Fetching the paper…
Reading the bibliography…
Numerous methods for crafting adversarial examples were proposed recently with high success rate.
Gradient-based learning applied to document recognition
Y. Lecun, L. Bottou, Y. Bengio, and P. Haffner. 1998 · 1998
Earlier work this paper cites.
The mnist database of handwritten digits
Yann LeCun, Corinna Cortes, and Christopher JC Burges. 1998 · 1998
Earlier work this paper cites.
Adversarial classification. In Proceedings of the Tenth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining . 99–108
Nilesh N. Dalvi, Pedro M. Domingos, Mausam, Sumit K. Sanghai, and Deepak Verma. 2004 · 2004
Earlier work this paper cites.
Good Word Attacks on Statistical Spam Filters.. In CEAS , Vol. 2005
Daniel Lowd and Christopher Meek. 2005 · 2005
Earlier work this paper cites.
ImageNet: A large-scale hierarchical image database. In 2009 IEEE Computer Society Conference on Computer Vision and Pattern Recognition (CVPR) . 248–255
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Fei-Fei Li. 2009 · 2009
Earlier work this paper cites.
A self-driving technology development company
Waymo. 2009 · 2009
Earlier work this paper cites.
An Abstraction-Refinement Approach to Verification of Artificial Neural Networks. In Proceedings of the 22nd International Conference on Computer Aided Verification (CAV) . 243–257
Luca Pulina and Armando Tacchella. 2010 · 2010
Earlier work this paper cites.
An Analysis of Single-Layer Networks in Unsupervised Feature Learning. In Proceedings of the Fourteenth International Conference on Artificial Intelligence and Statistics . 215–223
Adam Coates, Andrew Y. Ng, and Honglak Lee. 2011 · 2011
Earlier work this paper cites.
Deep Neural Networks Segment Neuronal Membranes in Electron Microscopy Images. In Proceedings of the 26th Annual Conference on Neural Information Processing Systems. 2852–2860
Dan C. Ciresan, Alessandro Giusti, Luca Maria Gambardella, and Jürgen Schmidhuber. 2012 · 2012
Earlier work this paper cites.
Deep Neural Networks for Acoustic Modeling in Speech Recognition: The Shared Views of Four Research Groups
G. Hinton, L. Deng, D. Yu, G. E. Dahl, A. Mohamed, N. Jaitly, A. Senior, V. Vanhoucke, P. Nguyen, T. N. Sainath, and B. Kingsbury. 2012 · 2012
Earlier work this paper cites.
Maxout Networks. In Proceedings of the 30th International Conference on Machine Learning . 1319–1327
Ian J. Goodfellow, David Warde-Farley, Mehdi Mirza, Aaron C. Courville, and Yoshua Bengio. 2013 · 2013
Earlier work this paper cites.
Looking at the bag is not enough to find the bomb: an evasion of structural methods for malicious pdf files detection. In Proceedings of the 8th ACM SIGSAC symposium on Information, computer and communications security . ACM, 119–130
Davide Maiorca, Igino Corona, and Giorgio Giacinto. 2013 · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples. In International Conference on Learning Representations
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014 · 2014
Earlier work this paper cites.
Large-Scale Video Classification with Convolutional Neural Networks. In Proceedings of 2014 IEEE Conference on Computer Vision and Pattern Recognition . 1725–1732
Andrej Karpathy, George Toderici, Sanketh Shetty, Thomas Leung, Rahul Sukthankar, and Fei-Fei Li. 2014 · 2014
Earlier work this paper cites.
Glove: Global Vectors for Word Representation. In Proceedings of the 2014 Conference on Empirical Methods in Natural Language Processing . 1532–1543
Jeffrey Pennington, Richard Socher, and Christopher D. Manning. 2014 · 2014
Earlier work this paper cites.
Practical Evasion of a Learning-Based Classifier: A Case Study. In 2014 IEEE Symposium on Security and Privacy . 197–211
Nedim Srndic and Pavel Laskov. 2014 · 2014
Earlier work this paper cites.
Intriguing properties of neural networks. In Proceedings of International Conference on Learning Representations
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014 · 2014
Earlier work this paper cites.
Natural evolution strategies
Daan Wierstra, Tom Schaul, Tobias Glasmachers, Yi Sun, Jan Peters, and Jürgen Schmidhuber. 2014 · 2014
Earlier work this paper cites.
An evasion and counter-evasion study in malicious websites detection. In IEEE Conference on Communications and Network Security . IEEE, 265–273
Li Xu, Zhenxin Zhan, Shouhuai Xu, and Keying Ye. 2014 · 2014
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. In Proceedings of 2015 IEEE Conference on Computer Vision and Pattern Recognition . 427–436
Anh Mai Nguyen, Jason Yosinski, and Jeff Clune. 2015 · 2015
Earlier work this paper cites.
