Fetching the paper…
Reading the bibliography…
Deep neural networks are at the forefront of machine learning research.
Wasserstein Adversarial Examples via Projected Sinkhorn Iterations
Eric Wong, Frank R. Schmidt, and J. Zico Kolter. 2019 · 1902
Earlier work this paper cites.
Pengfei Yang, Jiangchao Liu, Jianlin Li, Liqian Chen, and Xiaowei Huang. 2019 · 1902
Earlier work this paper cites.
Fooling automated surveillance cameras: adversarial patches to attack person detection
Simen Thys, Wiebe Van Ranst, and Toon Goedemé. 2019 · 1904
Earlier work this paper cites.
A theory of the learnable. In ACM Symp. on Theory of Computing . ACM
Leslie G. Valiant. 1984 · 1984
Earlier work this paper cites.
Regularization theory and neural networks architectures
Federico Girosi, Michael Jones, and Tomaso Poggio. 1995 · 1995
Earlier work this paper cites.
Machine learning. 1997
Tom M. Mitchell et al · 1997
Earlier work this paper cites.
Convex optimization
Stephen Boyd and Lieven Vandenberghe. 2004 · 2004
Earlier work this paper cites.
Adversarial classification. In SIGKDD . ACM
Nilesh Dalvi, Pedro Domingos, Sumit Sanghai, Deepak Verma, et al · 2004
Earlier work this paper cites.
Adversarial learning. In SIGKDD . ACM
Daniel Lowd and Christopher Meek. 2005 · 2005
Earlier work this paper cites.
Can machine learning be secure?. In ASIACCS . ACM
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D. Joseph, and J. Doug Tygar. 2006 · 2006
Earlier work this paper cites.
Nightmare at test time: robust learning by feature deletion
Amir Globerson and Sam Roweis. 2006 · 2006
Earlier work this paper cites.
Robust optimization
Aharon Ben-Tal, Laurent El Ghaoui, and Arkadi Nemirovski. 2009 · 2009
Earlier work this paper cites.
Feature weighting for improved classifier robustness. In CEAS
Aleksander Kołcz and Choon Hui Teo. 2009 · 2009
Earlier work this paper cites.
Exploring strategies for training deep neural networks
Hugo Larochelle, Yoshua Bengio, Jérôme Louradour, and Pascal Lamblin. 2009 · 2009
Earlier work this paper cites.
Antidote: understanding and defending against poisoning of anomaly detectors. In SIGCOMM . ACM
Benjamin IP. Rubinstein, Blaine Nelson, Ling Huang, Anthony D. Joseph, Shing-hon Lau, Satish Rao, Nina Taft, and JD. Tygar. 2009 · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D. Joseph, and JD. Tygar. 2010 · 2010
Earlier work this paper cites.
Sensitivity analysis for neural networks
Daniel S. Yeung, Ian Cloete, Daming Shi, and Wing Y Ng. 2010 · 2010
Earlier work this paper cites.
Robust statistics
Peter J. Huber. 2011 · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012 · 2012
Earlier work this paper cites.
Static prediction games for adversarial learning problems
Michael Brückner, Christian Kanzow, and Tobias Scheffer. 2012 · 2012
Earlier work this paper cites.
Optimization for machine learning
Suvrit Sra, Sebastian Nowozin, and Stephen J. Wright. 2012 · 2012
Earlier work this paper cites.
Auto-encoding variational Bayes
Diederik P. Kingma and Max Welling. 2013 · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013 · 2013
Earlier work this paper cites.
Security evaluation of pattern classifiers under attack. In TKDE . IEEE
Battista Biggio, Giorgio Fumera, and Fabio Roli. 2014 · 2014
Earlier work this paper cites.
Generative adversarial nets
Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014 · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Shixiang Gu and Luca Rigazio. 2014 · 2014
Earlier work this paper cites.
Practical evasion of a learning-based classifier: A case study. In S&P . IEEE
Pavel Laskov et al · 2014
Earlier work this paper cites.
Stochastic backpropagation and approximate inference in deep generative models
Shakir Mohamed Rezende, Danilo Jimenez and Daan Wierstra. 2014 · 2014
Earlier work this paper cites.
Sequence to sequence learning with neural networks
Ilya Sutskever, Oriol Vinyals, and Quoc V. Le. 2014 · 2014
Earlier work this paper cites.
Fundamental limits on adversarial robustness. In ICML Workshop
Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2015 · 2015
Earlier work this paper cites.
Explaining and Harnessing Adversarial Examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015 · 2015
Earlier work this paper cites.
Distilling the knowledge in a neural network
Geoffrey Hinton, Oriol Vinyals, and Jeff Dean. 2015 · 2015
Earlier work this paper cites.
Learning with a strong adversary
Ruitong Huang, Bing Xu, Dale Schuurmans, and Csaba Szepesvári. 2015 · 2015
Earlier work this paper cites.
