K. Fukunaga and L. Hostetler, “The estimation of the gradient of a density function, with applications in pattern recognition,” IEEE Transactions on Information Theory , vol. 21, no. 1, pp. 32–40, 1975
1975
Earlier work this paper cites.
R. Collobert, S. Bengio, and J. Mariéthoz, “Torch: a modular machine learning software library,” Idiap, Tech. Rep., 2002
2002
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in 2009 IEEE Conference on Computer Vision and Pattern Recognition . Ieee, 2009, pp. 248–255
2009
Earlier work this paper cites.
B. Biggio, B. Nelson, and P. Laskov, “Poisoning attacks against support vector machines,” arXiv preprint arXiv:1206.6389 , 2012
Original
2012
Earlier work this paper cites.
A. Geigel, “Neural network trojan,” Journal of Computer Security , vol. 21, no. 2, pp. 191–232, 2013
2013
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” arXiv preprint arXiv:1412.6572 , 2014
Original
2014
Earlier work this paper cites.
Y. Jia, E. Shelhamer, J. Donahue, S. Karayev, J. Long, R. Girshick, S. Guadarrama, and T. Darrell, “Caffe: Convolutional architecture for fast feature embedding,” in Proceedings of the ACM international conference on Multimedia , 2014, pp. 675–678
2014
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” arXiv preprint arXiv:1409.1556 , 2014
Original
2014
Earlier work this paper cites.
Y. Kim, R. Daly, J. Kim, C. Fallin, J. H. Lee, D. Lee, C. Wilkerson, K. Lai, and O. Mutlu, “Flipping bits in memory without accessing them: An experimental study of DRAM disturbance errors,” ACM SIGARCH Computer Architecture News , vol. 42, no. 3, pp. 361–372, 2014
2014
Earlier work this paper cites.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” nature , vol. 521, no. 7553, p. 436, 2015
2015
Earlier work this paper cites.
H. Xiao, B. Biggio, G. Brown, G. Fumera, C. Eckert, and F. Roli, “Is feature selection secure against training data poisoning?” in International Conference on Machine Learning (ICML) , 2015, pp. 1689–1698
2015
Earlier work this paper cites.
T. A. Tang, L. Mhamdi, D. McLernon, S. A. R. Zaidi, and M. Ghogho, “Deep learning approach for network intrusion detection in software defined networking,” in International Conference on Wireless Networks and Mobile Communications (WINCOM) . IEEE, 2016, pp. 258–263
2016
Earlier work this paper cites.
S. Alfeld, X. Zhu, and P. Barford, “Data poisoning attacks against autoregressive models.” in AAAI Conference on Artificial Intelligence (AAAI) , 2016, pp. 1452–1458
2016
Earlier work this paper cites.
R. Gilad-Bachrach, N. Dowlin, K. Laine, K. Lauter, M. Naehrig, and J. Wernsing, “Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy,” in International Conference on Machine Learning , 2016, pp. 201–210
2016
Earlier work this paper cites.
J. Konečnỳ, H. B. McMahan, F. X. Yu, P. Richtárik, A. T. Suresh, and D. Bacon, “Federated learning: Strategies for improving communication efficiency,” arXiv preprint arXiv:1610.05492 , 2016
Original
2016
Earlier work this paper cites.
O. Vinyals, C. Blundell, T. Lillicrap, D. Wierstra et al. , “Matching networks for one shot learning,” in Advances in Neural Information Processing Systems , 2016, pp. 3630–3638
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , 2016, pp. 770–778
2016
Earlier work this paper cites.
L. A. Gatys, A. S. Ecker, and M. Bethge, “Image style transfer using convolutional neural networks,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , 2016, pp. 2414–2423
2016
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction apis,” in 25th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 16) , 2016, pp. 601–618
2016
Earlier work this paper cites.
Q. Wang, W. Guo, K. Zhang, A. G. Ororbia II, X. Xing, X. Liu, and C. L. Giles, “Adversary resistant deep neural networks with an application to malware detection,” in Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (SIGKDD) . ACM, 2017, pp. 1145–1153
2017
Earlier work this paper cites.
I. Stoica, D. Song, R. A. Popa, D. Patterson, M. W. Mahoney, R. Katz, A. D. Joseph, M. Jordan, J. M. Hellerstein, J. E. Gonzalez et al. , “A berkeley view of systems challenges for AI,” arXiv preprint arXiv:1712.05855 , 2017
Original
2017
Earlier work this paper cites.
