Fetching the paper…
Reading the bibliography…
Deep neural network (DNN) accelerators received considerable attention in recent years due to the potential to save energy compared to mainstream hardware.
C. Neti, M. H. Schneider, and E. D. Young, “Maximally fault tolerant neural networks,” TNN , vol. 3, no. 1, pp. 14–23, 1992
1992
Earlier work this paper cites.
C. Chiu, K. Mehrotra, C. K. Mohan, and S. Ranka, “Training techniques to obtain fault-tolerant neural networks,” in Annual International Symposium on Fault-Tolerant Computing , 1994
1994
Earlier work this paper cites.
C. Alippi, V. Piuri, and M. Sami, “Sensitivity to errors in artificial neural networks: a behavioral approach,” ISCAS , vol. 6, 1994
1994
Earlier work this paper cites.
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proc. of the IEEE , vol. 86, no. 11, pp. 2278–2324, 1998
1998
Earlier work this paper cites.
D. Deodhare, M. Vidyasagar, and S. S. Keerthi, “Synthesis of fault-tolerant feedforward neural networks using minimax optimization,” TNN , vol. 9, no. 5, pp. 891–900, 1998
1998
Earlier work this paper cites.
S. Cavalieri and O. Mirabella, “A novel learning algorithm which improves the partial fault tolerance of multilayer neural networks,” Neural networks: the official journal of the International Neural Network Society , vol. 12 1, 1999
1999
Earlier work this paper cites.
Z. Guo, A. Carlson, L. Pang, K. Duong, T. K. Liu, and B. Nikolic, “Large-scale SRAM variability characterization in 45 nm CMOS,” JSSC , vol. 44, no. 11, 2009
2009
Earlier work this paper cites.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” Tech. Rep., 2009
2009
Earlier work this paper cites.
A. Leung, H. Wang, and J. Sum, “On the selection of weight decay parameter for faulty networks,” TNN , vol. 21, 2010
2010
Earlier work this paper cites.
2013
Earlier work this paper cites.
Y. Kim, R. Daly, J. Kim, C. Fallin, J. Lee, D. Lee, C. Wilkerson, K. Lai, and O. Mutlu, “Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors,” in ISCA , 2014
2014
Earlier work this paper cites.
F. Seide, H. Fu, J. Droppo, G. Li, and D. Yu, “1-bit stochastic gradient descent and its application to data-parallel distributed training of speech dnns,” in INTERSPEECH , 2014
2014
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in ICLR , 2014
2014
Earlier work this paper cites.
T. Chen, Z. Du, N. Sun, J. Wang, C. Wu, Y. Chen, and O. Temam, “Diannao: a small-footprint high-throughput accelerator for ubiquitous machine-learning,” 2014
2014
Earlier work this paper cites.
M. Lee, K. Hwang, and W. Sung, “Fault tolerance analysis of digital feed-forward deep neural networks,” ICASSP , 2014
2014
Earlier work this paper cites.
Z. Du, K. Palem, L. Avinash, O. Temam, Y. Chen, and C. Wu, “Leveraging the error resilience of machine-learning applications for designing highly energy efficient accelerators,” Asia and South Pacific Design Automation Conference (ASP-DAC) , 2014
2014
Earlier work this paper cites.
N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov, “Dropout: A simple way to prevent neural networks from overfitting,” Journal of Machine Learning Research , vol. 15, no. 56, pp. 1929–1958, 2014
2014
Earlier work this paper cites.
2015
Earlier work this paper cites.
M. Courbariaux, Y. Bengio, and J. David, “Binaryconnect: Training deep neural networks with binary weights during propagations,” in NeurIPS , 2015
2015
Earlier work this paper cites.
S. Ioffe and C. Szegedy, “Batch normalization: Accelerating deep network training by reducing internal covariate shift,” in ICML , 2015
2015
Earlier work this paper cites.
Z. Du, R. Fasthuber, T. Chen, P. Ienne, L. Li, T. Luo, X. Feng, Y. Chen, and O. Temam, “Shidiannao: shifting vision processing closer to the sensor,” in ISCA , 2015
2015
Earlier work this paper cites.
C. Lyu, K. Huang, and H. Liang, “A unified gradient regularization family for adversarial examples,” in ICDM , 2015
2015
Earlier work this paper cites.
