Fetching the paper…
Reading the bibliography…
In the scenario of black-box adversarial attack, the target model's parameters are unknown, and the attacker aims to find a successful adversarial perturbation based on query feedback under a query budget.
X. Wang and K. He, “Enhancing the transferability of adversarial attacks through variance tuning,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2021, pp. 1924–1933
1933
Earlier work this paper cites.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” 2009
2009
Earlier work this paper cites.
E. Tabak and E. Vanden-Eijnden, “Density estimation by dual ascent of the log-likelihood,” Communications in Mathematical Sciences , vol. 8, no. 1, pp. 217–233, 2010
2010
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in Proc. Int. Conf. Learn. Represent. , 2015
2015
Earlier work this paper cites.
D. P. Kingma and J. Ba, “Adam: A method for stochastic optimization,” in Proc. Int. Conf. Learn. Represent. , 2015
2015
Earlier work this paper cites.
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. S. Bernstein, A. C. Berg, and F. Li, “Imagenet large scale visual recognition challenge,” Int. J. Comput. Vis. , 2015
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in Proc. Int. Conf. Learn. Represent. , 2015
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Identity mappings in deep residual networks,” in Proc. Eur. Conf. Comput. Vis. , 2016, pp. 630–645
2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis, “Wide residual networks,” in Brit. Mach. Vis. Conf. , 2016
2016
Earlier work this paper cites.
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2016, pp. 2818–2826
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2017, pp. 1765–1773
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) . IEEE, 2017, pp. 39–57
2017
Earlier work this paper cites.
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh, “Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models,” in Proceedings of the 10th ACM workshop on artificial intelligence and security , 2017, pp. 15–26
2017
Earlier work this paper cites.
Y. Liu, X. Chen, C. Liu, and D. Song, “Delving into transferable adversarial examples and black-box attacks,” in Proc. Int. Conf. Learn. Represent. , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
G. Huang, Z. Liu, L. van der Maaten, and K. Q. Weinberger, “Densely connected convolutional networks,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2017, pp. 2261–2269
2017
Earlier work this paper cites.
D. Han, J. Kim, and J. Kim, “Deep pyramidal residual networks,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2017, pp. 6307–6315
2017
Earlier work this paper cites.
A. Kurakin, I. J. Goodfellow, and S. Bengio, “Adversarial examples in the physical world,” in Artificial intelligence safety and security . Chapman and Hall/CRC, 2018, pp. 99–112
2018
Earlier work this paper cites.
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok, “Synthesizing robust adversarial examples,” in Proc. Int. Conf. Mach. Learn. , 2018, pp. 284–293
2018
Earlier work this paper cites.
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin, “Black-box adversarial attacks with limited queries and information,” in Proc. Int. Conf. Mach. Learn. , 2018, pp. 2137–2146
2018
Earlier work this paper cites.
S. Liu, P.-Y. Chen, X. Chen, and M. Hong, “signsgd via zeroth-order oracle,” in Proc. Int. Conf. Learn. Represent. , 2018
2018
Earlier work this paper cites.
W. Brendel, J. Rauber, and M. Bethge, “Decision-based adversarial attacks: Reliable attacks against black-box machine learning models,” in Proc. Int. Conf. Learn. Represent. , 2018
2018
Earlier work this paper cites.
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, and J. Li, “Boosting adversarial attacks with momentum,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2018, pp. 9185–9193
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
C. Guo, M. Rana, M. Cisse, and L. van der Maaten, “Countering adversarial images using input transformations,” in Proc. Int. Conf. Learn. Represent. , 2018
2018
Cited alongside, same era.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in Proc. Int. Conf. Learn. Represent. , 2018
2018
Cited alongside, same era.
C. Xiao, B. Li, J.-Y. Zhu, W. He, M. Liu, and D. Song, “Generating adversarial examples with adversarial networks,” in Proc. Int. Joint Conf. on Artif. Intell. , 2018, pp. 3905–3911
2018
Cited alongside, same era.
