Fetching the paper…
Reading the bibliography…
Deep neural networks are vulnerable to adversarial attacks.
Imagenet: A large-scale hierarchical image database. In Computer Vision and Pattern Recognition, 2009. CVPR 2009. IEEE Conference on . Ieee, 248–255
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009 · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
MNIST handwritten digit database
Yann LeCun, Corinna Cortes, and CJ Burges. 2010 · 2010
Earlier work this paper cites.
Deep neural networks for acoustic modeling in speech recognition
Geoffrey Hinton, Li Deng, Dong Yu, George Dahl, Abdel-rahman Mohamed, Navdeep Jaitly, Andrew Senior, Vincent Vanhoucke, Patrick Nguyen, Brian Kingsbury, et al · 2012
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Ilya Sutskever, Geoffrey E Hinton, and A Krizhevsky. 2012 · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013 · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015 · 2015
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016 · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition . 2574–2582
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016 · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016a · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings. In Security and Privacy (EuroS&P), 2016 IEEE European Symposium on . IEEE, 372–387
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016b · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE Symposium on Security and Privacy (SP) . IEEE, 582–597
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2016c · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision. In Proceedings of the IEEE conference on computer vision and pattern recognition . 2818–2826
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. 2016 · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis. 2016 · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks. In 2017 IEEE Symposium on Security and Privacy (SP) . IEEE, 39–57
Nicholas Carlini and David Wagner. 2017 · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security . ACM, 15–26
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. 2017 · 2017
Cited alongside, same era.
Generating adversarial malware examples for black-box attacks based on GAN
Weiwei Hu and Ying Tan. 2017 · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security . ACM, 506–519
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami. 2017 · 2017
Cited alongside, same era.
Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In International Conference on Machine Learning
Anish Athalye, Nicholas Carlini, and David Wagner. 2018 · 2018
Cited alongside, same era.
Hopskipjumpattack: A query-efficient decision-based attack
Jianbo Chen, Michael I Jordan, and Martin J Wainwright. 2019 · 2019
Later among the works it cites.
Query-Efficient Hard-label Black-box Attack: An Optimization-based Approach. In International Conference on Learning Representations
Minhao Cheng, Thong Le, Pin-Yu Chen, Huan Zhang, JinFeng Yi, and Cho-Jui Hsieh. 2019 · 2019
Later among the works it cites.
Prior convictions: Black-box adversarial attacks with bandits and priors
Andrew Ilyas, Logan Engstrom, and Aleksander Madry. 2019 · 2019
Later among the works it cites.
NATTACK: Learning the Distributions of Adversarial Examples for an Improved Black-Box Attack on Deep Neural Networks. In International Conference on Machine Learning . 3866–3876
Yandong Li, Lijun Li, Liqiang Wang, Tong Zhang, and Boqing Gong. 2019 · 2019
Later among the works it cites.
Parsimonious Black-Box Adversarial Attacks via Efficient Combinatorial Optimization. In International Conference on Machine Learning . 4636–4645
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models. In International Conference on Learning Representations
Wieland Brendel, Jonas Rauber, and Matthias Bethge. 2018 · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
Guneet S Dhillon, Kamyar Azizzadenesheli, Zachary C Lipton, Jeremy Bernstein, Jean Kossaifi, Aran Khanna, and Anima Anandkumar. 2018 · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens Van Der Maaten. 2018 · 2018
Cited alongside, same era.
Black-box Adversarial Attacks with Limited Queries and Information. In Proceedings of the 35th International Conference on Machine Learning
Andrew Ilyas, Logan Engstrom, Anish Athalye, Jessy Lin, Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018 · 2018
Cited alongside, same era.
Characterizing adversarial subspaces using local intrinsic dimensionality
Xingjun Ma, Bo Li, Yisen Wang, Sarah M Erfani, Sudanthi Wijewickrema, Grant Schoenebeck, Dawn Song, Michael E Houle, and James Bailey. 2018 · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018 · 2018
Cited alongside, same era.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa. 2018 · 2018
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman. 2018 · 2018
Cited alongside, same era.
Seungyong Moon, Gaon An, and Hyun Oh Song. 2019 · 2019
Later among the works it cites.
On the Convergence and Robustness of Adversarial Training. In International Conference on Machine Learning . 6586–6595
Yisen Wang, Xingjun Ma, James Bailey, Jinfeng Yi, Bowen Zhou, and Quanquan Gu. 2019 · 2019
Later among the works it cites.
Defense against adversarial attacks using feature scattering-based adversarial training. In Advances in Neural Information Processing Systems . 1829–1839
Haichao Zhang and Jianyu Wang. 2019 · 2019
Later among the works it cites.
Theoretically Principled Trade-off between Robustness and Accuracy. In International Conference on Machine Learning . 7472–7482
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan. 2019 · 2019
Later among the works it cites.
Sign Bits Are All You Need for Black-Box Attacks. In International Conference on Learning Representations
Abdullah Al-Dujaili and Una-May O’Reilly. 2020 · 2020
Closest in time.
A Frank-Wolfe framework for efficient and effective adversarial attacks
Jinghui Chen, Dongruo Zhou, Jinfeng Yi, and Quanquan Gu. 2020 · 2020
Closest in time.
Sign-OPT: A Query-Efficient Hard-label Adversarial Attack. In International Conference on Learning Representations
Minhao Cheng, Simranjit Singh, Patrick H. Chen, Pin-Yu Chen, Sijia Liu, and Cho-Jui Hsieh. 2020 · 2020
Closest in time.
Sensible adversarial learning
Jungeum Kim and Xiao Wang. 2020 · 2020
Closest in time.
Improving Adversarial Robustness Requires Revisiting Misclassified Examples. In International Conference on Learning Representations
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu. 2020 · 2020
Closest in time.
Adversarial Interpolation Training: A Simple Approach for Improving Model Robustness
Haichao Zhang and Wei Xu. 2020 · 2020
Closest in time.