Fetching the paper…
Reading the bibliography…
Data poisoning attacks and backdoor attacks aim to corrupt a machine learning classifier via modifying, adding, and/or removing some carefully selected training examples, such that the corrupted classifier makes incorrect predictions as the attacker desires.
Discriminatory analysis: Nonparametric discrimination, consistency properties
Evelyn Fix and JL Hodges · 1951
Earlier work this paper cites.
Nearest neighbor pattern classification
Thomas Cover and Peter Hart · 1967
Earlier work this paper cites.
Asymptotic properties of nearest neighbor rules using edited data
Dennis L Wilson · 1972
Earlier work this paper cites.
Discovering informative patterns and data cleaning
Isabelle Guyon, Nada Matic, Vladimir Vapnik, et al · 1996
Earlier work this paper cites.
Histograms of oriented gradients for human detection
Navneet Dalal and Bill Triggs · 2005
Earlier work this paper cites.
Can machine learning be secure?
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D Joseph, and J Doug Tygar · 2006
Earlier work this paper cites.
Dimensionality reduction by learning an invariant mapping
Raia Hadsell, Sumit Chopra, and Yann LeCun · 2006
Earlier work this paper cites.
Casting out demons: Sanitizing training data for anomaly sensors
Gabriela F Cretu, Angelos Stavrou, Michael E Locasto, Salvatore J Stolfo, and Angelos D Keromytis · 2008
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles A Sutton, J Doug Tygar, and Kai Xia · 2008
Earlier work this paper cites.
Antidote: understanding and defending against poisoning of anomaly detectors
Benjamin IP Rubinstein, Blaine Nelson, Ling Huang, Anthony D Joseph, Shing-hon Lau, Satish Rao, Nina Taft, and J Doug Tygar · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D Joseph, and J Doug Tygar · 2010
Earlier work this paper cites.
Bagging classifiers for fighting poisoning attacks in adversarial classification tasks
Battista Biggio, Igino Corona, Giorgio Fumera, Giorgio Giacinto, and Fabio Roli · 2011
Earlier work this paper cites.
How much spam can you take? an analysis of crowdsourcing results to increase accuracy
Jeroen Vuurens, Arjen P de Vries, and Carsten Eickhoff · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, B Nelson, and P Laskov · 2012
Earlier work this paper cites.
Security evaluation of pattern classifiers under attack
Battista Biggio, Giorgio Fumera, and Fabio Roli · 2013
Earlier work this paper cites.
Robust logistic regression and classification
Jiashi Feng, Huan Xu, Shie Mannor, and Shuicheng Yan · 2014
Earlier work this paper cites.
Systematic poisoning attacks on and defenses for machine learning in healthcare
Mehran Mozaffari-Kermani, Susmita Sur-Kolay, Anand Raghunathan, and Niraj K Jha · 2014
Earlier work this paper cites.
Data poisoning attacks on factorization-based collaborative filtering
Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik · 2016
Earlier work this paper cites.
The vulnerability of learning to adversarial perturbation increases with intrinsic dimensionality
Laurent Amsaleg, James Bailey, Dominique Barbe, Sarah Erfani, Michael E Houle, Vinh Nguyen, and Miloš Radovanović · 2017
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Cited alongside, same era.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2017
Cited alongside, same era.
Towards poisoning of deep learning algorithms with back-gradient optimization
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli · 2017
Cited alongside, same era.
Certified defenses for data poisoning attacks
Jacob Steinhardt, Pang Wei W Koh, and Percy S Liang · 2017
Cited alongside, same era.
Fake co-visitation injection attacks to recommender systems
Data poisoning against differentially-private learners: Attacks and defenses
Yuzhe Ma, Xiaojin Zhu, and Justin Hsu · 2019
Later among the works it cites.
Deep k-nn defense against clean-label data poisoning attacks
Neehar Peri, Neal Gupta, W Ronny Huang, Liam Fowl, Chen Zhu, Soheil Feizi, Tom Goldstein, and John P Dickerson · 2019
Later among the works it cites.
Fast rates for a knn classifier robust to unknown asymmetric label noise
Henry WJ Reeve and Ata Kabán · 2019
Later among the works it cites.
Transferable clean-label poisoning attacks on deep neural nets
Chen Zhu, W Ronny Huang, Hengduo Li, Gavin Taylor, Christoph Studer, and Tom Goldstein · 2019
Later among the works it cites.
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov · 2020
Closest in time.
Deep k-nn for noisy labels
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Guolei Yang, Neil Zhenqiang Gong, and Ying Cai · 2017
Cited alongside, same era.
Poisoning attacks to graph-based recommender systems
Minghong Fang, Guolei Yang, Neil Zhenqiang Gong, and Jia Liu · 2018
Cited alongside, same era.
On the consistency of exact and approximate nearest neighbor with noisy data
Wei Gao, Xin-Yi Niu, and Zhi-Hua Zhou · 2018
Cited alongside, same era.
Manipulating machine learning: Poisoning attacks and countermeasures for regression learning
Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li · 2018
Cited alongside, same era.
Fine-pruning: Defending against backdooring attacks on deep neural networks
Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2018
Cited alongside, same era.
Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning
Nicolas Papernot and Patrick McDaniel · 2018
Cited alongside, same era.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein · 2018
Cited alongside, same era.
Dara Bahri, Heinrich Jiang, and Maya Gupta · 2020
Closest in time.
A simple framework for contrastive learning of visual representations
Ting Chen, Simon Kornblith, Mohammad Norouzi, and Geoffrey Hinton · 2020
Closest in time.
Detecting adversarial samples using influence functions and nearest neighbors
Gilad Cohen, Guillermo Sapiro, and Raja Giryes · 2020
Closest in time.
Momentum contrast for unsupervised visual representation learning
Kaiming He, Haoqi Fan, Yuxin Wu, Saining Xie, and Ross Girshick · 2020
Closest in time.
Metapoison: Practical general-purpose clean-label data poisoning
W Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor, and Tom Goldstein · 2020
Closest in time.
Certified robustness to label-flipping attacks via randomized smoothing
Elan Rosenfeld, Ezra Winston, Pradeep Ravikumar, and J Zico Kolter · 2020
Closest in time.
On certifying robustness against backdoor attacks via randomized smoothing
Binghui Wang, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong · 2020
Closest in time.
Rab: Provable robustness against backdoor attacks
Maurice Weber, Xiaojun Xu, Bojan Karlas, Ce Zhang, and Bo Li · 2020
Closest in time.
Robustness for non-parametric classification: A generic attack and defense
Yao-Yuan Yang, Cyrus Rashtchian, Yizhen Wang, and Kamalika Chaudhuri · 2020
Closest in time.
https://github.com/openai/CLIP , 2021
CLIP · 2021
Closest in time.
https://scikit-image.org/docs/dev/api/skimage.feature.html#skimage.feature.hog , 2021
HOG · 2021
Closest in time.
Data poisoning attacks to deep learning based recommender systems
Hai Huang, Jiaming Mu, Neil Zhenqiang Gong, Qi Li, Bin Liu, and Mingwei Xu · 2021
Closest in time.
Deep partition aggregation: Provable defense against general poisoning attacks
Alexander Levine and Soheil Feizi · 2021
Closest in time.
Learning transferable visual models from natural language supervision
Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, et al · 2021
Closest in time.