Fetching the paper…
Reading the bibliography…
Deep neural networks (DNN) have achieved unprecedented success in numerous machine learning tasks in various domains.
Theoretically principled trade-off between robustness and accuracy
Zhang, H., Yu, Y., Jiao, J., Xing, E. P., Ghaoui, L. E., and Jordan, M. I · 1901
Earlier work this paper cites.
You only propagate once: Painless adversarial training using maximal principle
Zhang, D., Zhang, T., Lu, Y., Zhu, Z., and Dong, B · 1905
Earlier work this paper cites.
On the limited memory bfgs method for large scale optimization
Liu, D. C. and Nocedal, J · 1989
Earlier work this paper cites.
Semidefinite programming
Vandenberghe, L. and Boyd, S · 1996
Earlier work this paper cites.
Long short-term memory
Hochreiter, S. and Schmidhuber, J · 1997
Earlier work this paper cites.
Incremental and decremental support vector machine learning
Cauwenberghs, G. and Poggio, T · 2001
Earlier work this paper cites.
Adversarial classification
Dalvi, N., Domingos, P., Sanghai, S., Verma, D., et al · 2004
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., and Fei-Fei, L · 2009
Earlier work this paper cites.
The security of machine learning
Barreno, M., Nelson, B., Joseph, A. D., and Tygar, J. D · 2010
Earlier work this paper cites.
Contractive auto-encoders: Explicit invariance during feature extraction
Rifai, S., Vincent, P., Muller, X., Glorot, X., and Bengio, Y · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Biggio, B., Nelson, B., and Laskov, P · 2012
Earlier work this paper cites.
Multi-column deep neural network for traffic sign classification
CireşAn, D., Meier, U., Masci, J., and Schmidhuber, J · 2012
Earlier work this paper cites.
A kernel two-sample test
Gretton, A., Borgwardt, K. M., Rasch, M. J., Schölkopf, B., and Smola, A · 2012
Earlier work this paper cites.
Deep neural networks for acoustic modeling in speech recognition
Hinton, G., Deng, L., Yu, D., Dahl, G., Mohamed, A.-r., Jaitly, N., Senior, A., Vanhoucke, V., Nguyen, P., Kingsbury, B., et al · 2012
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A., Sutskever, I., and Hinton, G. E · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Auto-encoding variational bayes
Kingma, D. P. and Welling, M · 2013
Earlier work this paper cites.
Distributed representations of words and phrases and their compositionality
Mikolov, T., Sutskever, I., Chen, K., Corrado, G. S., and Dean, J · 2013
Earlier work this paper cites.
Playing atari with deep reinforcement learning
Mnih, V., Kavukcuoglu, K., Silver, D., Graves, A., Antonoglou, I., Wierstra, D., and Riedmiller, M · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Drebin: Effective and explainable detection of android malware in your pocket
Arp, D., Spreitzenbarth, M., Gascon, H., Rieck, K., and Siemens, C · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Gu, S. and Rigazio, L · 2014
Earlier work this paper cites.
Deep speech: Scaling up end-to-end speech recognition
Hannun, A., Case, C., Casper, J., Catanzaro, B., Diamos, G., Elsen, E., Prenger, R., Satheesh, S., Sengupta, S., Coates, A., et al · 2014
Earlier work this paper cites.
Deepwalk: Online learning of social representations
Perozzi, B., Al-Rfou, R., and Skiena, S · 2014
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
Srivastava, N., Hinton, G., Krizhevsky, A., Sutskever, I., and Salakhutdinov, R · 2014
Earlier work this paper cites.
Natural evolution strategies
Wierstra, D., Schaul, T., Glasmachers, T., Sun, Y., Peters, J., and Schmidhuber, J · 2014
Earlier work this paper cites.
Distilling the knowledge in a neural network
Hinton, G., Vinyals, O., and Dean, J · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Ioffe, S. and Szegedy, C · 2015
Earlier work this paper cites.
