Fetching the paper…
Reading the bibliography…
Depending on how much information an adversary can access to, adversarial attacks can be classified as white-box attack and black-box attack.
An algorithm for quadratic programming
Frank, M · 1956
Earlier work this paper cites.
The mnist database of handwritten digits
LeCun, Y · 1998
Earlier work this paper cites.
Convex optimization
Boyd, S · 2004
Earlier work this paper cites.
Online convex optimization in the bandit setting: gradient descent without a gradient
Flaxman, A. D · 2005
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Deng, J · 2009
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A · 2012
Earlier work this paper cites.
Acoustic modeling using deep belief networks
Mohamed, A.-r · 2012
Earlier work this paper cites.
Revisiting frank-wolfe: Projection-free sparse convex optimization
Jaggi, M · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C · 2013
Earlier work this paper cites.
Natural evolution strategies
Wierstra, D · 2014
Earlier work this paper cites.
Fast r-cnn
Girshick, R · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
Kingma, D. P · 2015
Earlier work this paper cites.
Faster r-cnn: Towards real-time object detection with region proposal networks
Ren, S · 2015
Earlier work this paper cites.
End-to-end attention-based large vocabulary speech recognition
Bahdanau, D · 2016
Cited alongside, same era.
Hidden voice commands
Carlini, N · 2016
Cited alongside, same era.
Deep residual learning for image recognition
He, K · 2016
Cited alongside, same era.
Adversarial examples in the physical world
Kurakin, A · 2016
Cited alongside, same era.
Convergence rate of frank-wolfe for non-convex objectives
Lacoste-Julien, S · 2016
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M · 2016
Cited alongside, same era.
An optimal algorithm for bandit and zero-order convex optimization with two-point feedback
Shamir, O · 2017
Later among the works it cites.
Distributionally robust deep learning as a generalization of adversarial training
Staib, M · 2017
Later among the works it cites.
Can you fool ai with adversarial examples on a visual turing test?
Xu, X · 2017
Later among the works it cites.
Generalized conditional gradient for sparse estimation
Yu, Y · 2017
Later among the works it cites.
Zeroth-order (non)-convex stochastic optimization via conditional gradient and gradient updates
Balasubramanian, K · 2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
The limitations of deep learning in adversarial settings
Papernot, N · 2016
Cited alongside, same era.
Stochastic frank-wolfe methods for nonconvex optimization
Reddi, S. J · 2016
Cited alongside, same era.
Rethinking the inception architecture for computer vision
Szegedy, C · 2016
Cited alongside, same era.
Exploring the space of black-box attacks on deep neural networks
Bhagoji, A. N · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N · 2017
Cited alongside, same era.
Generating adversarial malware examples for black-box attacks based on gan
Hu, W · 2017
Cited alongside, same era.
Cheng, M · 2018
Closest in time.
Boosting adversarial attacks with momentum
Dong, Y · 2018
Closest in time.
On the information-adaptive variants of the admm: an iteration complexity perspective
Gao, X · 2018
Closest in time.
Delving into transferable adversarial examples and black-box attacks
Liu, Y · 2018
Closest in time.
Towards deep learning models resistant to adversarial attacks
Madry, A · 2018
Closest in time.
Robust deep reinforcement learning with adversarial attacks
Pattanaik, A · 2018
Closest in time.
How does batch normalization help optimization?(no, it is not about internal covariate shift)
Santurkar, S · 2018
Closest in time.
Certifying some distributional robustness with principled adversarial training
Sinha, A · 2018
Closest in time.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Tu, C · 2018
Closest in time.