Fetching the paper…
Reading the bibliography…
Machine learning classifiers are critically prone to evasion attacks.
Public watermarks and resistance to tampering
I. J. Cox and J. . M. G. Linnartz · 1997
Earlier work this paper cites.
Analysis of the sensitivity attack against electronic watermarks in images
J. Linnartz and Marten van Dijk · 1998
Earlier work this paper cites.
Blind newton sensitivity attack
P. Comesana, L. Perez-Freire, and F. Perez-Gonzalez · 2006
Earlier work this paper cites.
Tangential sensitivity analysis of watermarks using prior information
John W. Earl · 2007
Earlier work this paper cites.
Efficiency of coordinate descent methods on huge-scale optimization problems
Yu. Nesterov · 2012
Earlier work this paper cites.
Robustness of classifiers: from adversarial to random noise
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh · 2017
Earlier work this paper cites.
Simple black-box adversarial attacks on deep neural networks
N. Narodytska and S. Kasiviswanathan · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2017
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2018
Cited alongside, same era.
Empirical study of the topology and geometry of deep networks
Alhussein Fawzi, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, and Stefano Soatto · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Pytorch: An imperative style, high-performance deep learning library
Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Kopf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala · 2019
Later among the works it cites.
Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses
Jerome Rony, Luiz G. Hafemann, Luiz S. Oliveira, Ismail Ben Ayed, Robert Sabourin, and Eric Granger · 2019
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
Chun-Chen Tu, Paishun Ting, Pin-Yu Chen, Sijia Liu, Huan Zhang, Jinfeng Yi, Cho-Jui Hsieh, and Shin-Ming Cheng · 2019
Later among the works it cites.
HopSkipJumpAttack: A query-efficient decision-based attack
Jianbo Chen, Michael I Jordan, and Martin J Wainwright · 2020
Closest in time.
Qeba: Query-efficient boundary-based blackbox attack
H. Li, X. Xu, X. Zhang, S. Yang, and B. Li · 2020
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Query-efficient hard-label black-box attack: An optimization-based approach
Minhao Cheng, Thong Le, Pin-Yu Chen, Huan Zhang, Jinfeng Yi, and Cho-Jui Hsieh · 2019
Cited alongside, same era.
Simple black-box adversarial attacks
Chuan Guo, Jacob Gardner, Yurong You, Andrew Gordon Wilson, and Kilian Weinberger · 2019
Cited alongside, same era.
Prior convictions: Black-box adversarial attacks with bandits and priors
Andrew Ilyas, Logan Engstrom, and Aleksander Madry · 2019
Cited alongside, same era.
A primer on zeroth-order optimization in signal processing and machine learning: Principals, recent advances, and applications
S. Liu, P. Y. Chen, B. Kailkhura, G. Zhang, A. O. Hero III, and P. K. Varshney · 2020
Closest in time.
Geoda: a geometric framework for black-box adversarial attacks
Ali Rahmati, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, and Huaiyu Dai · 2020
Closest in time.
Foolbox native: Fast adversarial attacks to benchmark the robustness of machine learning models in pytorch, tensorflow, and jax
Jonas Rauber, Roland Zimmermann, Matthias Bethge, and Wieland Brendel · 2020
Closest in time.
Towards query-efficient black-box adversary with zeroth-order natural gradient descent
Pu Zhao, Pin-Yu Chen, Siyue Wang, and Xue Lin · 2020
Closest in time.