Fetching the paper…
Reading the bibliography…
ML models are known to be vulnerable to adversarial query attacks.
P. C. Fishburn, “Letter to the editor—additive utilities with incomplete product sets: Application to priorities and assignments,” Operations Research , vol. 15, no. 3, pp. 537–542, 1967. [Online]. Available: https://doi.org/10.1287/opre.15.3.537
1967
Earlier work this paper cites.
R. Braden et al. , “Rfc1636: Report of iab workshop on security in the internet architecture - february 8-10, 1994,” USA, 1994
1994
Earlier work this paper cites.
F. Pukelsheim, “The three sigma rule,” The American Statistician , vol. 48, no. 2, pp. 88–91, 1994. [Online]. Available: http://www.jstor.org/stable/2684253
1994
Earlier work this paper cites.
J. R. Douceur, “The sybil attack,” in Revised Papers from the First International Workshop on Peer-to-Peer Systems , ser. IPTPS ’01. Berlin, Heidelberg: Springer-Verlag, 2002, p. 251–260
2002
Earlier work this paper cites.
S. Dreiseitl et al. , “Logistic regression and artificial neural network classification models: a methodology review,” Journal of biomedical informatics , vol. 35, no. 5-6, pp. 352–359, 2002
2002
Earlier work this paper cites.
A. Moser et al. , “Limits of static analysis for malware detection,” in Twenty-third annual computer security applications conference (ACSAC 2007) . IEEE, 2007, pp. 421–430
2007
Earlier work this paper cites.
F. Maggi et al. , “Protecting a moving target: Addressing web application concept drift,” in Proceedings of the 12th International Symposium on Recent Advances in Intrusion Detection , ser. RAID ’09. Berlin, Heidelberg: Springer-Verlag, 2009, p. 21–40. [Online]. Available: https://doi.org/10.1007/978-3-642-04342-0_2
2009
Earlier work this paper cites.
C. Rossow et al. , “Prudent practices for designing malware experiments: Status quo and outlook,” in 2012 IEEE Symposium on Security and Privacy , 2012, pp. 65–79
2012
Earlier work this paper cites.
B. Biggio et al. , “Evasion attacks against machine learning at test time,” in Joint European conference on machine learning and knowledge discovery in databases . Springer, 2013, pp. 387–402
2013
Earlier work this paper cites.
R. K. Shahzad et al. , “Comparative analysis of voting schemes for ensemble-based malware detection,” Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications , vol. 4, no. 1, pp. 98–117, 2013
2013
Earlier work this paper cites.
2014
Earlier work this paper cites.
P. Laskov et al. , “Practical evasion of a learning-based classifier: A case study,” in 2014 IEEE symposium on security and privacy . IEEE, 2014, pp. 197–211
2014
Earlier work this paper cites.
D. Arp et al. , “Drebin: Effective and explainable detection of android malware in your pocket.” in Ndss , vol. 14, 2014, pp. 23–26
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
J. Schmidhuber, “Deep learning in neural networks: An overview,” Neural networks , vol. 61, pp. 85–117, 2015
2015
Earlier work this paper cites.
N. Papernot et al. , “Distillation as a defense to adversarial perturbations against deep neural networks,” in 2016 IEEE Symposium on Security and Privacy (SP) . IEEE, 2016, pp. 582–597
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
B. Miller et al. , “Reviewer integration and performance measurement for malware detection,” in International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment . Springer, 2016, pp. 122–141
2016
Earlier work this paper cites.
K. Allix et al. , “Androzoo: Collecting millions of android apps for the research community,” in Proceedings of the 13th International Conference on Mining Software Repositories , ser. MSR ’16. New York, NY, USA: ACM, 2016, pp. 468–471. [Online]. Available: http://doi.acm.org/10.1145/2901739.2903508
2016
Earlier work this paper cites.
A. Kurakin et al. , “Adversarial examples in the physical world,” 2016
2016
Earlier work this paper cites.
N. Papernot et al. , “The limitations of deep learning in adversarial settings,” in 2016 IEEE European symposium on security and privacy (EuroS&P) . IEEE, 2016, pp. 372–387
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
K. Grosse et al. , “Adversarial examples for malware detection,” in European symposium on research in computer security . Springer, 2017, pp. 62–79
2017
Earlier work this paper cites.
A. Demontis et al. , “Yes, machine learning can be more secure! a case study on android malware detection,” IEEE Transactions on Dependable and Secure Computing , 2017
2017
Earlier work this paper cites.
