Fetching the paper…
Reading the bibliography…
The success of machine learning is fueled by the increasing availability of computing power and large training datasets.
Efficient global optimization of expensive black-box functions
Donald R Jones, Matthias Schonlau, and William J Welch. 1998 · 1998
Earlier work this paper cites.
Can ML be secure?. In ACM Symposium on Inf., Computer and Communications Security, ASIACCS . ACM, 16–25
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D. Joseph, and J. D. Tygar. 2006 · 2006
Earlier work this paper cites.
Paragraph: Thwarting Signature Learning by Training Maliciously. In RAID 2006 (Lecture Notes in Computer Science, Vol. 4219) . Springer, 81–105
James Newsome, Brad Karp, and Dawn Xiaodong Song. 2006 · 2006
Earlier work this paper cites.
Misleading worm signature generators using deliberate noise injection. In IEEE Symposium on Security and Privacy, S& P 2006 . 15 pp.–31
R. Perdisci, D. Dagon, Wenke Lee, P. Fogla, and M. Sharif. 2006 · 2006
Earlier work this paper cites.
Casting out Demons: Sanitizing Training Data for Anomaly Sensors. In Security and Privacy, 2008. SP 2008. IEEE Symposium on . 81 –95
G.F. Cretu, A. Stavrou, M.E. Locasto, S.J. Stolfo, and A.D. Keromytis. 2008 · 2008
Earlier work this paper cites.
Exploiting ML to Subvert Your Spam Filter. In USENIX Workshop on Large-Scale Exploits and Emergent Threats, LEET 2008 . USENIX, 1–9
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D. Joseph, Benjamin I. P. Rubinstein, Udam Saini, Charles Sutton, J. Doug Tygar, and Kai Xia. 2008 · 2008
Earlier work this paper cites.
Misleading learners: Co-opting your spam filter
Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D Joseph, Benjamin IP Rubinstein, Udam Saini, Charles Sutton, JD Tygar, and Kai Xia. 2009 · 2009
Earlier work this paper cites.
Antidote: understanding and defending against poisoning of anomaly detectors. In 9th ACM SIGCOMM Conf. on Internet Measurement . 1–14
Benjamin IP Rubinstein, Blaine Nelson, Ling Huang, Anthony D Joseph, Shing-hon Lau, Satish Rao, Nina Taft, and J Doug Tygar. 2009 · 2009
Earlier work this paper cites.
Online Anomaly Detection under Adversarial Impact. In AISTATS 2010 . JMLR, 405–412
Marius Kloft and Pavel Laskov. 2010 · 2010
Earlier work this paper cites.
Outside the closed world: On using ML for network intrusion detection. In IEEE S&P 2010 . IEEE, 305–316
Robin Sommer and Vern Paxson. 2010 · 2010
Earlier work this paper cites.
Unbiased look at dataset bias. In CVPR 2011 . IEEE, 1521–1528
Antonio Torralba and Alexei A Efros. 2011 · 2011
Earlier work this paper cites.
Random search for hyper-parameter optimization
James Bergstra and Yoshua Bengio. 2012 · 2012
Earlier work this paper cites.
Poisoning Attacks against Support Vector Machines. In ICML 2012 . icml.cc / Omnipress
Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012 · 2012
Earlier work this paper cites.
Generic Methods for Optimization-Based Modeling. In 15th Int. Conf. on Art. Intell. and Statistics, AISTATS 2012 . JMLR, 318–326
Justin Domke. 2012 · 2012
Earlier work this paper cites.
Adversarial Label Flips Attack on Support Vector Machines. In ECAI 2012 - 20th Eur. Conf. on AI. Including Prestigious Applications of AI, PAIS-2012 . IOS Press, 870–875
Han Xiao, Huang Xiao, and Claudia Eckert. 2012 · 2012
Earlier work this paper cites.
Evasion Attacks against ML at Test Time. In ML and Knowl. Disc. in Databases - Eur. Conf., ECML PKDD 2013 . Springer, 387–402
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Srndic, Pavel Laskov, Giorgio Giacinto, and Fabio Roli. 2013a · 2013
Earlier work this paper cites.
Is data clustering in adversarial settings secure?. In 6th ACM Workshop on Art. Intell. and Sec., AISec 2013 . ACM, 87–98
Battista Biggio, Ignazio Pillai, Samuel Rota Bulò, Davide Ariu, Marcello Pelillo, and Fabio Roli. 2013b · 2013
Earlier work this paper cites.
