Fetching the paper…
Reading the bibliography…
A convolutional neural network strongly robust to adversarial perturbations at reasonable computational and performance cost has not yet been demonstrated.
Smallest channel in early human vision
E. Hildreth D. Marr, T. Poggio · 1980
Earlier work this paper cites.
Visual topography of v2 in the macaque
R Gattass, C G Gross, and J H Sandell · 1981
Earlier work this paper cites.
Visuotopic organization and extent of v3 and v4 of the macaque
R Gattass, AP Sousa, and CG Gross · 1988
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A Krizhevsky · 2009
Earlier work this paper cites.
Metamers of the ventral stream
J. Freeman and Eero Simoncelli · 2011
Earlier work this paper cites.
’intriguing properties of neural networks’
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Computational role of eccentricity dependent cortical magnification
Tomaso Poggio, Jim Mutch, and Leyla Isik · 2014
Earlier work this paper cites.
Large scale visual recognition challenge
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, Bernstein M., A.C. Berg, and Fei-Fei L · 2014
Earlier work this paper cites.
Using goal-driven deep learning models to understand sensory cortex
Daniel L K Yamins and James J DiCarlo · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Eigen-distortions of hierarchical representations, 2017
Alexander Berardino, Johannes Ballé, Valero Laparra, and Eero P. Simoncelli · 2017
Earlier work this paper cites.
Adversarial example defenses: Ensembles of weak defenses are not strong
Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song · 2017
Earlier work this paper cites.
Eccentricity dependent deep neural networks: Modeling invariance in human vision
Francis X. Chen, Gemma Roig, Leyla Isik, Xavier Boix, and Tomaso Poggio · 2017
Earlier work this paper cites.
Do deep neural networks suffer from crowding?
Anna Volokitin, Gemma Roig, and Tomaso Poggio · 2017
Cited alongside, same era.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2017
Cited alongside, same era.
Adversarial examples in the physical world
Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio · 2017
Cited alongside, same era.
Adversarial examples detection in deep networks with convolutional filter statistics
Xin Li and Fuxin Li · 2017
Cited alongside, same era.
Brain-score: Which artificial neural network for object recognition is most brain-like?
Martin Schrimpf, Jonas Kubilius, Ha Hong, Najib J. Majaj, Rishi Rajalingham, Elias B. Issa, Kohitij Kar, Pouya Bashivan, Jonathan Prescott-Roy, Kailyn Schmidt, Daniel L. K. Yamins, and James J. DiCarlo · 2018
Cited alongside, same era.
Provably minimally-distorted adversarial examples
Nicholas Carlini, Guy Katz, Clark Barrett, and David L. Dill · 2018
Later among the works it cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2018
Later among the works it cites.
Neural population control via deep image synthesis
Pouya Bashivan, Kohitij Kar, and James J. DiCarlo · 2019
Later among the works it cites.
On evaluating adversarial robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin · 2019
Later among the works it cites.
Towards the first adversarially robust neural network model on mnist
Lukas Schott, Jonas Rauber, Matthias Bethge, and Wieland Brendel · 2019
Later among the works it cites.
’robustness may be at odds with accuracy’
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Synthesizing robust adversarial examples
Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok · 2018
Cited alongside, same era.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Cited alongside, same era.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli · 2018
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2018
Cited alongside, same era.
Later among the works it cites.
’the limitations of adversarial training and the blind-spot attack’
Huan Zhang, Hongge Chen, Zhao Song, Duane Boning, Inderjit S. Dhillon, and Cho-Jui Hsieh · 2019
Later among the works it cites.
Adversarial examples are not bugs, they are features
Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Later among the works it cites.
Image synthesis with a single (robust) classifier
Shibani Santurkar, Andrew Ilyas, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Later among the works it cites.
Adversarial robustness as a prior for learned representations
Logan Engstrom, Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Brandon Tran, and Aleksander Madry · 2019
Later among the works it cites.
Towards large yet imperceptible adversarial image perturbations with perceptual color distance
Zhengyu Zhao, Zhuoran Liu, and Martha Larson · 2019
Later among the works it cites.
Feature denoising for improving adversarial robustness
Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan Yuille, and Kaiming He · 2019
Later among the works it cites.
Scale and translation-invariance for novel objects in human vision
Yena Han, Gemma Roig, Gad Geiger, and Tomaso Poggio · 2020
Closest in time.