Autoencoding beyond pixels using a learned similarity metric
Larsen, A. B. L., Sønderby, S. K., Larochelle, H., and Winther, O · 2015
Earlier work this paper cites.
Distributional smoothing with virtual adversarial training
Miyato, T., Maeda, S.-i., Koyama, M., Nakae, K., and Ishii, S · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., and Fei-Fei, L · 2015
Earlier work this paper cites.
Trust region policy optimization
Schulman, J., Levine, S., Abbeel, P., Jordan, M., and Moritz, P · 2015
Earlier work this paper cites.
Deepdga: Adversarially-tuned domain generation and detection
Anderson, H. S., Woodbridge, J., and Filar, B · 2016
Earlier work this paper cites.
Robustness of classifiers: from adversarial to random noise
Fawzi, A., Moosavi-Dezfooli, S.-M., and Frossard, P · 2016
Earlier work this paper cites.
Adversarial perturbations against deep neural networks for malware classification
Grosse, K., Papernot, N., Manoharan, P., Backes, M., and McDaniel, P · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Early methods for detecting adversarial images
Hendrycks, D. and Gimpel, K · 2016
Earlier work this paper cites.
Semi-supervised classification with graph convolutional networks
Kipf, T. N. and Welling, M · 2016
Earlier work this paper cites.
Adversarial training methods for semi-supervised text classification
Miyato, T., Dai, A. M., and Goodfellow, I · 2016
Earlier work this paper cites.
Asynchronous methods for deep reinforcement learning
Mnih, V., Badia, A. P., Mirza, M., Graves, A., Lillicrap, T., Harley, T., Silver, D., and Kavukcuoglu, K · 2016
Cited alongside, same era.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A · 2016
Cited alongside, same era.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Cited alongside, same era.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M. K · 2016
Cited alongside, same era.
Conditional image generation with pixelcnn decoders
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Athalye, A., Carlini, N., and Wagner, D · 2018
Later among the works it cites.
Adversarial attacks on node embeddings
Bojcheski, A. and Günnemann, S · 2018
Later among the works it cites.
Thermometer encoding: One hot way to resist adversarial examples
Buckman, J., Roy, A., Raffel, C., and Goodfellow, I · 2018
Later among the works it cites.
Audio adversarial examples: Targeted attacks on speech-to-text
Carlini, N. and Wagner, D · 2018
Later among the works it cites.
Ead: elastic-net attacks to deep neural networks via adversarial examples
Chen, P.-Y., Sharma, Y., Zhang, H., Yi, J., and Hsieh, C.-J · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Van den Oord, A., Kalchbrenner, N., Espeholt, L., Vinyals, O., Graves, A., et al · 2016
Cited alongside, same era.
Synthesizing robust adversarial examples
Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K · 2017
Cited alongside, same era.
Synthetic and natural noise both break neural machine translation
Belinkov, Y. and Bisk, Y · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Provably minimally-distorted adversarial examples
Carlini, N., Katz, G., Barrett, C., and Dill, D. L · 2017
Cited alongside, same era.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J · 2017
Cited alongside, same era.
Parseval networks: Improving robustness to adversarial examples
Cisse, M., Bojanowski, P., Grave, E., Dauphin, Y., and Usunier, N · 2017
Cited alongside, same era.
Cheng, M., Yi, J., Zhang, H., Chen, P.-Y., and Hsieh, C.-J · 2018
Later among the works it cites.
Fingerprint presentation attack detection: Generalization and efficiency
Chugh, T. and Jain, A. K · 2018
Later among the works it cites.
Fingerprint spoof buster: Use of minutiae-centered patches
Chugh, T., Cao, K., and Jain, A. K · 2018
Later among the works it cites.
Adversarial attack on graph structured data
Dai, H., Li, H., Tian, T., Huang, X., Wang, L., Zhu, J., and Song, L · 2018
Later among the works it cites.
