Fetching the paper…
Reading the bibliography…
Deep Learning (DL) is the most widely used tool in the contemporary field of computer vision.
S. Zulqarnain Gilani and A. Mian, “Learning from millions of 3d scans for large-scale 3d face recognition,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2018, pp. 1896–1905
1905
Earlier work this paper cites.
X. Wang and K. He, “Enhancing the transferability of adversarial attacks through variance tuning,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 1924–1933
1933
Earlier work this paper cites.
J. F. Nash et al. , “Equilibrium points in n-person games,” Proceedings of the national academy of sciences , vol. 36, no. 1, pp. 48–49, 1950
1950
Earlier work this paper cites.
H. Zhou, K. Chen, W. Zhang, H. Fang, W. Zhou, and N. Yu, “Dup-net: Denoiser and upsampler network for 3d adversarial point clouds defense,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2019, pp. 1961–1970
1970
Earlier work this paper cites.
Y. Nesterov, “A method for unconstrained convex minimization problem with the rate of convergence o (1/kˆ 2),” in Doklady an ussr , vol. 269, 1983, pp. 543–547
1983
Earlier work this paper cites.
A. Dabouei, S. Soleymani, J. Dawson, and N. Nasrabadi, “Fast geometrically-perturbed adversarial faces,” in 2019 IEEE Winter Conference on Applications of Computer Vision (WACV) . IEEE, 2019, pp. 1979–1988
1988
Earlier work this paper cites.
Y. LeCun, B. Boser, J. S. Denker, D. Henderson, R. E. Howard, W. Hubbard, and L. D. Jackel, “Backpropagation applied to handwritten zip code recognition,” Neural computation , vol. 1, no. 4, pp. 541–551, 1989
1989
Earlier work this paper cites.
D. L. Ruderman, T. W. Cronin, and C.-C. Chiao, “Statistics of cone responses to natural images: implications for visual coding,” JOSA A , vol. 15, no. 8, pp. 2036–2045, 1998
1998
Earlier work this paper cites.
C. Manning and H. Schutze, Foundations of statistical natural language processing . MIT press, 1999
1999
Earlier work this paper cites.
A. R. Conn, N. I. Gould, and P. L. Toint, Trust region methods . SIAM, 2000
2000
Earlier work this paper cites.
M. R. Luo, G. Cui, and B. Rigg, “The development of the cie 2000 colour-difference formula: Ciede2000,” Color Research & Application: Endorsed by Inter-Society Color Council, The Colour Group (Great Britain), Canadian Society for Color, Color Science Association of Japan, Dutch Society for the Study of Color, The Swedish Colour Centre Foundation, Colour Society of Australia, Centre Français de la Couleur , vol. 26, no. 5, pp. 340–350, 2001
2001
Earlier work this paper cites.
N. Hansen and A. Ostermeier, “Completely derandomized self-adaptation in evolution strategies,” Evolutionary computation , vol. 9, no. 2, pp. 159–195, 2001
2001
Earlier work this paper cites.
G. Hickok and D. Poeppel, “The cortical organization of speech processing,” Nature reviews neuroscience , vol. 8, no. 5, pp. 393–402, 2007
2007
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in 2009 IEEE conference on computer vision and pattern recognition . Ieee, 2009, pp. 248–255
2009
Earlier work this paper cites.
S. Das and P. N. Suganthan, “Differential evolution: A survey of the state-of-the-art,” IEEE transactions on evolutionary computation , vol. 15, no. 1, pp. 4–31, 2010
2010
Earlier work this paper cites.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” in Advances in neural information processing systems , 2012, pp. 1097–1105
2012
Earlier work this paper cites.
2013
Earlier work this paper cites.
M. Helmstaedter, K. L. Briggman, S. C. Turaga, V. Jain, H. S. Seung, and W. Denk, “Connectomic reconstruction of the inner plexiform layer in the mouse retina,” Nature , vol. 500, no. 7461, pp. 168–174, 2013
2013
Earlier work this paper cites.
R. Fletcher, Practical methods of optimization . John Wiley & Sons, 2013
2013
Earlier work this paper cites.
2013
Earlier work this paper cites.
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
M. Fredrikson, E. Lantz, S. Jha, S. Lin, D. Page, and T. Ristenpart, “Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing,” in 23rd { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 14) , 2014, pp. 17–32
2014
Earlier work this paper cites.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” nature , vol. 521, no. 7553, pp. 436–444, 2015
2015
Earlier work this paper cites.
H. Y. Xiong, B. Alipanahi, L. J. Lee, H. Bretschneider, D. Merico, R. K. Yuen, Y. Hua, S. Gueroussov, H. S. Najafabadi, T. R. Hughes et al. , “The human splicing code reveals new insights into the genetic determinants of disease,” Science , vol. 347, no. 6218, 2015
2015
Earlier work this paper cites.
C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich, “Going deeper with convolutions,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2015, pp. 1–9
2015
Earlier work this paper cites.
M. M. Najafabadi, F. Villanustre, T. M. Khoshgoftaar, N. Seliya, R. Wald, and E. Muharemagic, “Deep learning applications and challenges in big data analytics,” Journal of Big Data , vol. 2, no. 1, p. 1, 2015
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
O. Vinyals, A. Toshev, S. Bengio, and D. Erhan, “Show and tell: A neural image caption generator,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2015, pp. 3156–3164
2015
Earlier work this paper cites.
O. M. Parkhi, A. Vedaldi, and A. Zisserman, “Deep face recognition,” in Proceedings of the British Machine Vision Conference (BMVC) . BMVA Press, September 2015, pp. 41.1–41.12
2015
Earlier work this paper cites.
F. Schroff, D. Kalenichenko, and J. Philbin, “Facenet: A unified embedding for face recognition and clustering,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2015, pp. 815–823
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 770–778
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
A. Rozsa, E. M. Rudd, and T. E. Boult, “Adversarial diversity and hard positive generation,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops , 2016, pp. 25–32
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 2818–2826
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in 2016 IEEE European symposium on security and privacy (EuroS&P) . IEEE, 2016, pp. 372–387
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: a simple and accurate method to fool deep neural networks,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 2574–2582
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in 2016 IEEE Symposium on Security and Privacy (SP) . IEEE, 2016, pp. 582–597
2016
Earlier work this paper cites.
X. Wu, M. Fredrikson, S. Jha, and J. F. Naughton, “A methodology for formalizing model-inversion attacks,” in 2016 IEEE 29th Computer Security Foundations Symposium (CSF) . IEEE, 2016, pp. 355–370
2016
Earlier work this paper cites.
A. Nguyen, A. Dosovitskiy, J. Yosinski, T. Brox, and J. Clune, “Synthesizing the preferred inputs for neurons in neural networks via deep generator networks,” Advances in neural information processing systems , vol. 29, pp. 3387–3395, 2016
2016
Earlier work this paper cites.
