Transferable clean-label poisoning attacks on deep neural nets
Original
Chen Zhu, W Ronny Huang, Ali Shafahi, Hengduo Li, Gavin Taylor, Christoph Studer, and Tom Goldstein · 1905
Earlier work this paper cites.
Generalized resilience and robust statistics
Original
Banghua Zhu, Jiantao Jiao, and Jacob Steinhardt · 1909
Earlier work this paper cites.
Refit: a unified watermark removal framework for deep learning systems with limited data
Original
Xinyun Chen, Wenxiao Wang, Chris Bender, Yiming Ding, Ruoxi Jia, Bo Li, and Dawn Song · 1911
Earlier work this paper cites.
A survey of sampling from contaminated distributions
John W Tukey · 1960
Earlier work this paper cites.
Robust estimation of a location parameter
Peter J Huber · 1964
Earlier work this paper cites.
Robust regression using repeated medians
Andrew F Siegel · 1982
Earlier work this paper cites.
Learning disjunction of conjunctions
Leslie G Valiant · 1985
Earlier work this paper cites.
The" automatic" robustness of minimum distance functionals
David L Donoho and Richard C Liu · 1988
Earlier work this paper cites.
Learning in the presence of malicious errors
Michael Kearns and Ming Li · 1993
Earlier work this paper cites.
General notions of statistical depth function
Yijun Zuo and Robert Serfling · 2000
Earlier work this paper cites.
Backdoor attacks against transfer learning with pre-trained deep learning models
Original
Shuo Wang, Surya Nepal, Carsten Rudolph, Marthie Grobler, Shangyu Chen, and Tianle Chen · 2001
Earlier work this paper cites.
Learning to detect malicious clients for robust federated learning
Original
Suyi Li, Yong Cheng, Wei Wang, Yang Liu, and Tianjian Chen · 2002
Earlier work this paper cites.
Face-off: Adversarial face obfuscation
Original
Chuhan Gao, Varun Chandrasekaran, Kassem Fawaz, and Somesh Jha · 2003
Earlier work this paper cites.
Inverting gradients–How easy is it to break privacy in federated learning?
Original
Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, and Michael Moeller · 2003
Earlier work this paper cites.
Stop-and-go: Exploring backdoor attacks on deep reinforcement learning-based traffic congestion control systems
Original
Yue Wang, Esha Sarkar, Michail Maniatakos, and Saif Eddin Jabari · 2003
Earlier work this paper cites.
Metapoison: Practical general-purpose clean-label data poisoning
Original
W Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor, and Tom Goldstein · 2004
Earlier work this paper cites.
Robust statistics , volume 523
Peter J Huber · 2004
Earlier work this paper cites.
Spambayes: Effective open-source, bayesian based, email classification system
Tony A Meyer and Brendon Whateley · 2004
Earlier work this paper cites.
Data poisoning attacks on federated machine learning
Original
Gan Sun, Yang Cong, Jiahua Dong, Qiang Wang, and Ji Liu · 2004
Earlier work this paper cites.
Bullseye polytope: A scalable clean-label poisoning attack with improved transferability
Original
Hojjat Aghakhani, Dongyu Meng, Yu-Xiang Wang, Christopher Kruegel, and Giovanni Vigna · 2005
Earlier work this paper cites.
Backdoor attacks on federated meta-learning
Original
Chien-Lun Chen, Leana Golubchik, and Marco Paolieri · 2006
Earlier work this paper cites.
BadNL: Backdoor attacks against nlp models
Original
Xiaoyi Chen, Ahmed Salem, Michael Backes, Shiqing Ma, and Yang Zhang · 2006
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith · 2006
Earlier work this paper cites.
Subpopulation data poisoning attacks
Original
Matthew Jagielski, Giorgio Severi, Niklas Pousette Harger, and Alina Oprea · 2006
Earlier work this paper cites.
Backdoor attacks to graph neural networks
Original
Zaixi Zhang, Jinyuan Jia, Binghui Wang, and Neil Zhenqiang Gong · 2006
Earlier work this paper cites.
Backdoor attacks and countermeasures on deep learning: a comprehensive review
Original
Yansong Gao, Bao Gia Doan, Zhi Zhang, Siqi Ma, Anmin Fu, Surya Nepal, and Hyoungshick Kim · 2007
Earlier work this paper cites.
