Robust physical-world attacks on deep learning visual classification K Eykholt, I Evtimov, E Fernandes, B Li, A Rahmati, C Xiao, A Prakash, ... Proceedings of the IEEE conference on computer vision and pattern …, 2018 | 2399* | 2018 |

Physical adversarial examples for object detectors D Song, K Eykholt, I Evtimov, E Fernandes, B Li, A Rahmati, F Tramer, ... 12th USENIX workshop on offensive technologies (WOOT 18), 2018 | 407 | 2018 |

Is tricking a robot hacking? I Evtimov, D O’Hair, E Fernandes, R Calo, T Kohno Berkeley Technology Law Journal 34 (3), 891-918, 2019 | 27* | 2019 |

FoggySight: A Scheme for Facial Lookup Privacy I Evtimov, P Sturmfels, T Kohno Proceedings on Privacy Enhancing Technologies 2021 (3), 204-226, 2021 | 22 | 2021 |

Security and machine learning in the real world I Evtimov, W Cui, E Kamar, E Kiciman, T Kohno, J Li arXiv preprint arXiv:2007.07205, 2020 | 13 | 2020 |

ImageNet-X: Understanding Model Mistakes with Factor of Variation Annotations BY Idrissi, D Bouchacourt, R Balestriero, I Evtimov, C Hazirbas, N Ballas, ... arXiv preprint arXiv:2211.01866, 2022 | 8 | 2022 |

Adversarial evaluation of multimodal models under realistic gray box assumption I Evtimov, R Howes, B Dolhansky, H Firooz, CC Ferrer arXiv preprint arXiv:2011.12902, 2020 | 7 | 2020 |

Disrupting model training with adversarial shortcuts I Evtimov, I Covert, A Kusupati, T Kohno arXiv preprint arXiv:2106.06654, 2021 | 6 | 2021 |

A whac-a-mole dilemma: Shortcuts come in multiples where mitigating one amplifies others Z Li, I Evtimov, A Gordo, C Hazirbas, T Hassner, CC Ferrer, C Xu, ... Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern …, 2023 | 3 | 2023 |

You Only Need a Good Embeddings Extractor to Fix Spurious Correlations R Mehta, V Albiero, L Chen, I Evtimov, T Glaser, Z Li, T Hassner arXiv preprint arXiv:2212.06254, 2022 | 2 | 2022 |

Adversarial Text Normalization J Bitton, M Pavlova, I Evtimov arXiv preprint arXiv:2206.04137, 2022 | 1 | 2022 |

Disrupting Machine Learning: Emerging Threats and Applications for Privacy and Dataset Ownership I Evtimov University of Washington, 2021 | | 2021 |