Fetching the paper…
Reading the bibliography…
Adversarial attacks in deep learning models, especially for safety-critical systems, are gaining more and more attention in recent years, due to the lack of trust in the security and robustness of AI models.
S. Lawrence, C. L. Giles, A. C. Tsoi, and A. D. Back, “Face recognition: A convolutional neural-network approach,” IEEE Trans Neural Netw
1997
Earlier work this paper cites.
C. Nebauer, “Evaluation of convolutional neural networks for visual recognition,” IEEE Trans Neural Netw
1998
Earlier work this paper cites.
Y. LeCun, P. Haffner, L. Bottou, and Y. Bengio, “Object recognition with gradient-based learning,” in Shape, contour and grouping in computer vision
1999
Earlier work this paper cites.
N. Dalal and B. Triggs, “Histograms of oriented gradients for human detection,” in CVPR
2005
Earlier work this paper cites.
J. Philbin, O. Chum, M. Isard, J. Sivic, and A. Zisserman, “Object retrieval with large vocabularies and fast spatial matching,” in CVPR
2007
Earlier work this paper cites.
M. Everingham, A. Zisserman, C. K. I. Williams, L. Van Gool, M. Allan, C. M. Bishop, O. Chapelle, N. Dalal, T. Deselaers, G. Dorkó, S. Duffner, J. Eichhorn, J. D. R. Farquhar, M. Fritz, C. Garcia, T. Griffiths, F. Jurie, D. Keysers, M. Koskela, J. Laaksonen, D. Larlus, B. Leibe, H. Meng, H. Ney, B. Schiele, C. Schmid, E. Seemann, J. Shawe-taylor, A. Storkey, O. Szedmak, B. Triggs, I. Ulusoy, V. Viitaniemi, and J. Zhang, “The pascal visual object classes challenge 2007 (voc2007) results,” 2008
2008
Earlier work this paper cites.
——, “Lost in quantization: Improving particular object retrieval in large scale image databases,” in CVPR
2008
Earlier work this paper cites.
G. B. Huang, M. Mattar, T. Berg, and E. Learned-Miller, “Labeled faces in the wild: A database forstudying face recognition in unconstrained environments,” in ECCV Workshops
2008
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in CVPR
2009
Earlier work this paper cites.
G. J. Brostow, J. Fauqueur, and R. Cipolla, “Semantic object classes in video: A high-definition ground truth database,” Pattern Recognit Lett
2009
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al
2009
Earlier work this paper cites.
M. Everingham, L. Van Gool, C. K. Williams, J. Winn, and A. Zisserman, “The pascal visual object classes (voc) challenge,” Int J Comput Vis
2010
Earlier work this paper cites.
T. Brox and J. Malik, “Large displacement optical flow: descriptor matching in variational motion estimation,” IEEE Trans Pattern Anal Mach Intell
2010
Earlier work this paper cites.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” in NIPS
2012
Earlier work this paper cites.
T. Tran, I. Aib, E. Al-Shaer, and R. Boutaba, “An evasive attack on snort flowbits,” in NOMS
2012
Earlier work this paper cites.
A. Mogelmose, M. M. Trivedi, and T. B. Moeslund, “Vision-based traffic sign detection and analysis for intelligent driver assistance systems: Perspectives and survey,” IEEE Trans Intell Transp Syst
2012
Earlier work this paper cites.
A. Geiger, P. Lenz, and R. Urtasun, “Are we ready for autonomous driving? the kitti vision benchmark suite,” in CVPR
2012
Earlier work this paper cites.
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, “Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition,” Neural Netw
2012
Earlier work this paper cites.
S. Houben, J. Stallkamp, J. Salmen, M. Schlipsing, and C. Igel, “Detection of traffic signs in real-world images: The german traffic sign detection benchmark,” in IJCNN
2013
Earlier work this paper cites.
A. Geiger, P. Lenz, C. Stiller, and R. Urtasun, “Vision meets robotics: The kitti dataset,” Int J Rob Res
2013
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in ICLR
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
R. Girshick, J. Donahue, T. Darrell, and J. Malik, “Rich feature hierarchies for accurate object detection and semantic segmentation,” in CVPR
2014
Earlier work this paper cites.
T.-Y. Lin, M. Maire, S. Belongie, J. Hays, P. Perona, D. Ramanan, P. Dollár, and C. L. Zitnick, “Microsoft coco: Common objects in context,” in ECCV
2014
Earlier work this paper cites.
