Fetching the paper…
Reading the bibliography…
Deep learning models are vulnerable to backdoor attacks, where attackers inject malicious behavior through data poisoning and later exploit triggers to manipulate deployed models.
1912
Earlier work this paper cites.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” University of Toronto , 05 2012
2012
Earlier work this paper cites.
S. Houben, J. Stallkamp, J. Salmen, M. Schlipsing, and C. Igel, “Detection of traffic signs in real-world images: The German Traffic Sign Detection Benchmark,” in International Joint Conference on Neural Networks , no. 1288, 2013
2013
Earlier work this paper cites.
2015
Earlier work this paper cites.
C. Szegedy, W. Liu, Y. Jia, P. Sermanet, S. E. Reed, D. Anguelov, D. Erhan, V. Vanhoucke, and A. Rabinovich, “Going deeper with convolutions,” in IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2015, Boston, MA, USA, June 7-12, 2015 . IEEE Computer Society, 2015, pp. 1–9. [Online]. Available: https://doi.org/10.1109/CVPR.2015.7298594
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016, Las Vegas, NV, USA, June 27-30, 2016 . IEEE Computer Society, 2016, pp. 770–778. [Online]. Available: https://doi.org/10.1109/CVPR.2016.90
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
Y. Liu, Y. Xie, and A. Srivastava, “Neural trojans,” in 2017 IEEE International Conference on Computer Design, ICCD 2017, Boston, MA, USA, November 5-8, 2017 . IEEE Computer Society, 2017, pp. 45–48. [Online]. Available: https://doi.org/10.1109/ICCD.2017.16
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018, December 3-8, 2018, Montréal, Canada , S. Bengio, H. M. Wallach, H. Larochelle, K. Grauman, N. Cesa-Bianchi, and R. Garnett, Eds., 2018, pp. 8011–8021. [Online]. Available: https://proceedings.neurips.cc/paper/2018/hash/280cf18baf4311c92aa5a042336587d3-Abstract.html
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
G. Marín, P. Casas, and G. Capdehourat, “Deep in the dark - deep learning-based malware traffic detection without expert knowledge,” in 2019 IEEE Security and Privacy Workshops, SP Workshops 2019, San Francisco, CA, USA, May 19-23, 2019 . IEEE, 2019, pp. 36–42. [Online]. Available: https://doi.org/10.1109/SPW.2019.00019
2019
Earlier work this paper cites.
M. Buda, A. Saha, and M. A. Mazurowski, “Association of genomic subtypes of lower-grade gliomas with shape features automatically extracted by a deep learning algorithm,” Comput. Biol. Medicine , vol. 109, pp. 218–225, 2019. [Online]. Available: https://doi.org/10.1016/j.compbiomed.2019.05.002
2019
Earlier work this paper cites.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, May 19-23, 2019 . IEEE, 2019, pp. 707–723. [Online]. Available: https://doi.org/10.1109/SP.2019.00031
2019
Earlier work this paper cites.
X. Qiao, Y. Yang, and H. Li, “Defending neural backdoors via generative distribution modeling,” in Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, December 8-14, 2019, Vancouver, BC, Canada , H. M. Wallach, H. Larochelle, A. Beygelzimer, F. d’Alché-Buc, E. B. Fox, and R. Garnett, Eds., 2019, pp. 14 004–14 013. [Online]. Available: https://proceedings.neurips.cc/paper/2019/hash/78211247db84d96acf4e00092a7fba80-Abstract.html
2019
Earlier work this paper cites.
R. Feng, S. Chen, X. Xie, G. Meng, S. Lin, and Y. Liu, “A performance-sensitive malware detection system using deep learning on mobile devices,” IEEE Trans. Inf. Forensics Secur. , vol. 16, pp. 1563–1578, 2021. [Online]. Available: https://doi.org/10.1109/TIFS.2020.3025436
2020
Earlier work this paper cites.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in Computer Vision - ECCV 2020 - 16th European Conference, Glasgow, UK, August 23-28, 2020, Proceedings, Part X , ser. Lecture Notes in Computer Science, A. Vedaldi, H. Bischof, T. Brox, and J. Frahm, Eds., vol. 12355. Springer, 2020, pp. 182–199. [Online]. Available: https://doi.org/10.1007/978-3-030-58607-2_11
2020
Earlier work this paper cites.