Y. Liu, Y. Xie, and A. Srivastava, “Neural trojans,” in 2017 IEEE International Conference on Computer Design (ICCD) . IEEE, 2017, pp. 45–48
2017
Earlier work this paper cites.
T. Gu, B. Dolan-Gavitt, and S. Garg, “Badnets: Identifying vulnerabilities in the machine learning model supply chain,” arXiv preprint arXiv:1708.06733 , 2017
Original
2017
Earlier work this paper cites.
X. Chen, C. Liu, B. Li, K. Lu, and D. Song, “Targeted backdoor attacks on deep learning systems using data poisoning,” arXiv preprint arXiv:1712.05526 , 2017
Original
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2017, pp. 1765–1773
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in IEEE Symposium on Security and Privacy (SP) . IEEE, 2017, pp. 39–57
2017
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, “Practical black-box attacks against machine learning,” in Proceedings of the ACM on Asia Conference on Computer and Communications Security , 2017, pp. 506–519
2017
Earlier work this paper cites.
P. Mohassel and Y. Zhang, “Secureml: A system for scalable privacy-preserving machine learning,” in 2017 IEEE Symposium on Security and Privacy (SP) . IEEE, 2017, pp. 19–38
2017
Earlier work this paper cites.
B. Liang, H. Li, M. Su, X. Li, W. Shi, and X. Wang, “Detecting adversarial examples in deep networks with adaptive noise reduction,” arXiv preprint arXiv:1705.08378 , 2017
Original
2017
Earlier work this paper cites.
A. G. Howard, M. Zhu, B. Chen, D. Kalenichenko, W. Wang, T. Weyand, M. Andreetto, and H. Adam, “MobileNets: Efficient convolutional neural networks for mobile vision applications,” arXiv preprint arXiv:1704.04861 , 2017
Original
2017
Earlier work this paper cites.
J.-Y. Zhu, T. Park, P. Isola, and A. A. Efros, “Unpaired image-to-image translation using cycle-consistent adversarial networks,” in Proceedings of the IEEE international conference on computer vision , 2017, pp. 2223–2232
2017
Earlier work this paper cites.
W. Guo, D. Mu, J. Xu, P. Su, G. Wang, and X. Xing, “Lemna: Explaining deep learning based security applications,” in Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS) . ACM, 2018, pp. 364–379
2018
Earlier work this paper cites.
Y. Ji, X. Zhang, S. Ji, X. Luo, and T. Wang, “Model-Reuse attacks on deep learning systems,” in Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS) . ACM, 2018, pp. 349–363
2018
Earlier work this paper cites.
M. Zou, Y. Shi, C. Wang, F. Li, W. Song, and Y. Wang, “PoTrojan: powerful neural-level trojan designs in deep learning models,” arXiv preprint arXiv:1802.03043 , 2018
Original
2018
Earlier work this paper cites.
N. Akhtar and A. Mian, “Threat of adversarial attacks on deep learning in computer vision: A survey,” IEEE Access , vol. 6, pp. 14 410–14 430, 2018
2018
Earlier work this paper cites.
E. Chou, F. Tramèr, G. Pellegrino, and D. Boneh, “Sentinet: Detecting physical attacks against deep learning systems,” arXiv preprint arXiv:1812.00292 , 2018
Original
2018
Earlier work this paper cites.
M. Jagielski, A. Oprea, B. Biggio, C. Liu, C. Nita-Rotaru, and B. Li, “Manipulating machine learning: Poisoning attacks and countermeasures for regression learning,” in 2018 IEEE Symposium on Security and Privacy (SP) . IEEE, 2018, pp. 19–35
2018
Earlier work this paper cites.
Q. Xiao, K. Li, D. Zhang, and W. Xu, “Security risks in deep learning implementations,” in 2018 IEEE Security and Privacy Workshops (SPW) . IEEE, 2018, pp. 123–128
2018
Earlier work this paper cites.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in Network and Distributed System Security Symposium (NDSS) , 2018
2018
Earlier work this paper cites.
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein, “Poison frogs! targeted clean-label poisoning attacks on neural networks,” in Advances in Neural Information Processing Systems (NIPS) , 2018, pp. 6103–6113. [Online]. Available: https://github.com/ashafahi/inceptionv3-transferLearn-poison
2018
Earlier work this paper cites.
P. Vepakomma, O. Gupta, T. Swedish, and R. Raskar, “Split learning for health: Distributed deep learning without sharing raw patient data,” arXiv preprint arXiv:1812.00564 , 2018
Original
2018
Earlier work this paper cites.
