Fetching the paper…
Reading the bibliography…
Adversarial machine learning (AML) studies the adversarial phenomenon of machine learning, which may make inconsistent or unexpected predictions with humans.
Discrete cosine transform
Nasir Ahmed, T_ Natarajan, and Kamisetty R Rao · 1974
Earlier work this paper cites.
Digital steganography: hiding data within data
Donovan Artz · 2001
Earlier work this paper cites.
The sybil attack
John R Douceur · 2002
Earlier work this paper cites.
Finding optimal least-significant-bit substitution in image hiding by dynamic programming strategy
Chin-Chen Chang, Ju-Yuan Hsiao, and Chi-Shiang Chan · 2003
Earlier work this paper cites.
Pattern Recognition and Machine Learning
Christopher M Bishop and Nasser M Nasrabadi · 2006
Earlier work this paper cites.
Model selection and estimation in regression with grouped variables
Ming Yuan and Yi Lin · 2006
Earlier work this paper cites.
Advances in differential evolution
Uday K Chakraborty · 2008
Earlier work this paper cites.
Learning structural svms with latent variables
Chun-Nam John Yu and Thorsten Joachims · 2009
Earlier work this paper cites.
How to flip a bit?
Michel Agoyan, Jean-Max Dutertre, Amir-Pasha Mirbaha, David Naccache, Anne-Lise Ribotta, and Assia Tria · 2010
Earlier work this paper cites.
Distributed optimization and statistical learning via the alternating direction method of multipliers
Stephen Boyd, Neal Parikh, Eric Chu, Borja Peleato, Jonathan Eckstein, et al · 2011
Earlier work this paper cites.
Maximizing non-monotone submodular functions
Uriel Feige, Vahab S Mirrokni, and Jan Vondrák · 2011
Earlier work this paper cites.
A family of nonparametric density estimation algorithms
Esteban G Tabak and Cristina V Turner · 2013
Earlier work this paper cites.
Generative adversarial nets
Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio · 2014
Earlier work this paper cites.
Flipping bits in memory without accessing them: An experimental study of dram disturbance errors
Yoongu Kim, Ross Daly, Jeremie Kim, Chris Fallin, Ji Hye Lee, Donghyuk Lee, Chris Wilkerson, Konrad Lai, and Onur Mutlu · 2014
Earlier work this paper cites.
Natural evolution strategies
Daan Wierstra, Tom Schaul, Tobias Glasmachers, Yi Sun, Jan Peters, and Jürgen Schmidhuber · 2014
Earlier work this paper cites.
Manitest: Are classifiers really invariant?
Alhussein Fawzi and Pascal Frossard · 2015
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Image style transfer using convolutional neural networks
Leon A Gatys, Alexander S Ecker, and Matthias Bethge · 2016
Earlier work this paper cites.
Federated learning: Strategies for improving communication efficiency
Jakub Konečnỳ, H Brendan McMahan, Felix X Yu, Peter Richtárik, Ananda Theertha Suresh, and Dave Bacon · 2016
Earlier work this paper cites.
Deepfool: a simple and accurate method to fool deep neural networks
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, and Pascal Frossard · 2016
Earlier work this paper cites.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z Berkay Celik, and Ananthram Swami · 2016
Earlier work this paper cites.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter · 2016
Earlier work this paper cites.
Hiding images in plain sight: Deep steganography
Shumeet Baluja · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Earlier work this paper cites.
Adversarial image perturbation for privacy protection–a game theory perspective
Seong Joon Oh, Mario Fritz, and Bernt Schiele · 2017
Earlier work this paper cites.
Fault injection attack on deep neural network
Yannan Liu, Lingxiao Wei, Bo Luo, and Qiang Xu · 2017
Earlier work this paper cites.
Universal adversarial perturbations
Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard · 2017
Earlier work this paper cites.
Fast feature fool: A data independent approach to universal adversarial perturbations
KR Mopuri, U Garg, and R Venkatesh Babu · 2017
Earlier work this paper cites.
Simple black-box adversarial perturbations for deep networks
Nina Narodytska and Shiva Prasad Kasiviswanathan · 2017
Earlier work this paper cites.
Random gradient-free minimization of convex functions
Yurii Nesterov and Vladimir Spokoiny · 2017
Earlier work this paper cites.
Foolbox: A python toolbox to benchmark the robustness of machine learning models
Jonas Rauber, Wieland Brendel, and Matthias Bethge · 2017
Earlier work this paper cites.
Turning your weakness into a strength: Watermarking deep neural networks by backdooring
Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet · 2018
Earlier work this paper cites.
Are image-agnostic universal adversarial perturbations for face recognition difficult to detect?
Akshay Agarwal, Richa Singh, Mayank Vatsa, and Nalini Ratha · 2018
Earlier work this paper cites.
Threat of adversarial attacks on deep learning in computer vision: A survey
Naveed Akhtar and Ajmal Mian · 2018
Earlier work this paper cites.
