Fetching the paper…
Reading the bibliography…
Malware classifiers are subject to training-time exploitation due to the need to regularly retrain using samples collected from the wild.
Drebin: Effective and explainable detection of android malware in your pocket
D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon, K. Rieck, and C. Siemens · 2014
Earlier work this paper cites.
Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps
S. Arzt, S. Rasthofer, C. Fritz, E. Bodden, A. Bartel, J. Klein, Y. L. Traon, D. Octeau, and P. D. McDaniel · 2014
Earlier work this paper cites.
Androzoo: Collecting millions of android apps for the research community
K. Allix, T. F. Bissyandé, J. Klein, and Y. Le Traon · 2016
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
X. Chen, C. Liu, B. Li, K. Lu, and D. Song · 2017
Earlier work this paper cites.
Yes, machine learning can be more secure! a case study on android malware detection
A. Demontis, M. Melis, B. Biggio, D. Maiorca, D. Arp, K. Rieck, I. Corona, G. Giacinto, and F. Roli · 2017
Earlier work this paper cites.
Euphony: harmonious unification of cacophonous anti-virus vendor labels for android malware
M. Hurier, G. Suarez-Tangil, S. K. Dash, T. F. Bissyandé, Y. L. Traon, J. Klein, and L. Cavallaro · 2017
Earlier work this paper cites.
A unified approach to interpreting model predictions
S. M. Lundberg and S.-I. Lee · 2017
Earlier work this paper cites.
https://usa.kaspersky.com/about/press-releases/2018_kaspersky-lab-report-iot-malware-grew-three-fold-in-h1-2018 , 2018
Kaspersky lab report: Iot malware grew three-fold in h1 2018 · 2018
Earlier work this paper cites.
Ember: an open dataset for training static pe malware machine learning models
H. S. Anderson and P. Roth · 2018
Earlier work this paper cites.
Learning to evade static pe machine learning malware models via reinforcement learning
H. S. Anderson, A. Kharkar, B. Filar, D. Evans, and P. Roth · 2018
Earlier work this paper cites.
Malwareguard: Fireeye’s machine learning model to detect and prevent malware
J. Johns · 2018
Earlier work this paper cites.
Generic black-box end-to-end attack against state of the art API call based malware classifiers
I. Rosenberg, A. Shabtai, L. Rokach, and Y. Elovici · 2018
Earlier work this paper cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein · 2018
Earlier work this paper cites.
When does machine learning FAIL? Generalized transferability for evasion and poisoning attacks
O. Suciu, R. Marginean, Y. Kaya, H. Daume III, and T. Dumitras · 2018
Earlier work this paper cites.
Spectral signatures in backdoor attacks
B. Tran, J. Li, and A. Madry · 2018
Earlier work this paper cites.
Clean-label backdoor attacks
A. Turner, D. Tsipras, and A. Madry · 2018
Earlier work this paper cites.
Deeprefiner: Multi-layer android malware detection system applying deep neural networks
K. Xu, Y. Li, R. H. Deng, and K. Chen · 2018
Earlier work this paper cites.
A new backdoor attack in cnns by training set corruption without label poisoning
M. Barni, K. Kallas, and B. Tondi · 2019
Earlier work this paper cites.
Strip: A defence against trojan attacks on deep neural networks
Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal · 2019
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
T. Gu, B. Dolan-Gavitt, and S. Garg · 2019
Earlier work this paper cites.
Neuroninspect: Detecting backdoors in neural networks via output explanations
X. Huang, M. Alzantot, and M. Srivastava · 2019
Earlier work this paper cites.
TESSERACT: Eliminating experimental bias in malware classification across space and time
F. Pendlebury, F. Pierazzi, R. Jordaney, J. Kinder, and L. Cavallaro · 2019
Cited alongside, same era.
Universal adversarial triggers for attacking and analyzing nlp
E. Wallace, S. Feng, N. Kandpal, M. Gardner, and S. Singh · 2019
Cited alongside, same era.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao · 2019
Cited alongside, same era.
Latent backdoor attacks on deep neural networks
Y. Yao, H. Li, H. Zheng, and B. Y. Zhao · 2019
Cited alongside, same era.
Transferable clean-label poisoning attacks on deep neural nets
C. Zhu, W. R. Huang, H. Li, G. Taylor, C. Studer, and T. Goldstein · 2019
Cited alongside, same era.
On training robust PDF malware classifiers
Y. Chen, S. Wang, D. She, and S. Jana · 2020
On certifying robustness against backdoor attacks via randomized smoothing
B. Wang, X. Cao, N. Z. Gong, et al · 2020
Later among the works it cites.