K. Razavi, B. Gras, E. Bosman, B. Preneel, C. Giuffrida, and H. Bos, “Flip feng shui: Hammering a needle in the software stack,” in 25th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 16) , 2016, pp. 1–18
2016
Earlier work this paper cites.
B. Amos, B. Ludwiczuk, J. Harkes, P. Pillai, K. Elgazzar, and M. Satyanarayanan, “Openface: Face recognition with deep neural networks,” in IEEE Winter Conference on Applications of Computer Vision , vol. 1, no. 2, 2016, p. 6
2016
Earlier work this paper cites.
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition,” in Proceedings of the 2016 acm sigsac conference on computer and communications security , 2016, pp. 1528–1540
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
D. Krotov and J. J. Hopfield, “Dense associative memory for pattern recognition,” Advances in neural information processing systems , vol. 29, pp. 1172–1180, 2016
2016
Earlier work this paper cites.
A. Rozsa, M. Günther, and T. E. Boult, “Are accuracy and robustness correlated,” in 2016 15th IEEE international conference on machine learning and applications (ICMLA) . IEEE, 2016, pp. 227–232
2016
Earlier work this paper cites.
P. Tabacof and E. Valle, “Exploring the space of adversarial images,” in 2016 International Joint Conference on Neural Networks (IJCNN) . IEEE, 2016, pp. 426–433
2016
Earlier work this paper cites.
G. Huang, Z. Liu, L. Van Der Maaten, and K. Q. Weinberger, “Densely connected convolutional networks,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2017, pp. 4700–4708
2017
Earlier work this paper cites.
D. Silver, J. Schrittwieser, K. Simonyan, I. Antonoglou, A. Huang, A. Guez, T. Hubert, L. Baker, M. Lai, A. Bolton et al. , “Mastering the game of go without human knowledge,” nature , vol. 550, no. 7676, pp. 354–359, 2017
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2017, pp. 1765–1773
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) . IEEE, 2017, pp. 39–57
2017
Earlier work this paper cites.
——, “Adversarial examples are not easily detected: Bypassing ten detection methods,” in Proceedings of the 10th ACM workshop on artificial intelligence and security , 2017, pp. 3–14
2017
Earlier work this paper cites.
R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, and D. Batra, “Grad-cam: Visual explanations from deep networks via gradient-based localization,” in Proceedings of the IEEE international conference on computer vision , 2017, pp. 618–626
2017
Earlier work this paper cites.
V. Smith, C.-K. Chiang, M. Sanjabi, and A. S. Talwalkar, “Federated multi-task learning,” in Advances in neural information processing systems , 2017, pp. 4424–4434
2017
Earlier work this paper cites.
J. Redmon and A. Farhadi, “Yolo9000: better, faster, stronger,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2017, pp. 7263–7271
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
V. Behzadan and A. Munir, “Vulnerability of deep reinforcement learning to policy induction attacks,” in International Conference on Machine Learning and Data Mining in Pattern Recognition . Springer, 2017, pp. 262–275
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
J. Liu, W. Niu, J. Liu, J. Zhao, T. Chen, Y. Yang, Y. Xiang, and L. Han, “A method to effectively detect vulnerabilities on path planning of vin,” in International Conference on Information and Communications Security . Springer, 2017, pp. 374–384
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
S. Sabour, N. Frosst, and G. E. Hinton, “Dynamic routing between capsules,” in Advances in neural information processing systems , 2017, pp. 3856–3866
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
G. Katz, C. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer, “Reluplex: An efficient smt solver for verifying deep neural networks,” in International Conference on Computer Aided Verification . Springer, 2017, pp. 97–117
2017
Earlier work this paper cites.
M. Hein and M. Andriushchenko, “Formal guarantees on the robustness of a classifier against adversarial manipulation,” in Advances in Neural Information Processing Systems , 2017, pp. 2266–2276
2017
Earlier work this paper cites.
X. Cao and N. Z. Gong, “Mitigating evasion attacks to deep neural networks via region-based classification,” in Proceedings of the 33rd Annual Computer Security Applications Conference , 2017, pp. 278–287
2017
Earlier work this paper cites.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” 2017
2017
Earlier work this paper cites.
N. Akhtar and A. Mian, “Threat of adversarial attacks on deep learning in computer vision: A survey,” IEEE Access , vol. 6, pp. 14 410–14 430, 2018
2018
Earlier work this paper cites.
I. Masi, Y. Wu, T. Hassner, and P. Natarajan, “Deep face recognition: A survey,” in 2018 31st SIBGRAPI conference on graphics, patterns and images (SIBGRAPI) . IEEE, 2018, pp. 471–478
2018
Earlier work this paper cites.
N. Sünderhauf, O. Brock, W. Scheirer, R. Hadsell, D. Fox, J. Leitner, B. Upcroft, P. Abbeel, W. Burgard, M. Milford et al. , “The limits and potentials of deep learning for robotics,” The International Journal of Robotics Research , vol. 37, no. 4-5, pp. 405–420, 2018
2018
Earlier work this paper cites.
A. Arnab, O. Miksik, and P. H. Torr, “On the robustness of semantic segmentation models to adversarial attacks,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2018, pp. 888–897
2018
Earlier work this paper cites.
W. Zhou, X. Hou, Y. Chen, M. Tang, X. Huang, X. Gan, and Y. Yang, “Transferable adversarial perturbations,” in Proceedings of the European Conference on Computer Vision (ECCV) , 2018, pp. 452–467
2018
Earlier work this paper cites.
M. Ozdag, “Adversarial attacks and defenses against deep neural networks: a survey,” Procedia Computer Science , vol. 140, pp. 152–161, 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Y. Song, R. Shu, N. Kushman, and S. Ermon, “Constructing unrestricted adversarial examples with generative models,” in Advances in Neural Information Processing Systems , 2018, pp. 8312–8323
2018
Earlier work this paper cites.
T. Miyato, S.-i. Maeda, M. Koyama, and S. Ishii, “Virtual adversarial training: a regularization method for supervised and semi-supervised learning,” IEEE transactions on pattern analysis and machine intelligence , vol. 41, no. 8, pp. 1979–1993, 2018
2018
Earlier work this paper cites.
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li, “Boosting adversarial attacks with momentum,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2018, pp. 9185–9193
2018
Earlier work this paper cites.
W. Brendel, J. Rauber, and M. Bethge, “Decision-based adversarial attacks: Reliable attacks against black-box machine learning models,” ICLR , 2018
2018
Earlier work this paper cites.
N. Akhtar and A. Mian, “Hyperspectral recovery from rgb images using gaussian processes,” IEEE transactions on pattern analysis and machine intelligence , vol. 42, no. 1, pp. 100–113, 2018
2018
Earlier work this paper cites.
M. Sharif, L. Bauer, and M. K. Reiter, “On the suitability of lp-norms for creating and preventing adversarial examples,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops , 2018, pp. 1605–1613
2018
Earlier work this paper cites.
