Fetching the paper…
Reading the bibliography…
Backdoor attacks have been shown to be a serious threat against deep learning systems such as biometric authentication and autonomous driving.
Discrete cosine transform
Nasir Ahmed, T_ Natarajan, and Kamisetty R Rao. 1974 · 1974
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner. 1998 · 1998
Earlier work this paper cites.
Image quality assessment: from error visibility to structural similarity
Zhou Wang, Alan C Bovik, Hamid R Sheikh, and Eero P Simoncelli. 2004 · 2004
Earlier work this paper cites.
Digital watermarking and steganography
Ingemar Cox, Matthew Miller, Jeffrey Bloom, Jessica Fridrich, and Ton Kalker. 2007 · 2007
Earlier work this paper cites.
Scope of validity of PSNR in image/video quality assessment
Quan Huynh-Thu and Mohammed Ghanbari. 2008 · 2008
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database. In 2009 IEEE conference on computer vision and pattern recognition (CVPR) . Ieee, 248–255
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009 · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
The German traffic sign recognition benchmark: a multi-class classification competition. In The 2011 international joint conference on neural networks (IJCNN) . IEEE, 1453–1460
Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel. 2011 · 2011
Earlier work this paper cites.
Imagenet classification with deep convolutional neural networks
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2012 · 2012
Earlier work this paper cites.
Isolation-based anomaly detection
Fei Tony Liu, Kai Ming Ting, and Zhi-Hua Zhou. 2012 · 2012
Earlier work this paper cites.
Auto-encoding variational bayes
Diederik P Kingma and Max Welling. 2013 · 2013
Earlier work this paper cites.
Discrete cosine transform: algorithms, advantages, applications
K Ramamohan Rao and Ping Yip. 2014 · 2014
Earlier work this paper cites.
Image processing, analysis, and machine vision
Milan Sonka, Vaclav Hlavac, and Roger Boyle. 2014 · 2014
Earlier work this paper cites.
Delving deep into rectifiers: Surpassing human-level performance on imagenet classification. In Proceedings of the IEEE international conference on computer vision (ICCV) . 1026–1034
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2015 · 2015
Earlier work this paper cites.
Deep face recognition
Omkar M Parkhi, Andrea Vedaldi, and Andrew Zisserman. 2015 · 2015
Earlier work this paper cites.
Faster R-CNN: towards real-time object detection with region proposal networks. In Proceedings of the 28th International Conference on Neural Information Processing Systems (NeurIPS) . 91–99
Shaoqing Ren, Kaiming He, Ross Girshick, and Jian Sun. 2015 · 2015
Earlier work this paper cites.
Facenet: A unified embedding for face recognition and clustering. In Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR) . 815–823
Florian Schroff, Dmitry Kalenichenko, and James Philbin. 2015 · 2015
Earlier work this paper cites.
Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR) . 770–778
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
You only look once: Unified, real-time object detection. In Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR) . 779–788
Joseph Redmon, Santosh Divvala, Ross Girshick, and Ali Farhadi. 2016 · 2016
Earlier work this paper cites.
Improved techniques for training GANs. In Proceedings of the 30th International Conference on Neural Information Processing Systems (NeurIPS) . 2234–2242
Tim Salimans, Ian Goodfellow, Wojciech Zaremba, Vicki Cheung, Alec Radford, and Xi Chen. 2016 · 2016
Earlier work this paper cites.
Rethinking the inception architecture for computer vision. In Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR) . 2818–2826
Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. 2016 · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks. In IEEE Symposium on Security and Privacy (SP) . IEEE, 39–57
Nicholas Carlini and David Wagner. 2017 · 2017
Cited alongside, same era.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017 · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017 · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017 · 2017
Cited alongside, same era.
Grad-cam: Visual explanations from deep networks via gradient-based localization. In Proceedings of the IEEE international conference on computer vision (ICCV) . 618–626
Neural network inversion in adversarial setting via background knowledge alignment. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS) . 225–240
Ziqi Yang, Jiyi Zhang, Ee-Chien Chang, and Zhenkai Liang. 2019a · 2019
Later among the works it cites.
Neural network inversion in adversarial setting via background knowledge alignment. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS) . 225–240
Ziqi Yang, Jiyi Zhang, Ee-Chien Chang, and Zhenkai Liang. 2019b · 2019
Later among the works it cites.
A fourier perspective on model robustness in computer vision. In Annual Conference on Neural Information Processing Systems (NeurIPS) . 13255–13265
Dong Yin, Raphael Gontijo Lopes, Jonathon Shlens, Ekin D Cubuk, and Justin Gilmer. 2019 · 2019
Later among the works it cites.
Live Trojan attacks on deep neural networks. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops . 796–797
Robby Costales, Chengzhi Mao, Raphael Norwitz, Bryan Kim, and Junfeng Yang. 2020 · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Ramprasaath R Selvaraju, Michael Cogswell, Abhishek Das, Ramakrishna Vedantam, Devi Parikh, and Dhruv Batra. 2017 · 2017
Cited alongside, same era.
Membership inference attacks against machine learning models. In 2017 IEEE Symposium on Security and Privacy (SP) . IEEE, 3–18
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017 · 2017
Cited alongside, same era.
Shane Barratt and Rishi Sharma. 2018 · 2018
Cited alongside, same era.