S. Li, M. Xue, B. Z. H. Zhao, H. Zhu, and X. Zhang, “Invisible backdoor attacks on deep neural networks via steganography and regularization,” IEEE Trans. Dependable Secur. Comput. , vol. 18, no. 5, pp. 2088–2105, 2021. [Online]. Available: https://doi.org/10.1109/TDSC.2020.3021407
2020
Cited alongside, same era.
J. Dumford and W. J. Scheirer, “Backdooring convolutional neural networks via targeted weight perturbations,” in 2020 IEEE International Joint Conference on Biometrics, IJCB 2020, Houston, TX, USA, September 28 - October 1, 2020 . IEEE, 2020, pp. 1–9. [Online]. Available: https://doi.org/10.1109/IJCB48548.2020.9304875
2020
Cited alongside, same era.
R. Tang, M. Du, N. Liu, F. Yang, and X. Hu, “An embarrassingly simple approach for trojan attack in deep neural networks,” in KDD ’20: The 26th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, Virtual Event, CA, USA, August 23-27, 2020 , R. Gupta, Y. Liu, J. Tang, and B. A. Prakash, Eds. ACM, 2020, pp. 218–228. [Online]. Available: https://doi.org/10.1145/3394486.3403064
2020
Cited alongside, same era.
C. Wang, Q. Yang, R. Huang, S. Song, and G. Huang, “Efficient knowledge distillation from model checkpoints,” in Advances in Neural Information Processing Systems 35: Annual Conference on Neural Information Processing Systems 2022, NeurIPS 2022, New Orleans, LA, USA, November 28 - December 9, 2022 , S. Koyejo, S. Mohamed, A. Agarwal, D. Belgrave, K. Cho, and A. Oh, Eds., 2022. [Online]. Available: http://papers.nips.cc/paper_files/paper/2022/hash/03e0712bf85ebe7cec4f1a7fc53216c9-Abstract-Conference.html
2022
Later among the works it cites.
Z. Zhao, X. Chen, Y. Xuan, Y. Dong, D. Wang, and K. Liang, “DEFEAT: deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints,” in IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, New Orleans, LA, USA, June 18-24, 2022 . IEEE, 2022, pp. 15 192–15 201. [Online]. Available: https://doi.org/10.1109/CVPR52688.2022.01478
2022
Later among the works it cites.
S. Udeshi, S. Peng, G. Woo, L. Loh, L. Rawshan, and S. Chattopadhyay, “Model agnostic defence against backdoor attacks in machine learning,” IEEE Trans. Reliab. , vol. 71, no. 2, pp. 880–895, 2022. [Online]. Available: https://doi.org/10.1109/TR.2022.3159784
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
A. S. Rakin, Z. He, and D. Fan, “TBT: targeted neural network attack with bit trojan,” in 2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2020, Seattle, WA, USA, June 13-19, 2020 . Computer Vision Foundation / IEEE, 2020, pp. 13 195–13 204. [Online]. Available: https://openaccess.thecvf.com/content_CVPR_2020/html/Rakin_TBT_Targeted_Neural_Network_Attack_With_Bit_Trojan_CVPR_2020_paper.html
2020
Cited alongside, same era.
B. G. Doan, E. Abbasnejad, and D. C. Ranasinghe, “Februus: Input purification defense against trojan attacks on deep neural network systems,” in ACSAC ’20: Annual Computer Security Applications Conference, Virtual Event / Austin, TX, USA, 7-11 December, 2020 . ACM, 2020, pp. 897–912. [Online]. Available: https://doi.org/10.1145/3427228.3427264
2020
Cited alongside, same era.
