Fetching the paper…
Reading the bibliography…
Adversarial examples mainly exploit changes to input pixels to which humans are not sensitive to, and arise from the fact that models make decisions based on uninterpretable features.
P. G. Schyns and A. Oliva, “From blobs to boundary edges: Evidence for time-and spatial-scale-dependent scene recognition,”
1994
Earlier work this paper cites.
R. M. French, M. Mermillod, A. Chauvin, P. C. Quinn, and D. Mareschal, “The importance of starting blurry: Simulating improved basic-level category learning in infants due to weak visual acuity,” in
2002
Earlier work this paper cites.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” tech. rep., University of Toronto, 2009
2009
Earlier work this paper cites.
M. Mermillod, P. Bonin, L. Mondillon, D. Alleysson, and N. Vermeulen, “Coarse scales are sufficient for efficient categorization of emotional facial expressions: Evidence from neural computation,”
2010
Earlier work this paper cites.
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng, “Reading digits in natural images with unsupervised feature learning,” in
2011
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in
2014
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in
2015
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis, “Wide residual networks,” in
2016
Earlier work this paper cites.
J. Jo and Y. Bengio, “Measuring the tendency of cnns to learn surface statistical regularities,”
2017
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in
2018
Earlier work this paper cites.
N. Das, M. Shanbhogue, S.-T. Chen, F. Hohman, S. Li, L. Chen, M. E. Kounavis, and D. H. Chau, “Shield: Fast, practical defense and vaccination for deep learning using jpeg compression,”
2018
Earlier work this paper cites.
M. Sandler, A. Howard, M. Zhu, A. Zhmoginov, and L.-C. Chen, “Mobilenetv2: Inverted residuals and linear bottlenecks,”
2018
Cited alongside, same era.
A. Ilyas, S. Santurkar, D. Tsipras, L. Engstrom, B. Tran, and A. Madry, “Adversarial examples are not bugs, they are features,” in
2019
Cited alongside, same era.
D. Yin, R. Gontijo Lopes, J. Shlens, E. D. Cubuk, and J. Gilmer, “A fourier perspective on model robustness in computer vision,” in
2019
Cited alongside, same era.
H. Zhang, Y. Yu, J. Jiao, E. P. Xing, L. E. Ghaoui, and M. I. Jordan, “Theoretically principled trade-off between robustness and accuracy,” in
2019
Cited alongside, same era.
D. Hendrycks, K. Lee, and M. Mazeika, “Using pre-training can improve model robustness and uncertainty,” in
2019
Cited alongside, same era.
Z. Zhang, C. Jung, and X. Liang, “Adversarial defense by suppressing high-frequency components,”
2019
Later among the works it cites.
R. Geirhos, P. Rubisch, C. Michaelis, M. Bethge, F. A. Wichmann, and W. Brendel, “Imagenet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness.,” in
2019
Later among the works it cites.
Y. Sharma, G. W. Ding, and M. A. Brubaker, “On the effectiveness of low frequency perturbations,”
2019
Later among the works it cites.
C. Xie, Z. Zhang, J. Wang, Y. Zhou, Z. Ren, and A. L. Yuille, “Improving transferability of adversarial examples with input diversity,” in
2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
J. M. Cohen, E. Rosenfeld, and J. Z. Kolter, “Certified adversarial robustness via randomized smoothing,” in
2019
Cited alongside, same era.
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry, “Robustness may be at odds with accuracy,” in
2019
Cited alongside, same era.
C. Etmann, S. Lunz, P. Maass, and C. Schoenlieb, “On the connection between adversarial robustness and saliency map interpretability,” in
2019
Cited alongside, same era.
S. Kaur, J. Cohen, and Z. C. Lipton, “Are perceptually-aligned gradients a general property of robust classifiers?,” in
2019
Cited alongside, same era.
T. Zhang and Z. Zhu, “Interpreting adversarially trained convolutional neural networks,” in
2019
Cited alongside, same era.
Z. Liu, Q. Liu, T. Liu, N. Xu, X. Lin, Y. Wang, and W. Wen, “Feature distillation: Dnn-oriented jpeg compression against adversarial examples,” in
2019
Cited alongside, same era.
2019
Later among the works it cites.
A. Chan, Y. Tay, Y. S. Ong, and J. Fu, “Jacobian adversarially regularized networks for robustness,” in
2020
Later among the works it cites.
S. Addepalli, B. Vivek, A. Baburaj, G. Sriramanan, and R. Venkatesh Babu, “Towards achieving adversarial robustness by enforcing feature consistency across bit planes,”
2020
Later among the works it cites.
H. Wang, X. Wu, Z. Huang, and E. P. Xing, “High-frequency component helps explain the generalization of convolutional neural networks,” in
2020
Later among the works it cites.
2020
Later among the works it cites.
L. Rice, E. Wong, and J. Z. Kolter, “Overfitting in adversarially robust deep learning,” in
2020
Later among the works it cites.