Fetching the paper…
Reading the bibliography…
Certified defense methods against adversarial perturbations have been recently investigated in the black-box setting with a zeroth-order (ZO) perspective.
S.-i. Amari, “Backpropagation and stochastic gradient descent method,” Neurocomputing , vol. 5, no. 4-5, pp. 185–196, 1993
1993
Earlier work this paper cites.
Y. LeCun, C. Cortes, and C. Burges, “The mnist database,” http://yann.lecun.com/exdb/mnist/ , 1998
1998
Earlier work this paper cites.
A. Krizhevsky and G. Hinton, “Cifar-10 (canadian institute for advanced research),” https://www.cs.toronto.edu/ kriz/cifar.html , 2009
2009
Earlier work this paper cites.
——, “Cifar-100 (canadian institute for advanced research),” https://www.cs.toronto.edu/ kriz/cifar.html , 2009
2009
Earlier work this paper cites.
A. Hore and D. Ziou, “Image quality metrics: Psnr vs. ssim,” in 2010 20th ICPR . IEEE, 2010, pp. 2366–2369
2010
Earlier work this paper cites.
A. Coates, A. Y. Ng, and H. Lee, “The stl-10 dataset,” https://cs.stanford.edu/ acoates/stl10/ , 2011
2011
Earlier work this paper cites.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” in Adv. neural inf. process. syst , 2012, pp. 1097–1105
2012
Earlier work this paper cites.
A. Gretton, K. M. Borgwardt, M. J. Rasch, B. Schölkopf, and A. Smola, “A kernel two-sample test,” The Journal of Machine Learning Research , vol. 13, no. 1, pp. 723–773, 2012
2012
Earlier work this paper cites.
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in Proceedings of the 22nd ACM CCS , 2015, pp. 1322–1333
2015
Earlier work this paper cites.
O. Ronneberger, P. Fischer, and T. Brox, “U-net: Convolutional networks for biomedical image segmentation,” in Medical Image Computing and Computer-Assisted Intervention–MICCAI 2015: 18th International Conference, Munich, Germany, October 5-9, 2015, Proceedings, Part III 18 . Springer, 2015, pp. 234–241
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
S. Ioffe and C. Szegedy, “Batch normalization: Accelerating deep network training by reducing internal covariate shift,” in ICML . PMLR, 2015, pp. 448–456
2015
Earlier work this paper cites.
2015
Earlier work this paper cites.
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in 2016 EuroS&P . IEEE, 2016, pp. 372–387
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in 2016 SP . IEEE, 2016, pp. 582–597
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
X. Lian, H. Zhang, C.-J. Hsieh, Y. Huang, and J. Liu, “A comprehensive linear speedup analysis for asynchronous stochastic parallel optimization from zeroth-order to first-order,” Adv. neural inf. process. syst , vol. 29, 2016
2016
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) . Ieee, 2017, pp. 39–57
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
G. Katz, C. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer, “Reluplex: An efficient smt solver for verifying deep neural networks,” in CAV . Springer, 2017, pp. 97–117
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh, “Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models,” in Proceedings of the 10th ACM AISec , 2017, pp. 15–26
2017
Earlier work this paper cites.
X. Liu, Y. Wang, T. Liu, and Z. Zhang, “Tiny imagenet visual recognition challenge,” in ACM Multimedia . ACM, 2017, pp. 909–910
2017
Earlier work this paper cites.
Y. Tai, J. Yang, X. Liu, and C. Xu, “Memnet: A persistent memory network for image restoration,” in Proceedings of the ICCV , 2017, pp. 4539–4547
2017
Earlier work this paper cites.
K. Zhang, W. Zuo, Y. Chen, D. Meng, and L. Zhang, “Beyond a gaussian denoiser: Residual learning of deep cnn for image denoising,” IEEE transactions on image processing , vol. 26, no. 7, pp. 3142–3155, 2017
2017
Earlier work this paper cites.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust physical-world attacks on deep learning visual classification,” in Proceedings of the CVPR , 2018, pp. 1625–1634
2018
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” ICLR , 2018
2018
Cited alongside, same era.
