Fetching the paper…
Reading the bibliography…
The existence of adversarial examples capable of fooling trained neural network classifiers calls for a much better understanding of possible attacks to guide the development of safeguards against them.
Statistical decision functions which minimize the maximum risk
A. Wald · 1945
Earlier work this paper cites.
Non-cooperative games
J. Nash · 1951
Earlier work this paper cites.
Minimax theorems
K. Fan · 1953
Earlier work this paper cites.
Approximation capabilities of multilayer feedforward networks
K. Hornik · 1991
Earlier work this paper cites.
Convergence of probability measures
P. Billingsley · 1999
Earlier work this paper cites.
Stackelberg games for adversarial prediction problems
M. Brückner and T. Scheffer · 2011
Earlier work this paper cites.
Scikit-learn: Machine learning in Python
F. Pedregosa, G. Varoquaux, A. Gramfort, V. Michel, B. Thirion, O. Grisel, M. Blondel, P. Prettenhofer, R. Weiss, V. Dubourg, J. Vanderplas, A. Passos, D. Cournapeau, M. Brucher, M. Perrot, and E. Duchesnay · 2011
Earlier work this paper cites.
Static prediction games for adversarial learning problems
M. Brückner, C. Kanzow, and T. Scheffer · 2012
Earlier work this paper cites.
Generative adversarial nets
I. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, and Y. Bengio · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Lenet-5, convolutional neural networks
Y. LeCun et al · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and A. Zisserman · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Y. Liu, X. Chen, C. Liu, and D. Song · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
N. Papernot, P. McDaniel, and I. Goodfellow · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna · 2016
Earlier work this paper cites.
Wide residual networks
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh · 2017
Earlier work this paper cites.
Adversarial and clean data are not twins
Z. Gong, W. Wang, and W.-S. Ku · 2017
Earlier work this paper cites.
On the (statistical) detection of adversarial examples
K. Grosse, P. Manoharan, N. Papernot, M. Backes, and P. McDaniel · 2017
Earlier work this paper cites.
Densely connected convolutional networks
G. Huang, Z. Liu, L. Van Der Maaten, and K. Q. Weinberger · 2017
Earlier work this paper cites.
Query-efficient black-box adversarial examples
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin · 2017
Earlier work this paper cites.
Categorical reparameterization with gumbel-softmax
E. Jang, S. Gu, and B. Poole · 2017
Cited alongside, same era.
The concrete distribution: A continuous relaxation of discrete random variables
C. J. Maddison, A. Mnih, and Y. W. Teh · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2017
Cited alongside, same era.
On detecting adversarial perturbations
J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Cited alongside, same era.
Threat of adversarial attacks on deep learning in computer vision: A survey
N. Akhtar and A. Mian · 2018
Cited alongside, same era.
On evaluating adversarial robustness
N. Carlini, A. Athalye, N. Papernot, W. Brendel, J. Rauber, D. Tsipras, I. Goodfellow, A. Madry, and A. Kurakin · 2019
Later among the works it cites.
A geometric perspective on the transferability of adversarial directions
Z. Charles, H. Rosenberg, and D. Papailiopoulos · 2019
Later among the works it cites.
Minimally distorted adversarial examples with a fast adaptive boundary attack
F. Croce and M. Hein · 2019
Later among the works it cites.
AdverTorch v0.1: An adversarial robustness toolbox based on pytorch
G. W. Ding, L. Wang, and X. Jin · 2019
Later among the works it cites.
Evading defenses to transferable adversarial examples by translation-invariant attacks
Y. Dong, T. Pang, H. Su, and J. Zhu · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Synthesizing robust adversarial examples
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok · 2018
Cited alongside, same era.
Learning to attack: Adversarial transformation networks
S. Baluja and I. Fischer · 2018
Cited alongside, same era.
Adversarial attacks on face detectors using neural net based constrained optimization
A. J. Bose and P. Aarabi · 2018
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow · 2018
Cited alongside, same era.