J. Deng, Y. Fang, Z. Du, Y. Wang, H. Li, O. Temam, P. Ienne, D. Novo, X. Li, Y. Chen, and C. Wu, “Retraining-based timing error mitigation for hardware neural networks,” in DATE , 2015
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in ICLR , 2015
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Delving deep into rectifiers: Surpassing human-level performance on imagenet classification,” in ICCV , 2015
2015
Earlier work this paper cites.
D. D. Lin, S. S. Talathi, and V. S. Annapureddy, “Fixed point quantization of deep convolutional networks,” in ICML , 2016
2016
Earlier work this paper cites.
B. Reagen, P. N. Whatmough, R. Adolf, S. Rama, H. Lee, S. K. Lee, J. M. Hernández-Lobato, G. Wei, and D. M. Brooks, “Minerva: Enabling low-power, highly-accurate deep neural network accelerators,” in ISCA , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
Y. Chen, J. S. Emer, and V. Sze, “Eyeriss: A spatial architecture for energy-efficient dataflow for convolutional neural networks,” in ISCA , 2016
2016
Earlier work this paper cites.
M. Rastegari, V. Ordonez, J. Redmon, and A. Farhadi, “Xnor-net: Imagenet classification using binary convolutional neural networks,” in ECCV , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
G. Srinivasan, P. Wijesinghe, S. S. Sarwar, A. Jaiswal, and K. Roy, “Significance driven hybrid 8t-6t SRAM for energy-efficient synaptic storage in artificial neural networks,” in DATE , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis, “Wide residual networks,” in BMVC , 2016
2016
Earlier work this paper cites.
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in CVPR , 2016
2016
Earlier work this paper cites.
S. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: A simple and accurate method to fool deep neural networks,” in CVPR , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
N. Papernot, P. D. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in SP , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
N. Papernot, P. D. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in SP , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
V. Sze, Y. Chen, T. Yang, and J. S. Emer, “Efficient processing of deep neural networks: A tutorial and survey,” IEEE , vol. 105, no. 12, 2017
2017
Earlier work this paper cites.
S. Ganapathy, J. Kalamatianos, K. Kasprak, and S. Raasch, “On characterizing near-threshold SRAM failures in FinFET technology,” in DAC , 2017
2017
Earlier work this paper cites.
A. Tang, S. Sethumadhavan, and S. J. Stolfo, “CLKSCREW: exposing the perils of security-oblivious energy management,” in USENIX , 2017
2017
Earlier work this paper cites.
S. Shin, Y. Boo, and W. Sung, “Fixed-point optimization of deep neural networks with adaptive step size retraining,” in ICASSP , 2017
2017
Earlier work this paper cites.
H. Li, S. De, Z. Xu, C. Studer, H. Samet, and T. Goldstein, “Training quantized nets: A deeper understanding,” in NeurIPS , I. Guyon, U. von Luxburg, S. Bengio, H. M. Wallach, R. Fergus, S. V. N. Vishwanathan, and R. Garnett, Eds., 2017
2017
Earlier work this paper cites.
I. Hubara, M. Courbariaux, D. Soudry, R. El-Yaniv, and Y. Bengio, “Quantized neural networks: Training neural networks with low precision weights and activations,” JMLR , vol. 18, 2017
2017
Earlier work this paper cites.
Y. Dong, J. Li, and R. Ni, “Learning accurate low-bit deep neural networks with stochastic quantization,” in BMVC , 2017
2017
Earlier work this paper cites.
I. Gulrajani, F. Ahmed, M. Arjovsky, V. Dumoulin, and A. C. Courville, “Improved training of wasserstein gans,” in NeurIPS , 2017
2017
Earlier work this paper cites.
M. Arjovsky, S. Chintala, and L. Bottou, “Wasserstein generative adversarial networks,” in ICML , 2017
2017
Earlier work this paper cites.
K. K. Chang, A. G. Yaalikçi, S. Ghose, A. Agrawal, N. Chatterjee, A. Kashyap, D. Lee, M. O’Connor, H. Hassan, and O. Mutlu, “Understanding reduced-voltage operation in modern DRAM devices: Experimental characterization, analysis, and mechanisms,” vol. 1, no. 1, 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
T. Yang, Y. Chen, J. S. Emer, and V. Sze, “A method to estimate the energy consumption of deep neural networks,” in ACSSC , 2017
2017
Earlier work this paper cites.