Poisoning behavioral malware clustering. In 7th ACM Workshop on Art. Intell. and Sec., AISec 2014 . ACM, 27–36
Battista Biggio, Konrad Rieck, Davide Ariu, Christian Wressnegger, Igino Corona, Giorgio Giacinto, and Fabio Roli. 2014 · 2014
Earlier work this paper cites.
Robust Logistic Regression and Classification. In Advances in Neural Inf. Proc. Sys., NIPS . 253–261
Jiashi Feng, Huan Xu, Shie Mannor, and Shuicheng Yan. 2014 · 2014
Earlier work this paper cites.
Explaining and Harnessing Adversarial Examples. In ICLR 2015
Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015 · 2015
Earlier work this paper cites.
Gradient-based Hyperparameter Optimization through Reversible Learning. In 32nd Int. Conf. on ML, ICML 2015 . JMLR, 2113–2122
Dougal Maclaurin, David Duvenaud, and Ryan P. Adams. 2015 · 2015
Earlier work this paper cites.
Using Machine Teaching to Identify Optimal Training-Set Attacks on Machine Learners. In AAAI . 2871–2877
Shike Mei and Xiaojin Zhu. 2015 · 2015
Earlier work this paper cites.
Is Feature Selection Secure against Training Data Poisoning?. In 32nd Int. Conf. on ML, ICML 2015 . JMLR, 1689–1698
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli. 2015a · 2015
Earlier work this paper cites.
Support vector machines under adversarial label contamination
Huang Xiao, Battista Biggio, Blaine Nelson, Han Xiao, Claudia Eckert, and Fabio Roli. 2015b · 2015
Earlier work this paper cites.
Optimizing deep learning hyper-parameters through an evolutionary algorithm. In Workshop on ML in High-Performance Computing Environments . 1–5
Steven R Young, Derek C Rose, Thomas P Karnowski, Seung-Hwan Lim, and Robert M Patton. 2015 · 2015
Earlier work this paper cites.
Curie: A method for protecting SVM Classifier from Poisoning Attack
Ricky Laishram and Vir Virander Phoha. 2016 · 2016
Earlier work this paper cites.
Transferability in ML: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016 · 2016
Earlier work this paper cites.
Stealing ML Models via Prediction APIs. In USENIX Sec. Symp. 601–618
Florian Tramèr, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016 · 2016
Earlier work this paper cites.
Vulnerability of Deep Reinforcement Learning to Policy Induction Attacks. In ML and Data Mining in Pattern Recognition - 13th Int. Conf., MLDM 2017 . Springer, 262–275
Vahid Behzadan and Arslan Munir. 2017 · 2017
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017a · 2017
Earlier work this paper cites.
Infinity-Norm Support Vector Machines Against Adversarial Label Contamination. In ITASEC (CEUR Workshop Proceedings, Vol. 1816) . CEUR-WS.org, 106–115
Ambra Demontis, Battista Biggio, Giorgio Fumera, Giorgio Giacinto, and Fabio Roli. 2017 · 2017
Earlier work this paper cites.
Reinforcement learning with a corrupted reward channel. In 26th Int. Joint Conf. on AI, IJCAI 2017 . 4705–4713
Tom Everitt, Victoria Krakovna, Laurent Orseau, and Shane Legg. 2017 · 2017
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the ML model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017 · 2017
Earlier work this paper cites.
Understanding Black-box Predictions via Influence Functions. In Int. Conf. on ML, ICML . PMLR, 1885–1894
Pang Wei Koh and Percy Liang. 2017 · 2017
Earlier work this paper cites.
Hyperband: A novel bandit-based approach to hyperparameter optimization
Lisha Li, Kevin Jamieson, Giulia DeSalvo, Afshin Rostamizadeh, and Ameet Talwalkar. 2017 · 2017
Earlier work this paper cites.
Robust Linear Regression Against Training Data Poisoning. In 10th ACM Workshop on Art. Intell. and Sec., AISec 2017 . ACM, 91–102
Chang Liu, Bo Li, Yevgeniy Vorobeychik, and Alina Oprea. 2017a · 2017
Earlier work this paper cites.
Neural Trojans. In IEEE Int. Conf. on Computer Design, ICCD 2017 . 45–48
Yuntao Liu, Yang Xie, and Ankur Srivastava. 2017b · 2017
Earlier work this paper cites.
Particle swarm optimization for hyper-parameter selection in deep neural networks. In the genetic and evolutionary computation conference . 481–488
Pablo Ribalta Lorenzo, Jakub Nalepa, Michal Kawulok, Luciano Sanchez Ramos, and José Ranilla Pastor. 2017 · 2017
Earlier work this paper cites.
