J. H. Saltzer and M. D. Schroeder, “The protection of information in computer systems,” Proceedings of the IEEE , 1975
1975
Earlier work this paper cites.
M. Handley, V. Paxson, and C. Kreibich, “Network intrusion detection: Evasion, traffic normalization, and End-to-End protocol semantics,” in USENIX Security Symposium , 2001
2001
Earlier work this paper cites.
L. A. Gordon and M. P. Loeb, “The economics of information security investment,” ACM Transactions on Information and System Security (TISSEC) , vol. 5, no. 4, pp. 438–457, 2002
2002
Earlier work this paper cites.
E. Edelson, “The 419 scam: information warfare on the spam front and a proposal for local filtering,” Computers & Security , 2003
2003
Earlier work this paper cites.
N. Dalvi, P. Domingos, Mausam, S. Sanghai, and D. Verma, “Adversarial classification,” in ACM Int. Conf. Knowl. Discov. Data Mining , 2004
2004
Earlier work this paper cites.
R. Anderson and T. Moore, “The economics of information security,” Science , vol. 314, no. 5799, pp. 610–613, 2006
2006
Earlier work this paper cites.
G. Robles, J. M. Gonzalez-Barahona, and J. J. Merelo, “Beyond source code: the importance of other artifacts in software development (a case study),” Journal of Systems and Software , 2006
2006
Earlier work this paper cites.
S. W. Dekker, “Just culture: who gets to draw the line?” Cognition, Technology & Work , vol. 11, no. 3, pp. 177–185, 2009
2009
Earlier work this paper cites.
N. Khatri, G. D. Brown, and L. L. Hicks, “From a blame culture to a just culture in health care,” Health care management review , 2009
2009
Earlier work this paper cites.
T. Moore, “The economics of cybersecurity: Principles and policy options,” Elsevier Int. J. Critical Infrastructure Protection , 2010
2010
Earlier work this paper cites.
L. Huang, A. D. Joseph, B. Nelson, B. I. Rubinstein, and J. Tygar, “Adversarial machine learning,” in Proc. ACM Workshop Secur. and Artif. Intell. , Oct. 2011, pp. 43–58
2011
Earlier work this paper cites.
B. Biggio, G. Fumera, I. Pillai, and F. Roli, “A survey and experimental evaluation of image spam filtering techniques,” Pattern recognition letters , vol. 32, no. 10, pp. 1436–1446, 2011
2011
Earlier work this paper cites.
B. Biggio, B. Nelson, and P. Laskov, “Poisoning attacks against support vector machines,” in Int. Conf. Machin. Learning , 2012
2012
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in International Conference on Machine Learning , 2013
2013
Earlier work this paper cites.
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli, “Evasion attacks against machine learning at test time,” in Proc. Europ. Conf. Mach. Learn. and Knowl. Discov. Databases , 2013, pp. 387–402
2013
Earlier work this paper cites.
N. McDonald and S. Goggins, “Performance and participation in open source software on Github,” in CHI’13 extended abstracts on human factors in computing systems , 2013, pp. 139–144
2013
Earlier work this paper cites.
N. Šrndić and P. Laskov, “Practical evasion of a learning-based classifier: A case study,” in IEEE Symposium on Security and Privacy , 2014
2014
Earlier work this paper cites.
K. S. Wilson and M. A. Kiy, “Some fundamental cybersecurity concepts,” IEEE Access , 2014
2014
Earlier work this paper cites.
M. I. Jordan and T. M. Mitchell, “Machine Learning: Trends, Perspectives, and Prospects,” Science , 2015
2015
Earlier work this paper cites.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” Nature , 2015
2015
Earlier work this paper cites.
C. Xiao, D. M. Freeman, and T. Hwa, “Detecting clusters of fake accounts in online social networks,” in Proceedings of the 8th ACM Workshop on Artificial Intelligence and Security , 2015, pp. 91–101
2015
Earlier work this paper cites.
J. Gardiner and S. Nagaraja, “On the security of machine learning in malware C&C detection: A survey,” ACM Comput. Surv. , 2016
2016
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction APIs,” in USENIX Security Symposium , 2016
2016
Earlier work this paper cites.
N. Z. Gong and B. Liu, “You are who you know and how you behave: Attribute inference attacks via users’ social friends and behaviors,” in USENIX Security Symposium , 2016
2016
Earlier work this paper cites.
