Fetching the paper…
Reading the bibliography…
Backdoor attack intends to embed hidden backdoor into deep neural networks (DNNs), so that the attacked models perform well on benign samples, whereas their predictions will be maliciously changed if the hidden backdoor is activated by attacker-specified triggers.
L. Breiman, “Bagging predictors,” Machine learning , vol. 24, no. 2, pp. 123–140, 1996
1996
Earlier work this paper cites.
Y. Lecun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proceedings of the IEEE , vol. 86, no. 11, pp. 2278–2324, 1998
1998
Earlier work this paper cites.
P. Auer, N. Cesa-Bianchi, and P. Fischer, “Finite-time analysis of the multiarmed bandit problem,” Machine learning , vol. 47, no. 2, pp. 235–256, 2002
2002
Earlier work this paper cites.
G. B. Huang, M. Ramesh, T. Berg, and E. Learned-Miller, “Labeled faces in the wild: A database for studying face recognition in unconstrained environments,” University of Massachusetts, Amherst, Tech. Rep. 07-49, October 2007
2007
Earlier work this paper cites.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” Tech. Rep., 2009
2009
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in CVPR , 2009
2009
Earlier work this paper cites.
N. Kumar, A. C. Berg, P. N. Belhumeur, and S. K. Nayar, “Attribute and simile classifiers for face verification,” in ICCV , 2009
2009
Earlier work this paper cites.
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng, “Reading digits in natural images with unsupervised feature learning,” in NeurIPS Workshop , 2011
2011
Earlier work this paper cites.
L. Wolf, T. Hassner, and I. Maoz, “Face recognition in unconstrained videos with matched background similarity,” in CVPR , 2011
2011
Earlier work this paper cites.
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, “Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition,” Neural networks , vol. 32, pp. 323–332, 2012
2012
Earlier work this paper cites.
A. Mogelmose, M. M. Trivedi, and T. B. Moeslund, “Vision-based traffic sign detection and analysis for intelligent driver assistance systems: Perspectives and survey,” IEEE Transactions on Intelligent Transportation Systems , vol. 13, no. 4, pp. 1484–1497, 2012
2012
Earlier work this paper cites.
G. Hinton, O. Vinyals, and J. Dean, “Distilling the knowledge in a neural network,” in NeurIPS Workshop , 2014
2014
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” in ICLR , 2015
2015
Earlier work this paper cites.
O. M. Parkhi, A. Vedaldi, and A. Zisserman, “Deep face recognition,” in BMVC , 2015
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in CVPR , 2017
2017
Earlier work this paper cites.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in NDSS , 2017
2017
Earlier work this paper cites.
Y. Liu, Y. Xie, and A. Srivastava, “Neural trojans,” in ICCD , 2017
2017
Earlier work this paper cites.
R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, and D. Batra, “Grad-cam: Visual explanations from deep networks via gradient-based localization,” in ICCV , 2017
2017
Earlier work this paper cites.
J. Kirkpatrick, R. Pascanu, N. Rabinowitz, J. Veness, G. Desjardins, A. A. Rusu, K. Milan, J. Quan, T. Ramalho, A. Grabska-Barwinska et al. , “Overcoming catastrophic forgetting in neural networks,” Proceedings of the national academy of sciences , vol. 114, no. 13, pp. 3521–3526, 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in ICLR , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Y. Adi, C. Baum, M. Cisse, B. Pinkas, and J. Keshet, “Turning your weakness into a strength: Watermarking deep neural networks by backdooring,” in USENIX Security , 2018
2018
Earlier work this paper cites.
K. R. Mopuri, A. Ganeshan, and R. V. Babu, “Generalizable data-free objective for crafting universal adversarial perturbations,” IEEE transactions on pattern analysis and machine intelligence , vol. 41, no. 10, pp. 2452–2465, 2018
2018
Earlier work this paper cites.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in RAID , 2018
2018
Earlier work this paper cites.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in NeurIPS , 2018
2018
Earlier work this paper cites.
T. Garipov, P. Izmailov, D. Podoprikhin, D. P. Vetrov, and A. G. Wilson, “Loss surfaces, mode connectivity, and fast ensembling of dnns,” in NeurIPS , 2018
2018
Earlier work this paper cites.
X. Ma, B. Li, Y. Wang, S. M. Erfani, S. Wijewickrema, G. Schoenebeck, D. Song, M. E. Houle, and J. Bailey, “Characterizing adversarial subspaces using local intrinsic dimensionality,” in ICLR , 2018
2018
Earlier work this paper cites.