A. Møgelmose, D. Liu, and M. M. Trivedi, “Traffic sign detection for us roads: Remaining challenges and a case for tracking,” in ITSC
2014
Earlier work this paper cites.
Y. Xiang, R. Mottaghi, and S. Savarese, “Beyond pascal: A benchmark for 3d object detection in the wild,” in WACV
2014
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Delving deep into rectifiers: Surpassing human-level performance on imagenet classification,” in ICCV
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
R. Girshick, “Fast r-cnn,” in ICCV
2015
Earlier work this paper cites.
S. Ren, K. He, R. Girshick, and J. Sun, “Faster r-cnn: Towards real-time object detection with region proposal networks,” in NIPS
2015
Earlier work this paper cites.
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein, A. C. Berg, and L. Fei-Fei, “Imagenet large scale visual recognition challenge,” Int J Comput Vis
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in ICLR
2015
Earlier work this paper cites.
Z. Xiao, Q. Liu, G. Tang, and X. Zhai, “Elliptic fourier transformation-based histograms of oriented gradients for rotationally invariant object detection in remote-sensing images,” Int J Remote Sens
2015
Earlier work this paper cites.
M. Everingham, S. Eslami, L. Van Gool, C. K. Williams, J. Winn, and A. Zisserman, “The pascal visual object classes challenge: A retrospective,” Int J Comput Vis
2015
Earlier work this paper cites.
A. Dosovitskiy, P. Fischer, E. Ilg, P. Hausser, C. Hazirbas, V. Golkov, P. Van Der Smagt, D. Cremers, and T. Brox, “Flownet: Learning optical flow with convolutional networks,” in ICCV
2015
Earlier work this paper cites.
J. Revaud, P. Weinzaepfel, Z. Harchaoui, and C. Schmid, “Epicflow: Edge-preserving interpolation of correspondences for optical flow,” in CVPR
2015
Earlier work this paper cites.
L. Zheng, L. Shen, L. Tian, S. Wang, J. Wang, and Q. Tian, “Scalable person re-identification: A benchmark,” in ICCV
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
Z. Liu, P. Luo, X. Wang, and X. Tang, “Deep learning face attributes in the wild,” in ICCV
2015
Earlier work this paper cites.
D. Ravi, C. Wong, B. Lo, and G.-Z. Yang, “Deep learning for human activity recognition: A resource efficient implementation on low-power devices,” in BSN
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: a simple and accurate method to fool deep neural networks,” in CVPR
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in EuroS&P
2016
Earlier work this paper cites.
J. Redmon, S. Divvala, R. Girshick, and A. Farhadi, “You only look once: Unified, real-time object detection,” in CVPR
2016
Earlier work this paper cites.
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in CVPR
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR
2016
Earlier work this paper cites.
G. Cheng, P. Zhou, and J. Han, “Learning rotation-invariant convolutional neural networks for object detection in vhr optical remote sensing images,” IEEE Trans Geosci Remote Sens
2016
Earlier work this paper cites.
M. Cordts, M. Omran, S. Ramos, T. Rehfeld, M. Enzweiler, R. Benenson, U. Franke, S. Roth, and B. Schiele, “The cityscapes dataset for semantic urban scene understanding,” in CVPR
2016
Earlier work this paper cites.
F. Radenović, G. Tolias, and O. Chum, “Cnn image retrieval learns from bow: Unsupervised fine-tuning with hard examples,” in ECCV
2016
Earlier work this paper cites.
X. Liu, W. Liu, H. Ma, and H. Fu, “Large-scale vehicle re-identification in urban surveillance videos,” in ICME
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
S. Sabour, N. Frosst, and G. E. Hinton, “Dynamic routing between capsules,” in NIPS
2017
Earlier work this paper cites.
Y.-h. Tian, X.-l. Chen, H.-k. Xiong, H.-l. Li, L.-r. Dai, J. Chen, J.-l. Xing, X.-h. Wu, W.-m. Hu, Y. Hu et al
2017
Earlier work this paper cites.
A. Botev, H. Ritter, and D. Barber, “Practical gauss-newton optimisation for deep learning,” in ICML
2017
Earlier work this paper cites.
T. Anthony, Z. Tian, and D. Barber, “Thinking fast and slow with deep learning and tree search,” in NIPS
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in SP
2017
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, “Practical black-box attacks against machine learning,” in ACM AsiaCCS
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
T. B. Brown, D. Mané, A. Roy, M. Abadi, and J. Gilmer, “Adversarial patch,” in NIPS Workshop
2017
Earlier work this paper cites.
