Fetching the paper…
Reading the bibliography…
In recent years several adversarial attacks and defenses have been proposed.
Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel · 2012
Earlier work this paper cites.
Adam: A method for stochastic optimization
D. P. Kingma and J. Ba · 2014
Earlier work this paper cites.
Cifar-10 (canadian institute for advanced research)
A. Krizhevsky, V. Nair, and G. Hinton · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
S. Gu and L. Rigazio · 2015
Earlier work this paper cites.
Measuring neural net robustness with constraints
O. Bastani, Y. Ioannou, L. Lampropoulos, D. Vytiniotis, A. Nori, and A. Criminisi · 2016
Earlier work this paper cites.
Learning with a strong adversary
R. Huang, B. Xu, D. Schuurmans, and C. Szepesvari · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep networks
N. Papernot, P. McDonald, X. Wu, S. Jha, and A. Swami · 2016
Earlier work this paper cites.
Improving the robustness of deep neural networks via stability training
S. Zheng, Y. Song, T. Leung, and I. J. Goodfellow · 2016
Earlier work this paper cites.
Adversarial patch
T. B. Brown, D. Mané, A. Roy, M. Abadi, and J. Gilmer · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
A rotation and a translation suffice: Fooling CNNs with simple transformations
L. Engstrom, B. Tran, D. Tsipras, L. Schmidt, and A. Madry · 2017
Cited alongside, same era.
Formal guarantees on the robustness of a classifier against adversarial manipulation
M. Hein and M. Andriushchenko · 2017
Cited alongside, same era.
Reluplex: An efficient smt solver for verifying deep neural networks
G. Katz, C. Barrett, D. Dill, K. Julian, and M. Kochenderfer · 2017
Cited alongside, same era.
Adversarial examples in the physical world
A. Kurakin, I. J. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms
H. Xiao, K. Rasul, and R. Vollgraf · 2017
Cited alongside, same era.
Understanding deep neural networks with rectified linear unit
Certified defenses against adversarial examples
A. Raghunathan, J. Steinhardt, and P. Liang · 2018
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
E. Wong and J. Zico Kolter · 2018
Later among the works it cites.
Scaling provable adversarial defenses
E. Wong, F. Schmidt, J. H. Metzen, and J. Z. Kolter · 2018
Later among the works it cites.
Minimally distorted adversarial examples with a fast adaptive boundary attack
F. Croce and M. Hein · 2019
Closest in time.
Imagenet-trained cnns are biased towards texture; increasing shape bias improves accuracy and robustness
R. Geirhos, P. Rubisch, C.Michaelis, M. Bethge, F. A. Wichmann, and W. Brendel · 2019
Closest in time.
Benchmarking neural network robustness to common corruptions and perturbations
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
R. Arora, A. Basuy, P. Mianjyz, and A. Mukherjee · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. A. Wagner · 2018
Cited alongside, same era.
A randomized gradient-free attack on relu networks
F. Croce and M. Hein · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
S. Gowal, K. Dvijotham, R. Stanforth, R. Bunel, C. Qin, J. Uesato, R. Arandjelovic, T. A. Mann, and P. Kohli · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Valdu · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
M. Mirman, T. Gehr, and M. Vechev · 2018
Cited alongside, same era.
Logit pairing methods can fool gradient-based attacks
M. Mosbach, M. Andriushchenko, T. Trost, M. Hein, and D. Klakow · 2018
Cited alongside, same era.
D. Hendrycks and T. Dietterich · 2019
Closest in time.
Transfer of adversarial robustness between perturbation types
D. Kang, Y. Sun, T. Brown, D. Hendrycks, and J. Steinhardt · 2019
Closest in time.
Towards the first adversarially robust neural network model on MNIST
L. Schott, J. Rauber, M. Bethge, and W. Brendel · 2019
Closest in time.
Attacking the madry defense model with l 1 l_{1} -based adversarial examples
Y. Sharma and P. Chen · 2019
Closest in time.
Evaluating robustness of neural networks with mixed integer programming
V. Tjeng, K. Xiao, and R. Tedrake · 2019
Closest in time.
Adversarial training and robustness for multiple perturbations
F. Tramèr and D. Boneh · 2019
Closest in time.
Training for faster adversarial robustness verification via inducing relu stability
K. Y. Xiao, V. Tjeng, N. M. Shafiullah, and A. Madry · 2019
Closest in time.