Fetching the paper…
Reading the bibliography…
We propose a minimax formulation for removing backdoors from a given poisoned model based on a small set of clean data.
Remarques sur un résultat non publié de b. maurey
Gilles Pisier · 1981
Earlier work this paper cites.
The complexity of partial derivatives
Walter Baur and Volker Strassen · 1983
Earlier work this paper cites.
Some bounds on the complexity of gradients, jacobians, and hessians
Andreas Griewank · 1993
Earlier work this paper cites.
Covering number bounds of certain regularized linear function classes
Tong Zhang · 2002
Earlier work this paper cites.
Yiming Li, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shu-Tao Xia · 2007
Earlier work this paper cites.
Evaluating derivatives: principles and techniques of algorithmic differentiation
Andreas Griewank and Andrea Walther · 2008
Earlier work this paper cites.
On the use of stochastic hessian information in optimization methods for machine learning
Richard H Byrd, Gillian M Chin, Will Neveitt, and Jorge Nocedal · 2011
Earlier work this paper cites.
The theory of max-min and its application to weapons allocation problems , volume 5
John M Danskin · 2012
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Spectrally-normalized margin bounds for neural networks
Peter L Bartlett, Dylan J Foster, and Matus J Telgarsky · 2017
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning, 2017
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Earlier work this paper cites.
Understanding black-box predictions via influence functions
Pang Wei Koh and Percy Liang · 2017
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Earlier work this paper cites.
Universal adversarial perturbations
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2017
Earlier work this paper cites.
Automatic differentiation in machine learning: a survey
Atilim Gunes Baydin, Barak A Pearlmutter, Alexey Andreyevich Radul, and Jeffrey Mark Siskind · 2018
Earlier work this paper cites.
Detecting backdoor attacks on deep neural networks by activation clustering
Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava · 2018
Cited alongside, same era.
Spectral signatures in backdoor attacks
Brandon Tran, Jerry Li, and Aleksander Madry · 2018
Cited alongside, same era.
Deepinspect: A black-box trojan detection and mitigation framework for deep neural networks
Huili Chen, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar · 2019
Cited alongside, same era.
Robust anomaly detection and backdoor attack detection via differential privacy
Min Du, Ruoxi Jia, and Dawn Song · 2019
Cited alongside, same era.
Strip: A defence against trojan attacks on deep neural networks
Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith C. Ranasinghe, and Surya Nepal · 2019
Cited alongside, same era.
Intrinsic certified robustness of bagging against data poisoning attacks, 2020
Jinyuan Jia, Xiaoyu Cao, and Neil Zhenqiang Gong · 2020
Later among the works it cites.
Deep partition aggregation: Provable defense against general poisoning attacks, 2020
Alexander Levine and Soheil Feizi · 2020
Later among the works it cites.
Reflection backdoor: A natural backdoor attack on deep neural networks
Yunfei Liu, Xingjun Ma, James Bailey, and Feng Lu · 2020
Later among the works it cites.
Input-aware dynamic backdoor attack
Tuan Anh Nguyen and Anh Tran · 2020
Later among the works it cites.
Hidden trigger backdoor attacks
Aniruddha Saha, Akshayvarun Subramanya, and Hamed Pirsiavash · 2020
Later among the works it cites.
Practical detection of trojan neural networks: Data-limited and data-free cases
Ren Wang, Gaoyuan Zhang, Sijia Liu, Pin-Yu Chen, Jinjun Xiong, and Meng Wang · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems
Wenbo Guo, Lun Wang, Xinyu Xing, Min Du, and Dawn Song · 2019
Cited alongside, same era.
Pytorch: An imperative style, high-performance deep learning library
Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et al · 2019
Cited alongside, same era.
Meta-learning with implicit gradients
Aravind Rajeswaran, Chelsea Finn, Sham M Kakade, and Sergey Levine · 2019
Cited alongside, same era.
Label-consistent backdoor attacks
Alexander Turner, Dimitris Tsipras, and Aleksander Madry · 2019
Cited alongside, same era.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao · 2019
Cited alongside, same era.
Detecting ai trojans using meta neural analysis
Xiaojun Xu, Qi Wang, Huichen Li, Nikita Borisov, Carl A Gunter, and Bo Li · 2019
Cited alongside, same era.
Rademacher complexity for adversarially robust generalization
Dong Yin, Ramchandran Kannan, and Peter Bartlett · 2019
Cited alongside, same era.
Later among the works it cites.
Rab: Provable robustness against backdoor attacks
Maurice Weber, Xiaojun Xu, Bojan Karlaš, Ce Zhang, and Bo Li · 2020
Later among the works it cites.
Clean-label backdoor attacks on video recognition models, 2020
Shihao Zhao, Xingjun Ma, Xiang Zheng, James Bailey, Jingjing Chen, and Yu-Gang Jiang · 2020
Later among the works it cites.
Blind backdoors in deep learning models, 2021
Eugene Bagdasaryan and Vitaly Shmatikov · 2021
Closest in time.
Check your other door! establishing backdoor attacks in the frequency domain
Hasan Abed Al Kader Hammoud and Bernard Ghanem · 2021
Closest in time.
Certified robustness of nearest neighbors against data poisoning attacks, 2021
Jinyuan Jia, Xiaoyu Cao, and Neil Zhenqiang Gong · 2021
Closest in time.
Wanet–imperceptible warping-based backdoor attack
Anh Nguyen and Anh Tran · 2021
Closest in time.
Deepsweep: An evaluation framework for mitigating dnn backdoor attacks using data augmentation
Han Qiu, Yi Zeng, Shangwei Guo, Tianwei Zhang, Meikang Qiu, and Bhavani Thuraisingham · 2021
Closest in time.
Rethinking the backdoor attacks’ triggers: A frequency perspective
Yi Zeng, Won Park, Z Morley Mao, and Ruoxi Jia · 2021
Closest in time.
Backdoor defense via decoupling the training process
Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, and Kui Ren · 2022
Closest in time.
Semi-supervised robust training with generalized perturbed neighborhood
Yiming Li, Baoyuan Wu, Yan Feng, Yanbo Fan, Yong Jiang, Zhifeng Li, and Shu-Tao Xia · 2022
Closest in time.