Fetching the paper…
Reading the bibliography…
Advances in the development of adversarial attacks have been fundamental to the progress of adversarial defense research.
An algorithm for quadratic programming
M. Frank and P. Wolfe · 1956
Earlier work this paper cites.
The mnist database of handwritten digits
Y. LeCun · 1998
Earlier work this paper cites.
ImageNet: A Large-Scale Hierarchical Image Database
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky et al · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Adam: A method for stochastic optimization
D. P. Kingma and J. Ba · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2015
Earlier work this paper cites.
On graduated optimization for stochastic non-convex problems
E. Hazan, K. Y. Levy, and S. Shalev-Shwartz · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
A. Kurakin, I. Goodfellow, and S. Bengio · 2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Adversarial machine learning at scale
A. Kurakin, I. Goodfellow, and S. Bengio · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
A. Athalye, N. Carlini, and D. Wagner · 2018
Cited alongside, same era.
Thermometer encoding: One hot way to resist adversarial examples
J. Buckman, A. Roy, C. Raffel, and I. Goodfellow · 2018
Cited alongside, same era.
Countering adversarial images using input transformations
C. Guo, M. Rana, M. Cisse, and L. van der Maaten · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, T. Dimitris, and A. Vladu · 2018
Cited alongside, same era.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman · 2018
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Robustness via curvature regularization, and vice versa
S.-M. Moosavi-Dezfooli, A. Fawzi, J. Uesato, and P. Frossard · 2019
Later among the works it cites.
Adversarial robustness through local linearization
C. Qin, J. Martens, S. Gowal, D. Krishnan, K. Dvijotham, A. Fawzi, S. De, R. Stanforth, and P. Kohli · 2019
Later among the works it cites.
Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses
J. Rony, L. G. Hafemann, L. S. Oliveira, I. B. Ayed, R. Sabourin, and E. Granger · 2019
Later among the works it cites.
Adversarial training for free!
A. Shafahi, M. Najibi, M. A. Ghiasi, Z. Xu, J. Dickerson, C. Studer, L. S. Davis, G. Taylor, and T. Goldstein · 2019
Later among the works it cites.
Robustness may be at odds with accuracy
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry · 2019
Later among the works it cites.
Regularizer to mitigate gradient masking effect during single-step adversarial training
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel · 2018
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
J. Uesato, B. O’Donoghue, A. v. d. Oord, and P. Kohli · 2018
Cited alongside, same era.
Mitigating adversarial effects through randomization
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille · 2018
Cited alongside, same era.
On evaluating adversarial robustness
N. Carlini, A. Athalye, N. Papernot, W. Brendel, J. Rauber, D. Tsipras, I. Goodfellow, and A. Madry · 2019
Cited alongside, same era.
Unlabeled data improves adversarial robustness
Y. Carmon, A. Raghunathan, L. Schmidt, J. C. Duchi, and P. S. Liang · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
J. Cohen, E. Rosenfeld, and Z. Kolter · 2019
Cited alongside, same era.
Robustness (python library), 2019
L. Engstrom, A. Ilyas, H. Salman, S. Santurkar, and D. Tsipras · 2019
Cited alongside, same era.
B. Vivek, A. Baburaj, and R. Venkatesh Babu · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, and M. I. Jordan · 2019
Later among the works it cites.
Towards Achieving Adversarial Robustness by Enforcing Feature Consistency Across Bit Planes
S. Addepalli, B. S. Vivek, A. Baburaj, G. Sriramanan, and R. Venkatesh Babu · 2020
Closest in time.
Square attack: a query-efficient black-box adversarial attack via random search
M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein · 2020
Closest in time.
Overfitting in adversarially robust deep learning
L. Rice, E. Wong, and J. Z. Kolter · 2020
Closest in time.
Hydra: Pruning adversarially robust neural networks
V. Sehwag, S. Wang, P. Mittal, and S. Jana · 2020
Closest in time.
Improving adversarial robustness requires revisiting misclassified examples
Y. Wang, D. Zou, J. Yi, J. Bailey, X. Ma, and Q. Gu · 2020
Closest in time.
Fast is better than free: Revisiting adversarial training
E. Wong, L. Rice, and J. Z. Kolter · 2020
Closest in time.