Foveation-based mechanisms alleviate adversarial examples
Yan Luo, Xavier Boix, Gemma Roig, Tomaso Poggio, and Qi Zhao. 2015 · 2015
Earlier work this paper cites.
A unified gradient regularization family for adversarial examples. In ICDM . IEEE
Chunchuan Lyu, Kaizhu Huang, and Hai-Ning Liang. 2015 · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. In CVPR . IEEE
Anh Nguyen, Jason Yosinski, and Jeff Clune. 2015 · 2015
Earlier work this paper cites.
Adversarial manipulation of deep representations
Sara Sabour, Yanshuai Cao, Fartash Faghri, and David J. Fleet. 2015 · 2015
Earlier work this paper cites.
Uri Shaham, Yutaro Yamada, and Sahand Negahban. 2015 · 2015
Earlier work this paper cites.
Measuring neural net robustness with constraints
Osbert Bastani, Yani Ioannou, Leonidas Lampropoulos, Dimitrios Vytiniotis, Aditya Nori, and Antonio Criminisi. 2016 · 2016
Earlier work this paper cites.
Hidden Voice Commands. In USENIX Security
Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David Wagner, and Wenchao Zhou. 2016 · 2016
Earlier work this paper cites.
Group equivariant convolutional networks
Taco Cohen and Max Welling. 2016 · 2016
Earlier work this paper cites.
On security and sparsity of linear classifiers for adversarial settings. In Int. Workshops on SPR and SSPR . Springer
Ambra Demontis, Paolo Russu, Battista Biggio, Giorgio Fumera, and Fabio Roli. 2016 · 2016
Earlier work this paper cites.
A study of the effect of jpg compression on adversarial images
Gintare Karolina Dziugaite, Zoubin Ghahramani, and Daniel M. Roy. 2016 · 2016
Earlier work this paper cites.
Robustness of classifiers: from adversarial to random noise
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard. 2016 · 2016
Earlier work this paper cites.
Dropout as a bayesian approximation: Representing model uncertainty in deep learning
Yarin Gal and Zoubin Ghahramani. 2016 · 2016
Earlier work this paper cites.
Adversarial perturbations against deep neural networks for malware classification
Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes, and Patrick McDaniel. 2016 · 2016
Earlier work this paper cites.
Deep residual learning for image recognition. In CVPR . IEEE
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
Early methods for detecting adversarial images
Dan Hendrycks and Kevin Gimpel. 2016 · 2016
Earlier work this paper cites.
Dense associative memory for pattern recognition
Dmitry Krotov and John J. Hopfield. 2016 · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2016 · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks. In CVPR . IEEE
Seyed Mohsen Moosavi Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016 · 2016
Earlier work this paper cites.
Secure kernel machines against evasion attacks. In AISec . ACM
Paolo Russu, Ambra Demontis, Battista Biggio, Giorgio Fumera, and Fabio Roli. 2016 · 2016
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In SIGSAC . ACM
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter. 2016 · 2016
Earlier work this paper cites.
Exploring the space of adversarial images
Pedro Tabacof and Eduardo Valle. 2016 · 2016
Earlier work this paper cites.
A boundary tilting persepective on the phenomenon of adversarial examples
Thomas Tanay and Lewis Griffin. 2016 · 2016
Cited alongside, same era.
Automatically Evading Classifiers. In Network and Distributed Systems Symposium
Weilin Xu, Yanjun Qi, and David Evans. 2016 · 2016
Cited alongside, same era.
Robustness to adversarial examples through an ensemble of specialists
Mahdieh Abbasi and Christian Gagné. 2017 · 2017
Cited alongside, same era.
Vulnerability of deep reinforcement learning to policy induction attacks. In Int. Conference on Machine Learning and Data Mining in Pattern Recognition . Springer
Vahid Behzadan and Arslan Munir. 2017 · 2017
Cited alongside, same era.
Exploring the Space of Black-box Attacks on Deep Neural Networks
Robustness of Rotation-Equivariant Networks to Adversarial Perturbations
Beranger Dumont, Simona Maggio, and Pablo Montalvo. 2018 · 2018
Later among the works it cites.
A dual approach to scalable verification of deep networks
Krishnamurthy Dvijotham, Robert Stanforth, Sven Gowal, Timothy Mann, and Pushmeet Kohli. 2018 · 2018
Later among the works it cites.
Adversarial examples that fool both computer vision and time-limited humans
Gamaleldin Elsayed, Shreya Shankar, Brian Cheung, Nicolas Papernot, Alexey Kurakin, Ian Goodfellow, and Jascha Sohl-Dickstein. 2018 · 2018
Later among the works it cites.
Robust Physical-World Attacks on Deep Learning Visual Classification. In CVPR . IEEE
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song. 2018 · 2018
Later among the works it cites.
