Fetching the paper…
Reading the bibliography…
Although cyberattacks on machine learning (ML) production systems can be harmful, today, security practitioners are ill equipped, lacking methodologies and tactical tools that would allow them to analyze the security risks of their ML-based systems.
MulVAL: A Logic-based Network Security Analyzer.. In USENIX security symposium , Vol. 8. Baltimore, MD, 113–128
Xinming Ou, Sudhakar Govindavajhala, and Andrew W Appel. 2005 · 2005
Earlier work this paper cites.
Mulval extensions for dynamic asset protection
Eugen Bacic, Michael Froh, and Glen Henderson. 2006 · 2006
Earlier work this paper cites.
Decision making with the analytic hierarchy process
Thomas L Saaty. 2008 · 2008
Earlier work this paper cites.
MulVAL extensions II
Michael John Froh and Glen Henderson. 2009 · 2009
Earlier work this paper cites.
Adversarial machine learning. In Proceedings of the 4th ACM workshop on Security and artificial intelligence . 43–58
Ling Huang, Anthony D Joseph, Blaine Nelson, Benjamin IP Rubinstein, and J Doug Tygar. 2011 · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012 · 2012
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013 · 2013
Earlier work this paper cites.
Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing. In 23rd { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 14) . 17–32
Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart. 2014 · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014 · 2014
Earlier work this paper cites.
Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers
Giuseppe Ateniese, Luigi V Mancini, Angelo Spognardi, Antonio Villani, Domenico Vitali, and Giovanni Felici. 2015 · 2015
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security . 1322–1333
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015 · 2015
Earlier work this paper cites.
A logic-based network forensic model for evidence analysis. In IFIP International Conference on Digital Forensics . Springer, 129–145
Changwei Liu, Anoop Singhal, and Duminda Wijesekera. 2015 · 2015
Earlier work this paper cites.
Using machine teaching to identify optimal training-set attacks on machine learners. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 29
Shike Mei and Xiaojin Zhu. 2015 · 2015
Earlier work this paper cites.
Is feature selection secure against training data poisoning?. In International Conference on Machine Learning . PMLR, 1689–1698
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli. 2015 · 2015
Earlier work this paper cites.
Augmenting attack graphs to represent data link and network layer vulnerabilities. In Military Communications Conference, MILCOM 2016-2016 IEEE . IEEE, 1010–1015
Jaime C Acosta, Edgar Padilla, and John Homer. 2016 · 2016
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, Samy Bengio, et al · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016 · 2016
Earlier work this paper cites.
Tfx: A tensorflow-based production-scale machine learning platform. In Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining . 1387–1395
Denis Baylor, Eric Breck, Heng-Tze Cheng, Noah Fiedel, Chuan Yu Foo, Zakaria Haque, Salem Haykal, Mustafa Ispir, Vihan Jain, Levent Koc, et al · 2017
Earlier work this paper cites.
Adversarial examples are not easily detected: Bypassing ten detection methods. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security . 3–14
Nicholas Carlini and David Wagner. 2017 · 2017
Cited alongside, same era.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In Proceedings of the 10th ACM workshop on artificial intelligence and security . 15–26
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, and Cho-Jui Hsieh. 2017 · 2017
Cited alongside, same era.
A Game Theoretic approach based virtual machine migration for cloud environment security
Iman El Mir, El Mehdi Kandoussi, Mohamed Hanini, Abdelkrim Haqiq, and Dong Seong Kim. 2017 · 2017
Cited alongside, same era.
Model inversion attacks for prediction systems: Without knowledge of non-sensitive attributes. In 2017 15th Annual Conference on Privacy, Security and Trust (PST) . IEEE, 115–11509
Seira Hidano, Takao Murakami, Shuichi Katsumata, Shinsaku Kiyomoto, and Goichiro Hanaoka. 2017 · 2017
Cited alongside, same era.
MLsploit [Judges Remarks]
Evan Downing. 2019 · 2019
Later among the works it cites.
Design Procedure of Knowledge Base for Practical Attack Graph Generation. In Proceedings of the 2019 ACM Asia Conference on Computer and Communications Security . 594–601
Masaki Inokuchi, Yoshinobu Ohta, Shunichi Kinoshita, Tomohiko Yagyu, Orly Stan, Ron Bitton, Yuval Elovici, and Asaf Shabtai. 2019 · 2019
Later among the works it cites.
PRADA: protecting against DNN model stealing attacks. In 2019 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 512–527
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N Asokan. 2019 · 2019
Later among the works it cites.
secml: A python library for secure and explainable machine learning
Marco Melis, Ambra Demontis, Maura Pintor, Angelo Sotgiu, and Battista Biggio. 2019 · 2019
Later among the works it cites.
Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (SP) . IEEE, 739–753
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Modeling and analyses of IP spoofing attack in 6LoWPAN network
Monali Mavani and Krishna Asawa. 2017 · 2017
Cited alongside, same era.
Towards poisoning of deep learning algorithms with back-gradient optimization. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security . 27–38
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C Lupu, and Fabio Roli. 2017 · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning. In Proceedings of the 2017 ACM on Asia conference on computer and communications security . 506–519
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami. 2017 · 2017
Cited alongside, same era.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge. 2017 · 2017
Cited alongside, same era.
Membership inference attacks against machine learning models. In 2017 IEEE Symposium on Security and Privacy (SP) . IEEE, 3–18
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017 · 2017
Cited alongside, same era.
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli. 2018 · 2018
Cited alongside, same era.
Property inference attacks on fully connected neural networks using permutation invariant representations. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security . 619–633
Karan Ganju, Qi Wang, Wei Yang, Carl A Gunter, and Nikita Borisov. 2018 · 2018
Cited alongside, same era.
Analysis of Attack Graph Representations for Ranking Vulnerability Fixes.. In GCAI . 215–228
Tom Gonda, Tal Pascal, Rami Puzis, Guy Shani, and Bracha Shapira. 2018 · 2018
Cited alongside, same era.
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019 · 2019
Later among the works it cites.
Towards reverse-engineering black-box neural networks
Seong Joon Oh, Bernt Schiele, and Mario Fritz. 2019 · 2019
Later among the works it cites.
Extending Attack Graphs to Represent Cyber-Attacks in Communication Protocols and Modern IT Networks
Orly Stan, Ron Bitton, Michal Ezrets, Moran Dadon, Masaki Inokuchi, Yoshinobu Ohta, Yoshiyuki Yamada, Tomohiko Yagyu, Yuval Elovici, and Asaf Shabtai. 2019 · 2019
Later among the works it cites.
Neural network inversion in adversarial setting via background knowledge alignment. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 225–240
Ziqi Yang, Jiyi Zhang, Ee-Chien Chang, and Zhenkai Liang. 2019 · 2019
Later among the works it cites.
An Automated, End-to-End Framework for Modeling Attacks From Vulnerability Descriptions
Hodaya Binyamini, Ron Bitton, Masaki Inokuchi, Tomohiko Yagyu, Yuval Elovici, and Asaf Shabtai. 2020 · 2020
Later among the works it cites.
Exploring connections between active learning and model extraction. In 29th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 20) . 1309–1326
Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Songbai Yan. 2020 · 2020
Later among the works it cites.
Hopskipjumpattack: A query-efficient decision-based attack. In 2020 ieee symposium on security and privacy (sp) . IEEE, 1277–1294
Jianbo Chen, Michael I Jordan, and Martin J Wainwright. 2020 · 2020
Later among the works it cites.
Adversarial machine learning-industry perspectives. In 2020 IEEE Security and Privacy Workshops (SPW) . IEEE, 69–75
Ram Shankar Siva Kumar, Magnus Nyström, John Lambert, Andrew Marshall, Mario Goertzel, Andi Comissoneru, Matt Swann, and Sharon Xia. 2020 · 2020
Later among the works it cites.
Information leakage in embedding models. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security . 377–390
Congzheng Song and Ananth Raghunathan. 2020 · 2020
Later among the works it cites.
On managing vulnerabilities in AI/ML systems. In New Security Paradigms Workshop 2020 . 111–126
Jonathan M Spring, April Galyardt, Allen D Householder, and Nathan VanHoudnos. 2020 · 2020
Later among the works it cites.
Poisoning attacks on cyber attack detectors for industrial control systems. In Proceedings of the 36th Annual ACM Symposium on Applied Computing . 116–125
Moshe Kravchik, Battista Biggio, and Asaf Shabtai. 2021 · 2021
Closest in time.
Adversarial Machine Learning: Attacks From Laboratories to the Real World
Hsiao-Ying Lin and Battista Biggio. 2021 · 2021
Closest in time.
Heuristic Approach for Countermeasure Selection Using Attack Graphs. In 2021 IEEE 34th Computer Security Foundations Symposium (CSF) . IEEE Computer Society, 63–78
Orly Stan, Ron Bitton, Michal Ezrets, Moran Dadon, Masaki Inokuchi, Yoshinobu Ohta, Tomohiko Yagyu, Yuval Elovici, and Asaf Shabtai. [n. d.] · 2021
Closest in time.