Intriguing Properties of Machine Learning - Christian Szegedy et al 2014 ICLR - The first paper
Explaining and Harnessing Adversarial Examples - Ian Goodfellow, Christian Szegedy et al 2014
Deep Neural Networks are easily fooled - Anh Nguyen et al CVPR 2015
Distillation as a Defense to Adversarial Perturbations against Deep Neural Networks - Papernot et al 2015
The Limitations of Deep Learning in Adversarial Settings - Nicolash Papernot et al 2015
Practical Black Box Attacks Against Machine Learning- Papernot, Goodfellow et al 2016
Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples - Papernot and Goodfellow et al 2016
Adversarial Examples in the Physical World - Kurakin et al ICLR 2017
Adversarial Machine Learning at Scale - Kurakin et al ICLR 2017
Ensemble Adversarial Training: Attacks and Defenses - Florian Tramer et al ICLR 2018
Adversarial Examples: Attacks and Defenses for Deep Learning - Xiaoyong Yuan et al 2017
- https://ml.berkeley.edu/blog/2018/01/10/adversarial-examples/
- https://blog.openai.com/adversarial-example-research/
- https://nicholas.carlini.com/writing/2018/adversarial-machine-learning-reading-list.html
Adversarial Attacks and Defenses Competition
Defense Against The Dark Arts - A summary of research till now and ongoing research was provided by Ian Goodfellow in a Workshop at some IEEE conference. He also mentioned several research avenues that could be explored in Adversarial Setting.
To cite a quote from this blog:
Most defenses against adversarial examples that have been proposed so far just do not work very well at all, but the ones that do work are not adaptive. This means it is like they are playing a game of whack-a-mole: they close some vulnerabilities, but leave others open.