Fetching the paper…
Reading the bibliography…
To promote secure and private artificial intelligence (SPAI), we review studies on the model security and data privacy of DNNs.
A. C.-C. Yao, “How to generate and exchange secrets,” in 27th Annual Symposium on Foundations of Computer Science , 1986
1986
Earlier work this paper cites.
L. I. Rudin, S. Osher, and E. Fatemi, “Nonlinear total variation based noise removal algorithms,” Physica D: Nonlinear Phenomena , vol. 60, no. 1-4, pp. 259–268, 1992
1992
Earlier work this paper cites.
S. Hochreiter and J. Schmidhuber, “Long short-term memory,” Neural computation , vol. 9, no. 8, pp. 1735–1780, 1997
1997
Earlier work this paper cites.
D. Wierstra, T. Schaul, J. Peters, and J. Schmidhuber, “Natural evolution strategies,” in Proc. IEEE Congress on Evolutionary Computation , 2008
2008
Earlier work this paper cites.
G. F. Cretu, A. Stavrou, M. E. Locasto, S. J. Stolfo, and A. D. Keromytis, “Casting out demons: Sanitizing training data for anomaly sensors,” in 2008 IEEE Symposium on Security and Privacy (sp 2008) . IEEE, 2008, pp. 81–95
2008
Earlier work this paper cites.
C. Dwork, “Differential privacy: A survey of results,” in International Conference on Theory and Applications of Models of Computation , 2008
2008
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “ImageNet: a large-scale hierarchical image database,” in Proc. IEEE Conference on Computer Vision and Pattern Recognition , 2009
2009
Earlier work this paper cites.
K. Chaudhuri and C. Monteleoni, “Privacy-preserving logistic regression,” in Advances in Neural Information Processing Systems , 2009
2009
Earlier work this paper cites.
Y. Bengio et al. , “Learning deep architectures for AI,” Foundations and Trends in Machine Learning , vol. 2, no. 1, pp. 1–127, 2009
2009
Earlier work this paper cites.
H. Lee, R. Grosse, R. Ranganath, and A. Y. Ng, “Convolutional deep belief networks for scalable unsupervised learning of hierarchical representations,” in 26th Annual International Conference on Machine Learning , 2009
2009
Earlier work this paper cites.
2009
Earlier work this paper cites.
Y. LeCun, C. Cortes, and C. Burges, “Mnist handwritten digit database,” 2010. [Online]. Available: http://yann.lecun.com/exdb/mnist
2010
Earlier work this paper cites.
J. Dean, G. Corrado, R. Monga, K. Chen, M. Devin, M. Mao, A. Senior, P. Tucker, K. Yang, Q. V. Le et al. , “Large scale distributed deep networks,” in Advances in Neural Information Processing Systems , 2012
2012
Earlier work this paper cites.
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli, “Evasion attacks against machine learning at test time,” in Proc. Joint European Conference on Machine Learning and Knowledge Discovery in Databases , 2013
2013
Earlier work this paper cites.
2013
Earlier work this paper cites.
J. W. Bos, K. Lauter, J. Loftus, and M. Naehrig, “Improved security for a ring-based fully homomorphic encryption scheme,” in IMA International Conference on Cryptography and Coding , 2013
2013
Earlier work this paper cites.
2013
Earlier work this paper cites.
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
M. Li, D. G. Andersen, J. W. Park, A. J. Smola, A. Ahmed, V. Josifovski, J. Long, E. J. Shekita, and B.-Y. Su, “Scaling distributed machine learning with the parameter server.” in Symposium on Operating Systems Design and Implementation , 2014
2014
Earlier work this paper cites.
C. Dwork, A. Roth et al. , “The algorithmic foundations of differential privacy,” Foundations and Trends® in Theoretical Computer Science , vol. 9, no. 3–4, pp. 211–407, 2014
2014
Earlier work this paper cites.