Q. Cao, L. Shen, W. Xie, O. M. Parkhi, and A. Zisserman, “Vggface2: A dataset for recognising faces across pose and age,” in IEEE FGR , 2018
2018
Earlier work this paper cites.
M. Sugiyama, Introduction to statistical machine learning . Morgan Kaufmann, 2015
2018
Earlier work this paper cites.
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,” IEEE Access , vol. 7, pp. 47 230–47 244, 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in IEEE S&P , 2019
2019
Earlier work this paper cites.
Q. Xiao, Y. Chen, C. Shen, Y. Chen, and K. Li, “Seeing is not believing: Camouflage attacks on image scaling algorithms,” in USENIX Security , 2019
2019
Earlier work this paper cites.
H. Chen, C. Fu, J. Zhao, and F. Koushanfar, “Deepinspect: A black-box trojan detection and mitigation framework for deep neural networks.” in IJCAI , 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
J. Dai, C. Chen, and Y. Li, “A backdoor attack against lstm-based text classification systems,” IEEE Access , vol. 7, pp. 138 872–138 878, 2019
2019
Earlier work this paper cites.
A. N. Bhagoji, S. Chakraborty, P. Mittal, and S. Calo, “Analyzing federated learning through an adversarial lens,” in ICML , 2019
2019
Earlier work this paper cites.
C. Xie, K. Huang, P.-Y. Chen, and B. Li, “Dba: Distributed backdoor attacks against federated learning,” in ICLR , 2019
2019
Earlier work this paper cites.
Z. Sun, P. Kairouz, A. T. Suresh, and H. B. McMahan, “Can you really backdoor federated learning?” in NeurIPS Workshop , 2019
2019
Earlier work this paper cites.
Y. Yao, H. Li, H. Zheng, and B. Y. Zhao, “Latent backdoor attacks on deep neural networks,” in CCS , 2019
2019
Earlier work this paper cites.
S. Thys, W. Van Ranst, and T. Goedemé, “Fooling automated surveillance cameras: adversarial patches to attack person detection,” in CVPR Workshop , 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
X. Qiao, Y. Yang, and H. Li, “Defending neural backdoors via generative distribution modeling,” in NeurIPS , 2019
2019
Earlier work this paper cites.
H. Cheng, K. Xu, S. Liu, P.-Y. Chen, P. Zhao, and X. Lin, “Defending against backdoor attack on deep neural networks,” in KDD Workshop , 2019
2019
Earlier work this paper cites.
B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, T. Lee, I. Molloy, and B. Srivastava, “Detecting backdoor attacks on deep neural networks by activation clustering,” in AAAI Workshop , 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal, “Strip: A defence against trojan attacks on deep neural networks,” in ACSAC , 2019
2019
Earlier work this paper cites.
M. Subedar, N. Ahuja, R. Krishnan, I. J. Ndiour, and O. Tickoo, “Deep probabilistic models to detect data poisoning attacks,” in NeurIPS Workshop , 2019
2019
Earlier work this paper cites.
Y. Dong, H. Su, B. Wu, Z. Li, W. Liu, T. Zhang, and J. Zhu, “Efficient decision-based black-box adversarial attacks on face recognition,” in CVPR , 2019
2019
Earlier work this paper cites.
J. M. Cohen, E. Rosenfeld, and J. Z. Kolter, “Certified adversarial robustness via randomized smoothing,” in ICML , 2019
2019
Earlier work this paper cites.
J. Wang, G. Dong, J. Sun, X. Wang, and P. Zhang, “Adversarial sample detection for deep neural network through model mutation testing,” in ICSE , 2019
2019
Earlier work this paper cites.
J. Bai, B. Chen, Y. Li, D. Wu, W. Guo, S.-t. Xia, and E.-h. Yang, “Targeted attack for deep hashing based retrieval,” in ECCV , 2020
2020
Earlier work this paper cites.
D. Wu, S. Xia, and Y. Wang, “Adversarial weight perturbation helps robust generalization,” in NeurIPS , 2020
2020
Earlier work this paper cites.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in ECCV , 2020
2020
Earlier work this paper cites.
S. Li, M. Xue, B. Zhao, H. Zhu, and X. Zhang, “Invisible backdoor attacks on deep neural networks via steganography and regularization,” IEEE Transactions on Dependable and Secure Computing , 2020
2020
Earlier work this paper cites.
A. Saha, A. Subramanya, and H. Pirsiavash, “Hidden trigger backdoor attacks,” in AAAI , 2020
2020
Earlier work this paper cites.