Backdoor learning: A survey
Original
Yiming Li, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shu-Tao Xia · 2007
Earlier work this paper cites.
Backdoor attacks and defenses in feature-partitioned collaborative learning
Original
Yang Liu, Zhihao Yi, and Tianjian Chen · 2007
Earlier work this paper cites.
Intrinsic certified robustness of bagging against data poisoning attacks
Original
Jinyuan Jia, Xiaoyu Cao, and Neil Zhenqiang Gong · 2008
Earlier work this paper cites.
Removing backdoor-based watermarks in neural networks with limited data
Original
Xuankai Liu, Fengting Li, Bihan Wen, and Qi Li · 2008
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles A Sutton, J Doug Tygar, and Kai Xia · 2008
Earlier work this paper cites.
Extracting and composing robust features with denoising autoencoders
Pascal Vincent, Hugo Larochelle, Yoshua Bengio, and Pierre-Antoine Manzagol · 2008
Earlier work this paper cites.
Trojaning language models for fun and profit
Original
Xinyang Zhang, Zheng Zhang, and Ting Wang · 2008
Earlier work this paper cites.
Witches’ brew: Industrial scale data poisoning via gradient matching
Original
Jonas Geiping, Liam Fowl, W Ronny Huang, Wojciech Czaja, Gavin Taylor, Michael Moeller, and Tom Goldstein · 2009
Earlier work this paper cites.
Learning halfspaces with malicious noise
Adam R Klivans, Philip M Long, and Rocco A Servedio · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky · 2009
Earlier work this paper cites.
Poisoned classifiers are not only backdoored, they are fundamentally broken
Original
Mingjie Sun, Siddhant Agarwal, and J Zico Kolter · 2010
Earlier work this paper cites.
Support vector machines under adversarial label noise
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2011
Earlier work this paper cites.
Robust statistics: the approach based on influence functions , volume 196
Frank R Hampel, Elvezio M Ronchetti, Peter J Rousseeuw, and Werner A Stahel · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Original
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Certified robustness of nearest neighbors against data poisoning attacks
Original
Jinyuan Jia, Xiaoyu Cao, and Neil Zhenqiang Gong · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Auto-encoding variational bayes
Original
Diederik P Kingma and Max Welling · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Original
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
On the impossibility of cryptography with tamperable randomness
Per Austrin, Kai-Min Chung, Mohammad Mahmoody, Rafael Pass, and Karn Seth · 2014
Earlier work this paper cites.
Generative adversarial nets
Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart · 2015
Earlier work this paper cites.
Tiny imagenet visual recognition challenge
Ya Le and Xuan Yang · 2015
Earlier work this paper cites.
Using machine teaching to identify optimal training-set attacks on machine learners
Shike Mei and Xiaojin Zhu · 2015
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang · 2016
Earlier work this paper cites.
Agnostic estimation of mean and covariance
Kevin A Lai, Anup B Rao, and Santosh Vempala · 2016
Earlier work this paper cites.
Data poisoning attacks on factorization-based collaborative filtering, 2016
Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik · 2016
Earlier work this paper cites.
Microsoft chatbot is taught to swear on Twitter
Jane Wakefield · 2016
Earlier work this paper cites.
Machine learning with adversaries: Byzantine tolerant gradient descent
Peva Blanchard, Rachid Guerraoui, Julien Stainer, et al · 2017
Earlier work this paper cites.
Analysis of causative attacks against svms learning from data streams
Cody Burkard and Brent Lagesse · 2017
Earlier work this paper cites.
Learning from untrusted data
Moses Charikar, Jacob Steinhardt, and Gregory Valiant · 2017
Earlier work this paper cites.
Emnist: Extending mnist to handwritten letters
Gregory Cohen, Saeed Afshar, Jonathan Tapson, and Andre Van Schaik · 2017
Earlier work this paper cites.
Being robust (in high dimensions) can be practical
Ilias Diakonikolas, Gautam Kamath, Daniel M Kane, Jerry Li, Ankur Moitra, and Alistair Stewart · 2017
Earlier work this paper cites.