Fetching the paper…
Reading the bibliography…
We propose the use of data transformations as a defense against evasion attacks on ML classifiers.
R. Penrose, “On best approximate solutions of linear matrix equations,” in Mathematical Proceedings of the Cambridge Philosophical Society , vol. 52. Cambridge University Press, 1956, pp. 17–19
1956
Earlier work this paper cites.
Y. LeCun and C. Cortes, “The mnist database of handwritten digits,” 1998
1998
Earlier work this paper cites.
B. Scholkopf and A. J. Smola, Learning with Kernels: Support Vector Machines, Regularization, Optimization, and Beyond . Cambridge, MA, USA: MIT Press, 2001
2001
Earlier work this paper cites.
B. Schölkopf and A. J. Smola, Learning with Kernels: Support Vector Machines, Regularization, Optimization, and Beyond . MIT Press, Jan. 2002
2002
Earlier work this paper cites.
M. Barreno, B. Nelson, R. Sears, A. D. Joseph, and J. D. Tygar, “Can machine learning be secure?” in Proceedings of the 2006 ACM Symposium on Information, computer and communications security . ACM, 2006, pp. 16–25
2006
Earlier work this paper cites.
G. V. Cormack, “Email spam filtering: A systematic review,” Foundations and Trends in Information Retrieval , vol. 1, no. 4, pp. 335–455, 2007
2007
Earlier work this paper cites.
P. Laskov and M. Kloft, “A framework for quantitative security analysis of machine learning,” in Proceedings of the 2nd ACM workshop on Security and artificial intelligence . ACM, 2009, pp. 1–4
2009
Earlier work this paper cites.
L. Van Der Maaten, E. Postma, and J. Van den Herik, “Dimensionality reduction: a comparative review,” J Mach Learn Res , vol. 10, pp. 66–71, 2009
2009
Earlier work this paper cites.
R. Collobert, J. Weston, L. Bottou, M. Karlen, K. Kavukcuoglu, and P. Kuksa, “Natural language processing (almost) from scratch,” Journal of Machine Learning Research , vol. 12, no. Aug, pp. 2493–2537, 2011
2011
Earlier work this paper cites.
L. Huang, A. D. Joseph, B. Nelson, B. I. Rubinstein, and J. Tygar, “Adversarial machine learning,” in Proceedings of the 4th ACM workshop on Security and Artificial Intelligence . ACM, 2011, pp. 43–58
2011
Earlier work this paper cites.
F. Pedregosa, G. Varoquaux, A. Gramfort, V. Michel, B. Thirion, O. Grisel, M. Blondel, P. Prettenhofer, R. Weiss, V. Dubourg, J. Vanderplas, A. Passos, D. Cournapeau, M. Brucher, M. Perrot, and E. Duchesnay, “Scikit-learn: Machine learning in Python,” Journal of Machine Learning Research , vol. 12, pp. 2825–2830, 2011
2011
Earlier work this paper cites.
B. Biggio, B. Nelson, and P. Laskov, “Poisoning attacks against support vector machines,” in Proceedings of the 29th International Conference on Machine Learning (ICML-12) , 2012, pp. 1807–1814
2012
Earlier work this paper cites.
D. CireşAn, U. Meier, J. Masci, and J. Schmidhuber, “Multi-column deep neural network for traffic sign classification,” Neural Networks , vol. 32, pp. 333–338, 2012
2012
Earlier work this paper cites.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” in Advances in neural information processing systems , 2012, pp. 1097–1105
2012
Earlier work this paper cites.
D. Anguita, A. Ghio, L. Oneto, X. Parra, and J. L. Reyes-Ortiz, “A public domain dataset for human activity recognition using smartphones.” in ESANN , 2013
2013
Earlier work this paper cites.
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli, “Evasion attacks against machine learning at test time,” in Joint European Conference on Machine Learning and Knowledge Discovery in Databases . Springer, 2013, pp. 387–402
2013
Earlier work this paper cites.