RAB: Provable robustness against backdoor attacks
M. Weber, X. Xu, B. Karlas, C. Zhang, and B. Li · 2020
Later among the works it cites.
DBA: Distributed backdoor attacks against federated learning
C. Xie, K. Huang, P.-Y. Chen, and B. Li · 2020
Later among the works it cites.
T-miner: A generative approach to defend against trojan attacks on dnn-based text classification
A. Azizi, I. A. Tahmid, A. Waheed, N. Mangaokar, J. Pu, M. Javed, C. K. Reddy, and B. Viswanath · 2021
Later among the works it cites.
Blind backdoors in deep learning models
E. Bagdasaryan and V. Shmatikov · 2021
Later among the works it cites.
Deep feature space trojan attack of neural networks by controlled detoxification
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Sentinet: Detecting localized universal attacks against deep learning systems
E. Chou, F. Tramèr, and G. Pellegrino · 2020
Cited alongside, same era.
Februus: Input purification defense against trojan attacks on deep neural network systems
B. G. Doan, E. Abbasnejad, and D. C. Ranasinghe · 2020
Cited alongside, same era.
Trojannet: Embedding hidden trojan horse models in neural networks
C. Guo, R. W. Wu, and K. Q. Weinberger · 2020
Cited alongside, same era.
Sorel-20m: A large scale benchmark dataset for malicious pe detection
R. Harang and E. M. Rudd · 2020
Cited alongside, same era.
One-pixel signature: Characterizing cnn models for backdoor detection
S. Huang, W. Peng, Z. Jia, and Z. Tu · 2020
Cited alongside, same era.
Universal litmus patterns: Revealing backdoor attacks in cnns
S. Kolouri, A. Saha, H. Pirsiavash, and H. Hoffmann · 2020
Cited alongside, same era.
S. Cheng, Y. Liu, S. Ma, and X. Zhang · 2021
Later among the works it cites.
Spectre: Defending against backdoor attacks using robust statistics
J. Hayase, W. Kong, R. Somani, and S. Oh · 2021
Later among the works it cites.
Subpopulation data poisoning attacks
M. Jagielski, G. Severi, N. Pousette Harger, and A. Oprea · 2021
Later among the works it cites.
Explanation-guided backdoor poisoning attacks against malware classifiers
G. Severi, J. Meyer, S. Coull, and A. Oprea · 2021
Later among the works it cites.
Manipulating sgd with data ordering attacks
I. Shumailov, Z. Shumaylov, D. Kazhdan, Y. Zhao, N. Papernot, M. A. Erdogdu, and R. Anderson · 2021
Later among the works it cites.
Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection
D. Tang, X. Wang, H. Tang, and K. Zhang · 2021
Later among the works it cites.
Adversarial neuron pruning purifies backdoored deep models
D. Wu and Y. Wang · 2021
Later among the works it cites.
Detecting ai trojans using meta neural analysis
X. Xu, Q. Wang, H. Li, N. Borisov, C. A. Gunter, and B. Li · 2021
Later among the works it cites.
Rethinking the backdoor attacks’ triggers: A frequency perspective
Y. Zeng, W. Park, Z. M. Mao, and R. Jia · 2021
Later among the works it cites.
https://www.avast.com/en-us/technology/ai-and-machine-learning , 2022
Avast: Ai and machine learning · 2022
Closest in time.
https://www.blackberry.com/content/dam/bbcomv4/blackberry-com/en/products/resource-center/resource-library/ebooks/AI-Driven-EDR-EBook.pdf , 2022
Ai-driven edr · 2022
Closest in time.
https://www.deepinstinct.com/why-deep-instinct , 2022
Deep instinct · 2022
Closest in time.
https://www.virustotal.com/gui/home/upload , 2022
Virustotal · 2022
Closest in time.
A feature-based on-line detector to remove adversarial-backdoors by iterative demarcation
H. Fu, A. K. Veldanda, P. Krishnamurthy, S. Garg, and F. Khorrami · 2022
Closest in time.
Badencoder: Backdoor attacks to pre-trained encoders in self-supervised learning
J. Jia, Y. Liu, and N. Z. Gong · 2022
Closest in time.
Trojanzoo: Everything you ever wanted to know about neural backdoors (but were afraid to ask)
R. Pang, Z. Zhang, X. Gao, Z. Xi, S. Ji, P. Cheng, and T. Wang · 2022
Closest in time.