Fetching the paper…
Reading the bibliography…
Deep Neural Networks (DNNs) are susceptible to backdoor attacks during training.
W. Hoeffiding, “A class of statistics with asymptotically normal distributions,” Annals of Mathematical Statistics , vol. 19, no. 3, pp. 293–325, 1948
1948
Earlier work this paper cites.
P. J. Rousseeuw, “Silhouettes: a graphical aid to the interpretation and validation of cluster analysis,” Journal of Computational and Applied Mathematics , vol. 20, pp. 53–65, 1987
1987
Earlier work this paper cites.
B. Efron and R. J. Tibshirani, An introduction to the bootstrap . CRC Press, 1994
1994
Earlier work this paper cites.
S. Mika, G. Ratsch, J. Weston, B. Scholkopf, and K.-R. Mullers, “Fisher discriminant analysis with kernels,” in Proceedings of the IEEE Signal Processing Society Workshop . IEEE, 1999, pp. 41–48
1999
Earlier work this paper cites.
B. Schölkopf, A. J. Smola, F. Bach et al. , Learning with kernels: support vector machines, regularization, optimization, and beyond . MIT Press, 2002
2002
Earlier work this paper cites.
C. E. Rasmussen, “Gaussian processes in machine learning,” in Advanced Lectures on Machine Learning: ML Summer Schools 2003 , 2003, pp. 63–71
2003
Earlier work this paper cites.
C. M. Bishop and N. M. Nasrabadi, Pattern recognition and machine learning . Springer, 2006, vol. 4, no. 4
2006
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “ImageNet: A large-scale hierarchical image database,” in CVPR , 2009
2009
Earlier work this paper cites.
A. Krizhevsky and G. Hinton, “Learning multiple layers of features from tiny images,” Technical Report, Citeseer , 2009
2009
Earlier work this paper cites.
R. J. Serfling, Approximation theorems of mathematical statistics . John Wiley & Sons, 2009, vol. 162
2009
Earlier work this paper cites.
M. Everingham and J. Winn, “The PASCAL Visual Object Classes Challenge 2012 (VOC2012) development kit,” Pattern Analysis, Statistical Modelling and Computational Learning , vol. 8, p. 5, 2011
2011
Earlier work this paper cites.
A. Gretton, K. M. Borgwardt, M. J. Rasch, B. Schölkopf, and A. Smola, “A kernel two-sample test,” The Journal of Machine Learning Research , vol. 13, no. 1, pp. 723–773, 2012
2012
Earlier work this paper cites.
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, “Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition,” Neural Networks , vol. 32, pp. 323–332, 2012
2012
Earlier work this paper cites.
2013
Earlier work this paper cites.
C. Leys, C. Ley, O. Klein, P. Bernard, and L. Licata, “Detecting outliers: Do not use standard deviation around the mean, use absolute deviation around the median,” Journal of experimental social psychology , vol. 49, no. 4, pp. 764–766, 2013
2013
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” ICLR , 2014
2014
Earlier work this paper cites.
R. Timofte, K. Zimmermann, and L. Van Gool, “Multi-view traffic sign detection, recognition, and 3d localisation,” Machine vision and applications , vol. 25, no. 3, pp. 633–647, 2014
2014
Earlier work this paper cites.
K. P. Chwialkowski, A. Ramdas, D. Sejdinovic, and A. Gretton, “Fast two-sample testing with analytic representations of probability measures,” in NeurIPS , 2015
2015
Earlier work this paper cites.
I. J. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and harnessing adversarial examples,” ICLR , 2015
2015
Earlier work this paper cites.
Y. Li, K. Swersky, and R. Zemel, “Generative moment matching networks,” in ICML , 2015
2015
Earlier work this paper cites.
O. M. Parkhi, A. Vedaldi, and A. Zisserman, “Deep face recognition,” in BMVC , 2015
2015
Earlier work this paper cites.
J. V. Psutka and J. Psutka, “Sample size for maximum likelihood estimates of gaussian model,” in CAIP , 2015
2015
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” ICLR , 2015
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
L. A. Gatys, A. S. Ecker, and M. Bethge, “Image style transfer using convolutional neural networks,” in CVPR , 2016
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
——, “Identity mappings in deep residual networks,” in ECCV , 2016
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
M. Sharif, S. Bhagavatula, L. Bauer, and M. K. Reiter, “Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition,” in CCS , 2016
2016
Earlier work this paper cites.
S. Baluja, “Hiding images in plain sight: Deep steganography,” in NeurIPS , 2017
2017
Cited alongside, same era.
2017
Cited alongside, same era.
Y. Li, N. Wang, J. Liu, and X. Hou, “Demystifying neural style transfer,” in IJCAI , 2017
2017
Cited alongside, same era.
R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, and D. Batra, “Grad-CAM: Visual explanations from deep networks via gradient-based localization,” in ICCV , 2017
2017
Cited alongside, same era.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in IEEE S & \& P , 2017
2017
Cited alongside, same era.
2020
Later among the works it cites.
2020
Later among the works it cites.
J. Lin, L. Xu, Y. Liu, and X. Zhang, “Composite backdoor attack for deep neural network by mixing existing benign features,” in CCS , 2020
2020
Later among the works it cites.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection Backdoor: A natural backdoor attack on deep neural networks,” in ECCV , 2020
2020
Later among the works it cites.
Y. Liu, A. Mondal, A. Chakraborty, M. Zuzak, N. Jacobsen, D. Xing, and A. Srivastava, “A survey on neural trojans,” in ISQED , 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A. Athalye, N. Carlini, and D. Wagner, “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” in ICLR , 2018
2018
Cited alongside, same era.
