Fetching the paper…
Reading the bibliography…
In machine learning (ML) security, attacks like evasion, model stealing or membership inference are generally studied in individually.
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proceedings of the IEEE , vol. 86, no. 11, pp. 2278–2324, November 1998
1998
Earlier work this paper cites.
S. Mika, G. Ratsch, J. Weston, B. Scholkopf, and K. R. Mullers, “Fisher discriminant analysis with kernels,” in IEEE Signal Processing Society Workshop (Cat. No.98TH8468) , Aug 1999, pp. 41–48
1999
Earlier work this paper cites.
L. Remaki and M. Cheriet, “Kcs-new kernel family with compact support in scale space: formulation and impact,” IEEE Transactions on Image Processing , vol. 9, no. 6, pp. 970–981, 2000
2000
Earlier work this paper cites.
M. D. Stevenson, J. Oakley, and J. B. Chilcott, “Gaussian process modeling in conjunction with individual patient simulation modeling: A case study describing the calculation of cost-effectiveness ratios for the treatment of established osteoporosis,” Medical Decision Making , vol. 24, no. 1, pp. 89–100, 2004
2004
Earlier work this paper cites.
C. E. Rasmussen and C. K. I. Williams, Gaussian processes for machine learning . MIT Press, 2006
2006
Earlier work this paper cites.
T. Chen, J. Morris, and E. Martin, “Gaussian process regression for multivariate spectroscopic calibration,” Chemometrics and Intelligent Laboratory Systems , vol. 87, no. 1, pp. 59 – 71, 2007
2007
Earlier work this paper cites.
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng, “Reading digits in natural images with unsupervised feature learning,” in NIPS Workshop on Deep and Unsupervised Feature Learning , 2011
2011
Earlier work this paper cites.
GPy, “GPy: A gaussian process framework in python,” http://github.com/SheffieldML/GPy
2012
Earlier work this paper cites.
L. Clifton, D. A. Clifton, M. A. F. Pimentel, P. J. Watkinson, and L. Tarassenko, “Gaussian processes for personalized e-health monitoring with wearable sensors,” IEEE Transactions on Biomedical Engineering , vol. 60, no. 1, pp. 193–197, Jan 2013
2013
Earlier work this paper cites.
M. Lichman, “UCI machine learning repository,” 2013. [Online]. Available: http://archive.ics.uci.edu/ml
2013
Earlier work this paper cites.
P. Laskov et al. , “Practical evasion of a learning-based classifier: A case study,” in 2014 IEEE S&P , 2014, pp. 197–211
2014
Earlier work this paper cites.
D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon, and K. Rieck, “DREBIN: Effective and Explainable Detection of Android Malware in Your Pocket.” in NDSS , 2014
2014
Earlier work this paper cites.
I. J. Goodfellow et al. , “Explaining and harnessing adversarial examples,” in ICLR , 2015
2015
Earlier work this paper cites.
M. A. et al., “TensorFlow: Large-scale machine learning on heterogeneous systems,” 2015
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction apis,” in USENIX , 2016
2016
Cited alongside, same era.
P. Russu, A. Demontis, B. Biggio, G. Fumera, and F. Roli, “Secure kernel machines against evasion attacks,” in AISec@CCS . ACM, 2016
2016
Cited alongside, same era.
T. Tanay and L. D. Griffin, “A boundary tilting persepective on the phenomenon of adversarial examples,” CoRR , vol. 1608.07690, 2016
2016
Cited alongside, same era.
N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The Limitations of Deep Learning in Adversarial Settings,” in EuroS&P , 2016
2016
Cited alongside, same era.
N. Šrndić and P. Laskov, “Hidost: a static machine-learning-based detector of malicious files,” EURASIP Journal on Information Security , vol. 2016, no. 1, p. 22, Sep 2016. [Online]. Available: https://doi.org/10.1186/s13635-016-0045-0
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” pp. 274–283, 2018
2018
Closest in time.
