On evaluating adversarial robustness
Original
N. Carlini, A. Athalye, N. Papernot, W. Brendel, J. Rauber, D. Tsipras, I. Goodfellow, A. Madry, and A. Kurakin · 1902
Earlier work this paper cites.
Transfer of adversarial robustness between perturbation types
Original
D. Kang, Y. Sun, T. Brown, D. Hendrycks, and J. Steinhardt · 1905
Earlier work this paper cites.
Adversarial robustness as a prior for learned representations
Original
L. Engstrom, A. Ilyas, S. Santurkar, D. Tsipras, B. Tran, and A. Madry · 1906
Earlier work this paper cites.
Testing robustness against unforeseen adversaries
Original
D. Kang, Y. Sun, D. Hendrycks, T. Brown, and J. Steinhardt · 1908
Earlier work this paper cites.
An alternative surrogate loss for pgd-based adversarial testing
Original
S. Gowal, J. Uesato, C. Qin, P.-S. Huang, T. Mann, and P. Kohli · 1910
Earlier work this paper cites.
On the limited memory bfgs method for large scale optimization
D. C. Liu and J. Nocedal · 1989
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky and G. Hinton · 2009
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, D. E. Joan Bruna, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Describing textures in the wild
M. Cimpoi, S. Maji, I. Kokkinos, S. Mohamed, and A. Vedaldi · 2014
Earlier work this paper cites.
Manitest: Are classifiers really invariant?
A. Fawzi and P. Frossard · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Wide residual networks
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Adversarial patch
T. B. Brown, D. Mané, A. Roy, M. Abadi, and J. Gilmer · 2017
Earlier work this paper cites.
Adversarial examples for malware detection
K. Grosse, N. Papernot, P. Manoharan, M. Backes, and P. McDaniel · 2017
Earlier work this paper cites.
On calibration of modern neural networks
C. Guo, G. Pleiss, Y. Sun, and K. Q. Weinberger · 2017
Earlier work this paper cites.
Formal guarantees on the robustness of a classifier against adversarial manipulation
M. Hein and M. Andriushchenko · 2017
Earlier work this paper cites.
A baseline for detecting misclassified and out-of-distribution examples in neural networks
D. Hendrycks and K. Gimpel · 2017
Earlier work this paper cites.
Reluplex: an efficient smt solver for verifying deep neural networks
G. Katz, C. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer · 2017
Earlier work this paper cites.
Adversarial examples in the physical world
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Earlier work this paper cites.
Automatic differentiation in pytorch
A. Paszke, S. Gross, S. Chintala, G. Chanan, E. Yang, Z. DeVito, Z. Lin, A. Desmaison, L. Antiga, and A. Lerer · 2017
Earlier work this paper cites.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
J. Rauber, W. Brendel, and M. Bethge · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
R. Shokri, M. Stronati, C. Song, and V. Shmatikov · 2017
Earlier work this paper cites.
Adversarial examples for semantic segmentation and object detection
C. Xie, J. Wang, Z. Zhang, Y. Zhou, L. Xie, and A. Yuille · 2017
Earlier work this paper cites.
Generating natural language adversarial examples
M. Alzantot, Y. Sharma, A. Elgohary, B.-J. Ho, M. Srivastava, and K.-W. Chang · 2018
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Earlier work this paper cites.
Adversarial vision challenge
W. Brendel, J. Rauber, A. Kurakin, N. Papernot, B. Veliqi, M. Salathé, S. P. Mohanty, and M. Bethge · 2018
Earlier work this paper cites.
Unrestricted adversarial examples
Original
T. B. Brown, N. Carlini, C. Zhang, C. Olsson, P. Christiano, and I. Goodfellow · 2018
Earlier work this paper cites.
Thermometer encoding: One hot way to resist adversarial examples
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow · 2018
Earlier work this paper cites.
Cinic-10 is not imagenet or cifar-10
Original
L. N. Darlow, E. J. Crowley, A. Antoniou, and A. J. Storkey · 2018
Earlier work this paper cites.
Evaluating and understanding the robustness of adversarial logit pairing
L. Engstrom, A. Ilyas, and A. Athalye · 2018
Earlier work this paper cites.
Robust physical-world attacks on machine learning models
I. Evtimov, K. Eykholt, E. Fernandes, T. Kohno, B. Li, A. Prakash, A. Rahmati, and D. Song · 2018
Earlier work this paper cites.
Motivating the rules of the game for adversarial example research
Original
J. Gilmer, R. P. Adams, I. Goodfellow, D. Andersen, and G. E. Dahl · 2018
Earlier work this paper cites.
Countering adversarial images using input transformations
C. Guo, M. Rana, M. Cisse, and L. van der Maaten · 2018
Earlier work this paper cites.
Adversarial attacks and defences competition
A. Kurakin, I. Goodfellow, S. Bengio, Y. Dong, F. Liao, M. Liang, T. Pang, J. Zhu, X. Hu, C. Xie, et al · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Earlier work this paper cites.
Logit pairing methods can fool gradient-based attacks
M. Mosbach, M. Andriushchenko, T. Trost, M. Hein, and D. Klakow · 2018
Earlier work this paper cites.
Adversarial robustness toolbox v1.2.0
Original
M.-I. Nicolae, M. Sinn, M. N. Tran, B. Buesser, A. Rawat, M. Wistuba, V. Zantedeschi, N. Baracaldo, B. Chen, H. Ludwig, I. Molloy, and B. Edwards · 2018
Earlier work this paper cites.
Technical report on the cleverhans v2.1.0 adversarial examples library
Original
N. Papernot, F. Faghri, N. Carlini, I. Goodfellow, R. Feinman, A. Kurakin, C. Xie, Y. Sharma, T. Brown, A. Roy, A. Matyasko, V. Behzadan, K. Hambardzumyan, Z. Zhang, Y.-L. Juang, Z. Li, R. Sheatsley, A. Garg, J. Uesato, W. Gierke, Y. Dong, D. Berthelot, P. Hendricks, J. Rauber, and R. Long · 2018
Earlier work this paper cites.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
P. Samangouei, M. Kabkab, and R. Chellappa · 2018
Earlier work this paper cites.
Towards fast computation of certified robustness for relu networks
T.-W. Weng, H. Zhang, H. Chen, Z. Song, C.-J. Hsieh, D. Boning, I. S. Dhillon, and L. Daniel · 2018
Earlier work this paper cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
E. Wong and Z. Kolter · 2018
Earlier work this paper cites.
Controlling neural level sets
M. Atzmon, N. Haim, L. Yariv, O. Israelov, H. Maron, and Y. Lipman · 2019
Earlier work this paper cites.
A critique of the deepsec platform for security analysis of deep learning models
Original
N. Carlini · 2019
Earlier work this paper cites.
Unlabeled data improves adversarial robustness
Y. Carmon, A. Raghunathan, L. Schmidt, P. Liang, and J. C. Duchi · 2019
Earlier work this paper cites.
Certified adversarial robustness via randomized smoothing
J. M. Cohen, E. Rosenfeld, and J. Z. Kolter · 2019
Earlier work this paper cites.
Sparse and imperceivable adversarial attacks
F. Croce and M. Hein · 2019
Earlier work this paper cites.
AdverTorch v0.1: An adversarial robustness toolbox based on pytorch
Original
G. W. Ding, L. Wang, and X. Jin · 2019
Earlier work this paper cites.
Adversarial examples are a natural consequence of test error in noise
N. Ford, J. Gilmer, N. Carlini, and D. Cubuk · 2019
Earlier work this paper cites.