Fetching the paper…
Reading the bibliography…
Conventional adversarial defenses reduce classification accuracy whether or not a model is under attacks.
“Learning multiple layers of features from tiny images,”
Alex Krizhevsky, · 2009
Earlier work this paper cites.
“Evasion attacks against machine learning at test time,”
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli, · 2013
Earlier work this paper cites.
“Intriguing properties of neural networks,”
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus, · 2014
Earlier work this paper cites.
“Explaining and harnessing adversarial examples,”
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy, · 2015
Earlier work this paper cites.
“Deep residual learning for image recognition,”
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun, · 2016
Earlier work this paper cites.
“Wide residual networks,”
Sergey Zagoruyko and Nikos Komodakis, · 2016
Earlier work this paper cites.
“Towards evaluating the robustness of neural networks,”
Nicholas Carlini and David Wagner, · 2017
Earlier work this paper cites.
“Train cifar10 with pytorch,” https://github.com/kuangliu/pytorch-cifar, 2017
Kuangliu, · 2017
Earlier work this paper cites.
“Robust physical-world attacks on deep learning visual classification,”
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song, · 2018
Earlier work this paper cites.
“Wild patterns: Ten years after the rise of adversarial machine learning,”
Battista Biggio and Fabio Roli, · 2018
Earlier work this paper cites.
“Certified defenses against adversarial examples,”
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang, · 2018
Earlier work this paper cites.
“A dual approach to scalable verification of deep networks.,”
Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy A Mann, and Pushmeet Kohli, · 2018
Cited alongside, same era.
“Provable defenses against adversarial examples via the convex outer adversarial polytope,”
Eric Wong and J. Zico Kolter, · 2018
Cited alongside, same era.
“Scaling provable adversarial defenses,”
Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J Zico Kolter, · 2018
Cited alongside, same era.
“Thermometer encoding: One hot way to resist adversarial examples,”
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow, · 2018
Cited alongside, same era.
“Defense-GAN: Protecting classifiers against adversarial attacks using generative models,”
Pouya Samangouei, Maya Kabkab, and Rama Chellappa, · 2018
Cited alongside, same era.
“Countering adversarial images using input transformations,”
“Towards deep learning models resistant to adversarial attacks,”
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu, · 2018
Later among the works it cites.
“Barrage of random transforms for adversarially robust defense,”
Edward Raff, Jared Sylvester, Steven Forsyth, and Mark McLean, · 2019
Later among the works it cites.
“Adversarial robustness by one bit double quantization for visual classification,”
MaungMaung AprilPyone, Yuma Kinoshita, and Hitoshi Kiya, · 2019
Later among the works it cites.
“Encryption-then-compression systems using grayscale-based image encryption for jpeg images,”
Tatsuya Chuman, Warit Sirichotedumrong, and Hitoshi Kiya, · 2019
Later among the works it cites.
“Grayscale-based block scrambling image encryption using ycbcr color space for encryption-then-compression systems,”
Warit Sirichotedumrong and Hitoshi Kiya, · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten, · 2018
Cited alongside, same era.
“Mitigating adversarial effects through randomization,”
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille, · 2018
Cited alongside, same era.
“Pixeldefend: Leveraging generative models to understand and defend against adversarial examples,”
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman, · 2018
Cited alongside, same era.
“Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,”
Anish Athalye, Nicholas Carlini, and David A. Wagner, · 2018
Cited alongside, same era.
“Learnable image encryption,”
Masayuki Tanaka, · 2018
Cited alongside, same era.
“Bridging machine learning and cryptography in defence against adversarial attacks,”
Olga Taran, Shideh Rezaeifar, and Slava Voloshynovskiy, · 2018
Cited alongside, same era.
“Pixel-based image encryption without key management for privacy-preserving deep neural networks,”
Warit Sirichotedumrong, Yuma Kinoshita, and Hitoshi Kiya, · 2019
Later among the works it cites.
“Adversarial test on learnable image encryption,”
MaungMaung AprilPyone, Warit Sirichotedumrong, and Hitoshi Kiya, · 2019
Later among the works it cites.
“On evaluating adversarial robustness,”
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, and Aleksander Madry, · 2019
Later among the works it cites.
“AdverTorch v0.1: An adversarial robustness toolbox based on pytorch,”
Gavin Weiguang Ding, Luyu Wang, and Xiaomeng Jin, · 2019
Later among the works it cites.
“Harnessing the vulnerability of latent layers in adversarially trained models,”
Nupur Kumari, Mayank Singh, Abhishek Sinha, Harshitha Machiraju, Balaji Krishnamurthy, and Vineeth N Balasubramanian, · 2019
Later among the works it cites.