Fetching the paper…
Reading the bibliography…
Vision transformers rely on a patch token based self attention mechanism, in contrast to convolutional networks.
“Intriguing properties of neural networks,”
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, · 2013
Earlier work this paper cites.
“Deep inside convolutional networks: Visualising image classification models and saliency maps,”
K. Simonyan, A. Vedaldi, and A. Zisserman, · 2013
Earlier work this paper cites.
“Explaining and harnessing adversarial examples,”
I. Goodfellow, J. Shlens, and C. Szegedy, · 2015
Earlier work this paper cites.
“ImageNet Large Scale Visual Recognition Challenge,”
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein, A. Berg, and F. Li, · 2015
Earlier work this paper cites.
“Deep residual learning for image recognition,”
K. He, X. Zhang, S. Ren, and J. Sun, · 2016
Earlier work this paper cites.
“Wide residual networks,”
S. Zagoruyko and N. Komodakis, · 2016
Earlier work this paper cites.
“The limitations of deep learning in adversarial settings,”
N. Papernot, P. Mcdaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, · 2016
Earlier work this paper cites.
“Adversarial examples in the physical world,”
A. Kurakin, I. Goodfellow, and S. Bengio, · 2017
Earlier work this paper cites.
“Attention is all you need,”
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. Gomez, L. Kaiser, and I. Polosukhin, · 2017
Earlier work this paper cites.
“Towards evaluating the robustness of neural networks,”
N. Carlini and D. Wagner, · 2017
Earlier work this paper cites.
“A rotation and a translation suffice: Fooling cnns with simple transformations,”
L. Engstrom, D. Tsipras, L. Schmidt, and A. Madry, · 2017
Earlier work this paper cites.
T. Brown, D. Mané, A. Roy, M. Abadi, and J. Gilmer, · 2017
Earlier work this paper cites.
“Defense against the dark arts: An overview of adversarial example security research and future research directions,”
I. Goodfellow, · 2018
Earlier work this paper cites.
“Towards deep learning models resistant to adversarial attacks,”
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, · 2018
Earlier work this paper cites.
“Prior convictions: Black-box adversarial attacks with bandits and priors,”
A. Ilyas, L. Engstrom, and A. Madry, · 2018
Earlier work this paper cites.
“Black-box adversarial attacks with limited queries and information,”
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin, · 2018
Earlier work this paper cites.
“Spatially transformed adversarial examples,”
C. Xiao, J. Zhu, B. Li, W. He, M. Liu, and D. Song, · 2018
Earlier work this paper cites.
“Constructing unrestricted adversarial examples with generative models,”
Y. Song, R. Shu, N. Kushman, and S. Ermon, · 2018
Earlier work this paper cites.
“Poison frogs! targeted clean-label poisoning attacks on neural networks,”
A. Shafahi, W R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein, · 2018
Earlier work this paper cites.
“Defense-GAN: Protecting classifiers against adversarial attacks using generative models,”
P. Samangouei, M. Kabkab, and R. Chellappa, · 2018
Cited alongside, same era.
“Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,”
A. Athalye, N. Carlini, and D. Wagner, · 2018
Cited alongside, same era.
“Provable defenses against adversarial examples via the convex outer adversarial polytope,”
E. Wong and Z. Kolter, · 2018
Cited alongside, same era.
“Image transformer,”
N. Parmar, A. Vaswani, J. Uszkoreit, L. Kaiser, N. Shazeer, A. Ku, and D. Tran, · 2018
Cited alongside, same era.
“Maximal jacobian-based saliency map attack,”
R. Wiyatno and A. Xu, · 2018
Cited alongside, same era.
“Theoretically principled trade-off between robustness and accuracy,”
“Adversarially robust learning via entropic regularization,”
G. Jagatap, A. Joshi, A. Chowdhury, S. Garg, and C. Hegde, · 2020
Later among the works it cites.
“Defense against adversarial attacks by low-level image transformations,”
H. Yin, Z.and Wang, J. Wang, J. Tang, and W. Wang, · 2020
Later among the works it cites.
“Uncovering the limits of adversarial training against norm-bounded adversarial examples,”
S. Gowal, C. Qin, J. Uesato, T. Mann, and P. Kohli, · 2020
Later among the works it cites.
