Fetching the paper…
Reading the bibliography…
We show that we can easily design a single adversarial perturbation $P$ that changes the class of $n$ images $X_1,X_2,\dots,X_n$ from their original, unperturbed classes $c_1, c_2,\dots,c_n$ to desired (not necessarily all the same) classes $c^*_1,c^*_2,\dots,c^*_n$ for up to hundreds of images and target classes at once.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Intriguing properties of neural networks, 2013
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Adam: A method for stochastic optimization, 2014
Diederik P. Kingma and Jimmy Ba · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples, 2014
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Deep Residual Learning for Image Recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Understanding deep learning requires rethinking generalization, 2016
Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals · 2016
Cited alongside, same era.
Improving adversarial robustness of ensembles with diversity training, 2019
Sanjay Kariyappa and Moinuddin K. Qureshi · 2019
Cited alongside, same era.
Pytorch: An imperative style, high-performance deep learning library
Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Kopf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala · 2019
Cited alongside, same era.
Loss landscape sightseeing with multi-point optimization, 2019
Ivan Skorokhodov and Mikhail Burtsev · 2019
Cited alongside, same era.
Ensemble adversarial training: Attacks and defenses, 2020
Florian Tramer, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel · 2020
Cited alongside, same era.
Learning transferable visual models from natural language supervision, 2021
Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, Gretchen Krueger, and Ilya Sutskever · 2021
Later among the works it cites.
Adversarial examples for the openai clip in its zero-shot classification regime and their semantic generalization, 2021
Stanislav Fort · 2021
Later among the works it cites.
Robust out-of-distribution detection for neural networks, 2021
Jiefeng Chen, Yixuan Li, Xi Wu, Yingyu Liang, and Somesh Jha · 2021
Later among the works it cites.
Stanislav Fort, Andrew Brock, Razvan Pascanu, Soham De, and Samuel L. Smith · 2021
Later among the works it cites.
Adversarial vulnerability of powerful near out-of-distribution detection, 2022
Stanislav Fort · 2022
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A deep neural network’s loss surface contains every low-dimensional pattern, 2020
Wojciech Marian Czarnecki, Simon Osindero, Razvan Pascanu, and Max Jaderberg · 2020
Cited alongside, same era.
What does a deep neural network confidently perceive? the effective dimension of high certainty class manifolds and their low confidence boundaries, 2022
Stanislav Fort, Ekin Dogus Cubuk, Surya Ganguli, and Samuel S. Schoenholz · 2022
Later among the works it cites.