learning systems using adversarial examples
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2016
Cited alongside, same era.
Adversarial examples in the physical world
Alexey Kurakin, Ian J Goodfellow, and Samy Bengio · 2016
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed Mohsen Moosavi Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Cited alongside, same era.
Understanding neural networks through representation erasure
Jiwei Li, Will Monroe, and Dan Jurafsky · 2016
Cited alongside, same era.
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick D Mcdaniel · 2017
Later among the works it cites.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Later among the works it cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Later among the works it cites.
Magnet: A two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Later among the works it cites.
Magnet and ”efficient defenses against adversarial attacks” are not robust to adversarial examples
Nicholas Carlini and David Wagner · 2017
Later among the works it cites.
Adversarial example defenses: Ensembles of weak defenses are not strong
Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song · 2017
Later among the works it cites.
Safety verification of deep neural networks
Xiaowei Huang, Marta Kwiatkowska, Sen Wang, and Min Wu · 2017
Later among the works it cites.
Adversarial attacks on neural network policies
Sandy Huang, Nicolas Papernot, Ian Goodfellow, Yan Duan, and Pieter Abbeel · 2017
Later among the works it cites.
Tactics of adversarial attack on deep reinforcement learning agents
Yen-Chen Lin, Zhang-Wei Hong, Yuan-Hong Liao, Meng-Li Shih, Ming-Yu Liu, and Min Sun · 2017
Later among the works it cites.
No need to worry about adversarial examples in object detection in autonomous vehicles
Jiajun Lu, Hussein Sibai, Evan Fabry, and David A Forsyth · 2017
Later among the works it cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick D Mcdaniel, Ian J Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Later among the works it cites.
Manipulating machine learning: Poisoning attacks and countermeasures for regression learning
Matthew Jagielski, Alina Oprea, Chang Liu, Cristina Nitarotaru, and Bo Li · 2018
Closest in time.
Stealing hyperparameters in machine learning
Binghui Wang and Neil Zhenqiang Gong · 2018
Closest in time.
Handling the adversarial attacks
Ning Cao, Guofu Li, Pengjia Zhu, Qian Sun, Yingying Wang, Jing Li, Maoling Yan, and Yongbin Zhao · 2018
Closest in time.
Adversarial examples for generative models
Gamaleldin F. Elsayed, Ian Goodfellow, and Jascha Sohl-Dickstein · 2018
Closest in time.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wenchuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2018
Closest in time.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Closest in time.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Closest in time.
Task-aware compressed sensing with generative adversarial networks
Maya Kabkab, Pouya Samangouei, and Rama Chellappa · 2018
Closest in time.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Closest in time.
cleverhans v2.1.0: an adversarial machine learning library
Nicolas Papernot, Fartash Faghri, Nicholas Carlini, Ian Goodfellow, Reuben Feinman, Alexey Kurakin, Cihang Xie, Yash Sharma, Tom Brown, Aurko Roy, Alexander Matyasko, Vahid Behzadan, Karen Hambardzumyan, Zhishuai Zhang, Yi-Lin Juang, Zhi Li, Ryan Sheatsley, Abhibhav Garg, Jonathan Uesato, Willi Gierke, Yinpeng Dong, David Berthelot, Paul Hendricks, Jonas Rauber, and Rujun Long · 2018
Closest in time.
Analysis of classifiers’ robustness to adversarial perturbations
Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2018
Closest in time.