Fetching the paper…
Reading the bibliography…
Currently, deep neural networks (DNNs) are widely adopted in different applications.
R. Rivest and S. Dusse, “The md5 message-digest algorithm,” 1992
1992
Earlier work this paper cites.
R. V. Hogg, J. McKean, and A. T. Craig, Introduction to mathematical statistics . Pearson Education, 2005
2005
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” Citeseer, Tech. Rep., 2009
2009
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in CVPR , 2009
2009
Earlier work this paper cites.
L. Sachs, Applied statistics: a handbook of techniques . Springer Science & Business Media, 2012
2012
Earlier work this paper cites.
A. Krizhevsky, I. Sutskever, and G. E. Hinton, “Imagenet classification with deep convolutional neural networks,” NeurIPS , 2012
2012
Earlier work this paper cites.
G. Hinton, O. Vinyals, and J. Dean, “Distilling the knowledge in a neural network,” in NeurIPS Workshop , 2014
2014
Earlier work this paper cites.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” nature , vol. 521, no. 7553, pp. 436–444, 2015
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in ICLR , 2015
2015
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction apis,” in USENIX Security , 2016
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
J. Johnson, A. Alahi, and L. Fei-Fei, “Perceptual losses for real-time style transfer and super-resolution,” in ECCV , 2016
2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis, “Wide residual networks,” in BMVC , 2016
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, “Practical black-box attacks against machine learning,” in AsiaCCS , 2017
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in IEEE S&P , 2017
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in CVPR , 2017
2017
Earlier work this paper cites.
X. Huang and S. Belongie, “Arbitrary style transfer in real-time with adaptive instance normalization,” in ICCV , 2017
2017
Earlier work this paper cites.
I. Loshchilov and F. Hutter, “Sgdr: Stochastic gradient descent with warm restarts,” in ICLR , 2017
2017
Earlier work this paper cites.
J. Kirkpatrick, R. Pascanu, N. Rabinowitz, J. Veness, G. Desjardins, A. A. Rusu, K. Milan, J. Quan, T. Ramalho, A. Grabska-Barwinska et al. , “Overcoming catastrophic forgetting in neural networks,” Proceedings of the national academy of sciences , vol. 114, no. 13, pp. 3521–3526, 2017
2017
Earlier work this paper cites.
M. Kesarwani, B. Mukhoty, V. Arya, and S. Mehta, “Model extraction warning in mlaas paradigm,” in ACSAC , 2018
2018
Earlier work this paper cites.
Y. Adi, C. Baum, M. Cisse, B. Pinkas, and J. Keshet, “Turning your weakness into a strength: Watermarking deep neural networks by backdooring,” in USENIX Security , 2018
2018
Earlier work this paper cites.
T. Orekondy, B. Schiele, and M. Fritz, “Knockoff nets: Stealing functionality of black-box models,” in CVPR , 2019
2019
Earlier work this paper cites.
T. Lee, B. Edwards, I. Molloy, and D. Su, “Defending against neural network model stealing attacks using deceptive perturbations,” in IEEE S&P Workshop , 2019
2019
Cited alongside, same era.
N. Lukas, Y. Zhang, and F. Kerschbaum, “Deep neural network fingerprinting by conferrable adversarial examples,” in ICLR , 2019
2019
Cited alongside, same era.
2019
Cited alongside, same era.
M. Juuti, S. Szyller, S. Marchal, and N. Asokan, “Prada: protecting against dnn model stealing attacks,” in EuroS&P , 2019
2019
Cited alongside, same era.
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,” IEEE Access , vol. 7, pp. 47 230–47 244, 2019
Y. Dong, X. Yang, Z. Deng, T. Pang, Z. Xiao, H. Su, and J. Zhu, “Black-box detection of backdoor attacks with limited information and data,” in ICCV , 2021
2021
Later among the works it cites.
G. Shen, Y. Liu, G. Tao, S. An, Q. Xu, S. Cheng, S. Ma, and X. Zhang, “Backdoor scanning for deep neural networks through k-arm optimization,” in ICML , 2021
2021
Later among the works it cites.
S. Minaee, Y. Y. Boykov, F. Porikli, A. J. Plaza, N. Kehtarnavaz, and D. Terzopoulos, “Image segmentation using deep learning: A survey,” IEEE Transactions on Pattern Analysis and Machine Intelligence , vol. 44, no. 7, pp. 3523–3542, 2022
2022
Closest in time.
Z. Peng, S. Li, G. Chen, C. Zhang, H. Zhu, and M. Xue, “Fingerprinting deep neural networks globally via universal adversarial perturbations,” in CVPR , 2022
2022
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2019
Cited alongside, same era.
R. Geirhos, P. Rubisch, C. Michaelis, M. Bethge, F. A. Wichmann, and W. Brendel, “Imagenet-trained cnns are biased towards texture; increasing shape bias improves accuracy and robustness,” in ICLR , 2019
2019
Cited alongside, same era.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in IEEE S&P , 2019
2019
Cited alongside, same era.
