Robust physical-world attacks on deep learning visual classification K Eykholt, I Evtimov, E Fernandes, B Li, A Rahmati, C Xiao, A Prakash, ... Proceedings of the IEEE conference on computer vision and pattern …, 2018 | 2717* | 2018 |

Physical adversarial examples for object detectors D Song, K Eykholt, I Evtimov, E Fernandes, B Li, A Rahmati, F Tramer, ... 12th USENIX workshop on offensive technologies (WOOT 18), 2018 | 477 | 2018 |

Code llama: Open foundation models for code B Roziere, J Gehring, F Gloeckle, S Sootla, I Gat, XE Tan, Y Adi, J Liu, ... arXiv preprint arXiv:2308.12950, 2023 | 81 | 2023 |

Is tricking a robot hacking? I Evtimov, D O’Hair, E Fernandes, R Calo, T Kohno Berkeley Technology Law Journal 34 (3), 891-918, 2019 | 29* | 2019 |

Imagenet-x: Understanding model mistakes with factor of variation annotations BY Idrissi, D Bouchacourt, R Balestriero, I Evtimov, C Hazirbas, N Ballas, ... arXiv preprint arXiv:2211.01866, 2022 | 23 | 2022 |

FoggySight: A Scheme for Facial Lookup Privacy I Evtimov, P Sturmfels, T Kohno Proceedings on Privacy Enhancing Technologies 2021 (3), 204-226, 2021 | 23 | 2021 |

Robust physical-world attacks on deep learning visual classification K Eykholt, I Evtimov, E Fernandes, B Li, A Rahmati, C Xiao, A Prakash, ... | 16 | 2020 |

A whac-a-mole dilemma: Shortcuts come in multiples where mitigating one amplifies others Z Li, I Evtimov, A Gordo, C Hazirbas, T Hassner, CC Ferrer, C Xu, ... Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern …, 2023 | 15 | 2023 |

Security and machine learning in the real world I Evtimov, W Cui, E Kamar, E Kiciman, T Kohno, J Li arXiv preprint arXiv:2007.07205, 2020 | 13 | 2020 |

Disrupting model training with adversarial shortcuts I Evtimov, I Covert, A Kusupati, T Kohno arXiv preprint arXiv:2106.06654, 2021 | 8 | 2021 |

Adversarial evaluation of multimodal models under realistic gray box assumption I Evtimov, R Howes, B Dolhansky, H Firooz, CC Ferrer arXiv preprint arXiv:2011.12902, 2020 | 8 | 2020 |

You only need a good embeddings extractor to fix spurious correlations R Mehta, V Albiero, L Chen, I Evtimov, T Glaser, Z Li, T Hassner arXiv preprint arXiv:2212.06254, 2022 | 5 | 2022 |

Adversarial Text Normalization J Bitton, M Pavlova, I Evtimov arXiv preprint arXiv:2206.04137, 2022 | 1 | 2022 |

VPA: Fully Test-Time Visual Prompt Adaptation J Sun, M Ibrahim, M Hall, I Evtimov, ZM Mao, CC Ferrer, C Hazirbas Proceedings of the 31st ACM International Conference on Multimedia, 5796-5806, 2023 | | 2023 |

Confusing Large Models by Confusing Small Models V Albiero, R Mehta, I Evtimov, S Bell, L Sagun, A Markosyan Proceedings of the IEEE/CVF International Conference on Computer Vision …, 2023 | | 2023 |

ImageNet-X: Understanding Model Mistakes with Factor of Variation Annotations B Youbi Idrissi, D Bouchacourt, R Balestriero, I Evtimov, C Hazirbas, ... arXiv e-prints, arXiv: 2211.01866, 2022 | | 2022 |

Disrupting Machine Learning: Emerging Threats and Applications for Privacy and Dataset Ownership I Evtimov University of Washington, 2021 | | 2021 |