H. Hosseini and R. Poovendran, “Semantic adversarial examples,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops , 2018, pp. 1614–1619
2018
Earlier work this paper cites.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust physical-world attacks on deep learning visual classification,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2018, pp. 1625–1634
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy risk in machine learning: Analyzing the connection to overfitting,” in 2018 IEEE 31st Computer Security Foundations Symposium (CSF) . IEEE, 2018, pp. 268–282
2018
Earlier work this paper cites.
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” ICML , 2018
2018
Earlier work this paper cites.
M. Bafna, J. Murtagh, and N. Vyas, “Thwarting adversarial examples: An l _ 0 l\_0 -robustsparse fourier transform,” NeurIPS , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Z. Zhong, W. Xu, Y. Jia, and T. Wei, “Perception deception: Physical adversarial attack challenges and tactics for dnn-based object detection,” Black Hat Europe , 2018
2018
Earlier work this paper cites.
Y. Xiang, W. Niu, J. Liu, T. Chen, and Z. Han, “A pca-based model to predict adversarial examples on q-learning of path finding,” in 2018 IEEE Third International Conference on Data Science in Cyberspace (DSC) . IEEE, 2018, pp. 773–780
2018
Earlier work this paper cites.
X. Bai, W. Niu, J. Liu, X. Gao, Y. Xiang, and J. Liu, “Adversarial examples construction towards white-box q table variation in dqn pathfinding training,” in 2018 IEEE Third International Conference on Data Science in Cyberspace (DSC) . IEEE, 2018, pp. 781–787
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
X. Xu, X. Chen, C. Liu, A. Rohrbach, T. Darrell, and D. Song, “Fooling vision and language models despite localization and attention mechanism,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2018, pp. 4951–4961
2018
Earlier work this paper cites.
G. Goswami, N. Ratha, A. Agarwal, R. Singh, and M. Vatsa, “Unravelling robustness of deep learning based face recognition against adversarial attacks,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 32, no. 1, 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
S. Qiao, W. Shen, Z. Zhang, B. Wang, and A. Yuille, “Deep co-training for semi-supervised image recognition,” in Proceedings of the european conference on computer vision (eccv) , 2018, pp. 135–152
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
D. Krotov and J. Hopfield, “Dense associative memory is robust to adversarial inputs,” Neural computation , vol. 30, no. 12, pp. 3151–3167, 2018
2018
Earlier work this paper cites.
E. D. Cubuk, B. Zoph, S. S. Schoenholz, and Q. V. Le, “Intriguing properties of adversarial examples,” ICLR , 2018
2018
Earlier work this paper cites.
A. Rozsa, M. Gunther, and T. E. Boult, “Towards robust deep neural networks with bang,” WACV , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
D. Su, H. Zhang, H. Chen, J. Yi, P.-Y. Chen, and Y. Gao, “Is robustness the cost of accuracy?–a comprehensive study on the robustness of 18 deep image classification models,” in Proceedings of the European Conference on Computer Vision (ECCV) , 2018, pp. 631–648
2018
Earlier work this paper cites.
——, “Robustness of classifiers to universal perturbations: A geometric perspective,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
S. Jetley, N. Lord, and P. Torr, “With friends like these, who needs adversaries?” in Advances in neural information processing systems , 2018, pp. 10 749–10 759
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
X. Liu, M. Cheng, H. Zhang, and C.-J. Hsieh, “Towards robust neural networks via random self-ensemble,” in Proceedings of the European Conference on Computer Vision (ECCV) , 2018, pp. 369–385
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
C. Guo, M. Rana, M. Cisse, and L. Van Der Maaten, “Countering adversarial images using input transformations,” ICLR , 2018
2018
Earlier work this paper cites.
P. Samangouei, M. Kabkab, and R. Chellappa, “Defense-gan: Protecting classifiers against adversarial attacks using generative models,” ICLR , 2018
2018
Earlier work this paper cites.
A. Raghunathan, J. Steinhardt, and P. Liang, “Certified defenses against adversarial examples,” ICLR , 2018
2018
Earlier work this paper cites.
E. Wong and Z. Kolter, “Provable defenses against adversarial examples via the convex outer adversarial polytope,” in International Conference on Machine Learning . PMLR, 2018, pp. 5286–5295
2018
Earlier work this paper cites.
M. Mirman, T. Gehr, and M. Vechev, “Differentiable abstract interpretation for provably robust neural networks,” in International Conference on Machine Learning , 2018, pp. 3578–3586
2018
Earlier work this paper cites.
N. Akhtar, J. Liu, and A. Mian, “Defense against universal adversarial perturbations,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2018, pp. 3389–3398
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
M. Amodio, D. Van Dijk, K. Srinivasan, W. S. Chen, H. Mohsen, K. R. Moon, A. Campbell, Y. Zhao, X. Wang, M. Venkataswamy et al. , “Exploring single-cell data with deep multitasking neural networks,” Nature methods , pp. 1–7, 2019
2019
Earlier work this paper cites.
N. Carlini, A Complete List of All (arXiv) Adversarial Example Papers , 2020 (accessed October 1, 2020). [Online]. Available: https://nicholas.carlini.com/writing/2019/all-adversarial-example-papers.html
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
H. Zhang and J. Wang, “Towards adversarially robust object detection,” in Proceedings of the IEEE International Conference on Computer Vision , 2019, pp. 421–430
2019
Earlier work this paper cites.
Y. Jia, Y. Lu, J. Shen, Q. A. Chen, H. Chen, Z. Zhong, and T. Wei, “Fooling detection alone is not enough: Adversarial attack against multiple object tracking,” in International Conference on Learning Representations , 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
O. Vinyals, I. Babuschkin, W. M. Czarnecki, M. Mathieu, A. Dudzik, J. Chung, D. H. Choi, R. Powell, T. Ewalds, P. Georgiev et al. , “Grandmaster level in starcraft ii using multi-agent reinforcement learning,” Nature , vol. 575, no. 7782, pp. 350–354, 2019
2019
Earlier work this paper cites.
X. Yuan, P. He, Q. Zhu, and X. Li, “Adversarial examples: Attacks and defenses for deep learning,” IEEE transactions on neural networks and learning systems , vol. 30, no. 9, pp. 2805–2824, 2019
2019
Earlier work this paper cites.
Y. Zhou, M. Han, L. Liu, J. He, and X. Gao, “The adversarial attacks threats on computer vision: A survey,” in 2019 IEEE 16th International Conference on Mobile Ad Hoc and Sensor Systems Workshops (MASSW) . IEEE, 2019, pp. 25–30
2019
Earlier work this paper cites.
C. Xie, Z. Zhang, Y. Zhou, S. Bai, J. Wang, Z. Ren, and A. L. Yuille, “Improving transferability of adversarial examples with input diversity,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2019, pp. 2730–2739
2019
Earlier work this paper cites.
