Fetching the paper…
Reading the bibliography…
Collecting training data from untrusted sources exposes machine learning services to poisoning adversaries, who maliciously manipulate training data to degrade the model accuracy.
Some bounds on the complexity of gradients, jacobians, and hessians
Andreas Griewank · 1993
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Dynamic backdoor attacks against machine learning models
Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang · 2003
Earlier work this paper cites.
The theory and practice of online learning
Terry Anderson · 2008
Earlier work this paper cites.
Evaluating derivatives: principles and techniques of algorithmic differentiation , volume 105
Andreas Griewank and Andrea Walther · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
Large scale online learning of image similarity through ranking
Gal Chechik, Varun Sharma, Uri Shalit, and Samy Bengio · 2010
Earlier work this paper cites.
Don’t trigger me! a triggerless backdoor attack against deep neural networks
Ahmed Salem, Michael Backes, and Yang Zhang · 2010
Earlier work this paper cites.
Baaan: Backdoor attacks against autoencoder and gan-based machine learning models
Ahmed Salem, Yannick Sautter, Michael Backes, Mathias Humbert, and Yang Zhang · 2010
Earlier work this paper cites.
Road detection using support vector machine based on online learning and evaluation
Shengyan Zhou, Jianwei Gong, Guangming Xiong, Huiyan Chen, and Karl Iagnemma · 2010
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Generative adversarial nets
Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Batch normalization: Accelerating deep network training by reducing internal covariate shift
Sergey Ioffe and Christian Szegedy · 2015
Earlier work this paper cites.
Using machine teaching to identify optimal training-set attacks on machine learners
Shike Mei and Xiaojin Zhu · 2015
Earlier work this paper cites.
Privacy-preserving deep learning
Reza Shokri and Vitaly Shmatikov · 2015
Earlier work this paper cites.
A review on facial recognition for online learning authentication
Jasmine Valera, Jacinto Valera, and Yvette Gelogo · 2015
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli · 2015
Earlier work this paper cites.
Data poisoning attacks against autoregressive models
Scott Alfeld, Xiaojin Zhu, and Paul Barford · 2016
Earlier work this paper cites.
Federated learning: Strategies for improving communication efficiency
Jakub Konečnỳ, H Brendan McMahan, Felix X Yu, Peter Richtárik, Ananda Theertha Suresh, and Dave Bacon · 2016
Earlier work this paper cites.
Data poisoning attacks on factorization-based collaborative filtering
Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik · 2016
Earlier work this paper cites.
Protection of big data privacy
Abid Mehmood, Iynkaran Natgunanathan, Yong Xiang, Guang Hua, and Song Guo · 2016
Earlier work this paper cites.
Analysis of causative attacks against svms learning from data streams
Cody Burkard and Brent Lagesse · 2017
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner · 2017
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Earlier work this paper cites.
Understanding black-box predictions via influence functions
Pang Wei Koh and Percy Liang · 2017
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2017
Earlier work this paper cites.
The role of data privacy in marketing
Kelly D Martin and Patrick E Murphy · 2017
Earlier work this paper cites.
Communication-efficient learning of deep networks from decentralized data
Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas · 2017
Cited alongside, same era.
Towards poisoning of deep learning algorithms with back-gradient optimization
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli · 2017
Cited alongside, same era.
Certified defenses for data poisoning attacks
Jacob Steinhardt, Pang Wei Koh, and Percy Liang · 2017
Cited alongside, same era.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples
Anish Athalye, Nicholas Carlini, and David Wagner · 2018
Cited alongside, same era.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Cited alongside, same era.
Adversarial attacks on stochastic bandits
Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks
Francesco Croce and Matthias Hein · 2020
Later among the works it cites.
Benchmarking adversarial robustness on image classification
Yinpeng Dong, Qi-An Fu, Xiao Yang, Tianyu Pang, Hang Su, Zihao Xiao, and Jun Zhu · 2020
Later among the works it cites.
Can adversarial weight perturbations inject neural backdoors
Siddhant Garg, Adarsh Kumar, Vibhor Goel, and Yingyu Liang · 2020
Later among the works it cites.
Metapoison: Practical general-purpose clean-label data poisoning
W Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor, and Tom Goldstein · 2020
Later among the works it cites.
Adversarial machine learning-industry perspectives
Ram Shankar Siva Kumar, Magnus Nyström, John Lambert, Andrew Marshall, Mario Goertzel, Andi Comissoneru, Matt Swann, and Sharon Xia · 2020
Later among the works it cites.
Eeg-based brain-computer interfaces are vulnerable to backdoor attacks
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Kwang-Sung Jun, Lihong Li, Yuzhe Ma, and Xiaojin Zhu · 2018
Cited alongside, same era.
Stronger data poisoning attacks break data sanitization defenses
Pang Wei Koh, Jacob Steinhardt, and Percy Liang · 2018
Cited alongside, same era.