A. Hard, K. Rao, R. Mathews, S. Ramaswamy, F. Beaufays, S. Augenstein, H. Eichner, C. Kiddon, and D. Ramage, “Federated learning for mobile keyboard prediction,” arXiv preprint arXiv:1811.03604 , 2018
Original
2018
Earlier work this paper cites.
J. Dumford and W. Scheirer, “Backdooring convolutional neural networks via targeted weight perturbations,” arXiv preprint arXiv:1812.03128 , 2018
Original
2018
Earlier work this paper cites.
J. Breier, X. Hou, D. Jap, L. Ma, S. Bhasin, and Y. Liu, “Practical fault attack on deep neural networks,” in ACM SIGSAC Conference on Computer and Communications Security (CCS) , 2018, pp. 2204–2206
2018
Earlier work this paper cites.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust physical-world attacks on deep learning visual classification,” in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , 2018, pp. 1625–1634
2018
Earlier work this paper cites.
T. Liu, W. Wen, and Y. Jin, “SIN2: Stealth infection on neural network low-cost agile neural trojan attack methodology,” in 2018 IEEE International Symposium on Hardware Oriented Security and Trust (HOST) . IEEE, 2018, pp. 227–230
2018
Earlier work this paper cites.
C. Liao, H. Zhong, A. Squicciarini, S. Zhu, and D. Miller, “Backdoor embedding in convolutional neural network models via invisible perturbation,” arXiv preprint arXiv:1808.10307 , 2018
Original
2018
Earlier work this paper cites.
W. Xu, D. Evans, and Y. Qi, “Feature squeezing: Detecting adversarial examples in deep neural networks,” in Network and Distributed System Security Symposium (NDSS) , 2018. [Online]. Available: https://github.com/mzweilin/EvadeML-Zoo
2018
Earlier work this paper cites.
C. Guo, M. Rana, M. Cisse, and L. van der Maaten, “Countering adversarial images using input transformations,” in International Conference on Learning Representations (ICLR) , 2018. [Online]. Available: https://github.com/facebookarchive/adversarial_image_defenses
2018
Earlier work this paper cites.
S. Song, Y. Chen, N.-M. Cheung, and C.-C. J. Kuo, “Defense against adversarial attacks with Saak transform,” arXiv preprint arXiv:1808.01785 , 2018
Original
2018
Earlier work this paper cites.
M. Yan, C. Fletcher, and J. Torrellas, “Cache Telepathy: Leveraging shared resource attacks to learn DNN architectures,” arXiv preprint arXiv:1808.04761 , vol. 15, p. 38, 2018
Original
2018
Earlier work this paper cites.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-Pruning: Defending against backdooring attacks on deep neural networks,” in International Symposium on Research in Attacks, Intrusions and Defenses (RAID) , 2018. [Online]. Available: https://github.com/kangliucn/Fine-pruning-defense
2018
Earlier work this paper cites.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in Advances in Neural Information Processing Systems (NIPS) , 2018, pp. 8000–8010. [Online]. Available: https://github.com/MadryLab/backdoor_data_poisoning
2018
Earlier work this paper cites.
B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, T. Lee, I. Molloy, and B. Srivastava, “Detecting backdoor attacks on deep neural networks by activation clustering,” arXiv preprint arXiv:1811.03728 , 2018. [Online]. Available: https://github.com/Trusted-AI/adversarial-robustness-toolbox
Original
2018
Earlier work this paper cites.
N. Papernot and P. McDaniel, “Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning,” arXiv preprint arXiv:1803.04765 , 2018
Original
2018
Earlier work this paper cites.
H. Chen, B. D. Rouhani, and F. Koushanfar, “BlackMarks: Black-box multi-bit watermarking for deep neural networks,” 2018
2018
Earlier work this paper cites.
Y. Adi, C. Baum, M. Cisse, B. Pinkas, and J. Keshet, “Turning your weakness into a strength: Watermarking deep neural networks by backdooring,” in USENIX Security Symposium , 2018. [Online]. Available: https://github.com/adiyoss/WatermarkNN
2018
Earlier work this paper cites.
J. Guo and M. Potkonjak, “Watermarking deep neural networks for embedded systems,” in 2018 IEEE/ACM International Conference on Computer-Aided Design (ICCAD) , 2018, pp. 1–8
2018
Earlier work this paper cites.
J. Zhang, Z. Gu, J. Jang, H. Wu, M. P. Stoecklin, H. Huang, and I. Molloy, “Protecting intellectual property of deep neural networks with watermarking,” in Proceedings of the Asia Conference on Computer and Communications Security (AsiaCCS) . ACM, 2018, pp. 159–172
2018
Earlier work this paper cites.