Fetching the paper…
Reading the bibliography…
Adaptive attacks have (rightfully) become the de facto standard for evaluating defenses to adversarial examples.
Exact matrix completion via convex optimization
Candès, E. J. and Recht, B · 2009
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Auto-encoding variational Bayes
Kingma, D. P. and Welling, M · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Matrix estimation by universal singular value thresholding
Chatterjee, S. et al · 2015
Earlier work this paper cites.
Defensive distillation is not robust to adversarial examples
Carlini, N. and Wagner, D · 2016
Earlier work this paper cites.
Adversarial machine learning at scale
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Earlier work this paper cites.
Adversarial manipulation of deep representations
Sabour, S., Cao, Y., Faghri, F., and Fleet, D. J · 2016
Earlier work this paper cites.
Mitigating evasion attacks to deep neural networks via region-based classification
Cao, X. and Gong, N. Z · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J · 2017
Earlier work this paper cites.
Adversarial example defense: Ensembles of weak defenses are not strong
He, W., Wei, J., Chen, X., Carlini, N., and Song, D · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Earlier work this paper cites.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Rauber, J., Brendel, W., and Bethge, M · 2017
Earlier work this paper cites.
On the robustness of the cvpr 2018 white-box adversarial example defenses
Athalye, A. and Carlini, N · 2018
Earlier work this paper cites.
Thwarting adversarial examples: An l0-robust sparse fourier transform
Bafna, M., Murtagh, J., and Vyas, N · 2018
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2018
Cited alongside, same era.
Ead: elastic-net attacks to deep neural networks via adversarial examples
Chen, P.-Y., Sharma, Y., Zhang, H., Yi, J., and Hsieh, C.-J · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Dhillon, G. S., Azizzadenesheli, K., Lipton, Z. C., Bernstein, J. D., Kossaifi, J., Khanna, A., and Anandkumar, A · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
An alternative surrogate loss for PGD-based adversarial testing
Gowal, S., Uesato, J., Qin, C., Huang, P.-S., Mann, T., and Kohli, P · 2019
Later among the works it cites.
Are odds really odd? bypassing statistical detection of adversarial examples
Hosseini, H., Kannan, S., and Poovendran, R · 2019
Later among the works it cites.
A new defense against adversarial images: Turning a weakness into a strength
Hu, S., Yu, T., Guo, C., Chao, W.-L., and Weinberger, K. Q · 2019
Later among the works it cites.
Exploiting excessive invariance caused by norm-bounded adversarial robustness
Jacobsen, J.-H., Behrmannn, J., Carlini, N., Tramer, F., and Papernot, N · 2019
Later among the works it cites.
Are generative classifiers more robust to adversarial attacks?
Li, Y., Bradshaw, J., and Sharma, Y · 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Guo, C., Rana, M., Cisse, M., and van der Maaten, L · 2018
Cited alongside, same era.
Decision boundary analysis of adversarial examples
He, W., Li, B., and Song, D · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J · 2018
Cited alongside, same era.
Max-mahalanobis linear discriminant analysis networks
Pang, T., Du, C., and Zhu, J · 2018
Cited alongside, same era.
Deflecting adversarial attacks with pixel deflection
Prakash, A., Moran, N., Garber, S., DiLillo, A., and Storer, J · 2018
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Tramèr, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2018
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
Uesato, J., O’Donoghue, B., Oord, A. v. d., and Kohli, P · 2018
Cited alongside, same era.
Later among the works it cites.
Improving adversarial robustness via promoting ensemble diversity
Pang, T., Xu, K., Du, C., Chen, N., and Zhu, J · 2019
Later among the works it cites.
The odds are odd: A statistical test for detecting adversarial examples
Roth, K., Kilcher, Y., and Hofmann, T · 2019
Later among the works it cites.
Computer vision with a single (robust) classifier
Santurkar, S., Tsipras, D., Tran, B., Ilyas, A., Engstrom, L., and Madry, A · 2019
Later among the works it cites.
Adversarial training and robustness for multiple perturbations
Tramèr, F. and Boneh, D · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., and Madry, A · 2019
Later among the works it cites.
Error correcting output codes improve probability estimation and adversarial robustness of deep neural networks
Verma, G. and Swami, A · 2019
Later among the works it cites.
Disentangling improves vaes’ robustness to adversarial attacks, 2019
Willetts, M., Camuto, A., Roberts, S., and Holmes, C · 2019
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Croce, F. and Hein, M · 2020
Closest in time.
{EMPIR}: Ensembles of mixed precision deep networks for increased robustness against adversarial attacks
Sen, S., Ravindran, B., and Raghunathan, A · 2020
Closest in time.
Resisting adversarial attacks by k k -winners-take-all
Xiao, C., Zhong, P., and Zheng, C · 2020
Closest in time.
Adversarial example detection and classification with asymmetrical adversarial training
Yin, X., Kolouri, S., and Rohde, G. K · 2020
Closest in time.