Fetching the paper…
Reading the bibliography…
Data poisoning attacks, in which a malicious adversary aims to influence a model by injecting "poisoned" data into the training process, have attracted significant recent attention.
“Poisoning attacks with generative adversarial nets” arXiv preprint arXiv:1906.07773, 2019
Luis Muñoz-González, Bjarne Pfitzner, Matteo Russo, Javier Carnerero-Cano and Emil Lupu · 1906
Earlier work this paper cites.
“Market structure and equilibrium”
Heinrich von Stackelberg · 1934
Earlier work this paper cites.
“Iterative methods for solving minimax problems”
Yu.. Evtushenko · 1974
Earlier work this paper cites.
“The influence curve and its role in robust estimation”
Frank Hampel · 1974
Earlier work this paper cites.
“Threats to federated learning: A survey” arXiv preprint arXiv:2003.02133, 2020
Lingjuan Lyu, Han Yu and Qiang Yang · 2003
Earlier work this paper cites.
“Adversarial classification”
Nilesh Dalvi, Pedro Domingos, Sumit Sanghai and Deepak Verma · 2004
Earlier work this paper cites.
“Newton-type Methods for Minimax Optimization”
Guojun Zhang, Kaiwen Wu, Pascal Poupart and Yaoliang Yu · 2006
Earlier work this paper cites.
“Exploiting machine learning to subvert your spam filter.”
Blaine Nelson, Marco Barreno, Fuching Chi, Anthony Joseph, Benjamin Rubinstein, Udam Saini, Charles Sutton, J Tygar and Kai Xia · 2008
Earlier work this paper cites.
“Learning multiple layers of features from tiny images” tech. report, 2009
Alex Krizhevsky · 2009
Earlier work this paper cites.
“A game theoretical model for adversarial learning”
Wei Liu and Sanjay Chawla · 2009
Earlier work this paper cites.
“Mining adversarial patterns via regularized loss minimization”
Wei Liu and Sanjay Chawla · 2010
Earlier work this paper cites.
“Deep learning via hessian-free optimization”
James Martens · 2010
Earlier work this paper cites.
“Support vector machines under adversarial label noise”
Battista Biggio, Blaine Nelson and Pavel Laskov · 2011
Earlier work this paper cites.
“Poisoning attacks against support vector machines”
Battista Biggio, Blaine Nelson and Pavel Laskov · 2012
Earlier work this paper cites.
“The MNIST database of handwritten digit images for machine learning research [best of the web]”
Li Deng · 2012
Earlier work this paper cites.
“Intriguing properties of neural networks” International Conference on Learning Representation, 2014
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow and Rob Fergus · 2014
Earlier work this paper cites.
“Robust Estimators in High Dimensions without the Computational Intractability”
Ilias Diakonikolas, Gautam Kamath, Daniel. Kane, Jerry Li, Ankur Moitra and Alistair Stewart · 2016
Earlier work this paper cites.
“A Unified View on Multi-class Support Vector Classification”
Ürün Dogan, Tobias Glasmachers and Christian Igel · 2016
Earlier work this paper cites.
“Deep Residual Learning for Image Recognition”
Kaiming He, Xiangyu Zhang, Shaoqing Ren and Jian Sun · 2016
Earlier work this paper cites.
“Agnostic Estimation of Mean and Covariance”
Kevin. Lai, Anup. Rao and Santosh Vempala · 2016
Earlier work this paper cites.
“Microsoft chatbot is taught to swear on Twitter”
Jane Wakefield · 2016
Cited alongside, same era.
“Targeted backdoor attacks on deep learning systems using data poisoning” arXiv:1712.05526, 2017
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu and Dawn Song · 2017
Cited alongside, same era.
Tianyu Gu, Brendan Dolan-Gavitt and Siddharth Garg · 2017
Cited alongside, same era.
“Understanding black-box predictions via influence functions”
Pang Koh and Percy Liang · 2017
Cited alongside, same era.
“Unrolled Generative Adversarial Networks”
Luke Metz, Ben Poole, David Pfau and Jascha Sohl-Dickstein · 2017
Cited alongside, same era.
“Bullseye polytope: A scalable clean-label poisoning attack with improved transferability”
Hojjat Aghakhani, Dongyu Meng, Yu-Xiang Wang, Christopher Kruegel and Giovanni Vigna · 2021
Later among the works it cites.
“Influence functions in deep learning are fragile”
Samyadeep Basu, Philip Pope and Soheil Feizi · 2021
Later among the works it cites.
Liam Fowl, Ping-yeh Chiang, Micah Goldblum, Jonas Geiping, Arpit Bansal, Wojtek Czaja and Tom Goldstein · 2021
Later among the works it cites.
