N. Dalvi, P. Domingos, Mausam, S. Sanghai, D. Verma, Adversarial classification, in: Int’l Conf. Knowl. Disc. and Data Mining, 2004, pp. 99–108
2004
Earlier work this paper cites.
G. L. Wittel, S. F. Wu, On attacking statistical spam filters, in: 1st Conf. Email and Anti-Spam (CEAS), 2004
2004
Earlier work this paper cites.
A. Christmann, I. Steinwart, On robust properties of convex risk minimization methods for pattern recognition, JMLR 5 (2004) 1007–1034
2004
Earlier work this paper cites.
D. Lowd, C. Meek, Adversarial learning, in: Int’l Conf. Knowl. Disc. and Data Mining, ACM Press, Chicago, IL, USA, 2005, pp. 641–647
2005
Earlier work this paper cites.
D. Lowd, C. Meek, Good word attacks on statistical spam filters, in: 2nd Conf. Email and Anti-Spam (CEAS), Mountain View, CA, USA, 2005
2005
Earlier work this paper cites.
A. Adler, Vulnerabilities in biometric encryption systems, in: T. Kanade, A. K. Jain, N. K. Ratha (Eds.), 5th Int’l Conf. Audio- and Video-Based Biometric Person Auth., Vol. 3546 of LNCS, Springer, 2005, pp. 1100–1109
2005
Earlier work this paper cites.
E. R. Dougherty, J. Hua, Z. Xiong, Y. Chen, Optimal robust classifiers, Pattern Recognition 38 (10) (2005) 1520–1532
2005
Earlier work this paper cites.
M. Barreno, B. Nelson, R. Sears, A. D. Joseph, J. D. Tygar, Can machine learning be secure?, in: ASIA CCS ’06, ACM, 2006, pp. 16–25
2006
Earlier work this paper cites.
A. Globerson, S. T. Roweis, Nightmare at test time: robust learning by feature deletion, in: 23rd ICML, Vol. 148, ACM, 2006, pp. 353–360
2006
Earlier work this paper cites.
G. Fumera, I. Pillai, F. Roli, Spam filtering based on the analysis of text information embedded into images, JMLR 7 (2006) 2699–2720
2006
Earlier work this paper cites.
P. Fogla, M. Sharif, R. Perdisci, O. Kolesnikov, W. Lee, Polymorphic blending attacks, in: USENIX Sec. Symp., 2006, pp. 241–256
2006
Earlier work this paper cites.
J. Newsome, B. Karp, D. Song, Paragraph: Thwarting signature learning by training maliciously, in: RAID, LNCS, Springer, 2006, pp. 81–105
2006
Earlier work this paper cites.
P. Laskov, R. Lippmann (Eds.), NIPS Workshop on Machine Learning in Adversarial Environments for Computer Security , 2007
2007
Earlier work this paper cites.
B. Nelson, M. Barreno, F. J. Chi, A. D. Joseph, B. I. P. Rubinstein, U. Saini, C. Sutton, J. D. Tygar, K. Xia, Exploiting machine learning to subvert your spam filter, in: LEET ’08, USENIX Assoc., 2008, pp. 1–9
2008
Earlier work this paper cites.
C. H. Teo, A. Globerson, S. Roweis, A. Smola, Convex learning with invariances, in: NIPS 20, MIT Press, 2008, pp. 1489–1496
2008
Earlier work this paper cites.
B. Biggio, G. Fumera, F. Roli, Adversarial pattern classification using multiple classifiers and randomisation, in: SSPR 2008, Vol. 5342 of LNCS, Springer, 2008, pp. 500–509
2008
Earlier work this paper cites.
L. I. Kuncheva, Classifier ensembles for detecting concept change in streaming data: Overview and perspectives, in: SUEMA, 2008, pp. 5–10
2008
Earlier work this paper cites.
G. F. Cretu, A. Stavrou, M. E. Locasto, S. J. Stolfo, A. D. Keromytis, Casting out demons: Sanitizing training data for anomaly sensors, in: IEEE Symp. Security and Privacy, IEEE CS, 2008, pp. 81–95
2008
Earlier work this paper cites.
B. I. Rubinstein, B. Nelson, L. Huang, A. D. Joseph, S.-h. Lau, S. Rao, N. Taft, J. D. Tygar, Antidote: understanding and defending against poisoning of anomaly detectors, in: IMC ’09, ACM, 2009, pp. 1–14
2009
Earlier work this paper cites.
