Fetching the paper…
Reading the bibliography…
Deep Learning backdoor attacks have a threat model similar to traditional cyber attacks.
1902
Earlier work this paper cites.
1908
Earlier work this paper cites.
1909
Earlier work this paper cites.
W. Hoeffding and H. Robbins, “The central limit theorem for dependent random variables,” Duke Mathematical Journal , vol. 15, no. 3, pp. 773–780, 1948
1948
Earlier work this paper cites.
R. L. Thorndike, “Who belongs in the family,” in Psychometrika . Citeseer, 1953
1953
Earlier work this paper cites.
S. Lloyd, “Least squares quantization in pcm,” IEEE transactions on information theory , vol. 28, no. 2, pp. 129–137, 1982
1982
Earlier work this paper cites.
P. J. Rousseeuw, “Silhouettes: a graphical aid to the interpretation and validation of cluster analysis,” Journal of computational and applied mathematics , vol. 20, pp. 53–65, 1987
1987
Earlier work this paper cites.
P. Schatte, “On strong versions of the central limit theorem,” Mathematische Nachrichten , vol. 137, no. 1, pp. 249–256, 1988
1988
Earlier work this paper cites.
M. Ester, H.-P. Kriegel, J. Sander, X. Xu et al. , “A density-based algorithm for discovering clusters in large spatial databases with noise.” in kdd , vol. 96, no. 34, 1996, pp. 226–231
1996
Earlier work this paper cites.
C. E. Rasmussen, “Gaussian processes in machine learning,” in Summer school on machine learning . Springer, 2003, pp. 63–71
2003
Earlier work this paper cites.
Q. Lu and X. Yao, “Clustering and learning gaussian distribution for continuous optimization,” IEEE Transactions on Systems, Man, and Cybernetics, Part C (Applications and Reviews) , vol. 35, no. 2, pp. 195–204, 2005
2005
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” 2009
2009
Earlier work this paper cites.
D. A. Reynolds, “Gaussian mixture models.” Encyclopedia of biometrics , vol. 741, no. 659-663, 2009
2009
Earlier work this paper cites.
F. Larsson, M. Felsberg, and P.-E. Forssen, “Correlating fourier descriptors of local patches for road sign recognition,” IET Computer Vision , vol. 5, no. 4, pp. 244–254, 2011
2011
Earlier work this paper cites.
2012
Earlier work this paper cites.
C. Le Goues, M. Dewey-Vogt, S. Forrest, and W. Weimer, “A systematic study of automated program repair: Fixing 55 out of 105 bugs for $8 each,” in 2012 34th International Conference on Software Engineering (ICSE) . IEEE, 2012, pp. 3–13
2012
Earlier work this paper cites.
J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, “Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition,” Neural networks , vol. 32, pp. 323–332, 2012
2012
Earlier work this paper cites.
A. Geiger, P. Lenz, C. Stiller, and R. Urtasun, “Vision meets robotics: The kitti dataset,” The International Journal of Robotics Research , vol. 32, no. 11, pp. 1231–1237, 2013
2013
Earlier work this paper cites.
H. D. T. Nguyen, D. Qi, A. Roychoudhury, and S. Chandra, “Semfix: Program repair via semantic analysis,” in 2013 35th International Conference on Software Engineering (ICSE) . IEEE, 2013, pp. 772–781
2013
Earlier work this paper cites.
I. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. Courville, and Y. Bengio, “Generative adversarial nets,” Advances in neural information processing systems , vol. 27, 2014
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
Z. Liu, P. Luo, X. Wang, and X. Tang, “Deep learning face attributes in the wild,” in 2015 IEEE International Conference on Computer Vision (ICCV) , 2015, pp. 3730–3738
2015
Earlier work this paper cites.
O. Russakovsky, J. Deng, H. Su, J. Krause, S. Satheesh, S. Ma, Z. Huang, A. Karpathy, A. Khosla, M. Bernstein, A. C. Berg, and L. Fei-Fei, “ImageNet Large Scale Visual Recognition Challenge,” International Journal of Computer Vision (IJCV) , vol. 115, no. 3, pp. 211–252, 2015
2015
Earlier work this paper cites.
M. Cordts, M. Omran, S. Ramos, T. Rehfeld, M. Enzweiler, R. Benenson, U. Franke, S. Roth, and B. Schiele, “The cityscapes dataset for semantic urban scene understanding,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 3213–3223
2016
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 770–778
2016
Earlier work this paper cites.