Efficient Classifier Training to Minimize False Merges in Electron Microscopy Segmentation. In Proceedings of 2015 IEEE International Conference on Computer Vision . 657–665
Toufiq Parag, Dan C. Ciresan, and Alessandro Giusti. 2015 · 2015
Earlier work this paper cites.
Recognizing Functions in Binaries with Neural Networks. In Proceedings of the 24th USENIX Security Symposium, USENIX Security . 611–626
Eui Chul Richard Shin, Dawn Song, and Reza Moazzezi. 2015 · 2015
Earlier work this paper cites.
Towards Vision-Based Deep Reinforcement Learning for Robotic Motion Control
Fangyi Zhang, Jürgen Leitner, Michael Milford, Ben Upcroft, and Peter I. Corke. 2015 · 2015
Earlier work this paper cites.
Globally Normalized Transition-Based Neural Networks. In Proceedings of the 54th Annual Meeting of the Association for Computational Linguistics
Daniel Andor, Chris Alberti, David Weiss, Aliaksei Severyn, Alessandro Presta, Kuzman Ganchev, Slav Petrov, and Michael Collins. 2016 · 2016
Earlier work this paper cites.
Measuring Neural Net Robustness with Constraints. In NIPS . 2613–2621
Osbert Bastani, Yani Ioannou, Leonidas Lampropoulos, Dimitrios Vytiniotis, Aditya V. Nori, and Antonio Criminisi. 2016 · 2016
Earlier work this paper cites.
Hidden Voice Commands. In 25th USENIX Security Symposium . 513–530
Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David A. Wagner, and Wenchao Zhou. 2016 · 2016
Earlier work this paper cites.
Deep Learning
Ian J. Goodfellow, Yoshua Bengio, and Aaron C. Courville. 2016 · 2016
Earlier work this paper cites.
Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) . 770–778
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. In Proceedings of 2016 IEEE Conference on Computer Vision and Pattern Recognition . 2574–2582
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016 · 2016
Earlier work this paper cites.
Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples
Nicolas Papernot, Patrick D. McDaniel, and Ian J. Goodfellow. 2016a · 2016
Earlier work this paper cites.
Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security . 1528–1540
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter. 2016 · 2016
Earlier work this paper cites.
Rethinking the Inception Architecture for Computer Vision. In 2016 IEEE Conference on Computer Vision and Pattern Recognition, (CVPR) . 2818–2826
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jonathon Shlens, and Zbigniew Wojna. 2016 · 2016
Earlier work this paper cites.
Exploring the space of adversarial images. In 2016 International Joint Conference on Neural Networks, IJCNN 2016, Vancouver, BC, Canada, July 24-29, 2016 . IEEE, 426–433
Pedro Tabacof and Eduardo Valle. 2016 · 2016
Earlier work this paper cites.
Automatically evading classifiers: A Case Study on PDF Malware Classifiers. In Proceedings of the 2016 Network and Distributed Systems Symposium . 21–24
Weilin Xu, Yanjun Qi, and David Evans. 2016 · 2016
Earlier work this paper cites.
Derivative-free optimization via classification. In Thirtieth AAAI Conference on Artificial Intelligence
Yang Yu, Hong Qian, and Yi-Qi Hu. 2016 · 2016
Earlier work this paper cites.
Exploring the Space of Black-box Attacks on Deep Neural Networks
Arjun Nitin Bhagoji, Warren He, Bo Li, and Dawn Song. 2017 · 2017
Cited alongside, same era.
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer. 2017 · 2017
Cited alongside, same era.
Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy . 39–57
Nicholas Carlini and David A. Wagner. 2017b · 2017
Cited alongside, same era.
ZOO: Zeroth Order Optimization Based Black-box Attacks to Deep Neural Networks without Training Substitute Models. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security . 15–26
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. 2017 · 2017
Cited alongside, same era.
Yes, machine learning can be more secure! a case study on android malware detection
Decision boundary analysis of adversarial examples. In Proceedings of International Conference on Learning Representations
Warren He, Bo Li, and Dawn Song. 2018 · 2018
Later among the works it cites.
Texas becomes the latest state to get a self-driving car service
Peter Holley. 2018 · 2018
Later among the works it cites.
Black-box Adversarial Attacks with Limited Queries and Information. In Proceedings of the 35th International Conference on Machine Learning . 2142–2151
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018 · 2018
Later among the works it cites.
Adversarial Examples for Generative Models. In Proceedings of 2018 IEEE Security and Privacy Workshops . 36–42
Jernej Kos, Ian Fischer, and Dawn Song. 2018 · 2018
Later among the works it cites.
