Fetching the paper…
Reading the bibliography…
Obtaining deep networks that are robust against adversarial examples and generalize well is an open problem.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Understanding the difficulty of training deep feedforward neural networks
Xavier Glorot and Yoshua Bengio · 2010
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Generative adversarial nets
Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron C. Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Auto-encoding variational bayes
Diederik P. Kingma and Max Welling · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Fundamental limits on adversarial robustness
Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2015
Earlier work this paper cites.
Learning with a strong adversary
Ruitong Huang, Bing Xu, Dale Schuurmans, and Csaba Szepesvári · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Sergey Ioffe and Christian Szegedy · 2015
Earlier work this paper cites.
Spatial transformer networks
Max Jaderberg, Karen Simonyan, Andrew Zisserman, and Koray Kavukcuoglu · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P. Kingma and Jimmy Ba · 2015
Earlier work this paper cites.
Deep learning face attributes in the wild
Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang · 2015
Earlier work this paper cites.
Imagenet large scale visual recognition challenge
Olga Russakovsky, Jia Deng, Hao Su, Jonathan Krause, Sanjeev Satheesh, Sean Ma, Zhiheng Huang, Andrej Karpathy, Aditya Khosla, Michael S. Bernstein, Alexander C. Berg, and Fei-Fei Li · 2015
Earlier work this paper cites.
Defensive distillation is not robust to adversarial examples
Nicholas Carlini and David A. Wagner · 2016
Earlier work this paper cites.
Robustness of classifiers: from adversarial to random noise
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2016
Earlier work this paper cites.
Adaptive data augmentation for image classification
Alhussein Fawzi, Horst Samulowitz, Deepak S. Turaga, and Pascal Frossard · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Autoencoding beyond pixels using a learned similarity metric
Anders Boesen Lindbo Larsen, Søren Kaae Sønderby, Hugo Larochelle, and Ole Winther · 2016
Earlier work this paper cites.
Distributional smoothing with virtual adversarial training
Takeru Miyato, Shin-ichi Maeda, Masanori Koyama, Ken Nakae, and Shin Ishii · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami · 2016
Earlier work this paper cites.
Are accuracy and robustness correlated
Andras Rozsa, Manuel Günther, and Terrance E. Boult · 2016
Earlier work this paper cites.
Adversarial images for variational autoencoders
Pedro Tabacof, Julia Tavares, and Eduardo Valle · 2016
Earlier work this paper cites.
A boundary tilting persepective on the phenomenon of adversarial examples
Thomas Tanay and Lewis Griffin · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction apis
Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart · 2016
Earlier work this paper cites.
The vulnerability of learning to adversarial perturbation increases with intrinsic dimensionality
Laurent Amsaleg, James Bailey, Dominique Barbe, Sarah M. Erfani, Michael E. Houle, Vinh Nguyen, and Milos Radovanovic · 2017
Earlier work this paper cites.
Dimensionality reduction as a defense against evasion attacks on machine learning classifiers
Arjun Nitin Bhagoji, Daniel Cullina, and Prateek Mittal · 2017
Earlier work this paper cites.
Exploring the space of black-box attacks on deep neural networks
Arjun Nitin Bhagoji, Warren He, Bo Li, and Dawn Song · 2017
Earlier work this paper cites.
Comment on ”biologically inspired protection of deep networks from adversarial attacks”
Wieland Brendel and Matthias Bethge · 2017
Earlier work this paper cites.
Unrestricted adversarial examples
Tom B. Brown, Nicholas Carlini, Chiyuan Zhang, Catherine Olsson, Paul Christiano, and Ian Goodfellow · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh · 2017
Earlier work this paper cites.
Houdini: Fooling deep structured visual and speech recognition models with adversarial examples
Moustapha M Cisse, Yossi Adi, Natalia Neverova, and Joseph Keshet · 2017
Earlier work this paper cites.
EMNIST: an extension of MNIST to handwritten letters
Gregory Cohen, Saeed Afshar, Jonathan Tapson, and André van Schaik · 2017
Earlier work this paper cites.
A rotation and a translation suffice: Fooling CNNs with simple transformations
Logan Engstrom, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry · 2017
Cited alongside, same era.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner · 2017
Cited alongside, same era.
Adversarial examples for semantic image segmentation
Volker Fischer, Mummadi Chaithanya Kumar, Jan Hendrik Metzen, and Thomas Brox · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel · 2017
Cited alongside, same era.
Adversarial example defense: Ensembles of weak defenses are not strong
Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song · 2017
Adversarial spheres
Justin Gilmer, Luke Metz, Fartash Faghri, Samuel S. Schoenholz, Maithra Raghu, Martin Wattenberg, and Ian Goodfellow · 2018
Closest in time.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Closest in time.
Prior convictions: Black-box adversarial attacks with bandits and priors
Andrew Ilyas, Logan Engstrom, and Aleksander Madry · 2018
Closest in time.
Improving DNN robustness to adversarial attacks using jacobian regularization
Daniel Jakubovitz and Raja Giryes · 2018
Closest in time.
