activity
20152023
most citedZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models

1.8k citations · 2.4k across the 86 of their papers we have counts for

collaborators
Showing 2018 · cs.LGShow all

11 papers · 2 filters

cs.LG2018

Discrete Adversarial Attacks and Submodular Optimization with Applications to Text Classification

Qi Lei, Lingfei Wu, Pin-Yu Chen +3

Adversarial examples are carefully constructed modifications to an input that completely change the output of a classifier but are imperceptible to humans. Despite these successful…

cs.LG2018

Efficient Neural Network Robustness Certification with General Activation Functions

Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen +2

Finding minimum distortion of adversarial examples and thus certifying robustness in neural network classifiers for given data points is known to be a challenging problem. Neverthe…

cs.LG2018

On Extensions of CLEVER: A Neural Network Robustness Evaluation Algorithm

Tsui-Wei Weng, Huan Zhang, Pin-Yu Chen +3

CLEVER (Cross-Lipschitz Extreme Value for nEtwork Robustness) is an Extreme Value Theory (EVT) based robustness score for large-scale deep neural networks (DNNs). In this paper, we…

cs.LG2018

Characterizing Audio Adversarial Examples Using Temporal Dependency

Zhuolin Yang, Bo Li, Pin-Yu Chen +1

Recent studies have highlighted adversarial examples as a ubiquitous threat to different neural network models and many downstream applications. Nonetheless, as unique data propert…

cs.LG2018

Structured Adversarial Attack: Towards General Implementation and Better Interpretability

Kaidi Xu, Sijia Liu, Pu Zhao +6

When generating adversarial examples to attack deep neural networks (DNNs), Lp norm of the added perturbation is usually used to measure the similarity between original image and a…

cs.LG2018

Query-Efficient Hard-label Black-box Attack:An Optimization-based Approach

Minhao Cheng, Thong Le, Pin-Yu Chen +3

We study the problem of attacking a machine learning model in the hard-label black-box setting, where no model information is revealed except that the attacker can make queries to…