Fetching the paper…
Reading the bibliography…
Deep neural networks (DNNs) are vulnerable to backdoor attacks, where a backdoored model behaves normally with clean inputs but exhibits attacker-specified behaviors upon the inputs containing triggers.
O. Ronneberger, P. Fischer, and T. Brox, “U-net: Convolutional networks for biomedical image segmentation,” in Proc. Int. Conf. Med. Imag. Comput. Comput.-Assisted Intervention , 2015, pp. 234–241
2015
Earlier work this paper cites.
J. Johnson, A. Alahi, and L. Fei-Fei, “Perceptual losses for real-time style transfer and super-resolution,” in Proc. Eur. Conf. Comput. Vis. , 2016, pp. 694–711
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Identity mappings in deep residual networks,” in Proc. Eur. Conf. Comput. Vis. , 2016, pp. 630–645
2016
Earlier work this paper cites.
——, “Deep residual learning for image recognition,” in IEEE Conf. Comput. Vis. Pattern Recognit. , 2016, pp. 770–778
2016
Earlier work this paper cites.
C. Song, T. Ristenpart, and V. Shmatikov, “Machine learning models that remember too much,” in Proc. ACM Conf. Comp. Commun. Secur. , 2017, pp. 587–601
2017
Earlier work this paper cites.
T. Gu, B. Dolan-Gavitt, and S. Garg, “Badnets: Identifying vulnerabilities in the machine learning model supply chain,” IEEE Access , vol. 7, pp. 47 230––47 244, 2017
2017
Earlier work this paper cites.
X. Chen, C. Liu, B. Li, K. Lu, and D. Song, “Targeted backdoor attacks on deep learning systems using data poisoning,” arXiv , pp. 1–18, 2017
2017
Earlier work this paper cites.
Q. Fan, J. Yang, G. Hua, B. Chen, and D. Wipf, “A generic deep architecture for single image reflection removal and image smoothing,” in Proc. IEEE Conf. Comput. Vis. , 2017, pp. 3238–3247
2017
Earlier work this paper cites.
P. Isola, J.-Y. Zhu, T. Zhou, and A. A. Efros, “Image-to-image translation with conditional adversarial networks,” in IEEE Conf. Comput. Vis. Pattern Recognit. , 2017, pp. 1125–1134
2017
Earlier work this paper cites.
Y. Tian, K. Pei, S. Jana, and B. Ray, “Deeptest: Automated testing of deep-neural-network-driven autonomous cars,” in Proc. Int. Conf. Software Eng. , 2018, pp. 303–314
2018
Earlier work this paper cites.
M. Jagielski, A. Oprea, B. Biggio, C. Liu, C. Nita-Rotaru, and B. Li, “Manipulating machine learning: Poisoning attacks and countermeasures for regression learning,” in IEEE Symp. on Secur. and Priv. , 2018, pp. 19–35
2018
Earlier work this paper cites.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in Int. symp. Res. Attacks, Intrusions, and Defenses , 2018, pp. 273–294
2018
Earlier work this paper cites.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in Proc. Int. Conf. Neural Inf. Process. Syst. , 2018, pp. 1–16
2018
Earlier work this paper cites.
M. Sandler, A. Howard, M. Zhu, A. Zhmoginov, and L.-C. Chen, “Mobilenetv2: Inverted residuals and linear bottlenecks,” in IEEE Conf. Comput. Vis. Pattern Recognit. , 2018, pp. 4510–4520
2018
Earlier work this paper cites.
M. Barni, K. Kallas, and B. Tondi, “A new backdoor attack in cnns by training set corruption without label poisoning,” in IEEE Int. Conf. on Image Process. , 2019, pp. 101–105
2019
Earlier work this paper cites.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in IEEE Symp. on Secur. and Priv. , 2019, pp. 707–723
2019
Earlier work this paper cites.
Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal, “Strip: A defence against trojan attacks on deep neural networks,” in Annu. Comput. Secur. Appl. Conf. , 2019, pp. 113–125
2019
Earlier work this paper cites.
T. A. Nguyen and A. Tran, “Input-aware dynamic backdoor attack,” in Proc. Int. Conf. Neural Inf. Process. Syst. , 2020, pp. 3454–3464
2020
Earlier work this paper cites.
E. Chou, F. Tramer, and G. Pellegrino, “Sentinet: Detecting localized universal attacks against deep learning systems,” in Proc. IEEE Symp. Secur. Priv. Workshops , 2020, pp. 48–54
2020
Earlier work this paper cites.
