Fetching the paper…
Reading the bibliography…
It has been demonstrated that very simple attacks can fool highly-sophisticated neural network architectures.
Gradient-based learning applied to document recognition
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner · 1998
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky and G. Hinton · 2009
Earlier work this paper cites.
Deep sparse rectifier neural networks
X. Glorot, A. Bordes, and Y. Bengio · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
S. Gu and L. Rigazio · 2014
Earlier work this paper cites.
Statistical learning with sparsity: the lasso and generalizations
T. Hastie, R. Tibshirani, and M. Wainwright · 2015
Earlier work this paper cites.
Deep learning
Y. LeCun, Y. Bengio, and G. Hinton · 2015
Earlier work this paper cites.
Foveation-based mechanisms alleviate adversarial examples
Y. Luo, X. Boix, G. Roig, T. Poggio, and Q. Zhao · 2015
Earlier work this paper cites.
Deep learning
I. Goodfellow, Y. Bengio, and A. Courville · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
A. Kurakin, I. Goodfellow, and S. Bengio · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2016
Earlier work this paper cites.
Adversarial training methods for semi-supervised text classification
T. Miyato, A. M. Dai, and I. Goodfellow · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami · 2016
Earlier work this paper cites.
A boundary tilting persepective on the phenomenon of adversarial examples
T. Tanay and L. Griffin · 2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Improving the robustness of deep neural networks via stability training
S. Zheng, Y. Song, T. Leung, and I. Goodfellow · 2016
Cited alongside, same era.
Defense against universal adversarial perturbations
N. Akhtar, J. Liu, and A. Mian · 2017
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
Magnet and" efficient defenses against adversarial attacks" are not robust to adversarial examples
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
Generative adversarial perturbations
O. Poursaeed, I. Katsman, B. Gao, and S. Belongie · 2017
Later among the works it cites.
Foolbox v0. 8.0: A python toolbox to benchmark the robustness of machine learning models
J. Rauber, W. Brendel, and M. Bethge · 2017
Later among the works it cites.
A. S. Ross and F. Doshi-Velez · 2017
Later among the works it cites.
Upset and angri: Breaking high performance image classifiers
S. Sarkar, A. Bansal, U. Mahbub, and R. Chellappa · 2017
Later among the works it cites.
Ape-gan: Adversarial perturbation elimination with gan
S. Shen, G. Jin, K. Gao, and Y. Zhang · 2017
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
M. Cisse, Y. Adi, N. Neverova, and J. Keshet · 2017
Cited alongside, same era.
Boosting adversarial attacks with momentum
Y. Dong, F. Liao, T. Pang, H. Su, X. Hu, J. Li, and J. Zhu · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
K. Grosse, P. Manoharan, N. Papernot, M. Backes, and P. McDaniel · 2017
Cited alongside, same era.
Countering adversarial images using input transformations
C. Guo, M. Rana, M. Cisse, and L. van der Maaten · 2017
Cited alongside, same era.
Generative adversarial trainer: Defense to adversarial perturbations with gan
H. Lee, S. Han, and J. Lee · 2017
Cited alongside, same era.
Defense against adversarial attacks using high-level representation guided denoiser
F. Liao, M. Liang, Y. Dong, T. Pang, J. Zhu, and X. Hu · 2017
Cited alongside, same era.
Safetynet: Detecting and rejecting adversarial examples robustly
J. Lu, T. Issaranon, and D. Forsyth · 2017
Cited alongside, same era.
Later among the works it cites.
One pixel attack for fooling deep neural networks
J. Su, D. V. Vargas, and S. Kouichi · 2017
Later among the works it cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
W. Xu, D. Evans, and Y. Qi · 2017
Later among the works it cites.
Efficient defenses against adversarial attacks
V. Zantedeschi, M.-I. Nicolae, and A. Rawat · 2017
Later among the works it cites.
Threat of adversarial attacks on deep learning in computer vision: A survey
N. Akhtar and A. Mian · 2018
Later among the works it cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Later among the works it cites.
Enhancing robustness of machine learning systems via data transformations
A. N. Bhagoji, D. Cullina, C. Sitawarin, and P. Mittal · 2018
Later among the works it cites.
Thermometer encoding: One hot way to resist adversarial examples
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow · 2018
Later among the works it cites.
Characterizing adversarial subspaces using local intrinsic dimensionality
X. Ma, B. Li, Y. Wang, S. M. Erfani, S. Wijewickrema, G. Schoenebeck, D. Song, M. E. Houle, and J. Bailey · 2018
Later among the works it cites.
Deflecting adversarial attacks with pixel deflection
A. Prakash, N. Moran, S. Garber, A. DiLillo, and J. Storer · 2018
Later among the works it cites.
Searching for activation functions
P. Ramachandran, B. Zoph, and Q. V. Le · 2018
Later among the works it cites.
Mobilenetv2: Inverted residuals and linear bottlenecks
M. Sandler, A. Howard, M. Zhu, A. Zhmoginov, and L.-C. Chen · 2018
Later among the works it cites.
Trust region based adversarial attack on neural networks
Z. Yao, A. Gholami, P. Xu, K. Keutzer, and M. Mahoney · 2018
Later among the works it cites.