Fetching the paper…
Reading the bibliography…
We propose an intriguingly simple method for the construction of adversarial images in the black-box setting.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Human-level control through deep reinforcement learning
Mnih, V., Kavukcuoglu, K., Silver, D., Rusu, A. A., Veness, J., Bellemare, M. G., Graves, A., Riedmiller, M. A., Fidjeland, A., Ostrovski, G., Petersen, S., Beattie, C., Sadik, A., Antonoglou, I., King, H., Kumaran, D., Wierstra, D., Legg, S., and Hassabis, D · 2015
Earlier work this paper cites.
Deep speech 2 : End-to-end speech recognition in english and mandarin
Amodei, D., Ananthanarayanan, S., Anubhai, R., Bai, J., Battenberg, E., Case, C., Casper, J., Catanzaro, B., Chen, J., Chrzanowski, M., Coates, A., Diamos, G., Elsen, E., Engel, J., Fan, L., Fougner, C., Hannun, A. Y., Jun, B., Han, T., LeGresley, P., Li, X., Lin, L., Narang, S., Ng, A. Y., Ozair, S., Prenger, R., Qian, S., Raiman, J., Satheesh, S., Seetapun, D., Sengupta, S., Wang, C., Wang, Y., Wang, Z., Xiao, B., Xie, Y., Yogatama, D., Zhan, J., and Zhu, Z · 2016
Earlier work this paper cites.
A study of the effect of JPG compression on adversarial images
Dziugaite, G. K., Ghahramani, Z., and Roy, D · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Earlier work this paper cites.
Vulnerability of deep reinforcement learning to policy induction attacks
Behzadan, V. and Munir, A · 2017
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2017
Earlier work this paper cites.
ZOO: zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C · 2017
Cited alongside, same era.
Countering adversarial images using input transformations
Guo, C., Rana, M., Cissé, M., and van der Maaten, L · 2017
Cited alongside, same era.
Adversarial examples detection in deep networks with convolutional filter statistics
Li, X. and Li, F · 2017
Cited alongside, same era.
Safetynet: Detecting and rejecting adversarial examples robustly
Lu, J., Issaranon, T., and Forsyth, D. A · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Feature squeezing: Detecting adversarial examples in deep neural networks
Xu, W., Evans, D., and Qi, Y · 2017
Later among the works it cites.
On the robustness of the CVPR 2018 white-box adversarial example defenses
Athalye, A. and Carlini, N · 2018
Later among the works it cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D. A · 2018
Later among the works it cites.
Audio adversarial examples: Targeted attacks on speech-to-text
Carlini, N. and Wagner, D. A · 2018
Later among the works it cites.
Query-efficient hard-label black-box attack: An optimization-based approach
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Magnet: A two-pronged defense against adversarial examples
Meng, D. and Chen, H · 2017
Cited alongside, same era.
On detecting adversarial perturbations
Metzen, J. H., Genewein, T., Fischer, V., and Bischoff, B · 2017
Cited alongside, same era.
Universal adversarial perturbations
Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., and Frossard, P · 2017
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Tramèr, F., Kurakin, A., Papernot, N., Boneh, D., and McDaniel, P. D · 2017
Cited alongside, same era.
Adversarial examples for semantic segmentation and object detection
Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., and Yuille, A. L · 2017
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D. A
Cited in the paper.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D. A
Cited in the paper.
Cheng, M., Le, T., Chen, P., Yi, J., Zhang, H., and Hsieh, C · 2018
Later among the works it cites.
Adversarial vulnerability for any classifier
Fawzi, A., Fawzi, H., and Fawzi, O · 2018
Later among the works it cites.
Low frequency adversarial perturbations
Guo, C., Frank, J. S., and Weinberger, K. Q · 2018
Later among the works it cites.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J · 2018
Later among the works it cites.
Are adversarial examples inevitable?
Shafahi, A., Huang, W. R., Studer, C., Feizi, S., and Goldstein, T · 2018
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Tu, C., Ting, P., Chen, P., Liu, S., Zhang, H., Yi, J., Hsieh, C., and Cheng, S · 2018
Later among the works it cites.