Fetching the paper…
Reading the bibliography…
Advances in machine learning (ML) in recent years have enabled a dizzying array of applications such as data analytics, autonomous systems, and security diagnostics.
R. L. Rivest, L. Adleman, and M. L. Dertouzos, “On data banks and privacy homomorphisms,” Foundations of secure computation , vol. 4, no. 11, pp. 169–180, 1978
1978
Earlier work this paper cites.
D. C. Liu and J. Nocedal, “On the limited memory bfgs method for large scale optimization,” Mathematical programming , vol. 45, no. 1-3, pp. 503–528, 1989
1989
Earlier work this paper cites.
N. S. Altman, “An introduction to kernel and nearest-neighbor nonparametric regression,” The American Statistician , vol. 46, no. 3, pp. 175–185, 1992
1992
Earlier work this paper cites.
M. Kearns and M. Li, “Learning in the presence of malicious errors,” SIAM Journal on Computing , vol. 22, no. 4, pp. 807–837, 1993
1993
Earlier work this paper cites.
T. C. Rindfleisch, “Privacy, information technology, and health care,” Communications of the ACM , vol. 40, no. 8, pp. 92–100, 1997
1997
Earlier work this paper cites.
R. S. Sutton and A. G. Barto, Reinforcement Learning: An Introduction . MIT Press, 1998
1998
Earlier work this paper cites.
Y. LeCun and C. Cortes, “The mnist database of handwritten digits,” 1998
1998
Earlier work this paper cites.
H. Drucker, D. Wu, and V. N. Vapnik, “Support vector machines for spam categorization,” IEEE Transactions on Neural Networks , vol. 10, no. 5, pp. 1048–1054, 1999
1999
Earlier work this paper cites.
A. K. Jain, M. N. Murty, and P. J. Flynn, “Data clustering: A review,” ACM Computing Surveys , vol. 31, no. 3, pp. 264–323, 1999
1999
Earlier work this paper cites.
J. Cannady, “Next generation intrusion detection: Autonomous reinforcement learning of network attacks,” in Proceedings of the 23rd national information systems security conference , 2000, pp. 1–12
2000
Earlier work this paper cites.
G. Hulten, L. Spencer, and P. Domingos, “Mining time-changing data streams,” in Proceedings of the seventh ACM SIGKDD international conference on Knowledge discovery and data mining . ACM, 2001, pp. 97–106
2001
Earlier work this paper cites.
R. J. Bolton and D. J. Hand, “Statistical fraud detection: A review,” Statistical science , pp. 235–249, 2002
2002
Earlier work this paper cites.
J. Hu and M. P. Wellman, “Nash Q-learning for general-sum stochastic games,” Journal of Machine Learning Research , vol. 4, pp. 1039–1069, 2003
2003
Earlier work this paper cites.
L. Rosasco, E. De Vito, A. Caponnetto, M. Piana, and A. Verri, “Are loss functions all the same?” Neural Computation , vol. 16, no. 5, pp. 1063–1076, 2004
2004
Earlier work this paper cites.
G. L. Wittel and S. F. Wu, “On attacking statistical spam filters.” in CEAS , 2004
2004
Earlier work this paper cites.
N. Provos et al. , “A virtual honeypot framework.” in USENIX Security Symposium , vol. 173, 2004, pp. 1–14
2004
Earlier work this paper cites.
D. Lowd and C. Meek, “Good word attacks on statistical spam filters.” in CEAS , 2005
2005
Earlier work this paper cites.
J. Newsome, B. Karp, and D. Song, “Polygraph: Automatically generating signatures for polymorphic worms,” in Security and Privacy, 2005 IEEE Symposium on . IEEE, 2005, pp. 226–241
2005
Earlier work this paper cites.
D. Lowd and C. Meek, “Adversarial learning,” in Proceedings of the eleventh ACM SIGKDD international conference on Knowledge discovery in data mining . ACM, 2005, pp. 641–647
2005
Earlier work this paper cites.
C. M. Bishop, “Pattern recognition,” Machine Learning , 2006
2006
Earlier work this paper cites.
