Fetching the paper…
Reading the bibliography…
We study the problem of finding a universal (image-agnostic) perturbation to fool machine learning (ML) classifiers (e.g., neural nets, decision tress) in the hard-label black-box setting.
Revisiting software protection
Paul C Van Oorschot · 2003
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and Harnessing Adversarial Examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
DeepFool: a simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2015
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Universal adversarial perturbations
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Exploring the space of black-box attacks on deep neural networks
Arjun Nitin Bhagoji, Warren He, Bo Li, and Dawn Song · 2017
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2017
Cited alongside, same era.
Tom B Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
Black-box attacks on deep neural networks via gradient estimation
Arjun Nitin Bhagoji, Warren He, Bo Li, and Dawn Song · 2018
Closest in time.
Query-Efficient Hard-label Black-box Attack:An Optimization-based Approach
M. Cheng, T. Le, P.-Y. Chen, J. Yi, H. Zhang, and C.-J. Hsieh · 2018
Closest in time.
Zeroth-order stochastic variance reduction for nonconvex optimization
Sijia Liu, Bhavya Kailkhura, Pin-Yu Chen, Paishun Ting, Shiyu Chang, and Lisa Amini · 2018
Closest in time.
Generalizable data-free objective for crafting universal adversarial perturbations
Konda Reddy Mopuri, Aditya Ganeshan, and R Venkatesh Babu · 2018
Closest in time.
Playing the game of universal adversarial perturbations
Julien Perolat, Mateusz Malinowski, Bilal Piot, and Olivier Pietquin · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Generative adversarial perturbations
Omid Poursaeed, Isay Katsman, Bicheng Gao, and Serge Belongie · 2017
Cited alongside, same era.
Zeroth-order (non)-convex stochastic optimization via conditional gradient and gradient updates
Krishnakumar Balasubramanian and Saeed Ghadimi · 2018
Cited alongside, same era.
Ead: elastic-net attacks to deep neural networks via adversarial examples
Pin-Yu Chen, Yash Sharma, Huan Zhang, Jinfeng Yi, and Cho-Jui Hsieh
Cited in the paper.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh
Cited in the paper.
Closest in time.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Chun-Chen Tu, Paishun Ting, Pin-Yu Chen, Sijia Liu, Huan Zhang, Jinfeng Yi, Cho-Jui Hsieh, and Shin-Ming Cheng · 2018
Closest in time.