A simple unified framework for detecting out-of-distribution samples and adversarial attacks
Kimin Lee, Kibok Lee, Honglak Lee, and Jinwoo Shin · 2018
Cited alongside, same era.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Towards robust detection of adversarial examples
Tianyu Pang, Chao Du, Yinpeng Dong, and Jun Zhu · 2018
Cited alongside, same era.
Detection of adversarial training examples in poisoning attacks through anomaly detection
Andrea Paudice, Luis Muñoz-González, Andras Gyorgy, and Emil C Lupu · 2018
Cited alongside, same era.
Lubin Meng, Jian Huang, Zhigang Zeng, Xue Jiang, Shan Yu, Tzyy-Ping Jung, Chin-Teng Lin, Ricardo Chavarriaga, and Dongrui Wu · 2020
Later among the works it cites.
Boosting adversarial training with hypersphere embedding
Tianyu Pang, Xiao Yang, Yinpeng Dong, Kun Xu, Hang Su, and Jun Zhu · 2020
Later among the works it cites.
Hidden trigger backdoor attacks
Aniruddha Saha, Akshayvarun Subramanya, and Hamed Pirsiavash · 2020
Later among the works it cites.
Poisoned classifiers are not only backdoored, they are fundamentally broken
Mingjie Sun, Siddhant Agarwal, and J Zico Kolter · 2020
Later among the works it cites.
Online data poisoning attacks
Xuezhou Zhang, Xiaojin Zhu, and Laurent Lessard · 2020
Later among the works it cites.
Bullseye polytope: A scalable clean-label poisoning attack with improved transferability
Hojjat Aghakhani, Dongyu Meng, Yu-Xiang Wang, Christopher Kruegel, and Giovanni Vigna · 2021
Closest in time.
Eitan Borgnia, Jonas Geiping, Valeriia Cherepanova, Liam Fowl, Arjun Gupta, Amin Ghiasi, Furong Huang, Micah Goldblum, and Tom Goldstein · 2021
Closest in time.
Regularization can help mitigate poisoning attacks… with the right hyperparameters
Javier Carnerero-Cano, Luis Muñoz-González, Phillippa Spencer, and Emil C Lupu · 2021
Closest in time.
De-pois: An attack-agnostic defense against data poisoning attacks
Jian Chen, Xuxin Zhang, Rui Zhang, Chen Wang, and Ling Liu · 2021
Closest in time.
Black-box detection of backdoor attacks with limited information and data
Yinpeng Dong, Xiao Yang, Zhijie Deng, Tianyu Pang, Zihao Xiao, Hang Su, and Jun Zhu · 2021
Closest in time.
Learning and certification under instance-targeted poisoning
Ji Gao, Amin Karbasi, and Mohammad Mahmoody · 2021
Closest in time.
Spectre: Defending against backdoor attacks using robust statistics
Jonathan Hayase, Weihao Kong, Raghav Somani, and Sewoong Oh · 2021
Closest in time.
Top: Backdoor detection in neural networks via transferability of perturbation
Todd Huster and Emmanuel Ekwedike · 2021
Closest in time.
Provable guarantees against data poisoning using self-expansion and compatibility
Charles Jin, Melinda Sun, and Martin Rinard · 2021
Closest in time.
How robust are randomized smoothing based defenses to data poisoning?
Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, and Jihun Hamm · 2021
Closest in time.
Backdoor attacks on self-supervised learning
Aniruddha Saha, Ajinkya Tejankar, Soroush Abbasi Koohpayegani, and Hamed Pirsiavash · 2021
Closest in time.
Influence based defense against data poisoning attacks in online learning
Sanjay Seetharaman, Shubham Malaviya, Rosni KV, Manish Shukla, and Sachin Lodha · 2021
Closest in time.
Uncertainty-matching graph neural networks to defend against poisoning attacks
Uday Shankar Shanthamallu, Jayaraman J Thiagarajan, and Andreas Spanias · 2021
Closest in time.
Manipulating sgd with data ordering attacks
Ilia Shumailov, Zakhar Shumaylov, Dmitry Kazhdan, Yiren Zhao, Nicolas Papernot, Murat A Erdogdu, and Ross Anderson · 2021
Closest in time.
Preventing machine learning poisoning attacks using authentication and provenance
Jack W Stokes, Paul England, and Kevin Kane · 2021
Closest in time.
Poisoning morphnet for clean-label backdoor attack to point clouds
Guiyu Tian, Wenhao Jiang, Wei Liu, and Yadong Mu · 2021
Closest in time.
A backdoor attack against 3d point cloud classifiers
Zhen Xiang, David J Miller, Siheng Chen, Xi Li, and George Kesidis · 2021
Closest in time.
Explainability-based backdoor attacks against graph neural networks
Jing Xu, Stjepan Picek, et al · 2021
Closest in time.
Robust backdoor attacks against deep neural networks in real physical world
Mingfu Xue, Can He, Shichang Sun, Jian Wang, and Weiqiang Liu · 2021
Closest in time.