Y. Dong, S. Cheng, T. Pang, H. Su, and J. Zhu, “Query-efficient black-box adversarial attacks guided by a transfer-based prior,” IEEE Trans. Pattern Anal. Mach. Intell. , vol. 44, no. 12, pp. 9536–9548, 2022. [Online]. Available: https://doi.org/10.1109/TPAMI.2021.3126733
2021
Cited alongside, same era.
K. D. Doan, Y. Lao, W. Zhao, and P. Li, “LIRA: learnable, imperceptible and robust backdoor attacks,” in 2021 IEEE/CVF International Conference on Computer Vision, ICCV 2021, Montreal, QC, Canada, October 10-17, 2021 . IEEE, 2021, pp. 11 946–11 956. [Online]. Available: https://doi.org/10.1109/ICCV48922.2021.01175
2021
Cited alongside, same era.
K. D. Doan, Y. Lao, and P. Li, “Backdoor attack with imperceptible input and latent modification,” in Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, NeurIPS 2021, December 6-14, 2021, virtual , M. Ranzato, A. Beygelzimer, Y. N. Dauphin, P. Liang, and J. W. Vaughan, Eds., 2021, pp. 18 944–18 957. [Online]. Available: https://proceedings.neurips.cc/paper/2021/hash/9d99197e2ebf03fc388d09f1e94af89b-Abstract.html
2021
Cited alongside, same era.
T. A. Nguyen and A. T. Tran, “Wanet - imperceptible warping-based backdoor attack,” in 9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7, 2021 . OpenReview.net, 2021. [Online]. Available: https://openreview.net/forum?id=eEn8KTtJOx
2021
Cited alongside, same era.
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in 2021 IEEE/CVF International Conference on Computer Vision, ICCV 2021, Montreal, QC, Canada, October 10-17, 2021 . IEEE, 2021, pp. 16 443–16 452. [Online]. Available: https://doi.org/10.1109/ICCV48922.2021.01615
2021
Cited alongside, same era.
2021
Cited alongside, same era.
L. Li, D. Song, X. Li, J. Zeng, R. Ma, and X. Qiu, “Backdoor attacks on pre-trained models by layerwise weight poisoning,” in Proceedings of the 2021 Conference on Empirical Methods in Natural Language Processing, EMNLP 2021, Virtual Event / Punta Cana, Dominican Republic, 7-11 November, 2021 , M. Moens, X. Huang, L. Specia, and S. W. Yih, Eds. Association for Computational Linguistics, 2021, pp. 3023–3032. [Online]. Available: https://doi.org/10.18653/v1/2021.emnlp-main.241
2021
Cited alongside, same era.
2022
Later among the works it cites.
Y. Zeng, S. Chen, W. Park, Z. Mao, M. Jin, and R. Jia, “Adversarial unlearning of backdoors via implicit hypergradient,” in The Tenth International Conference on Learning Representations, ICLR 2022, Virtual Event, April 25-29, 2022 . OpenReview.net, 2022. [Online]. Available: https://openreview.net/forum?id=MeeQkFYVbzW
2022
Later among the works it cites.
J. Xia, T. Wang, J. Ding, X. Wei, and M. Chen, “Eliminating backdoor triggers for deep neural networks using attention relation graph distillation,” in Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence, IJCAI 2022, Vienna, Austria, 23-29 July 2022 , L. D. Raedt, Ed. ijcai.org, 2022, pp. 1481–1487. [Online]. Available: https://doi.org/10.24963/ijcai.2022/206
2022
Later among the works it cites.
J. C. L. Chai, T. Ng, C. Low, J. Park, and A. B. J. Teoh, “Recognizability embedding enhancement for very low-resolution face recognition and quality estimation,” in IEEE/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2023, Vancouver, BC, Canada, June 17-24, 2023 . IEEE, 2023, pp. 9957–9967. [Online]. Available: https://doi.org/10.1109/CVPR52729.2023.00960
2023
Closest in time.
