Fetching the paper…
Reading the bibliography…
Despite their impressive performance in classification tasks, neural networks are known to be vulnerable to adversarial attacks, subtle perturbations of the input data designed to deceive the model.
H. Hotelling, “Relations between two sets of variates.” Biometrika , 1936
1936
Earlier work this paper cites.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” Tech Report , 2009
2009
Earlier work this paper cites.
2013
Earlier work this paper cites.
A. M. Saxe, J. L. Mcclelland, and S. Ganguli, “Exact solutions to the nonlinear dynamics of learning in deep linear neural network,” in International Conference on Learning Representations , 2014
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in International Conference on Learning Representations (ICLR) , 2015
2015
Earlier work this paper cites.
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein et al. , “Imagenet large scale visual recognition challenge,” International journal of computer vision , vol. 115, pp. 211–252, 2015
2015
Earlier work this paper cites.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in IEEE symposium on security and privacy (SP) , 2016
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 770–778
2016
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, “Deepfool: a simple and accurate method to fool deep neural networks,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016
2016
Earlier work this paper cites.
C. Zhang, S. Bengio, M. Hardt, B. Recht, and O. Vinyals, “Delving into transferable adversarial examples and black-box attacks,” in International Conference on Learning Representations (ICLR) , 2017
2017
Earlier work this paper cites.
A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial machine learning at scale,” in International Conference on Learning Representations (ICLR) , 2017
2017
Earlier work this paper cites.
S. Gunasekar, B. Woodworth, S. Bhojanapalli, B. Neyshabur, and N. Srebro, “Implicit regularization in matrix factorization,” in Advances in Neural Information Processing Systems , 2017
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) , 2017
2017
Earlier work this paper cites.
M. Raghu, J. Gilmer, J. Yosinski, and J. Sohl-Dickstein, “Svcca: Singular vector canonical correlation analysis for deep learning dynamics and interpretability,” Advances in neural information processing systems , vol. 30, 2017
2017
Earlier work this paper cites.
J. Rauber, W. Brendel, and M. Bethge, “Foolbox: A python toolbox to benchmark the robustness of machine learning models,” ICML Workshop on Reliable Machine Learning in the Wild , 2017
2017
Earlier work this paper cites.
S. Gunasekar, J. D. Lee, D. Soudry, and N. Srebro, “Implicit bias of gradient descent on linear convolutional networks,” Advances in neural information processing systems , vol. 31, 2018
2018
Earlier work this paper cites.
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” in International conference on machine learning (ICML) , 2018
2018
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in International Conference on Learning Representations , 2018
2018
Earlier work this paper cites.
A. Shafahi, W. R. Huang, C. Studer, S. Feizi, and T. Goldstein, “Are adversarial examples inevitable?” in International Conference on Learning Representations , 2018
2018
Cited alongside, same era.
A. Morcos, M. Raghu, and S. Bengio, “Insights on representational similarity in neural networks with canonical correlation,” Advances in neural information processing systems , vol. 31, 2018
2018
Cited alongside, same era.
2019
Cited alongside, same era.
S. Arora, S. S. Du, W. Hu, Z. Li, R. R. Salakhutdinov, and R. Wang, “On exact computation with an infinitely wide neural net,” Advances in neural information processing systems , vol. 32, 2019
2019
Cited alongside, same era.
M. Pintor, F. Roli, W. Brendel, and B. Biggio, “Fast minimum-norm adversarial attacks through adaptive norm constraints,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Later among the works it cites.
F. Faghri, S. Gowal, C. Vasconcelos, D. J. Fleet, F. Pedregosa, and N. Le Roux, “Bridging the gap between adversarial robustness and optimization bias,” ICLR Workshop on Security and Safety in Machine Learning Systems , 2021
2021
Later among the works it cites.
Y. Cao, Z. Fang, Y. Wu, D.-X. Zhou, and Q. Gu, “Towards understanding the spectral bias of deep learning,” in Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence . International Joint Conferences on Artificial Intelligence Organization, 2021
2021
Later among the works it cites.
P. Harder, F.-J. Pfreundt, M. Keuper, and J. Keuper, “Spectraldefense: Detecting adversarial attacks on cnns in the fourier domain,” in International Joint Conference on Neural Networks (IJCNN) , 2021
2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A. Ilyas, S. Santurkar, D. Tsipras, L. Engstrom, B. Tran, and A. Madry, “Adversarial examples are not bugs, they are features,” Advances in neural information processing systems , vol. 32, 2019
2019
Cited alongside, same era.
F. Williams, M. Trager, D. Panozzo, C. Silva, D. Zorin, and J. Bruna, “Gradient dynamics of shallow univariate relu networks,” Advances in Neural Information Processing Systems , vol. 32, 2019
2019
Cited alongside, same era.