J. Su, D. V. Vargas, and K. Sakurai, “One pixel attack for fooling deep neural networks,” IEEE Transactions on Evolutionary Computation , vol. 23, no. 5, pp. 828–841, 2019
2019
Earlier work this paper cites.
J. Rony, L. G. Hafemann, L. S. Oliveira, I. B. Ayed, R. Sabourin, and E. Granger, “Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019, pp. 4322–4330
2019
Earlier work this paper cites.
Z. Yao, A. Gholami, P. Xu, K. Keutzer, and M. W. Mahoney, “Trust region based adversarial attack on neural networks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019, pp. 11 350–11 359
2019
Earlier work this paper cites.
Y. Liu, S.-M. Moosavi-Dezfooli, and P. Frossard, “A geometry-inspired decision-based attack,” in Proceedings of the IEEE International Conference on Computer Vision , 2019, pp. 4890–4898
2019
Earlier work this paper cites.
B. Ru, A. Cobb, A. Blaas, and Y. Gal, “Bayesopt adversarial attack,” in International Conference on Learning Representations , 2019
2019
Earlier work this paper cites.
M. Cheng, T. Le, P.-Y. Chen, J. Yi, H. Zhang, and C.-J. Hsieh, “Query-efficient hard-label black-box attack: An optimization-based approach,” ICLR , 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
A. Al-Dujaili and U.-M. O’Reilly, “Sign bits are all you need for black-box attacks,” in International Conference on Learning Representations , 2019
2019
Earlier work this paper cites.
A. Ilyas, L. Engstrom, and A. Madry, “Prior convictions: Black-box adversarial attacks with bandits and priors,” ICLR , 2019
2019
Earlier work this paper cites.
P. Zhao, S. Liu, P.-Y. Chen, N. Hoang, K. Xu, B. Kailkhura, and X. Lin, “On the design of black-box adversarial examples by leveraging gradient-free optimization and operator splitting method,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2019, pp. 121–130
2019
Earlier work this paper cites.
T. Brunner, F. Diehl, M. T. Le, and A. Knoll, “Guessing smart: Biased sampling for efficient black-box adversarial attacks,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2019, pp. 4958–4966
2019
Earlier work this paper cites.
G. Tolias, F. Radenovic, and O. Chum, “Targeted mismatch adversarial attack: Query with a flower to retrieve the tower,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2019, pp. 5037–5046
2019
Earlier work this paper cites.
Q. Huang, I. Katsman, H. He, Z. Gu, S. Belongie, and S.-N. Lim, “Enhancing adversarial example transferability with an intermediate level attack,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2019, pp. 4733–4742
2019
Earlier work this paper cites.
J. Lin, C. Song, K. He, L. Wang, and J. E. Hopcroft, “Nesterov accelerated gradient and scale invariance for adversarial attacks,” in International Conference on Learning Representations , 2019
2019
Earlier work this paper cites.
N. Inkawhich, W. Wen, H. H. Li, and Y. Chen, “Feature space perturbations yield more transferable adversarial examples,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019, pp. 7066–7074
2019
Earlier work this paper cites.
Y. Dong, T. Pang, H. Su, and J. Zhu, “Evading defenses to transferable adversarial examples by translation-invariant attacks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019, pp. 4312–4321
2019
Earlier work this paper cites.
Y. Shi, S. Wang, and Y. Han, “Curls & whey: Boosting black-box adversarial attacks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019, pp. 6519–6527
2019
Earlier work this paper cites.
A. Joshi, A. Mukherjee, S. Sarkar, and C. Hegde, “Semantic adversarial attacks: Parametric transformations that fool deep classifiers,” in Proceedings of the IEEE International Conference on Computer Vision , 2019, pp. 4773–4783
2019
Earlier work this paper cites.
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “A general framework for adversarial examples with objectives,” ACM Transactions on Privacy and Security (TOPS) , vol. 22, no. 3, pp. 1–30, 2019
2019
Earlier work this paper cites.
F. Croce and M. Hein, “Sparse and imperceivable adversarial attacks,” in Proceedings of the IEEE International Conference on Computer Vision , 2019, pp. 4724–4732
2019
Earlier work this paper cites.
2019
Cited alongside, same era.
C. Xie, K. Huang, P.-Y. Chen, and B. Li, “Dba: Distributed backdoor attacks against federated learning,” in International Conference on Learning Representations , 2019
2019
Cited alongside, same era.
A. N. Bhagoji, S. Chakraborty, P. Mittal, and S. Calo, “Analyzing federated learning through an adversarial lens,” in International Conference on Machine Learning . PMLR, 2019, pp. 634–643
2019
Cited alongside, same era.
K. Roth, Y. Kilcher, and T. Hofmann, “The odds are odd: A statistical test for detecting adversarial examples,” in International Conference on Machine Learning . PMLR, 2019, pp. 5498–5507
2019
Cited alongside, same era.
2020
Later among the works it cites.
T. Pang, K. Xu, Y. Dong, C. Du, N. Chen, and J. Zhu, “Rethinking softmax cross-entropy loss for adversarial robustness,” ICLR , 2020
2020
Later among the works it cites.
S. Sen, B. Ravindran, and A. Raghunathan, “Empir: Ensembles of mixed precision deep networks for increased robustness against adversarial attacks,” ICLR , 2020
2020
Later among the works it cites.
T. Pang, K. Xu, and J. Zhu, “Mixup inference: Better exploiting mixup to defend adversarial attacks,” ICLR , 2020
2020
Later among the works it cites.
X. Yin, S. Kolouri, and G. K. Rohde, “Adversarial example detection and classification with asymmetrical adversarial training,” ICLR , 2020
2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Y. Li, J. Bradshaw, and Y. Sharma, “Are generative classifiers more robust to adversarial attacks?” in International Conference on Machine Learning . PMLR, 2019, pp. 3804–3814
2019
Cited alongside, same era.
G. Verma and A. Swami, “Error correcting output codes improve probability estimation and adversarial robustness of deep neural networks,” Advances in Neural Information Processing Systems , vol. 32, pp. 8646–8656, 2019
2019
Cited alongside, same era.
T. Pang, K. Xu, C. Du, N. Chen, and J. Zhu, “Improving adversarial robustness via promoting ensemble diversity,” in International Conference on Machine Learning . PMLR, 2019, pp. 4970–4979
2019
Cited alongside, same era.
Z. Yang, B. Li, P.-Y. Chen, and D. Song, “Characterizing audio adversarial examples using temporal dependency,” ICLR , 2019
2019
Cited alongside, same era.
Y. Yang, G. Zhang, D. Katabi, and Z. Xu, “Me-net: Towards effective adversarial robustness with matrix estimation,” ICLR , 2019
2019
Cited alongside, same era.
T. Yu, S. Hu, C. Guo, W.-L. Chao, and K. Q. Weinberger, “A new defense against adversarial images: Turning a weakness into a strength,” NeurIPS , 2019
2019
Cited alongside, same era.
