Fetching the paper…
Reading the bibliography…
We propose the Square Attack, a score-based black-box $l_2$- and $l_\infty$-adversarial attack that does not rely on local gradient information and thus is not affected by gradient masking.
1904
Earlier work this paper cites.
1905
Earlier work this paper cites.
1908
Earlier work this paper cites.
1909
Earlier work this paper cites.
1910
Earlier work this paper cites.
Rastrigin, L.: The convergence of the random search method in the extremal control of a many parameter system. Automaton & Remote Control 24
1963
Earlier work this paper cites.
Matyas, J.: Random optimization. Automation and Remote control 26
1965
Earlier work this paper cites.
Schumer, M., Steiglitz, K.: Adaptive step size random search. IEEE Transactions on Automatic Control 13
1968
Earlier work this paper cites.
Schrack, G., Choit, M.: Optimized relative step size random searches. Mathematical Programming 10
1976
Earlier work this paper cites.
Haagerup, U.: The best constants in the Khintchine inequality. Studia Math. 70
1981
Earlier work this paper cites.
Nemirovsky, A.S., Yudin, D.B.: Problem Complexity and Method Efficiency in Optimization. Wiley-Interscience Series in Discrete Mathematics, John Wiley & Sons (1983)
1983
Earlier work this paper cites.
Boyd, S., Vandenberghe, L.: Convex Optimization. Cambridge University Press, Cambridge (2004)
2004
Earlier work this paper cites.
Zabinsky, Z.B.: Random search algorithms. Wiley encyclopedia of operations research and management science (2010)
2010
Earlier work this paper cites.
Duchi, J., Jordan, M., Wainwright, M., Wibisono, A.: Optimal rates for zero-order convex optimization: The power of two function evaluations. IEEE Transactions on Information Theory 61
2015
Earlier work this paper cites.
Gu, S., Rigazio, L.: Towards deep neural network architectures robust to adversarial examples. In: ICLR Workshop (2015)
2015
Earlier work this paper cites.
Bastani, O., Ioannou, Y., Lampropoulos, L., Vytiniotis, D., Nori, A., Criminisi, A.: Measuring neural net robustness with constraints. In: NeurIPS (2016)
2016
Earlier work this paper cites.
Fawzi, A., Frossard, P.: Measuring the effect of nuisance variables on classifiers. In: British Machine Vision Conference (BMVC) (2016)
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
Papernot, N., McDaniel, P., Wu, X., Jha, S., Swami, A.: Distillation as a defense to adversarial perturbations against deep networks. In: IEEE Symposium on Security & Privacy (2016)
2016
Earlier work this paper cites.
Zheng, S., Song, Y., Leung, T., Goodfellow, I.J.: Improving the robustness of deep neural networks via stability training. In: CVPR (2016)
2016
Earlier work this paper cites.
Brown, T.B., Mané, D., Roy, A., Abadi, M., Gilmer, J.: Adversarial patch. In: NeurIPS 2017 Workshop on Machine Learning and Computer Security (2017)
2017
Earlier work this paper cites.
Carlini, N., Wagner, D.: Adversarial examples are not easily detected: Bypassing ten detection methods. In: ACM Workshop on Artificial Intelligence and Security (2017)
2017
Cited alongside, same era.
Chen, P.Y., Zhang, H., Sharma, Y., Yi, J., Hsieh, C.J.: Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: 10th ACM Workshop on Artificial Intelligence and Security - AISec ’17. ACM Press (2017)
2017
Cited alongside, same era.
Narodytska, N., Kasiviswanathan, S.: Simple black-box adversarial attacks on deep neural networks. In: CVPR Workshops (2017)
2017
Cited alongside, same era.
Nesterov, Y., Spokoiny, V.: Random gradient-free minimization of convex functions. Foundations of Computational Mathematics 17
2017
Cited alongside, same era.
Yu, F., Koltun, V., Funkhouser, T.: Dilated residual networks. In: CVPR (2017)
Cohen, J.M., Rosenfeld, E., Kolter, Z.: Certified adversarial robustness via randomized smoothing. In: ICML (2019)
2019
Closest in time.