Synthesizing robust adversarial examples
Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok · 2018
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2018
Earlier work this paper cites.
Audio adversarial examples: Targeted attacks on speech-to-text
Nicholas Carlini and David Wagner · 2018
Earlier work this paper cites.
Attacking visual language grounding with adversarial examples: A case study on neural image captioning
Hongge Chen, Huan Zhang, Pin-Yu Chen, Jinfeng Yi, and Cho-Jui Hsieh · 2018
Earlier work this paper cites.
Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector
Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng Polo Chau · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Earlier work this paper cites.
Physical adversarial examples for object detectors
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Florian Tramèr, Atul Prakash, Tadayoshi Kohno, and Dawn Song · 2018
Earlier work this paper cites.
Robust physical-world attacks on deep learning visual classification
Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song · 2018
Earlier work this paper cites.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Earlier work this paper cites.
Geometric robustness of deep networks: analysis and improvement
Can Kanbak, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2018
Earlier work this paper cites.
Lavan: Localized and visible adversarial noise
Danny Karmon, Daniel Zoran, and Yoav Goldberg · 2018
Earlier work this paper cites.
Adversarial examples in the physical world
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2018
Earlier work this paper cites.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2018
Earlier work this paper cites.
Bi-real net: Enhancing the performance of 1-bit cnns with improved representational capability and advanced training algorithm
Zechun Liu, Baoyuan Wu, Wenhan Luo, Xin Yang, Wei Liu, and Kwang-Ting Cheng · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Generalizable data-free objective for crafting universal adversarial perturbations
Konda Reddy Mopuri, Aditya Ganeshan, and R Venkatesh Babu · 2018
Earlier work this paper cites.
Technical report on the cleverhans v2.1.0 adversarial examples library
Nicolas Papernot, Fartash Faghri, Nicholas Carlini, Ian Goodfellow, Reuben Feinman, Alexey Kurakin, Cihang Xie, Yash Sharma, Tom Brown, Aurko Roy, Alexander Matyasko, Vahid Behzadan, Karen Hambardzumyan, Zhishuai Zhang, Yi-Lin Juang, Zhi Li, Ryan Sheatsley, Abhibhav Garg, Jonathan Uesato, Willi Gierke, Yinpeng Dong, David Berthelot, Paul Hendricks, Jonas Rauber, and Rujun Long · 2018
Earlier work this paper cites.
Generative adversarial perturbations
Omid Poursaeed, Isay Katsman, Bicheng Gao, and Serge Belongie · 2018
Earlier work this paper cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein · 2018
Earlier work this paper cites.
Learning visually-grounded semantics from contrastive adversarial samples
Haoyue Shi, Jiayuan Mao, Tete Xiao, Yuning Jiang, and Jian Sun · 2018
Earlier work this paper cites.
Constructing unrestricted adversarial examples with generative models
Yang Song, Rui Shu, Nate Kushman, and Stefano Ermon · 2018
Earlier work this paper cites.
Generating adversarial examples with adversarial networks
Chaowei Xiao, Bo Li, Jun Yan Zhu, Warren He, Mingyan Liu, and Dawn Song · 2018
Earlier work this paper cites.
Spatially transformed adversarial examples
Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song · 2018
Earlier work this paper cites.
Fooling vision and language models despite localization and attention mechanism
Xiaojun Xu, Xinyun Chen, Chang Liu, Anna Rohrbach, Trevor Darrell, and Dawn Song · 2018
Earlier work this paper cites.
Generating adversarial examples with conditional generative adversarial net
Ping Yu, Kaitao Song, and Jianfeng Lu · 2018
Earlier work this paper cites.
An admm-based universal framework for adversarial attacks on deep neural networks
Pu Zhao, Sijia Liu, Yanzhi Wang, and Xue Lin · 2018
Earlier work this paper cites.
Sign bits are all you need for black-box attacks
Abdullah Al-Dujaili and Una-May O’Reilly · 2019
Earlier work this paper cites.
A new backdoor attack in cnns by training set corruption without label poisoning
Mauro Barni, Kassem Kallas, and Benedetta Tondi · 2019
Earlier work this paper cites.
Analyzing federated learning through an adversarial lens
Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo · 2019
Earlier work this paper cites.
Query-efficient hard-label black-box attack: An optimization-based approach
Minhao Cheng, Thong Le, Pin-Yu Chen, Huan Zhang, Jinfeng Yi, and Cho-Jui Hsieh · 2019
Earlier work this paper cites.
Improving black-box adversarial attacks with a transfer-based prior
Shuyu Cheng, Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Earlier work this paper cites.
Sparse and imperceivable adversarial attacks
Francesco Croce and Matthias Hein · 2019
Earlier work this paper cites.
Advfaces: Adversarial face synthesis
Debayan Deb, Jianbang Zhang, and Anil K Jain · 2019
Earlier work this paper cites.
AdverTorch v0.1: An adversarial robustness toolbox based on pytorch
Gavin Weiguang Ding, Luyu Wang, and Xiaomeng Jin · 2019
Earlier work this paper cites.
