Fetching the paper…
Reading the bibliography…
The problem of adversarial defenses for image classification, where the goal is to robustify a classifier against adversarial examples, is considered.
Relations between the statistics of natural images and the response properties of cortical cells
David J. Field · 1987
Earlier work this paper cites.
What is the goal of sensory coding?
David J. Field · 1994
Earlier work this paper cites.
The statistics of natural images
Daniel L. Ruderman · 1994
Earlier work this paper cites.
Emergence of simple-cell receptive field properties by learning a sparse code for natural images
Bruno A. Olshausen and David J. Field · 1996
Earlier work this paper cites.
The “independent components” of natural scenes are edge filters
Anthony J. Bell and Terrence J. Sejnowski · 1997
Earlier work this paper cites.
Statistics of natural images and models
Jinggang Huang and D. Mumford · 1999
Earlier work this paper cites.
The exploitation of regularities in the environment by the brain
H. B. Barlow · 2001
Earlier work this paper cites.
Natural image statistics and neural representation
Eero P. Simoncelli and Bruno A. Olshausen · 2001
Earlier work this paper cites.
Statistics of natural image categories
Antonio Torralba and Aude Oliva · 2003
Earlier work this paper cites.
On advances in statistical modeling of natural images
A. Srivastava, A. B. Lee, Eero P. Simoncelli, and S.-C. Zhu · 2004
Earlier work this paper cites.
Statistical regularities of art images and natural scenes: spectra, sparseness and nonlinearities
Daniel J. Graham and David J. Field · 2007
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Natural image statistics and low-complexity feature selection
Manuela Vasconcelos and Nuno Vasconcelos · 2009
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Understanding deep image representations by inverting them
Aravindh Mahendran and Andrea Vedaldi · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
A study of the effect of jpg compression on adversarial images
Gintare Karolina Dziugaite, Zoubin Ghahramani, and Daniel M. Roy · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, X. Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Deepfool: A simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna · 2016
Earlier work this paper cites.
Pixel recurrent neural networks
Aäron van den Oord, Nal Kalchbrenner, and Koray Kavukcuoglu · 2016
Earlier work this paper cites.
Wide residual networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression
Nilaksh Das, Madhuri Shanbhogue, Shang-Tse Chen, Fred Hohman, Li Chen, Michael E. Kounavis, and Duen Horng Chau · 2017
Earlier work this paper cites.
Pixelcnn models with auxiliary variables for natural image modeling
Alexander Kolesnikov and Christoph H. Lampert · 2017
Earlier work this paper cites.
Openimages: A public dataset for large-scale multi-label and multi-class image classification
Ivan Krasin, Tom Duerig, Neil Alldrin, Vittorio Ferrari, Sami Abu-El-Haija, Alina Kuznetsova, Hassan Rom, Jasper Uijlings, Stefan Popov, Andreas Veit, Serge Belongie, Victor Gomes, Abhinav Gupta, Chen Sun, Gal Chechik, David Cai, Zheyun Feng, Dhyanesh Narayanan, and Kevin Murphy · 2017
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
Generative adversarial trainer: Defense to adversarial perturbations with gan
Hyeungill Lee, Sungyeob Han, and Jungwoo Lee · 2017
Earlier work this paper cites.
Enhanced deep residual networks for single image super-resolution
Bee Lim, Sanghyun Son, Heewon Kim, Seungjun Nah, and Kyoung Mu Lee · 2017
Earlier work this paper cites.
Magnet: A two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Earlier work this paper cites.
Plug & play generative networks: Conditional iterative generation of images in latent space
Anh M Nguyen, Jeff Clune, Yoshua Bengio, Alexey Dosovitskiy, and Jason Yosinski · 2017
Earlier work this paper cites.
