Fetching the paper…
Reading the bibliography…
Recent work has shown that additive threat models, which only permit the addition of bounded noise to the pixels of an image, are insufficient for fully capturing the space of imperceivable adversarial examples.
Adversarial classification
Dalvi, N., Domingos, P., Sanghai, S., Verma, D., et al · 2004
Earlier work this paper cites.
Image quality assessment: from error visibility to structural similarity
Wang, Z., Bovik, A. C., Sheikh, H. R., and Simoncelli, E. P · 2004
Earlier work this paper cites.
Adversarial learning
Lowd, D. and Meek, C · 2005
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Spatial transformer networks
Jaderberg, M., Simonyan, K., Zisserman, A., and Kavukcuoglu, K · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., and Fei-Fei, L · 2015
Earlier work this paper cites.
Adversarial feature learning
Donahue, J., Krähenbühl, P., and Darrell, T · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Cited alongside, same era.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I. J., and Bengio, S · 2016
Cited alongside, same era.
Synthesizing robust adversarial examples
Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K · 2017
Cited alongside, same era.
Wild patterns: Ten years after the rise of adversarial machine learning
Biggio, B. and Roli, F · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
pretrained-models.pytorch
Cadene, R · 2018
Later among the works it cites.
pytorch_resnet_cifar10
Idelbayev, Y · 2018
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Later among the works it cites.
Technical report on the cleverhans v2.1.0 adversarial examples library
Papernot, N., Faghri, F., Carlini, N., Goodfellow, I., Feinman, R., Kurakin, A., Xie, C., Sharma, Y., Brown, T., Roy, A., Matyasko, A., Behzadan, V., Hambardzumyan, K., Zhang, Z., Juang, Y.-L., Li, Z., Sheatsley, R., Garg, A., Uesato, J., Gierke, W., Dong, Y., Berthelot, D., Hendricks, P., Rauber, J., and Long, R · 2018
Later among the works it cites.
Robust perception through analysis by synthesis
Schott, L., Rauber, J., Brendel, W., and Bethge, M · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Engstrom, L., Tsipras, D., Schmidt, L., and Madry, A · 2017
Cited alongside, same era.
Automatic differentiation in pytorch
Paszke, A., Gross, S., Chintala, S., Chanan, G., Yang, E., DeVito, Z., Lin, Z., Desmaison, A., Antiga, L., and Lerer, A · 2017
Cited alongside, same era.
One pixel attack for fooling deep neural networks
Su, J., Vargas, D. V., and Kouichi, S · 2017
Cited alongside, same era.
Learning transferable architectures for scalable image recognition
Zoph, B., Vasudevan, V., Shlens, J., and Le, Q. V · 2017
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D
Cited in the paper.
On the suitability of lp-norms for creating and preventing adversarial examples
Sharif, M., Bauer, L., and Reiter, M. K · 2018
Later among the works it cites.
Spatially transformed adversarial examples
Xiao, C., Zhu, J.-Y., Li, B., He, W., Liu, M., and Song, D · 2018
Later among the works it cites.
The unreasonable effectiveness of deep features as a perceptual metric
Zhang, R., Isola, P., Efros, A. A., Shechtman, E., and Wang, O · 2018
Later among the works it cites.