Fetching the paper…
Reading the bibliography…
When machine learning training is outsourced to third parties, $backdoor$ $attacks$ become practical as the third party who trains the model may act maliciously to inject hidden behaviors into the otherwise accurate model.
Detecting ai trojans using meta neural analysis, 2019
X. Xu, Q. Wang, H. Li, N. Borisov, C. A. Gunter, and B. Li · 1910
Earlier work this paper cites.
Optimal brain damage
Y. Lecun, J. Denker, S. Solla, R. Howard, and L. Jackel · 1990
Earlier work this paper cites.
Approximation capabilities of multilayer feedforward networks
K. Hornik · 1991
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky · 2009
Earlier work this paper cites.
Mnist handwritten digit database
Y. LeCun, C. Cortes, and C. Burges · 2010
Earlier work this paper cites.
Reading digits in natural images with unsupervised feature learning
Y. Netzer, T. Wang, A. Coates, A. Bissacco, B. Wu, and A. Y. Ng · 2011
Earlier work this paper cites.
Scaling up biologically-inspired computer vision: A case study in unconstrained face recognition on facebook
N. Pinto, Z. Stone, T. E. Zickler, and D. Cox · 2011
Earlier work this paper cites.
From extractable collision resistance to succinct non-interactive arguments of knowledge, and back again
N. Bitansky, R. Canetti, A. Chiesa, and E. Tromer · 2012
Earlier work this paper cites.
Deep learning with differential privacy
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
K. He, X. Zhang, S. Ren, and J. Sun · 2016
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning, 2017
X. Chen, C. Liu, B. Li, K. Lu, and D. Song · 2017
Earlier work this paper cites.
On the impossibility of virus detection
D. Evans · 2017
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
T. Gu, B. Dolan-Gavitt, and S. Garg · 2017
Earlier work this paper cites.
Reluplex: An efficient smt solver for verifying deep neural networks, 2017
G. Katz, C. Barrett, D. Dill, K. Julian, and M. Kochenderfer · 2017
Earlier work this paper cites.
Pruning filters for efficient convnets, 2017
H. Li, A. Kadav, I. Durdanovic, H. Samet, and H. P. Graf · 2017
Earlier work this paper cites.
Feature visualization
C. Olah, A. Mordvintsev, and L. Schubert · 2017
Earlier work this paper cites.
Certified defenses for data poisoning attacks
J. Steinhardt, P. W. W. Koh, and P. S. Liang · 2017
Earlier work this paper cites.
Inception-v4, inception-resnet and the impact of residual connections on learning
C. Szegedy, S. Ioffe, V. Vanhoucke, and A. A. Alemi · 2017
Earlier work this paper cites.
Detecting backdoor attacks on deep neural networks by activation clustering, 2018
B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, T. Lee, I. Molloy, and B. Srivastava · 2018
Earlier work this paper cites.
Trojaning attack on neural networks
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu · 2018
Cited alongside, same era.
On the importance of single directions for generalization
A. S. Morcos, D. G. Barrett, N. C. Rabinowitz, and M. Botvinick · 2018
Cited alongside, same era.
Slalom: Fast, verifiable and private execution of neural networks in trusted hardware
F. Tramer and D. Boneh · 2018
Cited alongside, same era.
Spectral signatures in backdoor attacks
B. Tran, J. Li, and A. Madry · 2018
Cited alongside, same era.
Training for faster adversarial robustness verification via inducing relu stability
K. Y. Xiao, V. Tjeng, N. M. Shafiullah, and A. Madry · 2018
Cited alongside, same era.
On the effectiveness of mitigating data poisoning attacks with gradient shaping, 2020
S. Hong, V. Chandrasekaran, Y. Kaya, T. Dumitraş, and N. Papernot · 2020
Later among the works it cites.
Zoom in: An introduction to circuits
C. Olah, N. Cammarata, L. Schubert, G. Goh, M. Petrov, and S. Carter · 2020
Later among the works it cites.
