Fetching the paper…
Reading the bibliography…
Data poisoning and backdoor attacks manipulate training data to induce security breaches in a victim model.
Metapoison: Practical general-purpose clean-label data poisoning
Huang, W. R., Geiping, J., Fowl, L., Taylor, G., and Goldstein, T · 2004
Earlier work this paper cites.
How to break anonymity of the netflix prize dataset
Narayanan, A. and Shmatikov, V · 2006
Earlier work this paper cites.
The security of machine learning
Barreno, M., Nelson, B., Joseph, A. D., and Tygar, J. D · 2010
Earlier work this paper cites.
On the geometry of differential privacy
Hardt, M. and Talwar, K · 2010
Earlier work this paper cites.
Poisoning attacks against support vector machines
Biggio, B., Nelson, B., and Laskov, P · 2012
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Dwork, C., Roth, A., et al · 2014
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
Xiao, H., Biggio, B., Brown, G., Fumera, G., Eckert, C., and Roli, F · 2015
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Chen, X., Liu, C., Li, B., Lu, K., and Song, D · 2017
Earlier work this paper cites.
Improved regularization of convolutional neural networks with cutout
DeVries, T. and Taylor, G. W · 2017
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Gu, T., Dolan-Gavitt, B., and Garg, S · 2017
Earlier work this paper cites.
Towards poisoning of deep learning algorithms with back-gradient optimization
Muñoz-González, L., Biggio, B., Demontis, A., Paudice, A., Wongrassamee, V., Lupu, E. C., and Roli, F · 2017
Earlier work this paper cites.
mixup: Beyond empirical risk minimization
Zhang, H., Cisse, M., Dauphin, Y. N., and Lopez-Paz, D · 2017
Earlier work this paper cites.
Detecting backdoor attacks on deep neural networks by activation clustering
Chen, B., Carvalho, W., Baracaldo, N., Ludwig, H., Edwards, B., Lee, T., Molloy, I., and Srivastava, B · 2018
Cited alongside, same era.
Stronger data poisoning attacks break data sanitization defenses
Koh, P. W., Steinhardt, J., and Liang, P · 2018
Cited alongside, same era.
Label sanitization against label flipping poisoning attacks
Paudice, A., Muñoz-González, L., and Lupu, E. C · 2018
Cited alongside, same era.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
Cited alongside, same era.
Clean-label backdoor attacks
Turner, A., Tsipras, D., and Madry, A · 2018
Cited alongside, same era.
Bullseye Polytope: A Scalable Clean-Label Poisoning Attack with Improved Transferability
Aghakhani, H., Meng, D., Wang, Y.-X., Kruegel, C., and Vigna, G · 2020
Later among the works it cites.
Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff
Borgnia, E., Cherepanova, V., Fowl, L., Ghiasi, A., Geiping, J., Goldblum, M., Goldstein, T., and Gupta, A · 2020
Later among the works it cites.
An Attack on InstaHide: Is Private Learning Possible with Instance Encoding?
Carlini, N., Deng, S., Garg, S., Jha, S., Mahloujifar, S., Mahmoody, M., Song, S., Thakurta, A., and Tramer, F · 2020
Later among the works it cites.
Witches’ brew: Industrial scale data poisoning via gradient matching
Geiping, J., Fowl, L., Huang, W. R., Czaja, W., Taylor, G., Moeller, M., and Goldstein, T · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Synthesizing differentially private datasets using random mixing
Lee, K., Kim, H., Lee, K., Suh, C., and Ramchandran, K · 2019
Cited alongside, same era.
Data poisoning against differentially-private learners: Attacks and defenses
Ma, Y., Zhu, X., and Hsu, J · 2019
Cited alongside, same era.
Deep k-nn defense against clean-label data poisoning attacks, 2019
Peri, N., Gupta, N., Huang, W. R., Fowl, L., Zhu, C., Feizi, S., Goldstein, T., and Dickerson, J. P · 2019
Cited alongside, same era.
Subsampled rényi differential privacy and analytical moments accountant
Wang, Y.-X., Balle, B., and Kasiviswanathan, S. P · 2019
Cited alongside, same era.
Cutmix: Regularization strategy to train strong classifiers with localizable features
Yun, S., Han, D., Oh, S. J., Chun, S., Choe, J., and Yoo, Y · 2019
Cited alongside, same era.
Transferable clean-label poisoning attacks on deep neural nets
Zhu, C., Huang, W. R., Li, H., Taylor, G., Studer, C., and Goldstein, T · 2019
Cited alongside, same era.
InstaHide: Instance-hiding Schemes for Private Distributed Learning
Huang, Y., Song, Z., Li, K., and Arora, S
Cited in the paper.
Goldblum, M., Tsipras, D., Xie, C., Chen, X., Schwarzschild, A., Song, D., Madry, A., Li, B., and Goldstein, T · 2020
Later among the works it cites.
Maxup: A simple way to improve generalization of neural network training
Gong, C., Ren, T., Ye, M., and Liu, Q · 2020
Later among the works it cites.
Deep partition aggregation: Provable defense against general poisoning attacks
Levine, A. and Feizi, S · 2020
Later among the works it cites.
Hidden trigger backdoor attacks
Saha, A., Subramanya, A., and Pirsiavash, H · 2020
Later among the works it cites.
Just how toxic is data poisoning? a unified benchmark for backdoor and data poisoning attacks
Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J. P., and Goldstein, T · 2020
Later among the works it cites.
Rab: Provable robustness against backdoor attacks
Weber, M., Xu, X., Karlas, B., Zhang, C., and Li, B · 2020
Later among the works it cites.
How does mixup help with robustness and generalization?
Zhang, L., Deng, Z., Kawaguchi, K., Ghorbani, A., and Zou, J · 2020
Later among the works it cites.