Fetching the paper…
Reading the bibliography…
Adversarial robustness of deep neural networks has been actively investigated.
A. Krizhevsky
2009
Earlier work this paper cites.
H. Kuehne, H. Jhuang, E. Garrote, T. Poggio, and T. Serre, “Hmdb: a large video database for human motion recognition,” in
2011
Earlier work this paper cites.
2012
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in
2014
Earlier work this paper cites.
J. Donahue, L. A. Hendricks, S. Guadarrama, M. Rohrbach, S. Venugopalan, K. Saenko, and T. Darrell, “Long-term recurrent convolutional networks for visual recognition and description,” in
2015
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in
2015
Earlier work this paper cites.
S. Ioffe and C. Szegedy, “Batch normalization: Accelerating deep network training by reducing internal covariate shift,” in
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in
2016
Earlier work this paper cites.
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition,” in
2016
Earlier work this paper cites.
L.-C. Chen, G. Papandreou, I. Kokkinos, K. Murphy, and A. L. Yuille, “Deeplab: Semantic image segmentation with deep convolutional nets, atrous convolution, and fully connected crfs,” in
2017
Earlier work this paper cites.
K. He, G. Gkioxari, P. Dollar, and R. Girshick, “Mask r-cnn,” in
2017
Earlier work this paper cites.
J. Carreira and A. Zisserman, “Quo vadis, action recognition? a new model and the kinetics dataset,” in
2017
Earlier work this paper cites.
I. Goodfellow, N. Papernot, S. Huang, Y. Duan, and P. Abbeel, “Attacking machine learning with adversarial examples,”
2017
Earlier work this paper cites.
T. Brown, D. Mane, A. Roy, M. Abadi, and J. Gilmer, “Adversarial patch,” in
2017
Earlier work this paper cites.
A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial machine learning at scale,” in
2017
Earlier work this paper cites.
E. Jang, S. Gu, and B. Poole, “Categorical reparameterization with gumbel-softmax,” in
2017
Earlier work this paper cites.
C. J. Maddison, A. Mnih, and Y. W. Teh, “The concrete distribution: A continuous relaxation of discrete random variables,” in
2017
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, “Practical black-box attacks against machine learning,” in
2017
Cited alongside, same era.
K. Hara, H. Kataoka, and Y. Satoh, “Can spatiotemporal 3d cnns retrace the history of 2d cnns and imagenet?” in
2018
Cited alongside, same era.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in
2018
Cited alongside, same era.
P. Samangouei, M. Kabkab, and R. Chellappa, “Defense-GAN: Protecting classifiers against adversarial attacks using generative models,” in
2018
Cited alongside, same era.
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille, “Mitigating adversarial effects through randomization,” in
2018
Cited alongside, same era.
S. Li, A. Neupane, S. Paul, C. Song, S. V. Krishnamurthy, A. K. Roy-Chowdhury, and A. Swami, “Stealthy adversarial perturbations against real-time video classification systems.” in
2019
Later among the works it cites.
X. Wei, S. Liang, N. Chen, and X. Cao, “Transferable adversarial attacks for image and video object detection,” in
2019
Later among the works it cites.
X. Wei, J. Zhu, S. Yuan, and H. Su, “Sparse adversarial perturbations for videos,” in
2019
Later among the works it cites.
2019
Later among the works it cites.
C. Xiao, R. Deng, B. Li, T. Lee, B. Edwards, J. Yi, D. X. Song, M. Liu, and I. Molloy, “Advit: Adversarial frames identifier based on temporal consistency in videos,” in
2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” in
2018
Cited alongside, same era.
A. Raghunathan, J. Steinhardt, and P. Liang, “Certified defenses against adversarial examples,” in
2018
Cited alongside, same era.
E. Wong and J. Z. Kolter, “Provable defenses against adversarial examples via the convex outer adversarial polytope,” in
2018
Cited alongside, same era.
Y. Sharma and P.-Y. Chen, “Attacking the madry defense model with
2018
Cited alongside, same era.
M. Zajac, K. Zołna, N. Rostamzadeh, and P. O. Pinheiro, “Adversarial framing for image and video classification,” in
2019
Cited alongside, same era.
X. Jia, X. Wei, X. Cao, and H. Foroosh, “Comdefend: An efficient image compression model to defend adversarial examples,” in
2019
Cited alongside, same era.
E. Raff, J. Sylvester, S. Forsyth, and M. McLean, “Barrage of random transforms for adversarially robust defense,” in
2019
Cited alongside, same era.
Later among the works it cites.
S. Thys, W. Van Ranst, and T. Goedemé, “Fooling automated surveillance cameras: adversarial patches to attack person detection,” in
2019
Later among the works it cites.
J. Su, D. V. Vargas, and K. Sakurai, “One pixel attack for fooling deep neural networks,” in
2019
Later among the works it cites.
S. Addepalli, A. Baburaj, G. Sriramanan, and R. V. Babu, “Towards achieving adversarial robustness by enforcing feature consistency across bit planes,” in
2020
Closest in time.
C. Xie, M. Tan, B. Gong, J. Wang, A. Yuille, and Q. V. Le, “Adversarial examples improve image recognition,” in
2020
Closest in time.
T. Wu, L. Tong, and Y. Vorobeychik, “Defending against physically realizable attacks on image classification,” in
2020
Closest in time.
P. Maini, E. Wong, and J. Z. Kolter, “Adversarial robustness against the union of multiple perturbation models,” in
2020
Closest in time.
W.-A. Lin, C. P. Lau, A. Levine, R. Chellappa, and S. Feizi, “Dual manifold adversarial robustness: Defense against lp and non-lp adversarial attacks,” in
2020
Closest in time.
C. Xie and A. Yuille, “Intriguing properties of adversarial training at scale,” in
2020
Closest in time.
K. Xu, M. Qin, F. Sun, Y. Wang, Y.-K. Chen, and F. Ren, “Learning in the frequency domain,” in
2020
Closest in time.
F. Tramèr, N. Carlini, W. Brendel, and A. Madry, “On adaptive attacks to adversarial example defenses,” in
2020
Closest in time.
D. Hendrycks, K. Zhao, S. Basart, J. Steinhardt, and D. Song, “Natural adversarial examples,” in
2021
Closest in time.
C. Laidlaw, S. Singla, and S. Feizi, “Perceptual adversarial robustness: Defense against unseen threat models,” in
2021
Closest in time.