E. Ferrara, O. Varol, C. Davis, F. Menczer, and A. Flammini, “The rise of social bots,” Communications of the ACM , 2016
2016
Earlier work this paper cites.
D. I. Urbina, J. A. Giraldo, A. A. Cardenas, N. O. Tippenhauer, J. Valente, M. Faisal, J. Ruths, R. Candell, and H. Sandberg, “Limiting the impact of stealthy attacks on industrial control systems,” in ACM Conference on Computer and Communications Security , 2016
2016
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in IEEE Symposium on Security and Privacy , 2017
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in IEEE Symposium on Security and Privacy , 2017
2017
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami, “Practical black-box attacks against machine learning,” in Proc. ACM Conf. Comput. Commun. Secur. , 2017, pp. 506–519
2017
Earlier work this paper cites.
R. Jordaney, K. Sharad, S. K. Dash, Z. Wang, D. Papini, I. Nouretdinov, and L. Cavallaro, “Transcend: Detecting concept drift in malware classification models,” in USENIX Security Symposium , 2017
2017
Earlier work this paper cites.
G. Apruzzese, M. Colajanni, L. Ferretti, A. Guido, and M. Marchetti, “On the effectiveness of machine and deep learning for cybersecurity,” in Proc. IEEE Int. Conf. Cyber Conflicts , May 2018, pp. 371–390
2018
Earlier work this paper cites.
B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning,” Elsevier Pattern Recogn. , 2018
2018
Earlier work this paper cites.
N. Papernot, P. McDaniel, A. Sinha, and M. Wellman, “Sok: Security and privacy in machine learning,” in Proc. IEEE Europ. Symp. Secur. Privacy , 2018
2018
Earlier work this paper cites.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in ICLR , 2018
2018
Earlier work this paper cites.
J. Gilmer, R. P. Adams, I. Goodfellow, D. Andersen, and G. E. Dahl, “Motivating the rules of the game for adversarial example research,” arXiv:1807.06732 , 2018
Original
2018
Earlier work this paper cites.
D. Güera and E. J. Delp, “Deepfake video detection using recurrent neural networks,” in IEEE international conference on advanced video and signal based surveillance , 2018
2018
Earlier work this paper cites.
S. Madisetty and M. S. Desarkar, “A neural network-based ensemble approach for spam detection in Twitter,” IEEE Transactions on Computational Social Systems , vol. 5, no. 4, pp. 973–984, 2018
2018
Earlier work this paper cites.
M. Hutson, “Artificial intelligence faces reproducibility crisis,” Science , 2018
2018
Earlier work this paper cites.
F. Tramèr, P. Dupré, G. Rusak, G. Pellegrino, and D. Boneh, “Adversarial: Perceptual ad blocking meets adversarial machine learning,” in ACM Conference on Computer and Communications Security , 2019
2019
Earlier work this paper cites.
N. Carlini, A. Athalye, N. Papernot, W. Brendel, J. Rauber, D. Tsipras, I. Goodfellow, A. Madry, and A. Kurakin, “On evaluating adversarial robustness,” arXiv:1902.06705 , 2019
Original
2019
Earlier work this paper cites.
Q. Xiao, Y. Chen, C. Shen, Y. Chen, and K. Li, “Seeing is not believing: Camouflage attacks on image scaling algorithms,” in USENIX Security Symposium , 2019
2019
Earlier work this paper cites.
A. Demontis, M. Melis, M. Pintor, M. Jagielski, B. Biggio, A. Oprea, C. Nita-Rotaru, and F. Roli, “Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks,” in USENIX Security Symposium , 2019
2019
Earlier work this paper cites.
Y. Yao, H. Li, H. Zheng, and B. Y. Zhao, “Latent backdoor attacks on deep neural networks,” in ACM Conference on Computer and Communications Security , 2019
2019
Earlier work this paper cites.
“How not to get scammed, according to a former con artist,” https://www.vox.com/the-goods/2019/8/29/20836745/frank-abagnale-scam-me-if-you-can , 2019
2019
Earlier work this paper cites.
M. De Shon, “Information Security Analysis as Data Fusion,” in IEEE Int. Conf. Inf. Fusion , 2019
2019
Earlier work this paper cites.
G. Apruzzese, M. Colajanni, L. Ferretti, and M. Marchetti, “Addressing adversarial attacks against security systems based on machine learning,” in Proc. IEEE Int. Conf. Cyber Conflicts , May 2019, pp. 1–18
2019
Earlier work this paper cites.