C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, and Z. Wojna, “Rethinking the inception architecture for computer vision,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016, pp. 2818–2826
2016
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) . Ieee, 2017, pp. 39–57
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
G. Huang, Z. Liu, L. Van Der Maaten, and K. Q. Weinberger, “Densely connected convolutional networks,” in Proceedings of the IEEE conference on computer vision and pattern recognition , 2017, pp. 4700–4708
2017
Earlier work this paper cites.
S. G. Kwak and J. H. Kim, “Central limit theorem: the cornerstone of modern statistics,” Korean journal of anesthesiology , vol. 70, no. 2, pp. 144–156, 2017
2017
Earlier work this paper cites.
Y. Liu, Y. Xie, and A. Srivastava, “Neural trojans,” in 2017 IEEE International Conference on Computer Design (ICCD) . IEEE, 2017, pp. 45–48
2017
Earlier work this paper cites.
S. Ma, J. Zhai, F. Wang, K. H. Lee, X. Zhang, and D. Xu, “Mpi: Multiple perspective attack investigation with semantics aware execution partitioning,” in USENIX Security , 2017
2017
Earlier work this paper cites.
M. Raissi, P. Perdikaris, and G. E. Karniadakis, “Machine learning of linear differential equations using gaussian processes,” Journal of Computational Physics , vol. 348, pp. 683–693, 2017
2017
Earlier work this paper cites.
R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, and D. Batra, “Grad-cam: Visual explanations from deep networks via gradient-based localization,” in Proceedings of the IEEE international conference on computer vision , 2017, pp. 618–626
2017
Earlier work this paper cites.
J.-Y. Zhu, T. Park, P. Isola, and A. A. Efros, “Unpaired image-to-image translation using cycle-consistent adversarial networks,” in Proceedings of the IEEE international conference on computer vision , 2017, pp. 2223–2232
2017
Cited alongside, same era.
W. Brendel, J. Rauber, and M. Bethge, “Decision-based adversarial attacks: Reliable attacks against black-box machine learning models,” in International Conference on Learning Representations , 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
2018
Cited alongside, same era.
2020
Later among the works it cites.
J. Lin, L. Xu, Y. Liu, and X. Zhang, “Composite backdoor attack for deep neural network by mixing existing benign features,” in Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security , 2020, pp. 113–131
2020
Later among the works it cites.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in European Conference on Computer Vision . Springer, 2020, pp. 182–199
2020
Later among the works it cites.
M. McCoyd, W. Park, S. Chen, N. Shah, R. Roggenkemper, M. Hwang, J. X. Liu, and D. Wagner, “Minority reports defense: Defending against adversarial patches,” in International Conference on Applied Cryptography and Network Security . Springer, 2020, pp. 564–582
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in International Symposium on Research in Attacks, Intrusions, and Defenses . Springer, 2018, pp. 273–294
2018
Cited alongside, same era.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in NDSS , 2018
2018
Cited alongside, same era.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, and A. Vladu, “Towards deep learning models resistant to adversarial attacks,” in International Conference on Learning Representations , 2018
2018
Cited alongside, same era.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in Advances in Neural Information Processing Systems , 2018, pp. 8000–8010
2018
Cited alongside, same era.
M. Wen, J. Chen, R. Wu, D. Hao, and S.-C. Cheung, “Context-aware patch generation for better automated program repair,” in 2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE) . IEEE, 2018, pp. 1–11
2018
Cited alongside, same era.
R. Zhang, P. Isola, A. A. Efros, E. Shechtman, and O. Wang, “The unreasonable effectiveness of deep features as a perceptual metric,” in CVPR , 2018
2018
Cited alongside, same era.
2019
Cited alongside, same era.
M. Du, R. Jia, and D. Song, “Robust anomaly detection and backdoor attack detection via differential privacy,” in International Conference on Learning Representations , 2019
2019
Cited alongside, same era.
F. Mentzer, G. D. Toderici, M. Tschannen, and E. Agustsson, “High-fidelity generative image compression,” Advances in Neural Information Processing Systems , vol. 33, pp. 11 913–11 924, 2020
2020
Later among the works it cites.
