Fetching the paper…
Reading the bibliography…
Deep learning classifiers are susceptible to well-crafted, imperceptible variations of their inputs, known as adversarial attacks.
Guided image generation with conditional invertible neural networks
Ardizzone, L., Lüth, C., Kruse, J., Rother, C., and Köthe, U. (2019) · 1907
Earlier work this paper cites.
A survey of black-box adversarial attacks on computer vision models
Bhambri, S., Muku, S., Tulasi, A., and Buduru, A. B. (2019) · 1912
Earlier work this paper cites.
Normalizing flows for probabilistic modeling and inference
Papamakarios, G., Nalisnick, E., Rezende, D. J., Mohamed, S., and Lakshminarayanan, B. (2019) · 1912
Earlier work this paper cites.
Principles of Mathematical Analysis
Rudin, W. et al. (1964) · 1964
Earlier work this paper cites.
Matplotlib: A 2D graphics environment
Hunter, J. D. (2007) · 2007
Earlier work this paper cites.
Natural evolution strategies
Wierstra, D., Schaul, T., Peters, J., and Schmidhuber, J. (2008) · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A. and Hinton, G. (2009) · 2009
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., and Ng, A. Y. (2011) · 2011
Earlier work this paper cites.
A family of nonparametric density estimation algorithms
Tabak, E. G. and Turner, C. V. (2013) · 2013
Earlier work this paper cites.
All of statistics: a concise course in statistical inference
Wasserman, L. (2013) · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I. J., and Fergus, R. (2014) · 2014
Earlier work this paper cites.
Natural evolution strategies
Wierstra, D., Schaul, T., Glasmachers, T., Sun, Y., Peters, J., and Schmidhuber, J. (2014) · 2014
Earlier work this paper cites.
NICE: non-linear independent components estimation
Dinh, L., Krueger, D., and Bengio, Y. (2015) · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C. (2015) · 2015
Earlier work this paper cites.
Adam: A method for stochastic optimization
Kingma, D. P. and Ba, J. (2015) · 2015
Earlier work this paper cites.
Deep learning face attributes in the wild
Liu, Z., Luo, P., Wang, X., and Tang, X. (2015) · 2015
Earlier work this paper cites.
Variational inference with normalizing flows
Rezende, D. J. and Mohamed, S. (2015) · 2015
Earlier work this paper cites.
ImageNet large scale visual recognition challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M. S., Berg, A. C., and Li, F. (2015) · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Simonyan, K. and Zisserman, A. (2015) · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J. (2016) · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Papernot, N., McDaniel, P. D., and Goodfellow, I. J. (2016) · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z. (2016) · 2016
Cited alongside, same era.
Wide residual networks
Zagoruyko, S. and Komodakis, N. (2016) · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D. (2017) · 2017
Cited alongside, same era.
ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J. (2017) · 2017
Cited alongside, same era.
DAWNBench: An end-to-end deep learning benchmark and competition
Coleman, C., Narayanan, D., Kang, D., Zhao, T., Zhang, J., Nardi, L., Bailis, P., Olukotun, K., Ré, C., and Zaharia, M. (2017) · 2017
Cited alongside, same era.
Density estimation using real NVP
Dinh, L., Sohl-Dickstein, J., and Bengio, S. (2017) · 2017
Generating adversarial examples with adversarial networks
Xiao, C., Li, B., Zhu, J., He, W., Liu, M., and Song, D. (2018) · 2018
Later among the works it cites.
Adversarial attacks on neural networks for graph data
Zügner, D., Akbarnejad, A., and Günnemann, S. (2018) · 2018
Later among the works it cites.
Neural spline flows
Durkan, C., Bekasov, A., Murray, I., and Papamakarios, G. (2019) · 2019
Later among the works it cites.
Using self-supervised learning can improve model robustness and uncertainty
Hendrycks, D., Mazeika, M., Kadavath, S., and Song, D. (2019) · 2019
Later among the works it cites.
