Fetching the paper…
Reading the bibliography…
The vulnerability of deep neural networks to adversarial perturbations has been widely perceived in the computer vision community.
S. G. Mallat, “A theory for multiresolution signal decomposition: the wavelet representation,” IEEE Trans. Pattern Anal. Mach. Intell. , vol. 11, no. 7, pp. 674–693, 1989
1989
Earlier work this paper cites.
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proc. IEEE , vol. 86, no. 11, pp. 2278–2324, 1998
1998
Earlier work this paper cites.
E. P. Simoncelli and B. A. Olshausen, “Natural image statistics and neural representation,” Annu. Rev. Neurosci. , vol. 24, no. 1, pp. 1193–1216, 2001
2001
Earlier work this paper cites.
P.-T. Yap, R. Paramesran, and S.-H. Ong, “Image analysis by Krawtchouk moments,” IEEE Trans. Image Process. , vol. 12, no. 11, pp. 1367–1377, 2003
2003
Earlier work this paper cites.
Y. Bengio, A. Courville, and P. Vincent, “Representation learning: A review and new perspectives,” IEEE Trans. Pattern Anal. Mach. Intell. , vol. 35, no. 8, pp. 1798–1828, 2013
2013
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in Proc. Int. Conf. Learn. Represent. , 2014
2014
Earlier work this paper cites.
Y. Jia, E. Shelhamer, J. Donahue, S. Karayev, J. Long, R. Girshick, S. Guadarrama, and T. Darrell, “Caffe: Convolutional architecture for fast feature embedding,” in Proc. ACM Int. Conf. Multimed. , 2014, pp. 675–678
2014
Earlier work this paper cites.
I. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in Proc. Int. Conf. Learn. Represent. , 2015
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in Proc. Int. Conf. Learn. Represent. , 2015
2015
Earlier work this paper cites.
C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich, “Going deeper with convolutions,” in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. , 2015, pp. 1–9
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” Proc. IEEE Conf. Comput. Vis. Pattern Recognit. , pp. 770–778, 2016
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: a simple and accurate method to fool deep neural networks,” in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. , 2016, pp. 2574–2582
2016
Earlier work this paper cites.
A. Fawzi, S.-M. Moosavi-Dezfooli, and P. Frossard, “The robustness of deep networks: A geometrical perspective,” IEEE Signal Process Mag. , vol. 34, no. 6, pp. 50–62, 2017
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in Proc. IEEE Symp. Secur. Priv. , 2017, pp. 39–57
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. , 2017, pp. 1765–1773
2017
Earlier work this paper cites.
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh, “Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models,” in Proc. ACM Workshop Artif. Intell. Secur. , 2017, pp. 15–26
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
K. R. Mopuri, U. Garg, and R. V. Babu, “Fast Feature Fool: A data independent approach to universal adversarial perturbations,” in Proc. Br. Mach. Vis. Conf. , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
I. Goodfellow, P. McDaniel, and N. Papernot, “Making machine learning robust against adversarial inputs,” Commun. ACM , vol. 61, no. 7, pp. 56–66, 2018
2018
Earlier work this paper cites.
A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial examples in the physical world,” in Artificial intelligence safety and security . Chapman and Hall/CRC, 2018, pp. 99–112
2018
Earlier work this paper cites.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust physical-world attacks on deep learning visual classification,” in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. , 2018, pp. 1625–1634
2018
Earlier work this paper cites.
A. Ross and F. Doshi-Velez, “Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients,” in Proc. AAAI Conf. Artif. Intell. , vol. 32, no. 1, 2018
2018
Earlier work this paper cites.
B. Liang, H. Li, M. Su, X. Li, W. Shi, and X. Wang, “Detecting adversarial image examples in deep neural networks with adaptive noise reduction,” IEEE Trans. Dependable Secure Comput. , vol. 18, no. 1, pp. 72–85, 2018
2018
Cited alongside, same era.
A. N. Bhagoji, D. Cullina, C. Sitawarin, and P. Mittal, “Enhancing robustness of machine learning systems via data transformations,” in Proc. Annu. Conf. Inf. Sci. Syst. , 2018, pp. 1–5
2018
Cited alongside, same era.