C. Laidlaw and S. Feizi, “Functional adversarial attacks,” in Proc. Adv. Neural Inform. Process. Syst. , vol. 32, 2019
2019
Cited alongside, same era.
S. T. Jan, J. Messou, Y.-C. Lin, J.-B. Huang, and G. Wang, “Connecting the digital and physical world: Improving the robustness of adversarial attacks,” in Proc. of the AAAI Conf. on Artif. Intell. , vol. 33, no. 01, 2019, pp. 962–969
J. Du, H. Zhang, J. T. Zhou, Y. Yang, and J. Feng, “Query-efficient meta attack to deep neural networks,” in Proc. Int. Conf. Learn. Represent. , 2020
2020
Later among the works it cites.
H. Mohaghegh Dolatabadi, S. Erfani, and C. Leckie, “Advflow: Inconspicuous black-box adversarial attacks using normalizing flows,” in Proc. Adv. Neural Inform. Process. Syst. , 2020, pp. 15 871–15 884
2020
Later among the works it cites.
Z. Huang and T. Zhang, “Black-box adversarial attack with transferable model-based embedding,” in Proc. Int. Conf. Learn. Represent. , 2020
2020
Later among the works it cites.
A. Rahmati, S.-M. Moosavi-Dezfooli, P. Frossard, and H. Dai, “Geoda: a geometric framework for black-box adversarial attacks,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2020, pp. 8446–8455
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2019
Cited alongside, same era.
C. Guo, J. R. Gardner, Y. You, A. G. Wilson, and K. Q. Weinberger, “Simple black-box adversarial attacks,” in Proc. Int. Conf. Mach. Learn. , 2019, pp. 2484–2493
2019
Cited alongside, same era.
A. Ilyas, L. Engstrom, and A. Madry, “Prior convictions: Black-box adversarial attacks with bandits and priors,” in Proc. Int. Conf. Learn. Represent. , 2019
2019
Cited alongside, same era.
C.-C. Tu, P. Ting, P.-Y. Chen, S. Liu, H. Zhang, J. Yi, C.-J. Hsieh, and S.-M. Cheng, “Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks,” in Proc. of the AAAI Conf. on Artif. Intell. , vol. 33, no. 01, 2019, pp. 742–749
2019
Cited alongside, same era.
S. Cheng, Y. Dong, T. Pang, H. Su, and J. Zhu, “Improving black-box adversarial attacks with a transfer-based prior,” in Proc. Adv. Neural Inform. Process. Syst. , vol. 32, 2019
2019
Cited alongside, same era.
Y. Guo, Z. Yan, and C. Zhang, “Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks,” in Proc. Adv. Neural Inform. Process. Syst. , 2019, pp. 3820–3829
2019
Cited alongside, same era.
Y. Li, L. Li, L. Wang, T. Zhang, and B. Gong, “NATTACK: learning the distributions of adversarial examples for an improved black-box attack on deep neural networks,” in Proc. Int. Conf. Mach. Learn. , 2019, pp. 3866–3876
2019
Cited alongside, same era.
Y. Dong, H. Su, B. Wu, Z. Li, W. Liu, T. Zhang, and J. Zhu, “Efficient decision-based black-box adversarial attacks on face recognition,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2019, pp. 7714–7722
2019
Cited alongside, same era.
2020
Later among the works it cites.
J. Chen and Q. Gu, “Rays: A ray searching method for hard-label adversarial attack,” in Proc. Knowledge Discovery and Data Mining , 2020, pp. 1739–1747
2020
Later among the works it cites.
J. Chen, M. I. Jordan, and M. J. Wainwright, “Hopskipjumpattack: A query-efficient decision-based attack,” in IEEE Symposium on Security and Privacy . IEEE, 2020, pp. 1277–1294
2020
Later among the works it cites.
H. Li, X. Xu, X. Zhang, S. Yang, and B. Li, “QEBA: query-efficient boundary-based blackbox attack,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2020, pp. 1218–1227
2020
Later among the works it cites.