S. Hong, P. Frigo, Y. Kaya, C. Giuffrida, and T. Dumitraș, “Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks,” in 28th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 19) , 2019, pp. 497–514
2019
Cited alongside, same era.
A. S. Rakin, Z. He, and D. Fan, “Bit-flip attack: Crushing neural network with progressive bit search,” in Proceedings of the IEEE International Conference on Computer Vision , 2019, pp. 1211–1220
2019
Cited alongside, same era.
Later among the works it cites.
A. Ghiasi, A. Shafahi, and T. Goldstein, “Breaking certified defenses: Semantic adversarial examples with spoofed robustness certificates,” ICLR , 2020
2020
Later among the works it cites.
M. Zhou, Z. Niu, L. Wang, Q. Zhang, and G. Hua, “Adversarial ranking attack and defense,” ECCV , 2020
2020
Later among the works it cites.
S. Rezaei and X. Liu, “A target-agnostic attack on deep models: Exploiting security vulnerabilities of transfer learning,” ICLR , 2020
2020
Later among the works it cites.
H. Zhou, D. Chen, J. Liao, K. Chen, X. Dong, K. Liu, W. Zhang, G. Hua, and N. Yu, “Lg-gan: Label guided adversarial network for flexible targeted attack of point cloud based deep networks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 10 356–10 365
2020
Later among the works it cites.
Y. Zhao, Y. Wu, C. Chen, and A. Lim, “On isometry robustness of deep 3d point cloud models under adversarial attacks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 1201–1210
2020
Later among the works it cites.
A. Hamdi, S. Rojas, A. Thabet, and B. Ghanem, “Advpc: Transferable adversarial perturbations on 3d point clouds,” in European Conference on Computer Vision . Springer, 2020, pp. 241–257
2020
Later among the works it cites.
H. Zhang, L. Zhu, Y. Zhu, and Y. Yang, “Motion-excited sampler: Video adversarial attack with sparked prior,” ECCV , 2020
2020
Later among the works it cites.
A. Liu, T. Huang, X. Liu, Y. Xu, Y. Ma, X. Chen, S. J. Maybank, and D. Tao, “Spatiotemporal attacks for embodied agents,” in European Conference on Computer Vision . Springer, 2020, pp. 122–138
2020
Later among the works it cites.
J. Liu, N. Akhtar, and A. Mian, “Adversarial attack on skeleton-based human action recognition,” IEEE Transactions on Neural Networks and Learning Systems , 2020
2020
Later among the works it cites.
H. Jin, Z. Shi, V. J. S. A. Peruri, and X. Zhang, “Certified robustness of graph convolution networks for graph classification under topological attacks,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
Y. Fan, B. Wu, T. Li, Y. Zhang, M. Li, Z. Li, and Y. Yang, “Sparse adversarial attack via perturbation factorization,” in Proceedings of European Conference on Computer Vision , 2020
2020
Later among the works it cites.
S. U. Din, N. Akhtar, S. Younis, F. Shafait, A. Mansoor, and M. Shafique, “Steganographic universal adversarial perturbations,” Pattern Recognition Letters , vol. 135, pp. 146–152, 2020
2020
Later among the works it cites.
B. Yan, D. Wang, H. Lu, and X. Yang, “Cooling-shrinking attack: Blinding the tracker with imperceptible noises,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 990–999
2020
Later among the works it cites.
S. Liang, X. Wei, S. Yao, and X. Cao, “Efficient adversarial attacks for visual object tracking,” in European Conference on Computer Vision . Springer, 2020, pp. 34–50
2020
Later among the works it cites.
L. Huang, C. Gao, Y. Zhou, C. Xie, A. L. Yuille, C. Zou, and N. Liu, “Universal physical camouflage attacks on object detectors,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 720–729
2020
Later among the works it cites.
Z. Wu, S.-N. Lim, L. S. Davis, and T. Goldstein, “Making an invisibility cloak: Real world adversarial attacks on object detectors,” in European Conference on Computer Vision . Springer, 2020, pp. 1–17
2020
Later among the works it cites.
Q. Guo, X. Xie, F. Juefei-Xu, L. Ma, Z. Li, W. Xue, W. Feng, and Y. Liu, “Spark: Spatial-aware online incremental attack against visual tracking,” in Proceedings of the European Conference on Computer Vision (ECCV) , vol. 2. Springer, 2020
2020
Later among the works it cites.
A. Gleave, M. Dennis, C. Wild, N. Kant, S. Levine, and S. Russell, “Adversarial policies: Attacking deep reinforcement learning,” ICLR , 2020
2020
Later among the works it cites.
A. Rakhsha, G. Radanovic, R. Devidze, X. Zhu, and A. Singla, “Policy teaching via environment poisoning: Training-time adversarial attacks against reinforcement learning,” in International Conference on Machine Learning . PMLR, 2020, pp. 7974–7984
2020
Later among the works it cites.
X. Zhang, Y. Ma, A. Singla, and X. Zhu, “Adaptive reward-poisoning attacks against reinforcement learning,” in International Conference on Machine Learning . PMLR, 2020, pp. 11 225–11 234
2020
Later among the works it cites.
H. Zhang, H. Chen, C. Xiao, B. Li, M. Liu, D. Boning, and C.-J. Hsieh, “Robust deep reinforcement learning against adversarial perturbations on state observations,” NeurIPS , 2020
2020
Later among the works it cites.
X. Xu, J. Chen, J. Xiao, L. Gao, F. Shen, and H. T. Shen, “What machines see is not what they get: Fooling scene text recognition models with adversarial text images,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 12 304–12 314
2020
Later among the works it cites.
Y. Zhong and W. Deng, “Towards transferable adversarial attack against deep face recognition,” IEEE Transactions on Information Forensics and Security , vol. 16, pp. 1452–1466, 2020
2020
Later among the works it cites.
L. Yang, Q. Song, and Y. Wu, “Attacks on state-of-the-art face recognition using attentional adversarial attack generative network,” Multimedia Tools and Applications , pp. 1–21, 2020
2020
Later among the works it cites.
R. Tolosana, R. Vera-Rodriguez, J. Fierrez, A. Morales, and J. Ortega-Garcia, “Deepfakes and beyond: A survey of face manipulation and fake detection,” Information Fusion , vol. 64, pp. 131–148, 2020
2020
Later among the works it cites.
D.-L. Nguyen, S. S. Arora, Y. Wu, and H. Yang, “Adversarial light projection attacks on face recognition systems: A feasibility study,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops , 2020, pp. 814–815
2020
Later among the works it cites.
K. K. Nakka and M. Salzmann, “Indirect local attacks for context-aware semantic segmentation networks,” in European Conference on Computer Vision . Springer, 2020, pp. 611–628
2020
Later among the works it cites.
Y. He, S. Rahimian, B. Schiele, and M. Fritz, “Segmentations-leak: Membership inference attacks and defenses in semantic image segmentation,” in European Conference on Computer Vision . Springer, 2020, pp. 519–535
2020
Later among the works it cites.
2020
Later among the works it cites.
