Fetching the paper…
Reading the bibliography…
Deep neural network (DNN) models are valuable intellectual property of model owners, constituting a competitive advantage.
Learning a nonlinear embedding by preserving class neighbourhood structure
Ruslan Salakhutdinov and Geoff Hinton · 2007
Earlier work this paper cites.
Imagenet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
Pinocchio: Nearly practical verifiable computation
B. Parno, J. Howell, C. Gentry, and M. Raykova · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2015
Earlier work this paper cites.
Deep learning face attributes in the wild
Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang · 2015
Earlier work this paper cites.
Foveation-based mechanisms alleviate adversarial examples
Yan Luo, Xavier Boix, Gemma Roig, Tomaso Poggio, and Qi Zhao · 2015
Earlier work this paper cites.
Deep face recognition
Omkar M Parkhi, Andrea Vedaldi, and Andrew Zisserman · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
K. Simonyan and A. Zisserman · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Delving into transferable adversarial examples and black-box attacks
Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow · 2016
Earlier work this paper cites.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Earlier work this paper cites.
Wide residual networks
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Improving the robustness of deep neural networks via stability training
Stephan Zheng, Yang Song, Thomas Leung, and Ian Goodfellow · 2016
Earlier work this paper cites.
Sphereface: Deep hypersphere embedding for face recognition
Weiyang Liu, Yandong Wen, Zhiding Yu, Ming Li, Bhiksha Raj, and Le Song · 2017
Earlier work this paper cites.
Traffic sign recognition using a multi-task convolutional neural network
Hengliang Luo, Yi Yang, Bei Tong, Fuchao Wu, and Bin Fan · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
Embedding watermarks into deep neural networks
Yusuke Uchida, Yuki Nagai, Shigeyuki Sakazawa, and Shin’ichi Satoh · 2017
Earlier work this paper cites.
Learning adversary-resistant deep neural networks, 2017
Qinglong Wang, Wenbo Guo, Kaixuan Zhang, Alexander G. Ororbia II au2, Xinyu Xing, Xue Liu, and C. Lee Giles · 2017
Earlier work this paper cites.
Turning your weakness into a strength: Watermarking deep neural networks by backdooring
Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet · 2018
Earlier work this paper cites.
Enhancing robustness of machine learning systems via data transformations
Arjun Nitin Bhagoji, Daniel Cullina, Chawin Sitawarin, and Prateek Mittal · 2018
Earlier work this paper cites.
Thermometer encoding: One hot way to resist adversarial examples
Jacob Buckman, Aurko Roy, Colin Raffel, and Ian Goodfellow · 2018
Earlier work this paper cites.
Copycat cnn: Stealing knowledge by persuading confession with random non-labeled data
Jacson Rodrigues Correia-Silva, Rodrigo F Berriel, Claudine Badue, Alberto F de Souza, and Thiago Oliveira-Santos · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Earlier work this paper cites.
Boosting adversarial attacks with momentum
Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li · 2018
Earlier work this paper cites.
Watermarking deep neural networks for embedded systems
Jia Guo and Miodrag Potkonjak · 2018
Cited alongside, same era.
Adversarial examples in the physical world
Alexey Kurakin, Ian J Goodfellow, and Samy Bengio · 2018
Cited alongside, same era.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Cited alongside, same era.
Cosface: Large margin cosine loss for deep face recognition
Hao Wang, Yitong Wang, Zheng Zhou, Xing Ji, Dihong Gong, Jingchao Zhou, Zhifeng Li, and Wei Liu · 2018
Cited alongside, same era.
Protecting intellectual property of deep neural networks with watermarking
Jialong Zhang, Zhongshu Gu, Jiyong Jang, Hui Wu, Marc Ph Stoecklin, Heqing Huang, and Ian Molloy · 2018
Cited alongside, same era.
Towards federated learning at scale: System design
Keith Bonawitz, Hubert Eichner, Wolfgang Grieskamp, Dzmitry Huba, Alex Ingerman, Vladimir Ivanov, Chloe Kiddon, Jakub Konečnỳ, Stefano Mazzocchi, Brendan McMahan, et al · 2019
Cryptanalytic extraction of neural network models
Nicholas Carlini, Matthew Jagielski, and Ilya Mironov · 2020
Later among the works it cites.
High accuracy and high fidelity extraction of neural networks
Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot · 2020
Later among the works it cites.
High accuracy and high fidelity extraction of neural networks
Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot · 2020
Later among the works it cites.
Thieves of sesame street: Model extraction on bert-based apis
Kalpesh Krishna, Gaurav Singh Tomar, Ankur Parikh, Nicolas Papernot, and Mohit Iyyer · 2020
Later among the works it cites.
