Fetching the paper…
Reading the bibliography…
Machine learning models trained on data from the outside world can be corrupted by data poisoning attacks that inject malicious points into the models' training sets.
Random sample consensus: a paradigm for model fitting with applications to image analysis and automated cartography
Martin A Fischler and Robert C Bolles · 1981
Earlier work this paper cites.
Some properties of the bilevel programming problem
Jonathan F Bard · 1991
Earlier work this paper cites.
Learning in the presence of malicious errors
Michael Kearns and Ming Li · 1993
Earlier work this paper cites.
Fast exact multiplication by the Hessian
Barak A Pearlmutter · 1994
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Practical Bilevel Optimization: Algorithms and Applications
Jonathan F. Bard · 1999
Earlier work this paper cites.
On the learnability and design of output codes for multiclass problems
Koby Crammer and Yoram Singer · 2002
Earlier work this paper cites.
A survey of outlier detection methodologies
Victoria Hodge and Jim Austin · 2004
Earlier work this paper cites.
Spam filtering with naive Bayes – which naive Bayes?
Vangelis Metsis, Ion Androutsopoulos, and Georgios Paliouras · 2006
Earlier work this paper cites.
Casting out demons: Sanitizing training data for anomaly sensors
Gabriela F. Cretu, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo, and Angelos D. Keromytis · 2008
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles A Sutton, J Doug Tygar, and Kai Xia · 2008
Earlier work this paper cites.
On agnostic learning of parities, monomials, and halfspaces
Vitaly Feldman, Parikshit Gopalan, Subhash Khot, and Ashok Kumar Ponnuswami · 2009
Earlier work this paper cites.
Hardness of learning halfspaces with noise
Venkatesan Guruswami and Prasad Raghavendra · 2009
Earlier work this paper cites.
Learning halfspaces with malicious noise
Adam R. Klivans, Philip M. Long, and Rocco A. Servedio · 2009
Earlier work this paper cites.
Antidote: Understanding and defending against poisoning of anomaly detectors
Benjamin Rubinstein, Blaine Nelson, Ling Huang, Anthony D. Joseph, Shing-Hon Lau, Satish Rao, Nina Taft, and JD Tygar · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D. Joseph, and J. D. Tygar · 2010
Earlier work this paper cites.
Adaptive subgradient methods for online learning and stochastic optimization
John Duchi, Elad Hazan, and Yoram Singer · 2010
Earlier work this paper cites.
Deep learning via hessian-free optimization
James Martens · 2010
Earlier work this paper cites.
Support vector machines under adversarial label noise
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2011
Earlier work this paper cites.
Learning word vectors for sentiment analysis
Andrew L. Maas, Raymond E. Daly, Peter T. Pham, Dan Huang, Andrew Y. Ng, and Christopher Potts · 2011
Earlier work this paper cites.
Notes about the Carathéodory number
Imre Bárány and Roman Karasev · 2012
Earlier work this paper cites.
Security analysis of online centroid anomaly detection
Marius Kloft and Pavel Laskov · 2012
Earlier work this paper cites.
Adversarial label flips attack on support vector machines
Han Xiao, Huang Xiao, and Claudia Eckert · 2012
Earlier work this paper cites.
Poisoning attacks to compromise face templates
Battista Biggio, Luca Didaci, Giorgio Fumera, and Fabio Roli · 2013
Cited alongside, same era.
The power of localization for efficiently learning linear separators with noise
Pranjal Awasthi, Maria Florina Balcan, and Philip M. Long · 2014
Cited alongside, same era.
Security evaluation of pattern classifiers under attack
Battista Biggio, Giorgio Fumera, and Fabio Roli · 2014
Cited alongside, same era.
Generative adversarial nets
Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio · 2014
Cited alongside, same era.
On the practicality of integrity attacks on document-level sentiment analysis
Andrew Newell, Rahul Potharaju, Luojie Xiang, and Cristina Nita-Rotaru · 2014
Cited alongside, same era.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Towards deep learning models resistant to adversarial attacks (published at ICLR 2018)
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Later among the works it cites.
Towards poisoning of deep learning algorithms with back-gradient optimization
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli · 2017
Later among the works it cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Berkay Z. Celik, and Ananthram Swami · 2017
Later among the works it cites.
Certified defenses for data poisoning attacks
Jacob Steinhardt, Pang Wei Koh, and Percy Liang · 2017
Later among the works it cites.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Dan Boneh, and Patrick McDaniel · 2017
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Cited alongside, same era.
Tight bounds for approximate Carathéodory and beyond
Vahab Mirrokni, Renato Paes Leme, Adrian Vladu, and Sam Chiu wai Wong · 2015
Cited alongside, same era.
Support vector machines under adversarial label contamination
Huang Xiao, Battista Biggio, Blaine Nelson, Han Xiao, Claudia Eckert, and Fabio Roli · 2015
Cited alongside, same era.
Second order stochastic optimization in linear time
Naman Agarwal, Brian Bullins, and Elad Hazan · 2016
Cited alongside, same era.
Hidden voice commands
Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David Wagner, and Wenchao Zhou · 2016
Cited alongside, same era.
Robust estimators in high dimensions without the computational intractability
Ilias Diakonikolas, Gautam Kamath, Daniel Kane, Jerry Li, Ankur Moitra, and Alistair Stewart · 2016
Cited alongside, same era.
Generative poisoning attack method against neural networks
Chaofei Yang, Qing Wu, Hai Li, and Yiran Chen · 2017
Later among the works it cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Closest in time.
Sever: A robust meta-algorithm for stochastic optimization
Ilias Diakonikolas, Gautam Kamath, Daniel M. Kane, Jerry Li, Jacob Steinhardt, and Alistair Stewart · 2018
Closest in time.
Attack strength vs. detectability dilemma in adversarial machine learning
Christopher Frederickson, Michael Moore, Glenn Dawson, and Robi Polikar · 2018
Closest in time.
Manipulating machine learning: Poisoning attacks and countermeasures for regression learning
Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li · 2018
Closest in time.
Principled Approaches to Robust Machine Learning and Beyond
Jerry Li · 2018
Closest in time.
Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning
Nicolas Papernot and Patrick McDaniel · 2018
Closest in time.
Detection of adversarial training examples in poisoning attacks through anomaly detection
Andrea Paudice, Luis Muñoz-González, Andras Gyorgy, and Emil C Lupu · 2018
Closest in time.
Certified defenses against adversarial examples
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Closest in time.
Poison Frogs! Targeted clean-label poisoning attacks on neural networks
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein · 2018
Closest in time.
Certifiable distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2018
Closest in time.
Robust Learning: Information Theory and Algorithms
Jacob Steinhardt · 2018
Closest in time.
Resilience: A criterion for learning in the presence of arbitrary outliers
Jacob Steinhardt, Moses Charikar, and Gregory Valiant · 2018
Closest in time.
When does machine learning fail? generalized transferability for evasion and poisoning attacks
Octavian Suciu, Radu Mărginean, Yiğitcan Kaya, Hal Daumé III, and Tudor Dumitraş · 2018
Closest in time.
Adversarial machine learning
Yevgeniy Vorobeychik and Murat Kantarcioglu · 2018
Closest in time.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and J. Zico Kolter · 2018
Closest in time.
Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks
Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli · 2019
Closest in time.