Fetching the paper…
Reading the bibliography…
Deep learning models are vulnerable to various adversarial manipulations of their training data, parameters, and input sample.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
The German Traffic Sign Recognition Benchmark: A multi-class classification competition
Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Machine learning with adversaries: Byzantine tolerant gradient descent
Peva Blanchard, Rachid Guerraoui, Julien Stainer, et al · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Cited alongside, same era.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger · 2017
Cited alongside, same era.
Neural trojans
Yuntao Liu, Yang Xie, and Ankur Srivastava · 2017
Cited alongside, same era.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Cited alongside, same era.
Generative poisoning attack method against neural networks
Chaofei Yang, Qing Wu, Hai Li, and Yiran Chen · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Fine-pruning: Defending against backdooring attacks on deep neural networks
Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2018
Later among the works it cites.
The hidden vulnerability of distributed learning in byzantium
El Mahdi El Mhamdi, Rachid Guerraoui, and Sébastien Rouault · 2018
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein · 2018
Later among the works it cites.
Spectral signatures in backdoor attacks
Brandon Tran, Jerry Li, and Aleksander Madry · 2018
Later among the works it cites.
Generalized byzantine-tolerant sgd
Cong Xie, Oluwasanmi Koyejo, and Indranil Gupta · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov · 2018
Cited alongside, same era.
Detecting backdoor attacks on deep neural networks by activation clustering
Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava · 2018
Cited alongside, same era.
Semantic adversarial examples
Hossein Hosseini and Radha Poovendran · 2018
Cited alongside, same era.
Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing
Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart
Cited in the paper.
Stealing machine learning models via prediction apis
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart
Cited in the paper.
Dong Yin, Yudong Chen, Kannan Ramchandran, and Peter Bartlett · 2018
Later among the works it cites.
A little is enough: Circumventing defenses for distributed learning
Moran Baruch, Gilad Baruch, and Yoav Goldberg · 2019
Closest in time.
Comprehensive privacy analysis of deep learning: Stand-alone and federated learning under passive and active white-box inference attacks
Milad Nasr, Reza Shokri, and Amir Houmansadr · 2019
Closest in time.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao · 2019
Closest in time.