Evading defenses to transferable adversarial examples by translation-invariant attacks
Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu · 2019
Earlier work this paper cites.
Efficient decision-based black-box adversarial attacks on face recognition
Yinpeng Dong, Hang Su, Baoyuan Wu, Zhifeng Li, Wei Liu, Tong Zhang, and Jun Zhu · 2019
Earlier work this paper cites.
Exploring the landscape of spatial robustness
Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry · 2019
Earlier work this paper cites.
Badnets: Evaluating backdooring attacks on deep neural networks
Tianyu Gu, Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2019
Earlier work this paper cites.
Simple black-box adversarial attacks
Chuan Guo, Jacob Gardner, Yurong You, Andrew Gordon Wilson, and Kilian Weinberger · 2019
Earlier work this paper cites.
Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks
Yiwen Guo, Ziang Yan, and Changshui Zhang · 2019
Earlier work this paper cites.
Enhancing adversarial example transferability with an intermediate level attack
Qian Huang, Isay Katsman, Horace He, Zeqi Gu, Serge Belongie, and Ser-Nam Lim · 2019
Earlier work this paper cites.
Prior convictions: Black-box adversarial attacks with bandits and priors
Andrew Ilyas, Logan Engstrom, and Aleksander Madry · 2019
Earlier work this paper cites.
Connecting the digital and physical world: Improving the robustness of adversarial attacks
Steve TK Jan, Joseph Messou, Yen-Chen Lin, Jia-Bin Huang, and Gang Wang · 2019
Earlier work this paper cites.
Bert: Pre-training of deep bidirectional transformers for language understanding
Jacob Devlin Ming-Wei Chang Kenton and Lee Kristina Toutanova · 2019
Earlier work this paper cites.
Functional adversarial attacks
Cassidy Laidlaw and Soheil Feizi · 2019
Earlier work this paper cites.
Universal perturbation attack against image retrieval
Jie Li, Rongrong Ji, Hong Liu, Xiaopeng Hong, Yue Gao, and Qi Tian · 2019
Earlier work this paper cites.
Compressing convolutional neural networks via factorized convolutional filters
Tuanhui Li, Baoyuan Wu, Yujiu Yang, Yanbo Fan, Yong Zhang, and Wei Liu · 2019
Earlier work this paper cites.
Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks
Yandong Li, Lijun Li, Liqiang Wang, Tong Zhang, and Boqing Gong · 2019
Earlier work this paper cites.
Deepsec: A uniform platform for security analysis of deep learning model
Xiang Ling, Shouling Ji, Jiaxu Zou, Jiannan Wang, Chunming Wu, Bo Li, and Ting Wang · 2019
Earlier work this paper cites.
Perceptual-sensitive gan for generating adversarial patches
Aishan Liu, Xianglong Liu, Jiaxin Fan, Yuqing Ma, Anlan Zhang, Huiyuan Xie, and Dacheng Tao · 2019
Earlier work this paper cites.
Universal adversarial perturbation via prior driven uncertainty approximation
Hong Liu, Rongrong Ji, Jie Li, Baochang Zhang, Yue Gao, Yongjian Wu, and Feiyue Huang · 2019
Earlier work this paper cites.
signsgd via zeroth-order oracle
Sijia Liu, Pin-Yu Chen, Xiangyi Chen, and Mingyi Hong · 2019
Earlier work this paper cites.
A geometry-inspired decision-based attack
Yujia Liu, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2019
Earlier work this paper cites.
Sparsefool: A few pixels make a big difference
Apostolos Modas, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard · 2019
Earlier work this paper cites.
Parsimonious black-box adversarial attacks via efficient combinatorial optimization
Seungyong Moon, Gaon An, and Hyun Oh Song · 2019
Earlier work this paper cites.
Cross-domain transferability of adversarial perturbations
Muhammad Muzammal Naseer, Salman H Khan, Muhammad Haris Khan, Fahad Shahbaz Khan, and Fatih Porikli · 2019
Earlier work this paper cites.
Universal adversarial perturbations for speech recognition systems
Paarth Neekhara, Shehzeen Hussain, Prakhar Pandey, Shlomo Dubnov, Julian McAuley, and Farinaz Koushanfar · 2019
Earlier work this paper cites.
Adversarial robustness toolbox v1.0.0, 2019
Maria-Irina Nicolae, Mathieu Sinn, Minh Ngoc Tran, Beat Buesser, Ambrish Rawat, Martin Wistuba, Valentina Zantedeschi, Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, Ian M. Molloy, and Ben Edwards · 2019
Earlier work this paper cites.
Imperceptible, robust, and targeted adversarial examples for automatic speech recognition
Yao Qin, Nicholas Carlini, Garrison Cottrell, Ian Goodfellow, and Colin Raffel · 2019
Earlier work this paper cites.
