Fetching the paper…
Reading the bibliography…
Since the discovery of adversarial examples - the ability to fool modern CNN classifiers with tiny perturbations of the input, there has been much discussion whether they are a "bug" that is specific to current neural architectures and training methods or an inevitable "feature" of high dimensional geometry.
A simple explanation for the existence of adversarial examples with small hamming distance
Adi Shamir, Itay Safran, Eyal Ronen, and Orr Dunkelman · 1901
Earlier work this paper cites.
On evaluating adversarial robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian J. Goodfellow, Aleksander Madry, and Alexey Kurakin · 1902
Earlier work this paper cites.
Pattern classification
Richard O Duda, Peter E Hart, and David G Stork · 1973
Earlier work this paper cites.
The EM algorithm for mixtures of factor analyzers
Zoubin Ghahramani, Geoffrey E Hinton, et al · 1996
Earlier work this paper cites.
Information theory, inference and learning algorithms
David JC MacKay and David JC Mac Kay · 2003
Earlier work this paper cites.
The entire regularization path for the support vector machine
Trevor Hastie, Saharon Rosset, Robert Tibshirani, and Ji Zhu · 2004
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Scikit-learn: Machine learning in python
Fabian Pedregosa, Gaël Varoquaux, Alexandre Gramfort, Vincent Michel, Bertrand Thirion, Olivier Grisel, Mathieu Blondel, Peter Prettenhofer, Ron Weiss, Vincent Dubourg, et al · 2011
Earlier work this paper cites.
Auto-encoding variational Bayes
Diederik P Kingma and Max Welling · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep learning face attributes in the wild
Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang · 2015
Earlier work this paper cites.
cleverhans v1. 0.0: an adversarial machine learning library
Nicolas Papernot, Ian Goodfellow, Ryan Sheatsley, Reuben Feinman, and Patrick McDaniel · 2016
Cited alongside, same era.
A boundary tilting persepective on the phenomenon of adversarial examples
Thomas Tanay and Lewis D. Griffin · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner · 2017
Cited alongside, same era.
Improved training of wasserstein GANs
Ishaan Gulrajani, Faruk Ahmed, Martin Arjovsky, Vincent Dumoulin, and Aaron C Courville · 2017
Cited alongside, same era.
Theory of deep learning iii: explaining the non-overfitting puzzle, 2017
Tomaso Poggio, Kenji Kawaguchi, Qianli Liao, Brando Miranda, Lorenzo Rosasco, Xavier Boix, Jack Hidary, and Hrushikesh Mhaskar · 2017
Cited alongside, same era.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry · 2018
Later among the works it cites.
The implicit bias of gradient descent on separable data
Daniel Soudry, Elad Hoffer, Mor Shpigel Nacson, Suriya Gunasekar, and Nathan Srebro · 2018
Later among the works it cites.
Adversarial examples are a natural consequence of test error in noise, 2019
Nicolas Ford, Justin Gilmer, and Ekin D. Cubuk · 2019
Later among the works it cites.
Adversarial examples are not bugs, they are features
Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Later among the works it cites.
The curse of concentration in robust learning: Evasion and poisoning attacks from concentration of measure
Saeed Mahloujifar, Dimitrios I Diochnos, and Mohammad Mahmoody · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Adversarial risk and robustness: General definitions and implications for the uniform distribution
Dimitrios Diochnos, Saeed Mahloujifar, and Mohammad Mahmoody · 2018
Cited alongside, same era.
Limitations of adversarial robustness: strong no free lunch theorem
Elvis Dohmatob · 2018
Cited alongside, same era.
Adversarial spheres
Justin Gilmer, Luke Metz, Fartash Faghri, Samuel S Schoenholz, Maithra Raghu, Martin Wattenberg, and Ian Goodfellow · 2018
Cited alongside, same era.
Making machine learning robust against adversarial inputs
Ian Goodfellow, Patrick McDaniel, and Nicolas Papernot · 2018
Cited alongside, same era.
Detecting adversarial examples using data manifolds
Susmit Jha, Uyeong Jang, Somesh Jha, and Brian Jalaian · 2018
Cited alongside, same era.
On the geometry of adversarial examples
Marc Khoury and Dylan Hadfield-Menell · 2018
Cited alongside, same era.
On gans and gmms
Eitan Richardson and Yair Weiss · 2018
Cited alongside, same era.
A discussion of ’adversarial examples are not bugs, they are features’: Adversarial examples are just bugs, too
Preetum Nakkiran · 2019
Later among the works it cites.
Towards the first adversarially robust neural network model on mnist
L. Schott, J. Rauber, W. Brendel, and M. Bethge · 2019
Later among the works it cites.
Are adversarial examples inevitable?
Ali Shafahi, W Ronny Huang, Christoph Studer, Soheil Feizi, and Tom Goldstein · 2019
Later among the works it cites.
Disentangling adversarial robustness and generalization
David Stutz, Matthias Hein, and Bernt Schiele · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan · 2019
Later among the works it cites.
Gradient descent maximizes the margin of homogeneous neural networks
Kaifeng Lyu and Jian Li · 2020
Closest in time.
Principal component adversarial example
Yonggang Zhang, Xinmei Tian, Ya Li, Xinchao Wang, and Dacheng Tao · 2020
Closest in time.