J. Hayase and W. Kong, “Spectre: Defending against backdoor attacks using robust covariance estimation,” in Proc. Int. Conf. Mach. Learn. , 2020, pp. 1–30
2020
Earlier work this paper cites.
J. Lin, L. Xu, Y. Liu, and X. Zhang, “Composite backdoor attack for deep neural network by mixing existing benign features,” in Proc. ACM Conf. Comp. Commun. Secur. , 2020, pp. 113–131
2020
Earlier work this paper cites.
B. Wang, M. Zhao, W. Wang, X. Dai, Y. Li, and Y. Guo, “Adversarial analysis for source camera identification,” IEEE Trans. Circuits Syst. Video Technol. , vol. 31, no. 11, pp. 4174–4186, 2021
2021
Cited alongside, same era.
L. Fowl, J. Geiping, W. Czaja, M. Goldblum, and T. Goldstein, “Robbing the fed: Directly obtaining private data in federated learning with modified models,” in Proc. Int. Conf. Learn. Representations , 2021, pp. 7718–7727
2021
Cited alongside, same era.
S. Cheng, Y. Liu, S. Ma, and X. Zhang, “Deep feature space trojan attack of neural networks by controlled detoxification,” in Proc. AAAI Conf. Artif. Intell. , 2021, pp. 1148–1156
2021
Cited alongside, same era.
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in Proc. IEEE Conf. Comput. Vis. , 2021, pp. 16 443–16 452
2021
Cited alongside, same era.
Z. Xiang, D. J. Miller, and G. Kesidis, “Detection of backdoors in trained classifiers without access to the training set,” IEEE Trans. Neural Netw. Learn. Syst. , vol. 33, no. 3, pp. 1177–1191, 2022
2022
Closest in time.
——, “Post-training detection of backdoor attacks for two-class and multi-attack scenarios,” in Proc. Int. Conf. Learn. Representations , 2022, pp. 1–12
2022
Closest in time.
J. Zhang, D. Chen, J. Liao, W. Zhang, H. Feng, G. Hua, and N. Yu, “Deep model intellectual property protection via deep watermarking,” IEEE Trans. Pattern Anal. Mach. Intell. , vol. 44, no. 8, pp. 4005–4020, 2022
2022
Closest in time.
Q. Li, X. Wang, B. Ma, X. Wang, C. Wang, S. Gao, and Y. Shi, “Concealed attack for robust watermarking based on generative model and perceptual loss,” IEEE Trans. Circuits Syst. Video Technol. , vol. 32, no. 8, pp. 5695–5706, 2022
2022
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
T. A. Nguyen and A. T. Tran, “Wanet - imperceptible warping-based backdoor attack,” in Proc. Int. Conf. Learn. Representations , 2021, p. 1–16
2021
Cited alongside, same era.
J. Chen, L. Zhang, H. Zheng, X. Wang, and Z. Ming, “Deeppoison: Feature transfer based stealthy poisoning attack for dnns,” IEEE Trans. Circuits Syst. II, Exp. Briefs , no. 7, pp. 2618–2622, 2021
2021
Cited alongside, same era.
X. Gong, Y. Chen, Q. Wang, H. Huang, L. Meng, C. Shen, and Q. Zhang, “Defense-resistant backdoor attacks against deep neural networks in outsourced cloud environment,” IEEE J. Sel. Areas Commun. , vol. 39, no. 8, pp. 2617–2631, 2021
2021
Cited alongside, same era.
Y. Li, X. Lyu, N. Koren, L. Lyu, B. Li, and X. Ma, “Neural attention distillation: Erasing backdoor triggers from deep neural networks,” Proc. Int. Conf. Learn. Representations , 2021
2021
Cited alongside, same era.
Y. Li, T. Zhai, Y. Jiang, Z. Li, and S.-T. Xia, “Backdoor attack in the physical world,” in Proc. Int. Conf. Learn. Representations workshop , 2021, pp. 1–6
2021
Cited alongside, same era.
D. Wu and Y. Wang, “Adversarial neuron pruning purifies backdoored deep models,” Proc. Int. Conf. Neural Inf. Process. Syst. , pp. 16 913–16 925, 2021
2021
Cited alongside, same era.
X. Xu, Q. Wang, H. Li, N. Borisov, C. A. Gunter, and B. Li, “Detecting ai trojans using meta neural analysis,” in IEEE Symp. on Secur. and Priv. , 2021, pp. 103–120
2021
Cited alongside, same era.
