Fetching the paper…
Reading the bibliography…
Most existing methods to detect backdoored machine learning (ML) models take one of the two approaches: trigger inversion (aka.
D. C. Liu and J. Nocedal, “On the limited memory bfgs method for large scale optimization,” Mathematical programming , vol. 45, no. 1-3, pp. 503–528, 1989
1989
Earlier work this paper cites.
Y. LeCun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proceedings of the IEEE , vol. 86, no. 11, pp. 2278–2324, 1998
1998
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” 2009
2009
Earlier work this paper cites.
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
Y. Le and X. S. Yang, “Tiny imagenet visual recognition challenge,” 2015
2015
Earlier work this paper cites.
H. Karimi, J. Nutini, and M. Schmidt, “Linear convergence of gradient and proximal-gradient methods under the polyak-łojasiewicz condition,” in Joint European conference on machine learning and knowledge discovery in databases . Springer, 2016, pp. 795–811
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
H. Li, S. De, Z. Xu, C. Studer, H. Samet, and T. Goldstein, “Training quantized nets: A deeper understanding,” Advances in Neural Information Processing Systems , vol. 30, 2017
2017
Earlier work this paper cites.
C. Cartis, N. I. Gould, and P. L. Toint, “Worst-case evaluation complexity and optimality of second-order methods for nonconvex smooth optimization,” in Proceedings of the International Congress of Mathematicians: Rio de Janeiro 2018 . World Scientific, 2018, pp. 3711–3750
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in International Symposium on Research in Attacks, Intrusions, and Defenses . Springer, 2018, pp. 273–294
2018
Earlier work this paper cites.
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein, “Poison frogs! targeted clean-label poisoning attacks on neural networks,” Advances in neural information processing systems , vol. 31, 2018
2018
Earlier work this paper cites.
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
Y. Liu, W.-C. Lee, G. Tao, S. Ma, Y. Aafer, and X. Zhang, “Abs: Scanning neural networks for back-doors by artificial brain stimulation,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , 2019, pp. 1265–1282
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
C. Shorten and T. M. Khoshgoftaar, “A survey on image data augmentation for deep learning,” Journal of big data , vol. 6, no. 1, pp. 1–48, 2019
2019
Earlier work this paper cites.
D. Terjék, “Adversarial lipschitz regularization,” arXiv preprint arXiv:1907.05681 , 2019
2019
Cited alongside, same era.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in 2019 IEEE Symposium on Security and Privacy (SP) . IEEE, 2019, pp. 707–723
2019
Cited alongside, same era.
Q. Yang, Y. Liu, Y. Cheng, Y. Kang, T. Chen, and H. Yu, “Federated learning,” Synthesis Lectures on Artificial Intelligence and Machine Learning , vol. 13, no. 3, pp. 1–207, 2019
2019
Cited alongside, same era.
2020
Cited alongside, same era.
G. Fields, M. Samragh, M. Javaheripi, F. Koushanfar, and T. Javidi, “Trojan signatures in dnn weights,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2021, pp. 12–20
2021
Later among the works it cites.
Y. Li, X. Lyu, N. Koren, L. Lyu, B. Li, and X. Ma, “Anti-backdoor learning: Training clean models on poisoned data,” in Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, NeurIPS 2021, December 6-14, 2021, virtual , 2021, pp. 14 900–14 912. [Online]. Available: https://proceedings.neurips.cc/paper/2021
2021
Later among the works it cites.
——, “Neural attention distillation: Erasing backdoor triggers from deep neural networks,” in 9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7, 2021 , 2021. [Online]. Available: https://openreview.net/forum?id=9l0K4OM-oXE
2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2020
Cited alongside, same era.
V. Krishnan, A. Makdah, A. AlRahman, and F. Pasqualetti, “Lipschitz bounds and provably robust training by laplacian smoothing,” Advances in Neural Information Processing Systems , vol. 33, pp. 10 924–10 935, 2020
2020
Cited alongside, same era.
2020
Cited alongside, same era.
J. Lin, L. Xu, Y. Liu, and X. Zhang, “Composite backdoor attack for deep neural network by mixing existing benign features,” in Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security , 2020, pp. 113–131
2020
Cited alongside, same era.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in European Conference on Computer Vision . Springer, 2020, pp. 182–199
2020
Cited alongside, same era.
R. Pang, H. Shen, X. Zhang, S. Ji, Y. Vorobeychik, X. Luo, A. Liu, and T. Wang, “A tale of evil twins: Adversarial inputs versus poisoned models,” in Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security , 2020, pp. 85–99
2020
Cited alongside, same era.
2020
Cited alongside, same era.
Y.-Y. Yang, C. Rashtchian, H. Zhang, R. Salakhutdinov, and K. Chaudhuri, “Adversarial robustness through local lipschitzness,” 2020
2020
Cited alongside, same era.
2021
Later among the works it cites.
2021
Later among the works it cites.
Y. Ren, L. Li, and J. Zhou, “Simtrojan: Stealthy backdoor attack,” in 2021 IEEE International Conference on Image Processing (ICIP) . IEEE, 2021, pp. 819–823
2021
Later among the works it cites.
G. Shen, Y. Liu, G. Tao, S. An, Q. Xu, S. Cheng, S. Ma, and X. Zhang, “Backdoor scanning for deep neural networks through k-arm optimization,” in International Conference on Machine Learning . PMLR, 2021, pp. 9525–9536
2021
Later among the works it cites.
I. Shumailov, Z. Shumaylov, D. Kazhdan, Y. Zhao, N. Papernot, M. A. Erdogdu, and R. J. Anderson, “Manipulating sgd with data ordering attacks,” Advances in Neural Information Processing Systems , vol. 34, pp. 18 021–18 032, 2021
2021
Later among the works it cites.
X. Xu, Q. Wang, H. Li, N. Borisov, C. A. Gunter, and B. Li, “Detecting ai trojans using meta neural analysis,” in 2021 IEEE Symposium on Security and Privacy (SP) . IEEE, 2021, pp. 103–120
2021
Later among the works it cites.
Z. Yao, A. Gholami, S. Shen, M. Mustafa, K. Keutzer, and M. Mahoney, “Adahessian: An adaptive second order optimizer for machine learning,” in Proceedings of the AAAI Conference on Artificial Intelligence , vol. 35, no. 12, 2021, pp. 10 665–10 673
2021
Later among the works it cites.
“Tdc 2022,” https://trojandetection.ai/ , accessed: 2022-09-30
2022
Later among the works it cites.
2022
Later among the works it cites.
2022
Later among the works it cites.
2022
Later among the works it cites.
2022
Later among the works it cites.
2022
Later among the works it cites.
Z. Zhao, X. Chen, Y. Xuan, Y. Dong, D. Wang, and K. Liang, “Defeat: Deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2022, pp. 15 213–15 222
2022
Later among the works it cites.