S. Ren, K. He, R. Girshick, and J. Sun, “Faster R-CNN: towards real-time object detection with region proposal networks,” in Advances in Neural Information Processing Systems , 2015
2015
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in Proc. ACM SIGSAC Conference on Computer and Communications Security , 2015
2015
Earlier work this paper cites.
D. P. Kingma and J. Ba, “Adam: a method for stochastic optimization,” in Proc. International Conference on Learning Representations , 2015
2015
Earlier work this paper cites.
R. Shokri and V. Shmatikov, “Privacy-preserving deep learning,” in 22nd ACM SIGSAC Conference on Computer and Communications Security , 2015
2015
Earlier work this paper cites.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” Nature , vol. 521, no. 7553, p. 436, 2015
2015
Earlier work this paper cites.
O. Ronneberger, P. Fischer, and T. Brox, “U-net: Convolutional networks for biomedical image segmentation,” in International Conference on Medical Image Computing and Computer-Assisted Intervention , 2015
2015
Earlier work this paper cites.
S. Bach, A. Binder, G. Montavon, F. Klauschen, K.-R. Müller, and W. Samek, “On pixel-wise explanations for non-linear classifier decisions by layer-wise relevance propagation,” PLoS One , vol. 10, no. 7, p. e0130140, 2015
2015
Earlier work this paper cites.
A. L. Buczak and E. Guven, “A survey of data mining and machine learning methods for cyber security intrusion detection,” IEEE Communications Surveys & Tutorials , vol. 18, no. 2, pp. 1153–1176, 2016
2016
Earlier work this paper cites.
C. Yan, X. Wenyuan, and J. Liu, “Can you trust autonomous vehicles: contactless attacks against sensors of self-driving vehicle,” in DEF CON 24 Hacking Conference , 2016
2016
Earlier work this paper cites.
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition,” in Proc. ACM SIGSAC Conference on Computer and Communications Security , 2016
2016
Earlier work this paper cites.
N. Papernot, P. D. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “the limitations of deep learning in adversarial settings,” in Proc. IEEE European Symposium on Security and Privacy , 2016
2016
Earlier work this paper cites.
A. Kurakin, I. Goodfellow, S. Bengio et al. , “Adversarial examples in the physical world,” 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
A. Graese, A. Rozsa, and T. E. Boult, “Assessing threat of adversarial examples on deep neural networks,” in Proc. IEEE International Conference on Machine Learning and Applications , 2016
2016
Earlier work this paper cites.
A. V. Oord, N. Kalchbrenner, and K. Kavukcuoglu, “Pixel recurrent neural networks,” in Proc. 33rd International Conference on Machine Learning , 2016
2016
Earlier work this paper cites.
N. Papernot, P. D. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in Proc. IEEE Symposium on Security and Privacy , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in IEEE Conference on Computer Vision and Pattern Recognition , 2016
2016
Earlier work this paper cites.
R. Gilad-Bachrach, N. Dowlin, K. Laine, K. Lauter, M. Naehrig, and J. Wernsing, “Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy,” in International Conference on Machine Learning , 2016
2016
Earlier work this paper cites.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security , 2016
2016
Earlier work this paper cites.
N. Phan, Y. Wang, X. Wu, and D. Dou, “Differential privacy preservation for deep auto-encoders: an application of human behavior prediction.” in AAAI Conference on Artificial Intelligence , 2016
2016
Earlier work this paper cites.
I. Chillotti, N. Gama, M. Georgieva, and M. Izabachene, “Faster fully homomorphic encryption: Bootstrapping in less than 0.1 seconds,” in International Conference on the Theory and Application of Cryptology and Information Security , 2016
2016
Earlier work this paper cites.
M. Abadi, P. Barham, J. Chen, Z. Chen, A. Davis, J. Dean, M. Devin, S. Ghemawat, G. Irving, M. Isard et al. , “Tensorflow: a system for large-scale machine learning,” in 12th USENIX Symposium on Operating Systems Design and Implementation , 2016
2016
Earlier work this paper cites.