Adversarial attacks and defences: A survey
A. Chakraborty, M. Alam, V. Dey, A. Chattopadhyay, and D. Mukhopadhyay · 2018
Cited alongside, same era.
Stochastic activation pruning for robust adversarial defense
G. S. Dhillon, K. Azizzadenesheli, Z. C. Lipton, J. Bernstein, J. Kossaifi, A. Khanna, and A. Anandkumar · 2018
Cited alongside, same era.
A variational inequality perspective on generative adversarial networks
G. Gidel, H. Berard, G. Vignoud, P. Vincent, and S. Lacoste-Julien · 2019
Later among the works it cites.
Simple black-box adversarial attacks
C. Guo, J. R. Gardner, Y. You, A. G. Wilson, and K. Q. Weinberger · 2019
Later among the works it cites.
Prior convictions: Black-box adversarial attacks with bandits and priors
A. Ilyas, L. Engstrom, and A. Madry · 2019
Later among the works it cites.
Black-box adversarial attacks on video recognition models
L. Jiang, X. Ma, S. Chen, J. Bailey, and Y.-G. Jiang · 2019
Later among the works it cites.
Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks
Y. Li, L. Li, L. Wang, T. Zhang, and B. Gong · 2019
Later among the works it cites.
Pytorch: An imperative style, high-performance deep learning library
A. Paszke, S. Gross, F. Massa, A. Lerer, J. Bradbury, G. Chanan, T. Killeen, Z. Lin, N. Gimelshein, L. Antiga, et al · 2019
Later among the works it cites.
Curls & whey: Boosting black-box adversarial attacks
Y. Shi, S. Wang, and Y. Han · 2019
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
C.-C. Tu, P. Ting, P.-Y. Chen, S. Liu, H. Zhang, J. Yi, C.-J. Hsieh, and S.-M. Cheng · 2019
Later among the works it cites.
Painless stochastic gradient: Interpolation, line-search, and convergence rates
S. Vaswani, A. Mishkin, I. Laradji, M. Schmidt, G. Gidel, and S. Lacoste-Julien · 2019
Later among the works it cites.
Improving transferability of adversarial examples with input diversity
C. Xie, Z. Zhang, Y. Zhou, S. Bai, J. Wang, Z. Ren, and A. L. Yuille · 2019
Later among the works it cites.
Adversarial attacks and defenses in images, graphs and text: A review
H. Xu, Y. Ma, H. Liu, D. Deb, H. Liu, J. Tang, and A. Jain · 2019
Later among the works it cites.
Square attack: a query-efficient black-box adversarial attack via random search
M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein · 2020
Closest in time.
A closer look at the optimization landscapes of generative adversarial networks
H. Berard, G. Gidel, A. Almahairi, P. Vincent, and S. Lacoste-Julien · 2020
Closest in time.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
F. Croce and M. Hein · 2020
Closest in time.
MMA training: Direct input space margin maximization through adversarial training
G. W. Ding, Y. Sharma, K. Y. C. Lui, and R. Huang · 2020
Closest in time.
Query-efficient meta attack to deep neural networks
J. Du, H. Zhang, J. T. Zhou, Y. Yang, and J. Feng · 2020
Closest in time.
G. Gidel, D. Balduzzi, W. M. Czarnecki, M. Garnelo, and Y. Bachrach · 2020
Closest in time.
Black-box adversarial attack with transferable model-based embedding
Z. Huang and T. Zhang · 2020
Closest in time.
Regional homogeneity: Towards learning transferable universal adversarial perturbations against defenses
Y. Li, S. Bai, C. Xie, Z. Liao, X. Shen, and A. L. Yuille · 2020
Closest in time.
Skip connections matter: On the transferability of adversarial examples generated with resnets
D. Wu, Y. Wang, S.-T. Xia, J. Bailey, and X. Ma · 2020
Closest in time.