Fetching the paper…
Reading the bibliography…
Delusive attacks aim to substantially deteriorate the test accuracy of the learning model by slightly perturbing the features of correctly labeled training examples.
Machine learning for sequential data: A review
Thomas G Dietterich · 2002
Earlier work this paper cites.
Can machine learning be secure?
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D Joseph, and J Doug Tygar · 2006
Earlier work this paper cites.
Nightmare at test time: robust learning by feature deletion
Amir Globerson and Sam Roweis · 2006
Earlier work this paper cites.
Paragraph: Thwarting signature learning by training maliciously
James Newsome, Brad Karp, and Dawn Song · 2006
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles Sutton, JD Tygar, and Kai Xia · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky et al · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D Joseph, and J Doug Tygar · 2010
Earlier work this paper cites.
Support vector machines under adversarial label noise
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2011
Earlier work this paper cites.
Wrangler: Interactive visual specification of data transformation scripts
Sean Kandel, Andreas Paepcke, Joseph Hellerstein, and Jeffrey Heer · 2011
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y Ng · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Using machine teaching to identify optimal training-set attacks on machine learners
Shike Mei and Xiaojin Zhu · 2015
Earlier work this paper cites.
Imagenet large scale visual recognition challenge
Olga Russakovsky, Jia Deng, Hao Su, Jonathan Krause, Sanjeev Satheesh, Sean Ma, Zhiheng Huang, Andrej Karpathy, Aditya Khosla, Michael Bernstein, et al · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Earlier work this paper cites.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger · 2017
Earlier work this paper cites.
Understanding black-box predictions via influence functions
Pang Wei Koh and Percy Liang · 2017
Earlier work this paper cites.
Universal adversarial perturbations
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2017
Earlier work this paper cites.
Towards poisoning of deep learning algorithms with back-gradient optimization
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli · 2017
Earlier work this paper cites.
Distributionally robust deep learning as a generalization of adversarial training
Matthew Staib and Stefanie Jegelka · 2017
Earlier work this paper cites.
Certified defenses for data poisoning attacks
Jacob Steinhardt, Pang Wei Koh, and Percy Liang · 2017
Earlier work this paper cites.
Efficient label contamination attacks against black-box learning models
Mengchen Zhao, Bo An, Wei Gao, and Teng Zhang · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Earlier work this paper cites.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli · 2018
Earlier work this paper cites.
Curriculum adversarial training
Qi-Zhi Cai, Chang Liu, and Dawn Song · 2018
Earlier work this paper cites.
Detecting backdoor attacks on deep neural networks by activation clustering
Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava · 2018
Earlier work this paper cites.
Unsupervised representation learning by predicting image rotations
Spyros Gidaris, Praveer Singh, and Nikos Komodakis · 2018
Earlier work this paper cites.
With friends like these, who needs adversaries?
Saumya Jetley, Nicholas Lord, and Philip Torr · 2018
Earlier work this paper cites.
Stronger data poisoning attacks break data sanitization defenses
Pang Wei Koh, Jacob Steinhardt, and Percy Liang · 2018
Earlier work this paper cites.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Adversarially robust generalization requires more data
Ludwig Schmidt, Shibani Santurkar, Dimitris Tsipras, Kunal Talwar, and Aleksander Madry · 2018
Earlier work this paper cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein · 2018
Earlier work this paper cites.
Certifiable distributional robustness with principled adversarial training
Aman Sinha, Hongseok Namkoong, and John Duchi · 2018
Earlier work this paper cites.
Is robustness the cost of accuracy?–a comprehensive study on the robustness of 18 deep image classification models
Dong Su, Huan Zhang, Hongge Chen, Jinfeng Yi, Pin-Yu Chen, and Yupeng Gao · 2018
Earlier work this paper cites.
Spectral signatures in backdoor attacks
Brandon Tran, Jerry Li, and Aleksander Madry · 2018
Earlier work this paper cites.
Provable defenses against adversarial examples via the convex outer adversarial polytope
Eric Wong and Zico Kolter · 2018
Earlier work this paper cites.
Sever: A robust meta-algorithm for stochastic optimization
Ilias Diakonikolas, Gautam Kamath, Daniel Kane, Jerry Li, Jacob Steinhardt, and Alistair Stewart · 2019
Earlier work this paper cites.
Learning to confuse: generating training time adversarial data with auto-encoder
Ji Feng, Qi-Zhi Cai, and Zhi-Hua Zhou · 2019
Cited alongside, same era.
Strip: A defence against trojan attacks on deep neural networks
Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith C Ranasinghe, and Surya Nepal · 2019
Cited alongside, same era.
Badnets: Evaluating backdooring attacks on deep neural networks
Tianyu Gu, Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2019
Cited alongside, same era.