“Making an invisibility cloak: Real world adversarial attacks on object detectors,”
Z. Wu, S. Lim, L. Davis, and T. Goldstein, · 2020
Later among the works it cites.
“Self-training with noisy student improves imagenet classification,”
Qizhe Xie, Eduard H. Hovy, Minh-Thang Luong, and Quoc V. Le, · 2020
Later among the works it cites.
“Language models are few-shot learners,”
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, and M. Jordan, · 2019
Cited alongside, same era.
“Semantic adversarial attacks: Parametric transformations that fool deep classifiers,”
A. Joshi, A. Mukherjee, S. Sarkar, and C. Hegde, · 2019
Cited alongside, same era.
“Camou: Learning physical vehicle camouflages to adversarially attack detectors in the wild,”
Y. Zhang, H. Foroosh, P. David, and B. Gong, · 2019
Cited alongside, same era.
“Certified adversarial robustness via randomized smoothing,”
J. Cohen, E. Rosenfeld, and Z. Kolter, · 2019
Cited alongside, same era.
“Provably robust deep learning via adversarially trained smoothed classifiers,”
H. Salman, G. Yang, J. Li, P. Zhang, H. Zhang, I. Razenshteyn, and S. Bubeck, · 2019
Cited alongside, same era.
“Fooling automated surveillance cameras: adversarial patches to attack person detection,”
S. Thys, W. Van Ranst, and T. Goedemé, · 2019
Cited alongside, same era.
“Sparse and imperceivable adversarial attacks,”
F. Croce and M. Hein, · 2019
Cited alongside, same era.
T. B. Brown, B. Mann, N. Ryder, M. Subbiah, J. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell, S. Agarwal, A. Herbert-Voss, G. Krueger, T. J. Henighan, R. Child, A. Ramesh, D. M. Ziegler, J. Wu, C. Winter, C. Hesse, M. Chen, E. Sigler, M. Litwin, S. Gray, B. Chess, J. Clark, C. Berner, S. McCandlish, A.Radford, I. Sutskever, and D. Amodei, · 2020
Later among the works it cites.
“Pretrained transformers improve out-of-distribution robustness,”
D. Hendrycks, X. Liu, E. Wallace, A. Dziedzic, R. Krishnan, and D. Song, · 2020
Later among the works it cites.
“Sparse-rs: a versatile framework for query-efficient sparse black-box adversarial attacks,”
F. Croce, M. Andriushchenko, et al., · 2020
Later among the works it cites.
“Training data-efficient image transformers & distillation through attention,”
H. Touvron, M. Cord, M. Douze, F. Massa, A. Sablayrolles, and H. J’egou, · 2021
Closest in time.
“Understanding robustness of transformers for image classification,”
S. Bhojanapalli, A. Chakrabarti, D. Glasner, D. Li, T. Unterthiner, and A. Veit, · 2021
Closest in time.
“Mlp-mixer: An all-mlp architecture for vision,”
I. Tolstikhin, N. Houlsby, et al., · 2021
Closest in time.
“Bag of tricks for adversarial training,”
T. Pang, X. Yang, Y. Dong, H. Su, and J. Zhu, · 2021
Closest in time.
“The translucent patch: A physical and universal attack on object detectors,”
A. Zolfi, M. Kravchik, Y. Elovici, and A. Shabtai, · 2021
Closest in time.
“Coatnet: Marrying convolution and attention for all data sizes,”
Z. Dai, H. Liu, Q. Le, and M. Tan, · 2021
Closest in time.
“Cvt: Introducing convolutions to vision transformers,”
H. Wu, B. Xiao, N. Codella, M. Liu, X. Dai, L. Yuan, and L. Zhang, · 2021
Closest in time.
“Going deeper with image transformers,”
H. Touvron, M. Cord, A. Sablayrolles, G. Synnaeve, and H. J’egou, · 2021
Closest in time.
“On the robustness of vision transformers to adversarial examples,”
K. Mahmood, R. Mahmood, and M. Van Dijk, · 2021
Closest in time.
“Vision transformers are robust learners,”
S. Paul and P. Chen, · 2021
Closest in time.