Fetching the paper…
Reading the bibliography…
Data poisoning attacks aim at manipulating model behaviors through distorting training data.
Label-consistent backdoor attacks
Turner, A., Tsipras, D., and Madry, A · 1912
Earlier work this paper cites.
Gradient-based learning applied to document recognition
LeCun, Y., Bottou, L., Bengio, Y., and Haffner, P · 1998
Earlier work this paper cites.
On certifying robustness against backdoor attacks via randomized smoothing
Wang, B., Cao, X., Jia, J., and Gong, N. Z · 2002
Earlier work this paper cites.
RAB: provable robustness against backdoor attacks
Weber, M., Xu, X., Karlas, B., Zhang, C., and Li, B · 2003
Earlier work this paper cites.
A framework of randomized selection based certified defenses against data poisoning attacks
Chen, R., Li, J., Wu, C., Sheng, B., and Li, P · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A · 2009
Earlier work this paper cites.
Dataset security for machine learning: Data poisoning, backdoor attacks, and defenses
Goldblum, M., Tsipras, D., Xie, C., Chen, X., Schwarzschild, A., Song, D., Madry, A., Li, B., and Goldstein, T · 2012
Earlier work this paper cites.
Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition
Stallkamp, J., Schlipsing, M., Salmen, J., and Igel, C · 2012
Earlier work this paper cites.
Lin, M., Chen, Q., and Yan, S · 2014
Earlier work this paper cites.
Deep learning with differential privacy
Abadi, M., Chu, A., Goodfellow, I. J., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Earlier work this paper cites.
Robust estimators in high dimensions without the computational intractability
Diakonikolas, I., Kamath, G., Kane, D. M., Li, J. Z., Moitra, A., and Stewart, A · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Agnostic estimation of mean and covariance
Lai, K. A., Rao, A. B., and Vempala, S. S · 2016
Cited alongside, same era.
Achieving human parity in conversational speech recognition
Xiong, W., Droppo, J., Huang, X., Seide, F., Seltzer, M., Stolcke, A., Yu, D., and Zweig, G · 2016
Cited alongside, same era.
Targeted backdoor attacks on deep learning systems using data poisoning
Chen, X., Liu, C., Li, B., Lu, K., and Song, D · 2017
Cited alongside, same era.
Semi-supervised knowledge transfer for deep learning from private training data
Papernot, N., Abadi, M., Erlingsson, Ú., Goodfellow, I. J., and Talwar, K · 2017
Cited alongside, same era.
Certified defenses for data poisoning attacks
Steinhardt, J., Koh, P. W., and Liang, P · 2017
Cited alongside, same era.
Robust anomaly detection and backdoor attack detection via differential privacy
Du, M., Jia, R., and Song, D · 2020
Later among the works it cites.
Certified robustness to label-flipping attacks via randomized smoothing
Rosenfeld, E., Winston, E., Ravikumar, P., and Kolter, J. Z · 2020
Later among the works it cites.
Hidden trigger backdoor attacks
Saha, A., Subramanya, A., and Pirsiavash, H · 2020
Later among the works it cites.
Bullseye polytope: A scalable clean-label poisoning attack with improved transferability
Aghakhani, H., Meng, D., Wang, Y., Kruegel, C., and Vigna, G · 2021
Later among the works it cites.
Learning and certification under instance-targeted poisoning
Gao, J., Karbasi, A., and Mahmoody, M · 2021
Later among the works it cites.
Witches’ brew: Industrial scale data poisoning via gradient matching
Geiping, J., Fowl, L. H., Huang, W. R., Czaja, W., Taylor, G., Moeller, M., and Goldstein, T · 2021
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Unsupervised representation learning by predicting image rotations
Gidaris, S., Singh, P., and Komodakis, N · 2018
Cited alongside, same era.
Scalable private learning with PATE
Papernot, N., Song, S., Mironov, I., Raghunathan, A., Talwar, K., and Erlingsson, Ú · 2018
Cited alongside, same era.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., and Goldstein, T · 2018
Cited alongside, same era.
BERT: pre-training of deep bidirectional transformers for language understanding
Devlin, J., Chang, M., Lee, K., and Toutanova, K · 2019
Cited alongside, same era.
Sever: A robust meta-algorithm for stochastic optimization
Diakonikolas, I., Kamath, G., Kane, D., Li, J., Steinhardt, J., and Stewart, A · 2019
Cited alongside, same era.
Data poisoning against differentially-private learners: Attacks and defenses
Ma, Y., Zhu, X., and Hsu, J · 2019
Cited alongside, same era.
Transferable clean-label poisoning attacks on deep neural nets
Zhu, C., Huang, W. R., Li, H., Taylor, G., Studer, C., and Goldstein, T · 2019
Cited alongside, same era.
Later among the works it cites.
Intrinsic certified robustness of bagging against data poisoning attacks
Jia, J., Cao, X., and Gong, N. Z · 2021
Later among the works it cites.
Deep partition aggregation: Provable defenses against general poisoning attacks
Levine, A. and Feizi, S · 2021
Later among the works it cites.
Just how toxic is data poisoning? A unified benchmark for backdoor and data poisoning attacks
Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J. P., and Goldstein, T · 2021
Later among the works it cites.
Dplis: Boosting utility of differentially private deep learning via randomized smoothing
Wang, W., Wang, T., Wang, L., Luo, N., Zhou, P., Song, D., and Jia, R · 2021
Later among the works it cites.
On collective robustness of bagging against data poisoning
Chen, R., Li, Z., Li, J., Wu, C., and Yan, J · 2022
Closest in time.