Learning hand-eye coordination for robotic grasping with deep learning and large-scale data collection
Sergey Levine, Peter Pastor, Alex Krizhevsky, Julian Ibarz, and Deirdre Quillen. 2018 · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Ambra Demontis, Marco Melis, Battista Biggio, Davide Maiorca, Daniel Arp, Konrad Rieck, Igino Corona, Giorgio Giacinto, and Fabio Roli. 2017 · 2017
Cited alongside, same era.
Formal Verification of Piece-Wise Linear Feed-Forward Neural Networks. In Proceedings of the 15th International Symposium on Automated Technology for Verification and Analysis . 269–286
Rüdiger Ehlers. 2017 · 2017
Cited alongside, same era.
Note on Attacking Object Detectors with Adversarial Stickers
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Dawn Song, Tadayoshi Kohno, Amir Rahmati, Atul Prakash, and Florian Tramèr. 2017 · 2017
Cited alongside, same era.
Adversarial examples for malware detection. In European Symposium on Research in Computer Security . Springer, 62–79
Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes, and Patrick McDaniel. 2017 · 2017
Cited alongside, same era.
Google’s Cloud Vision API is Not Robust to Noise. In Proceedings of the 16th IEEE International Conference on Machine Learning and Applications . 101–105
Hossein Hosseini, Baicen Xiao, and Radha Poovendran. 2017 · 2017
Cited alongside, same era.
Densely Connected Convolutional Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition . 2261–2269
Gao Huang, Zhuang Liu, Laurens van der Maaten, and Kilian Q. Weinberger. 2017b · 2017
Cited alongside, same era.
Query-Efficient Black-box Adversarial Examples
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2017 · 2017
Cited alongside, same era.
Reluplex: An Efficient SMT Solver for Verifying Deep Neural Networks. In Proceedings of the 29th International Conference on Computer Aided Verification . 97–117
Guy Katz, Clark W. Barrett, David L. Dill, Kyle Julian, and Mykel J. Kochenderfer. 2017 · 2017
Cited alongside, same era.
Defense Against Adversarial Attacks Using High-Level Representation Guided Denoiser. In 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR . 1778–1787
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Xiaolin Hu, and Jun Zhu. 2018 · 2018
Later among the works it cites.
DeepGauge: multi-granularity testing criteria for deep learning systems. In Proceedings of the 33rd ACM/IEEE International Conference on Automated Software Engineering . 120–131
Lei Ma, Felix Juefei-Xu, Fuyuan Zhang, Jiyuan Sun, Minhui Xue, Bo Li, Chunyang Chen, Ting Su, Li Li, Yang Liu, Jianjun Zhao, and Yadong Wang. 2018 · 2018
Later among the works it cites.
Towards Deep Learning Models Resistant to Adversarial Attacks. In Proceedings of International Conference on Learning Representations
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018 · 2018
Later among the works it cites.
Efficient Characterization and Classification of Malware Using Deep Learning. In 2018 Resilience Week (RWS) . 77–83
L. D. L. Rosa, S. Kilgallon, T. Vanderbruggen, and J. Cavazos. 2018 · 2018
Later among the works it cites.
Reachability Analysis of Deep Neural Networks with Provable Guarantees. In Proceedings of the Twenty-Seventh International Joint Conference on Artificial Intelligence . 2651–2659
Wenjie Ruan, Xiaowei Huang, and Marta Kwiatkowska. 2018 · 2018
Later among the works it cites.
Fast and Effective Robustness Certification. In Advances in Neural Information Processing Systems . 10825–10836
Gagandeep Singh, Timon Gehr, Matthew Mirman, Markus Püschel, and Martin T. Vechev. 2018 · 2018
Later among the works it cites.
DARTS: Deceiving Autonomous Cars with Toxic Signs
Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Mung Chiang, and Prateek Mittal. 2018 · 2018
Later among the works it cites.
DeepMem: Learning Graph Neural Network Models for Fast and Robust Memory Forensic Analysis. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . 606–618
Wei Song, Heng Yin, Chang Liu, and Dawn Song. 2018 · 2018
Later among the works it cites.
Youcheng Sun, Xiaowei Huang, and Daniel Kroening. 2018a · 2018
Later among the works it cites.
Formal Security Analysis of Neural Networks using Symbolic Intervals. In Proceedings of the 27th USENIX Security Symposium on Security . 1599–1614
Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana. 2018 · 2018
Later among the works it cites.
Feature-Guided Black-Box Safety Testing of Deep Neural Networks. In Proceedings of the 24th International Conference on Tools and Algorithms for the Construction and Analysis of Systems . 408–426
Matthew Wicker, Xiaowei Huang, and Marta Kwiatkowska. 2018 · 2018
Later among the works it cites.