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” in ICML . PMLR, 2018, pp. 274–283
2018
Cited alongside, same era.
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok, “Synthesizing robust adversarial examples,” in ICML . PMLR, 2018, pp. 284–293
2018
Cited alongside, same era.
J. Uesato, B. O’Donoghue, P. Kohli, and A. van den Oord, “Adversarial risk and the dangers of evaluating against weak attacks,” in Proceedings of the PMLR , 2018, pp. 5025–5034
2018
Cited alongside, same era.
E. Wong and Z. Kolter, “Provable defenses against adversarial examples via the convex outer adversarial polytope,” in ICML . PMLR, 2018, pp. 5286–5295
Z. Huang and T. Zhang, “Black-box adversarial attack with transferable model-based embedding,” in ICLR , 2020
2020
Later among the works it cites.
D. Mekhazni, A. Bhuiyan, G. Ekladious, and E. Granger, “Unsupervised domain adaptation in the dissimilarity space for person re-identification,” in ECCV . Springer, 2020, pp. 159–174
2020
Later among the works it cites.
W. Zhang and D. Wu, “Discriminative joint probability maximum mean discrepancy (djp-mmd) for domain adaptation,” in 2020 IJCNN . IEEE, 2020, pp. 1–8
2020
Later among the works it cites.
A. Raj, Y. Bresler, and B. Li, “Improving robustness of deep-learning-based image reconstruction,” in ICML . PMLR, 2020, pp. 7932–7942
2020
Later among the works it cites.
J. Ho, A. Jain, and P. Abbeel, “Denoising diffusion probabilistic models,” Advances in Neural Information Processing Systems , vol. 33, pp. 6840–6851, 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
2018
Cited alongside, same era.
R. R. Bunel, I. Turkaslan, P. Torr, P. Kohli, and P. K. Mudigonda, “A unified view of piecewise linear neural network verification,” Advances in Neural Information Processing Systems , vol. 31, 2018
2018
Cited alongside, same era.
H. Zhang, T.-W. Weng, P.-Y. Chen, C.-J. Hsieh, and L. Daniel, “Efficient neural network robustness certification with general activation functions,” Adv. neural inf. process. syst , vol. 31, 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin, “Black-box adversarial attacks with limited queries and information,” in ICML . PMLR, 2018, pp. 2137–2146
2018
Cited alongside, same era.
Z. Zhong, L. Zheng, Z. Zheng, S. Li, and Y. Yang, “Camera style adaptation for person re-identification,” in Proceedings of the CVPR , 2018, pp. 5157–5166
2018
Cited alongside, same era.
Z. Zhang, “Improved adam optimizer for deep neural networks,” in 2018 IEEE/ACM 26th IWQoS . Ieee, 2018, pp. 1–2
2018
Cited alongside, same era.
2020
Later among the works it cites.
J. Cui, S. Liu, L. Wang, and J. Jia, “Learnable boundary guided adversarial training,” in Proceedings of the ICCV , 2021, pp. 15 721–15 730
2021
Later among the works it cites.
S. Addepalli, S. Jain, G. Sriramanan, and R. V. Babu, “Boosting adversarial robustness using feature level stochastic smoothing,” in Proceedings of the CVPR , 2021, pp. 93–102
2021
Later among the works it cites.
2021
Later among the works it cites.
X. Ma, Y. Liu, J. Bailey, and H. Shi, “Towards certified robustness for deep neural networks with lipschitz continuous activations,” IEEE Trans Neural Netw Learn Syst , vol. 32, no. 2, pp. 458–470, 2021
2021
Later among the works it cites.
R. Gupta, R. Stanforth, and P. Hennig, “Verifiable robustness of neural networks with contractive activation functions,” in Proceedings of the 38th ICML . PMLR, 2021, pp. 3774–3784
2021
Later among the works it cites.
