V. Vapnik, “Statistical learning theory,” 1998
1998
Earlier work this paper cites.
Y. LeCun and C. Cortes, “MNIST handwritten digit database,” 2010. [Online]. Available:
2010
Earlier work this paper cites.
A. Torralba, A. A. Efros
2011
Earlier work this paper cites.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” in
2012
Earlier work this paper cites.
G. Hinton, L. Deng, D. Yu, G. E. Dahl, A.-r. Mohamed, N. Jaitly, A. Senior, V. Vanhoucke, P. Nguyen, T. N. Sainath, and others, “Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups,”
2012
Earlier work this paper cites.
T. M. Cover and J. A. Thomas,
2012
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,”
Original
2013
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,”
Original
2014
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,”
Original
2014
Earlier work this paper cites.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,”
Original
2014
Earlier work this paper cites.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,”
Original
2015
Earlier work this paper cites.
Z. Liu, P. Luo, X. Wang, and X. Tang, “Deep learning face attributes in the wild,” in
2015
Earlier work this paper cites.
I. Goodfellow, Y. Bengio, and A. Courville,
2016
Earlier work this paper cites.
K. D. Julian, J. Lopez, J. S. Brush, M. P. Owen, and M. J. Kochenderfer, “Policy compression for aircraft collision avoidance systems,” in
2016
Earlier work this paper cites.
I. Vasiljevic, A. Chakrabarti, and G. Shakhnarovich, “Examining the impact of blur on recognition by convolutional networks,”
Original
2016
Earlier work this paper cites.
A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial machine learning at scale,”
Original
2016
Earlier work this paper cites.
A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial examples in the physical world,”
Original
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in
2016
Earlier work this paper cites.
C. Fefferman, S. Mitter, and H. Narayanan, “Testing the manifold hypothesis,”
2016
Earlier work this paper cites.