N. Akhtar, J. Liu, and A. Mian, “Defense against universal adversarial perturbations,” in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. , 2018, pp. 3389–3398
2018
Cited alongside, same era.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in Proc. Int. Conf. Learn. Represent. , 2018
2018
Cited alongside, same era.
E. Wong, L. Rice, and J. Z. Kolter, “Fast is better than free: Revisiting adversarial training,” in Proc. Int. Conf. Learn. Represent. , 2020
2020
Later among the works it cites.
F. Croce and M. Hein, “Minimally distorted adversarial examples with a fast adaptive boundary attack,” in Proc. Int. Conf. Mach. Learn. , 2020, pp. 2196–2205
2020
Later among the works it cites.
M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein, “Square attack: a query-efficient black-box adversarial attack via random search,” in Proc. Eur. Conf. Comput. Vis. , 2020, pp. 484–501
2020
Later among the works it cites.
S. Yuan, Q. Zhang, L. Gao, Y. Cheng, and J. Song, “Natural color fool: Towards boosting black-box unrestricted attacks,” in Proc. Adv. Neural Inf. Proces. Syst. , vol. 35, 2022, pp. 7546–7560
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
S. Liang, Y. Li, and R. Srikant, “Principled detection of out-of-distribution examples in neural networks,” in Proc. Int. Conf. Learn. Represent. , 2018
2018
Cited alongside, same era.
J. Su, D. V. Vargas, and K. Sakurai, “One pixel attack for fooling deep neural networks,” IEEE Trans. Evol. Comput. , vol. 23, no. 5, pp. 828–841, 2019
2019
Cited alongside, same era.
M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, and S. Jana, “Certified robustness to adversarial examples with differential privacy,” in Proc. IEEE Symp. Secur. Priv. , 2019, pp. 656–672
2019
Cited alongside, same era.
J. Cohen, E. Rosenfeld, and Z. Kolter, “Certified adversarial robustness via randomized smoothing,” in Proc. Int. Conf. Mach. Learn. , 2019, pp. 1310–1320
2019
Cited alongside, same era.
H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, and M. Jordan, “Theoretically principled trade-off between robustness and accuracy,” in Proc. Int. Conf. Mach. Learn. , 2019, pp. 7472–7482
2019
Cited alongside, same era.
J. Liu, W. Zhang, Y. Zhang, D. Hou, Y. Liu, H. Zha, and N. Yu, “Detection based defense against adversarial examples from the steganalysis point of view,” in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. , 2019, pp. 4825–4834
2019
Cited alongside, same era.
Z. Chen, B. Tondi, X. Li, R. Ni, Y. Zhao, and M. Barni, “Secure detection of image manipulation by means of random feature selection,” IEEE Trans. Inf. Forensics Secur. , vol. 14, no. 9, pp. 2454–2469, 2019
2019
Cited alongside, same era.
H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, and M. Jordan, “Theoretically principled trade-off between robustness and accuracy,” in Proc. Int. Conf. Mach. Learn. , 2019, pp. 7472–7482
2019
Cited alongside, same era.
L. Zhao, Q. Wang, C. Wang, Q. Li, C. Shen, and B. Feng, “Veriml: Enabling integrity assurances and fair payments for machine learning as a service,” IEEE Trans. Parallel Distrib. Syst. , vol. 32, no. 10, pp. 2524–2540, 2021
2021
Later among the works it cites.
J. M. Wing, “Trustworthy AI,” Commun. ACM , vol. 64, no. 10, pp. 64–71, 2021
2021
Later among the works it cites.
C. Xiang, A. N. Bhagoji, V. Sehwag, and P. Mittal, “PatchGuard: A provably robust defense against adversarial patches via small receptive fields and masking.” in Proc. USENIX Secur. Symp. , 2021, pp. 2237–2254
2021
Later among the works it cites.
X. Zhang, X. Zheng, and W. Mao, “Adversarial perturbation defense on deep neural networks,” ACM Comput. Surv. , vol. 54, no. 8, pp. 1–36, 2021
2021
Later among the works it cites.