A. Paszke, S. Gross, S. Chintala, G. Chanan, E. Yang, Z. DeVito, Z. Lin, A. Desmaison, L. Antiga, and A. Lerer, “Automatic differentiation in pytorch,” in NeurIPS Workshops , 2017
2017
Earlier work this paper cites.
A. Zhou, A. Yao, Y. Guo, L. Xu, and Y. Chen, “Incremental network quantization: Towards lossless cnns with low-precision weights,” in ICLR , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in SP , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
A. Rozsa, M. Günther, and T. E. Boult, “Adversarial robustness: Softmax versus openmax,” in BMVC , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh, “ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models,” in AISec , 2017
2017
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, “Practical black-box attacks against machine learning,” in AsiaCCS . ACM, 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
X. Li and F. Li, “Adversarial examples detection in deep networks with convolutional filter statistics,” in ICCV , 2017, pp. 5775–5783
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
D. Hendrycks and K. Gimpel, “Early methods for detecting adversarial images,” in ICLR , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
L. Amsaleg, J. Bailey, D. Barbe, S. M. Erfani, M. E. Houle, V. Nguyen, and M. Radovanovic, “The vulnerability of learning to adversarial perturbation increases with intrinsic dimensionality,” in WIFS , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
J. Marques, J. Andrade, and G. Fernandes, “Unreliable memory operation on a convolutional neural network processor,” IEEE International Workshop on Signal Processing Systems (SiPS) , 2017
2017
Cited alongside, same era.
L. Xia, M. Liu, X. Ning, K. Chakrabarty, and Y. Wang, “Fault-tolerant training with on-line fault detection for rram-based neural computing systems,” DAC , 2017
2017
Cited alongside, same era.
C. Torres-Huitzil and B. Girau, “Fault and error tolerance in neural networks: A review,” IEEE Access , vol. 5, 2017
2017
Cited alongside, same era.
L. Dinh, R. Pascanu, S. Bengio, and Y. Bengio, “Sharp minima can generalize for deep nets,” in ICML , 2017
2017
Cited alongside, same era.
S. Kim, P. Howe, T. Moreau, A. Alaghi, L. Ceze, and V. Sathe, “MATIC: learning around errors for efficient low-voltage neural network accelerators,” in DATE , 2018
A. Demontis, M. Melis, M. Pintor, M. Jagielski, B. Biggio, A. Oprea, C. Nita-Rotaru, and F. Roli, “Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks,” in USENIX , 2019
2019
Later among the works it cites.
J. Li, F. R. Schmidt, and J. Z. Kolter, “Adversarial camera stickers: A physical camera-based attack on deep learning systems,” in ICML , 2019
2019
Later among the works it cites.
E. B. Khalil, A. Gupta, and B. Dilkina, “Combinatorial attacks on binarized neural networks,” in ICLR , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
B. Zhuang, C. Shen, M. Tan, L. Liu, and I. D. Reid, “Towards effective low-bitwidth convolutional neural networks,” in CVPR , 2018
2018
Cited alongside, same era.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” ICLR , 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
B. Jacob, S. Kligys, B. Chen, M. Zhu, M. Tang, A. G. Howard, H. Adam, and D. Kalenichenko, “Quantization and training of neural networks for efficient integer-arithmetic-only inference,” in CVPR , 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
L. Hou and J. T. Kwok, “Loss-aware weight quantization of deep networks,” in ICLR , 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
S. Miyazato, X. Wang, T. Yamasaki, and K. Aizawa, “Reinforcing the robustness of a deep neural network to adversarial examples by using color quantization of training image data,” in ICIP , 2019
2019
Later among the works it cites.
K. Roth, Y. Kilcher, and T. Hofmann, “The odds are odd: A statistical test for detecting adversarial examples,” in ICML , 2019, pp. 5498–5507
2019
Later among the works it cites.
J. Liu, W. Zhang, Y. Zhang, D. Hou, Y. Liu, H. Zha, and N. Yu, “Detection based defense against adversarial examples from the steganalysis point of view,” in CVPR , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
D. Stutz, M. Hein, and B. Schiele, “Disentangling adversarial robustness and generalization,” CVPR , 2019
2019
Later among the works it cites.