M. Bun and T. Steinke, “Concentrated differential privacy: Simplifications, extensions, and lower bounds,” in Theory of Cryptography Conference , 2016
2016
Earlier work this paper cites.
Ö. Çiçek, A. Abdulkadir, S. S. Lienkamp, T. Brox, and O. Ronneberger, “3D U-Net: Learning dense volumetric segmentation from sparse annotation,” in International Conference on Medical Image Computing and Computer-Assisted Intervention , 2016
2016
Earlier work this paper cites.
B. Shickel, P. Tighe, A. Bihorac, and P. Rashidi, “Deep EHR: a survey of recent advances on deep learning techniques for electronic health record (EHR) analysis,” Journal of Biomedical and Health Informatics , 2017
2017
Earlier work this paper cites.
Y. Song, T. Kim, S. Nowozin, S. Ermon, and N. Kushman, “PixelDefend: leveraging generative models to understand and defend against adversarial examples,” in Proc. International Conference on Machine Learning , 2017
2017
Earlier work this paper cites.
J. H. Metzen, T. Genewein, V. Fischer, and B. Bischoff, “On detecting adversarial perturbations,” in Proc. International Conference on Learning Representations , 2017
2017
Earlier work this paper cites.
D. Meng and H. Chen, “Magnet: a two-pronged defense against adversarial examples,” in Proc. ACM SIGSAC Conference on Computer and Communications Security , 2017, pp. 135–147
2017
Earlier work this paper cites.
G. Katz, C. Barrett, D. L. Dill, K. Julian, and M. J. Kochenderfer, “Reluplex: an efficient SMT solver for verifying deep neural networks,” in Proc. International Conference on Computer Aided Verification (CAV) , 2017
2017
Earlier work this paper cites.
J. Steinhardt, P. W. W. Koh, and P. S. Liang, “Certified defenses for data poisoning attacks,” in Advances in Neural Information Processing Systems , 2017
2017
Earlier work this paper cites.
P. W. Koh and P. Liang, “Understanding black-box predictions via influence functions,” in Proc. 34th International Conference on Machine Learning , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in Proc. IEEE Symposium on Security and Privacy , 2017
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in Proc. IEEE Symposium on Security and Privacy , 2017
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in Proc. IEEE Conference on Computer Vision and Pattern Recognition , 2017
2017
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, “Practical black-box attacks against machine learning,” in Proc. ACM ASIA Conference on Computer and Communications Security , 2017
2017
Earlier work this paper cites.
A. Odena, C. Olah, and J. Shlens, “Conditional image synthesis with auxiliary classifier gans,” in Proc. 34th International Conference on Machine Learning , 2017
2017
Earlier work this paper cites.
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh, “ZOO: zeroth order optimization based black-box attacks to deep neural networks without training substitute models,” in Proc. 10th ACM Workshop on Artificial Intelligence and Security , 2017
2017
Earlier work this paper cites.
L. Muñoz-González, B. Biggio, A. Demontis, A. Paudice, V. Wongrassamee, E. C. Lupu, and F. Roli, “Towards poisoning of deep learning algorithms with back-gradient optimization,” in Proc. ACM Workshop on Artificial Intelligence and Security , 2017
2017
Cited alongside, same era.
2017
Cited alongside, same era.
2017
Cited alongside, same era.
Y. Liu, L. Wei, B. Luo, and Q. Xu, “Fault injection attack on deep neural network,” in Proc. IEEE/ACM International Conference on Computer-Aided Design (ICCAD) . IEEE, 2017, pp. 131–138
2017
Cited alongside, same era.
2018
Closest in time.
A. Sanyal, M. J. Kusner, A. Gascón, and V. Kanade, “TAPAS: Tricks to accelerate (encrypted) prediction as a service,” in International Conference in Machine Learning , 2018
2018
Closest in time.