A tale of evil twins: Adversarial inputs versus poisoned models
R. Pang, H. Shen, X. Zhang, S. Ji, Y. Vorobeychik, X. Luo, A. Liu, and T. Wang · 2020
Later among the works it cites.
Deep k-nn defense against clean-label data poisoning attacks
N. Peri, N. Gupta, W. R. Huang, L. Fowl, C. Zhu, S. Feizi, T. Goldstein, and J. P. Dickerson · 2020
Later among the works it cites.
Tbt: Targeted neural network attack with bit trojan
A. S. Rakin, Z. He, and D. Fan · 2020
Later among the works it cites.
Hidden trigger backdoor attacks
A. Saha, A. Subramanya, and H. Pirsiavash · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
J. Cohen, E. Rosenfeld, and Z. Kolter · 2019
Cited alongside, same era.
The lottery ticket hypothesis: Finding sparse, trainable neural networks
J. Frankle and M. Carbin · 2019
Cited alongside, same era.
Strip: A defence against trojan attacks on deep neural networks
Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal · 2019
Cited alongside, same era.
Certified robustness to adversarial examples with differential privacy
M. Lecuyer, V. Atlidakis, R. Geambasu, D. Hsu, and S. Jana · 2019
Cited alongside, same era.
Abs: Scanning neural networks for back-doors by artificial brain stimulation
Y. Liu, W.-C. Lee, G. Tao, S. Ma, Y. Aafer, and X. Zhang · 2019
Cited alongside, same era.
On the turing completeness of modern neural network architectures
J. Pérez, J. Marinković, and P. Barceló · 2019
Cited alongside, same era.
Language models are unsupervised multitask learners
A. Radford, J. Wu, R. Child, D. Luan, D. Amodei, and I. Sutskever · 2019
Cited alongside, same era.
Later among the works it cites.
Denoised smoothing: A provable defense for pretrained classifiers, 2020
H. Salman, M. Sun, G. Yang, A. Kapoor, and J. Z. Kolter · 2020
Later among the works it cites.
Gotta catch’em all: Using honeypots to catch adversarial attacks on neural networks
S. Shan, E. Wenger, B. Wang, B. Li, H. Zheng, and B. Y. Zhao · 2020
Later among the works it cites.
Bypassing backdoor detection algorithms in deep learning
R. Shokri et al · 2020
Later among the works it cites.
Poisoned classifiers are not only backdoored, they are fundamentally broken
M. Sun, S. Agarwal, and J. Z. Kolter · 2020
Later among the works it cites.
An embarrassingly simple approach for trojan attack in deep neural networks
R. Tang, M. Du, N. Liu, F. Yang, and X. Hu · 2020
Later among the works it cites.
Practical detection of trojan neural networks: Data-limited and data-free cases
R. Wang, G. Zhang, S. Liu, P.-Y. Chen, J. Xiong, and M. Wang · 2020
Later among the works it cites.
Gradient descent on neural networks typically occurs at the edge of stability
J. Cohen, S. Kaur, Y. Li, J. Z. Kolter, and A. Talwalkar · 2021
Closest in time.
Switch transformers: Scaling to trillion parameter models with simple and efficient sparsity, 2021
W. Fedus, B. Zoph, and N. Shazeer · 2021
Closest in time.
Proof-of-learning: Definitions and practice
H. Jia, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, A. Thudi, V. Chandrasekaran, and N. Papernot · 2021
Closest in time.
Demon in the variant: Statistical analysis of DNNs for robust backdoor contamination detection
D. Tang, X. Wang, H. Tang, and K. Zhang · 2021
Closest in time.
Detecting backdoored neural networks with structured adversarial attacks
C. Yang · 2021
Closest in time.
https://aihub.cloud.google.com/
AI Hub · 2022
Closest in time.
https://modelzoo.co
Model Zoo - Deep learning code and pretrained models for transfer learning, educational purposes, and more · 2022
Closest in time.