M. Cheng, S. Singh, P. H. Chen, P. Chen, S. Liu, and C. Hsieh, “Sign-opt: A query-efficient hard-label adversarial attack,” in Proc. Int. Conf. Learn. Represent. , 2020
2020
Later among the works it cites.
J. Lin, C. Song, K. He, L. Wang, and J. E. Hopcroft, “Nesterov accelerated gradient and scale invariance for adversarial attacks,” in Proc. Int. Conf. Learn. Represent. , 2020
2020
Later among the works it cites.
N. Inkawhich, K. J. Liang, B. Wang, M. Inkawhich, L. Carin, and Y. Chen, “Perturbing across the feature hierarchy to improve standard and strict blackbox attack transferability,” in Proc. Adv. Neural Inform. Process. Syst. , 2020, pp. 20 791–20 801
2020
Later among the works it cites.
D. Wu, Y. Wang, S. Xia, J. Bailey, and X. Ma, “Skip connections matter: On the transferability of adversarial examples generated with resnets,” in Proc. Int. Conf. Learn. Represent. , 2020
2020
Later among the works it cites.
Z. Yang, L. Li, X. Xu, S. Zuo, Q. Chen, B. Rubinstein, C. Zhang, and B. Li, “Characterizing adversarial transferability via gradient orthogonality and smoothness,” in Proc. Int. Conf. Mach. Learn. Worksh. , 2020
2020
Later among the works it cites.
Y. Lu and B. Huang, “Structured output learning with conditional generative flows,” in Proc. of the AAAI Conf. on Artif. Intell. , 2020, pp. 5005–5012
2020
Later among the works it cites.
A. Kuznetsova, H. Rom, N. Alldrin, J. Uijlings, I. Krasin, J. Pont-Tuset, S. Kamali, S. Popov, M. Malloci, A. Kolesnikov et al. , “The open images dataset v4,” Int. J. Comput. Vis. , pp. 1956–1981, 2020
2020
Later among the works it cites.
Y. Xiong and C.-J. Hsieh, “Improved adversarial training via learned optimizer,” in Proc. Eur. Conf. Comput. Vis. , 2020, pp. 85–100
2020
Later among the works it cites.
D. Wu, Y. Wang, S.-T. Xia, J. Bailey, and X. Ma, “Skip connections matter: On the transferability of adversarial examples generated with resnets,” in Proc. Int. Conf. Learn. Represent. , 2020
2020
Later among the works it cites.
W. Feng, B. Wu, T. Zhang, Y. Zhang, and Y. Zhang, “Meta-attack: Class-agnostic and model-agnostic physical adversarial attack,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2021, pp. 7787–7796
2021
Later among the works it cites.
X. Wang, J. Ren, S. Lin, X. Zhu, Y. Wang, and Q. Zhang, “A unified approach to interpreting and boosting adversarial transferability,” in Proc. Int. Conf. Learn. Represent. , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
Z. Yuan, J. Zhang, Y. Jia, C. Tan, T. Xue, and S. Shan, “Meta gradient adversarial attack,” in Proc. Int. Conf. Comput. Vis. , 2021, pp. 7728–7737
2021
Later among the works it cites.
J. Byun, H. Go, and C. Kim, “Small input noise is enough to defend against query-based black-box attacks,” Proc. Int. Conf. Learn. Represent. , 2021
2021
Later among the works it cites.
Y. Feng, B. Wu, Y. Fan, L. Liu, Z. Li, and S. Xia, “Boosting black-box attack with partially transferred conditional adversarial distribution,” in Proc. IEEE Conf. Comput. Vis. Pattern Recog. , 2022, pp. 15 095–15 104
2022
Later among the works it cites.
S. Jandial, P. Mangla, S. Varshney, and V. Balasubramanian, “Advgan++: Harnessing latent layers for adversary generation,” in Proc. Int. Conf. Comput. Vis. Worksh. , 2019, pp. 2045–2048
2048
Closest in time.