Towards the first adversarially robust neural network model on mnist
Lukas Schott, Jonas Rauber, Matthias Bethge, and Wieland Brendel · 2019
Earlier work this paper cites.
A general framework for adversarial examples with objectives
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K Reiter · 2019
Earlier work this paper cites.
One pixel attack for fooling deep neural networks
Jiawei Su, Danilo Vasconcellos Vargas, and Kouichi Sakurai · 2019
Earlier work this paper cites.
An empirical study of example forgetting during deep neural network learning
Mariya Toneva, Alessandro Sordoni, Remi Tachet des Combes, Adam Trischler, Yoshua Bengio, and Geoffrey J. Gordon · 2019
Earlier work this paper cites.
Label-consistent backdoor attacks
Alexander Turner, Dimitris Tsipras, and Aleksander Madry · 2019
Earlier work this paper cites.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao · 2019
Earlier work this paper cites.
At-gan: A generative attack model for adversarial transferring on generative adversarial nets
Xiaosen Wang, Kun He, and John E Hopcroft · 2019
Earlier work this paper cites.
advpattern: Physical-world attacks on deep person re-identification via adversarially transformable patterns
Zhibo Wang, Siyan Zheng, Mengkai Song, Qian Wang, Alireza Rahimpour, and Hairong Qi · 2019
Earlier work this paper cites.
Sparse adversarial perturbations for videos
Xingxing Wei, Jun Zhu, Sha Yuan, and Hang Su · 2019
Earlier work this paper cites.
Wasserstein adversarial examples via projected sinkhorn iterations
Eric Wong, Frank Schmidt, and Zico Kolter · 2019
Earlier work this paper cites.
Lp-box admm: A versatile framework for integer programming
Baoyuan Wu and Bernard Ghanem · 2019
Cited alongside, same era.
Dba: Distributed backdoor attacks against federated learning
Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li · 2019
Cited alongside, same era.
Improving transferability of adversarial examples with input diversity
Cihang Xie, Zhishuai Zhang, Yuyin Zhou, Song Bai, Jianyu Wang, Zhou Ren, and Alan L Yuille · 2019
Cited alongside, same era.
Structured adversarial attack: Towards general implementation and better interpretability
Kaidi Xu, Sijia Liu, Pu Zhao, Pin-Yu Chen, Huan Zhang, Deniz Erdogmus, Yanzhi Wang, and Xue Lin · 2019
Cited alongside, same era.
Exact adversarial attack to image captioning via structured output learning with latent variables
Yan Xu, Baoyuan Wu, Fumin Shen, Yanbo Fan, Yong Zhang, Heng Tao Shen, and Wei Liu · 2019
Cited alongside, same era.
Robust audio adversarial example for a physical attack
Enhancing the transferability of adversarial attacks through variance tuning
Xiaosen Wang and Kun He · 2021
Later among the works it cites.
Admix: Enhancing the transferability of adversarial attacks
Xiaosen Wang, Xuanran He, Jingdong Wang, and Kun He · 2021
Later among the works it cites.
Boosting adversarial transferability through enhanced momentum
Xiaosen Wang, Jiadong Lin, Han Hu, Jingdong Wang, and Kun He · 2021
Later among the works it cites.
A unified approach to interpreting and boosting adversarial transferability
Xin Wang, Jie Ren, Shuyun Lin, Xiangming Zhu, Yisen Wang, and Quanshi Zhang · 2021
Later among the works it cites.
Feature importance-aware transferable adversarial attacks
Zhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu, Zhan Qin, and Kui Ren · 2021
Later among the works it cites.
Backdoor attacks against deep learning systems in the physical world
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Hiromu Yakura and Jun Sakuma · 2019
Cited alongside, same era.
Latent backdoor attacks on deep neural networks
Yuanshun Yao, Huiying Li, Haitao Zheng, and Ben Y Zhao · 2019
Cited alongside, same era.
Adversarial examples: Opportunities and challenges
Jiliang Zhang and Chen Li · 2019
Cited alongside, same era.
Fault sneaking attack: A stealthy framework for misleading deep neural networks
Pu Zhao, Siyue Wang, Cheng Gongye, Yanzhi Wang, Yunsi Fei, and Xue Lin · 2019
Cited alongside, same era.
Seeing isn’t believing: Towards more robust adversarial attack against real world object detectors
Yue Zhao, Hong Zhu, Ruigang Liang, Qintao Shen, Shengzhi Zhang, and Kai Chen · 2019
Cited alongside, same era.
Square attack: a query-efficient black-box adversarial attack via random search
Maksym Andriushchenko, Francesco Croce, Nicolas Flammarion, and Matthias Hein · 2020
Cited alongside, same era.
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov · 2020
Cited alongside, same era.
Emily Wenger, Josephine Passananti, Arjun Nitin Bhagoji, Yuanshun Yao, Haitao Zheng, and Ben Y Zhao · 2021
Later among the works it cites.
A backdoor attack against 3d point cloud classifiers
Zhen Xiang, David J Miller, Siheng Chen, Xi Li, and George Kesidis · 2021
Later among the works it cites.