A. Kolcz, C. H. Teo, Feature weighting for improved classifier robustness, in: 6th Conf. Email and Anti-Spam (CEAS), 2009
2009
Earlier work this paper cites.
A. O. Thomas, A. Rusu, V. Govindaraju, Synthetic handwritten captchas, Pattern Recognition 42 (12) (2009) 3365 – 3373, new Frontiers in Handwriting Recognition
2009
Earlier work this paper cites.
H. Xu, C. Caramanis, S. Mannor, Robustness and regularization of support vector machines, JMLR 10 (2009) 1485–1510
2009
Earlier work this paper cites.
M. Kloft, P. Laskov, Online anomaly detection under adversarial impact, in: 13th AISTATS, 2010, pp. 405–412
2010
Earlier work this paper cites.
O. Dekel, O. Shamir, L. Xiao, Learning to classify with missing and corrupted features , Machine Learning 81 (2010) 149–178
2010
Earlier work this paper cites.
M. Barreno, B. Nelson, A. Joseph, J. Tygar, The security of machine learning, Machine Learning 81 (2010) 121–148
2010
Earlier work this paper cites.
P. Laskov, R. Lippmann, Machine learning in adversarial environments, Machine Learning 81 (2010) 115–119
2010
Earlier work this paper cites.
J. Galbally, C. McCool, J. Fierrez, S. Marcel, J. Ortega-Garcia, On the vulnerability of face verification systems to hill-climbing attacks, Patt. Rec. 43 (3) (2010) 1027–1038
2010
Earlier work this paper cites.
B. Biggio, G. Fumera, F. Roli, Multiple classifier systems for robust classifier design in adversarial environments, Int’l JMLC 1 (1) (2010) 27–41
2010
Earlier work this paper cites.
W. Liu, S. Chawla, Mining adversarial patterns via regularized loss minimization, Machine Learning 81 (1) (2010) 69–83
2010
Earlier work this paper cites.
B. Biggio, G. Fumera, I. Pillai, F. Roli, A survey and experimental evaluation of image spam filtering techniques, PRL 32 (10) (2011) 1436 – 1446
2011
Earlier work this paper cites.
L. Huang, A. D. Joseph, B. Nelson, B. Rubinstein, J. D. Tygar, Adversarial machine learning, in: 4th AISec, Chicago, IL, USA, 2011, pp. 43–57
2011
Earlier work this paper cites.
M. Martinez-Diaz, J. Fierrez, J. Galbally, J. Ortega-Garcia, An evaluation of indirect attacks and countermeasures in fingerprint verification systems, Patt. Rec. Lett. 32 (12) (2011) 1643 – 1651
2011
Earlier work this paper cites.
B. Biggio, I. Corona, G. Fumera, G. Giacinto, F. Roli, Bagging classifiers for fighting poisoning attacks in adversarial classification tasks, in: MCS, Vol. 6713 of LNCS, Springer-Verlag, 2011, pp. 350–359
2011
Earlier work this paper cites.
B. Nelson, B. Biggio, P. Laskov, Understanding the risk factors of learning in adversarial environments, in: AISec ’11, 2011, pp. 87–92
2011
Earlier work this paper cites.
B. Biggio, B. Nelson, P. Laskov, Poisoning attacks against support vector machines, in: 29th ICML, 2012, pp. 1807–1814
2012
Earlier work this paper cites.
M. Kloft, P. Laskov, Security analysis of online centroid anomaly detection, JMLR 13 (2012) 3647–3690
2012
Earlier work this paper cites.
M. Brückner, C. Kanzow, T. Scheffer, Static prediction games for adversarial learning problems, JMLR 13 (2012) 2617–2654
2012
Earlier work this paper cites.
B. Nelson, B. I. Rubinstein, L. Huang, A. D. Joseph, S. J. Lee, S. Rao, J. D. Tygar, Query strategies for evading convex-inducing classifiers, JMLR 13 (2012) 1293–1332
2012
Earlier work this paper cites.
A. Barth, B. I. Rubinstein, M. Sundararajan, J. C. Mitchell, D. Song, P. L. Bartlett, A learning-based approach to reactive security, IEEE Trans. Dependable and Sec. Comp. 9 (4) (2012) 482–493
2012
Earlier work this paper cites.
M. Wooldridge, Does game theory work?, IEEE IS 27 (6) (2012) 76–80
2012
Earlier work this paper cites.
G. Cybenko, C. E. Landwehr, Security analytics and measurements, IEEE Security & Privacy 10 (3) (2012) 5–8
2012
Earlier work this paper cites.