Fetching the paper…
Reading the bibliography…
State-of-the-art defenses against adversarial patch attacks can now achieve strong certifiable robustness with a marginal drop in model utility.
ImageNet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Fei-Fei Li · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2009
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y Ng · 2011
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Understanding the effective receptive field in deep convolutional neural networks
Wenjie Luo, Yujia Li, Raquel Urtasun, and Richard S. Zemel · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick D. McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami · 2016
Earlier work this paper cites.
Adversarial patch
Tom B. Brown, Dandelion Mané, Aurko Roy, Martín Abadi, and Justin Gilmer · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David A. Wagner · 2017
Earlier work this paper cites.
Hung Le and Ali Borji · 2017
Earlier work this paper cites.
Magnet: A two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Earlier work this paper cites.
Robust physical-world attacks on deep learning visual classification
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song · 2018
Earlier work this paper cites.
On visible adversarial perturbations & digital watermarking
Jamie Hayes · 2018
Earlier work this paper cites.
LaVAN: Localized and visible adversarial noise
Danny Karmon, Daniel Zoran, and Yoav Goldberg · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Differentiable abstract interpretation for provably robust neural networks
Matthew Mirman, Timon Gehr, and Martin T. Vechev · 2018
Earlier work this paper cites.
Not all pixels are born equal: An analysis of evasion attacks under locality constraints
Vikash Sehwag, Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Mung Chiang, and Prateek Mittal · 2018
Earlier work this paper cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and J. Zico Kolter · 2018
Earlier work this paper cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2018
Earlier work this paper cites.
Computing receptive fields of convolutional neural networks
Andre Araujo, Wade Norris, and Jack Sim · 2019
Earlier work this paper cites.
Approximating CNNs with bag-of-local-features models works surprisingly well on ImageNet
Wieland Brendel and Matthias Bethge · 2019
Cited alongside, same era.
Certified adversarial robustness via randomized smoothing
Jeremy M. Cohen, Elan Rosenfeld, and J. Zico Kolter · 2019
Cited alongside, same era.
Scalable verified training for provably robust image classification
Sven Gowal, Krishnamurthy Dvijotham, Robert Stanforth, Rudy Bunel, Chongli Qin, Jonathan Uesato, Relja Arandjelovic, Timothy Arthur Mann, and Pushmeet Kohli · 2019
Cited alongside, same era.
DPATCH: an adversarial patch attack on object detectors
Xin Liu, Huanrui Yang, Ziwei Liu, Linghao Song, Yiran Chen, and Hai Li · 2019
Cited alongside, same era.
Local gradients smoothing: Defense against localized adversarial attacks
Muzammal Naseer, Salman Khan, and Fatih Porikli · 2019
Cited alongside, same era.
Pytorch: An imperative style, high-performance deep learning library
Defending against adversarial patches with robust self-attention
Norman Mu and David Wagner · 2021
Later among the works it cites.
A real-time defense against website fingerprinting attacks
Shawn Shan, Arjun Nitin Bhagoji, Haitao Zheng, and Ben Y Zhao · 2021
Later among the works it cites.
Resnet strikes back: An improved training procedure in timm
Ross Wightman, Hugo Touvron, and Hervé Jégou · 2021
Later among the works it cites.
Patchguard: A provably robust defense against adversarial patches via small receptive fields and masking
Chong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, and Prateek Mittal · 2021
Later among the works it cites.
DetectorGuard: Provably securing object detectors against localized patch hiding attacks
Chong Xiang and Prateek Mittal · 2021
Later among the works it cites.
Patchguard++: Efficient provable attack detection against adversarial patches
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas Köpf, Edward Yang, Zachary DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala · 2019
Cited alongside, same era.
Generating 3d adversarial point clouds
Chong Xiang, Charles R Qi, and Bo Li · 2019
Cited alongside, same era.
Certified defenses for adversarial patches
Ping-Yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu, Christoph Studor, and Tom Goldstein · 2020
Cited alongside, same era.
