Fetching the paper…
Reading the bibliography…
In this paper, we aim to develop a scalable algorithm to preserve differential privacy (DP) in adversarial learning for deep neural networks (DNNs), with certified robustness to adversarial examples.
Calculus
Apostol, T · 1967
Earlier work this paper cites.
Principles of Mathematical Analysis
Rudin, W · 1976
Earlier work this paper cites.
In Mathematical Methods for Physicists (Third Edition) . Academic Press, 1985
Arfken, G · 1985
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Lecun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Dwork, C., McSherry, F., Nissim, K., and Smith, A · 2006
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A. and Hinton, G · 2009
Earlier work this paper cites.
Functional mechanism: regression analysis under differential privacy
Zhang, J., Zhang, Z., Xiao, X., Yang, Y., and Winslett, M · 2012
Earlier work this paper cites.
Broadening the scope of differential privacy using metrics
Chatzikokolakis, K., Andrés, M. E., Bordenabe, N. E., and Palamidessi, C · 2013
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Dwork, C. and Roth, A · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Gu, S. and Rigazio, L · 2014
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Fredrikson, M., Jha, S., and Ristenpart, T · 2015
Earlier work this paper cites.
Privacy-preserving deep learning
Shokri, R. and Shmatikov, V · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Earlier work this paper cites.
Federated learning of deep networks using model averaging
McMahan, H. B., Moore, E., Ramage, D., and y Arcas, B. A · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., and Swami, A · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Papernot, N., McDaniel, P., Wu, X., Jha, S., and Swami, A · 2016
Earlier work this paper cites.
Differential privacy preservation for deep auto-encoders: an application of human behavior prediction
Phan, N., Wang, Y., Wu, X., and Dou, D · 2016
Earlier work this paper cites.
Learning adversary-resistant deep neural networks
Wang, Q., Guo, W., Zhang, K., II, A. G. O., Xing, X., Giles, C. L., and Liu, X · 2016
Earlier work this paper cites.
On the protection of private information in machine learning systems: Two recent approches
Abadi, M., Erlingsson, U., Goodfellow, I., McMahan, H. B., Mironov, I., Papernot, N., Talwar, K., and Zhang, L · 2017
Cited alongside, same era.
Robustness to adversarial examples through an ensemble of specialists
Abbasi, M. and Gagné, C · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Parseval networks: Improving robustness to adversarial examples
Cisse, M., Bojanowski, P., Grave, E., Dauphin, Y., and Usunier, N · 2017
Cited alongside, same era.
Discovering adversarial examples with momentum
Dong, Y., Liao, F., Pang, T., Hu, X., and Zhu, J · 2017
Cited alongside, same era.
Concentrated differentially private gradient descent with adaptive per-iteration privacy budget
Lee, J. and Kifer, D · 2018
Later among the works it cites.
Second-order adversarial attack and certifiable robustness
Li, B., Chen, C., Wang, W., and Carin, L · 2018
Later among the works it cites.
Trojaning attack on neural networks
Liu, Y., Ma, S., Aafer, Y., Lee, W.-C., Zhai, J., Wang, W., and Zhang, X · 2018
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Later among the works it cites.
Scalable private learning with pate
Papernot, N., Song, S., Mironov, I., Raghunathan, A., Talwar, K., and Erlingsson, Ú · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Gao, J., Wang, B., and Qi, Y · 2017
Cited alongside, same era.
Accurate, large minibatch SGD: training imagenet in 1 hour
Goyal, P., Dollár, P., Girshick, R. B., Noordhuis, P., Wesolowski, L., Kyrola, A., Tulloch, A., Jia, Y., and He, K · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
Grosse, K., Manoharan, P., Papernot, N., Backes, M., and McDaniel, P. D · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Gu, T., Dolan-Gavitt, B., and Garg, S · 2017
Cited alongside, same era.
Blocking transferability of adversarial examples in black-box learning systems
Hosseini, H., Chen, Y., Kannan, S., Zhang, B., and Poovendran, R · 2017
Cited alongside, same era.
Mitigating fooling with competitive overcomplete output layer neural networks
Kardan, N. and Stanley, K. O · 2017
Cited alongside, same era.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Kolter, J. Z. and Wong, E · 2017
Cited alongside, same era.
Raghunathan, A., Steinhardt, J., and Liang, P · 2018
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
Later among the works it cites.
Operator norm, 2018
Operator norm · 2018
Later among the works it cites.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, Z · 2019
Closest in time.
Benchmarking neural network robustness to common corruptions and perturbations
Hendrycks, D. and Dietterich, T · 2019
Closest in time.
Heterogeneous gaussian mechanism: Preserving differential privacy in deep learning with provable robustness
Phan, N., Vu, M. N., Liu, Y., Jin, R., Dou, D., Wu, X., and Thai, M. T · 2019
Closest in time.
Provably robust deep learning via adversarially trained smoothed classifiers
Salman, H., Yang, G., Li, J., Zhang, P., Zhang, H., Razenshteyn, I. P., and Bubeck, S · 2019
Closest in time.
Privacy Risks of Securing Machine Learning Models against Adversarial Examples
Song, L., Shokri, R., and Mittal, P · 2019
Closest in time.
P3SGD: patient privacy preserving SGD for regularizing deep cnns in pathological image classification
Wu, B., Zhao, S., Sun, G., Zhang, X., Su, Z., Zeng, C., and Liu, Z · 2019
Closest in time.
Feature denoising for improving adversarial robustness
Xie, C., Wu, Y., van der Maaten, L., Yuille, A. L., and He, K · 2019
Closest in time.
Differentially private model publishing for deep learning
Yu, L., Liu, L., Pu, C., Gursoy, M., and Truex, S · 2019
Closest in time.
Fedcube, 2020
Baidu · 2020
Closest in time.
A tale of evil twins: Adversarial inputs versus poisoned models
Pang, R., Shen, H., Zhang, X., Ji, S., Vorobeychik, Y., Luo, X., Liu, A., and Wang, T · 2020
Closest in time.
An adaptive and fast convergent approach to differentially private deep learning
Xu, Z., Shi, S., Liu, X. A., Zhao, J., and Chen, L · 2020
Closest in time.