Fetching the paper…
Reading the bibliography…
Over the last few years, the phenomenon of adversarial examples --- maliciously constructed inputs that fool trained machine learning models --- has captured the attention of the research community, especially when the adversary is restricted to small modifications of a correctly handled input.
The Brunn-Minkowski inequality in Gauss space
Christer Borell · 1975
Earlier work this paper cites.
Adversarial classification
Nilesh Dalvi, Pedro Domingos, Sumit Sanghai, Deepak Verma, et al · 2004
Earlier work this paper cites.
Mean squared error: Love it or leave it? a new look at signal fidelity measures
Z. Wang and A. C. Bovik · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
A study of the effect of jpg compression on adversarial images
Gintare Karolina Dziugaite, Zoubin Ghahramani, and Daniel M Roy · 2016
Earlier work this paper cites.
Robustness of classifiers: from adversarial to random noise
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Efficient defenses against adversarial attacks
Valentina Zantedeschi, Maria-Irina Nicolae, and Ambrish Rawat · 2016
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression
Nilaksh Das, Madhuri Shanbhogue, Shang-Tse Chen, Fred Hohman, Li Chen, Michael E Kounavis, and Duen Horng Chau · 2017
Earlier work this paper cites.
A study and comparison of human and deep learning recognition performance under visual distortions
Samuel Dodge and Lina Karam · 2017
Earlier work this paper cites.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten · 2017
Cited alongside, same era.
Reluplex: An efficient smt solver for verifying deep neural networks
Guy Katz, Clark Barrett, David L Dill, Kyle Julian, and Mykel J Kochenderfer · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial examples
Aleksander Madry, Aleksander Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Cited alongside, same era.
Breaking the madry defense model with l1-based adversarial examples
Yash Sharma and Pin-Yu Chen · 2017
Cited alongside, same era.
Limitations of adversarial robustness: strong no free lunch theorem
Elvis Dohmatob · 2018
Later among the works it cites.
Robert Geirhos, Patricia Rubisch, Claudio Michaelis, Matthias Bethge, Felix A Wichmann, and Wieland Brendel · 2018
Later among the works it cites.
Benchmarking neural network robustness to common corruptions and surface variations
Dan Hendrycks and Thomas G Dietterich · 2018
Later among the works it cites.
Defense against adversarial attacks using high-level representation guided denoiser
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Jun Zhu, and Xiaolin Hu · 2018
Later among the works it cites.
Feature distillation: Dnn-oriented jpeg compression against adversarial examples
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Dan Boneh, and Patrick McDaniel · 2017
Cited alongside, same era.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
The effects of jpeg and jpeg2000 compression on attacks using adversarial examples
Ayse Elvan Aydemir, Alptekin Temizel, and Tugba Taskaya Temizel · 2018
Cited alongside, same era.
Why do deep convolutional networks generalize so poorly to small image transformations?
Aharon Azulay and Yair Weiss · 2018
Cited alongside, same era.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Cited alongside, same era.
Autoaugment: Learning augmentation policies from data
Ekin D Cubuk, Barret Zoph, Dandelion Mane, Vijay Vasudevan, and Quoc V Le · 2018
Cited alongside, same era.
Shield: Fast, practical defense and vaccination for deep learning using jpeg compression
Nilaksh Das, Madhuri Shanbhogue, Shang-Tse Chen, Fred Hohman, Siwei Li, Li Chen, Michael E Kounavis, and Duen Horng Chau · 2018
Cited alongside, same era.
Zihao Liu, Qi Liu, Tao Liu, Yanzhi Wang, and Wujie Wen · 2018
Later among the works it cites.
Saeed Mahloujifar, Dimitrios I Diochnos, and Mohammad Mahmoody · 2018
Later among the works it cites.
Deflecting adversarial attacks with pixel deflection
Aaditya Prakash, Nick Moran, Solomon Garber, Antonella DiLillo, and James Storer · 2018
Later among the works it cites.
Amir Rosenfeld, Richard Zemel, and John K Tsotsos · 2018
Later among the works it cites.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Mądry · 2018
Later among the works it cites.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2018
Later among the works it cites.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song · 2018
Later among the works it cites.