Fetching the paper…
Reading the bibliography…
We consider adversarial examples for image classification in the black-box decision-based setting.
An image synthesizer
K. Perlin · 1985
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna · 2015
Earlier work this paper cites.
Inception-v4, inception-resnet and the impact of residual connections on learning
C. Szegedy, S. Ioffe, and V. Vanhoucke · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh · 2017
Earlier work this paper cites.
The space of transferable adversarial examples
F. Tramèr, N. Papernot, I. J. Goodfellow, D. Boneh, and P. D. McDaniel · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Cited alongside, same era.
Synthesizing robust adversarial examples
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok · 2018
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
W. Brendel, J. Rauber, and M. Bethge · 2018
Cited alongside, same era.
W. Brendel, J. Rauber, A. Kurakin, N. Papernot, B. Veliqi, M. Salathé, S. P. Mohanty, and M. Bethge · 2018
Cited alongside, same era.
Query-efficient hard-label black-box attack: An optimization-based approach
M. Cheng, T. Le, P.-Y. Chen, J. Yi, H. Zhang, and C.-J. Hsieh · 2018
Cited alongside, same era.
Prior convictions: Black-box adversarial attacks with bandits and priors
A. Ilyas, L. Engstrom, and A. Madry · 2018
Closest in time.
Adversarial Attacks and Defences Competition
A. Kurakin, I. Goodfellow, S. Bengio, Y. Dong, F. Liao, M. Liang, T. Pang, J. Zhu, X. Hu, C. Xie, J. Wang, Z. Zhang, Z. Ren, A. Yuille, S. Huang, Y. Zhao, Y. Zhao, Z. Han, J. Long, Y. Berdibekov, T. Akiba, S. Tokui, and M. Abe · 2018
Closest in time.
Defense against adversarial attacks using high-level representation guided denoiser
F. Liao, M. Liang, Y. Dong, T. Pang, X. Hu, and J. Zhu · 2018
Closest in time.
Towards Deep Learning Models Resistant to Adversarial Attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Closest in time.
Ensemble adversarial training: Attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Low frequency adversarial perturbation
C. Guo, J. S. Frank, and K. Q. Weinberger · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin · 2018
Cited alongside, same era.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
C. Tu, P. Ting, P. Chen, S. Liu, H. Zhang, J. Yi, C. Hsieh, and S. Cheng · 2018
Closest in time.
Mitigating adversarial effects through randomization
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille · 2018
Closest in time.