Towards Poisoning of Deep Learning Algorithms with Back-gradient Optimization. In 10th ACM Workshop on Art. Intell. and Sec., AISec 2017 . ACM, 27–38
Luis Muñoz-González, Battista Biggio, Ambra Demontis, Andrea Paudice, Vasin Wongrassamee, Emil C. Lupu, and Fabio Roli. 2017 · 2017
Earlier work this paper cites.
Practical Black-Box Attacks against ML. In ACM Asia Conf. on Computer and Communications Security, AsiaCCS 2017 . ACM, 506–519
Nicolas Papernot, Patrick D. McDaniel, Ian J. Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2017 · 2017
Earlier work this paper cites.
Certified Defenses for Data Poisoning Attacks. In Neural Inf. Proc. Sys., NIPS . 3517–3529
Jacob Steinhardt, Pang Wei Koh, and Percy Liang. 2017 · 2017
Earlier work this paper cites.
Generative Poisoning Attack Method Against Neural Networks
Chaofei Yang, Qing Wu, Hai Li, and Yiran Chen. 2017 · 2017
Earlier work this paper cites.
A game-theoretic analysis of label flipping attacks on distributed support vector machines. In Conf. on Inf. Sciences and Sys., CISS 2017 . IEEE, 1–6
Rui Zhang and Quanyan Zhu. 2017 · 2017
Earlier work this paper cites.
Detecting poisoning attacks on ML in iot environments. In IEEE Int. congress on internet of things, ICIOT 2018 . IEEE, 57–64
Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, Amir Safavi, and Rui Zhang. 2018 · 2018
Earlier work this paper cites.
Wild patterns: Ten years after the rise of adversarial ML
Battista Biggio and Fabio Roli. 2018 · 2018
Earlier work this paper cites.
Adversarial attacks and defences: A survey
Anirban Chakraborty, Manaar Alam, Vishal Dey, Anupam Chattopadhyay, and Debdeep Mukhopadhyay. 2018 · 2018
Earlier work this paper cites.
Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering
Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018 · 2018
Earlier work this paper cites.
Bilevel Programming for Hyperparameter Optimization and Meta-Learning. In ICML , Vol. 80. PMLR, 1563–1572
Luca Franceschi, Paolo Frasconi, Saverio Salzo, Riccardo Grazzi, and Massimiliano Pontil. 2018 · 2018
Earlier work this paper cites.
Attack strength vs. detectability dilemma in adversarial ML. In Int. Joint Conf. on Neural Networks, IJCNN 2018 . IEEE, 1–8
Christopher Frederickson, Michael Moore, Glenn Dawson, and Robi Polikar. 2018 · 2018
Earlier work this paper cites.
Motivating the rules of the game for adversarial example research
Justin Gilmer, Ryan P Adams, Ian Goodfellow, David Andersen, and George E Dahl. 2018 · 2018
Earlier work this paper cites.
Contamination Attacks and Mitigation in Multi-Party ML
Jamie Hayes and Olga Ohrimenko. 2018 · 2018
Earlier work this paper cites.
Manipulating ML: Poisoning attacks and countermeasures for regression learning. In IEEE Symposium on Security and Privacy, S&P 2018 . IEEE, 19–35
Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li. 2018 · 2018
Earlier work this paper cites.
Data poisoning attacks in contextual bandits. In Int. Conf. on Decision and Game Theory for Security . Springer, 186–204
Yuzhe Ma, Kwang-Sung Jun, Lihong Li, and Xiaojin Zhu. 2018 · 2018
Earlier work this paper cites.
Adversarial Robustness Toolbox v1.2.0
Maria-Irina Nicolae, Mathieu Sinn, Minh Ngoc Tran, Beat Buesser, Ambrish Rawat, Martin Wistuba, Valentina Zantedeschi, Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, Ian Molloy, and Ben Edwards. 2018 · 2018
Earlier work this paper cites.
Label sanitization against label flipping poisoning attacks. In Joint Eur. Conf. on ML and Knowledge Discovery in Databases . Springer, 5–15
Andrea Paudice, Luis Muñoz-González, and Emil C Lupu. 2018 · 2018
Earlier work this paper cites.
Poison Frogs! Targeted Clean-Label Poisoning Attacks on Neural Networks. In Advances in Neural Inf. Proc. Sys., NeurIPS 2018 . 6106–6116
Ali Shafahi, W. Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018 · 2018
Earlier work this paper cites.