Enabling fast and universal audio adversarial attack using generative model
Yi Xie, Zhuohang Li, Cong Shi, Jian Liu, Yingying Chen, and Bo Yuan · 2021
Later among the works it cites.
Dehib: Deep hidden backdoor attack on semi-supervised learning via adversarial perturbation
Zhicong Yan, Gaolei Li, Yuan TIan, Jun Wu, Shenghong Li, Mingzhe Chen, and H Vincent Poor · 2021
Later among the works it cites.
Meta-learning the search distribution of black-box random search based adversarial attacks
Maksym Yatsura, Jan Metzen, and Matthias Hein · 2021
Later among the works it cites.
Consistency-sensitivity guided ensemble black-box adversarial attacks in low-dimensional spaces
Jianhe Yuan and Zhihai He · 2021
Later among the works it cites.
Meta gradient adversarial attack
Zheng Yuan, Jie Zhang, Yunpei Jia, Chuanqi Tan, Tao Xue, and Shiguang Shan · 2021
Later among the works it cites.
Openattack: An open-source textual adversarial attack toolkit
Guoyang Zeng, Fanchao Qi, Qianrui Zhou, Tingji Zhang, Bairu Hou, Yuan Zang, Zhiyuan Liu, and Maosong Sun · 2021
Later among the works it cites.
Advdoor: Adversarial backdoor attack of deep learning system
Quan Zhang, Yifeng Ding, Yongqiang Tian, Jianmin Guo, Min Yuan, and Yu Jiang · 2021
Later among the works it cites.
Trojaning language models for fun and profit
Xinyang Zhang, Zheng Zhang, Shouling Ji, and Ting Wang · 2021
Later among the works it cites.
How to inject backdoors with better consistency: Logit anchoring on clean data
Zhiyuan Zhang, Lingjuan Lyu, Weiqiang Wang, Lichao Sun, and Xu Sun · 2021
Later among the works it cites.
On success and simplicity: A second look at transferable targeted attacks
Zhengyu Zhao, Zhuoran Liu, and Martha Larson · 2021
Later among the works it cites.
Versatile weight attack via flipping limited bits
Jiawang Bai, Baoyuan Wu, Zhifeng Li, and Shu-tao Xia · 2022
Later among the works it cites.
Improving the transferability of targeted adversarial examples through object-based diverse input
Junyoung Byun, Seungju Cho, Myung-Joon Kwon, Hee-Seon Kim, and Changick Kim · 2022
Later among the works it cites.
Badprompt: backdoor attacks on continuous prompts
Xiangrui Cai, Sihan Xu, Ying Zhang, and Xiaojie Yuan · 2022
Later among the works it cites.
Black-box attacks via surrogate ensemble search
Zikui Cai, Chengyu Song, Srikanth Krishnamurthy, Amit Roy-Chowdhury, and M Salman Asif · 2022
Later among the works it cites.
Adversarial attack on attackers: Post-process to mitigate black-box score-based query attacks
Sizhe Chen, Zhehao Huang, Qinghua Tao, Yingwen Wu, Cihang Xie, and Xiaolin Huang · 2022
Later among the works it cites.
Effective backdoor defense by exploiting sensitivity of poisoned samples
Weixin Chen, Baoyuan Wu, and Haoqian Wang · 2022
Later among the works it cites.
A unified evaluation of textual backdoor learning: Frameworks and benchmarks
Ganqu Cui, Lifan Yuan, Bingxiang He, Yangyi Chen, Zhiyuan Liu, and Maosong Sun · 2022
Later among the works it cites.
Marksman backdoor: Backdoor attacks with arbitrary target class
Khoa D Doan, Yingjie Lao, and Ping Li · 2022
Later among the works it cites.
Query-efficient black-box adversarial attacks guided by a transfer-based prior
Yinpeng Dong, Shuyu Cheng, Tianyu Pang, Hang Su, and Jun Zhu · 2022
Later among the works it cites.
Ppt: Backdoor attacks on pre-trained models via poisoned prompt tuning
Wei Du, Yichun Zhao, Boqun Li, Gongshen Liu, and Shilin Wang · 2022
Later among the works it cites.
Ppt: Backdoor attacks on pre-trained models via poisoned prompt tuning
Wei Du, Yichun Zhao, Boqun Li, Gongshen Liu, and Shilin Wang · 2022
Later among the works it cites.
Stealthy backdoor attack with adversarial training
Le Feng, Sheng Li, Zhenxing Qian, and Xinpeng Zhang · 2022
Later among the works it cites.
Fiba: Frequency-injection based backdoor attack in medical image analysis
Yu Feng, Benteng Ma, Jing Zhang, Shanshan Zhao, Yong Xia, and Dacheng Tao · 2022
Later among the works it cites.
Boosting black-box attack with partially transferred conditional adversarial distribution
Yan Feng, Baoyuan Wu, Yanbo Fan, Li Liu, Zhifeng Li, and Shutao Xia · 2022
Later among the works it cites.
