Fetching the paper…
Reading the bibliography…
Deep neural networks have been shown to exhibit an intriguing vulnerability to adversarial input images corrupted with imperceptible perturbations.
Convex Optimization
S. Boyd and L. Vandenberghe · 2004
Earlier work this paper cites.
MNIST handwritten digit database, 2010
Y. LeCun and C. Cortes · 2010
Earlier work this paper cites.
Gnu parallel - the command-line power tool
O. Tange · 2011
Earlier work this paper cites.
Adversarial label flips attack on support vector machines
H. Xiao, H. Xiao, and C. M. Eckert · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Generative adversarial nets
I. J. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. C. Courville, and Y. Bengio · 2014
Earlier work this paper cites.
Auto-encoding variational bayes
D. P. Kingma and M. Welling · 2014
Earlier work this paper cites.
Conditional generative adversarial nets
M. Mirza and S. Osindero · 2014
Earlier work this paper cites.
Unpaired image-to-image translation using cycle-consistent adversarial networks
J.-Y. Zhu, T. Park, P. Isola, and A. A. Efros · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Adam: a method for stochastic optimization (2014)
D. Kingma and J. Ba · 2015
Earlier work this paper cites.
Deep learning face attributes in the wild
Z. Liu, P. Luo, X. Wang, and X. Tang · 2015
Earlier work this paper cites.
Support vector machines under adversarial label contamination
H. Xiao, B. Biggio, B. Nelson, H. Xiao, C. M. Eckert, and F. Roli · 2015
Earlier work this paper cites.
Infogan: Interpretable representation learning by information maximizing generative adversarial nets
X. Chen, Y. Duan, R. Houthooft, J. Schulman, I. Sutskever, and P. Abbeel · 2016
Earlier work this paper cites.
Autoencoding beyond pixels using a learned similarity metric
A. B. L. Larsen, S. K. Sønderby, and O. Winther · 2016
Earlier work this paper cites.
Convolutional network for attribute-driven and identity-preserving human face generation
M. Li, W. Zuo, and D. Zhang · 2016
Earlier work this paper cites.
Deep identity-aware transfer of facial attributes
M. Li, W. Zuo, and D. Zhang · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
N. Papernot, P. D. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami · 2016
Earlier work this paper cites.
Invertible conditional gans for image editing
G. Perarnau, J. van de Weijer, B. Raducanu, and J. M. Álvarez · 2016
Earlier work this paper cites.
Unsupervised representation learning with deep convolutional generative adversarial networks
A. Radford, L. Metz, and S. Chintala · 2016
Earlier work this paper cites.
Generative image modeling using style and structure adversarial networks
X. Wang and A. Gupta · 2016
Earlier work this paper cites.
T. B. Brown, D. Mané, A. Roy, M. Abadi, and J. Gilmer · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. A. Wagner · 2017
Earlier work this paper cites.
Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
X. Chen, C. Liu, B. Li, K. Lu, and D. Song · 2017
Earlier work this paper cites.
Measuring the Robustness of Neural Networks via Minimal Adversarial Examples
S. Dathathri, S. Zheng, S. Gao, and R. Murray · 2017
Cited alongside, same era.
A rotation and a translation suffice: Fooling cnns with simple transformations
L. Engstrom, D. Tsipras, L. Schmidt, and A. Madry · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
T. Gu, B. Dolan-Gavitt, and S. Garg · 2017
Cited alongside, same era.
Attgan: Facial attribute editing by only changing what you want
Z. He, W. Zuo, M. Kan, S. Shan, and X. Chen · 2017
Cited alongside, same era.
Generative attribute controller with conditional filtered generative adversarial networks
T. Kaneko, K. Hiramatsu, and K. Kashino · 2017
Cited alongside, same era.
Adversarial vulnerability for any classifier
A. Fawzi, H. Fawzi, and O. Fawzi · 2018
Later among the works it cites.
Analysis of classifiers’ robustness to adversarial perturbations
A. Fawzi, O. Fawzi, and P. Frossard · 2018
Later among the works it cites.
I. J. Goodfellow · 2018
Later among the works it cites.
Black-box adversarial attacks with limited queries and information
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin · 2018
Later among the works it cites.
Prior convictions: Black-box adversarial attacks with bandits and priors
A. Ilyas, L. Engstrom, and A. Madry · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
T. Kim, B. Kim, M. Cha, and J. Kim · 2017
Cited alongside, same era.
Understanding black-box predictions via influence functions
P. W. Koh and P. Liang · 2017
Cited alongside, same era.
Adversarial examples in the physical world
A. Kurakin, I. J. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Fader networks: Manipulating images by sliding attributes
G. Lample, N. Zeghidour, N. Usunier, A. Bordes, L. Denoyer, et al · 2017
Cited alongside, same era.
Unsupervised image-to-image translation networks
M.-Y. Liu, T. Breuel, and J. Kautz · 2017
Cited alongside, same era.
Universal adversarial perturbations
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard · 2017
Cited alongside, same era.
Conditional image synthesis with auxiliary classifier gans
A. Odena, C. Olah, and J. Shlens · 2017
Cited alongside, same era.
Y. Lu, Y.-W. Tai, and C.-K. Tang · 2018
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Later among the works it cites.
Nag: Network for adversary generation
K. R. Mopuri, U. Ojha, U. Garg, and R. V. Babu · 2018
Later among the works it cites.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Later among the works it cites.
Adversarially robust generalization requires more data
L. Schmidt, S. Santurkar, D. Tsipras, K. Talwar, and A. Madry · 2018
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein · 2018
Later among the works it cites.
Adversarial generative nets: Neural network attacks on state-of-the-art face recognition
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter · 2018
Later among the works it cites.
Constructing unrestricted adversarial examples with generative models
Y. Song, R. Shu, N. Kushman, and S. Ermon · 2018
Later among the works it cites.
Spectral signatures in backdoor attacks
B. Tran, J. Li, and A. Madry · 2018
Later among the works it cites.
Spatially transformed adversarial examples
C. Xiao, J.-Y. Zhu, B. Li, W. He, M. Liu, and D. X. Song · 2018
Later among the works it cites.
Dna-gan: Learning disentangled representations from multi-attribute images
T. Xiao, J. Hong, and J. Ma · 2018
Later among the works it cites.
Bdd100k: A diverse driving video database with scalable annotation tooling
F. Yu, W. Xian, Y. Chen, F. Liu, M. Liao, V. Madhavan, and T. Darrell · 2018
Later among the works it cites.
Generating natural adversarial examples
Z. Zhao, D. Dua, and S. Singh · 2018
Later among the works it cites.
Fast geometrically-perturbed adversarial faces
A. Dabouei, S. Soleymani, J. M. Dawson, and N. M. Nasrabadi · 2019
Closest in time.
Beyond pixel norm-balls: Parametric adversaries using an analytically differentiable renderer
H.-T. D. Liu, M. Tao, C.-L. Li, D. Nowrouzezahrai, and A. Jacobson · 2019
Closest in time.
Robustness via curvature regularization, and vice versa
S.-M. Moosavi-Dezfooli, A. Fawzi, J. Uesato, and P. Frossard · 2019
Closest in time.
Are adversarial examples inevitable?
A. Shafahi, W. R. Huang, C. Studer, S. Feizi, and T. Goldstein · 2019
Closest in time.
Clean-label backdoor attacks, 2019
A. Turner, D. Tsipras, and A. Madry · 2019
Closest in time.
Camou: Learning physical vehicle camouflages to adversarially attack detectors in the wild
Y. Zhang, H. Foroosh, P. David, and B. Gong · 2019
Closest in time.