V. Chandrasekaran, K. Chaudhuri, I. Giacomelli, S. Jha, and S. Yan, “Exploring connections between active learning and model extraction,” in USENIX Security , 2020
2020
Cited alongside, same era.
S. Kariyappa and M. K. Qureshi, “Defending against model stealing attacks with adaptive misinformation,” in CVPR , 2020
2020
Cited alongside, same era.
M. Jagielski, N. Carlini, D. Berthelot, A. Kurakin, and N. Papernot, “High accuracy and high fidelity extraction of neural networks,” in USENIX Security , 2020
2020
Cited alongside, same era.
R. Duan, X. Ma, Y. Wang, J. Bailey, A. K. Qin, and Y. Yang, “Adversarial camouflage: Hiding physical-world attacks with natural styles,” in CVPR , 2020
2020
Cited alongside, same era.
X. Chen, Y. Zhang, Y. Wang, H. Shu, C. Xu, and C. Xu, “Optical flow distillation: Towards efficient and stable video style transfer,” in ECCV , 2020
2020
Cited alongside, same era.
2022
Closest in time.
H. Yan, X. Li, H. Li, J. Li, W. Sun, and F. Li, “Monitoring-based differential privacy mechanism against query flooding-based model extraction attack,” IEEE Transactions on Dependable and Secure Computing , vol. 19, no. 4, pp. 2680–2694, 2022
2022
Closest in time.
K. Yang, R. Wang, and L. Wang, “Metafinger: Fingerprinting the deep neural networks with meta-training.” in IJCAI , 2022
2022
Closest in time.
Y. Gao, Y. Kim, B. G. Doan, Z. Zhang, G. Zhang, S. Nepal, D. Ranasinghe, and H. Kim, “Design and evaluation of a multi-domain trojan detection method on deep neural networks,” IEEE Transactions on Dependable and Secure Computing , vol. 19, no. 4, pp. 2349–2364, 2022
2022
Closest in time.
G. Gan, Y. Li, D. Wu, and S.-T. Xia, “Towards robust model watermark via reducing parametric vulnerability,” in ICCV , 2023
2023
Closest in time.
R. Wang, J. Ren, B. Li, T. She, W. Zhang, L. Fang, J. Chen, and L. Wang, “Free fine-tuning: A plug-and-play watermarking scheme for deep neural networks,” in ACM MM , 2023
2023
Closest in time.
Y. Li, M. Zhu, X. Yang, Y. Jiang, T. Wei, and S.-T. Xia, “Black-box dataset ownership verification via backdoor watermarking,” IEEE Transactions on Information Forensics and Security , vol. 18, pp. 2318–2332, 2023
2023
Closest in time.
Y. Li, M. Ya, Y. Bai, Y. Jiang, and S.-T. Xia, “BackdoorBox: A python toolbox for backdoor learning,” in ICLR Workshop , 2023
2023
Closest in time.
X. Qi, T. Xie, Y. Li, S. Mahloujifar, and P. Mittal, “Revisiting the assumption of latent separability for backdoor defenses,” in ICLR , 2023
2023
Closest in time.
H. Zhu, S. Liang, W. Hu, F. Li, J. Jia, and S. Wang, “Reliable model watermarking: Defending against theft without compromising on evasion,” in ACM MM , 2024
2024
Closest in time.
Y. Li, Y. Jiang, Z. Li, and S.-T. Xia, “Backdoor learning: A survey,” IEEE Transactions on Neural Networks and Learning Systems , vol. 35, no. 1, pp. 5–22, 2024
2024
Closest in time.
B. Li, Y. Cai, J. Cai, Y. Li, H. Qiu, R. Wang, and T. Zhang, “Purifying quantization-conditioned backdoors via layer-wise activation correction with distribution approximation,” in ICML , 2024
2024
Closest in time.
B. Li, Y. Cai, H. Li, F. Xue, Z. Li, and Y. Li, “Nearest is not dearest: Towards practical defense against quantization-conditioned backdoor attacks,” in CVPR , 2024
2024
Closest in time.
M. Ya, Y. Li, T. Dai, B. Wang, Y. Jiang, and S.-T. Xia, “Towards faithful xai evaluation via generalization-limited backdoor watermark,” in ICLR , 2024
2024
Closest in time.
H. Cai, P. Zhang, H. Dong, Y. Xiao, S. Koffas, and Y. Li, “Toward stealthy backdoor attacks against speech recognition via elements of sound,” IEEE Transactions on Information Forensics and Security , vol. 19, pp. 5852–5866, 2024
2024
Closest in time.
2024
Closest in time.
S. Shao, Y. Li, H. Yao, Y. He, Z. Qin, and K. Ren, “Explanation as a watermark: Towards harmless and multi-bit model ownership verification via watermarking feature attribution,” in NDSS , 2025
2025
Closest in time.