F. Chollet, “Xception: Deep learning with depthwise separable convolutions,” in CVPR
2017
Earlier work this paper cites.
J. Redmon and A. Farhadi, “Yolo9000: Better, faster, stronger,” in CVPR
2017
Earlier work this paper cites.
S. Ren, K. He, R. Girshick, and J. Sun, “Faster r-cnn: Towards real-time object detection with region proposal networks,” IEEE Trans Pattern Anal Mach Intell
2017
Earlier work this paper cites.
A. Chaurasia and E. Culurciello, “Linknet: Exploiting encoder representations for efficient semantic segmentation,” in VCIP
2017
Earlier work this paper cites.
T.-Y. Lin, P. Dollár, R. Girshick, K. He, B. Hariharan, and S. Belongie, “Feature pyramid networks for object detection,” in CVPR
2017
Earlier work this paper cites.
H. Zhao, J. Shi, X. Qi, X. Wang, and J. Jia, “Pyramid scene parsing network,” in CVPR
2017
Earlier work this paper cites.
J. Uhrig, N. Schneider, L. Schneider, U. Franke, T. Brox, and A. Geiger, “Sparsity invariant cnns,” in 3DV
2017
Earlier work this paper cites.
E. Ilg, N. Mayer, T. Saikia, M. Keuper, A. Dosovitskiy, and T. Brox, “Flownet 2.0: Evolution of optical flow estimation with deep networks,” in CVPR
2017
Earlier work this paper cites.
A. Ranjan and M. J. Black, “Optical flow estimation using a spatial pyramid network,” in CVPR
2017
Earlier work this paper cites.
L. Zheng, H. Zhang, S. Sun, M. Chandraker, Y. Yang, and Q. Tian, “Person re-identification in the wild,” in CVPR
2017
Cited alongside, same era.
Z. Zheng, L. Zheng, and Y. Yang, “Unlabeled samples generated by gan improve the person re-identification baseline in vitro,” in ICCV
2017
Cited alongside, same era.
2017
Cited alongside, same era.
2017
Cited alongside, same era.
B. Zhou, A. Lapedriza, A. Khosla, A. Oliva, and A. Torralba, “Places: A 10 million image database for scene recognition,” IEEE Trans Pattern Anal Mach Intell
A. Kortylewski, Q. Liu, H. Wang, Z. Zhang, and A. Yuille, “Combining compositional models and deep networks for robust object classification under occlusion,” in WACV
2020
Later among the works it cites.
K. Xu, G. Zhang, S. Liu, Q. Fan, M. Sun, H. Chen, P.-Y. Chen, Y. Wang, and X. Lin, “Adversarial t-shirt! evading person detectors in a physical world,” in ECCV
2020
Later among the works it cites.
K. Ren, T. Zheng, Z. Qin, and X. Liu, “Adversarial attacks and defenses in deep learning,” Engineering
2020
Later among the works it cites.
A. Serban, E. Poll, and J. Visser, “Adversarial examples on object recognition: A comprehensive survey,” ACM Comput Surv
2020
Later among the works it cites.
R. den Hollander, A. Adhikari, I. Tolios, M. van Bekkum, A. Bal, S. Hendriks, M. Kruithof, D. Gross, N. Jansen, G. Perez, K. Buurman, and S. Raaijmakers, “Adversarial patch camouflage against aerial detection,” in SPIE
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2017
Cited alongside, same era.
C. Szegedy, S. Ioffe, V. Vanhoucke, and A. A. Alemi, “Inception-v4, inception-resnet and the impact of residual connections on learning,” in AAAI
2017
Cited alongside, same era.
C. Hubschneider, A. Bauer, M. Weber, and J. M. Zöllner, “Adding navigation to the equation: Turning decisions for end-to-end vehicle control,” in ITSC
2017
Cited alongside, same era.
A. Dosovitskiy, G. Ros, F. Codevilla, A. Lopez, and V. Koltun, “Carla: An open urban driving simulator,” in CoRL
2017
Cited alongside, same era.
2017
Cited alongside, same era.
D. Hendrycks and K. Gimpel, “A baseline for detecting misclassified and out-of-distribution examples in neural networks,” in ICLR
2017
Cited alongside, same era.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in CVPR
2017
Cited alongside, same era.
2017
Cited alongside, same era.
2020
Later among the works it cites.
K. Yamanaka, R. Matsumoto, K. Takahashi, and T. Fujii, “Adversarial patch attacks on monocular depth estimation networks,” IEEE Access
2020
Later among the works it cites.
