Fetching the paper…
Reading the bibliography…
The arms race between attacks and defenses for machine learning models has come to a forefront in recent years, in both the security community and the privacy community.
Communication theory of secrecy systems
Claude E Shannon. 1949 · 1949
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
Nitish Srivastava, Geoffrey Hinton, Alex Krizhevsky, Ilya Sutskever, and Ruslan Salakhutdinov. 2014 · 1958
Earlier work this paper cites.
From few to many: Illumination cone models for face recognition under variable lighting and pose
Athinodoros S Georghiades, Peter N Belhumeur, and David J Kriegman. 2001 · 2001
Earlier work this paper cites.
Acquiring linear subspaces for face recognition under variable lighting
Kuang-Chih Lee, Jeffrey Ho, and David J Kriegman. 2005 · 2005
Earlier work this paper cites.
Natural language processing (almost) from scratch
Ronan Collobert, Jason Weston, Léon Bottou, Michael Karlen, Koray Kavukcuoglu, and Pavel Kuksa. 2011 · 2011
Earlier work this paper cites.
Adversarial machine learning. In ACM Workshop on Artificial Intelligence and Security (AISec) . 43–58
Ling Huang, Anthony D Joseph, Blaine Nelson, Benjamin IP Rubinstein, and JD Tygar. 2011 · 2011
Earlier work this paper cites.
Unbiased look at dataset bias.. In IEEE conference on computer vision and pattern recognition (CVPR)
Antonio Torralba, Alexei A Efros, et al · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines. In International Conference on Machine Learning (ICML) . 1467–1474
Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012 · 2012
Earlier work this paper cites.
Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups
Geoffrey Hinton, Li Deng, Dong Yu, George E Dahl, Abdel-rahman Mohamed, Navdeep Jaitly, Andrew Senior, Vincent Vanhoucke, Patrick Nguyen, Tara N Sainath, et al · 2012
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks. In Conference on Neural Information Processing Systems (NeurIPS) . 1097–1105
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2012 · 2012
Earlier work this paper cites.
A public domain dataset for human activity recognition using smartphones.. In European Symposium on Artificial Neural Networks (ESANN)
Davide Anguita, Alessandro Ghio, Luca Oneto, Xavier Parra, and Jorge Luis Reyes-Ortiz. 2013 · 2013
Earlier work this paper cites.
Evasion attacks against machine learning at test time. In European Conference on Machine Learning and Principles and Practice of Knowledge Discovery in Databases (ECML PKDD) . 387–402
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. 2013 · 2013
Earlier work this paper cites.
New types of deep neural network learning for speech recognition and related applications: An overview. In IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) . 8599–8603
Li Deng, Geoffrey Hinton, and Brian Kingsbury. 2013 · 2013
Earlier work this paper cites.
Intriguing properties of neural networks. In International Conference on Learning Representations (ICLR)
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014 · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples. In International Conference on Learning Representations (ICLR)
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015 · 2015
Earlier work this paper cites.
Privacy-preserving deep learning. In ACM Conference on Computer and Communications Security (CCS) . 1310–1321
Reza Shokri and Vitaly Shmatikov. 2015 · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition. In International Conference on Learning Representations (ICLR)
Karen Simonyan and Andrew Zisserman. 2015 · 2015
Earlier work this paper cites.
Deep learning with differential privacy. In ACM Conference on Computer and Communications Security (CCS) . 308–318
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016 · 2016
Earlier work this paper cites.
Globally normalized transition-based neural networks. In Proceedings of the Annual Meeting of the Association for Computational Linguistics (ACL) . 2442–2452
Daniel Andor, Chris Alberti, David Weiss, Aliaksei Severyn, Alessandro Presta, Kuzman Ganchev, Slav Petrov, and Michael Collins. 2016 · 2016
Earlier work this paper cites.
Deep residual learning for image recognition. In IEEE conference on computer vision and pattern recognition (CVPR) . 770–778
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings. In IEEE European Symposium on Security and Privacy (EuroS&P) . 372–387
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016 · 2016
Earlier work this paper cites.
Mastering the game of Go with deep neural networks and tree search
David Silver, Aja Huang, Chris J Maddison, Arthur Guez, Laurent Sifre, George Van Den Driessche, Julian Schrittwieser, Ioannis Antonoglou, Veda Panneershelvam, Marc Lanctot, et al · 2016
Cited alongside, same era.
Stealing machine learning models via prediction APIs.. In USENIX Security Symposium . 601–618
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016 · 2016
Cited alongside, same era.
Wide residual networks. In Proceedings of the British Machine Vision Conference (BMVC)
Sergey Zagoruyko and Nikos Komodakis. 2016 · 2016
Cited alongside, same era.
Towards evaluating the robustness of neural networks. In IEEE Symposium on Security and Privacy (S&P) . 39–57
Nicholas Carlini and David Wagner. 2017 · 2017
Cited alongside, same era.
On calibration of modern neural networks
Chuan Guo, Geoff Pleiss, Yu Sun, and Kilian Q Weinberger. 2017 · 2017
Cited alongside, same era.
