Fetching the paper…
Reading the bibliography…
We consider the blackbox transfer-based targeted adversarial attack threat model in the realm of deep neural network (DNN) image classifiers.
WordNet: An Electronic Lexical Database
George A Miller · 1998
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Fei-Fei Li · 2009
Earlier work this paper cites.
Web-scale Bayesian click-through rate prediction for sponsored search advertising in Microsoft’s bing search engine
Thore Graepel, Joaquin Quiñonero Candela, Thomas Borchert, and Ralf Herbrich · 2010
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images
Anh Mai Nguyen, Jason Yosinski, and Jeff Clune · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick D. McDaniel, and Ian J. Goodfellow · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, Laurens van der Maaten, and Kilian Q. Weinberger · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick D. McDaniel, Ian J. Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
LOTS about attacking deep features
Andras Rozsa, Manuel Günther, and Terrance E. Boult · 2017
Cited alongside, same era.
Revisiting Unreasonable Effectiveness of Data in Deep Learning Era
Chen Sun, Abhinav Shrivastava, Saurabh Singh, and Abhinav Gupta · 2017
Cited alongside, same era.
The space of transferable adversarial examples
Florian Tramèr, Nicolas Papernot, Ian J. Goodfellow, Dan Boneh, and Patrick D. McDaniel · 2017
Cited alongside, same era.
Restricted-Use Microdata
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Pushmeet Kohli, and Aäron van den Oord · 2018
Later among the works it cites.
Transferable adversarial perturbations
Wen Zhou, Xin Hou, Yongjun Chen, Mengyun Tang, Xiangqi Huang, Xiang Gan, and Yong Yang · 2018
Later among the works it cites.
Improving black-box adversarial attacks with a transfer-based prior
Shuyu Cheng, Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Later among the works it cites.
Evading defenses to transferable adversarial examples by translation-invariant attacks
Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Later among the works it cites.
Enhancing adversarial example transferability with an intermediate level attack
Qian Huang, Isay Katsman, Zeqi Gu, Horace He, Serge J. Belongie, and Ser-Nam Lim · 2019
Later among the works it cites.
Feature space perturbations yield more transferable adversarial examples
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
US Census Bureau · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Cited alongside, same era.
Automatic Threat Recognition of Prohibited Items at Aviation Checkpoint with X-ray Imaging: A Deep Learning Approach
Kevin J Liang, Geert Heilmann, Christopher Gregory, Souleymane O. Diallo, David Carlson, Gregory P. Spell, John B. Sigman, Kris Roe, and Lawrence Carin · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Detecting and Classifying Lesions in Mammograms with Deep Learning
Dezsö Ribli, Anna Horváth, Zsuzsa Unger, Péter Pollner, and István Csabai · 2018
Cited alongside, same era.
Mobilenetv2: Inverted residuals and linear bottlenecks
Mark Sandler, Andrew G. Howard, Menglong Zhu, Andrey Zhmoginov, and Liang-Chieh Chen · 2018
Cited alongside, same era.
Nathan Inkawhich, Wei Wen, Hai Li, and Yiran Chen · 2019
Later among the works it cites.
On the effectiveness of low frequency perturbations
Yash Sharma, Gavin Weiguang Ding, and Marcus A. Brubaker · 2019
Later among the works it cites.
Improving transferability of adversarial examples with input diversity
Cihang Xie, Zhishuai Zhang, Yuyin Zhou, Song Bai, Jianyu Wang, Zhou Ren, and Alan L. Yuille · 2019
Later among the works it cites.
Transferable perturbations of deep feature distributions
Nathan Inkawhich, Kevin J Liang, Lawrence Carin, and Yiran Chen · 2020
Closest in time.
Enhancing cross-task black-box transferability of adversarial examples with dispersion reduction
Yantao Lu, Yunhan Jia, Jianyu Wang, Bai Li, Weiheng Chai, Lawrence Carin, and Senem Velipasalar · 2020
Closest in time.
Background Adaptive Faster R-CNN for Semi-supervised Convolutional Object Detection of Threats in X-ray Images
John B. Sigman, Gregory P. Spell, Kevin J Liang, and Lawrence Carin · 2020
Closest in time.
Skip connections matter: On the transferability of adversarial examples generated with resnets
Dongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey, and Xingjun Ma · 2020
Closest in time.