Prior convictions: Black-box adversarial attacks with bandits and priors
Ilyas, A., Engstrom, L., and Madry, A. (2019) · 2019
Later among the works it cites.
Black-box adversarial attacks on video recognition models
Jiang, L., Ma, X., Chen, S., Bailey, J., and Jiang, Y. (2019) · 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Automatic differentiation in PyTorch
Paszke, A., Gross, S., Chintala, S., Chanan, G., Yang, E., DeVito, Z., Lin, Z., Desmaison, A., Antiga, L., and Lerer, A. (2017) · 2017
Cited alongside, same era.
Evolution strategies as a scalable alternative to reinforcement learning
Salimans, T., Ho, J., Chen, X., and Sutskever, I. (2017) · 2017
Cited alongside, same era.
Learning to attack: Adversarial transformation networks
Baluja, S. and Fischer, I. (2018) · 2018
Cited alongside, same era.
Robust physical-world attacks on deep learning visual classification
Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D. (2018) · 2018
Cited alongside, same era.
Unsupervised representation learning by predicting image rotations
Gidaris, S., Singh, P., and Komodakis, N. (2018) · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Ilyas, A., Engstrom, L., Athalye, A., and Lin, J. (2018) · 2018
Cited alongside, same era.
Later among the works it cites.
Functional adversarial attacks
Laidlaw, C. and Feizi, S. (2019) · 2019
Later among the works it cites.
NATTACK: learning the distributions of adversarial examples for an improved black-box attack on deep neural networks
Li, Y., Li, L., Wang, L., Zhang, T., and Gong, B. (2019) · 2019
Later among the works it cites.
Graph normalizing flows
Liu, J., Kumar, A., Ba, J., Kiros, J., and Swersky, K. (2019) · 2019
Later among the works it cites.
Parsimonious black-box adversarial attacks via efficient combinatorial optimization
Moon, S., An, G., and Song, H. O. (2019) · 2019
Later among the works it cites.
Adversarial training for free!
Shafahi, A., Najibi, M., Ghiasi, A., Xu, Z., Dickerson, J. P., Studer, C., Davis, L. S., Taylor, G., and Goldstein, T. (2019) · 2019
Later among the works it cites.
AutoZOOM: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Tu, C., Ting, P., Chen, P., Liu, S., Zhang, H., Yi, J., Hsieh, C., and Cheng, S. (2019) · 2019
Later among the works it cites.
A direct approach to robust deep learning using adversarial networks
Wang, H. and Yu, C. (2019) · 2019
Later among the works it cites.
Adversarial examples: Attacks and defenses for deep learning
Yuan, X., He, P., Zhu, Q., and Li, X. (2019) · 2019
Later among the works it cites.
Array programming with NumPy
Harris, C. R., Millman, K. J., van der Walt, S. J., Gommers, R., Virtanen, P., Cournapeau, D., Wieser, E., Taylor, J., Berg, S., Smith, N. J., Kern, R., Picus, M., Hoyer, S., van Kerkwijk, M. H., Brett, M., Haldane, A., del R’ıo, J. F., Wiebe, M., Peterson, P., G’erard-Marchant, P., Sheppard, K., Reddy, T., Weckesser, W., Abbasi, H., Gohlke, C., and Oliphant, T. E. (2020) · 2020
Closest in time.
Black-box adversarial attack with transferable model-based embedding
Huang, Z. and Zhang, T. (2020) · 2020
Closest in time.
Normalizing flows: An introduction and review of current methods
Kobyzev, I., Prince, S., and Brubaker, M. A. (2020) · 2020
Closest in time.
Graphaf: a flow-based autoregressive model for molecular graph generation
Shi*, C., Xu*, M., Zhu, Z., Zhang, W., Zhang, M., and Tang, J. (2020) · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
Wong, E., Rice, L., and Kolter, J. Z. (2020) · 2020
Closest in time.
Deep residual flow for out of distribution detection
Zisselman, E. and Tamar, A. (2020) · 2020
Closest in time.