When does ML { \{ FAIL } \} ? generalized transferability for evasion and poisoning attacks. In USENIX Sec. Symp. 1299–1316
Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daume III, and Tudor Dumitras. 2018 · 2018
Earlier work this paper cites.
Adversarial attack and defense on graph data: A survey
Lichao Sun, Yingtong Dou, Carl Yang, Ji Wang, Philip S Yu, Lifang He, and Bo Li. 2018 · 2018
Earlier work this paper cites.
Spectral signatures in backdoor attacks. In Conf. on Neural Inf. Proc. Sys., NIPS 2018 . 8011–8021
Brandon Tran, Jerry Li, and Aleksander Mądry. 2018 · 2018
Earlier work this paper cites.
A New Backdoor Attack in CNNS by Training Set Corruption Without Label Poisoning. In 2019 IEEE Int. Conf. on Image Proc., ICIP 2019 . IEEE, 101–105
Mauro Barni, Kassem Kallas, and Benedetta Tondi. 2019 · 2019
Earlier work this paper cites.
Analyzing Federated Learning through an Adversarial Lens. In 36th Int. Conf. on ML, ICML 2019 . PMLR, 634–643
Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin B. Calo. 2019 · 2019
Earlier work this paper cites.
Adversarial Attacks on Node Embeddings via Graph Poisoning. In ICML . 695–704
Aleksandar Bojchevski and Stephan Günnemann. 2019 · 2019
Earlier work this paper cites.
Understanding Distributed Poisoning Attack in Federated Learning. In IEEE Int. Conf. on Parallel and Distributed Sys. 233–239
Di Cao, Shan Chang, Zhijian Lin, Guohua Liu, and Donghong Sun. 2019 · 2019
Earlier work this paper cites.
On evaluating adversarial robustness
Nicholas Carlini, Anish Athalye, Nicolas Papernot, Wieland Brendel, Jonas Rauber, Dimitris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin. 2019 · 2019
Earlier work this paper cites.
DeepInspect: A Black-box Trojan Detection and Mitigation Framework for Deep Neural Networks. In Int. Joint Conf. on AI, IJCAI 2019 . 4658–4664
Huili Chen, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar. 2019 · 2019
Earlier work this paper cites.
Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning Attacks. In USENIX Sec. Symp. USENIX Association, 321–338
Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019 · 2019
Earlier work this paper cites.
Sever: A robust meta-algorithm for stochastic optimization. In Int. Conf. on ML . PMLR, 1596–1606
Ilias Diakonikolas, Gautam Kamath, Daniel Kane, Jerry Li, Jacob Steinhardt, and Alistair Stewart. 2019 · 2019
Earlier work this paper cites.
Learning to Confuse: Generating Training Time Adversarial Data with Auto-Encoder. In NeurIPS
Ji Feng, Qi-Zhi Cai, and Zhi-Hua Zhou. 2019 · 2019
Earlier work this paper cites.
Strip: A defence against trojan attacks on deep neural networks. In Computer Security Applications Conf. 113–125
Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith C Ranasinghe, and Surya Nepal. 2019 · 2019
Cited alongside, same era.
Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in AI Systems
Wenbo Guo, Lun Wang, Xinyu Xing, Min Du, and Dawn Song. 2019 · 2019
Cited alongside, same era.
Neuroninspect: Detecting backdoors in neural networks via output explanations
Xijie Huang, Moustafa Alzantot, and Mani Srivastava. 2019 · 2019
Cited alongside, same era.
Deceptive reinforcement learning under adversarial manipulations on cost signals. In Int. Conf. on Decision and Game Theory for Security . Springer, 217–237
Yunhan Huang and Quanyan Zhu. 2019 · 2019
Cited alongside, same era.
Trojaning Language Models for Fun and Profit
Xinyang Zhang, Zheng Zhang, and Ting Wang. 2020c · 2020
Later among the works it cites.
Clean-Label Backdoor Attacks on Video Recognition Models. In IEEE/CVF Int. Conf. on Computer Vision, ICCV 2020 . IEEE, 14431–14440
Shihao Zhao, Xingjun Ma, Xiang Zheng, James Bailey, Jingjing Chen, and Yu-Gang Jiang. 2020b · 2020
Later among the works it cites.
Backdoor Embedding in Convolutional Neural Network Models via Invisible Perturbation. In CODASPY ’20: Tenth ACM Conf. on Data and Application Security and Privacy 2020 . ACM, 97–108
Haoti Zhong, Cong Liao, Anna Cinzia Squicciarini, Sencun Zhu, and David J. Miller. 2020 · 2020
Later among the works it cites.