L. Barruffo, B. Caiazzo, A. Petrillo, and S. Santini, “A goa4 control architecture for the autonomous driving of high-speed trains over ETCS: design and experimental validation,” IEEE Trans. Intell. Transp. Syst. , vol. 25, no. 6, pp. 5096–5111, 2024. [Online]. Available: https://doi.org/10.1109/TITS.2023.3338295
2023
Closest in time.
D. Chen, X. Liu, J. Cui, and H. Zhong, “Poster: Membership inference attacks via contrastive learning,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS 2023, Copenhagen, Denmark, November 26-30, 2023 , W. Meng, C. D. Jensen, C. Cremers, and E. Kirda, Eds. ACM, 2023, pp. 3555–3557. [Online]. Available: https://doi.org/10.1145/3576915.3624384
2023
Closest in time.
X. Gong, Y. Chen, W. Yang, Q. Wang, Y. Gu, H. Huang, and C. Shen, “Redeem myself: Purifying backdoors in deep learning models using self attention distillation,” in 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, May 21-25, 2023 . IEEE, 2023, pp. 755–772. [Online]. Available: https://doi.org/10.1109/SP46215.2023.10179375
2023
Closest in time.
Y. Shi, M. Du, X. Wu, Z. Guan, J. Sun, and N. Liu, “Black-box backdoor defense via zero-shot image purification,” in Advances in Neural Information Processing Systems 36: Annual Conference on Neural Information Processing Systems 2023, NeurIPS 2023, New Orleans, LA, USA, December 10 - 16, 2023 , A. Oh, T. Naumann, A. Globerson, K. Saenko, M. Hardt, and S. Levine, Eds., 2023. [Online]. Available: http://papers.nips.cc/paper_files/paper/2023/hash/b36554b97da741b1c48c9de05c73993e-Abstract-Conference.html
2023
Closest in time.
Y. Zeng, M. Pan, H. A. Just, L. Lyu, M. Qiu, and R. Jia, “Narcissus: A practical clean-label backdoor attack with limited information,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, CCS 2023, Copenhagen, Denmark, November 26-30, 2023 , W. Meng, C. D. Jensen, C. Cremers, and E. Kirda, Eds. ACM, 2023, pp. 771–785. [Online]. Available: https://doi.org/10.1145/3576915.3616617
2023
Closest in time.
C. Gong, C. Lu, Z. Li, Z. Liu, J. Gong, and X. Chen, “Beyond imitation: A life-long policy learning framework for path tracking control of autonomous driving,” IEEE Trans. Veh. Technol. , vol. 73, no. 7, pp. 9786–9799, 2024. [Online]. Available: https://doi.org/10.1109/TVT.2024.3382309
2024
Closest in time.
S. Cheng, Y. Miao, Y. Dong, X. Yang, X. Gao, and J. Zhu, “Efficient black-box adversarial attacks via bayesian optimization guided by a function prior,” in Forty-first International Conference on Machine Learning, ICML 2024, Vienna, Austria, July 21-27, 2024 . OpenReview.net, 2024. [Online]. Available: https://openreview.net/forum?id=CR6Sl80cn8
2024
Closest in time.
Y. Li, A. Chen, W. Qian, C. Zhao, D. Lidder, and M. Huai, “Data poisoning attacks against conformal prediction,” in Forty-first International Conference on Machine Learning, ICML 2024, Vienna, Austria, July 21-27, 2024 . OpenReview.net, 2024. [Online]. Available: https://openreview.net/forum?id=f49AkFT5jf
2024
Closest in time.
R. Liu, D. Wang, Y. Ren, Z. Wang, K. Guo, Q. Qin, and X. Liu, “Unstoppable attack: Label-only model inversion via conditional diffusion model,” IEEE Trans. Inf. Forensics Secur. , vol. 19, pp. 3958–3973, 2024. [Online]. Available: https://doi.org/10.1109/TIFS.2024.3372815
2024
Closest in time.
2024
Closest in time.