Fetching the paper…
Reading the bibliography…
The increased adoption of Artificial Intelligence (AI) presents an opportunity to solve many socio-economic and environmental challenges; however, this cannot happen without securing AI-enabled technologies.
Towards Federated Learning at Scale: System Design. In SysML 2019
K. A. Bonawitz, Hubert Eichner, Wolfgang Grieskamp, Dzmitry Huba, Alex Ingerman, Vladimir Ivanov, Chloé M Kiddon, Jakub Konečný, Stefano Mazzocchi, Brendan McMahan, Timon Van Overveldt, David Petrou, Daniel Ramage, and Jason Roselander. 2019 · 1902
Earlier work this paper cites.
Systematic Poisoning Attacks on and Defenses for Machine Learning in Healthcare
M Mozaffari-Kermani, S Sur-Kolay, A Raghunathan, and NK Jha. 2015 · 1905
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
Nitish Srivastava, Geoffrey Hinton, Alex Krizhevsky, Ilya Sutskever, and Ruslan Salakhutdinov. 2014 · 1958
Earlier work this paper cites.
Bagging predictors
Leo Breiman. 1996 · 1996
Earlier work this paper cites.
Ensemble methods in machine learning. In International workshop on multiple classifier systems . Springer, 1–15
Thomas G Dietterich. 2000 · 2000
Earlier work this paper cites.
Can machine learning be secure?. In Proceedings of the 2006 ACM Symposium on Information, computer and communications security . 16–25
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D Joseph, and J Doug Tygar. 2006 · 2006
Earlier work this paper cites.
Casting out demons: Sanitizing training data for anomaly sensors. In 2008 IEEE Symposium on Security and Privacy (sp 2008) . IEEE, 81–95
Gabriela F Cretu, Angelos Stavrou, Michael E Locasto, Salvatore J Stolfo, and Angelos D Keromytis. 2008 · 2008
Earlier work this paper cites.
Exploiting Machine Learning to Subvert Your Spam Filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles A Sutton, J Doug Tygar, and Kai Xia. 2008 · 2008
Earlier work this paper cites.
Misleading learners: Co-opting your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles Sutton, JD Tygar, and Kai Xia. 2009 · 2009
Earlier work this paper cites.
Introduction to semi-supervised learning
Xiaojin Zhu and Andrew B Goldberg. 2009 · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D Joseph, and J Doug Tygar. 2010 · 2010
Earlier work this paper cites.
Multiple classifier systems for robust classifier design in adversarial environments
Battista Biggio, Giorgio Fumera, and Fabio Roli. 2010 · 2010
Earlier work this paper cites.
Bagging classifiers for fighting poisoning attacks in adversarial classification tasks. In International workshop on multiple classifier systems . Springer, 350–359
Battista Biggio, Igino Corona, Giorgio Fumera, Giorgio Giacinto, and Fabio Roli. 2011 · 2011
Earlier work this paper cites.
Adversarial machine learning. In Proceedings of the 4th ACM workshop on Security and artificial intelligence . 43–58
Ling Huang, Anthony D Joseph, Blaine Nelson, Benjamin IP Rubinstein, and J Doug Tygar. 2011 · 2011
Earlier work this paper cites.
Three classes of deep learning architectures and their applications: a tutorial survey
Li Deng. 2012 · 2012
Earlier work this paper cites.
Machine learning: the art and science of algorithms that make sense of data
Peter Flach. 2012 · 2012
Earlier work this paper cites.
A kernel two-sample test
Arthur Gretton, Karsten M Borgwardt, Malte J Rasch, Bernhard Schölkopf, and Alexander Smola. 2012 · 2012
Earlier work this paper cites.
Security analysis of online centroid anomaly detection
Marius Kloft and Pavel Laskov. 2012 · 2012
Earlier work this paper cites.
Poisoning attacks to compromise face templates. In 2013 International Conference on Biometrics (ICB) . IEEE, 1–7
Battista Biggio, Luca Didaci, Giorgio Fumera, and Fabio Roli. 2013b · 2013
Earlier work this paper cites.
Do deep nets really need to be deep?. In Advances in neural information processing systems . 2654–2662
Jimmy Ba and Rich Caruana. 2014 · 2014
Earlier work this paper cites.
Security Evaluation of Pattern Classifiers under Attack
Battista Biggio, Giorgio Fumera, and Fabio Roli. 2014b · 2014
Earlier work this paper cites.
