Fetching the paper…
Reading the bibliography…
In recent years, the adversarial vulnerability of deep neural networks (DNNs) has raised increasing attention.
C. Wah, S. Branson, P. Welinder, P. Perona, and S. Belongie, “The Caltech-UCSD Birds-200-2011 Dataset,” California Institute of Technology, Tech. Rep., 2011
2011
Earlier work this paper cites.
A. Oliva, “The art of hybrid images: Two for the view of one,” Art & Perception , vol. 1, no. 1-2, pp. 65–74, 2013
2013
Earlier work this paper cites.
J. Krause, J. Deng, M. Stark, and L. Fei-Fei, “Collecting a large-scale dataset of fine-grained cars,” 2013
2013
Earlier work this paper cites.
2013
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in ICLR , 2014
2014
Earlier work this paper cites.
M. D. Zeiler and R. Fergus, “Visualizing and understanding convolutional networks,” in ECCV , D. J. Fleet, T. Pajdla, B. Schiele, and T. Tuytelaars, Eds., 2014
2014
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in ICLR , Y. Bengio and Y. LeCun, Eds., 2015
2015
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, C. Szegedy et al. , “Explaining and harnessing adversarial examples,” in ICLR , 2015
2015
Earlier work this paper cites.
A. M. Nguyen, J. Yosinski, J. Clune et al. , “Deep neural networks are easily fooled: High confidence predictions for unrecognizable images,” in CVPR , 2015
2015
Earlier work this paper cites.
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. S. Bernstein, A. C. Berg, and F. Li, “Imagenet large scale visual recognition challenge,” International Journal of Computer Vision , 2015
2015
Earlier work this paper cites.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in ICLR , 2015
2015
Earlier work this paper cites.
J. Long, E. Shelhamer, and T. Darrell, “Fully convolutional networks for semantic segmentation,” in CVPR , 2015
2015
Earlier work this paper cites.
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in CVPR , 2016
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis, “Wide residual networks,” in BMVC , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
C. Szegedy, S. Ioffe, V. Vanhoucke, and A. A. Alemi, “Inception-v4, inception-resnet and the impact of residual connections on learning,” in AAAI , 2017
2017
Earlier work this paper cites.
G. Huang, Z. Liu, L. van der Maaten, and K. Q. Weinberger, “Densely connected convolutional networks,” in CVPR , 2017
2017
Earlier work this paper cites.
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh, “Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models,” in ACM workshop on artificial intelligence and security , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
F. N. Iandola, M. W. Moskewicz, K. Ashraf, S. Han, W. J. Dally, and K. Keutzer, “Squeezenet: Alexnet-level accuracy with 50x fewer parameters and <1mb model size,” in ICLR , 2017
2017
Earlier work this paper cites.
K. He, G. Gkioxari, P. Dollár, and R. B. Girshick, “Mask R-CNN,” in ICCV , 2017
2017
Earlier work this paper cites.
S. Ren, K. He, R. B. Girshick, and J. Sun, “Faster R-CNN: towards real-time object detection with region proposal networks,” IEEE Trans. Pattern Anal. Mach. Intell. , 2017
2017
Earlier work this paper cites.
T. Lin, P. Goyal, R. B. Girshick, K. He, and P. Dollár, “Focal loss for dense object detection,” in ICCV , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in ICLR , 2018
2018
Cited alongside, same era.
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li, “Boosting adversarial attacks with momentum,” in CVPR , 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
N. Das, M. Shanbhogue, S.-T. Chen, F. Hohman, S. Li, L. Chen, M. E. Kounavis, and D. H. Chau, “Shield: Fast, practical defense and vaccination for deep learning using jpeg compression,” in KDD , 2018
2018
Cited alongside, same era.
W. Zhou, X. Hou, Y. Chen, M. Tang, X. Huang, X. Gan, and Y. Yang, “Transferable adversarial perturbations,” in ECCV , 2018
D. Wu, Y. Wang, S. Xia, J. Bailey, and X. Ma, “Skip connections matter: On the transferability of adversarial examples generated with resnets,” in ICLR , 2020
2020
Later among the works it cites.
Y. Li, S. Bai, Y. Zhou, C. Xie, Z. Zhang, and A. L. Yuille, “Learning transferable adversarial examples via ghost networks,” in AAAI , 2020
2020
Later among the works it cites.
J. Lin, C. Song, K. He, L. Wang, and J. E. Hopcroft, “Nesterov accelerated gradient and scale invariance for adversarial attacks,” in ICLR , 2020
2020
Later among the works it cites.
L. Gao, Q. Zhang, J. Song, X. Liu, and H. Shen, “Patch-wise attack for fooling deep neural network,” in ECCV , 2020
2020
Later among the works it cites.
Y. Lu, Y. Jia, J. Wang, B. Li, W. Chai, L. Carin, and S. Velipasalar, “Enhancing cross-task black-box transferability of adversarial examples with dispersion reduction,” in CVPR , 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
J. Hu, L. Shen, G. Sun et al. , “Squeeze-and-excitation networks,” in CVPR , 2018
2018
Cited alongside, same era.
C. Liu, B. Zoph, J. Shlens, W. Hua, L. Li, L. Fei-Fei, A. L. Yuille, J. Huang, and K. Murphy, “Progressive neural architecture search,” in ECCV , 2018
2018
Cited alongside, same era.
N. Ma, X. Zhang, H. Zheng, and J. Sun, “Shufflenet V2: practical guidelines for efficient CNN architecture design,” in ECCV , V. Ferrari, M. Hebert, C. Sminchisescu, and Y. Weiss, Eds., 2018
2018
Cited alongside, same era.
