Fetching the paper…
Reading the bibliography…
Deep neural networks are easily misled by adversarial examples.
Evolutionsstrategien
Ingo Rechenberg. 1978 · 1978
Earlier work this paper cites.
The hardness of approximate optima in lattices, codes, and systems of linear equations
Sanjeev Arora, László Babai, Jacques Stern, and Z Sweedyk. 1997 · 1997
Earlier work this paper cites.
Convexity, classification, and risk bounds
Peter L Bartlett, Michael I Jordan, and Jon D McAuliffe. 2006 · 2006
Earlier work this paper cites.
On the consistency of multiclass classification methods
Ambuj Tewari and Peter L Bartlett. 2007 · 2007
Earlier work this paper cites.
Convolutional deep belief networks on cifar-10
Alex Krizhevsky and Geoff Hinton. 2010 · 2010
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks. In Advances in neural information processing systems . 1097–1105
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2012 · 2012
Earlier work this paper cites.
Min Lin, Qiang Chen, and Shuicheng Yan. 2013 · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013 · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014 · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Shixiang Gu and Luca Rigazio. 2014 · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman. 2014 · 2014
Earlier work this paper cites.
Fast r-cnn. In Proceedings of the IEEE international conference on computer vision . 1440–1448
Ross Girshick. 2015 · 2015
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016 · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE conference on computer vision and pattern recognition . 2574–2582
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016 · 2016
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 acm sigsac conference on computer and communications security . 1528–1540
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter. 2016 · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision. In Proceedings of the IEEE conference on computer vision and pattern recognition . 2818–2826
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. 2016 · 2016
Earlier work this paper cites.
Adversarial Patch
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer. 2017 · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp) . IEEE, 39–57
Nicholas Carlini and David Wagner. 2017 · 2017
Earlier work this paper cites.
A rotation and a translation suffice: Fooling cnns with simple transformations
Logan Engstrom, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry. 2017 · 2017
Cited alongside, same era.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens Van Der Maaten. 2017 · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017 · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia conference on computer and communications security . 506–519
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami. 2017 · 2017
Cited alongside, same era.
Adversarial risk and the dangers of evaluating against weak attacks
Jonathan Uesato, Brendan O’Donoghue, Aaron van den Oord, and Pushmeet Kohli. 2018 · 2018
Later among the works it cites.
Generating adversarial examples with adversarial networks
Chaowei Xiao, Bo Li, Jun-Yan Zhu, Warren He, Mingyan Liu, and Dawn Song. 2018a · 2018
Later among the works it cites.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song. 2018b · 2018
Later among the works it cites.
Instance adaptive adversarial training: Improved accuracy tradeoffs in neural nets
Yogesh Balaji, Tom Goldstein, and Judy Hoffman. 2019 · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Adam Paszke, Sam Gross, Soumith Chintala, Gregory Chanan, Edward Yang, Zachary DeVito, Zeming Lin, Alban Desmaison, Luca Antiga, and Adam Lerer. 2017 · 2017
Cited alongside, same era.
Adversarial generative nets: Neural network attacks on state-of-the-art face recognition
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter. 2017 · 2017
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2017 · 2017
Cited alongside, same era.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille. 2017 · 2017
Cited alongside, same era.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi. 2017 · 2017
Cited alongside, same era.
ADef: an iterative algorithm to construct adversarial deformations
Rima Alaifari, Giovanni S Alberti, and Tandri Gauksson. 2018 · 2018
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner. 2018a · 2018
Cited alongside, same era.
Unrestricted adversarial examples
Tom B Brown, Nicholas Carlini, Chiyuan Zhang, Catherine Olsson, Paul Christiano, and Ian Goodfellow. 2018 · 2018
Cited alongside, same era.
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin. 2019 · 2019
Later among the works it cites.
Why deep-learning AIs are so easy to fool
Douglas Heaven. 2019 · 2019
Later among the works it cites.
Benchmarking neural network robustness to common corruptions and perturbations
Dan Hendrycks and Thomas Dietterich. 2019 · 2019
Later among the works it cites.
Enhancing Transformation-Based Defenses Against Adversarial Attacks with a Distribution Classifier. In International Conference on Learning Representations
Connie Kou, Hwee Kuan Lee, Ee-Chien Chang, and Teck Khim Ng. 2019 · 2019
Later among the works it cites.
Adversarial training for free!. In Advances in Neural Information Processing Systems . 3353–3364
Ali Shafahi, Mahyar Najibi, Mohammad Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein. 2019 · 2019
Later among the works it cites.
One pixel attack for fooling deep neural networks
Jiawei Su, Danilo Vasconcellos Vargas, and Kouichi Sakurai. 2019 · 2019
Later among the works it cites.
Adversarial training and robustness for multiple perturbations. In Advances in Neural Information Processing Systems . 5858–5868
Florian Tramèr and Dan Boneh. 2019 · 2019
Later among the works it cites.
Bilateral adversarial training: Towards fast training of more robust models against adversarial attacks. In Proceedings of the IEEE International Conference on Computer Vision . 6629–6638
Jianyu Wang and Haichao Zhang. 2019 · 2019
Later among the works it cites.
Improving adversarial robustness requires revisiting misclassified examples. In International Conference on Learning Representations
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu. 2019 · 2019
Later among the works it cites.
You only propagate once: Painless adversarial training using maximal principle
Dinghuai Zhang, Tianyuan Zhang, Yiping Lu, Zhanxing Zhu, and Bin Dong. 2019b · 2019
Later among the works it cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P Xing, Laurent El Ghaoui, and Michael I Jordan. 2019a · 2019
Later among the works it cites.
Cat: Customized adversarial training for improved robustness
Minhao Cheng, Qi Lei, Pin-Yu Chen, Inderjit Dhillon, and Cho-Jui Hsieh. 2020 · 2020
Later among the works it cites.
Sanchari Sen, Balaraman Ravindran, and Anand Raghunathan. 2020 · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020 · 2020
Later among the works it cites.