Adversarial frontier stitching for remote neural network watermarking
Erwan Le Merrer, Patrick Perez, and Gilles Trédan · 2020
Later among the works it cites.
Deep neural network fingerprinting by conferrable adversarial examples
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Deepmarks: A secure fingerprinting framework for digital rights management of deep learning models
Huili Chen, Bita Darvish Rouhani, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar · 2019
Cited alongside, same era.
Blackmarks: Blackbox multibit watermarking for deep neural networks
Huili Chen, Bita Darvish Rouhani, and Farinaz Koushanfar · 2019
Cited alongside, same era.
Deepsigns: An end-to-end watermarking framework for ownership protection of deep neural networks
Bita Darvish Rouhani, Huili Chen, and Farinaz Koushanfar · 2019
Cited alongside, same era.
Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks
Lixin Fan, Kam Woh Ng, and Chee Seng Chan · 2019
Cited alongside, same era.
PRADA: protecting against DNN model stealing attacks
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N. Asokan · 2019
Cited alongside, same era.
Similarity of neural network representations revisited
Simon Kornblith, Mohammad Norouzi, Honglak Lee, and Geoffrey Hinton · 2019
Cited alongside, same era.
Nils Lukas, Yuxuan Zhang, and Florian Kerschbaum · 2020
Later among the works it cites.
Dataset inference: Ownership resolution in machine learning
Pratyush Maini, Mohammad Yaghini, and Nicolas Papernot · 2020
Later among the works it cites.
Model extraction attacks on recurrent neural networks
Tatsuya Takemura, Naoto Yanai, and Toru Fujiwara · 2020
Later among the works it cites.
Imitation attacks and defenses for black-box machine translation systems
Eric Wallace, Mitchell Stern, and Dawn Song · 2020
Later among the works it cites.
Afa: Adversarial fingerprinting authentication for deep neural networks
Jingjing Zhao, Qingyue Hu, Gaoyang Liu, Xiaoqiang Ma, Fei Chen, and Mohammad Mehedi Hassan · 2020
Later among the works it cites.
A systematic review on model watermarking for neural networks
Franziska Boenisch · 2021
Later among the works it cites.
Ipguard: Protecting intellectual property of deep neural networks via fingerprinting the classification boundary
Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong · 2021
Later among the works it cites.
Deepipr: Deep neural network ownership verification with passports
Lixin Fan, Kam Woh Ng, Chee Seng Chan, and Qiang Yang · 2021
Later among the works it cites.
Stealing links from graph neural networks
Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang · 2021
Later among the works it cites.
Entangled watermarks as a defense against model extraction
Hengrui Jia, Christopher A. Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot · 2021
Later among the works it cites.
Proof-of-learning: Definitions and practice
Hengrui Jia, Mohammad Yaghini, Christopher A Choquette-Choo, Natalie Dullerud, Anvith Thudi, Varun Chandrasekaran, and Nicolas Papernot · 2021
Later among the works it cites.
A survey of deep neural network watermarking techniques
Yue Li, Hongxia Wang, and Mauro Barni · 2021
Later among the works it cites.
Protecting artificial intelligence ips: a survey of watermarking and fingerprinting for machine learning
Francesco Regazzoni, Paolo Palmieri, Fethulah Smailbegovic, Rosario Cammarota, and Ilia Polian · 2021
Later among the works it cites.
Dawn: Dynamic adversarial watermarking of neural networks
Sebastian Szyller, Buse Gul Atli, Samuel Marchal, and N Asokan · 2021
Later among the works it cites.
Sebastian Szyller, Vasisht Duddu, Tommi Gröndahl, and N Asokan · 2021
Later among the works it cites.
Sok: How robust is image classification deep neural network watermarking?
Nils Lukas, Edward Jiang, Xinda Li, and Florian Kerschbaum · 2022
Later among the works it cites.
Metav: A meta-verifier approach to task-agnostic model fingerprinting
Xudong Pan, Yifan Yan, Mi Zhang, and Min Yang · 2022
Later among the works it cites.
“adversarial examples” for proof-of-learning
Rui Zhang, Jian Liu, Yuan Ding, Zhibo Wang, Qingbiao Wu, and Kui Ren · 2022
Later among the works it cites.
Effective ambiguity attack against passport-based dnn intellectual property protection schemes through fully connected layer substitution
Yiming Chen, Jinyu Tian, Xiangyu Chen, and Jiantao Zhou · 2023
Closest in time.
On the robustness of dataset inference
Sebastian Szyller, Rui Zhang, Jian Liu, and N Asokan · 2023
Closest in time.