A. Chindaudom, P. Siritanawan, K. Sumongkayothin, and K. Kotani, “Adversarialqr: An adversarial patch in qr code format,” in Joint ICIEV & icIVPR
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
C. Ertler, J. Mislej, T. Ollmann, L. Porzi, G. Neuhold, and Y. Kuang, “The mapillary traffic sign dataset for detection and classification on a global scale,” in ECCV
2020
Later among the works it cites.
F. Yu, H. Chen, X. Wang, W. Xian, Y. Chen, F. Liu, V. Madhavan, and T. Darrell, “Bdd100k: A diverse driving dataset for heterogeneous multitask learning,” in CVPR
2020
Later among the works it cites.
G. Zhao, M. Zhang, J. Liu, Y. Li, and J.-R. Wen, “Ap-gan: Adversarial patch attack on content-based image retrieval systems,” Geoinformatica
2020
Later among the works it cites.
E. Chou, F. Tramer, and G. Pellegrino, “Sentinet: Detecting localized universal attacks against deep learning systems,” in SP Workshops
2020
Later among the works it cites.
T. Gittings, S. Schneider, and J. Collomosse, “Vax-a-net: Training-time defence against adversarial patch attacks,” in ACCV
2020
Later among the works it cites.
S. Rao, D. Stutz, and B. Schiele, “Adversarial training against location-optimized adversarial patches,” in ECCV
2020
Later among the works it cites.
2020
Later among the works it cites.
A. Levine and S. Feizi, “(De) randomized smoothing for certifiable defense against patch attacks,” in NeurIPS
2020
Later among the works it cites.
P.-y. Chiang, R. Ni, A. Abdelkader, C. Zhu, C. Studer, and T. Goldstein, “Certified defenses for adversarial patches,” in ICLR
2020
Later among the works it cites.
S. Pavlitskaya, S. Ünver, and J. M. Zöllner, “Feasibility and suppression of adversarial patch attacks on end-to-end vehicle control,” in ITSC
2020
Later among the works it cites.
M. McCoyd, W. Park, S. Chen, N. Shah, R. Roggenkemper, M. Hwang, J. X. Liu, and D. Wagner, “Minority reports defense: Defending against adversarial patches,” in ACNS
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
C. Yang, A. Kortylewski, C. Xie, Y. Cao, and A. Yuille, “Patchattack: A black-box texture-based attack with reinforcement learning,” in ECCV
2020
Later among the works it cites.
2020
Later among the works it cites.
H. Zhang, H. Chen, C. Xiao, S. Gowal, R. Stanforth, B. Li, D. Boning, and C.-J. Hsieh, “Towards stable and efficient training of verifiably robust neural networks,” in ICLR
2020
Later among the works it cites.
A. Levine and S. Feizi, “Robustness certificates for sparse adversarial attacks by randomized ablation,” in AAAI
2020
Later among the works it cites.
K. H. Løkken, L. Aurdal, A. Brattli, and H. C. Palm, “Investigating robustness of adversarial camouflage (ac) for naval vessels,” in SPIE
2020
Later among the works it cites.
A. Kortylewski, J. He, Q. Liu, and A. L. Yuille, “Compositional convolutional neural networks: A deep architecture with innate robustness to partial occlusion,” in CVPR
2020
Later among the works it cites.
X. Chen, W. Wang, C. Bender, Y. Ding, R. Jia, B. Li, and D. Song, “Refit: a unified watermark removal framework for deep learning systems with limited data,” in ACM AsiaCCS
2021
Later among the works it cites.
G. Karmakar, A. Chowdhury, R. Das, J. Kamruzzaman, and S. Islam, “Assessing trust level of a driverless car using deep learning,” IEEE Trans Intell Transp Syst
2021
Later among the works it cites.
W. J. von Eschenbach, “Transparency and the black box problem: Why we do not trust ai,” Philos Technol
2021
Later among the works it cites.
2021
Later among the works it cites.
A. Zolfi, M. Kravchik, Y. Elovici, and A. Shabtai, “The translucent patch: A physical and universal attack on object detectors,” in CVPR
2021
Later among the works it cites.
N. Akhtar, A. Mian, N. Kardan, and M. Shah, “Advances in adversarial attacks and defenses in computer vision: A survey,” IEEE Access
2021
Later among the works it cites.
C. Zhang, P. Benz, C. Lin, A. Karjauv, J. Wu, and I. S. Kweon, “A survey on universal adversarial attack,” in IJCAI
2021
Later among the works it cites.