N. H. Imam and V. G. Vassilakis, “A survey of attacks against Twitter spam detectors in an adversarial environment,” Robotics , 2019
2019
Earlier work this paper cites.
M. Nasr, R. Shokri, and A. Houmansadr, “Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning,” in IEEE Symposium on Security and Privacy , 2019
2019
Earlier work this paper cites.
K. T. Co, L. Muñoz-González, S. de Maupeou, and E. C. Lupu, “Procedural noise adversarial examples for black-box attacks on deep convolutional networks,” in ACM Conference on Computer and Communications Security , 2019
2019
Earlier work this paper cites.
Y. Zhao, H. Zhu, R. Liang, Q. Shen, S. Zhang, and K. Chen, “Seeing isn’t believing: Towards more robust adversarial attack against real world object detectors,” in ACM Conference on Computer and Communications Security , 2019
2019
Earlier work this paper cites.
Y. Mirsky, T. Mahler, I. Shelef, and Y. Elovici, “CT-GAN: Malicious tampering of 3d medical imagery using deep learning,” in USENIX Security Symposium , 2019
2019
Earlier work this paper cites.
S. Hong, P. Frigo, Y. Kaya, C. Giuffrida, and T. Dumitraș, “Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks,” in USENIX Security Symposium , 2019
2019
Earlier work this paper cites.
L. Batina, S. Bhasin, D. Jap, and S. Picek, “CSINN: Reverse engineering of neural network architectures through electromagnetic side channel,” in USENIX Security Symposium , 2019
2019
Earlier work this paper cites.
L. Tong, B. Li, C. Hajaj, C. Xiao, N. Zhang, and Y. Vorobeychik, “Improving robustness of ML classifiers against realizable evasion attacks using conserved features,” in USENIX Security Symposium , 2019
2019
Earlier work this paper cites.
M. Fischer, M. Balunovic, D. Drachsler-Cohen, T. Gehr, C. Zhang, and M. Vechev, “DL2: Training and querying neural networks with logic,” in International Conference on Machine Learning , 2019
2019
Earlier work this paper cites.
A. Shafahi, M. Najibi, M. A. Ghiasi, Z. Xu, J. Dickerson, C. Studer, L. S. Davis, G. Taylor, and T. Goldstein, “Adversarial training for free!” Advances in Neural Information Processing Systems , 2019
2019
Earlier work this paper cites.
E. Wong, L. Rice, and J. Z. Kolter, “Fast is better than free: Revisiting adversarial training,” in International Conference on Learning Representations , 2019
2019
Earlier work this paper cites.
J. Caldeira, F. B. e Abreu, J. Reis, and J. Cardoso, “Assessing software development teams’ efficiency using process mining,” in International Conference on Process Mining , 2019
2019
Earlier work this paper cites.
X. Ling, S. Ji, J. Zou, J. Wang, C. Wu, B. Li, and T. Wang, “DEEPSEC: A uniform platform for security analysis of deep learning model,” in IEEE Symposium on Security and Privacy , 2019
2019
Earlier work this paper cites.
N. Carlini, “A critique of the DEEPSEC platform for security analysis of deep learning models,” arXiv preprint arXiv:1905.07112 , 2019
Original
2019
Earlier work this paper cites.
S. Li, A. Neupane, S. Paul, C. Song, S. V. Krishnamurthy, A. K. Roy-Chowdhury, and A. Swami, “Stealthy adversarial perturbations against real-time video classification systems.” in Network and Distributed Systems Security Symposium , 2019
2019
Earlier work this paper cites.
A. Salem, Y. Zhang, M. Humbert, P. Berrang, M. Fritz, and M. Backes, “ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models,” in Network and Distributed Systems Security Symposium , 2019
2019
Earlier work this paper cites.
J. Li, S. Ji, T. Du, B. Li, and T. Wang, “Textbugger: Generating adversarial text against real-world applications,” in Network and Distributed Systems Security Symposium , 2019
2019
Earlier work this paper cites.
S. Ma and Y. Liu, “Nic: Detecting adversarial samples with neural network invariant checking,” in Network and Distributed Systems Security Symposium , 2019
2019
Earlier work this paper cites.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in IEEE Symposium on Security and Privacy , 2019
2019
Earlier work this paper cites.