G. E. Dahl, J. W. Stokes, L. Deng, and D. Yu, “Large-scale malware classification using random projections and neural networks,” in 2013 IEEE International Conference on Acoustics, Speech and Signal Processing . IEEE, 2013, pp. 3422–3426
2013
Earlier work this paper cites.
D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon, and K. Rieck, “Drebin: Effective and explainable detection of android malware in your pocket.” in NDSS , 2014
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
J. Shlens, “A tutorial on principal component analysis,” arXiv preprint arXiv:1404.1100 , 2014
2014
Cited alongside, same era.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in International Conference on Learning Representations , 2014
2014
Cited alongside, same era.
Y. Taigman, M. Yang, M. Ranzato, and L. Wolf, “Deepface: Closing the gap to human-level performance in face verification,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2014, pp. 1701–1708
2014
Cited alongside, same era.
S. Dieleman and J. S. et.al., “Lasagne: First release.” Aug. 2015. [Online]. Available: http://dx.doi.org/10.5281/zenodo.27878
2015
Cited alongside, same era.
NVIDIA, “Self driving vehicles development platform,” http://www.nvidia.com/object/drive-px.html
2016
Later among the works it cites.
2016
Later among the works it cites.
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The limitations of deep learning in adversarial settings,” in 2016 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 2016, pp. 372–387
2016
Later among the works it cites.
N. Papernot, P. D. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in IEEE Symposium on Security and Privacy, SP 2016 , 2016, pp. 582–597
2016
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2015
Cited alongside, same era.
2015
Cited alongside, same era.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” Nature , vol. 521, no. 7553, pp. 436–444, 2015
2015
Cited alongside, same era.
2015
Cited alongside, same era.
2015
Cited alongside, same era.
A. Nguyen, J. Yosinski, and J. Clune, “Deep neural networks are easily fooled: High confidence predictions for unrecognizable images,” in 2015 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) . IEEE, 2015, pp. 427–436
2015
Cited alongside, same era.
2015
Cited alongside, same era.
N. Carlini, P. Mishra, T. Vaidya, Y. Zhang, M. Sherr, C. Shields, D. Wagner, and W. Zhou, “Hidden voice commands,” in 25th USENIX Security Symposium (USENIX Security 16), Austin, TX , 2016
2016
Cited alongside, same era.
P. Russu, A. Demontis, B. Biggio, G. Fumera, and F. Roli, “Secure kernel machines against evasion attacks,” in Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security , ser. AISec ’16. New York, NY, USA: ACM, 2016, pp. 59–69. [Online]. Available: http://doi.acm.org/10.1145/2996758.2996771
2016
Later among the works it cites.
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security . ACM, 2016, pp. 1528–1540
2016
Later among the works it cites.
C. Smutz and A. Stavrou, “When a tree falls: Using diversity in ensemble classifiers to identify evasion in malware detectors,” in 23nd Annual Network and Distributed System Security Symposium, NDSS 2016
2016
Later among the works it cites.
N. Šrndić and P. Laskov, “Hidost: a static machine-learning-based detector of malicious files,” EURASIP Journal on Information Security , vol. 2016, no. 1, p. 22, 2016
2016
Later among the works it cites.
2016
Later among the works it cites.
2016
Later among the works it cites.
W. Xu, Y. Qi, and D. Evans, “Automatically evading classifiers,” in Proceedings of the 2016 Network and Distributed Systems Symposium , 2016
2016
Later among the works it cites.
F. Zhang, P. P. Chan, B. Biggio, D. S. Yeung, and F. Roli, “Adversarial feature selection against evasion attacks,” IEEE Transactions on Cybernetics , vol. 46, no. 3, pp. 766–777, 2016
2016
Later among the works it cites.
2016
Later among the works it cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in IEEE Symposium on Security and Privacy, 2017
2017
Closest in time.
2017
Closest in time.
2017
Closest in time.
2017
Closest in time.