J. Bai, B. Chen, Y. Li, D. Wu, W. Guo, S.-t. Xia, and E.-h. Yang, “Targeted attack for deep hashing based retrieval,” in European Conference on Computer Vision . Springer, 2020, pp. 618–634
2020
Later among the works it cites.
Z. Zhang, Z. Zhang, Y. Zhou, Y. Shen, R. Jin, and D. Dou, “Adversarial attacks on deep graph matching,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
C. Yang, A. Kortylewski, C. Xie, Y. Cao, and A. Yuille, “Patchattack: A black-box texture-based attack with reinforcement learning,” in European Conference on Computer Vision . Springer, 2020, pp. 681–698
2020
Later among the works it cites.
X. Yang, F. Wei, H. Zhang, X. Ming, and J. Zhu, “Design and interpretation of universal adversarial patches in face detection,” ECCV , 2020
2020
Later among the works it cites.
Z. Kong, J. Guo, A. Li, and C. Liu, “Physgan: Generating physical-world-resilient adversarial examples for autonomous driving,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 14 254–14 263
2020
Later among the works it cites.
R. Duan, X. Ma, Y. Wang, J. Bailey, A. K. Qin, and Y. Yang, “Adversarial camouflage: Hiding physical-world attacks with natural styles,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 1000–1008
2020
Later among the works it cites.
A. Liu, J. Wang, X. Liu, B. Cao, C. Zhang, and H. Yu, “Bias-based universal adversarial patch attack for automatic check-out,” in Proc. Eur. Conf. Comput. Vis. Springer, 2020, pp. 395–410
2020
Later among the works it cites.
K. Xu, G. Zhang, S. Liu, Q. Fan, M. Sun, H. Chen, P.-Y. Chen, Y. Wang, and X. Lin, “Adversarial t-shirt! evading person detectors in a physical world,” in European Conference on Computer Vision . Springer, 2020, pp. 665–681
2020
Later among the works it cites.
A. Braunegg, A. Chakraborty, M. Krumdick, N. Lape, S. Leary, K. Manville, E. Merkhofer, L. Strickhart, and M. Walmer, “Apricot: A dataset of physical adversarial attacks on object detection,” in European Conference on Computer Vision . Springer, 2020, pp. 35–50
2020
Later among the works it cites.
C. Xie, M. Tan, B. Gong, J. Wang, A. L. Yuille, and Q. V. Le, “Adversarial examples improve image recognition,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 819–828
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
M. A. Jalwana, N. Akhtar, M. Bennamoun, and A. Mian, “Attack to explain deep representation,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 9543–9552
2020
Later among the works it cites.
M. Augustin, A. Meinke, and M. Hein, “Adversarial robustness on in-and out-distribution improves explainability,” in European Conference on Computer Vision . Springer, 2020, pp. 228–245
2020
Later among the works it cites.
K. Sakaguchi, R. Le Bras, C. Bhagavatula, and Y. Choi, “Winogrande: An adversarial winograd schema challenge at scale,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 34, no. 05, 2020, pp. 8732–8740
2020
Later among the works it cites.
R. Le Bras, S. Swayamdipta, C. Bhagavatula, R. Zellers, M. Peters, A. Sabharwal, and Y. Choi, “Adversarial filters of dataset biases,” in International Conference on Machine Learning . PMLR, 2020, pp. 1078–1088
2020
Later among the works it cites.
Y. Li, S. Cheng, H. Su, and J. Zhu, “Defense against adversarial attacks via controlling gradient leaking on embedded manifolds,” in European Conference on Computer Vision . Springer, 2020, pp. 753–769
2020
Later among the works it cites.
2020
Later among the works it cites.
A. Pal and R. Vidal, “A game theoretic analysis of additive adversarial attacks and defenses,” NeurIPS , 2020
2020
Later among the works it cites.
A. Daniely and H. Schacham, “Most relu networks suffer from l2 adversarial perturbations,” NeurIPS , 2020
2020
Later among the works it cites.
C. Zhang, P. Benz, T. Imtiaz, and I. S. Kweon, “Understanding adversarial examples from the mutual influence of images and perturbations,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 14 521–14 530
2020
Later among the works it cites.
2020
Later among the works it cites.
H. Zhang, H. Chen, Z. Song, D. Boning, I. S. Dhillon, and C.-J. Hsieh, “The limitations of adversarial training and the blind-spot attack,” ICLR , 2020
2020
Later among the works it cites.
S. Gowal, C. Qin, P.-S. Huang, T. Cemgil, K. Dvijotham, T. Mann, and P. Kohli, “Achieving robustness in the wild via adversarial mixing with disentangled representations,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 1211–1220
2020
Later among the works it cites.
B. Vivek and R. V. Babu, “Single-step adversarial training with dropout scheduling,” in 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . IEEE, 2020, pp. 947–956
2020
Later among the works it cites.
C. Song, K. He, J. Lin, L. Wang, and J. E. Hopcroft, “Robust local features for improving the generalization of adversarial training,” ICLR , 2020
2020
Later among the works it cites.
C. Xiao and C. Zheng, “One man’s trash is another man’s treasure: Resisting adversarial examples by adversarial examples,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 412–421
2020
Later among the works it cites.
M. Naseer, S. Khan, M. Hayat, F. S. Khan, and F. Porikli, “A self-supervised approach for adversarial robustness,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 262–271
2020
Later among the works it cites.
T. Chen, S. Liu, S. Chang, Y. Cheng, L. Amini, and Z. Wang, “Adversarial robustness: From self-supervised pre-training to fine-tuning,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 699–708
2020
Later among the works it cites.
2020
Later among the works it cites.
Y. Dong, Z. Deng, T. Pang, H. Su, and J. Zhu, “Adversarial distributional training for robust deep learning,” NeurIPS , 2020
2020
Later among the works it cites.
D. Madaan, J. Shin, and S. J. Hwang, “Adversarial neural pruning with latent vulnerability suppression,” in International Conference on Machine Learning . PMLR, 2020, pp. 6575–6585
2020
Later among the works it cites.
P. Maini, E. Wong, and Z. Kolter, “Adversarial robustness against the union of multiple perturbation models,” in International Conference on Machine Learning . PMLR, 2020, pp. 6640–6650
2020
Later among the works it cites.
S. Lee, H. Lee, and S. Yoon, “Adversarial vertex mixup: Toward better adversarially robust generalization,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 272–281
2020
Later among the works it cites.
C. Xie and A. Yuille, “Intriguing properties of adversarial training at scale,” ICLR , 2020
2020
Later among the works it cites.
V. Sehwag, S. Wang, P. Mittal, and S. Jana, “Hydra: Pruning adversarially robust neural networks,” Advances in Neural Information Processing Systems (NeurIPS) , vol. 7, 2020
2020
Later among the works it cites.
E. Wong, L. Rice, and J. Z. Kolter, “Fast is better than free: Revisiting adversarial training,” ICLR , 2020
2020
Later among the works it cites.