Gangsweep: Sweep out neural backdoors by gan. In 28th ACM Int. Conf. on Multimedia . 3173–3181
Liuwan Zhu, Rui Ning, Cong Wang, Chunsheng Xin, and Hongyi Wu. 2020 · 2020
Later among the works it cites.
Bullseye polytope: A scalable clean-label poisoning attack with improved transferability. In EuroS&P . 159–178
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Xuanqing Liu, Si Si, Jerry Zhu, Yang Li, and Cho-Jui Hsieh. 2019b · 2019
Cited alongside, same era.
ABS: Scanning Neural Networks for Back-doors by Artificial Brain Stimulation. In ACM SIGSAC Conf. on Computer and Communications Security, CCS 2019 . ACM, 1265–1282
Yingqi Liu, Wen-Chuan Lee, Guanhong Tao, Shiqing Ma, Yousra Aafer, and Xiangyu Zhang. 2019a · 2019
Cited alongside, same era.
Data Poisoning against Differentially-Private Learners: Attacks and Defenses. In IJCAI . 4732–4738
Yuzhe Ma, Xiaojin Zhu, and Justin Hsu. 2019 · 2019
Cited alongside, same era.
secml: A Python Library for Secure and Explainable ML
Marco Melis, Ambra Demontis, Maura Pintor, Angelo Sotgiu, and Battista Biggio. 2019 · 2019
Cited alongside, same era.
Defending neural backdoors via generative distribution modeling. In NeurIPS . 14004–14013
Ximing Qiao, Yukun Yang, and Hai Li. 2019 · 2019
Cited alongside, same era.
Can you really backdoor federated learning?
Ziteng Sun, Peter Kairouz, Ananda Theertha Suresh, and H Brendan McMahan. 2019 · 2019
Cited alongside, same era.
Label-consistent backdoor attacks
Alexander Turner, Dimitris Tsipras, and Aleksander Madry. 2019 · 2019
Cited alongside, same era.
Model agnostic defence against backdoor attacks in ML
Sakshi Udeshi, Shanshan Peng, Gerald Woo, Lionell Loh, Louth Rawshan, and Sudipta Chattopadhyay. 2019 · 2019
Cited alongside, same era.
Hojjat Aghakhani, Dongyu Meng, Yu-Xiang Wang, Christopher Kruegel, and Giovanni Vigna. 2021 · 2021
Later among the works it cites.
Poisoning Deep Reinforcement Learning Agents with In-Distribution Triggers
Chace Ashcraft and Kiran Karra. 2021 · 2021
Later among the works it cites.
Baseline Pruning-Based Approach to Trojan Detection in Neural Networks
Peter Bajcsy and Michael Majurski. 2021 · 2021
Later among the works it cites.
Defense Against Reward Poisoning Attacks in Reinforcement Learning
Kiarash Banihashem, Adish Singla, and Goran Radanovic. 2021 · 2021
Later among the works it cites.
Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff. In IEEE ICASSP 2021 . IEEE, 3855–3859
Eitan Borgnia, Valeriia Cherepanova, Liam Fowl, Amin Ghiasi, Jonas Geiping, Micah Goldblum, Tom Goldstein, and Arjun Gupta. 2021a · 2021
Later among the works it cites.
Eitan Borgnia, Jonas Geiping, Valeriia Cherepanova, Liam Fowl, Arjun Gupta, Amin Ghiasi, Furong Huang, Micah Goldblum, and Tom Goldstein. 2021b · 2021
Later among the works it cites.
Regularization Can Help Mitigate Poisoning Attacks… with the Right Hyperparameters
Javier Carnerero-Cano, Luis Muñoz-González, Phillippa Spencer, and Emil C Lupu. 2021 · 2021
Later among the works it cites.
Property Inference From Poisoning
Melissa Chase, Esha Ghosh, and Saeed Mahloujifar. 2021 · 2021
Later among the works it cites.
Badnl: Backdoor attacks against nlp models. In ICML Workshop on Adversarial ML (2021)
Xiaoyi Chen, Ahmed Salem, Michael Backes, Shiqing Ma, and Yang Zhang. 2021 · 2021
Later among the works it cites.
Deep Feature Space Trojan Attack of Neural Networks by Controlled Detoxification. In Thirty-Fifth AAAI Conf. on AI 2021 . AAAI Press, 1148–1156
Siyuan Cheng, Yingqi Liu, Shiqing Ma, and Xiangyu Zhang. 2021 · 2021
Later among the works it cites.