No bot expects the deepcaptcha! introducing immutable adversarial examples, with applications to captcha generation
Margarita Osadchy, Julio Hernandez-Castro, Stuart Gibson, Orr Dunkelman, and Daniel Pérez-Cabo · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
Tim Salimans, Andrej Karpathy, Xi Chen, and Diederik P. Kingma · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David A. Wagner · 2018
Earlier work this paper cites.
Adversarial attacks and defences: A survey
Anirban Chakraborty, Manaar Alam, Vishal Dey, Anupam Chattopadhyay, and Debdeep Mukhopadhyay · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Earlier work this paper cites.
Adversarial spheres, 2018
Justin Gilmer, Luke Metz, Fartash Faghri, Sam Schoenholz, Maithra Raghu, Martin Wattenberg, and Ian Goodfellow · 2018
Earlier work this paper cites.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten · 2018
Earlier work this paper cites.
Squeeze-and-excitation networks
Jie Hu, Li Shen, and Gang Sun · 2018
Earlier work this paper cites.
Detecting adversarial examples using data manifolds
Susmit Jha, Uyeong Jang, Somesh Jha, and Brian Jalaian · 2018
Earlier work this paper cites.
On the geometry of adversarial examples
Marc Khoury and Dylan Hadfield-Menell · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Adversarial attacks and defenses against deep neural networks: A survey
Mesut Ozdag · 2018
Earlier work this paper cites.
Deflecting adversarial attacks with pixel deflection
Aaditya Prakash, Nick Moran, Solomon Garber, Antonella DiLillo, and James A. Storer · 2018
Earlier work this paper cites.
Defense-GAN: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Earlier work this paper cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Earlier work this paper cites.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel · 2018
Earlier work this paper cites.
Mitigating adversarial effects through randomization
Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille · 2018
Earlier work this paper cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Earlier work this paper cites.
Are labels required for improving adversarial robustness?
Jean-Baptiste Alayrac, Jonathan Uesato, Po-Sen Huang, Alhussein Fawzi, Robert Stanforth, and Pushmeet Kohli · 2019
Earlier work this paper cites.
Controlling neural level sets
Matan Atzmon, Niv Haim, Lior Yariv, Ofer Israelov, Haggai Maron, and Yaron Lipman · 2019
Earlier work this paper cites.
Hilbert-based generative defense for adversarial examples
Yang Bai, Yan Feng, Yisen Wang, Tao Dai, Shutao Xia, and Yong Jiang · 2019
Earlier work this paper cites.
Large scale GAN training for high fidelity natural image synthesis
Andrew Brock, Jeff Donahue, and Karen Simonyan · 2019
Earlier work this paper cites.
Large scale gan training for high fidelity natural image synthesis
Andrew Brock, Jeff Donahue, and Karen Simonyan · 2019
Earlier work this paper cites.
Unlabeled data improves adversarial robustness
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, John C Duchi, and Percy S Liang · 2019
Earlier work this paper cites.
Learning implicit fields for generative shape modeling
Zhiqin Chen and Hao Zhang · 2019
Earlier work this paper cites.
Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks
Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli · 2019
Earlier work this paper cites.
Evading defenses to transferable adversarial examples by translation-invariant attacks
Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Cited alongside, same era.
Robustness (python library), 2019
Logan Engstrom, Andrew Ilyas, Hadi Salman, Shibani Santurkar, and Dimitris Tsipras · 2019
Cited alongside, same era.
Using pre-training can improve model robustness and uncertainty
Dan Hendrycks, Kimin Lee, and Mantas Mazeika · 2019
Cited alongside, same era.
Catastrophic child’s play: Easy to perform, hard to defend adversarial attacks
Chih-Hui Ho, Brandon Leung, Erik Sandström, Yen Chang, and Nuno Vasconcelos · 2019
Cited alongside, same era.
Adversarial defense via learning to generate diverse attacks
Yunseok Jang, Tianchen Zhao, Seunghoon Hong, and Honglak Lee · 2019
Cited alongside, same era.
