Fetching the paper…
Reading the bibliography…
Deep neural networks are vulnerable to Trojan attacks.
Color in business, science and industry
Deane B Judd · 1952
Earlier work this paper cites.
The influence curve and its role in robust estimation
Frank R Hampel · 1974
Earlier work this paper cites.
An Adaptive Algorithm for Spatial Greyscale
Robert W. Floyd and Louis Steinberg · 1976
Earlier work this paper cites.
The representation of colours in the cerebral cortex
Semir Zeki · 1980
Earlier work this paper cites.
Color image quantization for frame buffer display
Paul Heckbert · 1982
Earlier work this paper cites.
Polymorphism of the long-wavelength cone in normal human colour vision
Jay Neitz and Gerald H Jacobs · 1986
Earlier work this paper cites.
Retinal receptors in rodents maximally sensitive to ultraviolet light
Gerald H Jacobs, Jay Neitz, and Jess F Deegan · 1991
Earlier work this paper cites.
Void-and-cluster method for dither array generation
Robert A Ulichney · 1993
Earlier work this paper cites.
The local k-means algorithm for colour image quantization
Oleg Verevka · 1995
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
Human vision models for perceptually optimized image processing–a review
Marcus J Nadenau, Stefan Winkler, David Alleysson, and Murat Kunt · 2000
Earlier work this paper cites.
Color quantization using octrees
Dan S Bloomberg · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
Improving the performance of k-means for color quantization
M Emre Celebi · 2011
Earlier work this paper cites.
Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition
Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel · 2012
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep learning face attributes in the wild
Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang · 2015
Earlier work this paper cites.
Limitations of the ssim quality metric in the context of diagnostic imaging
Jean-François Pambrun and Rita Noumeir · 2015
Earlier work this paper cites.
Faster r-cnn: Towards real-time object detection with region proposal networks
Shaoqing Ren, Kaiming He, Ross Girshick, and Jian Sun · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Identity mappings in deep residual networks
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Simple gradient-based error-diffusion method
Xiangyu Y Hu · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
Deeplab: Semantic image segmentation with deep convolutional nets, atrous convolution, and fully connected crfs
Liang-Chieh Chen, George Papandreou, Iasonas Kokkinos, Kevin Murphy, and Alan L Yuille · 2017
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Earlier work this paper cites.
Improved regularization of convolutional neural networks with cutout
Terrance DeVries and Graham W Taylor · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Cited alongside, same era.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger · 2017
Cited alongside, same era.
Grad-cam: Visual explanations from deep networks via gradient-based localization
Ramprasaath R Selvaraju, Michael Cogswell, Abhishek Das, Ramakrishna Vedantam, Devi Parikh, and Dhruv Batra · 2017
Cited alongside, same era.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Cited alongside, same era.
Robust anomaly detection and backdoor attack detection via differential privacy
Min Du, Ruoxi Jia, and Dawn Song · 2020
Later among the works it cites.
On the effectiveness of mitigating data poisoning attacks with gradient shaping
Sanghyun Hong, Varun Chandrasekaran, Yiğitcan Kaya, Tudor Dumitraş, and Nicolas Papernot · 2020
Later among the works it cites.
Supervised contrastive learning
Prannay Khosla, Piotr Teterwak, Chen Wang, Aaron Sarna, Yonglong Tian, Phillip Isola, Aaron Maschinot, Ce Liu, and Dilip Krishnan · 2020
Later among the works it cites.
Universal litmus patterns: Revealing backdoor attacks in cnns
Soheil Kolouri, Aniruddha Saha, Hamed Pirsiavash, and Heiko Hoffmann · 2020
Later among the works it cites.
Shaofeng Li, Shiqing Ma, Minhui Xue, and Benjamin Zi Hao Zhao · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Aggregated residual transformations for deep neural networks
Saining Xie, Ross Girshick, Piotr Dollár, Zhuowen Tu, and Kaiming He · 2017
Cited alongside, same era.
Unpaired image-to-image translation using cycle-consistent adversarial networks
Jun-Yan Zhu, Taesung Park, Phillip Isola, and Alexei A Efros · 2017
Cited alongside, same era.