F. Bourse, M. Minelli, M. Minihold, and P. Paillier, “Fast homomorphic evaluation of deep discretized neural networks,” in Annual International Cryptology Conference , 2018
2018
Closest in time.
B. D. Rouhani, M. S. Riazi, and F. Koushanfar, “Deepsecure: Scalable provably-secure deep learning,” in 5th ACM/ESDA/IEEE Design Automation Conference , 2018
2018
Closest in time.
C. Juvekar, V. Vaikuntanathan, and A. Chandrakasan, “Gazelle: A low latency framework for secure neural network inference,” in 27th USENIX Security Symposium , 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A. Kurakin, I. Goodfellow, and S. Bengio, “Adversarial machine learning at scale,” in Proc. International Conference on Learning Representations , 2017
2017
Cited alongside, same era.
2017
Cited alongside, same era.
W. Xu, D. Evans, and Y. Qi, “Feature squeezing: detecting adversarial examples in deep neural networks,” in Proc. Network and Distributed System Symposium , 2017
2017
Cited alongside, same era.
N. Carlini and D. Wagner, “Adversarial examples are not easily detected: bypassing ten detection methods,” in Proc. 10th ACM Workshop on Artificial Intelligence and Security , 2017
2017
Cited alongside, same era.
W. He, J. Wei, X. Chen, N. Carlini, and D. Song, “Adversarial example defense: ensembles of weak defenses are not strong,” in Proc. USENIX Workshop on Offensive Technologies , 2017
2017
Cited alongside, same era.
M. Cisse, P. Bojanowski, E. Grave, Y. Dauphin, and N. Usunier, “Parseval networks: improving robustness to adversarial examples,” in Proc. International Conference on Machine Learning , 2017
2017
Cited alongside, same era.
2017
Cited alongside, same era.
2017
Cited alongside, same era.
2018
Closest in time.
Y. Aono, T. Hayashi, L. Wang, S. Moriai et al. , “Privacy-preserving deep learning via additively homomorphic encryption,” IEEE Transactions on Information Forensics and Security , vol. 13, no. 5, pp. 1333–1345, 2018
2018
Closest in time.
H. B. McMahan, D. Ramage, K. Talwar, and L. Zhang, “Learning differentially private recurrent language models,” in International Conference on Learning Representations , 2018
2018
Closest in time.
2018
Closest in time.
G. Acs, L. Melis, C. Castelluccia, and E. De Cristofaro, “Differentially private mixture of generative neural networks,” IEEE Transactions on Knowledge and Data Engineering , 2018
2018
Closest in time.
N. Papernot, S. Song, I. Mironov, A. Raghunathan, K. Talwar, and Ú. Erlingsson, “Scalable private learning with PATE,” in 6th International Conference on Learning Representations , 2018
2018
Closest in time.
J. Jordon, J. Yoon, and M. Van Der Schaar, “Pate-gan: Generating synthetic data with differential privacy guarantees,” in International Conference on Learning Representations , 2018
2018
Closest in time.
S. Lee, H. Kim, J. Park, J. Jang, C.-S. Jeong, and S. Yoon, “TensorLightning: A traffic-efficient distributed deep learning on commodity spark clusters,” IEEE Access , 2018
2018
Closest in time.
2018
Closest in time.
X. Li, H. Chen, X. Qi, Q. Dou, C.-W. Fu, and P.-A. Heng, “H-denseunet: Hybrid densely connected unet for liver and tumor segmentation from ct volumes,” IEEE Transactions on Medical Imaging , vol. 37, no. 12, pp. 2663–2674, 2018
2018
Closest in time.
Y. Jo, H. Cho, S. Y. Lee, G. Choi, G. Kim, H.-s. Min, and Y. Park, “Quantitative phase imaging and artificial intelligence: A review,” IEEE Journal of Selected Topics in Quantum Electronics , vol. 25, no. 1, pp. 1–14, 2018
2018
Closest in time.