Adversarial examples are not bugs, they are features
Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Cited alongside, same era.
A unified framework for data poisoning attack to graph-based semi-supervised learning
Xuanqing Liu, Si Si, Xiaojin Zhu, Yang Li, and Cho-Jui Hsieh · 2019
Cited alongside, same era.
Data poisoning against differentially-private learners: Attacks and defenses
Adversarial weight perturbation helps robust generalization
Dongxian Wu, Shu-Tao Xia, and Yisen Wang · 2020
Later among the works it cites.
Adversarial examples improve image recognition
Cihang Xie, Mingxing Tan, Boqing Gong, Jiang Wang, Alan L Yuille, and Quoc V Le · 2020
Later among the works it cites.
To be robust or to be fair: Towards fairness in adversarial training
Han Xu, Xiaorui Liu, Yaxin Li, and Jiliang Tang · 2020
Later among the works it cites.
A closer look at accuracy vs. robustness
Yao-Yuan Yang, Cyrus Rashtchian, Hongyang Zhang, Russ R Salakhutdinov, and Kamalika Chaudhuri · 2020
Later among the works it cites.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Yuzhe Ma, Xiaojin Zhu Zhu, and Justin Hsu · 2019
Cited alongside, same era.
A discussion of ’adversarial examples are not bugs, they are features’: Adversarial examples are just bugs, too
Preetum Nakkiran · 2019
Cited alongside, same era.
Image synthesis with a single (robust) classifier
Shibani Santurkar, Andrew Ilyas, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry · 2019
Cited alongside, same era.
Tensorclog: An imperceptible poisoning attack on deep neural network applications
Juncheng Shen, Xiaolei Zhu, and De Ma · 2019
Cited alongside, same era.
Robustness may be at odds with accuracy
Dimitris Tsipras, Shibani Santurkar, Logan Engstrom, Alexander Turner, and Aleksander Madry · 2019
Cited alongside, same era.
Label-consistent backdoor attacks
Alexander Turner, Dimitris Tsipras, and Aleksander Madry · 2019
Cited alongside, same era.
On the convergence and robustness of adversarial training
Yisen Wang, Xingjun Ma, James Bailey, Jinfeng Yi, Bowen Zhou, and Quanquan Gu · 2019
Cited alongside, same era.
Sicheng Zhu, Xiao Zhang, and David Evans · 2020
Later among the works it cites.
Clustering effect of adversarial robust models
Yang Bai, Xin Yan, Yong Jiang, Shu-Tao Xia, and Yisen Wang · 2021
Closest in time.
Robust learning under clean-label attack
Avrim Blum, Steve Hanneke, Jian Qian, and Han Shao · 2021
Closest in time.
Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff
Eitan Borgnia, Valeriia Cherepanova, Liam Fowl, Amin Ghiasi, Jonas Geiping, Micah Goldblum, Tom Goldstein, and Arjun Gupta · 2021
Closest in time.
Poisoning the unlabeled dataset of semi-supervised learning
Nicholas Carlini · 2021
Closest in time.
Poisoning and backdooring contrastive learning
Nicholas Carlini and Andreas Terzis · 2021
Closest in time.
Refit: A unified watermark removal framework for deep learning systems with limited data
Xinyun Chen, Wenxiao Wang, Chris Bender, Yiming Ding, Ruoxi Jia, Bo Li, and Dawn Song · 2021
Closest in time.
Lowkey: Leveraging adversarial attacks to protect social media users from facial recognition
Valeriia Cherepanova, Micah Goldblum, Harrison Foley, Shiyuan Duan, John P Dickerson, Gavin Taylor, and Tom Goldstein · 2021
Closest in time.
Robustbench: a standardized adversarial robustness benchmark
Francesco Croce, Maksym Andriushchenko, Vikash Sehwag, Edoardo Debenedetti, Nicolas Flammarion, Mung Chiang, Prateek Mittal, and Matthias Hein · 2021
Closest in time.
Adversarial training helps transfer learning via better representations
Zhun Deng, Linjun Zhang, Kailas Vodrahalli, Kenji Kawaguchi, and James Zou · 2021
Closest in time.
Learning diverse-structured networks for adversarial robustness
Xuefeng Du, Jingfeng Zhang, Bo Han, Tongliang Liu, Yu Rong, Gang Niu, Junzhou Huang, and Masashi Sugiyama · 2021
Closest in time.
Disrupting model training with adversarial shortcuts
Ivan Evtimov, Ian Covert, Aditya Kusupati, and Tadayoshi Kohno · 2021
Closest in time.
What doesn’t kill you makes you robust (er): Adversarial training against poisons and backdoors
Jonas Geiping, Liam Fowl, Gowthami Somepalli, Micah Goldblum, Michael Moeller, and Tom Goldstein · 2021
Closest in time.