N. Carlini et al. , “Towards evaluating the robustness of neural networks,” in 2017 ieee symposium on security and privacy (sp) . IEEE, 2017, pp. 39–57
2017
Earlier work this paper cites.
W. Yang et al. , “Malware detection in adversarial settings: Exploiting feature evolutions and confusions in android apps,” in Proceedings of the 33rd Annual Computer Security Applications Conference , 2017, pp. 288–302
2017
Earlier work this paper cites.
Jordaney et al., “Transcend: Detecting concept drift in malware classification models,” in 26th USENIX Security Symposium (USENIX Security 17) . Vancouver, BC: USENIX Association, Aug. 2017, pp. 625–642. [Online]. Available: https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/jordaney
2017
Earlier work this paper cites.
P.-Y. Chen et al. , “Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models,” in Proceedings of the 10th ACM workshop on artificial intelligence and security , 2017, pp. 15–26
2017
Earlier work this paper cites.
Z. Abaid et al. , “Quantifying the impact of adversarial evasion attacks on machine learning based android malware classifiers,” in 2017 IEEE 16th International Symposium on Network Computing and Applications (NCA) , 2017, pp. 1–10
2017
Earlier work this paper cites.
2017
Cited alongside, same era.
S. M. Lundberg et al. , “A unified approach to interpreting model predictions,” Advances in neural information processing systems , vol. 30, 2017
2017
Cited alongside, same era.
2017
Cited alongside, same era.
N. Papernot et al. , “Practical black-box attacks against machine learning.” Proceedings of the 2017 ACM on AsiA framework for enhancing deep neural networks against adversaria conference on computer and communications security , pp. 506–519, 2018
2018
Cited alongside, same era.
Pierazzi et al., “Intriguing properties of adversarial ml attacks in the problem space,” in 2020 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 2020, pp. 1308–1325. [Online]. Available: https://doi.ieeecomputersociety.org/10.1109/SP40000.2020.00073
2020
Later among the works it cites.
S. Chen et al. , “Stateful detection of black-box adversarial attacks,” in Proceedings of the 1st ACM Workshop on Security and Privacy on Artificial Intelligence , 2020, pp. 30–39
2020
Later among the works it cites.
S. Kariyappa et al. , “Defending against model stealing attacks with adaptive misinformation,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , June 2020
2020
Later among the works it cites.
B. G. Atli et al. , “Extraction of complex dnn models: Real threat or boogeyman?” in International Workshop on Engineering Dependable and Secure Machine Learning Systems . Springer, 2020, pp. 42–57
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
I. Rosenberg et al. , “Generic black-box end-to-end attack against state of the art api call based malware classifiers,” in International Symposium on Research in Attacks, Intrusions, and Defenses . Springer, 2018, pp. 490–510
2018
Cited alongside, same era.
S. Sengupta et al. , “Mtdeep: boosting the security of deep neural nets against adversarial attacks with moving target defense,” in Workshops at the Thirty-Second AAAI Conference on Artificial Intelligence , 2018
2018
Cited alongside, same era.
A. Ilyas et al. , “Black-box adversarial attacks with limited queries and information,” in International Conference on Machine Learning . PMLR, 2018, pp. 2137–2146
2018
Cited alongside, same era.
2018
Cited alongside, same era.
A. Al-Dujaili et al. , “Adversarial deep learning for robust detection of binary encoded malware,” in 2018 IEEE Security and Privacy Workshops (SPW) . IEEE, 2018, pp. 76–82
2018
Cited alongside, same era.
A. Athalye et al. , “Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples,” in International conference on machine learning . PMLR, 2018, pp. 274–283
2018
Cited alongside, same era.
N. Papernot et al. , “Sok: Security and privacy in machine learning,” in 2018 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE, 2018, pp. 399–414
2018
Cited alongside, same era.
S. Y. Yerima et al. , “Droidfusion: A novel multilevel classifier fusion approach for android malware detection,” IEEE transactions on cybernetics , vol. 49, no. 2, pp. 453–466, 2018
2018
Cited alongside, same era.
2020
Later among the works it cites.
S. Bulusu et al. , “Anomalous example detection in deep learning: A survey,” IEEE Access , vol. 8, pp. 132 330–132 347, 2020
2020
Later among the works it cites.
S. Afroz, “How to build realistic machine learning systems for security?” San Francisco, CA: USENIX Association, Jan. 2020
2020
Later among the works it cites.