“Adversarial Examples Make Strong Poisons”
Liam Fowl, Micah Goldblum, Ping-yeh Chiang, Jonas Geiping, Wojciech Czaja and Tom Goldstein · 2021
Later among the works it cites.
“Robust unlearnable examples: Protecting data privacy against adversarial learning”
Shaopeng Fu, Fengxiang He, Yang Liu, Li Shen and Dacheng Tao · 2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
“Towards Poisoning of Deep Learning Algorithms with Back-gradient Optimization”
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil. Lupu and Fabio Roli · 2017
Cited alongside, same era.
“Deep learning is robust to massive label noise” arXiv preprint arXiv:1705.10694
David Rolnick, Andreas Veit, Serge Belongie and Nir Shavit · 2017
Cited alongside, same era.
“Certified defenses for data poisoning attacks”
Jacob Steinhardt, Pang Koh and Percy Liang · 2017
Cited alongside, same era.
“Poison Frogs! Targeted Clean-Label Poisoning Attacks on Neural Networks”
Ali Shafahi, W. Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras and Tom Goldstein · 2018
Cited alongside, same era.
“Spectral Signatures in Backdoor Attacks”
Brandon Tran, Jerry Li and Aleksander Madry · 2018
Cited alongside, same era.
“Sever: A Robust Meta-Algorithm for Stochastic Optimization”
Ilias Diakonikolas, Gautam Kamath, Daniel. Kane, Jerry Li, Jacob Steinhardt and Alistair Stewart · 2019
Cited alongside, same era.
“PyTorch: An Imperative Style, High-Performance Deep Learning Library”
Adam Paszke et al · 2019
Cited alongside, same era.
“Witches’ Brew: ial Scale Data Poisoning via Gradient Matching”
Jonas Geiping, Liam Fowl, W. Huang, Wojciech Czaja, Gavin Taylor, Michael Moeller and Tom Goldstein · 2021
Later among the works it cites.
“MaxUp: Lightweight Adversarial Training with Data Augmentation Improves Neural Network Training”
Chengyue Gong, Tongzheng Ren, Mao Ye and Qiang Liu · 2021
Later among the works it cites.
“Unlearnable Examples: Making Personal Data Unexploitable”
Hanxun Huang, Xingjun Ma, Sarah Erfani, James Bailey and Yisen Wang · 2021
Later among the works it cites.
“Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning Attacks”
Avi Schwarzschild, Micah Goldblum, Arjun Gupta, John Dickerson and Tom Goldstein · 2021
Later among the works it cites.
“Manipulating SGD with Data Ordering Attacks”
Ilia Shumailov, Zakhar Shumaylov, Dmitry Kazhdan, Yiren Zhao, Nicolas Papernot, Murat Erdogdu and Ross Anderson · 2021
Later among the works it cites.
“Model-targeted poisoning attacks with provable convergence”
Fnu Suya, Saeed Mahloujifar, Anshuman Suri, David Evans and Yuan Tian · 2021
Later among the works it cites.
Antonio Cinà et al · 2022
Closest in time.
“An equivalence between data poisoning and Byzantine gradient attacks”
Sadegh Farhadkhani, Rachid Guerraoui and Oscar Villemaud · 2022
Closest in time.
“Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses”
Micah Goldblum, Dimitris Tsipras, Chulin Xie, Xinyun Chen, Avi Schwarzschild, Dawn Song, Aleksander Madry, Bo Li and Tom Goldstein · 2022
Closest in time.
“Stronger Data Poisoning Attacks Break Data Sanitization Defenses”
Pang Koh, Jacob Steinhardt and Percy Liang · 2022
Closest in time.
“Data Poisoning Won’t Save You From Facial Recognition”
Evani Radiya-Dixit, Sanghyun Hong, Nicholas Carlini and Florian Tramer · 2022
Closest in time.
“Autoregressive Perturbations for Data Poisoning”
Pedro Sandoval-Segura, Vasu Singla, Jonas Geiping, Micah Goldblum, Tom Goldstein and David. Jacobs · 2022
Closest in time.
“Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated Learning”
Virat Shejwalkar, Amir Houmansadr, Peter Kairouz and Daniel Ramage · 2022
Closest in time.
“On implicit bias in overparameterized bilevel optimization”
Paul Vicol, Jonathan Lorraine, Fabian Pedregosa, David Duvenaud and Roger Grosse · 2022
Closest in time.
“Availability Attacks Create Shortcuts”
Da Yu, Huishuai Zhang, Wei Chen, Jian Yin and Tie-Yan Liu · 2022
Closest in time.