activity
20152022
most citedZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models

1.8k citations · 2.3k across the 57 of their papers we have counts for

collaborators
Showing cs.CVShow all

11 papers · 1 filter

cs.CV2022

Towards Creativity Characterization of Generative Models via Group-based Subset Scanning

Celia Cintas, Payel Das, Brian Quanz +3

Deep generative models, such as Variational Autoencoders (VAEs) and Generative Adversarial Networks (GANs), have been employed widely in computational creativity research. However,…

cs.CV20216 cited

When Does Contrastive Learning Preserve Adversarial Robustness from Pretraining to Finetuning?

Lijie Fan, Sijia Liu, Pin-Yu Chen +2

Contrastive learning (CL) can learn generalizable feature representations and achieve the state-of-the-art performance of downstream tasks by finetuning a linear classifier on top…

cs.CV20213 cited

Simple Transparent Adversarial Examples

Jaydeep Borkar, Pin-Yu Chen

There has been a rise in the use of Machine Learning as a Service (MLaaS) Vision APIs as they offer multiple services including pre-built models and algorithms, which otherwise tak…

cs.CV2021

Domain Adaptation for Learning Generator from Paired Few-Shot Data

Chun-Chih Teng, Pin-Yu Chen, Wei-Chen Chiu

We propose a Paired Few-shot GAN (PFS-GAN) model for learning generators with sufficient source data and a few target data. While generative model learning typically needs large-sc…

cs.CV202028 cited

Transfer Learning without Knowing: Reprogramming Black-box Machine Learning Models with Scarce Data and Limited Resources

Yun-Yun Tsai, Pin-Yu Chen, Tsung-Yi Ho

Current transfer learning methods are mainly based on finetuning a pretrained model with target-domain data. Motivated by the techniques from adversarial machine learning (ML) that…

cs.CV2019

Adversarial T-shirt! Evading Person Detectors in A Physical World

Kaidi Xu, Gaoyuan Zhang, Sijia Liu +6

It is known that deep neural networks (DNNs) are vulnerable to adversarial attacks. The so-called physical adversarial examples deceive DNN-based decisionmakers by attaching advers…