Fetching the paper…
Reading the bibliography…
Recent works have shown that deep neural networks are vulnerable to adversarial examples that find samples close to the original image but can make the model misclassify.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
ImageNet Large Scale Visual Recognition Challenge
Olga Russakovsky, Jia Deng, Hao Su, Jonathan Krause, Sanjeev Satheesh, Sean Ma, Zhiheng Huang, Andrej Karpathy, Aditya Khosla, Michael Bernstein, Alexander C. Berg, and Li Fei-Fei · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
Certifiable some distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2017
Earlier work this paper cites.
Synthesizing robust adversarial examples
Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok · 2018
Earlier work this paper cites.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy Cohen, Elan Rosenfeld, and Zico Kolter · 2019
Cited alongside, same era.
Simple black-box adversarial attacks
Chuan Guo, Jacob Gardner, Yurong You, Andrew Gordon Wilson, and Kilian Weinberger · 2019
Cited alongside, same era.
Prior convictions: Black-box adversarial attacks with bandits and priors
Andrew Ilyas, Logan Engstrom, and Aleksander Madry · 2019
Cited alongside, same era.
signsgd via zeroth-order oracle
Sijia Liu, Pin-Yu Chen, Xiangyi Chen, and Mingyi Hong · 2019
Cited alongside, same era.
Geoda: A geometric framework for black-box adversarial attacks
Ali Rahmati, Seyed-Mohsen Moosavi-Dezfooli, Pascal Frossard, and Huaiyu Dai · 2020
Later among the works it cites.
On certifying robustness against backdoor attacks via randomized smoothing
Binghui Wang, Xiaoyu Cao, Neil Zhenqiang Gong, et al · 2020
Later among the works it cites.
Black-box certification with randomized smoothing: A functional optimization based framework
Dinghuai Zhang, Mao Ye, Chengyue Gong, Zhanxing Zhu, and Qiang Liu · 2020
Later among the works it cites.
On the effectiveness of small input noise for defending against query-based black-box attacks
Junyoung Byun, Hyojun Go, and Changick Kim · 2021
Later among the works it cites.
An image is worth 16x16 words: Transformers for image recognition at scale
Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, et al · 2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Sign bits are all you need for black-box attacks
Abdullah Al-Dujaili and Una-May O’Reilly · 2020
Cited alongside, same era.
Square attack: a query-efficient black-box adversarial attack via random search
Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion, and Matthias Hein · 2020
Cited alongside, same era.
Rays: A ray searching method for hard-label adversarial attack
Jinghui Chen and Quanquan Gu · 2020
Cited alongside, same era.
Advmind: Inferring adversary intent of black-box attacks
Ren Pang, Xinyang Zhang, Shouling Ji, Xiapu Luo, and Ting Wang · 2020
Cited alongside, same era.
Stateful detection of black-box adversarial attacks
Steven Chen, Nicholas Carlini, and David Wagner
Cited in the paper.
Boosting decision-based black-box adversarial attacks with random sign flip
Weilun Chen, Zhaoxiang Zhang, Xiaolin Hu, and Baoyuan Wu
Cited in the paper.
Random noise defense against query-based black-box attacks
Zeyu Qin, Yanbo Fan, Hongyuan Zha, and Baoyuan Wu · 2021
Later among the works it cites.
Training data-efficient image transformers & distillation through attention
Hugo Touvron, Matthieu Cord, Matthijs Douze, Francisco Massa, Alexandre Sablayrolles, and Herve Jegou · 2021
Later among the works it cites.
Adversarial attack on attackers: Post-process to mitigate black-box score-based query attacks
Sizhe Chen, Zhehao Huang, Qinghua Tao, Yingwen Wu, Cihang Xie, and Xiaolin Huang · 2022
Later among the works it cites.
Blacklight: Scalable defense for neural networks against { \{ Query-Based } \} { \{ Black-Box } \} attacks
Huiying Li, Shawn Shan, Emily Wenger, Jiayun Zhang, Haitao Zheng, and Ben Y Zhao · 2022
Later among the works it cites.