Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Original
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, and I. Goodfellow · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Original
I. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Discrete cosine transform: algorithms, advantages, applications
K Ramamohan Rao and Ping Yip · 2014
Earlier work this paper cites.
Adversarial examples in the physical world
Original
A. Kurakin, I. Goodfellow, and S. Bengio · 2016
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Original
W. Brendel, J. Rauber, and M. Bethge · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Original
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Original
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Ead: Elastic-net attacks to deep neural networks via adversarial examples
Original
P. Y. Chen, Y. Sharma, H. Zhang, J. Yi, and C. Hsieh · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
P. Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C. Hsieh · 2017
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Original
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li · 2017
Earlier work this paper cites.
Defense against adversarial attacks using high-level representation guided denoiser
Original
F. Liao, M. Liang, Y. Dong, T. Pang, X. Hu, and J. Zhu · 2017
Earlier work this paper cites.