Fetching the paper…
Reading the bibliography…
Recent work has documented the susceptibility of deep learning systems to adversarial examples, but most such attacks directly manipulate the digital input to a classifier.
ImageNet: A Large-Scale Hierarchical Image Database
Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., and Fei-Fei, L · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
Synthesizing robust adversarial examples
Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K · 2017
Earlier work this paper cites.
Brown, T. B., Mané, D., Roy, A., Abadi, M., and Gilmer, J · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
A rotation and a translation suffice: Fooling cnns with simple transformations
Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., and Madry, A · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Universal adversarial perturbations
Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., and Frossard, P · 2017
Cited alongside, same era.
Adversarial attacks beyond the image space
Zeng, X., Liu, C., Wang, Y.-S., Qiu, W., Xie, L., Tai, Y.-W., Tang, C. K., and Yuille, A. L · 2017
Later among the works it cites.
Loss functions for image restoration with neural networks
Zhao, H., Gallo, O., Frosio, I., and Kautz, J · 2017
Later among the works it cites.
Why do deep convolutional networks generalize so poorly to small image transformations?
Azulay, A. and Weiss, Y · 2018
Later among the works it cites.
Robust physical-world attacks on deep learning models
Evtimov, I., Eykholt, K., Fernandes, E., Kohno, T., Li, B., Prakash, A., Rahmati, A., and Song, D · 2018
Later among the works it cites.
Sok: Security and privacy in machine learning
Papernot, N., McDaniel, P., Sinha, A., and Wellman, M. P · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Automatic differentiation in pytorch
Paszke, A., Gross, S., Chintala, S., Chanan, G., Yang, E., DeVito, Z., Lin, Z., Desmaison, A., Antiga, L., and Lerer, A · 2017
Cited alongside, same era.
No need to worry about adversarial examples in object detection in autonomous vehicles
Lu, J., Sibai, H., Fabry, E., and Forsyth, D
Cited in the paper.
Standard detectors aren’t (currently) fooled by physical adversarial stop signs
Lu, J., Sibai, H., Fabry, E., and Forsyth, D
Cited in the paper.
One pixel attack for fooling deep neural networks
Su, J., Vargas, D. V., and Sakurai, K · 2019
Closest in time.