H. Wu, G. Liu, Y. Yao, and X. Zhang, “Watermarking neural networks with watermarked images,” IEEE Trans. Circuits Syst. Video Technol. , vol. 31, no. 7, pp. 2591–2601, 2021
2021
Cited alongside, same era.
Y. Ran, W. Wang, M. Li, L.-C. Li, Y.-G. Wang, and J. Li, “Cross-shaped adversarial patch attack,” IEEE Trans. Circuits Syst. Video Technol. , pp. 1–1, 2023
2023
Closest in time.
Z. Zhou, Y. Sun, Q. Sun, C. Li, and Z. Ren, “Only once attack: Fooling the tracker with adversarial template,” IEEE Trans. Circuits Syst. Video Technol. , vol. 33, no. 7, pp. 3173–3184, 2023
2023
Closest in time.
X. Gong, Z. Wang, Y. Chen, M. Xue, Q. Wang, and C. Shen, “Kaleidoscope: Physical backdoor attacks against deep neural networks with rgb filters,” IEEE Trans. Dependable Secur. Comput. , 2023
2023
Closest in time.
T. Xu, Y. Li, Y. Jiang, and S.-T. Xia, “Batt: Backdoor attack with transformation-based triggers,” in ICASSP . IEEE, 2023, pp. 1–5
2023
Closest in time.
X. Qi, T. Xie, Y. Li, S. Mahloujifar, and P. Mittal, “Revisiting the assumption of latent separability for backdoor defenses,” in Proc. Int. Conf. Learn. Representations , 2023
2023
Closest in time.
Y. Gao, Y. Li, L. Zhu, D. Wu, Y. Jiang, and S.-T. Xia, “Not all samples are born equal: Towards effective clean-label backdoor attacks,” Pat. Rec. , vol. 139, p. 109512, 2023
2023
Closest in time.
Y. Gao, Y. Li, X. Gong, S.-T. Xia, and Q. Wang, “Backdoor attack with sparse and invisible trigger,” arXiv , 2023
2023
Closest in time.
X. Gong, Y. Chen, W. Yang, H. Huang, and Q. Wang, “b3: Backdoor attacks against black-box machine learning models,” ACM Trans. Priv. Secur. , 2023
2023
Closest in time.
M. Xue, Y. Wu, S. Ni, L. Y. Zhang, Y. Zhang, and W. Liu, “Untargeted backdoor attack against deep neural networks with imperceptible trigger,” IEEE Trans. on Ind. Informatics , 2023
2023
Closest in time.
J. Guo, Y. Li, L. Wang, S.-T. Xia, H. Huang, C. Liu, and B. Li, “Domain watermark: Effective and harmless dataset copyright protection is closed at hand,” in Proc. Int. Conf. Neural Inf. Process. Syst. , 2023
2023
Closest in time.
Y. Li, M. Zhu, X. Yang, Y. Jiang, T. Wei, and S.-T. Xia, “Black-box dataset ownership verification via backdoor watermarking,” IEEE Trans. Inf. Forensics Secur. , 2023
2023
Closest in time.
X. Gong, Y. Chen, W. Yang, Q. Wang, Y. Gu, H. Huang, and C. Shen, “Redeem myself: Purifying backdoors in deep learning models using self attention distillation,” in Proc. IEEE Symp. Secur. Priv. IEEE Computer Society, 2023, pp. 755–772
2023
Closest in time.
N. M. Jebreel, J. Domingo-Ferrer, and Y. Li, “Defending against backdoor attacks by layer-wise feature analysis,” in PAKDD . Springer, 2023, pp. 428–440
2023
Closest in time.
J. Guo, Y. Li, X. Chen, H. Guo, L. Sun, and C. Liu, “Scale-up: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency,” Proc. Int. Conf. Learn. Representations , 2023
2023
Closest in time.
T. Xie, X. Qi, P. He, Y. Li, J. T. Wang, and P. Mittal, “Badexpert: Extracting backdoor functionality for accurate backdoor input detection,” in Proc. Int. Conf. Neural Inf. Process. Syst. , 2023
2023
Closest in time.
W. Sun, J. Jin, and W. Lin, “Minimum noticeable difference-based adversarial privacy preserving image generation,” IEEE Trans. Circuits Syst. Video Technol. , vol. 33, no. 3, pp. 1069–1081, 2023
2023
Closest in time.