PRADA: Protecting against DNN model stealing attacks
Mika Juuti, Sebastian Szyller, Alexey Dmitrenko, Samuel Marchal, and N. Asokan · 2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Formal guarantees on the robustness of a classifier against adversarial manipulation
Matthias Hein and Maksym Andriushchenko · 2017
Cited alongside, same era.
Adversarial attacks on neural network policies
Sandy H. Huang, Nicolas Papernot, Ian J. Goodfellow, Yan Duan, and Pieter Abbeel · 2017
Cited alongside, same era.
The robust manifold defense: Adversarial training using generative models
Andrew Ilyas, Ajil Jalal, Eirini Asteri, Constantinos Daskalakis, and Alexandros G. Dimakis · 2017
Cited alongside, same era.
Generative adversarial trainer: Defense to adversarial perturbations with GAN
Hyeungill Lee, Sungyeob Han, and Jungwoo Lee · 2017
Cited alongside, same era.
Tactics of adversarial attack on deep reinforcement learning agents
Yen-Chen Lin, Zhang-Wei Hong, Yuan-Hong Liao, Meng-Li Shih, Ming-Yu Liu, and Min Sun · 2017
Cited alongside, same era.
Towards robust neural networks via random self-ensemble
Xuanqing Liu, Minhao Cheng, Huan Zhang, and Cho-Jui Hsieh · 2017
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2017
Cited alongside, same era.
Harini Kannan, Alexey Kurakin, and Ian J. Goodfellow · 2018
Closest in time.
On the geometry of adversarial examples
Marc Khoury and Dylan Hadfield-Menell · 2018
Closest in time.
Adversarial examples for generative models
Jernej Kos, Ian Fischer, and Dawn Song · 2018
Closest in time.
Alex Lamb, Jonathan Binas, Anirudh Goyal, Dmitriy Serdyuk, Sandeep Subramanian, Ioannis Mitliagkas, and Yoshua Bengio · 2018
Closest in time.
Defense against adversarial attacks using high-level representation guided denoiser
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Xiaolin Hu, and Jun Zhu · 2018
Closest in time.
Towards imperceptible and robust adversarial example attacks against neural networks
Bo Luo, Yannan Liu, Lingxiao Wei, and Qiang Xu · 2018
Closest in time.
Characterizing adversarial subspaces using local intrinsic dimensionality
Xingjun Ma, Bo Li, Yisen Wang adn Sarah M. Erfani, Sudanthi Wijewickrema, Michael E. Houle, Grant Schoenebeck, Dawn Song, and James Bailey · 2018
Closest in time.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Closest in time.
Virtual adversarial training: a regularization method for supervised and semi-supervised learning
Takeru Miyato, Shin-ichi Maeda, Shin Ishii, and Masanori Koyama · 2018
Closest in time.
Towards reverse-engineering black-box neural networks
Seong Joon Oh, Max Augustin, Mario Fritz, and Bernt Schiele · 2018
Closest in time.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
Rama Chellappa Pouya Samangouei, Maya Kabkab · 2018
Closest in time.
Protecting JPEG images against adversarial attacks
Aaditya Prakash, Nick Moran, Solomon Garber, Antonella DiLillo, and James A. Storer · 2018
Closest in time.
Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients
Andrew Slavin Ross and Finale Doshi-Velez · 2018
Closest in time.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry · 2018
Closest in time.
Towards the first adversarially robust neural network model on mnist
Lukas Schott, Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2018
Closest in time.
Understanding adversarial training: Increasing local stability of supervised models through robust optimization
Uri Shaham, Yutaro Yamada, and Sahand Negahban · 2018
Closest in time.
Mahmood Sharif, Lujo Bauer, and Michael K. Reiter · 2018
Closest in time.
Adversarial vulnerability of neural networks increases with input dimension
Carl-Johann Simon-Gabriel, Yann Ollivier, Bernhard Schölkopf, Léon Bottou, and David Lopez-Paz · 2018
Closest in time.
Certifiable distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John C. Duchi · 2018
Closest in time.
Rendergan: Generating realistic labeled data
Leon Sixt, Benjamin Wild, and Tim Landgraf · 2018
Closest in time.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Closest in time.
Generative adversarial examples
Yang Song, Rui Shu, Nate Kushman, and Stefano Ermon · 2018
Closest in time.
Dong Su, Huan Zhang, Hongge Chen, Jinfeng Yi, Pin-Yu Chen, and Yupeng Gao · 2018
Closest in time.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Dan Boneh, and Patrick D. McDaniel · 2018
Closest in time.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2018
Closest in time.
Stealing hyperparameters in machine learning
Binghui Wang and Neil Zhenqiang Gong · 2018
Closest in time.
Analyzing the robustness of nearest neighbors to adversarial examples
Yizhen Wang, Somesh Jha, and Kamalika Chaudhuri · 2018
Closest in time.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song · 2018
Closest in time.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan L. Yuille · 2018
Closest in time.
Improving transferability of adversarial examples with input diversity
Cihang Xie, Zhishuai Zhang, Jianyu Wang, Yuyin Zhou, Zhou Ren, and Alan L. Yuille · 2018
Closest in time.
Generating natural adversarial examples
Zhengli Zhao, Dheeru Dua, and Sameer Singh · 2018
Closest in time.