M. Christodorescu and S. Jha, “Static analysis of executables to detect malicious patterns,” in 12th USENIX Security Symposium (USENIX Security 06) , 2006
2006
Earlier work this paper cites.
J. Zhang and M. Zulkernine, “Anomaly based network intrusion detection with unsupervised outlier detection,” in IEEE International Conference on Communications , vol. 5, 2006, pp. 2388–2393
2006
Earlier work this paper cites.
M. Barreno, B. Nelson, R. Sears, A. D. Joseph, and J. D. Tygar, “Can machine learning be secure?” in Proceedings of the 2006 ACM Symposium on Information, computer and communications security . ACM, 2006, pp. 16–25
2006
Earlier work this paper cites.
A. Globerson and S. Roweis, “Nightmare at test time: robust learning by feature deletion,” in Proceedings of the 23rd international conference on Machine learning . ACM, 2006, pp. 353–360
2006
Earlier work this paper cites.
B. Nelson and A. D. Joseph, “Bounding an attack’s complexity for a simple learning model,” in Proc. of the First Workshop on Tackling Computer Systems Problems with Machine Learning Techniques (SysML), Saint-Malo, France , 2006
2006
Earlier work this paper cites.
R. Perdisci, D. Dagon, W. Lee, P. Fogla, and M. Sharif, “Misleading worm signature generators using deliberate noise injection,” in Security and Privacy, 2006 IEEE Symposium on . IEEE, 2006, pp. 15–pp
2006
Earlier work this paper cites.
L. Xu, K. Crammer, and D. Schuurmans, “Robust support vector machine training via convex outlier ablation,” in Twenty-First AAAI National Conference on Artificial Intelligence , vol. 6, 2006, pp. 536–542
2006
Earlier work this paper cites.
C. Dwork, “Differential privacy: A survey of results,” in International Conference on Theory and Applications of Models of Computation . Springer Berlin Heidelberg, 2008, pp. 1–19
2008
Earlier work this paper cites.
A. Krizhevsky and G. Hinton, “Learning multiple layers of features from tiny images,” 2009
2009
Earlier work this paper cites.
V. Chandola, A. Banerjee, and V. Kumar, “Anomaly detection: A survey,” ACM Computing Surveys , vol. 41, no. 3, pp. 15:1–15:58, 2009
2009
Earlier work this paper cites.
M. Anthony and P. L. Bartlett, Neural network learning: Theoretical foundations . cambridge university press, 2009
2009
Earlier work this paper cites.
V. Vapnik and A. Vashist, “A new learning paradigm: Learning using privileged information,” Neural Networks , vol. 22, no. 5, pp. 544–557, 2009
2009
Earlier work this paper cites.
B. I. P. Rubinstein, B. Nelson, L. Huang, A. D. Joseph, S.-h. Lau, S. Rao, N. Taft, and J. D. Tygar, “Antidote: Understanding and defending against poisoning of anomaly detectors,” in 9th ACM SIGCOMM Conference on Internet measurement . ACM, 2009, pp. 1–14
2009
Earlier work this paper cites.
G. Stempfel and L. Ralaivola, “Learning SVMs from sloppily labeled data,” in International Conference on Artificial Neural Networks . Springer, 2009, pp. 884–893
2009
Earlier work this paper cites.
I. W. P. Consortium et al. , “Estimation of the warfarin dose with clinical and pharmacogenetic data,” N Engl J Med , vol. 2009, no. 360, pp. 753–764, 2009
2009
Earlier work this paper cites.
D. Erhan, Y. Bengio, A. Courville, and P. Vincent, “Visualizing higher-layer features of a deep network,” University of Montreal , vol. 1341, 2009
2009
Earlier work this paper cites.
D. Erhan, Y. Bengio, A. Courville, P.-A. Manzagol, P. Vincent, and S. Bengio, “Why does unsupervised pre-training help deep learning?” Journal of Machine Learning Research , vol. 11, pp. 625–660, 2010
2010
Earlier work this paper cites.
