Fetching the paper…
Reading the bibliography…
Backdoor data detection is traditionally studied in an end-to-end supervised learning (SL) setting.
G. Brys, M. Hubert, and P. Rousseeuw, “A robustification of independent component analysis,” Journal of Chemometrics: A Journal of the Chemometrics Society , vol. 19, no. 5-7, pp. 364–375, 2005
2005
Earlier work this paper cites.
A. Krizhevsky, G. Hinton et al. , “Learning multiple layers of features from tiny images,” 2009
2009
Earlier work this paper cites.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in CVPR , 2009, pp. 248–255
2009
Earlier work this paper cites.
A. Coates, A. Ng, and H. Lee, “An analysis of single-layer networks in unsupervised feature learning,” in Proceedings of the fourteenth international conference on artificial intelligence and statistics . JMLR, 2011
2011
Earlier work this paper cites.
L. Bottou, “Stochastic gradient descent tricks,” in Neural networks: Tricks of the trade . Springer, 2012
2012
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” in ICLR , 2014
2014
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
P. W. Koh and P. Liang, “Understanding black-box predictions via influence functions,” in ICML , 2017
2017
Earlier work this paper cites.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in NeurIPS , 2018, pp. 8000–8010
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, “Trojaning attack on neural networks,” in NDSS , 2018
2018
Earlier work this paper cites.
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,” IEEE Access , vol. 7, pp. 47 230–47 244, 2019
2019
Earlier work this paper cites.
Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal, “Strip: A defence against trojan attacks on deep neural networks,” in ACM ACSAC , 2019
2019
Earlier work this paper cites.
M. Tan and Q. Le, “Efficientnet: Rethinking model scaling for convolutional neural networks,” in ICML , 2019
2019
Earlier work this paper cites.
A. Turner, D. Tsipras, and A. Madry, “Label-consistent backdoor attacks,” arXiv:1912.02771 , 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
M. J. Wainwright, High-Dimensional Statistics: A Non-Asymptotic Viewpoint , ser. Cambridge Series in Statistical and Probabilistic Mathematics, 2019
2019
Earlier work this paper cites.
J. D. M.-W. C. Kenton and L. K. Toutanova, “Bert: Pre-training of deep bidirectional transformers for language understanding,” in NAACL-HLT , 2019
2019
Earlier work this paper cites.
Y. Li, B. Wu, Y. Jiang, Z. Li, and S.-T. Xia, “Backdoor learning: A survey,” arXiv:2007.08745 , 2020
2020
Earlier work this paper cites.
T. Chen, S. Kornblith, M. Norouzi, and G. Hinton, “A simple framework for contrastive learning of visual representations,” in ICML , 2020, pp. 1597–1607
2020
Cited alongside, same era.
T. Chen, S. Kornblith, K. Swersky, M. Norouzi, and G. E. Hinton, “Big self-supervised models are strong semi-supervised learners,” in NeruIPS , 2020
2020
Cited alongside, same era.
J.-B. Grill, F. Strub, F. Altché, C. Tallec, P. Richemond, E. Buchatskaya, C. Doersch, B. Avila Pires, Z. Guo, M. Gheshlaghi Azar et al. , “Bootstrap your own latent-a new approach to self-supervised learning,” in NeurIPS , vol. 33, 2020, pp. 21 271–21 284
2020
Cited alongside, same era.
C. Raffel, N. Shazeer, A. Roberts, K. Lee, S. Narang, M. Matena, Y. Zhou, W. Li, P. J. Liu et al. , “Exploring the limits of transfer learning with a unified text-to-text transformer.” J. Mach. Learn. Res. , 2020
2020
Cited alongside, same era.
E. Bagdasaryan and V. Shmatikov, “Blind backdoors in deep learning models,” in USENIX Security , 2021, pp. 1505–1521
2021
Later among the works it cites.
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in ICCV , 2021
2021
Later among the works it cites.
Y. Zeng, W. Park, Z. M. Mao, and R. Jia, “Rethinking the backdoor attacks’ triggers: A frequency perspective,” in ICCV , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
S. Li, M. Xue, B. Zhao, H. Zhu, and X. Zhang, “Invisible backdoor attacks on deep neural networks via steganography and regularization,” IEEE TDSC , 2020
2020
Cited alongside, same era.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in ECCV, 2020 . Springer, 2020, pp. 182–199
2020
Cited alongside, same era.
T. A. Nguyen and A. T. Tran, “Wanet-imperceptible warping-based backdoor attack,” in ICLR , 2020
2020
Cited alongside, same era.
A. Saha, A. Subramanya, and H. Pirsiavash, “Hidden trigger backdoor attacks,” in AAAI , 2020
2020
Cited alongside, same era.
K. He, H. Fan, Y. Wu, S. Xie, and R. Girshick, “Momentum contrast for unsupervised visual representation learning,” in CVPR , 2020, pp. 9729–9738
2020
Cited alongside, same era.
2020
Cited alongside, same era.
N. Peri, N. Gupta, W. R. Huang, L. Fowl, C. Zhu, S. Feizi, T. Goldstein, and J. P. Dickerson, “Deep k-nn defense against clean-label data poisoning attacks,” in ECCV , 2020
2020
Cited alongside, same era.
2020
Cited alongside, same era.
2021
Later among the works it cites.
2021
Later among the works it cites.
A. Radford, J. W. Kim, C. Hallacy, A. Ramesh, G. Goh, S. Agarwal, G. Sastry, A. Askell, P. Mishkin, J. Clark et al. , “Learning transferable visual models from natural language supervision,” in ICML , 2021
2021
Later among the works it cites.
W. Ma, D. Wang, R. Sun, M. Xue, S. Wen, and Y. Xiang, “The" beatrix”resurrections: Robust backdoor detection via gram matrices,” in NDSS Symposium , 2022
2022
Later among the works it cites.
K. He, X. Chen, S. Xie, Y. Li, P. Dollár, and R. Girshick, “Masked autoencoders are scalable vision learners,” in CVPR , 2022, pp. 16 000–16 009
2022
Later among the works it cites.
2022
Later among the works it cites.
N. Carlini and A. Terzis, “Poisoning and backdooring contrastive learning,” in ICLR , 2022
2022
Later among the works it cites.
A. Saha, A. Tejankar, S. A. Koohpayegani, and H. Pirsiavash, “Backdoor attacks on self-supervised learning,” in CVPR , 2022, pp. 13 337–13 346
2022
Later among the works it cites.
2022
Later among the works it cites.
T. Wang, Y. Yao, F. Xu, S. An, H. Tong, and T. Wang, “An invisible black-box backdoor attack through frequency domain,” in ECCV , 2022
2022
Later among the works it cites.
Y. Zeng, S. Chen, W. Park, Z. Mao, M. Jin, and R. Jia, “Adversarial unlearning of backdoors via implicit hypergradient,” in ICLR , 2022
2022
Later among the works it cites.
Y. Zeng, M. Pan, H. A. Just, L. Lyu, M. Qiu, and R. Jia, “Narcissus: A practical clean-label backdoor attack with limited information,” ACM CCS , 2023
2023
Closest in time.
X. Qi, T. Xie, J. T. Wang, T. Wu, S. Mahloujifar, and P. Mittal, “Towards a proactive ml approach for detecting backdoor poison samples,” 2023
2023
Closest in time.
Y. Zeng, M. Pan, H. Jahagirdar, M. Jin, L. Lyu, and R. Jia, “Meta-sift: How to sift out a clean subset in the presence of data poisoning?” 2023
2023
Closest in time.