Comdefend: An efficient image compression model to defend adversarial examples
Implicit neural representations with periodic activation functions
Vincent Sitzmann, Julien N. P. Martel, Alexander W. Bergman, David B. Lindell, and Gordon Wetzstein · 2020
Later among the works it cites.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry · 2020
Later among the works it cites.
Improving adversarial robustness requires revisiting misclassified examples
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Later among the works it cites.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Xiaojun Jia, Xingxing Wei, Xiaochun Cao, and Hassan Foroosh · 2019
Cited alongside, same era.
A style-based generator architecture for generative adversarial networks
Tero Karras, Samuli Laine, and Timo Aila · 2019
Cited alongside, same era.
Functional adversarial attacks
Cassidy Laidlaw and Soheil Feizi · 2019
Cited alongside, same era.
Adv-BNN: Improved adversarial defense through robust bayesian neural network
Xuanqing Liu, Yao Li, Chongruo Wu, and Cho-Jui Hsieh · 2019
Cited alongside, same era.
Feature distillation: Dnn-oriented jpeg compression against adversarial examples
Zihao Liu, Qi Liu, Tao Liu, Yanzhi Wang, and Wujie Wen · 2019
Cited alongside, same era.
Metric learning for adversarial robustness
Chengzhi Mao, Ziyuan Zhong, Junfeng Yang, Carl Vondrick, and Baishakhi Ray · 2019
Cited alongside, same era.
Occupancy networks: Learning 3d reconstruction in function space
Lars M. Mescheder, Michael Oechsle, Michael Niemeyer, Sebastian Nowozin, and Andreas Geiger · 2019
Cited alongside, same era.
Skip connections matter: On the transferability of adversarial examples generated with resnets
Dongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey, and Xingjun Ma · 2020
Later among the works it cites.
Adversarial weight perturbation helps robust generalization
Dongxian Wu, Shu-Tao Xia, and Yisen Wang · 2020
Later among the works it cites.
If-defense: 3d adversarial point cloud defense via implicit function based restoration
Ziyi Wu, Yueqi Duan, He Wang, Qingnan Fan, and Leonidas J. Guibas · 2020
Later among the works it cites.
Enhancing adversarial defense by k-winners-take-all
Chang Xiao, Peilin Zhong, and Changxi Zheng · 2020
Later among the works it cites.
Dreaming to distill: Data-free knowledge transfer via deepinversion
Hongxu Yin, Pavlo Molchanov, Zhizhong Li, José Manuel Álvarez, Arun Mallya, Derek Hoiem, Niraj Kumar Jha, and Jan Kautz · 2020
Later among the works it cites.
Gat: Generative adversarial training for adversarial example detection and robust classification
Xuwang Yin, Soheil Kolouri, and Gustavo K Rohde · 2020
Later among the works it cites.
Ensemble generative cleaning with feedback loops for defending adversarial attacks
Jianhe Yuan and Zhihai He · 2020
Later among the works it cites.
Adversarial interpolation training: A simple approach for improving model robustness, 2020
Haichao Zhang and Wei Xu · 2020
Later among the works it cites.
Towards stable and efficient training of verifiably robust neural networks
Huan Zhang, Hongge Chen, Chaowei Xiao, Sven Gowal, Robert Stanforth, Bo Li, Duane Boning, and Cho-Jui Hsieh · 2020
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2020
Later among the works it cites.
Manifold projection for adversarial defense on face recognition
Jianli Zhou, Chao Liang, and Jun Chen · 2020
Later among the works it cites.
Towards achieving adversarial robustness beyond perceptual limits
Sravanti Addepalli, Samyak Jain, Gaurang Sriramanan, Shivangi Khare, and Venkatesh Babu Radhakrishnan · 2021
Later among the works it cites.
Towards achieving adversarial robustness beyond perceptual limits
Sravanti Addepalli, Samyak Jain, Gaurang Sriramanan, Shivangi Khare, and Venkatesh Babu Radhakrishnan · 2021
Later among the works it cites.
