activity
20132022
most citedZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models

1.8k citations · 2.2k across the 20 of their papers we have counts for

collaborators
Showing 2021Show all

13 papers · 1 filter

cs.DC2021

Federated Two-stage Learning with Sign-based Voting

Zichen Ma, Zihan Lu, Yu Lu +3

Federated learning is a distributed machine learning mechanism where local devices collaboratively train a shared global model under the orchestration of a central server, while ke…

cs.LG2021★ 182 cited

On the Convergence and Robustness of Adversarial Training

Yisen Wang, Xingjun Ma, James Bailey +3

Improving the robustness of deep neural networks (DNNs) to adversarial examples is an important yet challenging problem for secure deep learning. Across existing defense techniques…

cs.LG2021★ 5 cited

How and When Adversarial Robustness Transfers in Knowledge Distillation?

Rulin Shao, Jinfeng Yi, Pin-Yu Chen +1

Knowledge distillation (KD) has been widely used in teacher-student training, with applications to model compression in resource-constrained deep learning. Current works mainly foc…

cs.CV2021

Adversarial Attack across Datasets

Yunxiao Qin, Yuanhao Xiong, Jinfeng Yi +2

Existing transfer attack methods commonly assume that the attacker knows the training set (e.g., the label set, the input size) of the black-box victim models, which is usually unr…

cs.AI2021

Trustworthy AI: From Principles to Practices

Bo Li, Peng Qi, Bo Liu +5

The rapid development of Artificial Intelligence (AI) technology has enabled the deployment of various systems based on it. However, many current AI systems are found vulnerable to…

cs.LG2021★ 4 cited

Training Meta-Surrogate Model for Transferable Adversarial Attack

Yunxiao Qin, Yuanhao Xiong, Jinfeng Yi +1

We consider adversarial attacks to a black-box model when no queries are allowed. In this setting, many methods directly attack surrogate models and transfer the obtained adversari…