Fetching the paper…
Reading the bibliography…
Data poisoning is a threat model in which a malicious actor tampers with training data to manipulate outcomes at inference time.
On Evaluating Adversarial Robustness
Carlini, N., Athalye, A., Papernot, N., Brendel, W., Rauber, J., Tsipras, D., Goodfellow, I., Madry, A., and Kurakin, A · 1902
Earlier work this paper cites.
Detecting AI Trojans Using Meta Neural Analysis
Xu, X., Wang, Q., Li, H., Borisov, N., Gunter, C. A., and Li, B · 1910
Earlier work this paper cites.
REFIT: A Unified Watermark Removal Framework for Deep Learning Systems with Limited Data
Chen, X., Wang, W., Bender, C., Ding, Y., Jia, R., Li, B., and Song, D · 1911
Earlier work this paper cites.
MaxUp: A Simple Way to Improve Generalization of Neural Network Training
Gong, C., Ren, T., Ye, M., and Liu, Q · 2002
Earlier work this paper cites.
On the Effectiveness of Mitigating Data Poisoning Attacks with Gradient Shaping
Hong, S., Chandrasekaran, V., Kaya, Y., Dumitraş, T., and Papernot, N · 2002
Earlier work this paper cites.
On Adaptive Attacks to Adversarial Example Defenses
Tramer, F., Carlini, N., Brendel, W., and Madry, A · 2002
Earlier work this paper cites.
RAB: Provable Robustness Against Backdoor Attacks
Weber, M., Xu, X., Karlas, B., Zhang, C., and Li, B · 2003
Earlier work this paper cites.
Bullseye Polytope: A Scalable Clean-Label Poisoning Attack with Improved Transferability
Aghakhani, H., Meng, D., Wang, Y.-X., Kruegel, C., and Vigna, G · 2005
Earlier work this paper cites.
Language Models are Few-Shot Learners
Brown, T. B., Mann, B., Ryder, N., Subbiah, M., Kaplan, J., Dhariwal, P., Neelakantan, A., Shyam, P., Sastry, G., Askell, A., Agarwal, S., Herbert-Voss, A., Krueger, G., Henighan, T., Child, R., Ramesh, A., Ziegler, D. M., Wu, J., Winter, C., Hesse, C., Chen, M., Sigler, E., Litwin, M., Gray, S., Chess, B., Clark, J., Berner, C., McCandlish, S., Radford, A., Sutskever, I., and Amodei, D · 2005
Earlier work this paper cites.
Adversarial Training against Location-Optimized Adversarial Patches
Rao, S., Stutz, D., and Schiele, B · 2005
Earlier work this paper cites.
Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks
Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J. P., and Goldstein, T · 2006
Earlier work this paper cites.
Li, Y., Wu, B., Jiang, Y., Li, Z., and Xia, S.-T · 2007
Earlier work this paper cites.
Learning Multiple Layers of Features from Tiny Images
Krizhevsky, A · 2009
Earlier work this paper cites.
The security of machine learning
Barreno, M., Nelson, B., Joseph, A. D., and Tygar, J. D · 2010
Earlier work this paper cites.
On Evaluating Neural Network Backdoor Defenses
Veldanda, A. and Garg, S · 2010
Earlier work this paper cites.
Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy Tradeoff
Borgnia, E., Cherepanova, V., Fowl, L., Ghiasi, A., Geiping, J., Goldblum, M., Goldstein, T., and Gupta, A · 2011
Earlier work this paper cites.
Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses
Goldblum, M., Tsipras, D., Xie, C., Chen, X., Schwarzschild, A., Song, D., Madry, A., Li, B., and Goldstein, T · 2012
Earlier work this paper cites.
Deep Residual Learning for Image Recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2015
Cited alongside, same era.
Spatial Transformer Networks
Jaderberg, M., Simonyan, K., Zisserman, A., and kavukcuoglu, k · 2015
Cited alongside, same era.
ImageNet Large Scale Visual Recognition Challenge
Russakovsky, O., Deng, J., Su, H., Krause, J., Satheesh, S., Ma, S., Huang, Z., Karpathy, A., Khosla, A., Bernstein, M., Berg, A. C., and Fei-Fei, L · 2015
Cited alongside, same era.