Y. Carmon, A. Raghunathan, L. Schmidt, J. C. Duchi, and P. Liang, “Unlabeled data improves adversarial robustness,” in NeurIPS , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
H. Zhang and J. Wang, “Defense against adversarial attacks using feature scattering-based adversarial training,” in NeurIPS , 2019
2019
Later among the works it cites.
A. S. Rakin, Z. He, and D. Fan, “Parametric noise injection: Trainable randomness to improve deep neural network robustness against adversarial attack,” CVPR , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
N. Mu and J. Gilmer, “Mnist-c: A robustness benchmark for computer vision,” ICML Workshops , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
R. G. Lopes, D. Yin, B. Poole, J. Gilmer, and E. D. Cubuk, “Improving robustness without sacrificing accuracy with patch gaussian augmentation,” in ICML Workshops , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
M. Klachko, M. R. Mahmoodi, and D. B. Strukov, “Improving noise tolerance of mixed-signal neural networks,” in IJCNN , 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
2019
Later among the works it cites.
M. Nagel, M. van Baalen, T. Blankevoort, and M. Welling, “Data-free quantization through weight equalization and bias correction,” in ICCV , 2019
2019
Later among the works it cites.
K. Murdock, D. Oswald, F. D. Garcia, J. Van Bulck, D. Gruss, and F. Piessens, “Plundervolt: Software-based fault injection attacks against intel sgx,” in SP , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
Z. He, A. S. Rakin, J. Li, C. Chakrabarti, and D. Fan, “Defending and harnessing the bit-flip based adversarial weight attack,” in CVPR , 2020
2020
Later among the works it cites.
D. Stutz, M. Hein, and B. Schiele, “Confidence-calibrated adversarial training: Generalizing to unseen attacks,” in ICML , 2020
2020
Later among the works it cites.
M. Alizadeh, A. Behboodi, M. van Baalen, C. Louizos, T. Blankevoort, and M. Welling, “Gradient ℓ 1 \ell_{1} regularization for quantization robustness,” in ICLR , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
T.-W. Weng, P. Zhao, S. Liu, P.-Y. Chen, X. Lin, and L. Daniel, “Towards certificated model robustness against weight perturbations,” in AAAI , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
F. Croce and M. Hein, “Minimally distorted adversarial examples with a fast adaptive boundary attack,” in ICML , 2020
2020
Later among the works it cites.
J. Li, R. Ji, H. Liu, J. Liu, B. Zhong, C. Deng, and Q. Tian, “Projection & probability-driven black-box attack,” in CVPR , 2020
2020
Later among the works it cites.
Y. Shi, Y. Han, and Q. Tian, “Polishing decision-based adversarial noise with a customized sampling,” in CVPR , 2020
2020
Later among the works it cites.
J. Chen, M. I. Jordan, and M. J. Wainwright, “Hopskipjumpattack: A query-efficient decision-based attack,” in SP , 2020
2020
Later among the works it cites.
P. Zhao, P. Chen, S. Wang, and X. Lin, “Towards query-efficient black-box adversary with zeroth-order natural gradient descent,” in AAAI , 2020
2020
Later among the works it cites.
J. Chen and Q. Gu, “Rays: A ray searching method for hard-label adversarial attack,” in KDD , 2020
2020
Later among the works it cites.
A. Al-Dujaili and U. O’Reilly, “Sign bits are all you need for black-box attacks,” in ICLR , 2020
2020
Later among the works it cites.
M. Cheng, S. Singh, P. H. Chen, P. Chen, S. Liu, and C. Hsieh, “Sign-opt: A query-efficient hard-label adversarial attack,” in ICLR , 2020
2020
Later among the works it cites.
W. Chen, Z. Zhang, X. Hu, and B. Wu, “Boosting decision-based black-box adversarial attacks with random sign flip,” in ECCV , 2020
2020
Later among the works it cites.
F. Suya, J. Chi, D. Evans, and Y. Tian, “Hybrid batch attacks: Finding black-box adversarial examples with limited queries,” in USENIX , 2020
2020
Later among the works it cites.
K. Xu, G. Zhang, S. Liu, Q. Fan, M. Sun, H. Chen, P.-Y. Chen, Y. Wang, and X. Lin, “Adversarial t-shirt! evading person detectors in a physical world.” in ECCV , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
S. Shan, E. Wenger, B. Wang, B. Li, H. Zheng, and B. Y. Zhao, “Gotta catch’em all: Using honeypots to catch adversarial attacks on neural networks,” in CCS , 2020
2020
Later among the works it cites.
