Fetching the paper…
Reading the bibliography…
Correctly evaluating defenses against adversarial examples has proven to be extremely difficult.
The protection of information in computer systems
Jerome H Saltzer and Michael D Schroeder · 1975
Earlier work this paper cites.
Adversarial classification
Nilesh Dalvi, Pedro Domingos, Sumit Sanghai, Deepak Verma, et al · 2004
Earlier work this paper cites.
Adversarial learning
Daniel Lowd and Christopher Meek · 2005
Earlier work this paper cites.
Can machine learning be secure?
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D Joseph, and J Doug Tygar · 2006
Earlier work this paper cites.
Nightmare at test time: robust learning by feature deletion
Amir Globerson and Sam Roweis · 2006
Earlier work this paper cites.
Feature weighting for improved classifier robustness
Aleksander Kołcz and Choon Hui Teo · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D Joseph, and JD Tygar · 2010
Earlier work this paper cites.
Multiple classifier systems for robust classifier design in adversarial environments
Battista Biggio, Giorgio Fumera, and Fabio Roli · 2010
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Large-scale malware classification using random projections and neural networks
George E Dahl, Jack W Stokes, Li Deng, and Dong Yu · 2013
Earlier work this paper cites.
Detection of malicious pdf files based on hierarchical document structure
Nedim Šrndic and Pavel Laskov · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples (2014)
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Defensive distillation is not robust to adversarial examples
Nicholas Carlini and David Wagner · 2016
Earlier work this paper cites.
Hidden voice commands
Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David Wagner, and Wenchao Zhou · 2016
Earlier work this paper cites.
Robustness of classifiers: from adversarial to random noise
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami · 2016
Earlier work this paper cites.
Mastering the game of go with deep neural networks and tree search
David Silver, Aja Huang, Chris J Maddison, Arthur Guez, Laurent Sifre, George Van Den Driessche, Julian Schrittwieser, Ioannis Antonoglou, Veda Panneershelvam, Marc Lanctot, et al · 2016
Earlier work this paper cites.
Comment on "biologically inspired protection of deep networks from adversarial attacks"
Wieland Brendel and Matthias Bethge · 2017
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Cited alongside, same era.
A rotation and a translation suffice: Fooling CNNs with simple transformations
Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry · 2017
Cited alongside, same era.
Adversarial example defenses: Ensembles of weak defenses are not strong
Decision boundary analysis of adversarial examples
Warren He, Bo Li, and Dawn Song · 2018
Later among the works it cites.
Benchmarking neural network robustness to common corruptions and surface variations
Dan Hendrycks and Thomas G Dietterich · 2018
Later among the works it cites.
With friends like these, who needs adversaries?
Saumya Jetley, Nicholas Lord, and Philip Torr · 2018
Later among the works it cites.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2018
Later among the works it cites.
On the limitation of magnet defense against l1-based adversarial examples
Pei-Hsuan Lu, Pin-Yu Chen, Kang-Cheng Chen, and Chia-Mu Yu · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song · 2017
Cited alongside, same era.
Sok: Science, security and the elusive goal of security as a scientific pursuit
Cormac Herley and Paul C van Oorschot · 2017
Cited alongside, same era.
Reluplex: An efficient smt solver for verifying deep neural networks
Guy Katz, Clark Barrett, David L Dill, Kyle Julian, and Mykel J Kochenderfer · 2017
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
J Zico Kolter and Eric Wong · 2017
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
Foolbox v0.8.0: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2017
Cited alongside, same era.
Marius Mosbach, Maksym Andriushchenko, Thomas Trost, Matthias Hein, and Dietrich Klakow · 2018
Later among the works it cites.
Technical report on the cleverhans v2.1.0 adversarial examples library
Nicolas Papernot, Fartash Faghri, Nicholas Carlini, Ian Goodfellow, Reuben Feinman, Alexey Kurakin, Cihang Xie, Yash Sharma, Tom Brown, Aurko Roy, Alexander Matyasko, Vahid Behzadan, Karen Hambardzumyan, Zhishuai Zhang, Yi-Lin Juang, Zhi Li, Ryan Sheatsley, Abhibhav Garg, Jonathan Uesato, Willi Gierke, Yinpeng Dong, David Berthelot, Paul Hendricks, Jonas Rauber, and Rujun Long · 2018
Later among the works it cites.
L2-nonexpansive neural networks
Haifeng Qian and Mark N Wegman · 2018
Later among the works it cites.
Certified defenses against adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Later among the works it cites.
Bypassing feature squeezing by increasing adversary strength
Yash Sharma and Pin-Yu Chen · 2018
Later among the works it cites.
Generative adversarial examples
Yang Song, Rui Shu, Nate Kushman, and Stefano Ermon · 2018
Later among the works it cites.
Ad-versarial: Defeating perceptual ad-blocking
Florian Tramèr, Pascal Dupré, Gili Rusak, Giancarlo Pellegrino, and Dan Boneh · 2018
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Chun-Chen Tu, Paishun Ting, Pin-Yu Chen, Sijia Liu, Huan Zhang, Jinfeng Yi, Cho-Jui Hsieh, and Shin-Ming Cheng · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli · 2018
Later among the works it cites.
Towards fast computation of certified robustness for ReLU networks
Tsui-Wei Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Duane Boning, Inderjit S Dhillon, and Luca Daniel · 2018
Later among the works it cites.
Is ami (attacks meet interpretability) robust to adversarial examples?
Nicholas Carlini · 2019
Closest in time.
The efficacy of shield under different threat models
Cory Cornelius · 2019
Closest in time.
Adversarial examples are a natural consequence of test error in noise
Nic Ford, Justin Gilmer, Nicolas Carlini, and Dogus Cubuk · 2019
Closest in time.
Towards the first adversarially robust neural network model on mnist
Lukas Schott, Jonas Rauber, Matthias Bethge, and Wieland Brendel · 2019
Closest in time.
Evaluating robustness of neural networks with mixed integer programming
Vincent Tjeng, Kai Xiao, and Russ Tedrake · 2019
Closest in time.
Training for faster adversarial robustness verification via inducing ReLU stability
Kai Y. Xiao, Vincent Tjeng, Nur Muhammad Shafiullah, and Aleksander Madry · 2019
Closest in time.