Deep Learning with Differential Privacy
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Cited alongside, same era.
Improved Regularization of Convolutional Neural Networks with Cutout
DeVries, T. and Taylor, G. W · 2017
Cited alongside, same era.
BadNets: Evaluating Backdooring Attacks on Deep Neural Networks
Gu, T., Liu, K., Dolan-Gavitt, B., and Garg, S · 2019
Later among the works it cites.
Evaluating Differentially Private Machine Learning in Practice
Jayaraman, B. and Evans, D · 2019
Later among the works it cites.
Data Poisoning against Differentially-Private Learners: Attacks and Defenses
Ma, Y., Zhu, X., and Hsu, J · 2019
Later among the works it cites.
Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks
Wang, B., Yao, Y., Shan, S., Li, H., Viswanath, B., Zheng, H., and Zhao, B. Y · 2019
Later among the works it cites.
CutMix: Regularization Strategy to Train Strong Classifiers With Localizable Features
Yun, S., Han, D., Oh, S. J., Chun, S., Choe, J., and Yoo, Y · 2019
Later among the works it cites.
Transferable Clean-Label Poisoning Attacks on Deep Neural Nets
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2017
Cited alongside, same era.
Automatic differentiation in PyTorch
Paszke, A., Gross, S., Chintala, S., Chanan, G., Yang, E., DeVito, Z., Lin, Z., Desmaison, A., Antiga, L., and Lerer, A · 2017
Cited alongside, same era.
Stronger Data Poisoning Attacks Break Data Sanitization Defenses
Koh, P. W., Steinhardt, J., and Liang, P · 2018
Cited alongside, same era.
Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks
Liu, K., Dolan-Gavitt, B., and Garg, S · 2018
Cited alongside, same era.
Towards Deep Learning Models Resistant to Adversarial Attacks
Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A · 2018
Cited alongside, same era.
Detection of Adversarial Training Examples in Poisoning Attacks through Anomaly Detection
Paudice, A., Muñoz-González, L., Gyorgy, A., and Lupu, E. C · 2018
Cited alongside, same era.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
Cited alongside, same era.
Zhu, C., Huang, W. R., Li, H., Taylor, G., Studer, C., and Goldstein, T · 2019
Later among the works it cites.
MetaPoison: Practical General-purpose Clean-label Data Poisoning
Huang, W. R., Geiping, J., Fowl, L., Taylor, G., and Goldstein, T · 2020
Later among the works it cites.
Adversarial Machine Learning-Industry Perspectives
Kumar, R. S. S., Nyström, M., Lambert, J., Marshall, A., Goertzel, M., Comissoneru, A., Swann, M., and Xia, S · 2020
Later among the works it cites.
Deep k-NN Defense Against Clean-Label Data Poisoning Attacks
Peri, N., Gupta, N., Huang, W. R., Fowl, L., Zhu, C., Feizi, S., Goldstein, T., and Dickerson, J. P · 2020
Later among the works it cites.
Hidden Trigger Backdoor Attacks
Saha, A., Subramanya, A., and Pirsiavash, H · 2020
Later among the works it cites.
Bypassing Backdoor Detection Algorithms in Deep Learning
Tan, T. J. L. and Shokri, R · 2020
Later among the works it cites.
Borgnia, E., Geiping, J., Cherepanova, V., Fowl, L., Gupta, A., Ghiasi, A., Huang, F., Goldblum, M., and Goldstein, T · 2021
Closest in time.
Witches’ Brew: Industrial Scale Data Poisoning via Gradient Matching
Geiping, J., Fowl, L. H., Huang, W. R., Czaja, W., Taylor, G., Moeller, M., and Goldstein, T · 2021
Closest in time.
Deep Partition Aggregation: Provable Defenses against General Poisoning Attacks
Levine, A. and Feizi, S · 2021
Closest in time.
Data Poisoning Won’t Save You From Facial Recognition
Radiya-Dixit, E. and Tramer, F · 2021
Closest in time.
Better Safe Than Sorry: Preventing Delusive Adversaries with Adversarial Training
Tao, L., Feng, L., Yi, J., Huang, S.-J., and Chen, S · 2021
Closest in time.