Fetching the paper…
Reading the bibliography…
We propose a versatile framework based on random search, Sparse-RS, for score-based sparse targeted and untargeted attacks in the black-box setting.
Yet another but more efficient black-box adversarial attack: tiling and evolution strategies
Meunier, L.; Atif, J.; and Teytaud, O. 2019 · 1910
Earlier work this paper cites.
The convergence of the random search method in the extremal control of a many parameter system
Rastrigin, L. 1963 · 1963
Earlier work this paper cites.
Improved Image Wasserstein Attacks and Defenses
Hu, J. E.; Swaminathan, A.; Salman, H.; and Yang, G. 2020 · 2004
Earlier work this paper cites.
RobustBench: a standardized adversarial robustness benchmark
Croce, F.; Andriushchenko, M.; Sehwag, V.; Debenedetti, E.; Flammarion, N.; Chiang, M.; Mittal, P.; and Hein, M. 2020 · 2010
Earlier work this paper cites.
Random search algorithms
Zabinsky, Z. B. 2010 · 2010
Earlier work this paper cites.
Stochastic sparse adversarial attacks
Césaire, M.; Hajri, H.; Lamprier, S.; and Gallinari, P. 2020 · 2011
Earlier work this paper cites.
Evasion Attacks against Machine Learning at Test Time
Biggio, B.; Corona, I.; Maiorca, D.; Nelson, B.; Srndic, N.; Laskov, P.; Giacinto, G.; and Roli, F. 2013 · 2013
Earlier work this paper cites.
Drebin: Effective and explainable detection of android malware in your pocket
Arp, D.; Spreitzenbarth, M.; Hubner, M.; Gascon, H.; Rieck, K.; and Siemens, C. 2014 · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C.; Zaremba, W.; Sutskever, I.; Bruna, J.; Erhan, D.; Goodfellow, I.; and Fergus, R. 2014 · 2014
Earlier work this paper cites.
Measuring the effect of nuisance variables on classifiers
Fawzi, A.; and Frossard, P. 2016 · 2016
Earlier work this paper cites.
Adversarial perturbations against deep neural networks for malware classification
Grosse, K.; Papernot, N.; Manoharan, P.; Backes, M.; and McDaniel, P. 2016 · 2016
Earlier work this paper cites.
DeepFool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M.; Fawzi, A.; and Frossard, P. 2016 · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N.; McDaniel, P.; Jha, S.; Fredrikson, M.; Celik, Z. B.; and Swami, A. 2016 · 2016
Earlier work this paper cites.
Adversarial Patch
Brown, T. B.; Mané, D.; Roy, A.; Abadi, M.; and Gilmer, J. 2017 · 2017
Earlier work this paper cites.
Towards Evaluating the Robustness of Neural Networks
Carlini, N.; and Wagner, D. 2017 · 2017
Earlier work this paper cites.
Generating adversarial malware examples for black-box attacks based on GAN
Hu, W.; and Tan, Y. 2017 · 2017
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A.; Goodfellow, I. J.; and Bengio, S. 2017 · 2017
Earlier work this paper cites.
Simple black-box adversarial attacks on deep neural networks
Narodytska, N.; and Kasiviswanathan, S. 2017 · 2017
Earlier work this paper cites.
Foolbox: A Python toolbox to benchmark the robustness of machine learning models
Rauber, J.; Brendel, W.; and Bethge, M. 2017 · 2017
Earlier work this paper cites.
Attack and defense of dynamic analysis-based, adversarial neural malware classification models
Stokes, J. W.; Wang, D.; Marinescu, M.; Marino, M.; and Bussone, B. 2017 · 2017
Earlier work this paper cites.
Adversarial deep learning for robust detection of binary encoded malware
Al-Dujaili, A.; Huang, A.; Hemberg, E.; and O’Reilly, U.-M. 2018 · 2018
Earlier work this paper cites.
Understanding deep neural networks with rectified linear unit
Arora, R.; Basuy, A.; Mianjyz, P.; and Mukherjee, A. 2018 · 2018
Earlier work this paper cites.
Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
Athalye, A.; Carlini, N.; and Wagner, D. A. 2018 · 2018
Earlier work this paper cites.
Practical black-box attacks on deep neural networks using efficient query mechanisms
Bhagoji, A. N.; He, W.; Li, B.; and Song, D. 2018 · 2018
Cited alongside, same era.
Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models
Brendel, W.; Rauber, J.; and Bethge, M. 2018 · 2018
Cited alongside, same era.
EAD: Elastic-Net Attacks to Deep Neural Networks via Adversarial Examples
Chen, P.; Sharma, Y.; Zhang, H.; Yi, J.; and Hsieh, C. 2018 · 2018
Cited alongside, same era.
Boosting Adversarial Attacks With Momentum
Dong, Y.; Liao, F.; Pang, T.; Su, H.; Zhu, J.; Hu, X.; and Li, J. 2018 · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Ilyas, A.; Engstrom, L.; Athalye, A.; and Lin, J. 2018 · 2018
Cited alongside, same era.
Lavan: Localized and visible adversarial noise
Karmon, D.; Zoran, D.; and Goldberg, Y. 2018 · 2018
On Effectiveness of Adversarial Examples and Defenses for Malware Classification
Podschwadt, R.; and Takabi, H. 2019 · 2019
Later among the works it cites.
Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses
Rony, J.; Hafemann, L. G.; Oliveira, L. S.; Ayed, I. B.; Sabourin, R.; and Granger, E. 2019 · 2019
Later among the works it cites.
Towards the first adversarially robust neural network model on MNIST
Schott, L.; Rauber, J.; Bethge, M.; and Brendel, W. 2019 · 2019
Later among the works it cites.
Fooling automated surveillance cameras: adversarial patches to attack person detection
Thys, S.; Van Ranst, W.; and Goedemé, T. 2019 · 2019
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Tu, C.-C.; Ting, P.; Chen, P.-Y.; Liu, S.; Zhang, H.; Yi, J.; Hsieh, C.-J.; and Cheng, S.-M. 2019 · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Towards Deep Learning Models Resistant to Adversarial Attacks
Madry, A.; Makelov, A.; Schmidt, L.; Tsipras, D.; and Valdu, A. 2018 · 2018
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
Uesato, J.; O’Donoghue, B.; Van den Oord, A.; and Kohli, P. 2018 · 2018
Cited alongside, same era.
The unreasonable effectiveness of deep features as a perceptual metric
Zhang, R.; Isola, P.; Efros, A. A.; Shechtman, E.; and Wang, O. 2018 · 2018
Cited alongside, same era.
Genattack: practical black-box attacks with gradient-free optimization
Alzantot, M.; Sharma, Y.; Chakraborty, S.; and Srivastava, M. 2019 · 2019
Cited alongside, same era.
Guessing smart: biased sampling for efficient black-box adversarial attacks
Brunner, T.; Diehl, F.; Le, M. T.; and Knoll, A. 2019 · 2019
Cited alongside, same era.
ZO-AdaMM: Zeroth-order adaptive momentum method for black-box optimization
Chen, X.; Liu, S.; Xu, K.; Li, X.; Lin, X.; Hong, M.; and Cox, D. 2019 · 2019
Cited alongside, same era.
Wasserstein Adversarial Examples via Projected Sinkhorn Iterations
Wong, E.; Schmidt, F. R.; and Kolter, J. Z. 2019 · 2019
Later among the works it cites.
Adversarial framing for image and video classification
Zajac, M.; Zołna, K.; Rostamzadeh, N.; and Pinheiro, P. O. 2019 · 2019
Later among the works it cites.
On the design of black-box adversarial examples by leveraging gradient-free optimization and operator splitting method
Zhao, P.; Liu, S.; Chen, P.-Y.; Hoang, N.; Xu, K.; Kailkhura, B.; and Lin, X. 2019 · 2019
Later among the works it cites.
There are No Bit Parts for Sign Bits in Black-Box Attacks
Al-Dujaili, A.; and O’Reilly, U.-M. 2020 · 2020
Closest in time.
Square Attack: a query-efficient black-box adversarial attack via random search
Andriushchenko, M.; Croce, F.; Flammarion, N.; and Hein, M. 2020 · 2020
Closest in time.
Minimally distorted Adversarial Examples with a Fast Adaptive Boundary Attack
Croce, F.; and Hein, M. 2020 · 2020
Closest in time.
Sparse adversarial attack via perturbation factorization
Fan, Y.; Wu, B.; Li, T.; Zhang, Y.; Li, M.; Li, Z.; and Yang, Y. 2020 · 2020
Closest in time.
Black-Box Adversarial Attack with Transferable Model-based Embedding
Huang, Z.; and Zhang, T. 2020 · 2020
Closest in time.
A principled approach for generating adversarial images under non-smooth dissimilarity metrics
Pooladian, A.-A.; Finlay, C.; Hoheisel, T.; and Oberman, A. M. 2020 · 2020
Closest in time.
Adversarial Training against Location-Optimized Adversarial Patches
Rao, S.; Stutz, D.; and Schiele, B. 2020 · 2020
Closest in time.
Adversarial Library
Rony, J.; and Ben Ayed, I. 2020 · 2020
Closest in time.
PatchAttack: A Black-box Texture-based Attack with Reinforcement Learning
Yang, C.; Kortylewski, A.; Xie, C.; Cao, Y.; and Yuille, A. 2020 · 2020
Closest in time.
Mind the box: l 1 l_{1} -APGD for sparse adversarial attacks on image classifiers
Croce, F.; and Hein, M. 2021 · 2021
Closest in time.
Perceptual Adversarial Robustness: Defense Against Unseen Threat Models
Laidlaw, C.; Singla, S.; and Feizi, S. 2021 · 2021
Closest in time.
PDPGD: Primal-Dual Proximal Gradient Descent Adversarial Attack
Matyasko, A.; and Chau, L.-P. 2021 · 2021
Closest in time.
Fast Minimum-norm Adversarial Attacks through Adaptive Norm Constraints
Pintor, M.; Roli, F.; Brendel, W.; and Biggio, B. 2021 · 2021
Closest in time.
Fixing data augmentation to improve adversarial robustness
Rebuffi, S.-A.; Gowal, S.; Calian, D. A.; Stimberg, F.; Wiles, O.; and Mann, T. 2021 · 2021
Closest in time.