Backdoor Learning Curves: Explaining Backdoor Poisoning Beyond Influence Functions
Antonio Emanuele Cinà, Kathrin Grosse, Sebastiano Vascon, Ambra Demontis, Battista Biggio, Fabio Roli, and Marcello Pelillo. 2021 · 2021
Later among the works it cites.
The Hammer and the Nut: Is Bilevel Optimization Really Needed to Poison Linear Classifiers?. In Int. Joint Conf. on Neural Networks, IJCNN 2021 . IEEE, 1–8
Antonio Emanuele Cinà, Sebastiano Vascon, Ambra Demontis, Battista Biggio, Fabio Roli, and Marcello Pelillo. 2021 · 2021
Later among the works it cites.
LIRA: Learnable, Imperceptible and Robust Backdoor Attacks. In IEEE ICCV . 11966–11976
Khoa Doan, Yingjie Lao, Weijie Zhao, and Ping Li. 2021 · 2021
Later among the works it cites.
Black-box Detection of Backdoor Attacks with Limited Information and Data. In ICCV
Yinpeng Dong, Xiao Yang, Zhijie Deng, Tianyu Pang, Zihao Xiao, Hang Su, and Jun Zhu. 2021 · 2021
Later among the works it cites.
Preventing unauthorized use of proprietary data: Poisoning for secure dataset release
Liam Fowl, Ping-yeh Chiang, Micah Goldblum, Jonas Geiping, Arpit Bansal, Wojtek Czaja, and Tom Goldstein. 2021a · 2021
Later among the works it cites.
What Doesn’t Kill You Makes You Robust (er): Adversarial Training against Poisons and Backdoors
Jonas Geiping, Liam Fowl, Gowthami Somepalli, Micah Goldblum, Michael Moeller, and Tom Goldstein. 2021b · 2021
Later among the works it cites.
Witches’ Brew: Industrial Scale Data Poisoning via Gradient Matching. In ICLR 2021 . OpenReview
Jonas Geiping, Liam H. Fowl, W. Ronny Huang, Wojciech Czaja, Gavin Taylor, Michael Moeller, and Tom Goldstein. 2021a · 2021
Later among the works it cites.
Subpopulation data poisoning attacks. In ACM SIGSAC Conf. on Computer and Communications Security, CCS 2021 . 3104–3122
Matthew Jagielski, Giorgio Severi, Niklas Pousette Harger, and Alina Oprea. 2021 · 2021
Later among the works it cites.
Defense against neural trojan attacks: A survey
Sara Kaviani and Insoo Sohn. 2021 · 2021
Later among the works it cites.
Can You Hear It? Backdoor Attacks via Ultrasonic Triggers
Stefanos Koffas, Jing Xu, Mauro Conti, and Stjepan Picek. 2021 · 2021
Later among the works it cites.
Universal litmus patterns: Revealing backdoor attacks in cnns. In IEEE/CVF Int. Conf. on Computer Vision, ICCV 2021 . 301–310
Soheil Kolouri, Aniruddha Saha, Hamed Pirsiavash, and Heiko Hoffmann. 2020 · 2021
Later among the works it cites.
Deep Partition Aggregation: Provable Defenses against General Poisoning Attacks. In ICLR 2021
Alexander Levine and Soheil Feizi. 2021 · 2021
Later among the works it cites.
Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks
Yige Li, Nodens Koren, Lingjuan Lyu, Xixiang Lyu, Bo Li, and Xingjun Ma. 2021a · 2021
Later among the works it cites.
Invisible Backdoor Attack With Sample-Specific Triggers. In IEEE/CVF Int. Conf. on Computer Vision, ICCV 2021 . 16463–16472
Yuezun Li, Yiming Li, Baoyuan Wu, Longkang Li, Ran He, and Siwei Lyu. 2021b · 2021
Later among the works it cites.
Excess capacity and backdoor poisoning
Naren Manoj and Avrim Blum. 2021 · 2021
Later among the works it cites.
How Robust are Randomized Smoothing based Defenses to Data Poisoning?. In IEEE/CVF Int. Conf. on Computer Vision, ICCV 2021 . 13244–13253
Akshay Mehra, Bhavya Kailkhura, Pin-Yu Chen, and Jihun Hamm. 2021 · 2021
Later among the works it cites.
WaNet - Imperceptible Warping-based Backdoor Attack. In ICLR, 2021 . OpenReview.net
Tuan Anh Nguyen and Anh Tuan Tran. 2021 · 2021
Later among the works it cites.