D. Yin, R. Gontijo Lopes, J. Shlens, E. D. Cubuk, and J. Gilmer, “A fourier perspective on model robustness in computer vision,” Advances in Neural Information Processing Systems , vol. 32, 2019
2019
Cited alongside, same era.
N. Rahaman, A. Baratin, D. Arpit, F. Draxler, M. Lin, F. Hamprecht, Y. Bengio, and A. Courville, “On the spectral bias of neural networks,” in International conference on machine learning , 2019
2019
Cited alongside, same era.
Y. Tsuzuku and I. Sato, “On the structural sensitivity of deep convolutional networks to the directions of fourier basis functions,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2019, pp. 51–60
2019
Cited alongside, same era.
Y. Sharma, G. W. Ding, and M. A. Brubaker, “On the effectiveness of low frequency perturbations,” in Proceedings of the 28th International Joint Conference on Artificial Intelligence , 2019, pp. 3389–3396
2019
Cited alongside, same era.
S. Kornblith, M. Norouzi, H. Lee, and G. Hinton, “Similarity of neural network representations revisited,” in International conference on machine learning , 2019
2019
Cited alongside, same era.
Z. Wu, S.-N. Lim, L. S. Davis, and T. Goldstein, “Making an invisibility cloak: Real world adversarial attacks on object detectors,” in European Conference on Computer Vision (ECCV) , 2020
2020
Cited alongside, same era.
Later among the works it cites.
F. Croce, M. Andriushchenko, V. Sehwag, E. Debenedetti, N. Flammarion, M. Chiang, P. Mittal, and M. Hein, “Robustbench: a standardized adversarial robustness benchmark,” in Thirty-fifth Conference on Neural Information Processing Systems Datasets and Benchmarks Track , 2021
2021
Later among the works it cites.
J. Bac, E. M. Mirkes, A. N. Gorban, I. Tyukin, and A. Zinovyev, “Scikit-dimension: a python package for intrinsic dimension estimation,” Entropy , vol. 23, no. 10, p. 1368, 2021
2021
Later among the works it cites.
G. Vardi, “On the implicit bias in deep-learning algorithms,” Preprint, arXiv:2208.12591 , 2022
2022
Later among the works it cites.
N. Karantzas, E. Besier, J. Ortega Caro, X. Pitkow, A. S. Tolias, A. B. Patel, and F. Anselmi, “Understanding robustness and generalization of artificial neural networks through fourier masks,” Frontiers in Artificial Intelligence , vol. 5, p. 890016, 2022
2022
Later among the works it cites.
J. Sahs, R. Pyle, A. Damaraju, J. O. Caro, O. Tavaslioglu, A. Lu, F. Anselmi, and A. B. Patel, “Shallow univariate relu networks as splines: initialization, loss surface, hessian, and gradient flow dynamics,” Frontiers in artificial intelligence , vol. 5, p. 889981, 2022
2022
Later among the works it cites.
E. Boursier, L. Pullaud-Vivien, and N. Flammarion, “Gradient flow dynamics of shallow relu networks for square loss and orthogonal inputs,” in Advances in Neural Information Processing Systems 35 , 2022
2022
Later among the works it cites.
S. Fridovich-Keil, R. Gontijo Lopes, and R. Roelofs, “Spectral bias in practice: The role of function frequency in generalization,” Advances in Neural Information Processing Systems , vol. 35, pp. 7368–7382, 2022
2022
Later among the works it cites.
C. Luo, Q. Lin, W. Xie, B. Wu, J. Xie, and L. Shen, “Frequency-driven imperceptible adversarial attack on semantic similarity,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition , 2022, pp. 15 315–15 324
2022
Later among the works it cites.
J. Howard, “Imagenette,” https://github.com/fastai/imagenette
2022
Later among the works it cites.
M. Wang and C. Ma, “Understanding multi-phase optimization dynamics and rich nonlinear behaviors of reLU networks,” in Thirty-seventh Conference on Neural Information Processing Systems , 2023
2023
Closest in time.
E. Abbe, S. Bengio, E. Boix-Adsera, E. Littwin, and J. Susskind, “Transformers learn through gradual rank increase,” Advances in Neural Information Processing Systems , vol. 36, 2023
2023
Closest in time.
2024
Closest in time.
2024
Closest in time.
J. O. Caro, Y. Ju, R. Pyle, S. Dey, W. Brendel, F. Anselmi, and A. B. Patel, “Translational symmetry in convolutions with localized kernels causes an implicit bias toward high frequency adversarial examples,” Frontiers in Computational Neuroscience , vol. 18, p. 1387077, 2024
2024
Closest in time.
L. Basile, S. Acevedo, L. Bortolussi, F. Anselmi, and A. Rodriguez, “Intrinsic dimension correlation: uncovering nonlinear connections in multimodal representations,” in The Thirteenth International Conference on Learning Representations , 2025
2025
Closest in time.