Croce, F., Hein, M.: Sparse and imperceivable adversarial attacks. In: ICCV (2019)
2019
Closest in time.
Davis, D., Drusvyatskiy, D.: Stochastic model-based minimization of weakly convex functions. SIAM Journal on Optimization 29
2019
Closest in time.
Guo, C., Frank, J.S., Weinberger, K.Q.: Low frequency adversarial perturbation. In: UAI (2019)
2019
Closest in time.
Guo, C., Gardner, J.R., You, Y., Wilson, A.G., Weinberger, K.Q.: Simple black-box adversarial attacks. In: ICML (2019)
2019
Closest in time.
Ilyas, A., Engstrom, L., Madry, A.: Prior convictions: Black-box adversarial attacks with bandits and priors. In: ICLR (2019)
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2017
Cited alongside, same era.
Akhtar, N., Mian, A.: Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access 6
2018
Cited alongside, same era.
Athalye, A., Carlini, N., Wagner, D.A.: Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In: ICML (2018)
2018
Cited alongside, same era.
Bhagoji, A.N., He, W., Li, B., Song, D.: Practical black-box attacks on deep neural networks using efficient query mechanisms. In: ECCV (2018)
2018
Cited alongside, same era.
Biggio, B., Roli, F.: Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition 84
2018
Cited alongside, same era.
Brendel, W., Rauber, J., Bethge, M.: Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. In: ICLR (2018)
2018
Cited alongside, same era.
Chen, P., Sharma, Y., Zhang, H., Yi, J., Hsieh, C.: Ead: Elastic-net attacks to deep neural networks via adversarial examples. In: AAAI (2018)
2018
Cited alongside, same era.
Ilyas, A., Engstrom, L., Athalye, A., Lin, J.: Black-box adversarial attacks with limited queries and information. In: ICML (2018)
2018
Cited alongside, same era.
2019
Closest in time.
Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., Madry, A.: Adversarial examples are not bugs, they are features. NeurIPS (2019)
2019
Closest in time.
Li, Y., Li, L., Wang, L., Zhang, T., Gong, B.: Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks. In: ICML (2019)
2019
Closest in time.
Seungyong, M., Gaon, A., Hyun, O.S.: Parsimonious black-box adversarial attacks via efficient combinatorial optimization. In: ICML (2019)
2019
Closest in time.
Su, J., Vargas, D., Sakurai, K.: One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation (2019)
2019
Closest in time.
Tramèr, F., Boneh, D.: Adversarial training and robustness for multiple perturbations. In: NeurIPS (2019)
2019
Closest in time.
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., Madry, A.: Robustness may be at odds with accuracy. In: ICLR (2019)
2019
Closest in time.
Tu, C.C., Ting, P., Chen, P.Y., Liu, S., Zhang, H., Yi, J., Hsieh, C.J., Cheng, S.M.: Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks. In: AAAI Conference on Artificial Intelligence (2019)
2019
Closest in time.
Yan, Z., Guo, Y., Zhang, C.: Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks. In: NeurIPS (2019)
2019
Closest in time.
Yin, D., Lopes, R.G., Shlens, J., Cubuk, E.D., Gilmer, J.: A Fourier perspective on model robustness in computer vision. In: NeurIPS (2019)
2019
Closest in time.
Zhang, H., Yu, Y., Jiao, J., Xing, E.P., Ghaoui, L.E., Jordan, M.I.: Theoretically principled trade-off between robustness and accuracy. In: ICML (2019)
2019
Closest in time.
Zheng, T., Chen, C., Ren, K.: Distributionally adversarial attack. In: AAAI (2019)
2019
Closest in time.
Al-Dujaili, A., O’Reilly, U.M.: There are no bit parts for sign bits in black-box attacks. In: ICLR (2020)
2020
Closest in time.
Croce, F., Hein, M.: Minimally distorted adversarial examples with a fast adaptive boundary attack. In: ICML (2020)
2020
Closest in time.
Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: ICML (2020)
2020
Closest in time.
Du, J., Zhang, H., Zhou, J.T., Yang, Y., Feng, J.: Query-efficient meta attack to deep neural networks. In: ICLR (2020)
2020
Closest in time.