Fetching the paper…
Reading the bibliography…
We present a black-box adversarial attack algorithm which sets new state-of-the-art model evasion rates for query efficiency in the $\ell_\infty$ and $\ell_2$ metrics, where only loss-oracle access to the model is available.
Bandit based monte-carlo planning
Kocsis, L. and Szepesvári, C · 2006
Earlier work this paper cites.
A search strategy using a hamming-distance oracle
Maurer, P. M · 2009
Earlier work this paper cites.
Optimistic optimization of a deterministic function without the knowledge of its smoothness
Munos, R · 2011
Earlier work this paper cites.
Query strategies for evading convex-inducing classifiers
Nelson, B., Rubinstein, B. I., Huang, L., Joseph, A. D., Lee, S. J., Rao, S., and Tygar, J · 2012
Earlier work this paper cites.
Query matrices for retrieving binary vectors based on the hamming distance oracle
Vaishampayan, V. A · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Graphbpt: An efficient hierarchical data structure for image representation and probabilistic inference
Al-Dujaili, A., Merciol, F., and Lefèvre, S · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Liu, Y., Chen, X., Liu, C., and Song, D · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
Embedded bandits for large-scale black-box optimization
Al-Dujaili, A. and Suresh, S · 2017
Earlier work this paper cites.
Exploring the space of black-box attacks on deep neural networks
Bhagoji, A. N., He, W., Li, B., and Song, D · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J · 2017
Cited alongside, same era.
Machine learning as an adversarial service: Learning black-box adversarial examples
Hayes, J. and Danezis, G · 2017
Cited alongside, same era.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I. J., and Bengio, S · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Simple black-box adversarial attacks on deep neural networks
Narodytska, N. and Kasiviswanathan, S. P · 2017
Back to basics: Benchmarking canonical evolution strategies for playing atari
Chrabaszcz, P., Loshchilov, I., and Hutter, F · 2018
Later among the works it cites.
On visual hallmarks of robustness to adversarial malware
Huang, A., Al-Dujaili, A., Hemberg, E., and O’Reilly, U.-M · 2018
Later among the works it cites.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J · 2018
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Tu, C.-C., Ting, P., Chen, P.-Y., Liu, S., Zhang, H., Yi, J., Hsieh, C.-J., and Cheng, S.-M · 2018
Later among the works it cites.
Generating adversarial examples with adversarial networks, 2018
Xiao, C., Li, B., Zhu, J.-Y., He, W., Liu, M., and Song, D · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
Evolution strategies as a scalable alternative to reinforcement learning
Salimans, T., Ho, J., Chen, X., Sidor, S., and Sutskever, I · 2017
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Tramèr, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2017
Cited alongside, same era.
Multi-objective simultaneous optimistic optimization
Al-Dujaili, A. and Suresh, S · 2018
Cited alongside, same era.
Adversarial deep learning for robust detection of binary encoded malware
Al-Dujaili, A., Huang, A., Hemberg, E., and O’Reilly, U.-M · 2018
Cited alongside, same era.
signSGD: Compressed optimisation for non-convex problems
Bernstein, J., Wang, Y.-X., Azizzadenesheli, K., and Anandkumar, A · 2018
Cited alongside, same era.
Wild patterns: Ten years after the rise of adversarial machine learning
Biggio, B. and Roli, F · 2018
Cited alongside, same era.
Later among the works it cites.
Sparse optimization theory and methods
Zhao, Y.-B · 2018
Later among the works it cites.
Distributionally adversarial attack
Zheng, T., Chen, C., and Ren, K · 2018
Later among the works it cites.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, J. Z · 2019
Closest in time.
Explaining vulnerabilities of deep learning to adversarial malware binaries
Demetrio, L., Biggio, B., Giovanni, L., Roli, F., and Alessandro, A · 2019
Closest in time.
Prior convictions: Black-box adversarial attacks with bandits and priors
Ilyas, A., Engstrom, L., and Madry, A · 2019
Closest in time.
signSGD via zeroth-order oracle
Liu, S., Chen, P.-Y., Chen, X., and Hong, M · 2019
Closest in time.
A simple explanation for the existence of adversarial examples with small hamming distance
Shamir, A., Safran, I., Ronen, E., and Dunkelman, O · 2019
Closest in time.