Fetching the paper…
Reading the bibliography…
Adversarial examples raise questions about whether neural network models are sensitive to the same visual features as humans.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
ImageNet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2009
Earlier work this paper cites.
Sun database: Large-scale scene recognition from abbey to zoo
Jianxiong Xiao, James Hays, Krista A Ehinger, Aude Oliva, and Antonio Torralba · 2010
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y. Ng · 2011
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P. Kingma and Jimmy Ba · 2014
Earlier work this paper cites.
A note on the evaluation of generative models
Lucas Theis, Aäron van den Oord, and Matthias Bethge · 2015
Earlier work this paper cites.
Early methods for detecting adversarial images
Dan Hendrycks and Kevin Gimpel · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Cited alongside, same era.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R. Curtin, Saurabh Shintre, and Andrew B. Gardner · 2017
Cited alongside, same era.
Adversarial and clean data are not twins
Zhitao Gong, Wenlu Wang, and Wei-Shinn Ku · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel · 2017
Cited alongside, same era.
Adversarial examples detection in deep networks with convolutional filter statistics
Xin Li and Fuxin Li · 2017
Cited alongside, same era.
Evaluation methodology for attacks against confidence thresholding models
Ian Goodfellow, Yao Qin, and David Berthelot · 2018
Later among the works it cites.
Matrix capsules with em routing
Geoffrey E. Hinton, Sara Sabour, and Nicholas Frosst · 2018
Later among the works it cites.
With friends like these, who needs adversaries?
Saumya Jetley, Nicholas A. Lord, and Philip H. S. Torr · 2018
Later among the works it cites.
Adversarial attacks and defences competition
Alexey Kurakin, Ian Goodfellow, Samy Bengio, Yinpeng Dong, Fangzhou Liao, Ming Liang, Tianyu Pang, Jun Zhu, Xiaolin Hu, Cihang Xie, et al · 2018
Later among the works it cites.
Robust perception through analysis by synthesis
Lukas Schott, Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Cited alongside, same era.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Cited alongside, same era.
Dynamic routing between capsules
Sara Sabour, Nicholas Frosst, and Geoffrey E. Hinton · 2017
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2017
Cited alongside, same era.
Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms
Han Xiao, Kashif Rasul, and Roland Vollgraf · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David A. Wagner · 2018
Cited alongside, same era.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner
Cited in the paper.
The unreasonable effectiveness of deep features as a perceptual metric
Richard Zhang, Phillip Isola, Alexei A Efros, Eli Shechtman, and Oliver Wang · 2018
Later among the works it cites.
Are odds really odd? bypassing statistical detection of adversarial examples
Hossein Hosseini, Sreeram Kannan, and Radha Poovendran · 2019
Closest in time.
On the vulnerability of capsule networks to adversarial attacks
Felix Michels, Tobias Uelwer, Eric Upschulte, and Stefan Harmeling · 2019
Closest in time.
Mnist-c: A robustness benchmark for computer vision
Norman Mu and Justin Gilmer · 2019
Closest in time.
Deepcaps: Going deeper with capsule networks
Jathushan Rajasegaran, Vinoj Jayasundara, Sandaru Jayasekara, Hirunima Jayasekara, Suranga Seneviratne, and Ranga Rodrigo · 2019
Closest in time.
The odds are odd: A statistical test for detecting adversarial examples
Kevin Roth, Yannic Kilcher, and Thomas Hofmann · 2019
Closest in time.