Fetching the paper…
Reading the bibliography…
Recent works have demonstrated that deep learning models are vulnerable to backdoor poisoning attacks, where these attacks instill spurious correlations to external trigger patterns or objects (e.g., stickers, sunglasses, etc.).
Yiming Li, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shu-Tao Xia · 2007
Earlier work this paper cites.
Yiming Li, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shutao Xia · 2007
Earlier work this paper cites.
The pascal visual object classes (voc) challenge
Mark Everingham, Luc Van Gool, Christopher K. I. Williams, John M. Winn, and Andrew Zisserman · 2009
Earlier work this paper cites.
Face recognition in unconstrained videos with matched background similarity
Lior Wolf, Tal Hassner, and Itay Maoz · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Detection of traffic signs in real-world images: The german traffic sign detection benchmark
Sebastian Houben, Johannes Stallkamp, Jan Salmen, Marc Schlipsing, and C. Igel · 2013
Earlier work this paper cites.
Microsoft coco: Common objects in context
Tsung-Yi Lin, Michael Maire, Serge J. Belongie, James Hays, Pietro Perona, Deva Ramanan, Piotr Dollár, and C. Lawrence Zitnick · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, D. Erhan, Ian J. Goodfellow, and Rob Fergus · 2014
Earlier work this paper cites.
Manitest: Are classifiers really invariant?
Alhussein Fawzi and Pascal Frossard · 2015
Earlier work this paper cites.
Deep face recognition
Omkar M. Parkhi, Andrea Vedaldi, and Andrew Zisserman · 2015
Earlier work this paper cites.
Faster r-cnn: Towards real-time object detection with region proposal networks
Shaoqing Ren, Kaiming He, Ross B. Girshick, and Jian Sun · 2015
Earlier work this paper cites.
Imagenet large scale visual recognition challenge
Olga Russakovsky, Jia Deng, Hao Su, Jonathan Krause, Sanjeev Satheesh, Sean Ma, Zhiheng Huang, Andrej Karpathy, Aditya Khosla, Michael Bernstein, et al · 2015
Earlier work this paper cites.
Facenet: A unified embedding for face recognition and clustering
Florian Schroff, Dmitry Kalenichenko, and James Philbin · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Ssd: Single shot multibox detector
W. Liu, Dragomir Anguelov, D. Erhan, Christian Szegedy, Scott E. Reed, Cheng-Yang Fu, and Alexander C. Berg · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow · 2016
Earlier work this paper cites.
You only look once: Unified, real-time object detection
Joseph Redmon, Santosh Kumar Divvala, Ross B. Girshick, and Ali Farhadi · 2016
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter · 2016
Earlier work this paper cites.
Analysis of causative attacks against svms learning from data streams
Cody Burkard and Brent Lagesse · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Cited alongside, same era.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Cited alongside, same era.
Improved regularization of convolutional neural networks with cutout
Terrance Devries and Graham W. Taylor · 2017
Cited alongside, same era.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Cited alongside, same era.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, and Kilian Q. Weinberger · 2017
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Defending against physically realizable attacks on image classification
Tong Wu, Liang Tong, and Yevgeniy Vorobeychik · 2019
Later among the works it cites.
Cutmix: Regularization strategy to train strong classifiers with localizable features
Sangdoo Yun, Dongyoon Han, Seong Joon Oh, Sanghyuk Chun, Junsuk Choe, and Youngjoon Yoo · 2019
Later among the works it cites.
Yolov4: Optimal speed and accuracy of object detection
Alexey Bochkovskiy, Chien-Yao Wang, and Hong-Yuan Mark Liao · 2020
Later among the works it cites.
Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff
Eitan Borgnia, Valeriia Cherepanova, Liam Fowl, Amin Ghiasi, Jonas Geiping, Micah Goldblum, Tom Goldstein, and Arjun Gupta · 2020
Later among the works it cites.
Language models are few-shot learners
Tom B Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, et al · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2017
Cited alongside, same era.
mixup: Beyond empirical risk minimization
Hongyi Zhang, Moustapha Cisse, Yann N Dauphin, and David Lopez-Paz · 2017
Cited alongside, same era.
Vggface2: A dataset for recognising faces across pose and age, 2018
Qiong Cao, Li Shen, Weidi Xie, Omkar M. Parkhi, and Andrew Zisserman · 2018
Cited alongside, same era.
Detecting backdoor attacks on deep neural networks by activation clustering
Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava · 2018
Cited alongside, same era.
Robust physical-world attacks on deep learning visual classification
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song · 2018
Cited alongside, same era.
Geometric robustness of deep networks: Analysis and improvement
Can Kanbak, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2018
Cited alongside, same era.
Resilience: A criterion for learning in the presence of arbitrary outliers
Jacob Steinhardt, Moses Charikar, and Gregory Valiant · 2018
Cited alongside, same era.
Later among the works it cites.
An image is worth 16x16 words: Transformers for image recognition at scale
Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, et al · 2020
Later among the works it cites.
Composite backdoor attack for deep neural network by mixing existing benign features
Junyu Lin, Lei Xu, Yingqi Liu, and X. Zhang · 2020
Later among the works it cites.
Backdoor attacks on facial recognition in the physical world
Emily Wenger, Josephine Passananti, Yuanshun Yao, Haitao Zheng, and Ben Y Zhao · 2020
Later among the works it cites.
Check your other door! establishing backdoor attacks in the frequency domain
Hasan Abed Al Kader Hammoud and Bernard Ghanem · 2021
Later among the works it cites.
Pointba: Towards backdoor attacks in 3d point cloud, 2021
Xinke Li, Zhirui Chen, Yue Zhao, Zekun Tong, Yabang Zhao, Andrew Lim, and Joey Tianyi Zhou · 2021
Later among the works it cites.
Swin transformer: Hierarchical vision transformer using shifted windows
Ze Liu, Yutong Lin, Yue Cao, Han Hu, Yixuan Wei, Zheng Zhang, Stephen Lin, and Baining Guo · 2021
Later among the works it cites.
Excess capacity and backdoor poisoning, 2021
Naren Sarayu Manoj and Avrim Blum · 2021
Later among the works it cites.
Poisoned classifiers are not only backdoored, they are fundamentally broken, 2021
Mingjie Sun, Siddhant Agarwal, and J Zico Kolter · 2021
Later among the works it cites.
How to inject backdoors with better consistency: Logit anchoring on clean data
Zhiyuan Zhang, Lingjuan Lyu, Weiqiang Wang, Lichao Sun, and Xu Sun · 2021
Later among the works it cites.
Baddet: Backdoor attacks on object detection
Shih-Han Chan, Yinpeng Dong, Junyi Zhu, Xiaolu Zhang, and Jun Zhou · 2022
Closest in time.
A yolor based visual detection of amateur drones
Emrullah Kızılay and Ilhan Aydin · 2022
Closest in time.
Circumventing backdoor defenses that are based on latent separability
Xiangyu Qi, Ting Xie, Saeed Mahloujifar, and Prateek Mittal · 2022
Closest in time.
Chong Xiang, Alexander Valtchanov, Saeed Mahloujifar, and Prateek Mittal · 2022
Closest in time.