Fetching the paper…
Reading the bibliography…
In a poisoning attack, an adversary with control over a small fraction of the training data attempts to select that data in a way that induces a corrupted model that misbehaves in favor of the adversary.
The MNIST database of handwritten digits
LeCun, Y · 1998
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
Nelson, B., Barreno, M., Chi, F. J., Joseph, A. D., Rubinstein, B. I., Saini, U., Sutton, C. A., Tygar, J. D., and Xia, K · 2008
Earlier work this paper cites.
Support Vector Machines under adversarial label noise
Biggio, B., Nelson, B., and Laskov, P · 2011
Earlier work this paper cites.
Adversarial machine learning
Huang, L., Joseph, A. D., Nelson, B., Rubinstein, B. I., and Tygar, J. D · 2011
Earlier work this paper cites.
Poisoning attacks against Support Vector Machines
Biggio, B., Nelson, B., and Laskov, P · 2012
Earlier work this paper cites.
Online learning and online convex optimization
Shalev-Shwartz, S · 2012
Earlier work this paper cites.
Adversarial label flips attack on Support Vector Machines
Xiao, H., Xiao, H., and Eckert, C · 2012
Earlier work this paper cites.
Adam: A method for stochastic optimization
Kingma, D. P. and Ba, J · 2014
Earlier work this paper cites.
Support Vector Machines under adversarial label contamination
Xiao, H., Biggio, B., Nelson, B., Xiao, H., Eckert, C., and Roli, F · 2015
Earlier work this paper cites.
CVXPY: A Python-embedded modeling language for convex optimization
Diamond, S. and Boyd, S · 2016
Earlier work this paper cites.
Data poisoning attacks on factorization-based collaborative filtering
Li, B., Wang, Y., Singh, A., and Vorobeychik, Y · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision
Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., and Wojna, Z · 2016
Earlier work this paper cites.
UCI Machine Learning Repository, 2017
Dua, D. and Graff, C · 2017
Cited alongside, same era.
Understanding black-box predictions via influence functions
Koh, P. W. and Liang, P · 2017
Cited alongside, same era.
A survey of algorithms and analysis for adaptive online learning
McMahan, H. B · 2017
Cited alongside, same era.
Certified defenses for data poisoning attacks
Steinhardt, J., Koh, P. W. W., and Liang, P. S · 2017
Cited alongside, same era.
Generative poisoning attack method against neural networks
Yang, C., Wu, Q., Li, H., and Chen, Y · 2017
Cited alongside, same era.
Manipulating machine learning: Poisoning attacks and countermeasures for regression learning
Jagielski, M., Oprea, A., Biggio, B., Liu, C., Nita-Rotaru, C., and Li, B · 2018
Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks
Demontis, A., Melis, M., Pintor, M., Jagielski, M., Biggio, B., Oprea, A., Nita-Rotaru, C., and Roli, F · 2019
Later among the works it cites.
Subpopulation data poisoning attacks
Jagielski, M., Hand, P., and Oprea, A · 2019
Later among the works it cites.
Data poisoning against differentially-private learners: Attacks and defenses
Ma, Y., Zhu, X., and Hsu, J · 2019
Later among the works it cites.
Poisoning attacks with generative adversarial nets
Muñoz-González, L., Pfitzner, B., Russo, M., Carnerero-Cano, J., and Lupu, E. C · 2019
Later among the works it cites.
Transferable clean-label poisoning attacks on Deep Neural Nets
Zhu, C., Huang, W. R., Shafahi, A., Li, H., Taylor, G., Studer, C., and Goldstein, T · 2019
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Stronger data poisoning attacks break data sanitization defenses
Koh, P. W., Steinhardt, J., and Liang, P · 2018
Cited alongside, same era.
Learning under p p -tampering attacks
Mahloujifar, S., Diochnos, D. I., and Mahmoody, M · 2018
Cited alongside, same era.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
Cited alongside, same era.
Data poisoning attacks against online learning
Wang, Y. and Chaudhuri, K · 2018
Cited alongside, same era.
Are we really making much progress? a worrying analysis of recent neural recommendation approaches
Dacrema, M. F., Cremonesi, P., and Jannach, D · 2019
Cited alongside, same era.
The curse of concentration in robust learning: Evasion and poisoning attacks from concentration of measure
Mahloujifar, S., Diochnos, D. I., and Mahmoody, M
Cited in the paper.
Later among the works it cites.
Witches’ brew: Industrial scale data poisoning via gradient matching
Geiping, J., Fowl, L., Huang, W. R., Czaja, W., Taylor, G., Moeller, M., and Goldstein, T · 2020
Closest in time.
Gurobi optimizer reference manual, 2020
Gurobi Optimization, Inc · 2020
Closest in time.
On the effectiveness of mitigating data poisoning attacks with gradient shaping
Hong, S., Chandrasekaran, V., Kaya, Y., Dumitraş, T., and Papernot, N · 2020
Closest in time.
Metapoison: Practical general-purpose clean-label data poisoning
Huang, W. R., Geiping, J., Fowl, L., Taylor, G., and Goldstein, T · 2020
Closest in time.
Poisoning attacks on algorithmic fairness
Solans, D., Biggio, B., and Castillo, C · 2020
Closest in time.
Differentially private learning needs better features (or much more data)
Tramèr, F. and Boneh, D · 2020
Closest in time.