Fetching the paper…
Reading the bibliography…
To explore the vulnerability of deep neural networks (DNNs), many attack paradigms have been well studied, such as the poisoning-based backdoor attack in the training stage and the adversarial attack in the inference stage.
R. Glowinski and A. Marroco, “Sur l’approximation, par éléments finis d’ordre un, et la résolution, par pénalisation-dualité d’une classe de problèmes de dirichlet non linéaires,” ESAIM: Mathematical Modelling and Numerical Analysis-Modélisation Mathématique et Analyse Numérique , vol. 9, no. R2, pp. 41–76, 1975
1975
Earlier work this paper cites.
D. Gabay and B. Mercier, “A dual algorithm for the solution of nonlinear variational problems via finite element approximation,” Computers & mathematics with applications , vol. 2, no. 1, pp. 17–40, 1976
1976
Earlier work this paper cites.
E. G. Gol’shtein and N. Tret’yakov, “Modified lagrangians in convex programming and their generalizations,” in Point-to-Set Maps and Mathematical Programming . Springer, 1979, pp. 86–97
1979
Earlier work this paper cites.
J. Eckstein and D. P. Bertsekas, “On the douglas—rachford splitting method and the proximal point algorithm for maximal monotone operators,” Mathematical Programming , vol. 55, no. 1-3, pp. 293–318, 1992
1992
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” Technical report , 2009
2009
Earlier work this paper cites.
M. Agoyan, J.-M. Dutertre, A.-P. Mirbaha, D. Naccache, A.-L. Ribotta, and A. Tria, “How to flip a bit?” in IOLTS , 2010
2010
Earlier work this paper cites.
S. Boyd, N. Parikh, and E. Chu, Distributed optimization and statistical learning via the alternating direction method of multipliers . Now Publishers Inc, 2011
2011
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in ICLR , 2014
2014
Earlier work this paper cites.
Y. Kim, R. Daly, J. Kim, C. Fallin, J. H. Lee, D. Lee, C. Wilkerson, K. Lai, and O. Mutlu, “Flipping bits in memory without accessing them: An experimental study of dram disturbance errors,” ACM SIGARCH Computer Architecture News , vol. 42, no. 3, pp. 361–372, 2014
2014
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in ICLR , 2015
2015
Earlier work this paper cites.
B. Selmke, S. Brummer, J. Heyszl, and G. Sigl, “Precise laser fault injections into 90 nm and 45 nm sram-cells,” in CARDIS , 2015
2015
Earlier work this paper cites.
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein et al. , “Imagenet large scale visual recognition challenge,” International journal of computer vision , vol. 115, no. 3, pp. 211–252, 2015
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in ICLR , 2015
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
S. Levine, C. Finn, T. Darrell, and P. Abbeel, “End-to-end training of deep visuomotor policies,” The Journal of Machine Learning Research , vol. 17, no. 1, pp. 1334–1373, 2016
2016
Earlier work this paper cites.
V. Van Der Veen, Y. Fratantonio, M. Lindorfer, D. Gruss, C. Maurice, G. Vigna, H. Bos, K. Razavi, and C. Giuffrida, “Drammer: Deterministic rowhammer attacks on mobile platforms,” in CCS , 2016
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in CVPR , 2017
2017
Earlier work this paper cites.
W. Xu, D. Evans, and Y. Qi, “Feature squeezing: Detecting adversarial examples in deep neural networks,” NDSS , 2017
2017
Earlier work this paper cites.
Y. Liu, Y. Xie, and A. Srivastava, “Neural trojans,” in ICCD , 2017
2017
Earlier work this paper cites.
Y. Liu, L. Wei, B. Luo, and Q. Xu, “Fault injection attack on deep neural network,” in ICCAD , 2017
2017
Earlier work this paper cites.
S. Migacz, “8-bit inference with tensorrt,” in GPU technology conference , 2017
2017
Earlier work this paper cites.
B. Zhang, D. Xiong, and J. Su, “Neural machine translation with deep attention,” IEEE transactions on pattern analysis and machine intelligence , vol. 42, no. 1, pp. 154–163, 2018
2018
Earlier work this paper cites.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust physical-world attacks on deep learning visual classification,” in CVPR , 2018
2018
Earlier work this paper cites.
J. Breier, X. Hou, D. Jap, L. Ma, S. Bhasin, and Y. Liu, “Practical fault attack on deep neural networks,” in CCS , 2018
2018
Earlier work this paper cites.
B. Wu and B. Ghanem, “ ℓ p \ell_{p} -box admm: A versatile framework for integer programming,” IEEE transactions on pattern analysis and machine intelligence , vol. 41, no. 7, pp. 1695–1708, 2018
2018
Earlier work this paper cites.
N. Akhtar and A. Mian, “Threat of adversarial attacks on deep learning in computer vision: A survey,” IEEE Access , vol. 6, pp. 14 410–14 430, 2018
2018
Cited alongside, same era.
K. R. Mopuri, A. Ganeshan, and R. V. Babu, “Generalizable data-free objective for crafting universal adversarial perturbations,” IEEE transactions on pattern analysis and machine intelligence , vol. 41, no. 10, pp. 2452–2465, 2018
2018
Cited alongside, same era.
C. Xie, J. Wang, Z. Zhang, Z. Ren, and A. Yuille, “Mitigating adversarial effects through randomization,” ICLR , 2018
2018
Cited alongside, same era.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in RAID , 2018
2018
Cited alongside, same era.