T. A. Nguyen and A. Tran, “Input-aware dynamic backdoor attack,” Advances in Neural Information Processing Systems , vol. 33, 2020
2020
Later among the works it cites.
T. A. Nguyen and A. T. Tran, “Wanet-imperceptible warping-based backdoor attack,” in International Conference on Learning Representations , 2020
2020
Later among the works it cites.
A. Saha, A. Subramanya, and H. Pirsiavash, “Hidden trigger backdoor attacks,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 34, no. 07, 2020, pp. 11 957–11 965
2020
Later among the works it cites.
2020
Later among the works it cites.
Y. Shen, Y. Xu, C. Yang, J. Zhu, and B. Zhou, “Genforce,” https://github.com/genforce/genforce , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
R. Wang, G. Zhang, S. Liu, P.-Y. Chen, J. Xiong, and M. Wang, “Practical detection of trojan neural networks: Data-limited and data-free cases,” in 16th European Conference on Computer Vision , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
P. Zhao, P.-Y. Chen, P. Das, K. N. Ramamurthy, and X. Lin, “Bridging mode connectivity in loss landscapes and adversarial robustness,” in International Conference on Learning Representations (ICLR 2020) , 2020
2020
Later among the works it cites.
X. Chen, H. Irshad, Y. Chen, A. Gehani, and V. Yegneswaran, “ { \{ CLARION } \} : Sound and clear provenance tracking for microservice deployments,” in 30th USENIX Security Symposium (USENIX Security 21) , 2021, pp. 3989–4006
2021
Later among the works it cites.
K. Doan, Y. Lao, and P. Li, “Backdoor attack with imperceptible input and latent modification,” Advances in Neural Information Processing Systems , vol. 34, pp. 18 944–18 957, 2021
2021
Later among the works it cites.
K. Doan, Y. Lao, W. Zhao, and P. Li, “Lira: Learnable, imperceptible and robust backdoor attacks,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2021, pp. 11 966–11 976
2021
Later among the works it cites.
P. Kiourti, W. Li, A. Roy, K. Sikka, and S. Jha, “Online defense of trojaned models using misattributions,” in Annual Computer Security Applications Conference (ACSAC) , 2021
2021
Later among the works it cites.
Y. Li, N. Koren, L. Lyu, X. Lyu, B. Li, and X. Ma, “Neural attention distillation: Erasing backdoor triggers from deep neural networks,” in International Conference on Learning Representations , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
G. Shen, Y. Liu, G. Tao, S. An, Q. Xu, S. Cheng, S. Ma, and X. Zhang, “Backdoor scanning for deep neural networks through k-arm optimization,” in International Conference on Machine Learning , 2021
2021
Later among the works it cites.
SRI-CSL, “Trinity-trojai,” 2021. [Online]. Available: https://github.com/SRI-CSL/Trinity-TrojAI
2021
Later among the works it cites.
D. Tang, X. Wang, H. Tang, and K. Zhang, “Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection,” in 30th USENIX Security Symposium (USENIX Security 21) , 2021
2021
Later among the works it cites.
D. Wu and Y. Wang, “Adversarial neuron pruning purifies backdoored deep models,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Later among the works it cites.
C. Xiang, A. N. Bhagoji, V. Sehwag, and P. Mittal, “Patchguard: A provably robust defense against adversarial patches via small receptive fields and masking,” in 30th USENIX Security Symposium (USENIX Security 21) , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
L. Yu, S. Ma, Z. Zhang, G. Tao, X. Zhang, D. Xu, V. E. Urias, H. W. Lin, G. Ciocarlie, V. Yegneswaran et al. , “Alchemist: Fusing application and audit logs for precise attack provenance without instrumentation,” in Proc. of NDSS , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
2022
Later among the works it cites.
G. Tao, Y. Liu, G. Shen, Q. Xu, S. An, Z. Zhang, and X. Zhang, “Model orthogonalization: Class distance hardening in neural networks for better security,” in 2022 IEEE Symposium on Security and Privacy (SP). IEEE , vol. 3, 2022
2022
Later among the works it cites.
G. Tao, G. Shen, Y. Liu, S. An, Q. Xu, S. Ma, P. Li, and X. Zhang, “Better trigger inversion optimization in backdoor scanning,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2022, pp. 13 368–13 378
2022
Later among the works it cites.
2022
Later among the works it cites.