Fetching the paper…
Reading the bibliography…
It is well-known that classifiers are vulnerable to adversarial perturbations.
On the problem of the most efficient tests of statistical hypotheses
Jerzy Neyman and Egon Sharpe Pearson · 1933
Earlier work this paper cites.
On simultaneous confidence intervals for multinomial proportions
Leo A Goodman · 1965
Earlier work this paper cites.
Simultaneous confidence intervals and sample size determination for multinomial proportions
Cristina P Sison and Joseph Glaz · 1995
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Mitigating evasion attacks to deep neural networks via region-based classification
Xiaoyu Cao and Neil Zhenqiang Gong · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Provably minimally-distorted adversarial examples
Nicholas Carlini, Guy Katz, Clark Barrett, and David L Dill · 2017
Earlier work this paper cites.
Maximum resilience of artificial neural networks
Chih-Hong Cheng, Georg Nührenberg, and Harald Ruess · 2017
Earlier work this paper cites.
Parseval networks: Improving robustness to adversarial examples
Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier · 2017
Earlier work this paper cites.
Output range analysis for deep neural networks
Souradeep Dutta, Susmit Jha, Sriram Sanakaranarayanan, and Ashish Tiwari · 2017
Earlier work this paper cites.
Formal verification of piece-wise linear feed-forward neural networks
Ruediger Ehlers · 2017
Earlier work this paper cites.
Safety verification of deep neural networks
Xiaowei Huang, Marta Kwiatkowska, Sen Wang, and Min Wu · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks
Guy Katz, Clark Barrett, David L Dill, Kyle Julian, and Mykel J Kochenderfer · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
An approach to reachability analysis for feed-forward relu neural networks
Alessio Lomuscio and Lalit Maganti · 2017
Earlier work this paper cites.
Magnet: a two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Earlier work this paper cites.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Earlier work this paper cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2017
Earlier work this paper cites.
On the robustness of the cvpr 2018 white-box adversarial example defenses
Anish Athalye and Nicholas Carlini · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Cited alongside, same era.
A unified view of piecewise linear neural network verification
Rudy R Bunel, Ilker Turkaslan, Philip Torr, Pushmeet Kohli, and Pawan K Mudigonda · 2018
Cited alongside, same era.
Provable robustness of relu networks via maximization of linear regions
Francesco Croce, Maksym Andriushchenko, and Matthias Hein · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel · 2018
Later among the works it cites.
Lipschitz-margin training: Scalable certification of perturbation invariance for deep neural networks
Yusuke Tsuzuku, Issei Sato, and Masashi Sugiyama · 2018
Later among the works it cites.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Pushmeet Kohli, and Aaron Oord · 2018
Later among the works it cites.
Towards fast computation of certified robustness for relu networks
Tsui-Wei Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Duane Boning, Inderjit S Dhillon, and Luca Daniel · 2018
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Guneet S Dhillon, Kamyar Azizzadenesheli, Zachary C Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, and Anima Anandkumar · 2018
Cited alongside, same era.
Deep neural networks and mixed integer linear optimization
Matteo Fischetti and Jason Jo · 2018
Cited alongside, same era.
Ai2: Safety and robustness certification of neural networks with abstract interpretation
Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev · 2018
Cited alongside, same era.
Regularisation of neural networks by enforcing lipschitz continuity
Henry Gouk, Eibe Frank, Bernhard Pfahringer, and Michael Cree · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Timothy Mann, and Pushmeet Kohli · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens Van Der Maaten · 2018
Cited alongside, same era.
AttriGuard: A practical defense against attribute inference attacks via adversarial machine learning
Jinyuan Jia and Neil Zhenqiang Gong · 2018
Cited alongside, same era.
Scaling provable adversarial defenses
Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J Zico Kolter · 2018
Later among the works it cites.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille · 2018
Later among the works it cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Later among the works it cites.
Efficient neural network robustness certification with general activation functions
Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, and Luca Daniel · 2018
Later among the works it cites.
Sorting out lipschitz function approximation
Cem Anil, James Lucas, and Roger Grosse · 2019
Closest in time.
https://www.clarifai.com/demo
Clarifai · 2019
Closest in time.
Certified adversarial robustness via randomized smoothing
Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter · 2019
Closest in time.
https://cloud.google.com/vision/
Google Cloud Vision · 2019
Closest in time.
Rank verification for exponential families
Kenneth Hung, William Fithian, et al · 2019
Closest in time.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2019
Closest in time.
Tight certificates of adversarial robustness for randomly smoothed classifiers
Guang-He Lee, Yang Yuan, Shiyu Chang, and Tommi Jaakkola · 2019
Closest in time.
Adv-bnn: Improved adversarial defense through robust bayesian neural network
Xuanqing Liu, Yao Li, Chongruo Wu, and Cho-Jui Hsieh · 2019
Closest in time.
Theoretical evidence for adversarial robustness through randomization
Rafael Pinot, Laurent Meunier, Alexandre Araujo, Hisashi Kashima, Florian Yger, Cedric Gouy-Pailler, and Jamal Atif · 2019
Closest in time.
Provably robust deep learning via adversarially trained smoothed classifiers
Hadi Salman, Jerry Li, Ilya Razenshteyn, Pengchuan Zhang, Huan Zhang, Sebastien Bubeck, and Greg Yang · 2019
Closest in time.
Towards the first adversarially robust neural network model on mnist
Lukas Schott, Jonas Rauber, Matthias Bethge, and Wieland Brendel · 2019
Closest in time.
Peernets: Exploiting peer wisdom against adversarial attacks
Jan Svoboda, Jonathan Masci, Federico Monti, Michael M Bronstein, and Leonidas Guibas · 2019
Closest in time.