2020

Towards Backdoor Attacks and Defense in Robust Machine Learning Models

Soremekun, Ezekiel, Udeshi, Sakshi, Chattopadhyay, Sudipta

Understand

The introduction of robust optimisation has pushed the state-of-the-art in defending against adversarial attacks.

  • Notably, the state-of-the-art projected gradient descent (PGD)-based training method has been shown to be universally and reliably effective in defending against adversarial inputs.
  • This robustness approach uses PGD as a reliable and universal "first-order adversary".
  • However, the behaviour of such optimisation has not been studied in the light of a fundamentally different class of attacks called backdoors.

Reading the bibliography…