Fetching the paper…
Reading the bibliography…
Deep neural networks (DNNs) have been proven vulnerable to backdoor attacks, where hidden features (patterns) trained to a normal model, which is only activated by some specific input (called triggers), trick the model into producing unexpected behavior.
Privacy risks of securing machine learning models against adversarial examples
Liwei Song, Reza Shokri, and Prateek Mittal · 1909
Earlier work this paper cites.
Learning algorithms for classification: A comparison on handwritten digit recognition
Yann LeCun, LD Jackel, Léon Bottou, Corinna Cortes, John S Denker, Harris Drucker, Isabelle Guyon, Urs A Muller, Eduard Sackinger, Patrice Simard, et al · 1995
Earlier work this paper cites.
Defending against statistical steganalysis
Niels Provos · 2001
Earlier work this paper cites.
Digital watermarking and steganography
Ingemar Cox, Matthew Miller, Jeffrey Bloom, Jessica Fridrich, and Ton Kalker · 2007
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Secure data transmission using video steganography
R Balaji and Garewal Naveen · 2011
Earlier work this paper cites.
Multi-column deep neural networks for image classification
Dan Ciregan, Ueli Meier, and Jürgen Schmidhuber · 2012
Earlier work this paper cites.
Deep neural networks for acoustic modeling in speech recognition: The shared views of four research groups
Geoffrey Hinton, Li Deng, Dong Yu, George E Dahl, Abdel-rahman Mohamed, Navdeep Jaitly, Andrew Senior, Vincent Vanhoucke, Patrick Nguyen, Tara N Sainath, et al · 2012
Earlier work this paper cites.
Information hiding using least significant bit steganography and cryptography
Shailender Gupta, Ankur Goyal, and Bharat Bhushan · 2012
Earlier work this paper cites.
Audio steganography: a survey on recent approaches
Masoud Nosrati, Ronak Karimi, and Mehdi Hariri · 2012
Earlier work this paper cites.
Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition
Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel · 2012
Earlier work this paper cites.
Representation learning: A review and new perspectives
Yoshua Bengio, Aaron Courville, and Pascal Vincent · 2013
Earlier work this paper cites.
Image watermarking using lsb (least significant bit)
Gurpreet Kaur and Kamaljeet Kaur · 2013
Earlier work this paper cites.
Detection of traffic signs in real-world images: The german traffic sign detection benchmark
Sebastian Houben, Johannes Stallkamp, Jan Salmen, Marc Schlipsing, and Christian Igel · 2013
Earlier work this paper cites.
Human-level control through deep reinforcement learning
Volodymyr Mnih, Koray Kavukcuoglu, David Silver, Andrei A Rusu, Joel Veness, Marc G Bellemare, Alex Graves, Martin Riedmiller, Andreas K Fidjeland, Georg Ostrovski, et al · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli · 2015
Earlier work this paper cites.
Adversarial diversity and hard positive generation
Andras Rozsa, Ethan M Rudd, and Terrance E Boult · 2016
Earlier work this paper cites.
Mastering the game of go with deep neural networks and tree search
David Silver, Aja Huang, Chris J Maddison, Arthur Guez, Laurent Sifre, George Van Den Driessche, Julian Schrittwieser, Ioannis Antonoglou, Veda Panneershelvam, Marc Lanctot, et al · 2016
Cited alongside, same era.
Data poisoning attacks against autoregressive models
Scott Alfeld, Xiaojin Zhu, and Paul Barford · 2016
Cited alongside, same era.
Steganalysis via deep residual network
Songtao Wu, Sheng-hua Zhong, and Yan Liu · 2016
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami · 2016
Cited alongside, same era.
11 adversarial perturbations of deep neural networks
David Warde-Farley and Ian Goodfellow · 2016
Cited alongside, same era.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Backdoor embedding in convolutional neural network models via invisible perturbation
Cong Liao, Haoti Zhong, Anna Cinzia Squicciarini, Sencun Zhu, and David J. Miller · 2018
Later among the works it cites.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Later among the works it cites.
Universal adversarial training
Ali Shafahi, Mahyar Najibi, Zheng Xu, John Dickerson, Larry S Davis, and Tom Goldstein · 2018
Later among the works it cites.
Fine-pruning: Defending against backdooring attacks on deep neural networks
Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2018
Later among the works it cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang · 2016
Cited alongside, same era.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Cited alongside, same era.
Understanding black-box predictions via influence functions
Pang Wei Koh and Percy Liang · 2017
Cited alongside, same era.
Universal adversarial perturbations
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2017
Cited alongside, same era.
Universal adversarial perturbations
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2017
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana · 2018
Later among the works it cites.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao · 2019
Closest in time.
Tabor: A highly accurate approach to inspecting and restoring Trojan backdoors in AI systems
Wenbo Guo, Lun Wang, Xinyu Xing, Min Du, and Dawn Song · 2019
Closest in time.
Gotta catch’em all: Using concealed trapdoors to detect adversarial attacks on neural networks
Shawn Shan, Emily Willson, Bolun Wang, Bo Li, Haitao Zheng, and Ben Y Zhao · 2019
Closest in time.
Badnets: Evaluating backdooring attacks on deep neural networks
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg · 2019
Closest in time.
Generalizable data-free objective for crafting universal adversarial perturbations
Konda Reddy Mopuri, Aditya Ganeshan, and R. Venkatesh Babu · 2019
Closest in time.
DPATCH: an adversarial patch attack on object detectors
Xin Liu, Huanrui Yang, Ziwei Liu, Linghao Song, Yiran Chen, and Hai Li · 2019
Closest in time.
Adversarial examples are not bugs, they are features
Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Closest in time.
Abs: Scanning neural networks for back-doors by artificial brain stimulation
Yingqi Liu, Wen-Chuan Lee, Guanhong Tao, Shiqing Ma, Yousra Aafer, and Xiangyu Zhang · 2019
Closest in time.
Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection
Di Tang, Xiaofeng Wang, Haixu Tang, and Kehuan Zhang · 2019
Closest in time.
STRIP: A defence against trojan attacks on deep neural networks
Yansong Gao, Chang Xu, Derui Wang, Shiping Chen, Damith Chinthana Ranasinghe, and Surya Nepal · 2019
Closest in time.
Revealing backdoors, post-training, in DNN classifiers via novel inference on optimized perturbations inducing group misclassification
Zhen Xiang, David J. Miller, and George Kesidis · 2020
Closest in time.