Sentinet: Detecting physical attacks against deep learning systems
Edward Chou, Florian Tramèr, Giancarlo Pellegrino, and Dan Boneh · 2018
Cited alongside, same era.
Squeeze-and-excitation networks
Jie Hu, Li Shen, and Gang Sun · 2018
Cited alongside, same era.
Fine-pruning: Defending against backdooring attacks on deep neural networks
Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2018
Cited alongside, same era.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2018
Cited alongside, same era.
Mobilenetv2: Inverted residuals and linear bottlenecks
Mark Sandler, Andrew Howard, Menglong Zhu, Andrey Zhmoginov, and Liang-Chieh Chen · 2018
Cited alongside, same era.
Later among the works it cites.
Composite backdoor attack for deep neural network by mixing existing benign features
Junyu Lin, Lei Xu, Yingqi Liu, and Xiangyu Zhang · 2020
Later among the works it cites.
Reflection backdoor: A natural backdoor attack on deep neural networks
Yunfei Liu, Xingjun Ma, James Bailey, and Feng Lu · 2020
Later among the works it cites.
Input-aware dynamic backdoor attack
Tuan Anh Nguyen and Anh Tran · 2020
Later among the works it cites.
Nnoculation: broad spectrum and targeted treatment of backdoored dnns
Akshaj Kumar Veldanda, Kang Liu, Benjamin Tan, Prashanth Krishnamurthy, Farshad Khorrami, Ramesh Karri, Brendan Dolan-Gavitt, and Siddharth Garg · 2020
Later among the works it cites.
Bridging mode connectivity in loss landscapes and adversarial robustness
Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin · 2020
Later among the works it cites.
Poisoning and backdooring contrastive learning
Nicholas Carlini and Andreas Terzis · 2021
Later among the works it cites.
Deep feature space trojan attack of neural networks by controlled detoxification
Siyuan Cheng, Yingqi Liu, Shiqing Ma, and Xiangyu Zhang · 2021
Later among the works it cites.
Lira: Learnable, imperceptible and robust backdoor attacks
Khoa Doan, Yingjie Lao, Weijie Zhao, and Ping Li · 2021
Later among the works it cites.
Spectre: Defending against backdoor attacks using robust statistics
Jonathan Hayase, Weihao Kong, Raghav Somani, and Sewoong Oh · 2021
Later among the works it cites.
Neural attention distillation: Erasing backdoor triggers from deep neural networks
Yige Li, Nodens Koren, Lingjuan Lyu, Xixiang Lyu, Bo Li, and Xingjun Ma · 2021
Later among the works it cites.
Invisible backdoor attack with sample-specific triggers
Yuezun Li, Yiming Li, Baoyuan Wu, Longkang Li, Ran He, and Siwei Lyu · 2021
Later among the works it cites.
Yingqi Liu, Guangyu Shen, Guanhong Tao, Zhenting Wang, Shiqing Ma, and Xiangyu Zhang · 2021
Later among the works it cites.
Wanet–imperceptible warping-based backdoor attack
Anh Nguyen and Anh Tran · 2021
Later among the works it cites.
Backdoor scanning for deep neural networks through k-arm optimization
Guangyu Shen, Yingqi Liu, Guanhong Tao, Shengwei An, Qiuling Xu, Siyuan Cheng, Shiqing Ma, and Xiangyu Zhang · 2021
Later among the works it cites.
Data-free model extraction
Jean-Baptiste Truong, Pratyush Maini, Robert J Walls, and Nicolas Papernot · 2021
Later among the works it cites.
Badencoder: Backdoor attacks to pre-trained encoders in self-supervised learning
Jinyuan Jia, Yupei Liu, and Neil Zhenqiang Gong · 2022
Closest in time.
Dynamic backdoor attacks against machine learning models
Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang · 2022
Closest in time.
Model orthogonalization: Class distance hardening in neural networks for better security
Guanhong Tao, Yingqi Liu, Guangyu Shen, Qiuling Xu, Shengwei An, Zhuo Zhang, and Xiangyu Zhang · 2022
Closest in time.
Towards understanding and defending input space trojans
Zhenting Wang, Hailun Ding, Juan Zhai, and Shiqing Ma · 2022
Closest in time.