R. Sommer and V. Paxson, “Outside the closed world: On using machine learning for network intrusion detection,” in 2010 IEEE symposium on security and privacy . IEEE, 2010, pp. 305–316
2010
Earlier work this paper cites.
M. Kloft and P. Laskov, “Online anomaly detection under adversarial impact,” in International Conference on Artificial Intelligence and Statistics , 2010, pp. 405–412
2010
Earlier work this paper cites.
L. Bottou, “Large-scale machine learning with stochastic gradient descent,” in Proceedings of COMPSTAT’2010 . Springer, 2010, pp. 177–186
2010
Cited alongside, same era.
J. Masci, U. Meier, D. Cireşan, and J. Schmidhuber, “Stacked convolutional auto-encoders for hierarchical feature extraction,” in International Conference on Artificial Neural Networks and Machine Learning , 2011, pp. 52–59
2011
Cited alongside, same era.
D. M. Powers, “Evaluation: from precision, recall and f-measure to roc, informedness, markedness and correlation,” 2011
2011
Cited alongside, same era.
B. Biggio, B. Nelson, and P. Laskov, “Support vector machines under adversarial label noise.” in ACML , 2011, pp. 97–112
2011
Cited alongside, same era.
M. Tambe, Security and game theory: algorithms, deployed systems, lessons learned . Cambridge University Press, 2011
2011
A. Sinha, T. H. Nguyen, D. Kar, M. Brown, M. Tambe, and A. X. Jiang, “From physical security to cybersecurity,” Journal of Cybersecurity , p. tyv007, 2015
2015
Later among the works it cites.
R. Shokri and V. Shmatikov, “Privacy-preserving deep learning,” in 22nd ACM SIGSAC Conference on Computer and Communications Security , 2015, pp. 1310–1321
2015
Later among the works it cites.
2015
Later among the works it cites.
B. Letham, C. Rudin, T. H. McCormick, D. Madigan et al. , “Interpretable classifiers using rules and bayesian analysis: Building a better stroke prediction model,” The Annals of Applied Statistics , vol. 9, no. 3, pp. 1350–1371, 2015
2015
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
M. Brückner and T. Scheffer, “Stackelberg games for adversarial prediction problems,” in Proceedings of the 17th ACM SIGKDD international conference on Knowledge discovery and data mining . ACM, 2011, pp. 547–555
2011
Cited alongside, same era.
S. P. Kasiviswanathan, H. K. Lee, K. Nissim, S. Raskhodnikova, and A. Smith, “What can we learn privately?” SIAM Journal on Computing , vol. 40, no. 3, pp. 793–826, 2011
2011
Cited alongside, same era.
K. Chaudhuri, C. Monteleoni, and A. D. Sarwate, “Differentially private empirical risk minimization,” Journal of Machine Learning Research , vol. 12, no. Mar, pp. 1069–1109, 2011
2011
Cited alongside, same era.
D. Kifer and A. Machanavajjhala, “No free lunch in data privacy,” in Proceedings of the 2011 ACM SIGMOD International Conference on Management of data . ACM, 2011, pp. 193–204
2011
Cited alongside, same era.
K. P. Murphy, Machine Learning: A Probabilistic Perspective . MIT Press, 2012
2012
Cited alongside, same era.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” in Advances in Neural Information Processing Systems , 2012, pp. 1097–1105
2012
Cited alongside, same era.
B. Biggio, B. Nelson, and L. Pavel, “Poisoning attacks against support vector machines,” in Proceedings of the 29th International Conference on Machine Learning , 2012
2012
Cited alongside, same era.
2016
Closest in time.
O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowozin, K. Vaswani, and M. Costa, “Oblivious multi-party machine learning on trusted processors,” in 25th USENIX Security Symposium (USENIX Security 16) , 2016
2016
Closest in time.
D. Silver, A. Huang, C. J. Maddison, A. Guez, L. Sifre, G. Van Den Driessche, J. Schrittwieser, I. Antonoglou, V. Panneershelvam, M. Lanctot et al. , “Mastering the game of Go with deep neural networks and tree search,” Nature , vol. 529, no. 7587, pp. 484–489, 2016
2016
Closest in time.