Imperceptible and robust backdoor attack in 3d point cloud
Kuofeng Gao, Jiawang Bai, Baoyuan Wu, Mengxi Ya, and Shu-Tao Xia · 2022
Later among the works it cites.
Stealthy attack on algorithmic-protected dnns via smart bit flipping
Behnam Ghavami, Seyd Movi, Zhenman Fang, and Lesley Shannon · 2022
Later among the works it cites.
Physical backdoor attacks to lane detection systems in autonomous driving
Xingshuo Han, Guowen Xu, Yuan Zhou, Xuehuan Yang, Jiwei Li, and Tianwei Zhang · 2022
Later among the works it cites.
Few-shot backdoor attacks via neural tangent kernels
Jonathan Hayase and Sewoong Oh · 2022
Later among the works it cites.
Handcrafted backdoors in deep neural networks
Sanghyun Hong, Nicholas Carlini, and Alexey Kurakin · 2022
Later among the works it cites.
Membership inference via backdooring
Hongsheng Hu, Zoran Salcic, Gillian Dobbie, Jinjun Chen, Lichao Sun, and Xuyun Zhang · 2022
Later among the works it cites.
Backdoor defense via decoupling the training process
Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, and Kui Ren · 2022
Later among the works it cites.
Las-at: Adversarial training with learnable attack strategy
Xiaojun Jia, Yong Zhang, Baoyuan Wu, Ke Ma, Jue Wang, and Xiaochun Cao · 2022
Later among the works it cites.
Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection
Yiming Li, Yang Bai, Yong Jiang, Yong Yang, Shu-Tao Xia, and Bo Li · 2022
Later among the works it cites.
Frequency domain model augmentation for adversarial attack
Yuyang Long, Qilong Zhang, Boheng Zeng, Lianli Gao, Xianglong Liu, Jian Zhang, and Jingkuan Song · 2022
Later among the works it cites.
Hibernated backdoor: A mutual information empowered backdoor attack to deep neural networks
Rui Ning, Jiang Li, Chunsheng Xin, Hongyi Wu, and Chonggang Wang · 2022
Later among the works it cites.
Trojanzoo: Towards unified, holistic, and practical evaluation of neural backdoors
Ren Pang, Zheng Zhang, Xiangshan Gao, Zhaohan Xi, Shouling Ji, Peng Cheng, and Ting Wang · 2022
Later among the works it cites.
Ignore previous prompt: Attack techniques for language models
Fábio Perez and Ian Ribeiro · 2022
Later among the works it cites.
Ribac: Towards r obust and i mperceptible b ackdoor a ttack against c ompact dnn
Huy Phan, Cong Shi, Yi Xie, Tianfang Zhang, Zhuohang Li, Tianming Zhao, Jian Liu, Yan Wang, Yingying Chen, and Bo Yuan · 2022
Later among the works it cites.
Invisible and efficient backdoor attacks for compressed deep neural networks
Huy Phan, Yi Xie, Jian Liu, Yingying Chen, and Bo Yuan · 2022
Later among the works it cites.
Revisiting the assumption of latent separability for backdoor defenses
Xiangyu Qi, Tinghao Xie, Yiming Li, Saeed Mahloujifar, and Prateek Mittal · 2022
Later among the works it cites.
Towards practical deployment-stage backdoor attack on deep neural networks
Xiangyu Qi, Tinghao Xie, Ruizhe Pan, Jifeng Zhu, Yong Yang, and Kai Bu · 2022
Later among the works it cites.
Boosting the transferability of adversarial attacks with reverse adversarial perturbation
Zeyu Qin, Yanbo Fan, Yi Liu, Li Shen, Yong Zhang, Jue Wang, and Baoyuan Wu · 2022
Later among the works it cites.
T-bfa: Targeted bit-flip adversarial weight attack
Adnan Siraj Rakin, Zhezhi He, Jingtao Li, Fan Yao, Chaitali Chakrabarti, and Deliang Fan · 2022
Later among the works it cites.
Dynamic backdoor attacks against machine learning models
Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang · 2022
Later among the works it cites.
Facehack: Attacking facial recognition systems using malicious facial characteristics
Esha Sarkar, Hadjer Benkraouda, Gopika Krishnan, Homer Gamil, and Michail Maniatakos · 2022
Later among the works it cites.
Promptattack: Prompt-based attack for language models via gradient search
Yundi Shi, Piji Li, Changchun Yin, Zhaoyang Han, Lu Zhou, and Zhe Liu · 2022
Later among the works it cites.
Tools and practices for responsible ai engineering
Ryan Soklaski, Justin Goodwin, Olivia Brown, Michael Yee, and Jason Matterer · 2022
Later among the works it cites.
Sleeper agent: Scalable hidden trigger backdoors for neural networks trained from scratch
Hossein Souri, Liam Fowl, Rama Chellappa, Micah Goldblum, and Tom Goldstein · 2022
Later among the works it cites.