Differentiable abstract interpretation for provably robust neural networks. In International Conference on Machine Learning (ICML) . 3575–3583
Matthew Mirman, Timon Gehr, and Martin Vechev. 2018 · 2018
Later among the works it cites.
Machine learning with membership privacy using adversarial regularization. In ACM Conference on Computer and Communications Security (CCS)
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2018 · 2018
Later among the works it cites.
SoK: Security and privacy in machine learning. In IEEE European Symposium on Security and Privacy (EuroS&P) . 399–414
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael Wellman. 2018 · 2018
Later among the works it cites.
Certified defenses against adversarial examples. In International Conference on Learning Representations (ICLR)
Aditi Raghunathan, Jacob Steinhardt, and Percy Liang. 2018 · 2018
Later among the works it cites.
Adversarially robust generalization requires more data. In Conference on Neural Information Processing Systems (NeurIPS)
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Understanding black-box predictions via influence functions. In International Conference on Machine Learning (ICML) . 1885–1894
Pang Wei Koh and Percy Liang. 2017 · 2017
Cited alongside, same era.
Towards measuring membership privacy
Yunhui Long, Vincent Bindschaedler, and Carl A Gunter. 2017 · 2017
Cited alongside, same era.
Deepstack: Expert-level artificial intelligence in heads-up no-limit poker
Matej Moravčík, Martin Schmid, Neil Burch, Viliam Lisỳ, Dustin Morrill, Nolan Bard, Trevor Davis, Kevin Waugh, Michael Johanson, and Michael Bowling. 2017 · 2017
Cited alongside, same era.
Membership inference attacks against machine learning models. In IEEE Symposium on Security and Privacy (S&P) . 3–18
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017 · 2017
Cited alongside, same era.
Machine learning models that remember too much. In ACM Conference on Computer and Communications Security (CCS) . 587–601
Congzheng Song, Thomas Ristenpart, and Vitaly Shmatikov. 2017 · 2017
Cited alongside, same era.
Certified defenses for data poisoning attacks. In Conference on Neural Information Processing Systems (NeurIPS) . 3517–3529
Jacob Steinhardt, Pang Wei W Koh, and Percy S Liang. 2017 · 2017
Cited alongside, same era.
Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms
Han Xiao, Kashif Rasul, and Roland Vollgraf. 2017 · 2017
Cited alongside, same era.
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry. 2018 · 2018
Later among the works it cites.
Poison frogs! Targeted clean-label poisoning attacks on neural networks. In Conference on Neural Information Processing Systems (NeurIPS)
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018 · 2018
Later among the works it cites.
On the suitability of L P L_{P} -norms for creating and preventing adversarial examples. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) Workshops . 1605–1613
Mahmood Sharif, Lujo Bauer, and Michael K Reiter. 2018 · 2018
Later among the works it cites.
Certifying some distributional robustness with principled adversarial training. In International Conference on Learning Representations (ICLR)
Aman Sinha, Hongseok Namkoong, and John Duchi. 2018 · 2018
Later among the works it cites.
Stealing hyperparameters in machine learning. In IEEE Symposium on Security and Privacy (S&P)
Binghui Wang and Neil Zhenqiang Gong. 2018 · 2018
Later among the works it cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope. In International Conference on Machine Learning (ICML) . 5283–5292
Eric Wong and Zico Kolter. 2018 · 2018
Later among the works it cites.
Scaling provable adversarial defenses. In Conference on Neural Information Processing Systems (NeurIPS)
Eric Wong, Frank Schmidt, Jan Hendrik Metzen, and J Zico Kolter. 2018 · 2018
Later among the works it cites.
Privacy risk in machine learning: Analyzing the connection to overfitting. In IEEE Computer Security Foundations Symposium (CSF) . 268–282
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018 · 2018
Later among the works it cites.
Certified adversarial robustness via randomized smoothing. In International Conference on Machine Learning (ICML)
Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter. 2019 · 2019
Closest in time.
Exploiting excessive invariance caused by norm-bounded adversarial robustness. In International Conference on Learning Representations (ICLR) Workshop on Safe Machine Learning
Jörn-Henrik Jacobsen, Jens Behrmannn, Nicholas Carlini, Florian Tramer, and Nicolas Papernot. 2019 · 2019
Closest in time.
Certified robustness to adversarial examples with differential privacy. In IEEE Symposium on Security and Privacy (S&P)
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana. 2019 · 2019
Closest in time.
Defending against model stealing attacks using deceptive perturbations. In Deep Learning and Security Workshop (DLS)
Taesung Lee, Benjamin Edwards, Ian Molloy, and Dong Su. 2019 · 2019
Closest in time.
Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In IEEE Symposium on Security and Privacy (S&P)
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019 · 2019
Closest in time.
ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models. In Network and Distributed Systems Security Symposium (NDSS)
Ahmed Salem, Yang Zhang, Mathias Humbert, Mario Fritz, and Michael Backes. 2019 · 2019
Closest in time.
Robustness may be at odds with accuracy. In International Conference on Learning Representations (ICLR)
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry. 2019 · 2019
Closest in time.
Theoretically principled trade-off between robustness and accuracy. In International Conference on Machine Learning (ICML)
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P Xing, Laurent El Ghaoui, and Michael I Jordan. 2019 · 2019
Closest in time.