Fetching the paper…
Reading the bibliography…
Deep Convolution Neural Networks (CNNs) can easily be fooled by subtle, imperceptible changes to the input images.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” Citeseer, Tech. Rep., 2009
2009
Earlier work this paper cites.
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng, “Reading digits in natural images with unsupervised feature learning,” 2011
2011
Earlier work this paper cites.
C.-Y. Lee, S. Xie, P. Gallagher, Z. Zhang, and Z. Tu, “Deeply-supervised nets,” 2014
2014
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” 2014
2014
Earlier work this paper cites.
2015
Earlier work this paper cites.
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein, A. C. Berg, and L. Fei-Fei, “ImageNet Large Scale Visual Recognition Challenge,” International Journal of Computer Vision (IJCV) , vol. 115, no. 3, pp. 211–252, 2015
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
L. A. Gatys, A. S. Ecker, and M. Bethge, “Image style transfer using convolutional neural networks,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 2414–2423
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: a simple and accurate method to fool deep neural networks,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 2574–2582
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 770–778
2016
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) . IEEE, 2017, pp. 39–57
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
V. Zantedeschi, M.-I. Nicolae, and A. Rawat, “Efficient defenses against adversarial attacks,” in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security , 2017, pp. 39–49
2017
Earlier work this paper cites.
S. Motiian, M. Piccirilli, D. A. Adjeroh, and G. Doretto, “Unified deep supervised domain adaptation and generalization,” in Proceedings of the IEEE International Conference on Computer Vision , 2017, pp. 5715–5725
2017
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in International Conference on Learning Representations , 2018. [Online]. Available: https://openreview.net/forum?id=rJzIBfZAb
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel, “Ensemble adversarial training: Attacks and defenses,” in International Conference on Learning Representations , 2018. [Online]. Available: https://openreview.net/forum?id=rkZvSe-RZ
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li, “Boosting adversarial attacks with momentum,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2018, pp. 9185–9193
2018
Cited alongside, same era.
J. Uesato, B. O’donoghue, P. Kohli, and A. Oord, “Adversarial risk and the dangers of evaluating against weak attacks,” in International Conference on Machine Learning . PMLR, 2018, pp. 5025–5034
2018
Cited alongside, same era.
2018
Cited alongside, same era.
2018
P. T. Jackson, A. Atapour-Abarghouei, S. Bonner, T. P. Breckon, and B. Obara, “Style augmentation: Data augmentation via style randomization,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops , 2019, pp. 83–92
2019
Later among the works it cites.
R. Nakano, “A discussion of ’adversarial examples are not bugs, they are features’: Adversarially robust neural style transfer,” Distill , 2019, https://distill.pub/2019/advex-bugs-discussion/response-4
2019
Later among the works it cites.
D. Hendrycks, K. Lee, and M. Mazeika, “Using pre-training can improve model robustness and uncertainty,” in International Conference on Machine Learning . PMLR, 2019, pp. 2712–2721
2019
Later among the works it cites.
H. Zhang and W. Xu, “Adversarial interpolation training: A simple approach for improving model robustness,” 2020. [Online]. Available: https://openreview.net/forum?id=Syejj0NYvr
2020
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
2018
Cited alongside, same era.
2018
Cited alongside, same era.
J. Wang and H. Zhang, “Bilateral adversarial training: Towards fast training of more robust models against adversarial attacks,” in Proceedings of the IEEE International Conference on Computer Vision , 2019, pp. 6629–6638
2019
Cited alongside, same era.
2019
Cited alongside, same era.
2019
Cited alongside, same era.
H. Zhang and J. Wang, “Defense against adversarial attacks using feature scattering-based adversarial training,” in Advances in Neural Information Processing Systems , 2019
2019
Cited alongside, same era.
D. Hendrycks and T. Dietterich, “Benchmarking neural network robustness to common corruptions and perturbations,” Proceedings of the International Conference on Learning Representations , 2019
2019
Cited alongside, same era.
A. Shafahi, M. Najibi, M. A. Ghiasi, Z. Xu, J. Dickerson, C. Studer, L. S. Davis, G. Taylor, and T. Goldstein, “Adversarial training for free!” in Advances in Neural Information Processing Systems , 2019, pp. 3353–3364
2019
Cited alongside, same era.
E. Wong, L. Rice, and J. Z. Kolter, “Fast is better than free: Revisiting adversarial training,” in International Conference on Learning Representations , 2020. [Online]. Available: https://openreview.net/forum?id=BJx040EFvH
2020
Closest in time.
C. Xie, M. Tan, B. Gong, J. Wang, A. L. Yuille, and Q. V. Le, “Adversarial examples improve image recognition,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 819–828
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
Y. Tashiro, Y. Song, and S. Ermon, “Diversity can be transferred: Output diversification for white- and black-box attacks,” in Advances in Neural Information Processing Systems , 2020
2020
Closest in time.
F. Croce and M. Hein, “Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks,” in ICML , 2020
2020
Closest in time.
F. Croce and M. Hein, “Minimally distorted adversarial examples with a fast adaptive boundary attack,” in ICML , 2020
2020
Closest in time.
M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein, “Square attack: a query-efficient black-box adversarial attack via random search,” 2020
2020
Closest in time.
T. Wu, L. Tong, and Y. Vorobeychik, “Defending against physically realizable attacks on image classification,” in International Conference on Learning Representations , 2020. [Online]. Available: https://openreview.net/forum?id=H1xscnEKDr
2020
Closest in time.
2020
Closest in time.
2021
Closest in time.
S.-A. Rebuffi, S. Gowal, D. A. Calian, F. Stimberg, O. Wiles, and T. A. Mann, “Data augmentation can improve robustness,” Advances in Neural Information Processing Systems , vol. 34, pp. 29 935–29 948, 2021
2021
Closest in time.
S. Gowal, S.-A. Rebuffi, O. Wiles, F. Stimberg, D. A. Calian, and T. A. Mann, “Improving robustness using generated data,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Closest in time.