M. Andriushchenko and N. Flammarion, “Understanding and improving fast adversarial training,” NeurIPS , 2020
2020
Later among the works it cites.
P. Zhao, P.-Y. Chen, P. Das, K. N. Ramamurthy, and X. Lin, “Bridging mode connectivity in loss landscapes and adversarial robustness,” ICLR , 2020
2020
Later among the works it cites.
D. Wu, S.-T. Xia, and Y. Wang, “Adversarial weight perturbation helps robust generalization,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
T. Wu, L. Tong, and Y. Vorobeychik, “Defending against physically realizable attacks on image classification,” ICLR , 2020
2020
Later among the works it cites.
M. Guo, Y. Yang, R. Xu, Z. Liu, and D. Lin, “When nas meets robustness: In search of robust architectures against adversarial attacks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 631–640
2020
Later among the works it cites.
A. Bui, T. Le, H. Zhao, P. Montague, O. deVel, T. Abraham, and D. Phung, “Improving adversarial robustness by enforcing local and global compactness,” ECCV , 2020
2020
Later among the works it cites.
A. Jeddi, M. J. Shafiee, M. Karg, C. Scharfenberger, and A. Wong, “Learn2perturb: an end-to-end feature perturbation learning to improve adversarial robustness,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 1241–1250
2020
Later among the works it cites.
G. Li, S. Ding, J. Luo, and C. Liu, “Enhancing intrinsic adversarial robustness via feature pyramid decoder,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 800–808
2020
Later among the works it cites.
T. Borkar, F. Heide, and L. Karam, “Defending against universal attacks through selective feature regeneration,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 709–719
2020
Later among the works it cites.
A. Chan, Y. Tay, Y. S. Ong, and J. Fu, “Jacobian adversarially regularized networks for robustness,” ICLR , 2020
2020
Later among the works it cites.
A. Dabouei, S. Soleymani, F. Taherkhani, J. Dawson, and N. M. Nasrabadi, “Exploiting joint robustness to adversarial perturbations,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 1122–1131
2020
Later among the works it cites.
S. Addepalli, A. Baburaj, G. Sriramanan, and R. V. Babu, “Towards achieving adversarial robustness by enforcing feature consistency across bit planes,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 1020–1029
2020
Later among the works it cites.
Y. Qin, N. Frosst, S. Sabour, C. Raffel, G. Cottrell, and G. Hinton, “Detecting and diagnosing adversarial images with class-conditional capsule reconstructions,” ICLR , 2020
2020
Later among the works it cites.
S. Li, S. Zhu, S. Paul, A. Roy-Chowdhury, C. Song, S. Krishnamurthy, A. Swami, and K. S. Chan, “Connecting the dots: Detecting adversarial perturbations using context inconsistency,” in European Conference on Computer Vision . Springer, 2020, pp. 396–413
2020
Later among the works it cites.
J. Yuan and Z. He, “Ensemble generative cleaning with feedback loops for defending adversarial attacks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 581–590
2020
Later among the works it cites.
G. Cohen, G. Sapiro, and R. Giryes, “Detecting adversarial samples using influence functions and nearest neighbors,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 14 453–14 462
2020
Later among the works it cites.
F. Croce and M. Hein, “Provable robustness against all adversarial l_p-perturbations for p ≥ \geq 1.” in ICLR , 2020
2020
Later among the works it cites.
J. Jia, X. Cao, B. Wang, and N. Z. Gong, “Certified robustness for top-k predictions against adversarial perturbations via randomized smoothing,” ICLR , 2020
2020
Later among the works it cites.
R. Zhai, C. Dan, D. He, H. Zhang, B. Gong, P. Ravikumar, C.-J. Hsieh, and L. Wang, “Macer: Attack-free and scalable robust training via maximizing certified radius,” ICLR , 2020
2020
Later among the works it cites.
M. Fischer, M. Baader, and M. Vechev, “Certified defense to image transformations via randomized smoothing,” NeurIPS , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
P.-y. Chiang, R. Ni, A. Abdelkader, C. Zhu, C. Studor, and T. Goldstein, “Certified defenses for adversarial patches,” ICLR , 2020
2020
Later among the works it cites.
P. Awasthi, H. Jain, A. S. Rawat, and A. Vijayaraghavan, “Adversarial robustness via robust low rank representations,” NeurIPS , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
A. Rahnama, A. T. Nguyen, and E. Raff, “Robust design of deep neural networks against adversarial attacks based on lyapunov theory,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 8178–8187
2020
Later among the works it cites.
S. Saralajew, L. Holdijk, T. Villmann, and U. Mittweida, “Fast adversarial robustness certification of nearest prototype classifiers for arbitrary seminorms,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
S. Goldwasser, A. T. Kalai, Y. T. Kalai, and O. Montasser, “Beyond perturbations: Learning guarantees with arbitrary adversarial test examples,” 2020
2020
Later among the works it cites.
H. Salman, M. Sun, G. Yang, A. Kapoor, and J. Z. Kolter, “Denoised smoothing: A provable defense for pretrained classifiers,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
Z. He, A. S. Rakin, J. Li, C. Chakrabarti, and D. Fan, “Defending and harnessing the bit-flip based adversarial weight attack,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 14 095–14 103
2020
Later among the works it cites.
2020
Later among the works it cites.
S. Sharmin, N. Rathi, P. Panda, and K. Roy, “Inherent adversarial robustness of deep spiking neural networks: Effects of discrete input encoding and non-linear activations,” in European Conference on Computer Vision . Springer, 2020, pp. 399–414
2020
Later among the works it cites.
X. Zhang and M. Zitnik, “Gnnguard: Defending graph neural networks against adversarial attacks,” NeurIPS , 2020
2020
Later among the works it cites.
M. Du, R. Jia, and D. Song, “Robust anomaly detection and backdoor attack detection via differential privacy,” ICLR , 2020
2020
Later among the works it cites.
S. Jia, C. Ma, Y. Song, and X. Yang, “Robust tracking against adversarial attacks,” in European Conference on Computer Vision . Springer, 2020, pp. 69–84
2020
Later among the works it cites.
R. Shao, P. Perera, P. C. Yuen, and V. M. Patel, “Open-set adversarial defense,” ECCV , 2020
2020
Later among the works it cites.
J. Zhou, C. Liang, and J. Chen, “Manifold projection for adversarial defense on face recognition,” in European Conference on Computer Vision . Springer, 2020, pp. 288–305
2020
Later among the works it cites.
M. Goldblum, L. Fowl, and T. Goldstein, “Adversarially robust few-shot learning: A meta-learning approach,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
S. Kariyappa and M. K. Qureshi, “Defending against model stealing attacks with adaptive misinformation,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 770–778
2020
Later among the works it cites.
2020
Later among the works it cites.
J. Yang and C. Vondrick, “Multitask learning strengthens adversarial robustness,” in European Conference on Computer Vision . Springer, 2020
2020
Later among the works it cites.
