Fetching the paper…
Reading the bibliography…
We study adversarial examples in a black-box setting where the adversary only has API access to the target model and each query is expensive.
The MNIST database of handwritten digits
Yann LeCun · 1998
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, Patrick Haffner, et al · 1998
Earlier work this paper cites.
Natural evolution strategies
Daan Wierstra, Tom Schaul, Jan Peters, and Juergen Schmidhuber · 2008
Earlier work this paper cites.
ImageNet: A Large-Scale Hierarchical Image Database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow · 2016
Earlier work this paper cites.
The shattered gradients problem: If resnets are the answer, then what is the question?
David Balduzzi, Marcus Frean, Lennox Leary, JP Lewis, Kurt Wan-Duo Ma, and Brian McWilliams · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh · 2017
Earlier work this paper cites.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger · 2017
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2017
Cited alongside, same era.
CIFAR10 adversarial examples challenge
Aleksander Madry · 2017
Cited alongside, same era.
MNIST adversarial examples challenge
Aleksander Madry · 2017
Cited alongside, same era.
Simple black-box adversarial perturbations for deep networks
Nina Narodytska and Shiva Prasad Kasiviswanathan · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
Query-limited black-box attacks to classifiers
Fnu Suya, Yuan Tian, David Evans, and Paolo Papotti · 2017
Cited alongside, same era.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Chun-Chen Tu, Paishun Ting, Pin-Yu Chen, Sijia Liu, Huan Zhang, Hsieh Cho-Jui Yi, Jinfeng, and Shin-Ming Cheng · 2018
Later among the works it cites.
There are no bit parts for sign bits in black-box attacks
Abdullah Al-Dujaili and Una-May O’Reilly · 2019
Closest in time.
GenAttack: Practical black-box attacks with gradient-free optimization
Moustafa Alzantot, Yash Sharma, Supriyo Chakraborty, and Mani Srivastava · 2019
Closest in time.
Exploring the space of black-box attacks on deep neural networks
Arjun Nitin Bhagoji, Warren He, Bo Li, and Dawn Song · 2019
Closest in time.
Boundary attack++: Query-efficient decision-based adversarial attack
Jianbo Chen and Michael I Jordan · 2019
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2018
Cited alongside, same era.
Guessing smart: Biased sampling for efficient black-box adversarial attacks
Thomas Brunner, Frederik Diehl, Michael Truong Le, and Alois Knoll · 2018
Cited alongside, same era.
Prototypical examples in deep learning: Metrics, characteristics, and utility
Nicholas Carlini, Ulfar Erlingsson, and Nicolas Papernot · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Cited alongside, same era.
Query-efficient black-box attack by active learning
Pengcheng Li, Jinfeng Yi, and Lijun Zhang · 2018
Cited alongside, same era.
Stateful detection of black-box adversarial attacks
Steven Chen, Nicholas Carlini, and David Wagner · 2019
Closest in time.
Query-efficient hard-label black-box attack: An optimization-based approach
Minhao Cheng, Thong Le, Pin-Yu Chen, Jinfeng Yi, Huan Zhang, and Cho-Jui Hsieh · 2019
Closest in time.
Improving black-box adversarial attacks with a transfer-based prior
Shuyu Cheng, Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Closest in time.
Evading defenses to transferable adversarial examples by translation-invariant attacks
Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Closest in time.
Simple black-box adversarial attacks
Chuan Guo, Jacob R Gardner, Yurong You, Andrew Gordon Wilson, and Kilian Q Weinberger · 2019
Closest in time.
Prior convictions: Black-box adversarial attacks with bandits and priors
Andrew Ilyas, Logan Engstrom, and Aleksander Madry · 2019
Closest in time.
Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks
Yandong Li, Lijun Li, Liqiang Wang, Tong Zhang, and Boqing Gong · 2019
Closest in time.
Parsimonious black-box adversarial attacks via efficient combinatorial optimization
Seungyong Moon, Gaon An, and Hyun Oh Song · 2019
Closest in time.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Closest in time.
Improving transferability of adversarial examples with input diversity
Cihang Xie, Zhishuai Zhang, Jianyu Wang, Yuyin Zhou, Zhou Ren, and Alan Yuille · 2019
Closest in time.