Y. Tian, K. Pei, S. Jana, and B. Ray, “Deeptest: Automated testing of deep-neural-network-driven autonomous cars,” in 40th International Conference on Software Engineering , 2018
2018
Closest in time.
S. Wang, K. Pei, J. Whitehouse, J. Yang, and S. Jana, “Efficient formal safety analysis of neural networks,” in Advances in Neural Information Processing Systems , 2018
2018
Closest in time.
J. Li, F. Schmidt, and Z. Kolter, “Adversarial camera stickers: a physical camera-based attack on deep learning systems,” in Proc. International Conference on Machine Learning , 2019
2019
Closest in time.
2019
Closest in time.
S. Hu, T. Yu, C. Guo, W.-L. Chao, and K. Q. Weinberger, “A new defense against adversarial images: turning a weakness into a strength,” in Advances in Neural Information Processing Systems , 2019
2019
Closest in time.
J. M. Cohen, E. Rosenfeld, and J. Z. Kolter, “Certified adversarial robustness via randomized smoothing,” in Proc. International Conference on Machine Learning , 2019
2019
Closest in time.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: identifying and mitigating backdoor attacks in neural networks,” in Proc. 40th IEEE Symposium on Security and Privacy , 2019
2019
Closest in time.
W. Brendel, J. Rauber, M. Kümmerer, I. Ustyuzhaninov, and M. Bethge, “Accurate, reliable and fast robustness evaluation,” in Advances in Neural Information Processing Systems , 2019
2019
Closest in time.
C. Laidlaw and S. Feizi, “Functional adversarial attacks,” in Advances in Neural Information Processing Systems , 2019
2019
Closest in time.
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel, “Ensemble adversarial training: attacks and defenses,” in Proc. International Conference on Learning Representations , 2019
2019
Closest in time.
A. Ilyas, L. Engstrom, and A. Madry, “Prior convictions: black-box adversarial attacks with bandits and priors,” in Proc. International Conference on Learning Representations , 2019
2019
Closest in time.
J. Su, D. V. Vargas, and K. Sakurai, “One pixel attack for fooling deep neural networks,” IEEE Transactions on Evolutionary Computation , no. 5, pp. 828–841, 2019
2019
Closest in time.
C. Guo, J. Gardner, Y. You, A. G. Wilson, and K. Weinberger, “Simple black-box adversarial attacks,” in Proc. International Conference on Machine Learning , 2019
2019
Closest in time.
2019
Closest in time.
C. Zhu, W. R. Huang, H. Li, G. Taylor, C. Studer, and T. Goldstein, “Transferable clean-label poisoning attacks on deep neural nets,” in Proc. International Conference on Machine Learning , 2019
2019
Closest in time.
2019
Closest in time.
M. Barni, K. Kallas, and B. Tondi, “A new backdoor attack in CNNs by training set corruption without label poisoning,” in Proc. IEEE International Conference on Image Processing (ICIP) , 2019
2019
Closest in time.
2019
Closest in time.
P. Zhao, S. Wang, C. Gongye, Y. Wang, Y. Fei, and X. Lin, “Fault sneaking attack: a stealthy framework for misleading deep neural networks,” in Proc. 56th ACM/IEEE Design Automation Conference (DAC) , 2019
2019
Closest in time.
C. Xie, Y. Wu, L. v. d. Maaten, A. L. Yuille, and K. He, “Feature denoising for improving adversarial robustness,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2019, pp. 501–509
2019
Closest in time.
C. Qin, J. Martens, S. Gowal, D. Krishnan, K. Dvijotham, A. Fawzi, S. De, R. Stanforth, and P. Kohli, “Adversarial robustness through local linearization,” in Advances in Neural Information Processing Systems , 2019
2019
Closest in time.
H. Zhang and J. Wang, “Defense against adversarial attacks using feature scattering-based adversarial training,” in Advances in Neural Information Processing Systems , 2019
2019
Closest in time.