Sentinet: Detecting localized universal attacks against deep learning systems
Edward Chou, Florian Tramer, and Giancarlo Pellegrino · 2020
Cited alongside, same era.
Christian Cosgrove, Adam Kortylewski, Chenglin Yang, and Alan L. Yuille · 2020
Cited alongside, same era.
(De)randomized smoothing for certifiable defense against patch attacks
Alexander Levine and Soheil Feizi · 2020
Cited alongside, same era.
Minority reports defense: Defending against adversarial patches
Michael McCoyd, Won Park, Steven Chen, Neil Shah, Ryan Roggenkemper, Minjune Hwang, Jason Xinyu Liu, and David A. Wagner · 2020
Cited alongside, same era.
Chong Xiang and Prateek Mittal · 2021
Later among the works it cites.
Shape matters: deformable patch attack
Zhaoyu Chen, Bo Li, Shuang Wu, Jianghe Xu, Shouhong Ding, and Wenqiang Zhang · 2022
Later among the works it cites.
Towards practical certifiable patch defense with vision transformer
Zhaoyu Chen, Bo Li, Jianghe Xu, Shuang Wu, Shouhong Ding, and Wenqiang Zhang · 2022
Later among the works it cites.
Masked autoencoders are scalable vision learners
Kaiming He, Xinlei Chen, Saining Xie, Yanghao Li, Piotr Dollár, and Ross Girshick · 2022
Later among the works it cites.
Vip: Unified certified detection and recovery for patch attack with vision transformers
Junbo Li, Huan Zhang, and Cihang Xie · 2022
Later among the works it cites.
Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection
Jiang Liu, Alexander Levine, Chun Pong Lau, Rama Chellappa, and Soheil Feizi · 2022
Later among the works it cites.
Give me your attention: Dot-product attention considered harmful for adversarial patch robustness
Giulio Lovisotto, Nicole Finnie, Mauricio Munoz, Chaithanya Kumar Mummadi, and Jan Hendrik Metzen · 2022
Later among the works it cites.
Certified patch robustness via smoothed vision transformers
Hadi Salman, Saachi Jain, Eric Wong, and Aleksander Madry · 2022
Later among the works it cites.
Adversarial sticker: A stealthy attack method in the physical world
Xingxing Wei, Ying Guo, and Jie Yu · 2022
Later among the works it cites.
Patchcleanser: Certifiably robust defense against adversarial patches for any image classifier
Chong Xiang, Saeed Mahloujifar, and Prateek Mittal · 2022
Later among the works it cites.
Certified defences against adversarial patch attacks on semantic segmentation
Maksym Yatsura, Kaspar Sakmann, N Grace Hua, Matthias Hein, and Jan Hendrik Metzen · 2022
Later among the works it cites.
X-detect: Explainable adversarial patch detection for object detectors in retail
Omer Hofman, Amit Giloni, Yarin Hayun, Ikuya Morikawa, Toshiya Shimizu, Yuval Elovici, and Asaf Shabtai · 2023
Closest in time.
Aniruddha Saha, Shuhua Yu, Arash Norouzzadeh, Wan-Yi Lin, and Chaithanya Kumar Mummadi · 2023
Closest in time.
Jedi: Entropy-based localization and removal of adversarial patches
Bilel Tarchoun, Anouar Ben Khalifa, Mohamed Ali Mahjoub, Nael Abu-Ghazaleh, and Ihsen Alouani · 2023
Closest in time.
Short: Certifiably robust perception against adversarial patch attacks: A survey
Chong Xiang, Chawin Sitawarin, Tong Wu, and Prateek Mittal · 2023
Closest in time.
Objectseeker: Certifiably robust object detection against patch hiding attacks via patch-agnostic masking
Chong Xiang, Alexander Valtchanov, Saeed Mahloujifar, and Prateek Mittal · 2023
Closest in time.
Patchzero: Defending against adversarial patch attacks by detecting and zeroing the patch
Ke Xu, Yao Xiao, Zhaoheng Zheng, Kaijie Cai, and Ram Nevatia · 2023
Closest in time.