P. Sperl, C. Kao, P. Chen, X. Lei, and K. Böttinger, “DLA: dense-layer-analysis for adversarial example detection,” 2020
2020
Later among the works it cites.
G. Cohen, G. Sapiro, and R. Giryes, “Detecting adversarial samples using influence functions and nearest neighbors,” in CVPR , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
T. Pang, X. Yang, Y. Dong, T. Xu, J. Zhu, and H. Su, “Boosting adversarial training with hypersphere embedding,” in NeurIPS , 2020
2020
Later among the works it cites.
W. Wag, J. Chen, and M.-H. Yang, “Adversarial training with bi-directional likelihood regularization for visual classification,” in ECCV , 2020
2020
Later among the works it cites.
A. Bui, T. Le, H. Zhao, P. Montague, O. deVel, T. Abraham, and D. Q. Phung, “Improving adversarial robustness by enforcing local and global compactness,” in ECCV , 2020
2020
Later among the works it cites.
H. Wang, T. Chen, S. Gui, T. Hu, J. Liu, and Z. Wang, “Once-for-all adversarial training: In-situ tradeoff between robustness and accuracy for free,” in NeurIPS , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
L.-H. Hoang, M. Hanif, and M. Shafique, “Ft-clipact: Resilience analysis of deep neural networks and improving their fault tolerance using clipped activation,” DATE , 2020
2020
Later among the works it cites.
D. Stutz, N. Chandramoorthy, M. Hein, and B. Schiele, “Bit error robustness for energy-efficient dnn accelerators,” in MLSys , 2021
2021
Closest in time.
P. Stock, A. Fan, B. Graham, E. Grave, R. Gribonval, H. Jégou, and A. Joulin, “Training with quantization noise for extreme model compression,” in ICLR , 2021
2021
Closest in time.
C. Baskin, N. Liss, E. Schwartz, E. Zheltonozhskii, R. Giryes, A. M. Bronstein, and A. Mendelson, “UNIQ: uniform noise injection for non-uniform quantization of neural networks,” ACM Transactions on Computer Systems , vol. 37, no. 1-4, pp. 4:1–4:15, 2021
2021
Closest in time.
S. Buschjäger, J. Chen, K. Chen, M. Günzel, C. Hakert, K. Morik, R. Novkin, L. Pfahler, and M. Yayla, “Margin-maximization in binarized neural networks for optimizing bit error tolerance,” in DATE . IEEE, 2021
2021
Closest in time.
J. Rony, E. Granger, M. Pedersoli, and I. B. Ayed, “Augmented lagrangian adversarial attacks,” in ICCV , 2021
2021
Closest in time.
J. Li, R. Ji, P. Chen, B. Zhang, X. Hong, R. Zhang, S. Li, J. Li, F. Huang, and Y. Wu, “Aha! adaptive history-driven attack for decision-based black-box models,” in ICCV , 2021
2021
Closest in time.
S. N. Shukla, A. K. Sahu, D. Willmott, and J. Z. Kolter, “Simple and efficient hard label black-box adversarial attacks in low query budget regimes,” in KDD , 2021
2021
Closest in time.
T. Maho, T. Furon, and E. L. Merrer, “Surfree: A fast surrogate-free black-box attack,” in CVPR , 2021
2021
Closest in time.
Y. Dong, S. Cheng, T. Pang, H. Su, and J. Zhu, “Query-efficient black-box adversarial attacks guided by a transfer-based prior,” PAMI , 2021
2021
Closest in time.
2021
Closest in time.
J. Tian, J. Zhou, Y. Li, and J. Duan, “Detecting adversarial examples from sensitivity inconsistency of spatial-transform domain,” in AAAI , 2021
2021
Closest in time.
Y. Li, M. R. Min, T. Lee, W. Yu, E. Kruus, W. Wang, and C.-J. Hsieh, “Towards robustness of deep neural networks via regularization,” in ICCV , 2021
2021
Closest in time.
B. Zi, S. Zhao, X. Ma, and Y. Jiang, “Revisiting adversarial robustness distillation: Robust soft labels make student better,” in ICCV , 2021
2021
Closest in time.