Fetching the paper…
Reading the bibliography…
Patch adversarial attacks on images, in which the attacker can distort pixels within a region of bounded size, are an important threat model since they provide a quantitative model for physical adversarial attacks.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Adversarial patch, 2017
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer · 2017
Earlier work this paper cites.
Robust physical-world attacks on deep learning visual classification
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song · 2018
Earlier work this paper cites.
Lavan: Localized and visible adversarial noise
Danny Karmon, Daniel Zoran, and Yoav Goldberg · 2018
Earlier work this paper cites.
On visible adversarial perturbations & digital watermarking
Jamie Hayes · 2018
Earlier work this paper cites.
Local gradients smoothing: Defense against localized adversarial attacks
Muzammal Naseer, Salman Khan, and Fatih Murat Porikli · 2018
Cited alongside, same era.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Mann, and Pushmeet Kohli · 2018
Cited alongside, same era.
Second-order adversarial attack and certifiable robustness
Bai Li, Changyou Chen, Wenlin Wang, and Lawrence Carin · 2018
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Cited alongside, same era.
Provably robust deep learning via adversarially trained smoothed classifiers
Hadi Salman, Greg Yang, Jerry Li, Pengchuan Zhang, Huan Zhang, Ilya Razenshteyn, and Sebastien Bubeck · 2019
Wasserstein smoothing: Certified robustness against wasserstein adversarial attacks
Alexander Levine and Soheil Feizi · 2019
Later among the works it cites.
Certified defenses for adversarial patches
PingYeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu, Christoph Studor, and Tom Goldstein · 2020
Closest in time.
Robustness certificates for sparse adversarial attacks by randomized ablation
Alexander Levine and Soheil Feizi · 2020
Closest in time.
Patchguard: Provable defense against adversarial patches using masks on small receptive fields
Chong Xiang, A. Bhagoji, V. Sehwag, and P. Mittal · 2020
Closest in time.
Clipped bagnet: Defending against sticker attacks with clipped bag-of-features
Z. Zhang, B. Yuan, Michael McCoyd, and D. Wagner · 2020
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, and S. Jana · 2019
Cited alongside, same era.
Tight certificates of adversarial robustness for randomly smoothed classifiers
Guang-He Lee, Yang Yuan, Shiyu Chang, and Tommi S. Jaakkola · 2019
Cited alongside, same era.
Regularized training and tight certification for randomized smoothed classifier with provable robustness, 2020
Huijie Feng, Chunpeng Wu, Guoyang Chen, Weifeng Zhang, and Yang Ning · 2020
Closest in time.
Certified robustness to label-flipping attacks via randomized smoothing
Elan Rosenfeld, Ezra Winston, Pradeep Ravikumar, and J. Zico Kolter · 2020
Closest in time.