A tutorial survey of architectures, algorithms, and applications for deep learning
Li Deng. 2014 · 2014
Earlier work this paper cites.
Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing. In 23rd { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 14) . 17–32
Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart. 2014 · 2014
Earlier work this paper cites.
Towards deep neural network architectures robust to adversarial examples
Shixiang Gu and Luca Rigazio. 2014 · 2014
Earlier work this paper cites.
Practical evasion of a learning-based classifier: A case study. In 2014 IEEE symposium on security and privacy . IEEE, 197–211
Pavel Laskov et al · 2014
Earlier work this paper cites.
On the practicality of integrity attacks on document-level sentiment analysis. In Proceedings of the 2014 Workshop on Artificial Intelligent and Security Workshop . 83–93
Andrew Newell, Rahul Potharaju, Luojie Xiang, and Cristina Nita-Rotaru. 2014 · 2014
Earlier work this paper cites.
Intriguing properties of neural networks. In International Conference on Learning Representations
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014 · 2014
Earlier work this paper cites.
Crypto-nets: Neural networks over encrypted data
Pengtao Xie, Misha Bilenko, Tom Finley, Ran Gilad-Bachrach, Kristin Lauter, and Michael Naehrig. 2014 · 2014
Earlier work this paper cites.
A review of homomorphic encryption and software tools for encrypted statistical machine learning
Louis JM Aslett, Pedro M Esperança, and Chris C Holmes. 2015 · 2015
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security . 1322–1333
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015 · 2015
Earlier work this paper cites.
EXPLAINING AND HARNESSING ADVERSARIAL EXAMPLES
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015 · 2015
Earlier work this paper cites.
Distilling the knowledge in a neural network
Geoffrey Hinton, Oriol Vinyals, and Jeff Dean. 2015 · 2015
Earlier work this paper cites.
Deep neural networks are easily fooled: High confidence predictions for unrecognizable images. In Proceedings of the IEEE conference on computer vision and pattern recognition . 427–436
Anh Nguyen, Jason Yosinski, and Jeff Clune. 2015 · 2015
Earlier work this paper cites.
Adversarial Perturbations Against Deep Neural Networks for Malware Classification
Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes, and Patrick McDaniel. 2016 · 2016
Earlier work this paper cites.
Federated optimization: Distributed machine learning for on-device intelligence
Jakub Konečnỳ, H Brendan McMahan, Daniel Ramage, and Peter Richtárik. 2016a · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016a · 2016
Earlier work this paper cites.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016b · 2016
Earlier work this paper cites.
Data poisoning attacks on factorization-based collaborative filtering. In Advances in neural information processing systems . 1885–1893
Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik. 2016 · 2016
Earlier work this paper cites.
Machine Learning
P. Louridas and C. Ebert. 2016 · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks. In Proceedings of the IEEE conference on computer vision and pattern recognition . 2574–2582
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard. 2016 · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016a · 2016
Earlier work this paper cites.
Practical black-box attacks against deep learning systems using adversarial examples
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami. 2016b · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings. In 2016 IEEE European symposium on security and privacy (EuroS&P) . IEEE, 372–387
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami. 2016c · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE Symposium on Security and Privacy (SP) . IEEE, 582–597
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2016d · 2016
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 2016 acm sigsac conference on computer and communications security . 1528–1540
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter. 2016 · 2016
Cited alongside, same era.
Stealing machine learning models via prediction apis. In 25th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 16) . 601–618
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016 · 2016
Cited alongside, same era.
Mahdieh Abbasi and Christian Gagné. 2017 · 2017
Cited alongside, same era.
Understanding How Adversarial Noise Affects Single Image Classification. In International Conference on Intelligent Information Technologies . Springer, 287–295
Amit Adate, Rishabh Saxena, et al · 2017
Cited alongside, same era.
Decision boundary analysis of adversarial examples. In 6th International Conference on Learning Representations, ICLR 2018
Warren He, Bo Li, and Dawn Song. 2018 · 2018
Later among the works it cites.
On the correlation between local intrinsic dimensionality and outlierness. In International Conference on Similarity Search and Applications . Springer, 177–191
Michael E Houle, Erich Schubert, and Arthur Zimek. 2018 · 2018
Later among the works it cites.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018 · 2018
Later among the works it cites.
Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In 2018 IEEE Symposium on Security and Privacy (SP) . IEEE, 19–35
Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li. 2018 · 2018
Later among the works it cites.