Stochastic activation pruning for robust adversarial defense
Dhillon, G. S., Azizzadenesheli, K., Lipton, Z. C., Bernstein, J., Kossaifi, J., Khanna, A., and Anandkumar, A · 2018
Later among the works it cites.
Boosting adversarial attacks with momentum
Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J · 2018
Later among the works it cites.
Analysis of classifiers’ robustness to adversarial perturbations
Fawzi, A., Fawzi, O., and Frossard, P · 2018
Later among the works it cites.
Black-box generation of adversarial text sequences to evade deep learning classifiers
Gao, J., Lanchantin, J., Soffa, M. L., and Qi, Y · 2018
Later among the works it cites.
Detecting egregious responses in neural sequence-to-sequence models
He, T. and Glass, J · 2018
Later among the works it cites.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J · 2018
Later among the works it cites.
Adversarial example generation with syntactically controlled paraphrase networks
Iyyer, M., Wieting, J., Gimpel, K., and Zettlemoyer, L · 2018
Later among the works it cites.
Adversarial examples for generative models
Kos, J., Fischer, I., and Song, D · 2018
Later among the works it cites.
Discrete attacks and submodular optimization with applications to text classification
Lei, Q., Wu, L., Chen, P., Dimakis, A. G., Dhillon, I. S., and Witbrock, M · 2018
Later among the works it cites.
Adversarial over-sensitivity and over-stability strategies for dialogue models
Niu, T. and Bansal, M · 2018
Later among the works it cites.
Mathematical theory of optimal processes
Pontryagin, L. S · 2018
Later among the works it cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Samangouei, P., Kabkab, M., and Chellappa, R · 2018
Later among the works it cites.
Adversarially robust generalization requires more data
Schmidt, L., Santurkar, S., Tsipras, D., Talwar, K., and Madry, A · 2018
Later among the works it cites.
Bypassing feature squeezing by increasing adversary strength
Sharma, Y. and Chen, P.-Y · 2018
Later among the works it cites.
Constructing unrestricted adversarial examples with generative models
Song, Y., Shu, R., Kushman, N., and Ermon, S · 2018
Later among the works it cites.
Is robustness the cost of accuracy?–a comprehensive study on the robustness of 18 deep image classification models
Su, D., Zhang, H., Chen, H., Yi, J., Chen, P.-Y., and Gao, Y · 2018
Later among the works it cites.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2018
Later among the works it cites.
Scaling provable adversarial defenses
Wong, E., Schmidt, F., Metzen, J. H., and Kolter, J. Z · 2018
Later among the works it cites.
Adversarial attacks on neural networks for graph data
Zügner, D., Akbarnejad, A., and Günnemann, S · 2018
Later among the works it cites.
Advfaces: Adversarial face synthesis
Deb, D., Zhang, J., and Jain, A. K · 2019
Closest in time.
Graph adversarial training: Dynamically regularizing based on graph structure
Feng, F., He, X., Tang, J., and Chua, T.-S · 2019
Closest in time.
Adversarial examples are not bugs, they are features
Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., and Madry, A · 2019
Closest in time.
Say what i want: Towards the dark side of neural dialogue models
Liu, H., Derr, T., Liu, Z., and Tang, J · 2019
Closest in time.
Attacking graph convolutional networks via rewiring
Ma, Y., Wang, S., Wu, L., and Tang, J · 2019
Closest in time.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T · 2019
Closest in time.
Disentangling adversarial robustness and generalization
Stutz, D., Hein, M., and Schiele, B · 2019
Closest in time.
One pixel attack for fooling deep neural networks
Su, J., Vargas, D. V., and Sakurai, K · 2019
Closest in time.
Topology attack and defense for graph neural networks: An optimization perspective
Xu, K., Chen, H., Liu, S., Chen, P.-Y., Weng, T.-W., Hong, M., and Lin, X · 2019
Closest in time.
Adversarial attacks on graph neural networks via meta learning
Zügner, D. and Günnemann, S · 2019
Closest in time.