Fetching the paper…
Reading the bibliography…
Recently, adversarial attack methods have been developed to challenge the robustness of machine learning models.
Imagenet: A large-scale hierarchical image database
Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., and Fei-Fei, L · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A. and Hinton, G · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Adversarial manipulation of deep representations
Sabour, S., Cao, Y., Faghri, F., and Fleet, D. J · 2015
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Moosavi-Dezfooli, S.-M., Fawzi, A., and Frossard, P · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A · 2016
Earlier work this paper cites.
Adversarial diversity and hard positive generation
Rozsa, A., Rudd, E. M., and Boult, T. E · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction apis
Tramèr, F., Zhang, F., Juels, A., Reiter, M. K., and Ristenpart, T · 2016
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., and Hsieh, C.-J · 2017
Earlier work this paper cites.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2017
Earlier work this paper cites.
Universal adversarial perturbations
Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., and Frossard, P · 2017
Cited alongside, same era.
Fast feature fool: A data independent approach to universal adversarial perturbations
Mopuri, K. R., Garg, U., and Babu, R. V · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
Query-efficient hard-label black-box attack: An optimization-based approach
Cheng, M., Le, T., Chen, P.-Y., Yi, J., Zhang, H., and Hsieh, C.-J · 2018
Cited alongside, same era.
Learning universal adversarial perturbations with generative models
Hayes, J. and Danezis, G · 2018
Cited alongside, same era.
Simple black-box adversarial attacks
Guo, C., Gardner, J., You, Y., Wilson, A. G., and Weinberger, K · 2019
Later among the works it cites.
Prior convictions: Black-box adversarial attacks with bandits and priors
Ilyas, A., Engstrom, L., and Madry, A · 2019
Later among the works it cites.
Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks
Li, Y., Li, L., Wang, L., Zhang, T., and Gong, B · 2019
Later among the works it cites.
Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses
Rony, J., Hafemann, L. G., Oliveira, L. S., Ayed, I. B., Sabourin, R., and Granger, E · 2019
Later among the works it cites.
One pixel attack for fooling deep neural networks
Su, J., Vargas, D. V., and Sakurai, K · 2019
Later among the works it cites.
Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Art of singular vectors and universal adversarial perturbations
Khrulkov, V. and Oseledets, I · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Adversarial robustness toolbox v1. 0.0
Nicolae, M.-I., Sinn, M., Tran, M. N., Buesser, B., Rawat, A., Wistuba, M., Zantedeschi, V., Baracaldo, N., Chen, B., Ludwig, H., et al · 2018
Cited alongside, same era.
Generative adversarial perturbations
Poursaeed, O., Katsman, I., Gao, B., and Belongie, S · 2018
Cited alongside, same era.
Accurate, reliable and fast robustness evaluation
Brendel, W., Rauber, J., Kümmerer, M., Ustyuzhaninov, I., and Bethge, M · 2019
Cited alongside, same era.
Sign-opt: A query-efficient hard-label adversarial attack
Cheng, M., Singh, S., Chen, P., Chen, P.-Y., Liu, S., and Hsieh, C.-J · 2019
Cited alongside, same era.
Advertorch v0. 1: An adversarial robustness toolbox based on pytorch
Ding, G. W., Wang, L., and Jin, X · 2019
Cited alongside, same era.
Tu, C.-C., Ting, P., Chen, P.-Y., Liu, S., Zhang, H., Yi, J., Hsieh, C.-J., and Cheng, S.-M · 2019
Later among the works it cites.
Square attack: a query-efficient black-box adversarial attack via random search
Andriushchenko, M., Croce, F., Flammarion, N., and Hein, M · 2020
Later among the works it cites.
Rays: A ray searching method for hard-label adversarial attack
Chen, J. and Gu, Q · 2020
Later among the works it cites.
Simple iterative method for generating targeted universal adversarial perturbations
Hirano, H. and Takemoto, K · 2020
Later among the works it cites.
Foolbox native: Fast adversarial attacks to benchmark the robustness of machine learning models in pytorch, tensorflow, and jax
Rauber, J., Zimmermann, R., Bethge, M., and Brendel, W · 2020
Later among the works it cites.
Decision-based universal adversarial attack
Wu, J., Zhou, M., Liu, S., Liu, Y., and Zhu, C · 2020
Later among the works it cites.
Dast: Data-free substitute training for adversarial attacks
Zhou, M., Wu, J., Liu, Y., Liu, S., and Zhu, C · 2020
Later among the works it cites.