Fetching the paper…
Reading the bibliography…
Data poisoning attacks aim to manipulate the model produced by a learning algorithm by adversarially modifying the training set.
Statistical inference , volume 2
George Casella and Roger L Berger · 2002
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith · 2006
Earlier work this paper cites.
Differentially private empirical risk minimization
Kamalika Chaudhuri, Claire Monteleoni, and Anand D Sarwate · 2011
Earlier work this paper cites.
Differential privacy
Cynthia Dwork · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Private convex empirical risk minimization and high-dimensional regression
Daniel Kifer, Adam Smith, and Abhradeep Thakurta · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart · 2015
Earlier work this paper cites.
Using machine teaching to identify optimal training-set attacks on machine learners
Shike Mei and Xiaojin Zhu · 2015
Cited alongside, same era.
Is feature selection secure against training data poisoning?
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli · 2015
Cited alongside, same era.
Data poisoning attacks against autoregressive models
Scott Alfeld, Xiaojin Zhu, and Paul Barford · 2016
Cited alongside, same era.
Data poisoning attacks on factorization-based collaborative filtering
Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik · 2016
Cited alongside, same era.
Differentially private distributed convex optimization via objective perturbation
Erfan Nozari, Pavankumar Tallapragada, and Jorge Cortés · 2016
Cited alongside, same era.
Stealing machine learning models via prediction apis
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart · 2016
Certified defenses for data poisoning attacks
Jacob Steinhardt, Pang Wei W Koh, and Percy S Liang · 2017
Later among the works it cites.
Efficient label contamination attacks against black-box learning models
Mengchen Zhao, Bo An, Wei Gao, and Teng Zhang · 2017
Later among the works it cites.
Adversarial attacks on stochastic bandits
Kwang-Sung Jun, Lihong Li, Yuzhe Ma, and Jerry Zhu · 2018
Later among the works it cites.
Stronger data poisoning attacks break data sanitization defenses
Pang Wei Koh, Jacob Steinhardt, and Percy Liang · 2018
Later among the works it cites.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
UCI machine learning repository, 2017
Dheeru Dua and Efi Karra Taniskidou · 2017
Cited alongside, same era.
Towards poisoning of deep learning algorithms with back-gradient optimization
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli · 2017
Cited alongside, same era.
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang · 2018
Later among the works it cites.
Xuezhou Zhang and Xiaojin Zhu · 2019
Closest in time.