A. Agarwal, G. Goswami, M. Vatsa, R. Singh, and N. K. Ratha, “Damad: Database, attack, and model agnostic adversarial perturbation detector,” IEEE Trans. Neural Networks Learn. Syst. , vol. 33, no. 8, pp. 3277–3289, 2021
2021
Later among the works it cites.
S. Qi, Y. Zhang, C. Wang, J. Zhou, and X. Cao, “A survey of orthogonal moments for image representation: theory, implementation, and evaluation,” ACM Comput. Surv. , vol. 55, no. 1, pp. 1–35, 2021
2021
Later among the works it cites.
H. Yang, S. Qi, J. Tian, P. Niu, and X. Wang, “Robust and discriminative image representation: Fractional-order Jacobi-Fourier moments,” Pattern Recognit. , vol. 115, p. 107898, 2021
2021
Later among the works it cites.
Z. Liu, Y. Lin, Y. Cao, H. Hu, Y. Wei, Z. Zhang, S. Lin, and B. Guo, “Swin transformer: hierarchical vision transformer using shifted windows,” Proc. IEEE Int. Conf. Comput. Vis. , pp. 10 012–10 022, 2021
2021
Later among the works it cites.
X. Qin, B. Li, S. Tan, W. Tang, and J. Huang, “Gradually enhanced adversarial perturbations on color pixel vectors for image steganography,” IEEE Trans. Circuits Syst. Video Technol. , vol. 32, no. 8, pp. 5110–5123, 2022
2022
Later among the works it cites.
J. Zhang, J. Wang, H. Wang, and X. Luo, “Self-recoverable adversarial examples: a new effective protection mechanism in social networks,” IEEE Trans. Circuits Syst. Video Technol. , vol. 33, no. 2, pp. 562–574, 2022
2022
Later among the works it cites.
H. Liu, Y. Wang, W. Fan, X. Liu, Y. Li, S. Jain, Y. Liu, A. Jain, and J. Tang, “Trustworthy AI: A computational perspective,” ACM Trans. Intell. Syst. Technolog. , vol. 14, no. 1, pp. 1–59, 2022
2022
Later among the works it cites.
A. Cullen, P. Montague, S. Liu, S. Erfani, and B. Rubinstein, “Double bubble, toil and trouble: enhancing certified robustness through transitivity,” Proc. Adv. Neural Inf. Proces. Syst. , vol. 35, pp. 19 099–19 112, 2022
2022
Later among the works it cites.
S. Qi, Y. Zhang, C. Wang, J. Zhou, and X. Cao, “A principled design of image representation: Towards forensic tasks,” IEEE Trans. Pattern Anal. Mach. Intell. , 2022
2022
Later among the works it cites.
P. Li, Y. Zhang, L. Yuan, J. Zhao, X. Xu, and X. Zhang, “Adversarial attacks on video object segmentation with hard region discovery,” IEEE Trans. Circuits Syst. Video Technol. , 2023
2023
Closest in time.
Z. Zhou, Y. Sun, Q. Sun, C. Li, and Z. Ren, “Only once attack: Fooling the tracker with adversarial template,” IEEE Trans. Circuits Syst. Video Technol. , 2023
2023
Closest in time.
T. Chen and Z. Ma, “Towards robust neural image compression: Adversarial attack and model finetuning,” IEEE Transactions on Circuits and Systems for Video Technology , 2023
2023
Closest in time.
G.-L. Chen and C.-C. Hsu, “Jointly defending DeepFake manipulation and adversarial attack using decoy mechanism,” IEEE Trans. Pattern Anal. Mach. Intell. , 2023
2023
Closest in time.
V. Veerabadran, J. Goldman, S. Shankar, B. Cheung, N. Papernot, A. Kurakin, I. Goodfellow, J. Shlens, J. Sohl-Dickstein, M. C. Mozer et al. , “Subtle adversarial image manipulations influence both human and machine perception,” Nat. Commun. , vol. 14, no. 1, p. 4933, 2023
2023
Closest in time.
L. Schwinn, R. Raab, A. Nguyen, D. Zanca, and B. Eskofier, “Exploring misclassifications of robust neural networks to enhance adversarial attacks,” Appl. Intell. , vol. 53, no. 17, pp. 19 843–19 859, 2023
2023
Closest in time.