Stealthy backdoors as compression artifacts
Yulong Tian, Fnu Suya, Fengyuan Xu, and David Evans · 2022
Later among the works it cites.
An invisible black-box backdoor attack through frequency domain
Tong Wang, Yuan Yao, Feng Xu, Shengwei An, Hanghang Tong, and Ting Wang · 2022
Later among the works it cites.
Dispersed pixel perturbation-based imperceptible backdoor trigger for image classifier models
Yulong Wang, Minghui Zhao, Shenghong Li, Xin Yuan, and Wei Ni · 2022
Later among the works it cites.
Bppattack: Stealthy and efficient trojan attacks against deep neural networks via image quantization and contrastive adversarial learning
Zhenting Wang, Juan Zhai, and Shiqing Ma · 2022
Later among the works it cites.
Thinking two moves ahead: Anticipating other users improves backdoor attacks in federated learning
Yuxin Wen, Jonas Geiping, Liam Fowl, Hossein Souri, Rama Chellappa, Micah Goldblum, and Tom Goldstein · 2022
Later among the works it cites.
Backdoorbench: A comprehensive benchmark of backdoor learning
Baoyuan Wu, Hongrui Chen, Mingda Zhang, Zihao Zhu, Shaokui Wei, Danni Yuan, and Chao Shen · 2022
Later among the works it cites.
Data-efficient backdoor attacks
Pengfei Xia, Ziqiang Li, Wei Zhang, and Bin Li · 2022
Later among the works it cites.
Data-efficient backdoor attacks
Pengfei Xia, Ziqiang Li, Wei Zhang, and Bin Li · 2022
Later among the works it cites.
Stochastic variance reduced ensemble adversarial attack for boosting the adversarial transferability
Yifeng Xiong, Jiadong Lin, Min Zhang, John E. Hopcroft, and Kun He · 2022
Later among the works it cites.
Exploring the universal vulnerability of prompt-based learning paradigm
Lei Xu, Yangyi Chen, Ganqu Cui, Hongcheng Gao, and Zhiyuan Liu · 2022
Later among the works it cites.
Ptb: Robust physical backdoor attacks against deep neural networks in real world
Mingfu Xue, Can He, Yinghao Wu, Shichang Sun, Yushu Zhang, Jian Wang, and Weiqiang Liu · 2022
Later among the works it cites.
Generalizable black-box adversarial attack with meta learning
Fei Yin, Yong Zhang, Baoyuan Wu, Yan Feng, Jingyi Zhang, Yanbo Fan, and Yujiu Yang · 2022
Later among the works it cites.
Poison ink: Robust and invisible backdoor attack
Jie Zhang, Chen Dongdong, Qidong Huang, Jing Liao, Weiming Zhang, Huamin Feng, Gang Hua, and Nenghai Yu · 2022
Later among the works it cites.
Improving adversarial transferability via neuron attribution-based attacks
Jianping Zhang, Weibin Wu, Jen-tse Huang, Yizhan Huang, Wenxuan Wang, Yuxin Su, and Michael R Lyu · 2022
Later among the works it cites.
Neurotoxin: durable backdoors in federated learning
Zhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang, Michael Mahoney, Prateek Mittal, Ramchandran Kannan, and Joseph Gonzalez · 2022
Later among the works it cites.
Ap-gan: Adversarial patch attack on content-based image retrieval systems
Guoping Zhao, Mingyu Zhang, Jiajun Liu, Yaxian Li, and Ji-Rong Wen · 2022
Later among the works it cites.
Defeat: Deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints
Zhendong Zhao, Xiaojun Chen, Yuexin Xuan, Ye Dong, Dakui Wang, and Kaitai Liang · 2022
Later among the works it cites.
Imperceptible backdoor attack: from input space to feature representation
Nan Zhong, Zhenxing Qian, and Xinpeng Zhang · 2022
Later among the works it cites.
Adversarial eigen attack on black-box models
Linjun Zhou, Peng Cui, Xingxuan Zhang, Yinan Jiang, and Shiqiang Yang · 2022
Later among the works it cites.
Toward understanding and boosting adversarial transferability from a distribution perspective
Yao Zhu, Yuefeng Chen, Xiaodan Li, Kejiang Chen, Yuan He, Xiang Tian, Bolun Zheng, Yaowu Chen, and Qingming Huang · 2022
Later among the works it cites.
Rethinking adversarial transferability from a data distribution perspective
Yao Zhu, Jiacheng Sun, and Zhenguo Li · 2022
Later among the works it cites.
Architectural backdoors in neural networks
Mikel Bober-Irizar, Ilia Shumailov, Yiren Zhao, Robert Mullins, and Nicolas Papernot · 2023
Closest in time.
The dark side of dynamic routing neural networks: Towards efficiency backdoor injection
Simin Chen, Hanlin Chen, Mirazul Haque, Cong Liu, and Wei Yang · 2023
Closest in time.