Property inference attacks on fully connected neural networks using permutation invariant representations. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS) . 619–633
Karan Ganju, Qi Wang, Wei Yang, Carl A Gunter, and Nikita Borisov. 2018 · 2018
Cited alongside, same era.
Loss surfaces, mode connectivity, and fast ensembling of DNNs. In Proceedings of the 32nd International Conference on Neural Information Processing Systems (NeurIPS) . 8803–8812
Timur Garipov, Pavel Izmailov, Dmitrii Podoprikhin, Dmitry Vetrov, and Andrew Gordon Wilson. 2018 · 2018
Cited alongside, same era.
Spectral signatures in backdoor attacks. In Proceedings of the 32nd International Conference on Neural Information Processing Systems (NeurIPS) . 8011–8021
Brandon Tran, Jerry Li, and Aleksander Mądry. 2018 · 2018
Cited alongside, same era.
Clean-label backdoor attacks
Alexander Turner, Dimitris Tsipras, and Aleksander Madry. 2018 · 2018
Cited alongside, same era.
High-fidelity facial reflectance and geometry inference from an unconstrained image
Shugo Yamaguchi, Shunsuke Saito, Koki Nagano, Yajie Zhao, Weikai Chen, Kyle Olszewski, Shigeo Morishima, and Hao Li. 2018 · 2018
Cited alongside, same era.
Februus: Input purification defense against trojan attacks on deep neural network systems. In Proceedings of the Annual Computer Security Applications Conference (ACSAC) . 897–912
Bao Gia Doan, Ehsan Abbasnejad, and Damith C Ranasinghe. 2020 · 2020
Later among the works it cites.
One-pixel signature: Characterizing cnn models for backdoor detection. In European Conference on Computer Vision (ECCV) . Springer, 326–341
Shanjiaoyang Huang, Weiqi Peng, Zhiwei Jia, and Zhuowen Tu. 2020 · 2020
Later among the works it cites.
Universal litmus patterns: Revealing backdoor attacks in cnns. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . 301–310
Soheil Kolouri, Aniruddha Saha, Hamed Pirsiavash, and Heiko Hoffmann. 2020 · 2020
Later among the works it cites.
Invisible backdoor attacks on deep neural networks via steganography and regularization
Shaofeng Li, Minhui Xue, Benjamin Zhao, Haojin Zhu, and Xinpeng Zhang. 2020a · 2020
Later among the works it cites.
Composite Backdoor Attack for Deep Neural Network by Mixing Existing Benign Features. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security (CCS) . 113–131
Junyu Lin, Lei Xu, Yingqi Liu, and Xiangyu Zhang. 2020 · 2020
Later among the works it cites.
Reflection backdoor: A natural backdoor attack on deep neural networks. In European Conference on Computer Vision (ECCV) . Springer, 182–199
Yunfei Liu, Xingjun Ma, James Bailey, and Feng Lu. 2020 · 2020
Later among the works it cites.
Input-Aware Dynamic Backdoor Attack. In Proceedings of the Annual Conference on Neural Information Processing Systems (NeurIPS)
Tuan Anh Nguyen and Anh Tran. 2020 · 2020
Later among the works it cites.
A tale of evil twins: Adversarial inputs versus poisoned models. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security (CCS) . 85–99
Ren Pang, Hua Shen, Xinyang Zhang, Shouling Ji, Yevgeniy Vorobeychik, Xiapu Luo, Alex Liu, and Ting Wang. 2020 · 2020
Later among the works it cites.
Hidden trigger backdoor attacks. In Proceedings of the AAAI Conference on Artificial Intelligence (AAAI) . 11957–11965
Aniruddha Saha, Akshayvarun Subramanya, and Hamed Pirsiavash. 2020 · 2020
Later among the works it cites.
Dynamic backdoor attacks against machine learning models
Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang. 2020 · 2020
Later among the works it cites.
Bypassing Backdoor Detection Algorithms in Deep Learning. In 2020 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 175–183
Reza Shokri et al · 2020
Later among the works it cites.
An embarrassingly simple approach for trojan attack in deep neural networks. In Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining (KDD) . 218–228
Ruixiang Tang, Mengnan Du, Ninghao Liu, Fan Yang, and Xia Hu. 2020 · 2020
Later among the works it cites.
High-frequency component helps explain the generalization of convolutional neural networks. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . 8684–8694
Haohan Wang, Xindi Wu, Zeyi Huang, and Eric P Xing. 2020 · 2020
Later among the works it cites.
RABA: A Robust Avatar Backdoor Attack on Deep Neural Network
Ying He, Zhili Shen, Chang Xia, Jingyu Hua, Wei Tong, and Sheng Zhong. 2021 · 2021
Closest in time.
Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. In Proceedings of the International Conference on Learning Representations (ICLR)
Yige Li, Nodens Koren, Lingjuan Lyu, Xixiang Lyu, Bo Li, and Xingjun Ma. 2021 · 2021
Closest in time.
Latent backdoor attacks on deep neural networks. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS) . 2041–2055
Yuanshun Yao, Huiying Li, Haitao Zheng, and Ben Y Zhao. 2019 · 2055
Closest in time.
Image denoising by sparse 3-D transform-domain collaborative filtering
Kostadin Dabov, Alessandro Foi, Vladimir Katkovnik, and Karen Egiazarian. 2007 · 2095
Closest in time.