Fetching the paper…
Reading the bibliography…
There are two major paradigms of white-box adversarial attacks that attempt to impose input perturbations.
The gradient projection method for nonlinear programming. part ii. nonlinear constraints
Rosen, J · 1961
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A. and Hinton, G · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Imagenet large scale visual recognition challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., et al · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
DeepFool: a simple and accurate method to fool deep neural networks
Moosavi Dezfooli, S. M., Fawzi, A., and Frossard, P · 2016
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A · 2016
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
One pixel attack for fooling deep neural networks
Su, J., Vargas, D. V., and Kouichi, S · 2017
Later among the works it cites.
Threat of adversarial attacks on deep learning in computer vision: A survey
Akhtar, N. and Mian, A · 2018
Later among the works it cites.
Gradient masking causes CLEVER to overestimate adversarial perturbation size
Goodfellow, I · 2018
Later among the works it cites.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J · 2018
Later among the works it cites.
Evaluating the robustness of neural networks: An extreme value theory approach
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Nicolas Papernot, Nicholas Carlini, I. G. R. F. F. F. A. M. K. H. Y.-L. J. A. K. R. S. A. G. Y.-C. L · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S
Cited in the paper.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I., and Bengio, S
Cited in the paper.
Weng, T.-W., Zhang, H., Chen, P.-Y., Yi, J., Su, D., Gao, Y., Hsieh, C.-J., and Daniel, L · 2018
Later among the works it cites.
Distributionally adversarial attack
Zheng, T., Chen, C., and Ren, K · 2018
Later among the works it cites.