Fetching the paper…
Reading the bibliography…
The evaluation of robustness against adversarial manipulation of neural networks-based classifiers is mainly tested with empirical attacks as methods for the exact computation, even when available, do not scale to large networks.
Cifar-10 (canadian institute for advanced research)
Krizhevsky, A., Nair, V., and Hinton, G · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Gu, S. and Rigazio, L · 2015
Earlier work this paper cites.
Measuring neural net robustness with constraints
Bastani, O., Ioannou, Y., Lampropoulos, L., Vytiniotis, D., Nori, A., and Criminisi, A · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Learning with a strong adversary
Huang, R., Xu, B., Schuurmans, D., and Szepesvari, C · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
Simple black-box adversarial perturbations for deep networks
Narodytska, N. and Kasiviswanathan, S. P · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep networks
Papernot, N., McDonald, P., Wu, X., Jha, S., and Swami, A · 2016
Earlier work this paper cites.
Improving the robustness of deep neural networks via stability training
Zheng, S., Song, Y., Leung, T., and Goodfellow, I. J · 2016
Earlier work this paper cites.
Adversarial patch
Brown, T. B., Mané, D., Roy, A., Abadi, M., and Gilmer, J · 2017
Earlier work this paper cites.
A rotation and a translation suffice: Fooling CNNs with simple transformations
Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., and Madry, A · 2017
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
Hein, M. and Andriushchenko, M · 2017
Cited alongside, same era.
Reluplex: An efficient smt solver for verifying deep neural networks
Katz, G., Barrett, C., Dill, D., Julian, K., and Kochenderfer, M · 2017
Cited alongside, same era.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I. J., and Bengio, S · 2017
Cited alongside, same era.
cleverhans v2.0.0: an adversarial machine learning library
Papernot, N., Carlini, N., Goodfellow, I., Feinman, R., Faghri, F., Matyasko, A., Hambardzumyan, K., Juang, Y.-L., Kurakin, A., Sheatsley, R., Garg, A., and Lin, Y.-C · 2017
Cited alongside, same era.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Rauber, J., Brendel, W., and Bethge, M · 2017
Cited alongside, same era.
Scaling up the randomized gradient-free adversarial attack reveals overestimation of robustness using established attacks
Croce, F., Rauber, J., and Hein, M · 2019
Closest in time.
Sparsefool: a few pixels make a big difference
Modas, A., Moosavi-Dezfooli, S., and Frossard, P · 2019
Closest in time.
One pixel attack for fooling deep neural networks
Su, J., Vargas, D. V., and Kouichi, S · 2019
Closest in time.
Evaluating robustness of neural networks with mixed integer programming
Tjeng, V., Xiao, K., and Tedrake, R · 2019
Closest in time.
Adversarial training and robustness for multiple perturbations
Tramèr, F. and Boneh, D · 2019
Closest in time.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D. A · 2018
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2018
Cited alongside, same era.
Ead: Elastic-net attacks to deep neural networks via adversarial examples
Chen, P., Sharma, Y., Zhang, H., Yi, J., and Hsieh, C · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Valdu, A · 2018
Cited alongside, same era.
Logit pairing methods can fool gradient-based attacks
Mosbach, M., Andriushchenko, M., Trost, T., Hein, M., and Klakow, D · 2018
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D
Cited in the paper.
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D
Cited in the paper.
Wasserstein adversarial examples via projected sinkhorn iterations
Wong, E., Schmidt, F. R., and Kolter, J. Z · 2019
Closest in time.
Distributionally adversarial attack
Zheng, T., Chen, C., and Ren, K · 2019
Closest in time.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Croce, F. and Hein, M · 2020
Closest in time.
Rethinking softmax cross-entropy loss for adversarial robustness
Pang, T., Xu, K., Dong, Y., Du, C., Chen, N., and Zhu, J · 2020
Closest in time.