Fetching the paper…
Reading the bibliography…
Machine learning algorithms are known to be susceptible to data poisoning attacks, where an adversary manipulates the training data to degrade performance of the resulting classifier.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
Fast and robust fixed-point algorithms for independent component analysis
Hyvarinen, A · 1999
Earlier work this paper cites.
Kernel Fisher Discriminants
Mika, S · 2003
Earlier work this paper cites.
Can machine learning be secure?
Barreno, M., Nelson, B., Sears, R., Joseph, A. D., and Tygar, J. D · 2006
Earlier work this paper cites.
Antidote: Understanding and defending against poisoning of anomaly detectors
Rubinstein, B. I., Nelson, B., Huang, L., Joseph, A. D., Lau, S.-h., Rao, S., Taft, N., and Tygar, J. D · 2009
Earlier work this paper cites.
Kernel descriptors for visual recognition
Bo, L., Ren, X., and Fox, D · 2010
Earlier work this paper cites.
Support vector machines under adversarial label noise
Biggio, B., Nelson, B., and Laskov, P · 2011
Earlier work this paper cites.
Learning word vectors for sentiment analysis
Maas, A. L., Daly, R. E., Pham, P. T., Huang, D., Ng, A. Y., and Potts, C · 2011
Earlier work this paper cites.
Adversarial label flips attack on support vector machines
Xiao, H., Xiao, H., and Eckert, C · 2012
Earlier work this paper cites.
Robust sparse regression under adversarial corruption
Chen, Y., Caramanis, C., and Mannor, S · 2013
Earlier work this paper cites.
mpmath: a Python library for arbitrary-precision floating-point arithmetic (version 0.18) , December 2013
Johansson, F. et al · 2013
Earlier work this paper cites.
Building high-level features using large scale unsupervised learning
Le, Q. V · 2013
Earlier work this paper cites.
Learning with noisy labels
Natarajan, N., Dhillon, I. S., Ravikumar, P. K., and Tewari, A · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Security evaluation of pattern classifiers under attack
Biggio, B., Fumera, G., and Roli, F · 2014
Earlier work this paper cites.
Variance estimation in high-dimensional linear models
Dicker, L. H · 2014
Earlier work this paper cites.
Decaf: A deep convolutional activation feature for generic visual recognition
Donahue, J., Jia, Y., Vinyals, O., Hoffman, J., Zhang, N., Tzeng, E., and Darrell, T · 2014
Earlier work this paper cites.
Random design analysis of ridge regression
Hsu, D., Kakade, S. M., and Zhang, T · 2014
Earlier work this paper cites.
How transferable are features in deep neural networks?
Yosinski, J., Clune, J., Bengio, Y., and Lipson, H · 2014
Earlier work this paper cites.
Robust regression via hard thresholding
Bhatia, K., Jain, P., and Kar, P · 2015
Cited alongside, same era.
Explaining and harnessing adversarial examples
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2015
Cited alongside, same era.
Is feature selection secure against training data poisoning?
Xiao, H., Biggio, B., Brown, G., Fumera, G., Eckert, C., and Roli, F · 2015
Cited alongside, same era.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Cited alongside, same era.
Classification with noisy labels by importance reweighting
Liu, T. and Tao, D · 2016
Cited alongside, same era.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Cited alongside, same era.
Stronger data poisoning attacks break data sanitization defenses
Koh, P. W., Steinhardt, J., and Liang, P · 2018
Later among the works it cites.
Certified robustness to adversarial examples with differential privacy
Lecuyer, M., Atlidakis, V., Geambasu, R., Hsu, D., and Jana, S · 2018
Later among the works it cites.
Certified adversarial robustness with additive gaussian noise
Li, B., Chen, C., Wang, W., and Carin, L · 2018
Later among the works it cites.
Sok: Security and privacy in machine learning
Papernot, N., McDaniel, P., Sinha, A., and Wellman, M. P · 2018
Later among the works it cites.
Robust estimation via robust gradient estimation
Prasad, A., Suggala, A. S., Balakrishnan, S., and Ravikumar, P · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Adversarial examples are not easily detected: Bypassing ten detection methods
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Targeted backdoor attacks on deep learning systems using data poisoning
Chen, X., Liu, C., Li, B., Lu, K., and Song, D · 2017
Cited alongside, same era.
Understanding black-box predictions via influence functions
Koh, P. W. and Liang, P · 2017
Cited alongside, same era.
Robust linear regression against training data poisoning
Liu, C., Li, B., Vorobeychik, Y., and Oprea, A · 2017
Cited alongside, same era.
Towards poisoning of deep learning algorithms with back-gradient optimization
Muñoz González, L., Biggio, B., Demontis, A., Paudice, A., Wongrassamee, V., Lupu, E. C., and Roli, F · 2017
Cited alongside, same era.
Making deep neural networks robust to label noise: A loss correction approach
Patrini, G., Rozza, A., Krishna Menon, A., Nock, R., and Qu, L · 2017
Cited alongside, same era.
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
Later among the works it cites.
Connecting optimization and regularization paths
Suggala, A., Prasad, A., and Ravikumar, P. K · 2018
Later among the works it cites.
Spectral signatures in backdoor attacks
Tran, B., Li, J., and Madry, A · 2018
Later among the works it cites.
Representer point selection for explaining deep neural networks
Yeh, C.-K., Kim, J., Yen, I. E.-H., and Ravikumar, P. K · 2018
Later among the works it cites.
Certified adversarial robustness via randomized smoothing
Cohen, J., Rosenfeld, E., and Kolter, J. Z · 2019
Later among the works it cites.
Efficient algorithms and lower bounds for robust linear regression
Diakonikolas, I., Kong, W., and Stewart, A · 2019
Later among the works it cites.
Tight certificates of adversarial robustness for randomly smoothed classifiers
Lee, G.-H., Yuan, Y., Chang, S., and Jaakkola, T. S · 2019
Later among the works it cites.
Label sanitization against label flipping poisoning attacks
Paudice, A., Muñoz-González, L., and Lupu, E. C · 2019
Later among the works it cites.
Learning with bad training data via iterative trimmed loss minimization
Shen, Y. and Sanghavi, S · 2019
Later among the works it cites.
On defending against label flipping attacks on malware detection systems
Taheri, R., Javidan, R., Shojafar, M., Pooranian, Z., Miri, A., and Conti, M · 2019
Later among the works it cites.
Transferable clean-label poisoning attacks on deep neural nets
Zhu, C., Huang, W. R., Li, H., Taylor, G., Studer, C., and Goldstein, T · 2019
Later among the works it cites.
A simple framework for contrastive learning of visual representations
Chen, T., Kornblith, S., Norouzi, M., and Hinton, G · 2020
Closest in time.
A framework for robustness certification of smoothed classifiers using f-divergences
Dvijotham, K., Hayes, J., Balle, B., Kolter, Z., Qin, C., Gyorgy, A., Xiao, K., Gowal, S., and Kohli, P · 2020
Closest in time.