K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, “Robust physical-world attacks on deep learning visual classification,” in CVPR , 2018
2018
Cited alongside, same era.
K. Lee, K. Lee, H. Lee, and J. Shin, “A simple unified framework for detecting out-of-distribution samples and adversarial attacks,” in NeurIPS , 2018
2018
Cited alongside, same era.
S. Liang, Y. Li, and R. Srikant, “Enhancing the reliability of out-of-distribution image detection in neural networks,” ICLR , 2018
2018
Cited alongside, same era.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in NDSS , 2018
2018
Cited alongside, same era.
A. Rajkomar, E. Oren, K. Chen, A. M. Dai, N. Hajaj, M. Hardt, P. J. Liu, X. Liu, J. Marcus, M. Sun et al. , “Scalable and accurate deep learning with electronic health records,” NPJ Digital Medicine , vol. 1, no. 1, pp. 1–10, 2018
2018
Cited alongside, same era.
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein, “Poison frogs! targeted clean-label poisoning attacks on neural networks,” in NeurIPS , 2018
2018
Cited alongside, same era.
2020
Later among the works it cites.
A. Nguyen and A. Tran, “Input-aware dynamic backdoor attack,” in NeurIPS , 2020
2020
Later among the works it cites.
R. Pang, H. Shen, X. Zhang, S. Ji, Y. Vorobeychik, X. Luo, A. Liu, and T. Wang, “A tale of evil twins: Adversarial inputs versus poisoned models,” in CCS , 2020
2020
Later among the works it cites.
A. Saha, A. Subramanya, and H. Pirsiavash, “Hidden trigger backdoor attacks,” AAAI , 2020
2020
Later among the works it cites.
C. S. Sastry and S. Oore, “Detecting out-of-distribution examples with Gram matrices,” in ICML , 2020
2020
Later among the works it cites.
M. Tancik, B. Mildenhall, and R. Ng, “StegaStamp: Invisible hyperlinks in physical photographs,” in CVPR , 2020
2020
Later among the works it cites.
E. Zisselman and A. Tamar, “Deep residual flow for out of distribution detection,” in CVPR , 2020
2020
Later among the works it cites.
A. Azizi, I. A. Tahmid, A. Waheed, N. Mangaokar, J. Pu, M. Javed, C. K. Reddy, and B. Viswanath, “T-miner: A generative approach to defend against trojan attacks on dnn-based text classification,” in USENIX Security , 2021
2021
Later among the works it cites.
X. Chen, A. Salem, D. Chen, M. Backes, S. Ma, Q. Shen, Z. Wu, and Y. Zhang, “Badnl: Backdoor attacks against nlp models with semantic-preserving improvements,” in ACSAC , 2021
2021
Later among the works it cites.
X. Gong, Y. Chen, Q. Wang, H. Huang, L. Meng, C. Shen, and Q. Zhang, “Defense-resistant backdoor attacks against deep neural networks in outsourced cloud environment,” IEEE Journal on Selected Areas in Communications , vol. 39, no. 8, pp. 2617–2631, 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
C. Li, X. Chen, D. Wang, S. Wen, M. E. Ahmed, S. Camtepe, and Y. Xiang, “Backdoor attack on machine learning based android malware detectors,” IEEE TDSC , 2021
2021
Later among the works it cites.
S. Li, H. Liu, T. Dong, B. Z. H. Zhao, M. Xue, H. Zhu, and J. Lu, “Hidden backdoors in human-centric language models,” in CCS , 2021
2021
Later among the works it cites.
S. Li, M. Xue, B. Zhao, H. Zhu, and X. Zhang, “Invisible backdoor attacks on deep neural networks via steganography and regularization,” IEEE TDSC , 2021
2021
Later among the works it cites.
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in ICCV , 2021
2021
Later among the works it cites.
Y. Liu, G. Shen, G. Tao, Z. Wang, S. Ma, and X. Zhang, “ Ex
2021
Later among the works it cites.
——, “Wanet–imperceptible warping-based backdoor attack,” in ICLR , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
G. Severi, J. Meyer, S. Coull, and A. Oprea, “ { \{ Explanation-Guided } \} backdoor poisoning attacks against malware classifiers,” in USENIX Security , 2021
2021
Later among the works it cites.
D. Tang, X. Wang, H. Tang, and K. Zhang, “Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection,” in USENIX Security , 2021
2021
Later among the works it cites.
X. Xu, Q. Wang, H. Li, N. Borisov, C. A. Gunter, and B. Li, “Detecting AI trojans using meta neural analysis,” in IEEE S & \& P , 2021
2021
Later among the works it cites.
T. Zhai, Y. Li, Z. Zhang, B. Wu, Y. Jiang, and S.-T. Xia, “Backdoor attack against speaker verification,” in ICASSP , 2021
2021
Later among the works it cites.
J. Jia, Y. Liu, and N. Z. Gong, “BadEncoder: Backdoor attacks to pre-trained encoders in self-supervised learning,” in IEEE S & \& P , 2022
2022
Closest in time.
R. Pang, Z. Zhang, X. Gao, Z. Xi, S. Ji, P. Cheng, and T. Wang, “TROJANZOO: Towards unified, holistic, and practical evaluation of neural backdoors,” in EuroS & \& P , 2022
2022
Closest in time.
A. Salem, R. Wen, M. Backes, S. Ma, and Y. Zhang, “Dynamic backdoor attacks against machine learning models,” in EuroS & \& P , 2022
2022
Closest in time.