Advances in adversarial attacks and defenses in computer vision: A survey
Naveed Akhtar, Ajmal Mian, Navid Kardan, and Mubarak Shah · 2021
Later among the works it cites.
Ltd: Low temperature distillation for robust adversarial training, 2021
Erh-Chung Chen and Che-Rung Lee · 2021
Later among the works it cites.
Efficient robust training via backward smoothing, 2021
Jinghui Chen, Yu Cheng, Zhe Gan, Quanquan Gu, and Jingjing Liu · 2021
Later among the works it cites.
Learning continuous image representation with local implicit image function
Yinbo Chen, Sifei Liu, and Xiaolong Wang · 2021
Later among the works it cites.
RobustBench: a standardized adversarial robustness benchmark
Francesco Croce, Maksym Andriushchenko, Vikash Sehwag, Edoardo Debenedetti, Nicolas Flammarion, Mung Chiang, Prateek Mittal, and Matthias Hein · 2021
Later among the works it cites.
Learnable boundary guided adversarial training
Jiequan Cui, Shu Liu, Liwei Wang, and Jiaya Jia · 2021
Later among the works it cites.
Parameterizing activation functions for adversarial robustness
Sihui Dai, Saeed Mahloujifar, and Prateek Mittal · 2021
Later among the works it cites.
COIN: COmpression with implicit neural representations
Emilien Dupont, Adam Golinski, Milad Alizadeh, Yee Whye Teh, and Arnaud Doucet · 2021
Later among the works it cites.
Improving robustness using generated data
Sven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg, Dan Andrei Calian, and Timothy A Mann · 2021
Later among the works it cites.
Ad-nerf: Audio driven neural radiance fields for talking head synthesis
Yudong Guo, Keyu Chen, Sen Liang, Yongjin Liu, Hujun Bao, and Juyong Zhang · 2021
Later among the works it cites.
Naturalistic physical adversarial patch for object detectors
Yu-Chih-Tuan Hu, Bo-Han Kung, Daniel Stanley Tan, Jun-Cheng Chen, Kai-Lung Hua, and Wen-Huang Cheng · 2021
Later among the works it cites.
Exploring architectural ingredients of adversarially robust deep neural networks
Hanxun Huang, Yisen Wang, Sarah Monazam Erfani, Quanquan Gu, James Bailey, and Xingjun Ma · 2021
Later among the works it cites.
Manifold regularization for locally stable deep neural networks, 2021
Charles Jin and Martin Rinard · 2021
Later among the works it cites.
Stable neural ODE with lyapunov-stable equilibrium points for defending against adversarial attacks
QIYU KANG, Yang Song, Qinxu Ding, and Wee Peng Tay · 2021
Later among the works it cites.
Alias-free generative adversarial networks
Tero Karras, Miika Aittala, Samuli Laine, Erik Harkonen, Janne Hellsten, Jaakko Lehtinen, and Timo Aila · 2021
Later among the works it cites.
Dnr: A tunable robust pruning framework through dynamic network rewiring of dnns
Souvik Kundu, Mahdi Nazemi, Peter A. Beerel, and Massoud Pedram · 2021
Later among the works it cites.
Exploring adversarial fake images on face manifold
Dongze Li, Wei Wang, Hongxing Fan, and Jing Dong · 2021
Later among the works it cites.
Adversarial attacks are reversible with natural supervision
Chengzhi Mao, Mia Chiquier, Hao Wang, Junfeng Yang, and Carl Vondrick · 2021
Later among the works it cites.
Bag of tricks for adversarial training
Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu · 2021
Later among the works it cites.
Helper-based adversarial training: Reducing excessive margin to achieve a better accuracy vs. robustness trade-off
Rahul Rade and Seyed-Mohsen Moosavi-Dezfooli · 2021
Later among the works it cites.
Fixing data augmentation to improve adversarial robustness
Sylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg, Olivia Wiles, and Timothy A. Mann · 2021
Later among the works it cites.