O. A. Aslan et al. , “A comprehensive review on malware detection approaches,” IEEE Access , vol. 8, pp. 6249–6271, 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
F. Tramer et al. , “On adaptive attacks to adversarial example defenses,” Advances in Neural Information Processing Systems , vol. 33, pp. 1633–1645, 2020
2020
Later among the works it cites.
D. Hendrycks et al. , “Unsolved problems in ml safety,” arXiv preprint arXiv:2109.13916 , 2021
2021
Later among the works it cites.
Z. Zhang et al. , “Seat: Similarity encoder by adversarial training for detecting model extraction attack queries,” in Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security , ser. AISec ’21. New York, NY, USA: Association for Computing Machinery, 2021, p. 37–48. [Online]. Available: https://doi.org/10.1145/3474369.3486863
2021
Later among the works it cites.
2021
Later among the works it cites.
Z. Yan et al. , “Policy-driven attack: Learning to query for hard-label black-box adversarial examples,” in International Conference on Learning Representations , 2021. [Online]. Available: https://openreview.net/forum?id=pzpytjk3Xb2
2021
Later among the works it cites.
G. Severi et al. , “Explanation-guided backdoor poisoning attacks against malware classifiers,” in 30th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 21) , 2021
2021
Later among the works it cites.
D. Li et al. , “A framework for enhancing deep neural networks against adversarial malware,” IEEE Transactions on Network Science and Engineering , vol. 8, no. 1, pp. 736–750, 2021
2021
Later among the works it cites.
F. Ceschin et al. , “No need to teach new tricks to old malware: Winning an evasion challenge with xor-based adversarial samples,” in Reversing and Offensive-Oriented Trends Symposium , ser. ROOTS’20. New York, NY, USA: Association for Computing Machinery, 2021, p. 13–22. [Online]. Available: https://doi.org/10.1145/3433667.3433669
2021
Later among the works it cites.
G. Pang et al. , “Deep learning for anomaly detection: A review,” ACM Comput. Surv. , vol. 54, no. 2, mar 2021. [Online]. Available: https://doi.org/10.1145/3439950
2021
Later among the works it cites.
J. Ma et al. , “Partner-assisted learning for few-shot image classification,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2021, pp. 10 573–10 582
2021
Later among the works it cites.
A. Amich et al. , “Morphence: Moving target defense against adversarial examples,” in Annual Computer Security Applications Conference , ser. ACSAC. New York, NY, USA: Association for Computing Machinery, 2021, p. 61–75. [Online]. Available: https://doi.org/10.1145/3485832.3485899
2021
Later among the works it cites.
D. Li et al. , “Arms race in adversarial malware detection: A survey,” ACM Comput. Surv. , vol. 55, no. 1, nov 2021. [Online]. Available: https://doi.org/10.1145/3484491
2021
Later among the works it cites.
H. Li et al. , “Blacklight: Scalable defense for neural networks against Query-Based Black-Box attacks,” in 31st USENIX Security Symposium (USENIX Security 22) . Boston, MA: USENIX Association, Aug. 2022. [Online]. Available: https://www.usenix.org/conference/usenixsecurity22/presentation/li-huiying
2022
Later among the works it cites.
2022
Later among the works it cites.
M. Maghsoudimehrabani et al. , “Proactive detection of query-based adversarial scenarios in nlp systems,” in Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security , ser. AISec’22. New York, NY, USA: Association for Computing Machinery, 2022, p. 103–113. [Online]. Available: https://doi.org/10.1145/3560830.3563727
2022
Later among the works it cites.
D. Arp et al. , “Dos and don’ts of machine learning in computer security,” in Proc. of the USENIX Security Symposium , 2022
2022
Later among the works it cites.
Dauodi et al., “A deep dive inside drebin: An explorative analysis beyond android malware detection scores,” ACM Trans. Priv. Secur. , vol. 25, no. 2, may 2022. [Online]. Available: https://doi.org/10.1145/3503463
2022
Later among the works it cites.
F. Barbero et al. , “Transcending transcend: Revisiting malware classification in the presence of concept drift,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 805–823
2022
Later among the works it cites.
2022
Later among the works it cites.
G. Apruzzese et al. , “”real attackers don’t compute gradients”: Bridging the gap between adversarial ml research and practice,” in Proceedings of the 1st IEEE Conference on Secure and Trustworthy Machine Learning (SaTML) , 2023
2023
Closest in time.