Fetching the paper…
Reading the bibliography…
In a \emph{data poisoning attack}, an attacker modifies, deletes, and/or inserts some training examples to corrupt the learnt machine learning model.
On the problem of the most efficient tests of statistical hypotheses
Jerzy Neyman and Egon Sharpe Pearson · 1933
Earlier work this paper cites.
The use of confidence or fiducial limits illustrated in the case of the binomial
Charles J Clopper and Egon S Pearson · 1934
Earlier work this paper cites.
Bagging predictors
Leo Breiman · 1996
Earlier work this paper cites.
Casting out demons: Sanitizing training data for anomaly sensors
Gabriela F. Cretu, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo, and Angelos D. Keromytis · 2008
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles A Sutton, J Doug Tygar, and Kai Xia · 2008
Earlier work this paper cites.
Antidote: understanding and defending against poisoning of anomaly detectors
Benjamin IP Rubinstein, Blaine Nelson, Ling Huang, Anthony D Joseph, Shing-hon Lau, Satish Rao, Nina Taft, and JD Tygar · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D Joseph, and JD Tygar · 2010
Earlier work this paper cites.
Bagging classifiers for fighting poisoning attacks in adversarial classification tasks
Battista Biggio, Igino Corona, Giorgio Fumera, Giorgio Giacinto, and Fabio Roli · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Is data clustering in adversarial settings secure?
Battista Biggio, Ignazio Pillai, Samuel Rota Bulò, Davide Ariu, Marcello Pelillo, and Fabio Roli · 2013
Earlier work this paper cites.
Poisoning behavioral malware clustering
Battista Biggio, Konrad Rieck, Davide Ariu, Christian Wressnegger, Igino Corona, Giorgio Giacinto, and Fabio Roli · 2014
Earlier work this paper cites.
Robust logistic regression and classification
Jiashi Feng, Huan Xu, Shie Mannor, and Shuicheng Yan · 2014
Earlier work this paper cites.
Systematic poisoning attacks on and defenses for machine learning in healthcare
Mehran Mozaffari-Kermani, Susmita Sur-Kolay, Anand Raghunathan, and Niraj K Jha · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Martín Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang · 2016
Cited alongside, same era.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Cited alongside, same era.
Data poisoning attacks on factorization-based collaborative filtering
Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik · 2016
Cited alongside, same era.
Mitigating evasion attacks to deep neural networks via region-based classification
Xiaoyu Cao and Neil Zhenqiang Gong · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Spectral signatures in backdoor attacks
Brandon Tran, Jerry Li, and Aleksander Madry · 2018
Later among the works it cites.
Adversarial attacks on neural networks for graph data
Daniel Zügner, Amir Akbarnejad, and Stephan Günnemann · 2018
Later among the works it cites.
Analyzing federated learning through an adversarial lens
Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo · 2019
Later among the works it cites.
Certified adversarial robustness via randomized smoothing
Jeremy M Cohen, Elan Rosenfeld, and J Zico Kolter · 2019
Later among the works it cites.
Data poisoning against differentially-private learners: Attacks and defenses
Yuzhe Ma, Xiaojin Zhu, and Justin Hsu · 2019
Later among the works it cites.
Attacking graph-based classification via manipulating the graph structure
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Cited alongside, same era.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2017
Cited alongside, same era.
Towards poisoning of deep learning algorithms with back-gradient optimization
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli · 2017
Cited alongside, same era.
Certified defenses for data poisoning attacks
Jacob Steinhardt, Pang Wei W Koh, and Percy S Liang · 2017
Cited alongside, same era.
Poisoning attacks to graph-based recommender systems
Minghong Fang, Guolei Yang, Neil Zhenqiang Gong, and Jia Liu · 2018
Cited alongside, same era.
Manipulating machine learning: Poisoning attacks and countermeasures for regression learning
Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li · 2018
Cited alongside, same era.
Stronger data poisoning attacks break data sanitization defenses
Pang Wei Koh, Jacob Steinhardt, and Percy Liang · 2018
Cited alongside, same era.
Binghui Wang and Neil Zhenqiang Gong · 2019
Later among the works it cites.
Transferable clean-label poisoning attacks on deep neural nets
Chen Zhu, W Ronny Huang, Hengduo Li, Gavin Taylor, Christoph Studer, and Tom Goldstein · 2019
Later among the works it cites.
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov · 2020
Closest in time.
Influence function based data poisoning attacks to top-n recommender systems
Minghong Fang, Neil Zhenqiang Gong, and Jia Liu · 2020
Closest in time.
Certified robustness of community detection against adversarial structural perturbation via randomized smoothing
Jinyuan Jia, Binghui Wang, Xiaoyu Cao, and Neil Zhenqiang Gong · 2020
Closest in time.
Deep partition aggregation: Provable defense against general poisoning attacks
Alexander Levine and Soheil Feizi · 2020
Closest in time.
Certified robustness to label-flipping attacks via randomized smoothing
Elan Rosenfeld, Ezra Winston, Pradeep Ravikumar, and J Zico Kolter · 2020
Closest in time.
On certifying robustness against backdoor attacks via randomized smoothing
Binghui Wang, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong · 2020
Closest in time.
Backdoor attacks to graph neural networks
Zaixi Zhang, Jinyuan Jia, Binghui Wang, and Neil Zhenqiang Gong · 2020
Closest in time.