Adversarial transfer attacks with unknown data and class overlap
Luke E. Richards, André T. Nguyen, Ryan Capps, Steven Forsyth, Cynthia Matuszek, and Edward Raff · 2021
Later among the works it cites.
Exploring misclassifications of robust neural networks to enhance adversarial attacks
Leo Schwinn, René Raab, An Nguyen, Dario Zanca, and Bjoern M. Eskofier · 2021
Later among the works it cites.
Robust learning via persistency of excitation
Kaustubh Sridhar, Oleg Sokolsky, Insup Lee, and James Weimer · 2021
Later among the works it cites.
Imagine: Image synthesis by image-guided model inversion
Pei Wang, Yijun Li, Krishna Kumar Singh, Jingwan Lu, and Nuno Vasconcelos · 2021
Later among the works it cites.
Enhancing the transferability of adversarial attacks through variance tuning
Xiaosen Wang and Kun He · 2021
Later among the works it cites.
Admix: Enhancing the transferability of adversarial attacks
Xiaosen Wang, Xu He, Jingdong Wang, and Kun He · 2021
Later among the works it cites.
Do wider neural networks really help adversarial robustness?
Boxi Wu, Jinghui Chen, Deng Cai, Xiaofei He, and Quanquan Gu · 2021
Later among the works it cites.
Adversarial purification with score-based generative models
Jongmin Yoon, Sung Ju Hwang, and Juho Lee · 2021
Later among the works it cites.
Geometry-aware instance-reweighted adversarial training
Jingfeng Zhang, Jianing Zhu, Gang Niu, Bo Han, Masashi Sugiyama, and Mohan Kankanhalli · 2021
Later among the works it cites.
Towards lightweight controllable audio synthesis with conditional implicit neural representations
Jan Zuiderveld, Marco Federici, and Erik J Bekkers · 2021
Later among the works it cites.
Combating adversaries with anti-adversaries
Motasem Alfarra, Juan C. Perez, Ali Thabet, Adel Bibi, Philip H.S. Torr, and Bernard Ghanem · 2022
Closest in time.
Evaluating the adversarial robustness of adaptive test-time defenses
Francesco Croce, Sven Gowal, Thomas Brunner, Evan Shelhamer, Matthias Hein, and Taylan Cemgil · 2022
Closest in time.
Transferable adversarial attack based on integrated gradients
Yi Huang and Adams Wai-Kin Kong · 2022
Closest in time.
Black-box test-time shape refinement for single view 3d reconstruction
Brandon Leung, Chih-Hui Ho, and Nuno Vasconcelos · 2022
Closest in time.
Diffusion models for adversarial purification
Weili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao, Arash Vahdat, and Anima Anandkumar · 2022
Closest in time.
Robustness and accuracy could be reconcilable by (proper) definition, 2022
Tianyu Pang, Min Lin, Xiao Yang, Jun Zhu, and Shuicheng Yan · 2022
Closest in time.
Hindering adversarial attacks with implicit neural representations
Andrei A Rusu, Dan Andrei Calian, Sven Gowal, and Raia Hadsell · 2022
Closest in time.
Robust learning meets generative models: Can proxy distributions improve adversarial robustness?
Vikash Sehwag, Saeed Mahloujifar, Tinashe Handina, Sihui Dai, Chong Xiang, Mung Chiang, and Prateek Mittal · 2022
Closest in time.
Robust learning meets generative models: Can proxy distributions improve adversarial robustness?
Vikash Sehwag, Saeed Mahloujifar, Tinashe Handina, Sihui Dai, Chong Xiang, Mung Chiang, and Prateek Mittal · 2022
Closest in time.
Generating videos with dynamics-aware implicit generative adversarial networks
Sihyun Yu, Jihoon Tack, Sangwoo Mo, Hyunsu Kim, Junho Kim, Jung-Woo Ha, and Jinwoo Shin · 2022
Closest in time.