Fetching the paper…
Reading the bibliography…
Localized adversarial patches aim to induce misclassification in machine learning models by arbitrarily modifying pixels within a restricted region of an image.
Asirra: A captcha that exploits interest-aligned manual image categorization
Jeremy Elson, John (JD) Douceur, Jon Howell, and Jared Saul · 2007
Earlier work this paper cites.
ImageNet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Fei-Fei Li · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2009
Earlier work this paper cites.
ImageNet classification with deep convolutional neural networks
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton · 2012
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Cynthia Dwork and Aaron Roth · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Going deeper with convolutions
Christian Szegedy, Wei Liu, Yangqing Jia, Pierre Sermanet, Scott Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Understanding the effective receptive field in deep convolutional neural networks
Wenjie Luo, Yujia Li, Raquel Urtasun, and Richard S. Zemel · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick D. McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Adversarial patch
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
wordnet: WordNet Interface
Ingo Feinerer and Kurt Hornik · 2017
Earlier work this paper cites.
BadNets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Earlier work this paper cites.
Hung Le and Ali Borji · 2017
Earlier work this paper cites.
Magnet: A two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Earlier work this paper cites.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Earlier work this paper cites.
Inception-v4, inception-resnet and the impact of residual connections on learning
Christian Szegedy, Sergey Ioffe, Vincent Vanhoucke, and Alexander A. Alemi · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David A. Wagner · 2018
Cited alongside, same era.
PAC-learning in the presence of adversaries
Daniel Cullina, Arjun Nitin Bhagoji, and Prateek Mittal · 2018
Cited alongside, same era.
Robust physical-world attacks on deep learning visual classification
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song · 2018
Cited alongside, same era.
On visible adversarial perturbations & digital watermarking
Jamie Hayes · 2018
Cited alongside, same era.
LaVAN: Localized and visible adversarial noise
Danny Karmon, Daniel Zoran, and Yoav Goldberg · 2018
Cited alongside, same era.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2018
DPATCH: an adversarial patch attack on object detectors
Xin Liu, Huanrui Yang, Ziwei Liu, Linghao Song, Yiran Chen, and Hai Li · 2019
Later among the works it cites.
Local gradients smoothing: Defense against localized adversarial attacks
Muzammal Naseer, Salman Khan, and Fatih Porikli · 2019
Later among the works it cites.
Pytorch: An imperative style, high-performance deep learning library
Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Köpf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala · 2019
Later among the works it cites.
Provably robust deep learning via adversarially trained smoothed classifiers
Hadi Salman, Jerry Li, Ilya P. Razenshteyn, Pengchuan Zhang, Huan Zhang, Sébastien Bubeck, and Greg Yang · 2019
Later among the works it cites.
Fooling automated surveillance cameras: Adversarial patches to attack person detection
Simen Thys, Wiebe Van Ranst, and Toon Goedemé · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin T. Vechev · 2018
Cited alongside, same era.
Sok: Security and privacy in machine learning
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P Wellman · 2018
Cited alongside, same era.
Certified defenses against adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Cited alongside, same era.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry · 2018
Cited alongside, same era.
Not all pixels are born equal: An analysis of evasion attacks under locality constraints
Vikash Sehwag, Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Mung Chiang, and Prateek Mittal · 2018
Cited alongside, same era.
Rademacher complexity for adversarially robust generalization
Dong Yin, Ramchandran Kannan, and Peter Bartlett · 2019
Later among the works it cites.
Adversarial examples: Attacks and defenses for deep learning
Xiaoyong Yuan, Pan He, Qile Zhu, and Xiaolin Li · 2019
Later among the works it cites.
Pretrained bag-of-local-features neural networks
Wieland Brendel · 2020
Closest in time.
Certified defenses for adversarial patches
Ping-Yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu, Christoph Studor, and Tom Goldstein · 2020
Closest in time.
ImageNette: A smaller subset of 10 easily classified classes from imagenet
fast.ai · 2020
Closest in time.
Code for the paper “(de)randomized smoothing for certifiable defense against patch attacks"
Alexander Levine and Soheil Feizi · 2020
Closest in time.
(De)randomized smoothing for certifiable defense against patch attacks
Alexander Levine and Soheil Feizi · 2020
Closest in time.
Minority reports defense: Defending against adversarial patches
Michael McCoyd, Won Park, Steven Chen, Neil Shah, Ryan Roggenkemper, Minjune Hwang, Jason Xinyu Liu, and David A. Wagner · 2020
Closest in time.
Adversarial training against location-optimized adversarial patches
Sukrut Rao, David Stutz, and Bernt Schiele · 2020
Closest in time.
torchvision.models
Torchvision · 2020
Closest in time.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Closest in time.
Defending against physically realizable attacks on image classification
Tong Wu, Liang Tong, and Yevgeniy Vorobeychik · 2020
Closest in time.
Patchguard: Provable defense against adversarial patches using masks on small receptive fields
Chong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, and Prateek Mittal · 2020
Closest in time.
Clipped bagnet: Defending against sticker attacks with clipped bag-of-features
Zhanyuan Zhang, Benson Yuan, Michael McCoyd, and David Wagner · 2020
Closest in time.
Certified robustness against physically-realizable patch attack via randomized cropping, 2021
Wan-Yi Lin, Fatemeh Sheikholeslami, jinghao shi, Leslie Rice, and J Zico Kolter · 2021
Closest in time.
Efficient certified defenses against patch attacks on image classifiers
Jan Hendrik Metzen and Maksym Yatsura · 2021
Closest in time.