S. J. Oh, M. Augustin, B. Schiele, and M. Fritz, “Towards reverse-engineering black-box neural networks,” in ICLR , 2018
2018
Closest in time.
A. Raghunathan, J. Steinhardt, and P. Liang, “Certified defenses against adversarial examples,” in ICLR , 2018
2018
Closest in time.
O. Suciu, R. Marginean, Y. Kaya, H. Daume III, and T. Dumitras, “When does machine learning { \{ FAIL } \} ? generalized transferability for evasion and poisoning attacks,” in USENIX , 2018, pp. 1299–1316
2018
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2016
Cited alongside, same era.
2016
Cited alongside, same era.
A. Demontis, M. Melis, B. Biggio, D. Maiorca, D. Arp, K. Rieck, I. Corona, G. Giacinto, and F. Roli, “Yes, machine learning can be more secure! a case study on android malware detection,” IEEE Transactions on Dependable and Secure Computing , 2017
2017
Cited alongside, same era.
M. Melis, A. Demontis, B. Biggio, G. Brown, G. Fumera, and F. Roli, “Is deep learning safe for robot vision? adversarial examples against the icub humanoid,” in ICCV Workshops 2017 , pp. 751–759
2017
Cited alongside, same era.
N. Carlini and D. Wagner, “Adversarial examples are not easily detected: Bypassing ten detection methods,” pp. 3–14, 2017
2017
Cited alongside, same era.
B. Hitaj, G. Ateniese, and F. Perez-Cruz, “Deep models under the gan: information leakage from collaborative deep learning,” in ACM SIGSAC CCS , 2017, pp. 603–618
2017
Cited alongside, same era.
M. Hein and M. Andriushchenko, “Formal guarantees on the robustness of a classifier against adversarial manipulation,” in NIPS , 2017
2017
Cited alongside, same era.
J. Bradshaw, A. G. d. G. Matthews, and Z. Ghahramani, “Adversarial Examples, Uncertainty, and Transfer Testing Robustness in Gaussian Process Hybrid Deep Networks,” ArXiv e-prints , Jul. 2017
2017
Cited alongside, same era.
2018
Closest in time.
Y. Wang, S. Jha, and K. Chaudhuri, “Analyzing the robustness of nearest neighbors to adversarial examples,” in ICML , 2018, pp. 5120–5129
2018
Closest in time.
A. Fawzi, H. Fawzi, and O. Fawzi, “Adversarial vulnerability for any classifier,” in NIPS , 2018, pp. 1186–1195
2018
Closest in time.
M. T. Smith, M. A. Álvarez, M. Zwiessele, and N. D. Lawrence, “Differentially private regression with gaussian processes,” in AISTATS , 2018, pp. 1195–1203
2018
Closest in time.
I. Bogunovic, J. Scarlett, S. Jegelka, and V. Cevher, “Adversarially robust optimization with gaussian processes,” in NIPS , 2018, pp. 5765–5775
2018
Closest in time.
A. Salem, Y. Zhang, M. Humbert, M. Fritz, and M. Backes, “ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models,” in NDSS , 2019
2019
Closest in time.
R. S. Liwei Song and P. Mittal, “Membership inference attacks against adversarially robust deep learning models,” 2019
2019
Closest in time.
M. Juuti, S. Szyller, S. Marchal, and N. Asokan, “Prada: protecting against dnn model stealing attacks,” pp. 512–527, 2019
2019
Closest in time.
K. Grosse, D. Pfaff, M. T. Smith, and M. Backes, “The limitations of model uncertainty in adversarial settings,” Bayesian Deepl Learning Workshop @NeurIPS , 2019
2019
Closest in time.
M. T. Smith, K. Grosse, M. Backes, and M. A. Alvarez, “Adversarial vulnerability bounds for gaussian process classification,” ML with guarantees @NeurIPS , 2019
2019
Closest in time.
A. Blaas, L. Laurenti, A. Patane, L. Cardelli, M. Kwiatkowska, and S. Roberts, “Robustness quantification for classification with gaussian processes,” AIstats , 2020
2020
Closest in time.