Fetching the paper…
Reading the bibliography…
Deep neural networks were shown to be vulnerable to single pixel modifications.
Differential evolution–a simple and efficient heuristic for global optimization over continuous spaces
Storn, R. and Price, K · 1997
Earlier work this paper cites.
Can machine learning be secure?
Barreno, M., Nelson, B., Sears, R., Joseph, A. D., and Tygar, J. D · 2006
Earlier work this paper cites.
The security of machine learning
Barreno, M., Nelson, B., Joseph, A. D., and Tygar, J. D · 2010
Earlier work this paper cites.
Deep inside convolutional networks: Visualising image classification models and saliency maps
Simonyan, K., Vedaldi, A., and Zisserman, A · 2013
Earlier work this paper cites.
Self organizing classifiers: first steps in structured evolutionary machine learning
Vargas, D. V., Takano, H., and Murata, J · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C. e. a · 2014
Earlier work this paper cites.
Learning with a strong adversary
Huang, R., Xu, B., Schuurmans, D., and Szepesvári, C · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Nguyen, A., Yosinski, J., and Clune, J · 2015
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A · 2016
Cited alongside, same era.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Cited alongside, same era.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M. K · 2016
Cited alongside, same era.
Brown, T. B., Mané, D., Roy, A., Abadi, M., and Gilmer, J · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Evading classifiers by morphing in the dark
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Later among the works it cites.
One pixel attack for fooling deep neural networks
Su, J., Vargas, D. V., and Kouichi, S · 2017
Later among the works it cites.
Spectrum-diverse neuroevolution with unified neural models
Vargas, D. V. and Murata, J · 2017
Later among the works it cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Xu, W., Evans, D., and Qi, Y · 2017
Later among the works it cites.
Synthesizing robust adversarial examples
Athalye, A. and Sutskever, I · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Dang, H., Huang, Y., and Chang, E.-C · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
Grosse, K., Manoharan, P., Papernot, N., Backes, M., and McDaniel, P · 2017
Cited alongside, same era.
Universal adversarial perturbations
Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., and Frossard, P · 2017
Cited alongside, same era.
Simple black-box adversarial attacks on deep neural networks
Narodytska, N. and Kasiviswanathan, S · 2017
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
Buckman, J., Roy, A., Raffel, C., and Goodfellow, I
Cited in the paper.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D
Cited in the paper.
Magnet and” efficient defenses against adversarial attacks” are not robust to adversarial examples
Carlini, N. and Wagner, D
Cited in the paper.
Athalye, A., Carlini, N., and Wagner, D · 2018
Later among the works it cites.
Characterizing adversarial subspaces using local intrinsic dimensionality
Ma, X., Li, B., Wang, Y., Erfani, S. M., Wijewickrema, S., Schoenebeck, G., Song, D., Houle, M. E., and Bailey, J · 2018
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Later among the works it cites.
Ensemble adversarial training: Attacks and defenses
Tramèr, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2018
Later among the works it cites.