Y. Liu, S. Ma, Y. Aafer, W. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in NDSS , 2018
A. Saha, A. Subramanya, and H. Pirsiavash, “Hidden trigger backdoor attacks,” in AAAI , 2020
2020
Later among the works it cites.
A. S. Rakin, Z. He, and D. Fan, “Tbt: Targeted neural network attack with bit trojan,” in CVPR , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
D. Wu, Y. Wang, S.-T. Xia, J. Bailey, and X. Ma, “Skip connections matter: On the transferability of adversarial examples generated with resnets,” in ICLR , 2020
2020
Later among the works it cites.
W. Chen, Z. Zhang, X. Hu, and B. Wu, “Boosting decision-based black-box adversarial attacks with random sign flip,” in ECCV , 2020
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
Y. Ji, X. Zhang, S. Ji, X. Luo, and T. Wang, “Model-reuse attacks on deep learning systems,” in CCS , 2018
2018
Cited alongside, same era.
D. Gruss, M. Lipp, M. Schwarz, D. Genkin, J. Juffinger, S. O’Connell, W. Schoechl, and Y. Yarom, “Another flip in the wall of rowhammer defenses,” in IEEE S&P , 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,” IEEE Access , vol. 7, pp. 47 230–47 244, 2019
2019
Cited alongside, same era.
Y. Dong, H. Su, B. Wu, Z. Li, W. Liu, T. Zhang, and J. Zhu, “Efficient decision-based black-box adversarial attacks on face recognition,” in CVPR , 2019
2019
Cited alongside, same era.
S. G. Finlayson, J. D. Bowers, J. Ito, J. L. Zittrain, A. L. Beam, and I. S. Kohane, “Adversarial attacks on medical machine learning,” Science , vol. 363, no. 6433, pp. 1287–1289, 2019
2019
Cited alongside, same era.
A. Arnab, O. Miksik, and P. H. Torr, “On the robustness of semantic segmentation models to adversarial attacks,” IEEE Transactions on Pattern Analysis and Machine Intelligence , vol. 42, no. 12, pp. 3040–3053, 2019
2019
Cited alongside, same era.
M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein, “Square attack: a query-efficient black-box adversarial attack via random search,” in ECCV , 2020
2020
Later among the works it cites.
J. Bai, B. Chen, Y. Li, D. Wu, W. Guo, S.-t. Xia, and E.-h. Yang, “Targeted attack for deep hashing based retrieval,” in ECCV , 2020
2020
Later among the works it cites.
S. Bai, Y. Li, Y. Zhou, Q. Li, and P. H. Torr, “Adversarial metric attack and defense for person re-identification,” IEEE Transactions on Pattern Analysis and Machine Intelligence , 2020
2020
Later among the works it cites.
Y. Liu, A. Mondal, A. Chakraborty, M. Zuzak, N. Jacobsen, D. Xing, and A. Srivastava, “A survey on neural trojans.” in ISQED , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” ECCV , 2020
2020
Later among the works it cites.
S. Zhao, X. Ma, X. Zheng, J. Bailey, J. Chen, and Y.-G. Jiang, “Clean-label backdoor attacks on video recognition models,” in CVPR , 2020
2020
Later among the works it cites.
A. Nguyen and A. Tran, “Input-aware dynamic backdoor attack,” in NeurIPS , 2020
2020
Later among the works it cites.
T.-W. Weng, P. Zhao, S. Liu, P.-Y. Chen, X. Lin, and L. Daniel, “Towards certificated model robustness against weight perturbations,” in AAAI , 2020
2020
Later among the works it cites.
Z. He, A. S. Rakin, J. Li, C. Chakrabarti, and D. Fan, “Defending and harnessing the bit-flip based adversarial weight attack,” in CVPR , 2020
2020
Later among the works it cites.
J. Li, A. S. Rakin, Y. Xiong, L. Chang, Z. He, D. Fan, and C. Chakrabarti, “Defending bit-flip attack through dnn weight reconstruction,” in ACM DAC , 2020
2020
Later among the works it cites.
K. Huang, P. H. Siegel, and A. A. Jiang, “Functional error correction for reliable neural networks,” in ISIT , 2020
2020
Later among the works it cites.
B. Wu, L. Shen, T. Zhang, and B. Ghanem, “Map inference via l2-sphere linear program reformulation,” International Journal of Computer Vision , pp. 1–24, 2020
2020
Later among the works it cites.
Y. Fan, B. Wu, T. Li, Y. Zhang, M. Li, Z. Li, and Y. Yang, “Sparse adversarial attack via perturbation factorization,” in ECCV , 2020
2020
Later among the works it cites.
J. Bai, B. Wu, Y. Zhang, Y. Li, Z. Li, and S.-T. Xia, “Targeted attack against deep neural networks via flipping limited weight bits,” in ICLR , 2021
2021
Later among the works it cites.
T. A. Nguyen and A. T. Tran, “Wanet - imperceptible warping-based backdoor attack,” in ICLR , 2021
2021
Later among the works it cites.
D. Stutz, N. Chandramoorthy, M. Hein, and B. Schiele, “Bit error robustness for energy-efficient dnn accelerators,” in MLSys , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
X. Sun, Z. Zhang, X. Ren, R. Luo, and L. Li, “Exploring the vulnerability of deep neural networks: A study of parameter corruption,” in AAAI , 2021
2021
Later among the works it cites.