Y. Carmon, A. Raghunathan, L. Schmidt, J. C. Duchi, and P. S. Liang, “Unlabeled data improves adversarial robustness,” in Advances in Neural Information Processing Systems , 2019
2019
Closest in time.
M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, and S. Jana, “Certified robustness to adversarial examples with differential privacy,” in 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 2019, pp. 656–672
2019
Closest in time.
J. Hayes, L. Melis, G. Danezis, and E. De Cristofaro, “Logan: Membership inference attacks against generative models,” Privacy Enhancing Technologies , vol. 2019, no. 1, pp. 133–152, 2019
2019
Closest in time.
M. Nasr, R. Shokri, and A. Houmansadr, “Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning,” in 2019 IEEE symposium on security and privacy (SP) . IEEE, 2019, pp. 739–753
2019
Closest in time.
K. Bonawitz, H. Eichner, W. Grieskamp, D. Huba, A. Ingerman, V. Ivanov, C. Kiddon, J. Konecny, S. Mazzocchi, H. B. McMahan et al. , “Towards federated learning at scale: System design,” in Conference on Systems and Machine Learning , 2019
2019
Closest in time.
L. Yu, L. Liu, C. Pu, M. E. Gursoy, and S. Truex, “Differentially private model publishing for deep learning,” in Differentially Private Model Publishing for Deep Learning , 2019
2019
Closest in time.
A. Ilyas, S. Santurkar, D. Tsipras, L. Engstrom, B. Tran, and A. Madry, “Adversarial examples are not bugs, they are features,” in Advances in Neural Information Processing Systems , 2019
2019
Closest in time.
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry, “Robustness may be at odds with accuracy,” in International Conference on Learning Representations , no. 2019, 2019
2019
Closest in time.
G. Singh, T. Gehr, M. Püschel, and M. Vechev, “An abstract domain for certifying neural networks,” Proceedings of the ACM on Programming Languages , vol. 3, no. POPL, p. 41, 2019
2019
Closest in time.
F. Croce and M. Hein, “Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks,” in Proc. International Conference on Machine Learning , 2020
2020
Closest in time.
——, “Minimally distorted adversarial examples with a fast adaptive boundary attack,” in Proc. International Conference on Machine Learning , 2020
2020
Closest in time.
M. Andriushchenko, F. Croce, N. Flammarion, and M. Hein, “Square attack: a query-efficient black-box adversarial attack via random search,” in Proc. European Conference on Computer Vision , 2020
2020
Closest in time.
2020
Closest in time.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: a natural backdoor attack on deep neural networks,” in Proc. European Conference on Computer Vision , 2020
2020
Closest in time.
2020
Closest in time.
A. S. Rakin, Z. He, and D. Fan, “TBT: targeted neural network attack with bit trojan,” in Proc. IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2020
2020
Closest in time.
J. Zhang, X. Xu, B. Han, G. Niu, L. Cui, M. Sugiyama, and M. Kankanhalli, “Attacks which do not kill training make adversarial learning stronger,” in Proc. International Conference on Machine Learning , 2020
2020
Closest in time.
M. Balunovic and M. Vechev, “Adversarial training and provable defenses: Bridging the gap,” in International Conference on Learning Representations , 2020. [Online]. Available: https://openreview.net/forum?id=SJxSDxrKDr
2020
Closest in time.
2020
Closest in time.
J. Geiping, L. Fowl, W. R. Huang, W. Czaja, G. Taylor, M. Moeller, and T. Goldstein, “Witches’ brew: industrial scale data poisoning via gradient matching,” Proc. International Conference on Learning Representations , 2021
2021
Closest in time.
T. A. Nguyen and A. T. Tran, “Wanet - imperceptible warping-based backdoor attack,” in Proc. International Conference on Learning Representations , 2021
2021
Closest in time.
S. Lee, C. Park, H. Lee, J. Yi, J. Lee, and S. Yoon, “Removing undesirable feature contributions using out-of-distribution data,” in Proc. International Conference on Learning Representations , 2021
2021
Closest in time.