Analysis of classifiers’ robustness to adversarial perturbations
Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2018b · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Arjun Nitin Bhagoji, Warren He, Bo Li, and Dawn Song. 2017 · 2017
Cited alongside, same era.
ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In AISec . ACM
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. 2017 · 2017
Cited alongside, same era.
Parseval networks: Improving robustness to adversarial examples
Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier. 2017 · 2017
Cited alongside, same era.
Keeping the bad guys out: Protecting and vaccinating deep learning with JPEG compression
Nilaksh Das, Madhuri Shanbhogue, Shang-Tse Chen, Fred Hohman, Li Chen, Michael E. Kounavis, and Duen Horng Chau. 2017 · 2017
Cited alongside, same era.
Formal verification of piece-wise linear feed-forward neural networks
Ruediger Ehlers. 2017 · 2017
Cited alongside, same era.
A rotation and a translation suffice: Fooling CNNs with simple transformations
Logan Engstrom, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry. 2017 · 2017
Cited alongside, same era.
Robust physical-world attacks on deep learning models
Ivan Evtimov, Kevin Eykholt, Earlence Fernandes, Tadayoshi Kohno, Bo Li, Atul Prakash, Amir Rahmati, and Dawn Song. 2017 · 2017
Cited alongside, same era.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R. Curtin, Saurabh Shintre, and Andrew B. Gardner. 2017 · 2017
Cited alongside, same era.
Ai 2: Safety and robustness certification of neural networks with abstract interpretation. In S&P . IEEE
Timon Gehr, Matthew Mirman, Dana Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, and Martin Vechev. 2018 · 2018
Later among the works it cites.
Resisting Adversarial Attacks using Gaussian Mixture Variational Autoencoders
Partha Ghosh, Arpan Losalka, and Michael J. Black. 2018 · 2018
Later among the works it cites.
Gradient Masking Causes CLEVER to Overestimate Adversarial Perturbation Size
Ian Goodfellow. 2018 · 2018
Later among the works it cites.
On the effectiveness of interval bound propagation for training verifiably robust models
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Timothy Mann, and Pushmeet Kohli. 2018 · 2018
Later among the works it cites.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten. 2018 · 2018
Later among the works it cites.
Safety and Trustworthiness of Deep Neural Networks: A Survey
Xiaowei Huang, Daniel Kroening, Marta Kwiatkowska, Wenjie Ruan, Youcheng Sun, Emese Thamo, Min Wu, and Xinping Yi. 2018 · 2018
Later among the works it cites.
Limitations of the Lipschitz constant as a defense against adversarial examples. In ECML PKDD . Springer
Todd Huster, Cho-Yu Jason Chiang, and Ritu Chadha. 2018 · 2018
Later among the works it cites.
Black-box Adversarial Attacks with Limited Queries and Information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018 · 2018
Later among the works it cites.
Enablers of Adversarial Attacks in Machine Learning. In MILCOM . IEEE
Rauf Izmailov, Shridatt Sugrim, Ritu Chadha, Patrick McDaniel, and Ananthram Swami. 2018 · 2018
Later among the works it cites.
Geometric robustness of deep networks: analysis and improvement. In CVPR . IEEE
Can Kanbak, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard. 2018 · 2018
Later among the works it cites.
Art of singular vectors and universal adversarial perturbations. In CVPR . IEEE
Valentin Khrulkov and Ivan Oseledets. 2018 · 2018
Later among the works it cites.
Adversarial Examples on Discrete Sequences for Beating Whole-Binary Malware Detection
Felix Kreuk, Assi Barak, Shir Aviv-Reuven, Moran Baruch, Benny Pinkas, and Joseph Keshet. 2018 · 2018
Later among the works it cites.
Alex Lamb, Jonathan Binas, Anirudh Goyal, Dmitriy Serdyuk, Sandeep Subramanian, Ioannis Mitliagkas, and Yoshua Bengio. 2018 · 2018
Later among the works it cites.
Adversarial perturbations against real-time video classification systems
Shasha Li, Ajaya Neupane, Sujoy Paul, Chengyu Song, Srikanth V. Krishnamurthy, Amit K. Roy Chowdhury, and Ananthram Swami. 2018 · 2018
Later among the works it cites.
A Survey on Security Threats and Defensive Techniques of Machine Learning: A Data Driven View
Qiang Liu, Pan Li, Wentao Zhao, Wei Cai, Shui Yu, and Victor CM Leung. 2018a · 2018
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018 · 2018
Later among the works it cites.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin Vechev. 2018 · 2018
Later among the works it cites.
Robustness of Classifiers to Universal Perturbations: A Geometric Perspective
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, Pascal Frossard, and Stefano Soatto. 2018 · 2018
Later among the works it cites.