S. Zhao, X. Ma, X. Zheng, J. Bailey, J. Chen, and Y.-G. Jiang, “Clean-label backdoor attacks on video recognition models,” in CVPR , 2020
2020
Earlier work this paper cites.
K. Kurita, P. Michel, and G. Neubig, “Weight poisoning attacks on pre-trained models,” in ACL , 2020
2020
Earlier work this paper cites.
S. Wang, S. Nepal, C. Rudolph, M. Grobler, S. Chen, and T. Chen, “Backdoor attacks against transfer learning with pre-trained deep learning models,” IEEE Transactions on Services Computing , 2020
2020
Earlier work this paper cites.
A. S. Rakin, Z. He, and D. Fan, “Tbt: Targeted neural network attack with bit trojan,” in CVPR , 2020
2020
Earlier work this paper cites.
R. Tang, M. Du, N. Liu, F. Yang, and X. Hu, “An embarrassingly simple approach for trojan attack in deep neural networks,” in KDD , 2020
2020
Cited alongside, same era.
S. Kolouri, A. Saha, H. Pirsiavash, and H. Hoffmann, “Universal litmus patterns: Revealing backdoor attacks in cnns,” in CVPR , 2020
2020
Cited alongside, same era.
B. Wang, X. Cao, N. Z. Gong et al. , “On certifying robustness against backdoor attacks via randomized smoothing,” in CVPR Workshop , 2020
2020
Cited alongside, same era.
2020
Cited alongside, same era.
Y. Liu, A. Mondal, A. Chakraborty, M. Zuzak, N. Jacobsen, D. Xing, and A. Srivastava, “A survey on neural trojans,” in ISQED , 2020
2020
S. Cheng, Y. Liu, S. Ma, and X. Zhang, “Deep feature space trojan attack of neural networks by controlled detoxification,” in AAAI , 2021
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
2020
Cited alongside, same era.
2020
Cited alongside, same era.
2020
Cited alongside, same era.
H. Zhong, C. Liao, A. C. Squicciarini, S. Zhu, and D. Miller, “Backdoor embedding in convolutional neural network models via invisible perturbation,” in ACM CODASPY , 2020
2020
Cited alongside, same era.
E. Quiring and K. Rieck, “Backdooring and poisoning neural networks with image-scaling attacks,” in IEEE S&P Workshop , 2020
2020
Cited alongside, same era.
S. Garg, A. Kumar, V. Goel, and Y. Liang, “Can adversarial weight perturbations inject neural backdoors?” in CIKM , 2020
2020
Cited alongside, same era.
J. Geiping, L. H. Fowl, W. R. Huang, W. Czaja, G. Taylor, M. Moeller, and T. Goldstein, “Witches’ brew: Industrial scale data poisoning via gradient matching,” in ICLR , 2020
2020
Cited alongside, same era.
2021
Closest in time.
I. Shumailov, Z. Shumaylov, D. Kazhdan, Y. Zhao, N. Papernot, M. A. Erdogdu, and R. Anderson, “Manipulating sgd with data ordering attacks,” in NeurIPS , 2021
2021
Closest in time.
2021
Closest in time.
Y. Dong, X. Yang, Z. Deng, T. Pang, Z. Xiao, H. Su, and J. Zhu, “Black-box detection of backdoor attacks with limited information and data,” in ICCV , 2021
2021
Closest in time.
2021
Closest in time.
E. Wenger, J. Passananti, A. N. Bhagoji, Y. Yao, H. Zheng, and B. Y. Zhao, “Backdoor attacks against deep learning systems in the physical world,” in CVPR , 2021
2021
Closest in time.
X. Chen, A. Salem, D. Chen, M. Backes, S. Ma, Q. Shen, Z. Wu, and Y. Zhang, “Badnl: Backdoor attacks against nlp models with semantic-preserving improvements,” in ACSAC , 2021
2021
Closest in time.
F. Qi, Y. Yao, S. Xu, Z. Liu, and M. Sun, “Turn the combination lock: Learnable textual backdoor attacks via word substitution,” in ACL , 2021
2021
Closest in time.
F. Qi, M. Li, Y. Chen, Z. Zhang, Z. Liu, Y. Wang, and M. Sun, “Hidden killer: Invisible textual backdoor attacks with syntactic trigger,” in ACL , 2021
2021
Closest in time.
W. Yang, Y. Lin, P. Li, J. Zhou, and X. Sun, “Rethinking stealthiness of backdoor attack against nlp models,” in ACL , 2021
2021
Closest in time.
