Fetching the paper…
Reading the bibliography…
Backdoor attacks insert malicious data into a training set so that, during inference time, it misclassifies inputs that have been patched with a backdoor trigger as the malware specified label.
G. Griffin, A. Holub, and P. Perona, “Caltech-256 object category dataset,” 2007
2007
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” 2009
2009
Earlier work this paper cites.
N. Kumar, A. C. Berg, P. N. Belhumeur, and S. K. Nayar, “Attribute and simile classifiers for face verification,” in 2009 IEEE 12th international conference on computer vision . IEEE, 2009, pp. 365–372
2009
Earlier work this paper cites.
L. Bottou, “Stochastic gradient descent tricks,” in Neural networks: Tricks of the trade . Springer, 2012, pp. 421–436
2012
Earlier work this paper cites.
F. Schomm, F. Stahl, and G. Vossen, “Marketplaces for data: an initial survey,” ACM SIGMOD Record , vol. 42, no. 1, pp. 15–26, 2013
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
Y. Le and X. Yang, “Tiny imagenet visual recognition challenge,” CS 231N , vol. 7, no. 7, p. 3, 2015
2015
Earlier work this paper cites.
Z. Liu, P. Luo, X. Wang, and X. Tang, “Deep learning face attributes in the wild,” in Proceedings of International Conference on Computer Vision (ICCV) , December 2015
2015
Earlier work this paper cites.
C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich, “Going deeper with convolutions,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2015, pp. 1–9
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 770–778
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis, “Wide residual networks,” arXiv preprint arXiv:1605.07146 , 2016
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
X. Chen, C. Liu, B. Li, K. Lu, and D. Song, “Targeted backdoor attacks on deep learning systems using data poisoning,” 2017
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in 2017 IEEE symposium on security and privacy (SP) . IEEE, 2017, pp. 3–18
2017
Cited alongside, same era.
2018
Cited alongside, same era.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in International Symposium on Research in Attacks, Intrusions, and Defenses . Springer, 2018, pp. 273–294
2018
Cited alongside, same era.
A. Athalye, L. Engstrom, A. Ilyas, and K. Kwok, “Synthesizing robust adversarial examples,” in International conference on machine learning . PMLR, 2018, pp. 284–293
2018
Cited alongside, same era.
S. Zhao, X. Ma, X. Zheng, J. Bailey, J. Chen, and Y.-G. Jiang, “Clean-label backdoor attacks on video recognition models,” 2020
2020
Later among the works it cites.
S. Li, M. Xue, B. Zhao, H. Zhu, and X. Zhang, “Invisible backdoor attacks on deep neural networks via steganography and regularization,” IEEE Transactions on Dependable and Secure Computing , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
T. A. Nguyen and A. Tran, “Input-aware dynamic backdoor attack,” Advances in Neural Information Processing Systems , vol. 33, pp. 3454–3464, 2020
2020
Later among the works it cites.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in European Conference on Computer Vision . Springer, 2020, pp. 182–199
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
M. Tan and Q. Le, “Efficientnet: Rethinking model scaling for convolutional neural networks,” in International conference on machine learning . PMLR, 2019, pp. 6105–6114
2019
Cited alongside, same era.
A. Turner, D. Tsipras, and A. Madry, “Label-consistent backdoor attacks,” 2019
2019
Cited alongside, same era.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 2019, pp. 707–723
2019
Cited alongside, same era.
2019
Cited alongside, same era.
C. Qin, J. Martens, S. Gowal, D. Krishnan, K. Dvijotham, A. Fawzi, S. De, R. Stanforth, and P. Kohli, “Adversarial robustness through local linearization,” Advances in Neural Information Processing Systems , vol. 32, 2019
2019
Cited alongside, same era.
S. Cheng, Y. Dong, T. Pang, H. Su, and J. Zhu, “Improving black-box adversarial attacks with a transfer-based prior,” Advances in neural information processing systems , vol. 32, 2019
2019
Cited alongside, same era.
A. Paszke, S. Gross, F. Massa, A. Lerer, J. Bradbury, G. Chanan, T. Killeen, Z. Lin, N. Gimelshein, L. Antiga et al. , “Pytorch: An imperative style, high-performance deep learning library,” Advances in neural information processing systems , vol. 32, pp. 8026–8037, 2019
2019
Cited alongside, same era.
2019
Cited alongside, same era.
2020
Later among the works it cites.
2020
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
Y. Li, X. Lyu, N. Koren, L. Lyu, B. Li, and X. Ma, “Anti-backdoor learning: Training clean models on poisoned data,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Later among the works it cites.
Y. Zeng, W. Park, Z. M. Mao, and R. Jia, “Rethinking the backdoor attacks’ triggers: A frequency perspective,” in ICCV , 2021
2021
Later among the works it cites.
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in ICCV , 2021
2021
Later among the works it cites.
Y. Li, T. Zhai, Y. Jiang, Z. Li, and S.-T. Xia, “Backdoor attack in the physical world,” in ICLR Workshop , 2021
2021
Later among the works it cites.
N. Manoj and A. Blum, “Excess capacity and backdoor poisoning,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Later among the works it cites.
Y. Zeng, S. Chen, W. Park, Z. Mao, M. Jin, and R. Jia, “Adversarial unlearning of backdoors via implicit hypergradient,” in International Conference on Learning Representations , 2022
2022
Closest in time.