A Marauder’s Map of Security and Privacy in Machine Learning
Nicolas Papernot. 2018 · 2018
Later among the works it cites.
SoK: Security and privacy in machine learning. In EuroS&P . IEEE
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P. Wellman. 2018 · 2018
Later among the works it cites.
Bidirectional Learning for Robust Neural Networks
Sidney Pontes-Filho and Marcus Liwicki. 2018 · 2018
Later among the works it cites.
Generative adversarial perturbations. In CVPR . IEEE
Omid Poursaeed, Isay Katsman, Bicheng Gao, and Serge Belongie. 2018 · 2018
Later among the works it cites.
Blind pre-processing: A robust defense method against adversarial examples
Adnan Siraj Rakin, Zhezhi He, Boqing Gong, and Deliang Fan. 2018 · 2018
Later among the works it cites.
Adversarially Robust Training through Structured Gradient Regularization
Kevin Roth, Aurelien Lucchi, Sebastian Nowozin, and Thomas Hofmann. 2018 · 2018
Later among the works it cites.
Reachability analysis of deep neural networks with provable guarantees
Wenjie Ruan, Xiaowei Huang, and Marta Kwiatkowska. 2018 · 2018
Later among the works it cites.
Adversarially Robust Generalization Requires More Data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry. 2018 · 2018
Later among the works it cites.
Defending against Adversarial Images using Basis Functions Transformations
Uri Shaham, James Garritano, Yutaro Yamada, Ethan Weinberger, Alex Cloninger, Xiuyuan Cheng, and Kelly Stanton. 2018 · 2018
Later among the works it cites.
Certifying some distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi. 2018b · 2018
Later among the works it cites.
PixelDefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman. 2018a · 2018
Later among the works it cites.
Constructing unrestricted adversarial examples with generative models
Yang Song, Rui Shu, Nate Kushman, and Stefano Ermon. 2018b · 2018
Later among the works it cites.
Is Robustness the Cost of Accuracy?–A Comprehensive Study on the Robustness of 18 Deep Image Classification Models. In ECCV
Dong Su, Huan Zhang, Hongge Chen, Jinfeng Yi, Pin-Yu Chen, and Yupeng Gao. 2018 · 2018
Later among the works it cites.
Transferable Adversarial Attacks for Image and Video Object Detection
Xingxing Wei, Siyuan Liang, Xiaochun Cao, and Jun Zhu. 2018 · 2018
Later among the works it cites.
Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach
Tsui-Wei Weng, Huan Zhang, Pin-Yu Chen, Jinfeng Yi, Dong Su, Yupeng Gao, Cho-Jui Hsieh, and Luca Daniel. 2018 · 2018
Later among the works it cites.
Feature-guided black-box safety testing of deep neural networks. In TACAS 2018 . Springer
Matthew Wicker, Xiaowei Huang, and Marta Kwiatkowska. 2018 · 2018
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and J. Zico Kolter. 2018 · 2018
Later among the works it cites.
A Game-Based Approximate Verification of Deep Neural Networks with Provable Guarantees
Min Wu, Matthew Wicker, Wenjie Ruan, Xiaowei Huang, and Marta Kwiatkowska. 2018 · 2018
Later among the works it cites.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song. 2018 · 2018
Later among the works it cites.
Mitigating Adversarial Effects through Randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille. 2018 · 2018
Later among the works it cites.
Robust audio adversarial example for a physical attack
Hiromu Yakura and Jun Sakuma. 2018 · 2018
Later among the works it cites.
Detecting Adversarial Perturbations with Saliency
Chiliang Zhang, Zhimou Yang, and Zuochang Ye. 2018 · 2018
Later among the works it cites.
On Evaluating Adversarial Robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian J. Goodfellow, Aleksander Madry, and Alexey Kurakin. 2019 · 2019
Later among the works it cites.
Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks. In USENIX Security
Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019 · 2019
Later among the works it cites.
Benchmarking neural network robustness to common corruptions and perturbations
Dan Hendrycks and Thomas Dietterich. 2019 · 2019
Later among the works it cites.
Adversarial Examples Are Not Bugs, They Are Features
Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019 · 2019
Later among the works it cites.
A Convex Relaxation Barrier to Tight Robust Verification of Neural Networks
Hadi Salman, Greg Yang, Huan Zhang, Cho-Jui Hsieh, and Pengchuan Zhang. 2019 · 2019
Later among the works it cites.
One pixel attack for fooling deep neural networks
Jiawei Su, Danilo Vasconcellos Vargas, and Kouichi Sakurai. 2019 · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry. 2019 · 2019
Later among the works it cites.
The limitations of adversarial training and the blind-spot attack
Huan Zhang, Hongge Chen, Zhao Song, Duane Boning, Inderjit S Dhillon, and Cho-Jui Hsieh. 2019 · 2019
Later among the works it cites.