F. Qi, Y. Chen, X. Zhang, M. Li, Z. Liu, and M. Sun, “Mind the style of text! adversarial and backdoor attacks based on text style transfer,” in EMNLP , 2021
2021
Closest in time.
W. Yang, L. Li, Z. Zhang, X. Ren, X. Sun, and B. He, “Be careful about poisoned word embeddings: Exploring the vulnerability of the embedding layers in nlp models,” in NAACL , 2021
2021
Closest in time.
L. Li, D. Song, X. Li, J. Zeng, R. Ma, and X. Qiu, “Backdoor attacks on pre-trained models by layerwise weight poisoning,” in EMNLP , 2021
2021
Closest in time.
Z. Xi, R. Pang, S. Ji, and T. Wang, “Graph backdoor,” in USENIX Security , 2021
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
Z. Xiang, D. J. Miller, S. Chen, X. Li, and G. Kesidis, “A backdoor attack against 3d point cloud classifiers,” in ICCV , 2021
2021
Closest in time.
X. Li, Z. Chen, Y. Zhao, Z. Tong, Y. Zhao, A. Lim, and J. T. Zhou, “Pointba: Towards backdoor attacks in 3d point cloud,” in ICCV , 2021
2021
Closest in time.
Z. Yan, J. Wu, G. Li, S. Li, and M. Guizani, “Deep neural backdoor in semi-supervised learning: Threats and countermeasures,” IEEE Transactions on Information Forensics and Security , vol. 16, pp. 4827–4842, 2021
2021
Closest in time.
L. Wang, Z. Javed, X. Wu, W. Guo, X. Xing, and D. Song, “Backdoorl: Backdoor attack against competitive reinforcement learning,” in IJCAI , 2021
2021
Closest in time.
C. Ashcraft and K. Karra, “Poisoning deep reinforcement learning agents with in-distribution triggers,” in ICLR Workshop , 2021
2021
Closest in time.
2021
Closest in time.
S. Hong, M.-A. Panaitescu-Liess, Y. Kaya, and T. Dumitras, “Qu-anti-zation: Exploiting quantization artifacts for achieving adversarial outcomes,” in NeurIPS , 2021
2021
Closest in time.
X. Pan, M. Zhang, Y. Yan, and M. Yang, “Understanding the threats of trojaned quantized neural network in model supply chains,” in ACSAC , 2021
2021
Closest in time.
T. Zhai, Y. Li, Z. Zhang, B. Wu, Y. Jiang, and S.-T. Xia, “Backdoor attack against speaker verification,” in ICASSP , 2021
2021
Closest in time.
2021
Closest in time.
C. Li, X. Chen, D. Wang, S. Wen, M. E. Ahmed, S. Camtepe, and Y. Xiang, “Backdoor attack on machine learning based android malware detectors,” IEEE Transactions on Dependable and Secure Computing , 2021
2021
Closest in time.
G. Severi, J. Meyer, S. Coull, and A. Oprea, “Explanation-guided backdoor poisoning attacks against malware classifiers,” in USENIX Security , 2021
2021
Closest in time.
Y. Li, Y. Li, Y. Lv, Y. Jiang, and S.-T. Xia, “Hidden backdoor attack against semantic segmentation models,” in ICLR Workshop , 2021
2021
Closest in time.
M. S. Ozdayi, M. Kantarcioglu, and Y. R. Gel, “Defending against backdoors in federated learning with robust learning rate,” in AAAI , 2021
2021
Closest in time.
X. Liu, H. Li, G. Xu, Z. Chen, X. Huang, and R. Lu, “Privacy-enhanced federated learning against poisoning adversaries,” IEEE Transactions on Information Forensics and Security , vol. 16, pp. 4574–4588, 2021
2021
Closest in time.
2021
Closest in time.
Y.-S. Lin, W.-C. Lee, and Z. B. Celik, “What do you see? evaluation of explainable artificial intelligence (xai) interpretability through neural backdoors,” in KDD , 2021
2021
Closest in time.
2021
Closest in time.
Y. Zeng, H. Qiu, S. Guo, T. Zhang, M. Qiu, and B. Thuraisingham, “Deepsweep: An evaluation framework for mitigating dnn backdoor attacks using data augmentation,” in AsiaCCS , 2021
2021
Closest in time.
Y. Li, X. Lyu, N. Koren, L. Lyu, B. Li, and X. Ma, “Neural attention distillation: Erasing backdoor triggers from deep neural networks,” in ICLR , 2021
2021
Closest in time.