Stronger data poisoning attacks break data sanitization defenses
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Shumeet Baluja and Ian Fischer. 2017 · 2017
Cited alongside, same era.
Analysis of causative attacks against SVMs learning from data streams. In Proceedings of the 3rd ACM on International Workshop on Security And Privacy Analytics . 31–36
Cody Burkard and Brent Lagesse. 2017 · 2017
Cited alongside, same era.
Mitigating evasion attacks to deep neural networks via region-based classification. In Proceedings of the 33rd Annual Computer Security Applications Conference . 278–287
Xiaoyu Cao and Neil Zhenqiang Gong. 2017 · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp) . IEEE, 39–57
Nicholas Carlini and David Wagner. 2017b · 2017
Cited alongside, same era.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security . 15–26
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. 2017 · 2017
Cited alongside, same era.
Houdini: Fooling deep structured visual and speech recognition models with adversarial examples. In Advances in neural information processing systems . 6977–6987
Moustapha M Cisse, Yossi Adi, Natalia Neverova, and Joseph Keshet. 2017 · 2017
Cited alongside, same era.
Evading classifiers by morphing in the dark. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security . 119–133
Hung Dang, Yue Huang, and Ee-Chien Chang. 2017 · 2017
Cited alongside, same era.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner. 2017 · 2017
Cited alongside, same era.
Pang Wei Koh, Jacob Steinhardt, and Percy Liang. 2018 · 2018
Later among the works it cites.
On the connection between differential privacy and adversarial robustness in machine learning
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana. 2018 · 2018
Later among the works it cites.
Security matters: A survey on adversarial machine learning
Guofu Li, Pengjia Zhu, Jin Li, Zhemin Yang, Ning Cao, and Zhiyi Chen. 2018 · 2018
Later among the works it cites.
A survey on security threats and defensive techniques of machine learning: A data driven view
Qiang Liu, Pan Li, Wentao Zhao, Wei Cai, Shui Yu, and Victor CM Leung. 2018b · 2018
Later among the works it cites.
Characterizing Adversarial Subspaces Using Local Intrinsic Dimensionality. In International Conference on Learning Representations
Xingjun Ma, Bo Li, Yisen Wang, Sarah M Erfani, Sudanthi Wijewickrema, Grant Schoenebeck, Dawn Song, Michael E Houle, and James Bailey. 2018 · 2018
Later among the works it cites.
Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018 · 2018
Later among the works it cites.
Adversarial attacks and defenses against deep neural networks: a survey
Mesut Ozdag. 2018 · 2018
Later among the works it cites.
SoK: Security and privacy in machine learning. In 2018 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 399–414
Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P Wellman. 2018 · 2018
Later among the works it cites.
Query-efficient black-box attack by active learning. In 2018 IEEE International Conference on Data Mining (ICDM) . IEEE, 1200–1205
Li Pengcheng, Jinfeng Yi, and Lijun Zhang. 2018 · 2018
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks. In Advances in Neural Information Processing Systems . 6103–6113
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018 · 2018
Later among the works it cites.
When does machine learning { \{ FAIL } \} ? generalized transferability for evasion and poisoning attacks. In 27th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 18) . 1299–1316
Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daume III, and Tudor Dumitras. 2018 · 2018
Later among the works it cites.
Reinforcement learning: An introduction
Richard S Sutton and Andrew G Barto. 2018 · 2018
Later among the works it cites.
Attacks meet interpretability: Attribute-steered detection of adversarial samples. In Advances in Neural Information Processing Systems . 7717–7728
Guanhong Tao, Shiqing Ma, Yingqi Liu, and Xiangyu Zhang. 2018 · 2018
Later among the works it cites.
Adversarial machine learning: A literature review. In International Conference on Machine Learning and Data Mining in Pattern Recognition . Springer, 324–334
Sam Thomas and Nasseh Tabrizi. 2018 · 2018
Later among the works it cites.
Ensemble adversarial training: Attacks and defenses. In 6th International Conference on Learning Representations, ICLR 2018
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick Drew McDaniel. 2018 · 2018
Later among the works it cites.
Lightweight Privacy-preserving Training and Evaluation for Discretized Neural Networks
Jialu Chen, Jun Zhou, Zhenfu Cao, Athanasios V Vasilakos, Xiaolei Dong, and Kim-Kwang Raymond Choo. 2019 · 2019
Later among the works it cites.
Certified robustness to adversarial examples with differential privacy. In 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 656–672
Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana. 2019 · 2019
Later among the works it cites.