I. Goodfellow, Y. Bengio, and A. Courville, “Deep learning,” 2016, Book in preparation for MIT Press (www.deeplearningbook.org)
2016
Closest in time.
A. Sinha, D. Kar, and M. Tambe, “Learning adversary behavior in security games: A pac model perspective,” in Proceedings of the 2016 International Conference on Autonomous Agents & Multiagent Systems . International Foundation for Autonomous Agents and Multiagent Systems, 2016, pp. 214–222
2016
Closest in time.
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in Proceedings of the 1st IEEE European Symposium on Security and Privacy . IEEE, 2016
2016
Closest in time.
2016
Closest in time.
2016
Closest in time.
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security . ACM, 2016, pp. 1528–1540
2016
Closest in time.
S. Alfeld, X. Zhu, and P. Barford, “Data poisoning attacks against autoregressive models,” in Thirtieth AAAI Conference on Artificial Intelligence , 2016
2016
Closest in time.
2016
Closest in time.
2016
Closest in time.
W. Xu, Y. Qi, and D. Evans, “Automatically evading classifiers,” in Proceedings of the 2016 Network and Distributed Systems Symposium , 2016
2016
Closest in time.
2016
Closest in time.
2016
Closest in time.
D. Warde-Farley and I. Goodfellow, “Adversarial perturbations of deep neural networks,” Advanced Structured Prediction, T. Hazan, G. Papandreou, and D. Tarlow, Eds , 2016
2016
Closest in time.
N. Carlini, P. Mishra, T. Vaidya, Y. Zhang, M. Sherr, C. Shields, D. Wagner, and W. Zhou, “Hidden voice commands,” in 25th USENIX Security Symposium (USENIX Security 16), Austin, TX , 2016
2016
Closest in time.
2016
Closest in time.
F. McSherry, “Statistical inference considered harmful,” 2016. [Online]. Available: https://github.com/frankmcsherry/blog/blob/master/posts/2016-06-14.md
2016
Closest in time.
2016
Closest in time.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in Proceedings of the 37th IEEE Symposium on Security and Privacy . IEEE, 2016
2016
Closest in time.
2016
Closest in time.
2016
Closest in time.
D. Warde-Farley and I. Goodfellow, “Adversarial perturbations of deep neural networks,” in Advanced Structured Prediction , T. Hazan, G. Papandreou, and D. Tarlow, Eds., 2016
2016
Closest in time.
M. Hardt, N. Megiddo, C. Papadimitriou, and M. Wootters, “Strategic classification,” in Proceedings of the 2016 ACM Conference on Innovations in Theoretical Computer Science , ser. ITCS ’16, 2016, pp. 111–122
2016
Closest in time.
2016
Closest in time.
2016
Closest in time.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in ACM SIGSAC Conference on Computer and Communications Security . ACM, 2016, pp. 308–318
2016
Closest in time.
R. Gilad-Bachrach, N. Dowlin, K. Laine, K. Lauter, M. Naehrig, and J. Wernsing, “Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy,” in Proceedings of The 33rd International Conference on Machine Learning , 2016, pp. 201–210
2016
Closest in time.
2016
Closest in time.
S. Barocas and A. D. Selbst, “Big data’s disparate impact,” California Law Review , vol. 104, 2016
2016
Closest in time.
A. Datta, S. Sen, and Y. Zick, “Algorithmic transparency via quantitative input influence,” in Proceedings of 37th IEEE Symposium on Security and Privacy , 2016
2016
Closest in time.
A. Mahendran and A. Vedaldi, “Visualizing deep convolutional neural networks using natural pre-images,” International Journal of Computer Vision , pp. 1–23, 2016
2016
Closest in time.
B. Li and Y. Vorobeychik, “Feature cross-substitution in adversarial classification,” in Advances in Neural Information Processing Systems , 2014, pp. 2087–2095
2095
Closest in time.