Fetching the paper…
Reading the bibliography…
Deep neural networks (DNNs) are known to be vulnerable to adversarial attacks that would trigger misclassification of DNNs but may be imperceptible to human perception.
Statistical analysis of some multi-category large margin classification methods
Tong Zhang · 2004
Earlier work this paper cites.
Lineare funktionalanalysis. eine anwendungsorientierte einführung.. aufl
HW Alt · 2006
Earlier work this paper cites.
Convexity, classification, and risk bounds
Peter L Bartlett, Michael I Jordan, and Jon D McAuliffe · 2006
Earlier work this paper cites.
Optimal transport: old and new
Cédric Villani · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
On the consistency of multi-label learning
Wei Gao and Zhi-Hua Zhou · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Olga Russakovsky, Jia Deng, Hao Su, Jonathan Krause, Sanjeev Satheesh, Sean Ma, Zhiheng Huang, Andrej Karpathy, Aditya Khosla, Michael Bernstein, Alexander C. Berg, and Li Fei-Fei · 2015
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter · 2016
Earlier work this paper cites.
Multiclass classification calibration functions
Bernardo Ávila Pires and Csaba Szepesvári · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
Wasserstein generative adversarial networks
Martin Arjovsky, Soumith Chintala, and Léon Bottou · 2017
Earlier work this paper cites.
Improved training of wasserstein gans
Ishaan Gulrajani, Faruk Ahmed, Martin Arjovsky, Vincent Dumoulin, and Aaron C Courville · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Constructing unrestricted adversarial examples with generative models
Yang Song, Rui Shu, Nate Kushman, and Stefano Ermon · 2018
Cited alongside, same era.
Synthesizing robust adversarial examples
Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok · 2018
Cited alongside, same era.
Generating natural adversarial examples
Zhengli Zhao, Dheeru Dua, and Sameer Singh · 2018
Cited alongside, same era.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song · 2018
Cited alongside, same era.
Harini Kannan, Alexey Kurakin, and Ian Goodfellow · 2018
Cited alongside, same era.
Generating adversarial examples with adversarial networks
Chaowei Xiao, Bo Li, Jun-Yan Zhu, Warren He, Mingyan Liu, and Dawn Song · 2018
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Later among the works it cites.
Minimally distorted adversarial examples with a fast adaptive boundary attack
F. Croce and M. Hein · 2020
Later among the works it cites.
Stronger and faster wasserstein adversarial attacks
Kaiwen Wu, Allen Houze Wang, and Yaoliang Yu · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Later among the works it cites.
Understanding and mitigating the tradeoff between robustness and accuracy
Aditi Raghunathan, Sang Michael Xie, Fanny Yang, John C. Duchi, and Percy Liang · 2020
Later among the works it cites.
A Closer Look at Accuracy vs. Robustness
Yao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Ruslan Salakhutdinov, and Kamalika Chaudhuri · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Fine-grained synthesis of unrestricted adversarial examples
Omid Poursaeed, Tianxing Jiang, Harry Yang, Serge J. Belongie, and Ser-Nam Lim · 2019
Cited alongside, same era.
ADef: an iterative algorithm to construct adversarial deformations
Rima Alaifari, Giovanni S. Alberti, and Tandri Gauksson · 2019
Cited alongside, same era.
Beyond pixel norm-balls: Parametric adversaries using an analytically differentiable renderer
Hsueh-Ti Derek Liu, Michael Tao, Chun-Liang Li, Derek Nowrouzezahrai, and Alec Jacobson · 2019
Cited alongside, same era.
Wasserstein adversarial examples via projected sinkhorn iterations
Eric Wong, Frank Schmidt, and Zico Kolter · 2019
Cited alongside, same era.
Adversarial training for free!
Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein · 2019
Cited alongside, same era.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P Xing, Laurent El Ghaoui, and Michael I Jordan · 2019
Cited alongside, same era.
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2020
Later among the works it cites.
Improving adversarial robustness requires revisiting misclassified examples
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu · 2020
Later among the works it cites.
Deepemd: Few-shot image classification with differentiable earth mover’s distance and structured classifiers
Chi Zhang, Yujun Cai, Guosheng Lin, and Chunhua Shen · 2020
Later among the works it cites.
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Later among the works it cites.
Mind the box: l1-apgd for sparse adversarial attacks on image classifiers
Francesco Croce and Matthias Hein · 2021
Closest in time.
Fast minimum-norm adversarial attacks through adaptive norm constraints
Maura Pintor, Fabio Roli, Wieland Brendel, and Battista Biggio · 2021
Closest in time.
Learning to generate noise for multi-attack robustness
Divyam Madaan, Jinwoo Shin, and Sung Ju Hwang · 2021
Closest in time.
Fundamental tradeoffs in distributionally adversarial training
Mohammad Mehrabi, Adel Javanmard, Ryan A. Rossi, Anup B. Rao, and Tung Mai · 2021
Closest in time.
Towards efficient and effective adversarial training
Gaurang Sriramanan, Sravanti Addepalli, Arya Baburaj, and R. Venkatesh Babu · 2021
Closest in time.
Adversarial robustness with semi-infinite constrained learning
Alexander Robey, Luiz F. O. Chamon, George J. Pappas, Hamed Hassani, and Alejandro Ribeiro · 2021
Closest in time.