M. Sandler, A. G. Howard, M. Zhu, A. Zhmoginov, and L. Chen, “Mobilenetv2: Inverted residuals and linear bottlenecks,” in CVPR , 2018
2018
Cited alongside, same era.
W. Brendel, J. Rauber, M. Bethge et al. , “Decision-based adversarial attacks: Reliable attacks against black-box machine learning models,” in ICLR , 2018
2018
Cited alongside, same era.
F. Tramèr, A. Kurakin, N. Papernot, I. J. Goodfellow, D. Boneh, and P. D. McDaniel, “Ensemble adversarial training: attacks and defenses,” in ICLR , 2018
2018
Cited alongside, same era.
Z. Yan, Y. Guo, C. Zhang et al. , “Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks,” NeurIPS , 2019
2019
Cited alongside, same era.
2020
Later among the works it cites.
M. Naseer, S. H. Khan, M. Hayat, F. S. Khan, and F. Porikli, “A self-supervised approach for adversarial robustness,” in CVPR , 2020
2020
Later among the works it cites.
H. Wang, X. Wu, Z. Huang, and E. P. Xing, “High-frequency component helps explain the generalization of convolutional neural networks,” in CVPR , 2020
2020
Later among the works it cites.
M. Zhou, J. Wu, Y. Liu, S. Liu, and C. Zhu, “Dast: Data-free substitute training for adversarial attacks,” in CVPR , 2020
2020
Later among the works it cites.
C. Zhang, P. Benz, T. Imtiaz, and I.-S. Kweon, “Understanding adversarial examples from the mutual influence of images and perturbations,” in CVPR , 2020
2020
Later among the works it cites.
Y. Li, S. Bai, C. Xie, Z. Liao, X. Shen, and A. L. Yuille, “Regional homogeneity: Towards learning transferable universal adversarial perturbations against defenses,” in ECCV , 2020
2020
Later among the works it cites.
A. Liu, J. Wang, X. Liu, B. Cao, C. Zhang, and H. Yu, “Bias-based universal adversarial patch attack for automatic check-out,” in ECCV , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
J. Wang, J. Zhao, Q. Yin, X. Luo, Y. Zheng, Y.-Q. Shi, and S. K. Jha, “Smsnet: A new deep convolutional neural network model for adversarial example detection,” IEEE Transactions on Multimedia , vol. 24, pp. 230–244, 2022
2022
Closest in time.
L. Gao, Z. Huang, J. Song, Y. Yang, and H. T. Shen, “Push & pull: Transferable adversarial examples with attentive attack,” IEEE Transactions on Multimedia , vol. 24, pp. 2329–2338, 2022
2022
Closest in time.
Q. Zhang, X. Li, Y. Chen, J. Song, L. Gao, Y. He, and H. Xue, “Beyond imagenet attack: Towards crafting adversarial examples for black-box domains,” in ICLR , 2022
2022
Closest in time.
S. Yuan, Q. Zhang, L. Gao, Y. Cheng, and J. Song, “Natural color fool: Towards boosting black-box unrestricted attacks,” in NeurIPS , 2022
2022
Closest in time.
Y. Long, Q. Zhang, B. Zeng, L. Gao, X. Liu, J. Zhang, and J. Song, “Frequency domain model augmentation for adversarial attack,” in ECCV , 2022
2022
Closest in time.
X. Wang, Y. Guo, J. Song, L. Gao, and H. T. Shen, “Amanet: Adaptive multi-path aggregation for learning human 2d-3d correspondences,” IEEE Transactions on Multimedia , vol. 25, pp. 979–992, 2023
2023
Closest in time.
C. Wan, F. Huang, and X. Zhao, “Average gradient-based adversarial attack,” IEEE Transactions on Multimedia , vol. 25, pp. 9572–9585, 2023
2023
Closest in time.
S. Zhang, D. Zuo, Y. Yang, and X. Zhang, “A transferable adversarial belief attack with salient region perturbation restriction,” IEEE Transactions on Multimedia , vol. 25, pp. 4296–4306, 2023
2023
Closest in time.
Z. Wang, H. Yang, Y. Feng, P. Sun, H. Guo, Z. Zhang, and K. Ren, “Towards transferable targeted adversarial examples,” in CVPR , 2023
2023
Closest in time.
Z. Huang, X. Wang, Y. Wei, L. Huang, H. Shi, W. Liu, and T. S. Huang, “Ccnet: Criss-cross attention for semantic segmentation,” IEEE Trans. Pattern Anal. Mach. Intell. , 2023
2023
Closest in time.
X. Wang, X. Chen, L. Gao, J. Song, and H. T. Shen, “Cpi-parser: Integrating causal properties into multiple human parsing,” IEEE Transactions on Image Processing , vol. 33, pp. 5771–5782, 2024
2024
Closest in time.
R. Ran, J. Wei, C. Zhang, G. Wang, Y. Yang, and H. T. Shen, “Adaptive multi-scale degradation-based attack for boosting the adversarial transferability,” IEEE Transactions on Multimedia , pp. 1–12, 2024
2024
Closest in time.
X. Wei and S. Zhao, “Boosting adversarial transferability with learnable patch-wise masks,” IEEE Transactions on Multimedia , vol. 26, pp. 3778–3787, 2024
2024
Closest in time.
X. Wang, H. Chen, P. Sun, J. Li, A. Zhang, W. Liu, and N. Jiang, “Advst: Generating unrestricted adversarial images via style transfer,” IEEE Transactions on Multimedia , vol. 26, pp. 4846–4858, 2024
2024
Closest in time.
Y. Sun, S. Yuan, X. Wang, L. Gao, and J. Song, “Any target can be offense: Adversarial example generation via generalized latent infection,” in ECCV , 2024
2024
Closest in time.