C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing Properties of Neural Networks,” in
2014
Earlier work this paper cites.
I. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and Harnessing Adversarial Examples,” in
2015
Earlier work this paper cites.
M. Backes, S. Bugiel, and E. Derr, “Reliable third-party library detection in android and its security applications,” in
2016
Earlier work this paper cites.
P. Rajpurkar, J. Zhang, K. Lopyrev, and P. Liang, “SQuAD: 100,000+ Questions for Machine Comprehension of Text,” in
2016
Earlier work this paper cites.
N. Papernot, P. D. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, “The Limitations of Deep Learning in Adversarial Settings,” in
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks,” in
2016
Earlier work this paper cites.
T. Gu, B. Dolan-Gavitt, and S. Garg, “BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain,”
2017
Earlier work this paper cites.
A. Trischler, T. Wang, X. Yuan, J. Harris, A. Sordoni, P. Bachman, and K. Suleman, “NewsQA: A machine comprehension dataset,” in
2017
Earlier work this paper cites.
N. Carlini and D. A. Wagner, “Towards Evaluating the Robustness of Neural Networks,” in
2017
Earlier work this paper cites.
A. Kurakin, I. J. Goodfellow, and S. Bengio, “Adversarial Machine Learning at Scale,” in
2017
Earlier work this paper cites.
D. Meng and H. Chen, “MagNet: A Two-Pronged Defense Against Adversarial Examples,” in
2017
Earlier work this paper cites.
Y. Ji, X. Zhang, and T. Wang, “Backdoor Attacks against Learning Systems,” in
2017
Earlier work this paper cites.
J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, “BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding,”
2018
Earlier work this paper cites.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in
2018
Earlier work this paper cites.
Y. Ji, X. Zhang, S. Ji, X. Luo, and T. Wang, “Model-Reuse Attacks on Deep Learning Systems,” in
2018
Earlier work this paper cites.
A. M. Founta, C. Djouvas, D. Chatzakou, I. Leontiadis, J. Blackburn, G. Stringhini, A. Vakali, M. Sirivianos, and N. Kourtellis, “Large Scale Crowdsourcing and Characterization of Twitter Abusive Behavior,” in
2018
Earlier work this paper cites.
B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, T. Lee, I. Molloy, and B. Srivastava, “Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering,” in
2018
Earlier work this paper cites.
E. Chou, F. Tramer, G. Pellegrino, and D. Boneh, “SentiNet: Detecting Physical Attacks Against Deep Learning Systems,” in
2018
Earlier work this paper cites.
B. Biggio and F. Roli, “Wild Patterns: Ten Years after The Rise of Adversarial Machine Learning,”
2018
Earlier work this paper cites.
C. Guo, M. Rana, M. Cissé, and L. van der Maaten, “Countering Adversarial Images Using Input Transformations,” in
2018
Earlier work this paper cites.
F. Tramèr, A. Kurakin, N. Papernot, I. Goodfellow, D. Boneh, and P. McDaniel, “Ensemble Adversarial Training: Attacks and Defenses,” in
2018
Earlier work this paper cites.