Trojdiff: Trojan attacks on diffusion models with diverse targets
Weixin Chen, Dawn Song, and Bo Li · 2023
Closest in time.
How to backdoor diffusion models?
Sheng-Yen Chou, Pin-Yu Chen, and Tsung-Yi Ho · 2023
Closest in time.
Villandiffusion: A unified backdoor attack framework for diffusion models
Sheng-Yen Chou, Pin-Yu Chen, and Tsung-Yi Ho · 2023
Closest in time.
Label poisoning is all you need
Rishi Dev Jha, Jonathan Hayase, and Sewoong Oh · 2023
Closest in time.
Color backdoor: A robust poisoning attack in color space
Wenbo Jiang, Hongwei Li, Guowen Xu, and Tianwei Zhang · 2023
Closest in time.
Black-box dataset ownership verification via backdoor watermarking
Yiming Li, Mingyan Zhu, Xue Yang, Yong Jiang, Tao Wei, and Shu-Tao Xia · 2023
Closest in time.
A proxy-free strategy for practically improving the poisoning efficiency in backdoor attacks
Ziqiang Li, Hong Sun, Pengfei Xia, Beihao Xia, Xue Rui, Wei Zhang, and Bin Li · 2023
Closest in time.
Explore the effect of data selection on poison efficiency in backdoor attacks
Ziqiang Li, Pengfei Xia, Hong Sun, Yueqi Zeng, Wei Zhang, and Bin Li · 2023
Closest in time.
Prompt injection attack against llm-integrated applications
Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, and Yang Liu · 2023
Closest in time.
Iba: Towards irreversible backdoor attacks in federated learning
Dung Thuy Nguyen, Tuan Minh Nguyen, Anh Tuan Tran, Khoa D Doan, and KOK SENG WONG · 2023
Closest in time.
Badgpt: Exploring security vulnerabilities of chatgpt via backdoor attacks to instructgpt
Jiawen Shi, Yixin Liu, Pan Zhou, and Lichao Sun · 2023
Closest in time.
Query-efficient black-box adversarial attack with customized iteration and sampling
Yucheng Shi, Yahong Han, Qinghua Hu, Yi Yang, and Qi Tian · 2023
Closest in time.
Rickrolling the artist: Injecting backdoors into text encoders for text-to-image synthesis
Lukas Struppek, Dominik Hintersdorf, and Kristian Kersting · 2023
Closest in time.
Hiding visual information via obfuscating adversarial perturbations
Zhigang Su, Dawei Zhou, Nannan Wang, Decheng Liu, Zhen Wang, and Xinbo Gao · 2023
Closest in time.
Poisoning language models during instruction tuning
Alexander Wan, Eric Wallace, Sheng Shen, and Dan Klein · 2023
Closest in time.
Robust backdoor attack with visible, semantic, sample-specific, and compatible triggers
Ruotong Wang, Hongrui Chen, Zihao Zhu, Li Liu, Yong Zhang, Yanbo Fan, and Baoyuan Wu · 2023
Closest in time.
Defenses in adversarial machine learning: A survey, 2023
Baoyuan Wu, Shaokui Wei, Mingli Zhu, Meixi Zheng, Zihao Zhu, Mingda Zhang, Hongrui Chen, Danni Yuan, Li Liu, and Qingshan Liu · 2023
Closest in time.
Computation and data efficient backdoor attacks
Yutong Wu, Xingshuo Han, Han Qiu, and Tianwei Zhang · 2023
Closest in time.
Trojllm: A black-box trojan prompt attack on large language models
Jiaqi Xue, Mengxin Zheng, Ting Hua, Yilin Shen, Yepeng Liu, Ladislau Boloni, and Qian Lou · 2023
Closest in time.
Poisonprompt: Backdoor attack on prompt-based large language models
Hongwei Yao, Jian Lou, and Zhan Qin · 2023
Closest in time.
Backdoor attacks against deep image compression via adaptive frequency trigger
Yi Yu, Yufei Wang, Wenhan Yang, Shijian Lu, Yap-Peng Tan, and Alex C Kot · 2023
Closest in time.
A3fl: Adversarially adaptive backdoor attacks to federated learning
Hangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin, and Dinghao Wu · 2023
Closest in time.
Robust physical-world attacks on face recognition
Xin Zheng, Yanbo Fan, Baoyuan Wu, Yong Zhang, Jue Wang, and Shirui Pan · 2023
Closest in time.
Autodan: Automatic and interpretable adversarial attacks on large language models
Sicheng Zhu, Ruiyi Zhang, Bang An, Gang Wu, Joe Barrow, Zichao Wang, Furong Huang, Ani Nenkova, and Tong Sun · 2023
Closest in time.
Boosting backdoor attack with a learnable poisoning sample selection strategy
Zihao Zhu, Mingda Zhang, Shaokui Wei, Li Shen, Yanbo Fan, and Baoyuan Wu · 2023
Closest in time.