E. Kim, J. Rego, Y. Watkins, and G. T. Kenyon, “Modeling biological immunity to adversarial examples,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020, pp. 4666–4675
2020
Later among the works it cites.
H. Wang, T. Chen, S. Gui, T.-K. Hu, J. Liu, and Z. Wang, “Calibratable adversarial training: In-situ tradeoff between robustness and accuracy for free,” NeurIPS , 2020
2020
Later among the works it cites.
C.-H. Weng, Y.-T. Lee, and S.-H. B. Wu, “On the trade-off between adversarial and backdoor robustness,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
H. Chen, B. Zhang, S. Xue, X. Gong, H. Liu, R. Ji, and D. Doermann, “Anti-bandit neural architecture search for model defense,” in European Conference on Computer Vision . Springer, 2020, pp. 70–85
2020
Later among the works it cites.
B. Phan, F. Mannan, and F. Heide, “Adversarial imaging pipelines,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 16 051–16 061
2021
Closest in time.
W. Wang, B. Yin, T. Yao, L. Zhang, Y. Fu, S. Ding, J. Li, F. Huang, and X. Xue, “Delving into data: Effectively substitute training for black-box attack,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 4761–4770
2021
Closest in time.
T. Maho, T. Furon, and E. Le Merrer, “Surfree: A fast surrogate-free black-box attack,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 10 430–10 439
2021
Closest in time.
X. Li, J. Li, Y. Chen, S. Ye, Y. He, S. Wang, H. Su, and H. Xue, “Qair: Practical query-efficient black-box attacks for image retrieval,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 3330–3339
2021
Closest in time.
C. Ma, L. Chen, and J.-H. Yong, “Simulating unknown target models for query-efficient black-box attacks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 11 835–11 844
2021
Closest in time.
W. Wu, Y. Su, M. R. Lyu, and I. King, “Improving the transferability of adversarial samples with adversarial transformations,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 9024–9033
2021
Closest in time.
Z. Chen, L. Xie, S. Pang, Y. He, and B. Zhang, “Magdr: Mask-guided detection and reconstruction for defending deepfakes,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 9014–9023
2021
Closest in time.
D. Hendrycks, K. Zhao, S. Basart, J. Steinhardt, and D. Song, “Natural adversarial examples,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 15 262–15 271
2021
Closest in time.
N. Akhtar, M. Jalwana, M. Bennamoun, and A. S. Mian, “Attack to fool and explain deep networks,” IEEE Transactions on Pattern Analysis and Machine Intelligence , 2021
2021
Closest in time.
Y. Diao, T. Shao, Y.-L. Yang, K. Zhou, and H. Wang, “Basar:black-box attack on skeletal action recognition,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 7597–7607
2021
Closest in time.
H. Wang, F. He, Z. Peng, T. Shao, Y.-L. Yang, K. Zhou, and D. Hogg, “Understanding the robustness of skeleton-based action recognition under adversarial attack,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 14 656–14 665
2021
Closest in time.
R. Pony, I. Naeh, and S. Mannor, “Over-the-air adversarial flickering attacks against video recognition networks,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 515–524
2021
Closest in time.
A. Rampini, F. Pestarini, L. Cosmo, S. Melzi, and E. Rodola, “Universal spectral adversarial attacks for deformable shapes,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 3216–3226
2021
Closest in time.
P.-C. Chen, B.-H. Kung, and J.-C. Chen, “Class-aware robust adversarial training for object detection,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 10 420–10 429
2021
Closest in time.
A. Zolfi, M. Kravchik, Y. Elovici, and A. Shabtai, “The translucent patch: A physical and universal attack on object detectors,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 15 232–15 241
2021
Closest in time.
S. Jia, Y. Song, C. Ma, and X. Yang, “Iou attack: Towards temporally coherent black-box adversarial attack for visual object tracking,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 6709–6718
2021
Closest in time.
Z. Xiao, X. Gao, C. Fu, Y. Dong, W. Gao, X. Zhang, J. Zhou, and J. Zhu, “Improving transferability of adversarial patches on face recognition with generative models,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 11 845–11 854
2021
Closest in time.
D. Li, W. Wang, H. Fan, and J. Dong, “Exploring adversarial fake images on face manifold,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 5789–5798
2021
Closest in time.
A. Mehra, B. Kailkhura, P.-Y. Chen, and J. Hamm, “How robust are randomized smoothing based defenses to data poisoning?” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 13 244–13 253
2021
Closest in time.
J. Wang, A. Liu, Z. Yin, S. Liu, S. Tang, and X. Liu, “Dual attention suppression attack: Generate adversarial camouflage in physical world,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 8565–8574
2021
Closest in time.
A. Sayles, A. Hooda, M. Gupta, R. Chatterjee, and E. Fernandes, “Invisible perturbations: Physical adversarial examples exploiting the rolling shutter effect,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 14 666–14 675
2021
Closest in time.
R. Duan, X. Mao, A. K. Qin, Y. Chen, S. Ye, Y. He, and Y. Yang, “Adversarial laser beam: Effective physical-world attack to dnns in a blink,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 16 062–16 071
2021
Closest in time.
J. Lee, E. Kim, and S. Yoon, “Anti-adversarially manipulated attributions for weakly and semi-supervised semantic segmentation,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 4071–4080
2021
Closest in time.
A. Elliott, S. Law, and C. Russell, “Explaining classifiers using adversarial perturbations on the perceptual ball,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 10 693–10 702
2021
Closest in time.
C. Gong, T. Ren, M. Ye, and Q. Liu, “Maxup: Lightweight adversarial training with data augmentation improves neural network training,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 2474–2483
2021
Closest in time.
R. Hosseini, X. Yang, and P. Xie, “Dsrna: Differentiable search of robust neural architectures,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2021, pp. 6196–6205
2021
Closest in time.
G. Cazenavette, C. Murdock, and S. Lucey, “Architectural adversarial robustness: The case for deep pursuit,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2021, pp. 7150–7158
2021
Closest in time.
Z. Deng, X. Yang, S. Xu, H. Su, and J. Zhu, “Libre: A practical bayesian approach to adversarial detection,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 972–982
2021
Closest in time.
P. Awasthi, G. Yu, C.-S. Ferng, A. Tomkins, and D.-C. Juan, “Adversarial robustness across representation spaces,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 7608–7616
2021
Closest in time.
T. Wu, Z. Liu, Q. Huang, Y. Wang, and D. Lin, “Adversarial robustness under long-tailed distribution,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 8659–8668
2021
Closest in time.
M. A. Jalwana, N. Akhtar, M. Bennamoun, and A. Mian, “Cameras: Enhanced resolution and sanity preserving class activation mapping for image saliency,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2021
2021
Closest in time.
Y. Yu, X. Gao, and C.-Z. Xu, “Lafeat: Piercing through adversarial defenses with latent features,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2021, pp. 5735–5745
2021
Closest in time.