Indicators of Attack Failure: Debugging and Improving Optimization of Adversarial Examples
Maura Pintor, Luca Demetrio, Angelo Sotgiu, Giovanni Manca, Ambra Demontis, Nicholas Carlini, Battista Biggio, and Fabio Roli. 2021 · 2021
Later among the works it cites.
Just how toxic is data poisoning? a unified benchmark for backdoor and data poisoning attacks. In Int. Conf. on ML, ICML 2021 . PMLR, 9389–9398
Avi Schwarzschild, Micah Goldblum, Arjun Gupta, John P Dickerson, and Tom Goldstein. 2021 · 2021
Later among the works it cites.
Explanation-Guided Backdoor Poisoning Attacks Against Malware Classifiers. In USENIX Sec. Symp
Giorgio Severi, Jim Meyer, Scott Coull, and Alina Oprea. 2021 · 2021
Later among the works it cites.
Backdoor Scanning for Deep Neural Networks through K-Arm Optimization
Guangyu Shen, Yingqi Liu, Guanhong Tao, Shengwei An, Qiuling Xu, Siyuan Cheng, Shiqing Ma, and Xiangyu Zhang. 2021 · 2021
Later among the works it cites.
Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch
Hossein Souri, Micah Goldblum, Liam Fowl, Rama Chellappa, and Tom Goldstein. 2021 · 2021
Later among the works it cites.
Can Shape Structure Features Improve Model Robustness under Diverse Adversarial Settings?. In IEEE CVF Int. Conf. on Computer Vision . 7526–7535
Mingjie Sun, Zichao Li, Chaowei Xiao, Haonan Qiu, Bhavya Kailkhura, Mingyan Liu, and Bo Li. 2021 · 2021
Later among the works it cites.
Demon in the Variant: Statistical Analysis of { \{ DNNs } \} for Robust Backdoor Contamination Detection
Di Tang, XiaoFeng Wang, Haixu Tang, and Kehuan Zhang. 2021 · 2021
Later among the works it cites.
NNoculation: Catching BadNets in the Wild. In 14th ACM Workshop on AI and Security . 49–60
Akshaj Kumar Veldanda, Kang Liu, Benjamin Tan, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri, Brendan Dolan-Gavitt, and Siddharth Garg. 2021 · 2021
Later among the works it cites.
With Great Dispersion Comes Greater Resilience: Efficient Poisoning Attacks and Defenses for Linear Regression Models
Jialin Wen, Benjamin Zi Hao Zhao, Minhui Xue, Alina Oprea, and Haifeng Qian. 2021 · 2021
Later among the works it cites.
Backdoor Attacks Against Deep Learning Sys. in the Physical World
Emily Wenger, Josephine Passananti, Arjun Nitin Bhagoji, Yuanshun Yao, Haitao Zheng, and Ben Y. Zhao. 2021 · 2021
Later among the works it cites.
Adversarial Neuron Pruning Purifies Backdoored Deep Models. In NeurIPS
Dongxian Wu and Yisen Wang. 2021 · 2021
Later among the works it cites.
Graph Backdoor. In USENIX Sec. Symp. 1523–1540
Zhaohan Xi, Ren Pang, Shouling Ji, and Ting Wang. 2021 · 2021
Later among the works it cites.
L-Red: Efficient Post-Training Detection of Imperceptible Backdoor Attacks Without Access to the Training Set. In IEEE Int. Conf. on Acoustics, Speech and Signal Proc., ICASSP 2021 . IEEE, 3745–3749
Zhen Xiang, David J Miller, and George Kesidis. 2021a · 2021
Later among the works it cites.
Reverse engineering imperceptible backdoor attacks on deep neural networks for detection and training set cleansing
Zhen Xiang, David J Miller, and George Kesidis. 2021b · 2021
Later among the works it cites.
TAD: Trigger Approximation based Black-box Trojan Detection for AI
Xinqiao Zhang, Huili Chen, and Farinaz Koushanfar. 2021a · 2021
Later among the works it cites.
Bridging mode connectivity in loss landscapes and adversarial robustness. In ICLR, 2021
Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin. 2020a · 2021
Later among the works it cites.
CLEAR: Clean-Up Sample-Targeted Backdoor in Neural Networks. In IEEE/CVF Int. Conf. on Computer Vision, ICCV 2021 . 16453–16462
Liuwan Zhu, Rui Ning, Chunsheng Xin, Chonggang Wang, and Hongyi Wu. 2021 · 2021
Later among the works it cites.