H. Cai, Y. Lou, D. McKenzie, and W. Yin, “A zeroth-order block coordinate descent algorithm for huge-scale black-box optimization,” in ICML . PMLR, 2021, pp. 1193–1203
2021
Later among the works it cites.
C. K. Joshi, C. Yang, and S. Wang, “Certified robustness of graph neural networks against adversarial attacks,” in Proceedings of the AIES , vol. 36, no. 5, 2022, pp. 4415–4422
2022
Later among the works it cites.
G. Katz, C. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer, “Formal verification of neural networks: From verification of robustness to certificates,” IEEE Trans Neural Netw Learn Syst , 2022
2022
Later among the works it cites.
A. Verma, A. V. Subramanyam, and R. R. Shah, “Wasserstein metric attack on person re-identification,” in 2022 IEEE 5th International Conference on Multimedia Information Processing and Retrieval (MIPR) . IEEE, 2022, pp. 234–239
2022
Later among the works it cites.
H. Wang and Y. Wang, “Self-ensemble adversarial training for improved robustness,” ICLR , 2022
2022
Later among the works it cites.
2022
Later among the works it cites.
H. Salman, S. Jain, E. Wong, and A. Madry, “Certified patch robustness via smoothed vision transformers,” in Proceedings of the CVPR , 2022, pp. 15 137–15 147
2022
Later among the works it cites.
Y. Zhang, Y. Yao, J. Jia, J. Yi, M. Hong, S. Chang, and S. Liu, “How to robustify black-box ml models? a zeroth-order optimization perspective,” ICLR , 2022
2022
Later among the works it cites.
A. Sinha, S. P. Joshi, P. S. Das, S. Jana, and R. Sarkar, “An ml prediction model based on clinical parameters and automated ct scan features for covid-19 patients,” Scientific Reports , vol. 12, no. 1, p. 11255, 2022
2022
Later among the works it cites.
I. A. Elaalami, S. O. Olatunji, and R. M. Zagrouba, “At-bod: An adversarial attack on fool dnn-based blackbox object detection models,” Applied Sciences , vol. 12, no. 4, p. 2003, 2022
2022
Later among the works it cites.
X. Wei, Y. Guo, J. Yu, and B. Zhang, “Simultaneously optimizing perturbations and positions for black-box adversarial patch attacks,” IEEE Trans. Pattern Anal. Mach. Intell , 2022
2022
Later among the works it cites.
H. Cai, D. Mckenzie, W. Yin, and Z. Zhang, “Zeroth-order regularized optimization (zoro): Approximately sparse gradients and adaptive sampling,” SIAM Journal on Optimization , vol. 32, no. 2, pp. 687–714, 2022
2022
Later among the works it cites.
2022
Later among the works it cites.
A. Verma, A. Subramanyam, M. A. Jauhar, D. Gera, and R. R. Shah, “Meta perturbed re-id defense,” in 2023 IEEE International Conference on Multimedia and Expo (ICME) . IEEE, 2023, pp. 2597–2602
2023
Closest in time.
M. Hussain, D. Koundal, and J. Manhas, “Deep learning-based diagnosis of disc degenerative diseases using mri: A comprehensive review,” Computers and Electrical Engineering , vol. 105, p. 108524, 2023
2023
Closest in time.
Z. Cheng, F. Zhu, X.-Y. Zhang, and C.-L. Liu, “Adversarial training with distribution normalization and margin balance,” Pattern Recognition , vol. 136, p. 109182, 2023
2023
Closest in time.
J. Wei, L. Yao, and Q. Meng, “Self-adaptive logit balancing for deep neural network robustness: Defence and detection of adversarial attacks,” Neurocomputing , 2023
2023
Closest in time.
F. Yin, Y. Zhang, B. Wu, Y. Feng, J. Zhang, Y. Fan, and Y. Yang, “Generalizable black-box adversarial attack with meta learning,” IEEE Trans. Pattern Anal. Mach. Intell , 2023
2023
Closest in time.