Biometric Backdoors: A Poisoning Attack Against Unsupervised Template Updating
Giulio Lovisotto, Simon Eberz, and Ivan Martinovic. 2019 · 2019
Later among the works it cites.
Challenges and Advances in Adversarial Machine Learning
Luis MUÑOZ-GONZÁLEZ, Javier CARNERERO-CANO, T Kenneth, and Emil C LUPU. 2019 · 2019
Later among the works it cites.
The Security of Machine Learning Systems
Luis Muñoz-González and Emil C. Lupu. 2019 · 2019
Later among the works it cites.
Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 739–753
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019 · 2019
Later among the works it cites.
A taxonomy and survey of attacks against machine learning
Nikolaos Pitropakis, Emmanouil Panaousis, Thanassis Giannetsos, Eleftherios Anastasiadis, and George Loukas. 2019 · 2019
Later among the works it cites.
Review of artificial intelligence adversarial attack and defense technologies
Shilin Qiu, Qihe Liu, Shijie Zhou, and Chunjiang Wu. 2019 · 2019
Later among the works it cites.
Adversarial training for free!. In Advances in Neural Information Processing Systems . 3353–3364
Ali Shafahi, Mahyar Najibi, Mohammad Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein. 2019 · 2019
Later among the works it cites.
One pixel attack for fooling deep neural networks
Jiawei Su, Danilo Vasconcellos Vargas, and Kouichi Sakurai. 2019 · 2019
Later among the works it cites.
A Taxonomy and Terminology of Adversarial Machine Learning
Elham Tabassi, Kevin J Burns, Michael Hadjimichael, Andres D Molina-Markham, and Julian T Sexton. 2019 · 2019
Later among the works it cites.
The security of machine learning in an adversarial setting: A survey
Xianmin Wang, Jing Li, Xiaohui Kuang, Yu-an Tan, and Jin Li. 2019 · 2019
Later among the works it cites.
Adversarial Examples in Modern Machine Learning: A Review
Rey Reza Wiyatno, Anqi Xu, Ousmane Dia, and Archy de Berker. 2019 · 2019
Later among the works it cites.
AdvIT: Adversarial Frames Identifier Based on Temporal Consistency in Videos. In Proceedings of the IEEE International Conference on Computer Vision . 3968–3977
Chaowei Xiao, Ruizhi Deng, Bo Li, Taesung Lee, Benjamin Edwards, Jinfeng Yi, Dawn Song, Mingyan Liu, and Ian Molloy. 2019 · 2019
Later among the works it cites.
Federated machine learning: Concept and applications
Qiang Yang, Yang Liu, Tianjian Chen, and Yongxin Tong. 2019 · 2019
Later among the works it cites.
Adversarial Attack, Defense, and Applications with Deep Learning Frameworks
Zhizhou Yin, Wei Liu, and Sanjay Chawla. 2019 · 2019
Later among the works it cites.
Adversarial examples: Attacks and defenses for deep learning
Xiaoyong Yuan, Pan He, Qile Zhu, and Xiaolin Li. 2019 · 2019
Later among the works it cites.
Adversarial examples: Opportunities and challenges
Jiliang Zhang and Chen Li. 2019 · 2019
Later among the works it cites.
Poisoning and evasion attacks against deep learning algorithms in autonomous vehicles
Wenbo Jiang, Hongwei Li, Sen Liu, Xizhao Luo, and Rongxing Lu. 2020 · 2020
Later among the works it cites.
Machine learning for enterprises: Applications, algorithm selection, and challenges
In Lee and Yong Jae Shin. 2020 · 2020
Later among the works it cites.
Adversarial Attacks and Defenses on Cyber-Physical Systems: A Survey
Jiao Li, Yang Liu, Tao Chen, Zhen Xiao, Zhenjiang Li, and Jianping Wang. 2020 · 2020
Later among the works it cites.
Adversarial Attacks and Defenses in Deep Learning
Kui Ren, Tianhang Zheng, Zhan Qin, and Xue Liu. 2020 · 2020
Later among the works it cites.
Behind DeepMind’s AlphaStar AI that Reached Grandmaster Level in StarCraft II
Sebastian Risi and Mike Preuss. 2020 · 2020
Later among the works it cites.
Adversarial Attacks on Deep-learning Models in Natural Language Processing: A Survey
Wei Emma Zhang, Quan Z Sheng, Ahoud Alhazmi, and Chenliang Li. 2020 · 2020
Later among the works it cites.