Fetching the paper…
Reading the bibliography…
Clean-label poisoning attacks inject innocuous looking (and "correctly" labeled) poison images into training data, causing a model to misclassify a targeted image after being trained on this data.
Poisoning attacks against support vector machines
Biggio, B., Nelson, B., and Laskov, P · 2012
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Krizhevsky, A., Sutskever, I., and Hinton, G. E · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Biggio, B., Corona, I., Maiorca, D., Nelson, B., Šrndić, N., Laskov, P., Giacinto, G., and Roli, F · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
A field guide to forward-backward splitting with a fasta implementation
Goldstein, T., Studer, C., and Baraniuk, R · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
Kingma, D. P. and Ba, J · 2014
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
Srivastava, N., Hinton, G., Krizhevsky, A., Sutskever, I., and Salakhutdinov, R · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Goodfellow, I., Shlens, J., and Szegedy, C · 2015
Earlier work this paper cites.
Using machine teaching to identify optimal training-set attacks on machine learners
Mei, S. and Zhu, X · 2015
Earlier work this paper cites.
Going deeper with convolutions
Szegedy, C., Liu, W., Jia, Y., Sermanet, P., Reed, S., Anguelov, D., Erhan, D., Vanhoucke, V., and Rabinovich, A · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Cited alongside, same era.
Adversarial examples in the physical world
Kurakin, A., Goodfellow, I., and Bengio, S · 2016
Cited alongside, same era.
Delving into transferable adversarial examples and black-box attacks
Liu, Y., Chen, X., Liu, C., and Song, D · 2016
Cited alongside, same era.
Understanding deep learning requires rethinking generalization
Zhang, C., Bengio, S., Hardt, M., Recht, B., and Vinyals, O · 2016
Cited alongside, same era.
Densely connected convolutional networks
Huang, G., Liu, Z., Van Der Maaten, L., and Weinberger, K. Q · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Later among the works it cites.
Certified defenses for data poisoning attacks
Steinhardt, J., Koh, P. W., and Liang, P · 2017
Later among the works it cites.
The space of transferable adversarial examples
Tramèr, F., Papernot, N., Goodfellow, I., Boneh, D., and McDaniel, P · 2017
Later among the works it cites.
Aggregated residual transformations for deep neural networks
Xie, S., Girshick, R., Dollár, P., Tu, Z., and He, K · 2017
Later among the works it cites.
Boosting adversarial attacks with momentum
Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., and Li, J · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Koh, P. W. and Liang, P · 2017
Cited alongside, same era.
Webvision database: Visual learning and understanding from web data
Li, W., Wang, L., Li, W., Agustsson, E., and Van Gool, L · 2017
Cited alongside, same era.
Trojaning attack on neural networks
Liu, Y., Ma, S., Aafer, Y., Lee, W.-C., Zhai, J., Wang, W., and Zhang, X · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Learning under p-tampering attacks
Mahloujifar, S., Diochnos, D. I., and Mahmoody, M · 2017
Cited alongside, same era.
Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
Chen, X., Liu, C., Li, B., Lu, K., and Song, D
Cited in the paper.
Dual path networks
Chen, Y., Li, J., Xiao, H., Jin, X., Yan, S., and Feng, J
Cited in the paper.
Hu, J., Shen, L., and Sun, G · 2018
Later among the works it cites.
Mobilenetv2: Inverted residuals and linear bottlenecks
Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., and Chen, L.-C · 2018
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
Later among the works it cites.
When does machine learning fail? generalized transferability for evasion and poisoning attacks
Suciu, O., Mărginean, R., Kaya, Y., Daumé III, H., and Dumitraş, T · 2018
Later among the works it cites.
Clean-label backdoor attacks, 2019
Turner, A., Tsipras, D., and Madry, A · 2019
Closest in time.