On Collective Robustness of Bagging Against Data Poisoning. In ICML
Ruoxin Chen, Zenan Li, Jie Li, Junchi Yan, and Chentao Wu. 2022 · 2022
Closest in time.
Energy-Latency Attacks via Sponge Poisoning
Antonio Emanuele Cinà, Ambra Demontis, Battista Biggio, Fabio Roli, and Marcello Pelillo. 2022a · 2022
Closest in time.
Machine Learning Security against Data Poisoning: Are We There Yet?
Antonio Emanuele Cinà, Kathrin Grosse, Ambra Demontis, Battista Biggio, Fabio Roli, and Marcello Pelillo. 2022b · 2022
Closest in time.
A black-box adversarial attack for poisoning clustering
Antonio Emanuele Cinà, Alessandro Torcinovich, and Marcello Pelillo. 2022c · 2022
Closest in time.
Dataset Security for Machine Learning: Data Poisoning, Backdoor Attacks, and Defenses
Micah Goldblum, Dimitris Tsipras, Chulin Xie, Xinyun Chen, Avi Schwarzschild, Dawn Song, Aleksander Madry, Bo Li, and Tom Goldstein. 2022 · 2022
Closest in time.
Planting undetectable backdoors in machine learning models
Shafi Goldwasser, Michael P Kim, Vinod Vaikuntanathan, and Or Zamir. 2022 · 2022
Closest in time.
Backdoor Smoothing: Demystifying Backdoor Attacks on Deep Neural Networks
Kathrin Grosse, Taesung Lee, Battista Biggio, Youngja Park, Michael Backes, and Ian Molloy. 2022 · 2022
Closest in time.
AEVA: Black-box Backdoor Detection Using Adversarial Extreme Value Analysis. In ICLR,2022
Junfeng Guo, Ang Li, and Cong Liu. 2022 · 2022
Closest in time.
Trigger Hunting with a Topological Prior for Trojan Detection. In ICLR, 2022
Xiaoling Hu, Xiao Lin, Michael Cogswell, Yi Yao, Susmit Jha, and Chao Chen. 2022 · 2022
Closest in time.
Backdoor Defense via Decoupling the Training Process. In ICLR, 2022
Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, and Kui Ren. 2022 · 2022
Closest in time.
Stronger data poisoning attacks break data sanitization defenses
Pang Wei Koh, Jacob Steinhardt, and Percy Liang. 2022 · 2022
Closest in time.
Traceback of Targeted Data Poisoning Attacks in Neural Networks. In USENIX Sec. Symp. USENIX Association
Shawn Shan, Arjun Nitin Bhagoji, Haitao Zheng, and Ben Y Zhao. 2022 · 2022
Closest in time.
Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Federated Learning. In IEEE Symposium on Security and Privacy
Virat Shejwalkar, Amir Houmansadr, Peter Kairouz, and Daniel Ramage. 2022 · 2022
Closest in time.
A Comprehensive Survey on Poisoning Attacks and Countermeasures in Machine Learning
Zhiyi Tian, Lei Cui, Jie Liang, and Shui Yu. 2022 · 2022
Closest in time.
Improved Certified Defenses against Data Poisoning with (Deterministic) Finite Aggregation. In ICML . PMLR, 22769–22783
Wenxiao Wang, Alexander J Levine, and Soheil Feizi. 2022 · 2022
Closest in time.
Post-Training Detection of Backdoor Attacks for Two-Class and Multi-Attack Scenarios. In ICLR,2022
Zhen Xiang, David Miller, and George Kesidis. 2022 · 2022
Closest in time.
Not All Poisons are Created Equal: Robust Training against Data Poisoning. In ICML . PMLR, 25154–25165
Yu Yang, Tian Yu Liu, and Baharan Mirzasoleiman. 2022 · 2022
Closest in time.
Adversarial Unlearning of Backdoors via Implicit Hypergradient. In ICLR, 2022
Yi Zeng, Si Chen, Won Park, Zhuoqing Mao, Ming Jin, and Ruoxi Jia. 2022 · 2022
Closest in time.
Machine Learning Security in Industry: A Quantitative Survey
Kathrin Grosse, Lukas Bieringer, Tarek Richard Besold, Battista Biggio, and Katharina Krombholz. 2023 · 2023
Closest in time.
Latent backdoor attacks on deep neural networks. In ACM SIGSAC Conf. on Computer and Communications Security, CCS 2019 . 2041–2055
Yuanshun Yao, Huiying Li, Haitao Zheng, and Ben Y Zhao. 2019 · 2055
Closest in time.