G. R. Machado, E. Silva, and R. R. Goldschmidt, “Adversarial machine learning in image classification: A survey toward the defender’s perspective,” ACM Comput Surv
2021
Later among the works it cites.
2021
Later among the works it cites.
Y. Mirsky, “Ipatch: A remote adversarial patch,” arXiv preprint arXiv:2105.00113
2021
Later among the works it cites.
X. Zhou, Z. Pan, Y. Duan, J. Zhang, and S. Wang, “A data independent approach to generate adversarial patches,” Mach Vis Appl
2021
Later among the works it cites.
M. Lu, Q. Li, L. Chen, and H. Li, “Scale-adaptive adversarial patch attack for remote sensing image aircraft detection,” Remote Sens
2021
Later among the works it cites.
H. Huang, Y. Wang, Z. Chen, Z. Tang, W. Zhang, and K.-K. Ma, “Rpattack: Refined patch attack on general object detectors,” in ICME
2021
Later among the works it cites.
Y. Wang, H. Lv, X. Kuang, G. Zhao, Y.-a. Tan, Q. Zhang, and J. Hu, “Towards a physical-world adversarial patch for blinding object detection models,” Inf Sci
2021
Later among the works it cites.
D. Lang, D. Chen, R. Shi, and Y. He, “Attention-guided digital adversarial patches on visual detection,” Secur Commun Netw
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
——, “PatchGuard: A provably robust defense against adversarial patches via small receptive fields and masking,” in USENIX Security
2021
Later among the works it cites.
2021
Later among the works it cites.
C. Xiang and P. Mittal, “Detectorguard: Provably securing object detectors against localized patch hiding attacks,” in CCS
2021
Later among the works it cites.
C.-Y. Wang, A. Bochkovskiy, and H.-Y. M. Liao, “Scaled-yolov4: Scaling cross stage partial network,” in CVPR
2021
Later among the works it cites.
W.-Y. Lin, F. Sheikholeslami, jinghao shi, L. Rice, and J. Z. Kolter, “Certified robustness against physically-realizable patch attack via randomized cropping,” 2021. [Online]. Available: https://openreview.net/forum?id=vttv9ADGuWF
2021
Later among the works it cites.
J. H. Metzen and M. Yatsura, “Efficient certified defenses against patch attacks on image classifiers,” in ICLR
2021
Later among the works it cites.
2021
Later among the works it cites.
A. Kortylewski, Q. Liu, A. Wang, Y. Sun, and A. Yuille, “Compositional convolutional neural networks: A robust and interpretable model for object recognition under occlusion,” Int J Comput Vis
2021
Later among the works it cites.
A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, X. Zhai, T. Unterthiner, M. Dehghani, M. Minderer, G. Heigold, S. Gelly, J. Uszkoreit, and N. Houlsby, “An image is worth 16x16 words: Transformers for image recognition at scale,” in ICLR
2021
Later among the works it cites.
2021
Later among the works it cites.
M. Lennon, N. Drenkow, and P. Burlina, “Patch attack invariance: How sensitive are patch attacks to 3d pose?” in ICCV
2021
Later among the works it cites.
——, “Surreptitious adversarial examples through functioning qr code,” J Imaging
2022
Closest in time.
V. Yadav, “p2-trafficsigns,” Website, 2017, accessed on May 30, 2022. [Online]. Available: https://github.com/vxy10/p2-TrafficSigns
2022
Closest in time.
J. Jongejan et al
2022
Closest in time.
G. Jocher, A. Stoken, J. Borovec et al
2022
Closest in time.
F. Nesti, G. Rossolini, S. Nair, A. Biondi, and G. Buttazzo, “Evaluating the robustness of semantic segmentation for autonomous driving against real-world adversarial patch attacks,” in WACV
2022
Closest in time.
J. Howard, K. Turgutlu, L. Wright, T. Abraham, H. Husain, Y. Liu, V. Tran, J. Varty, R. Osmulski, Nirant, A. Shaw, P. Butterfill, D. Mishkin, B. Dwyer, M. S. Z. Rizvi, and S. Doria, “Imagenette by fast.ai,” Website, 2021, accessed on June 2, 2022. [Online]. Available: https://github.com/fastai/imagenette
2022
Closest in time.
C. Deotte, “How to choose cnn architecture mnist,” Website, 2018, accessed on June 3, 2022. [Online]. Available: https://www.kaggle.com/code/cdeotte/how-to-choose-cnn-architecture-mnist/notebook
2022
Closest in time.
R. Wightman et al
2022
Closest in time.