Spatially Transformed Adversarial Examples. In International Conference on Learning Representations
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song. 2018 · 2018
Later among the works it cites.
CommanderSong: A Systematic Approach for Practical Adversarial Voice Recognition. In 27th USENIX Security Symposium, USENIX Security . 49–64
Xuejing Yuan, Yuxuan Chen, Yue Zhao, Yunhui Long, Xiaokang Liu, Kai Chen, Shengzhi Zhang, Heqing Huang, Xiaofeng Wang, and Carl A. Gunter. 2018 · 2018
Later among the works it cites.
Generating Natural Adversarial Examples. In International Conference on Learning Representations
Zhengli Zhao, Dheeru Dua, and Sameer Singh. 2018 · 2018
Later among the works it cites.
GenAttack: practical black-box attacks with gradient-free optimization. In Proceedings of the Genetic and Evolutionary Computation Conference . 1111–1119
Moustafa Alzantot, Yash Sharma, Supriyo Chakraborty, Huan Zhang, Cho-Jui Hsieh, and Mani B. Srivastava. 2019 · 2019
Closest in time.
Accurate, reliable and fast robustness evaluation
Wieland Brendel, Jonas Rauber, Matthias Kümmerer, Ivan Ustyuzhaninov, and Matthias Bethge. 2019 · 2019
Closest in time.
A critique of the DeepSec Platform for Security Analysis of Deep Learning Models
Nicholas Carlini. 2019 · 2019
Closest in time.
Procedural Noise Adversarial Examples for Black-Box Attacks on Deep Convolutional Networks. In CCS 2019 (accepted)
Kenneth T Co, Luis Muñoz-González, Sixte de Maupeou, and Emil C Lupu. 2019 · 2019
Closest in time.
Prior Convictions: Black-box Adversarial Attacks with Bandits and Priors. In 7th International Conference on Learning Representations (ICLR)
Andrew Ilyas, Logan Engstrom, and Aleksander Madry. 2019 · 2019
Closest in time.
Connecting the Digital and Physical World: Improving the Robustness of Adversarial Attacks. In The Thirty-Third AAAI Conference on Artificial Intelligence . 962–969
Steve T. K. Jan, Joseph Messou, Yen-Chen Lin, Jia-Bin Huang, and Gang Wang. 2019 · 2019
Closest in time.
MNIST Adversarial Examples Challenge
Madry Lab. 2019 · 2019
Closest in time.
Towards improved testing for deep learning. In Proceedings of the 41st International Conference on Software Engineering: New Ideas and Emerging Results (ICSE) . 85–88
Jasmine Sekhon and Cody Fleming. 2019 · 2019
Closest in time.
Curls & Whey: Boosting Black-Box Adversarial Attacks. In Computer Vision and Pattern Recognition (CVPR), 2019
Yucheng Shi, Siyu Wang, and Yahong Han. 2019 · 2019
Closest in time.
An Abstract Domain for Certifying Neural Networks. In POPL
Gagandeep Singh, Timon Gehr, Markus Püschel, and Martin Vechev. 2019 · 2019
Closest in time.
One Pixel Attack for Fooling Deep Neural Networks
J. Su, D. V. Vargas, and K. Sakurai. 2019 · 2019
Closest in time.
Evaluating Robustness Of Neural Networks With Mixed Integer Programming
Vincent Tjeng, Kai Xiao, and Russ Tedrake. 2019 · 2019
Closest in time.
AutoZOOM: Autoencoder-Based Zeroth Order Optimization Method for Attacking Black-Box Neural Networks. In The Thirty-Third AAAI Conference on Artificial Intelligence . 742–749
Chun-Chen Tu, Pai-Shun Ting, Pin-Yu Chen, Sijia Liu, Huan Zhang, Jinfeng Yi, Cho-Jui Hsieh, and Shin-Ming Cheng. 2019 · 2019
Closest in time.
DeepHunter: a coverage-guided fuzz testing framework for deep neural networks. In Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA) . 146–157
Xiaofei Xie, Lei Ma, Felix Juefei-Xu, Minhui Xue, Hongxu Chen, Yang Liu, Jianjun Zhao, Bo Li, Jianxiong Yin, and Simon See. 2019 · 2019
Closest in time.
On the Design of Black-box Adversarial Examples by Leveraging Gradient-free Optimization and Operator Splitting Method. In ICCV 2019 (accepted)
Pu Zhao, Sijia Liu, Pin-Yu Chen, Nghia Hoang, Kaidi Xu, Bhavya Kailkhura, and Xue Lin. 2019 · 2019
Closest in time.
Feature Cross-Substitution in Adversarial Classification. In Proceedings of Advances in Neural Information Processing Systems . 2087–2095
Bo Li and Yevgeniy Vorobeychik. 2014 · 2095
Closest in time.