Fetching the paper…
Reading the bibliography…
Natural images are virtually surrounded by low-density misclassified regions that can be efficiently discovered by gradient-guided search --- enabling the generation of adversarial images.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky, G. Hinton, et al · 2009
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Adam: A method for stochastic optimization
D. Kingma and J. Ba · 2014
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
N. Srivastava, G. E. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and Harnessing Adversarial Examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and A. Zisserman · 2015
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna · 2015
Earlier work this paper cites.
Dropout as a bayesian approximation: Representing model uncertainty in deep learning
Y. Gal and Z. Ghahramani · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2016
Earlier work this paper cites.
Vulnerability of deep reinforcement learning to policy induction attacks
V. Behzadan and A. Munir · 2017
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
W. Brendel, J. Rauber, and M. Bethge · 2017
Earlier work this paper cites.
Adversarial Examples Are Not Easily Detected: Bypassing Ten Detection Methods
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Towards Evaluating the Robustness of Neural Networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
ZOO: zeroth order optimization based black-box attacks to deep neural networks without training substitute models
P. Chen, H. Zhang, Y. Sharma, J. Yi, and C. Hsieh · 2017
Earlier work this paper cites.
Houdini: Fooling deep structured prediction models
M. Cisse, Y. Adi, N. Neverova, and J. Keshet · 2017
Earlier work this paper cites.
Detecting Adversarial Samples from Artifacts
R. Feinman, R. R. Curtin, S. Shintre, and A. B. Gardner · 2017
Earlier work this paper cites.
Model-agnostic meta-learning for fast adaptation of deep networks
C. Finn, P. Abbeel, and S. Levine · 2017
Cited alongside, same era.
On the (Statistical) Detection of Adversarial Examples
K. Grosse, P. Manoharan, N. Papernot, M. Backes, and P. McDaniel · 2017
Cited alongside, same era.
Adversarial attacks on neural network policies
S. Huang, N. Papernot, I. Goodfellow, Y. Duan, and P. Abbeel · 2017
Cited alongside, same era.
Adversarial Machine Learning at Scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Cited alongside, same era.
Adversarial examples detection in deep networks with convolutional filter statistics
X. Li and F. Li · 2017
Cited alongside, same era.
Magnet: A two-pronged defense against adversarial examples
D. Meng and H. Chen · 2017
Adversarial Logit Pairing
H. Kannan, A. Kurakin, and I. Goodfellow · 2018
Later among the works it cites.
Towards robust neural networks via random self-ensemble
X. Liu, M. Cheng, H. Zhang, and C. Hsieh · 2018
Later among the works it cites.
Characterizing adversarial subspaces using local intrinsic dimensionality
X. Ma, B. Li, Y. Wang, S. M. Erfani, S. N. R. Wijewickrema, G. Schoenebeck, D. Song, M. E. Houle, and J. Bailey · 2018
Later among the works it cites.
Towards Deep Learning Models Resistant to Adversarial Attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Later among the works it cites.
Enhancing Robustness of Machine Learning Systems via Data Transformations
A. Nitin Bhagoji, D. Cullina, C. Sitawarin, and P. Mittal · 2018
Later among the works it cites.
Towards robust detection of adversarial examples
T. Pang, C. Du, Y. Dong, and J. Zhu · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
On detecting adversarial perturbations
J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
N. Papernot, P. D. McDaniel, I. J. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
F. Tramèr, A. Kurakin, N. Papernot, D. Boneh, and P. D. McDaniel · 2017
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
E. Wong and J. Zico Kolter · 2017
Cited alongside, same era.
Adversarial examples for semantic segmentation and object detection
C. Xie, J. Wang, Z. Zhang, Y. Zhou, L. Xie, and A. L. Yuille · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. A. Wagner · 2018
Cited alongside, same era.
Later among the works it cites.
Deflecting adversarial attacks with pixel deflection
A. Prakash, N. Moran, S. Garber, A. DiLillo, and J. A. Storer · 2018
Later among the works it cites.
Certified Defenses against Adversarial Examples
A. Raghunathan, J. Steinhardt, and P. Liang · 2018
Later among the works it cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Later among the works it cites.
Are adversarial examples inevitable?
A. Shafahi, W. R. Huang, C. Studer, S. Feizi, and T. Goldstein · 2018
Later among the works it cites.
Certifying some distributional robustness with principled adversarial training
A. Sinha, H. Namkoong, and J. C. Duchi · 2018
Later among the works it cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman · 2018
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
C. Tu, P. Ting, P. Chen, S. Liu, H. Zhang, J. Yi, C. Hsieh, and S. Cheng · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
J. Uesato, B. O’Donoghue, P. Kohli, and A. van den Oord · 2018
Later among the works it cites.
Mitigating adversarial effects through randomization
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. L. Yuille · 2018
Later among the works it cites.
Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks
W. Xu, D. Evans, and Y. Qi · 2018
Later among the works it cites.
Simple black-box adversarial attacks
C. Guo, J. R. Gardner, Y. You, A. G. Wilson, and K. Q. Weinberger · 2019
Closest in time.
The odds are odd: A statistical test for detecting adversarial examples
K. Roth, Y. Kilcher, and T. Hofmann · 2019
Closest in time.