D. Wu and Y. Wang, “Adversarial neuron pruning purifies backdoored deep models,” in NeurIPS , 2021
2021
Closest in time.
X. Xu, Q. Wang, H. Li, N. Borisov, C. A. Gunter, and B. Li, “Detecting ai trojans using meta neural analysis,” in IEEE S&P , 2021
2021
Closest in time.
S. Zheng, Y. Zhang, H. Wagner, M. Goswami, and C. Chen, “Topological detection of trojaned neural networks,” in NeurIPS , 2021
2021
Closest in time.
E. Borgnia, V. Cherepanova, L. Fowl, A. Ghiasi, J. Geiping, M. Goldblum, T. Goldstein, and A. Gupta, “Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff,” in ICASSP , 2021
2021
Closest in time.
X. Liu, F. Li, B. Wen, and Q. Li, “Removing backdoor-based watermarks in neural networks with limited data,” in ICPR , 2021
2021
Closest in time.
D. Tang, X. Wang, H. Tang, and K. Zhang, “Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection,” in USENIX Security , 2021
2021
Closest in time.
J. Hayase and W. Kong, “Spectre: Defending against backdoor attacks using robust covariance estimation,” in ICML , 2021
2021
Closest in time.
2021
Closest in time.
Y. Zeng, W. Park, Z. M. Mao, and R. Jia, “Rethinking the backdoor attacks’ triggers: A frequency perspective,” in ICCV , 2021
2021
Closest in time.
J. Jia, X. Cao, and N. Z. Gong, “Intrinsic certified robustness of bagging against data poisoning attacks,” in AAAI , 2021
2021
Closest in time.
A. Levine and S. Feizi, “Deep partition aggregation: Provable defenses against general poisoning attacks,” in ICLR , 2021
2021
Closest in time.
Y. Li, B. Wu, Y. Feng, Y. Fan, Y. Jiang, Z. Li, and S.-T. Xia, “Semi-supervised robust training with generalized perturbed neighborhood,” Pattern Recognition , vol. 124, p. 108472, 2022
2022
Closest in time.
J. Jia, Y. Liu, and N. Z. Gong, “Badencoder: Backdoor attacks to pre-trained encoders in self-supervised learning,” in IEEE S&P , 2022
2022
Closest in time.
N. Carlini and A. Terzis, “Poisoning and backdooring contrastive learning,” in ICLR , 2022
2022
Closest in time.
S. Fang and A. Choromanska, “Backdoor attacks on the dnn interpretation system,” in AAAI , 2022
2022
Closest in time.
Y. Li, H. Zhong, X. Ma, Y. Jiang, and S.-T. Xia, “Few-shot backdoor attacks on visual object tracking,” in ICLR , 2022
2022
Closest in time.
Y. Liu, Z. Yi, Y. Kang, Y. He, W. Liu, T. Zou, and Q. Yang, “Defending label inference and backdoor attacks in vertical federated learning,” in AAAI , 2022
2022
Closest in time.
K. Chen, Y. Meng, X. Sun, S. Guo, T. Zhang, J. Li, and C. Fan, “Badpre: Task-agnostic backdoor attacks to pre-trained nlp foundation models,” in ICLR , 2022
2022
Closest in time.
Y. Li, L. Zhu, X. Jia, Y. Jiang, S.-T. Xia, and X. Cao, “Defending against model stealing via verifying embedded external features,” in AAAI , 2022
2022
Closest in time.
Y. Zeng, S. Chen, W. P. Z. Morley Mao, M. Jin, and R. Jia, “Adversarial unlearning of backdoors via implicit hypergradient,” in ICLR , 2022
2022
Closest in time.
J. Guo, A. Li, and C. Liu, “Aeva: Black-box backdoor detection using adversarial extreme value analysis,” in ICLR , 2022
2022
Closest in time.
X. Hu, X. Lin, M. Cogswell, Y. Yao, S. Jha, and C. Chen, “Trigger hunting with a topological prior for trojan detection,” in ICLR , 2022
2022
Closest in time.
Z. Xiang, D. J. Miller, and G. Kesidis, “Post-training detection of backdoor attacks for two-class and multi-attack scenarios,” in ICLR , 2022
2022
Closest in time.
K. Huang, Y. Li, B. Wu, Z. Qin, and K. Ren, “Backdoor defense via decoupling the training process,” in ICLR , 2022
2022
Closest in time.
J. Jia, X. Cao, and N. Z. Gong, “Certified robustness of nearest neighbors against data poisoning attacks,” in AAAI , 2022
2022
Closest in time.