Improving robustness using generated data
Sven Gowal, Sylvestre-Alvise Rebuffi, Olivia Wiles, Florian Stimberg, Dan Andrei Calian, and Timothy Mann · 2021
Closest in time.
Spectre: defending against backdoor attacks using robust statistics
Jonathan Hayase, Weihao Kong, Raghav Somani, and Sewoong Oh · 2021
Closest in time.
On the effectiveness of adversarial training against common corruptions
Klim Kireev, Maksym Andriushchenko, and Nicolas Flammarion · 2021
Closest in time.
Adversarial training is not ready for robot learning
Mathias Lechner, Ramin Hasani, Radu Grosu, Daniela Rus, and Thomas A Henzinger · 2021
Closest in time.
Deep partition aggregation: Provable defenses against general poisoning attacks
Alexander Levine and Soheil Feizi · 2021
Closest in time.
Uncovering the connections between adversarial transferability and knowledge transferability
Kaizhao Liang, Jacky Y Zhang, Boxin Wang, Zhuolin Yang, Sanmi Koyejo, and Bo Li · 2021
Closest in time.
Understanding the limits of unsupervised domain adaptation via data poisoning
Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, and Jihun Hamm · 2021
Closest in time.
Wanet - imperceptible warping-based backdoor attack
Tuan Anh Nguyen and Anh Tuan Tran · 2021
Closest in time.
An empirical study on the relation between network interpretability and adversarial robustness
Adam Noack, Isaac Ahern, Dejing Dou, and Boyang Li · 2021
Closest in time.
Data poisoning won’t save you from facial recognition
Evani Radiya-Dixit and Florian Tramer · 2021
Closest in time.
Backdoor attacks on self-supervised learning
Aniruddha Saha, Ajinkya Tejankar, Soroush Abbasi Koohpayegani, and Hamed Pirsiavash · 2021
Closest in time.
Arae: Adversarially robust training of autoencoders improves novelty detection
Mohammadreza Salehi, Atrin Arya, Barbod Pajoum, Mohammad Otoofi, Amirreza Shaeiri, Mohammad Hossein Rohban, and Hamid R Rabiee · 2021
Closest in time.
Unadversarial examples: Designing objects for robust vision
Hadi Salman, Andrew Ilyas, Logan Engstrom, Sai Vemprala, Aleksander Madry, and Ashish Kapoor · 2021
Closest in time.
Just how toxic is data poisoning? a unified benchmark for backdoor and data poisoning attacks
Avi Schwarzschild, Micah Goldblum, Arjun Gupta, John P Dickerson, and Tom Goldstein · 2021
Closest in time.
Consistency regularization for adversarial robustness
Jihoon Tack, Sihyun Yu, Jongheon Jeong, Minseon Kim, Sung Ju Hwang, and Jinwoo Shin · 2021
Closest in time.
Adversarial training reduces information and improves transferability
Matteo Terzi, Alessandro Achille, Marco Maggipinto, and Gian Antonio Susto · 2021
Closest in time.
Analysis and applications of class-wise robustness in adversarial training
Qi Tian, Kun Kuang, Kelu Jiang, Fei Wu, and Yisen Wang · 2021
Closest in time.
Adversarially-trained deep nets transfer better: Illustration on image classification
Francisco Utrera, Evan Kravitz, N. Benjamin Erichson, Rajiv Khanna, and Michael W. Mahoney · 2021
Closest in time.
Adversarial neuron pruning purifies backdoored deep models
Dongxian Wu and Yisen Wang · 2021
Closest in time.
Improved ood generalization via adversarial training and pretraing
Mingyang Yi, Lu Hou, Jiacheng Sun, Lifeng Shang, Xin Jiang, Qun Liu, and Zhiming Ma · 2021
Closest in time.
Neural tangent generalization attacks
Chia-Hung Yuan and Shan-Hung Wu · 2021
Closest in time.
What do deep nets learn? class-wise patterns revealed in the input space
Shihao Zhao, Xingjun Ma, Yisen Wang, James Bailey, Bo Li, and Yu-Gang Jiang · 2021
Closest in time.
Understanding the interaction of adversarial training with noisy labels
Jianing Zhu, Jingfeng Zhang, Bo Han, Tongliang Liu, Gang Niu, Hongxia Yang, Mohan Kankanhalli, and Masashi Sugiyama · 2021
Closest in time.
Adversarially robust models may not transfer better: Sufficient conditions for domain transferability from the view of regularization
Anonymous · 2022
Closest in time.
With false friends like these, who can notice mistakes?
Lue Tao, Lei Feng, Jinfeng Yi, and Songcan Chen · 2022
Closest in time.