Fetching the paper…
Reading the bibliography…
Conventional adversarial training methods using attacks that manipulate the pixel value directly and individually, leading to models that are less robust in face of spatial transformation-based attacks.
S. Zagoruyko and N. Komodakis · 1907
Earlier work this paper cites.
The structure of locally orderless images
J. J. Koenderink and A. J. van Doorn · 1999
Earlier work this paper cites.
On robustness properties of convex risk minimization methods for pattern recognition
A. Christmann and I. Steinwart · 2004
Earlier work this paper cites.
Adversarial classification
N. Dalvi, P. Domingos, Mausam, S. Sanghai, and D. Verma · 2004
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky · 2009
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng · 2011
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
A. Krizhevsky, I. Sutskever, and G. E. Hinton · 2012
Earlier work this paper cites.
OpenDR: An approximate differentiable renderer
M. M. Loper and M. J. Black · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Spatial transformer networks
M. Jaderberg, K. Simonyan, A. Zisserman, and k. kavukcuoglu · 2015
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Cited alongside, same era.
A rotation and a translation suffice: Fooling CNNs with simple transformations
L. Engstrom, D. Tsipras, L. Schmidt, and A. Madry · 2017
Cited alongside, same era.
Adversarial machine learning at scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Magnet: a two-pronged defense against adversarial examples
D. Meng and H. Chen · 2017
Cited alongside, same era.
Defense against adversarial attacks using high-level representation guided denoiser
F. Liao, M. Liang, Y. Dong, and T. Pang · 2018
Later among the works it cites.
Adversarial geometry and lighting using a differentiable renderer
H. D. Liu, M. Tao, C. Li, D. Nowrouzezahrai, and A. Jacobson · 2018
Later among the works it cites.
Towards robust neural networks via random self-ensemble
X. Liu, M. Cheng, H. Zhang, and C.-J. Hsieh · 2018
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Later among the works it cites.
Deflecting adversarial attacks with pixel deflection
A. Prakash, N. Moran, S. Garber, A. DiLillo, and J. Storer · 2018
Later among the works it cites.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
On detecting adversarial perturbations
J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Cited alongside, same era.
Learning and querying fast generative models for reinforcement learning
L. Buesing, T. Weber, S. Racanière, S. M. A. Eslami, D. J. Rezende, D. P. Reichert, F. Viola, F. Besse, K. Gregor, D. Hassabis, and D. Wierstra · 2018
Cited alongside, same era.
Reblur2deblur: Deblurring videos via self-supervised learning
H. Chen, J. Gu, O. Gallo, M. Liu, A. Veeraraghavan, and J. Kautz · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
C. Guo, M. Rana, M. Cissé, and L. van der Maaten · 2018
Cited alongside, same era.
Differentiable programming for image processing and deep learning in halide
T.-M. Li, M. Gharbi, A. Adams, F. Durand, and J. Ragan-Kelley · 2018
Cited alongside, same era.
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Later among the works it cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman · 2018
Later among the works it cites.
Ensemble adversarial training: Attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, D. Boneh, and P. McDaniel · 2018
Later among the works it cites.
Spatially transformed adversarial examples
C. Xiao, J.-Y. Zhu, B. Li, W. He, M. Liu, and D. Song · 2018
Later among the works it cites.
Mitigating adversarial effects through randomization
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille · 2018
Later among the works it cites.
Bilateral adversarial training: Towards fast training of more robust models against adversarial attacks
J. Wang and H. Zhang · 2019
Closest in time.
Feature denoising for improving adversarial robustness
C. Xie, Y. Wu, L. van der Maaten, A. Yuille, and K. He · 2019
Closest in time.