Fetching the paper…
Reading the bibliography…
Currently, sample-specific backdoor attacks (SSBAs) are the most advanced and malicious methods since they can easily circumvent most of the current backdoor defenses.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, and L. Fei-Fei, “Imagenet: A large-scale hierarchical image database,” in CVPR , 2009
2009
Earlier work this paper cites.
D. Gong, Z. Li, J. Liu, and Y. Qiao, “Multi-feature canonical correlation analysis for face photo-sketch image retrieval,” in ACM MM , 2013
2013
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in ICLR , 2015
2015
Earlier work this paper cites.
H. Xiao, B. Biggio, G. Brown, G. Fumera, C. Eckert, and F. Roli, “Is feature selection secure against training data poisoning?” in ICML , 2015
2015
Earlier work this paper cites.
K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in CVPR , 2016
2016
Earlier work this paper cites.
2017
Earlier work this paper cites.
S.-M. Moosavi-Dezfooli, A. Fawzi, O. Fawzi, and P. Frossard, “Universal adversarial perturbations,” in CVPR , 2017
2017
Earlier work this paper cites.
Y. Liu, Y. Xie, and A. Srivastava, “Neural trojans,” in ICCD , 2017
2017
Earlier work this paper cites.
J. Kirkpatrick, R. Pascanu, N. Rabinowitz, J. Veness, G. Desjardins, A. A. Rusu, K. Milan, J. Quan, T. Ramalho, A. Grabska-Barwinska et al. , “Overcoming catastrophic forgetting in neural networks,” Proceedings of the national academy of sciences , vol. 114, no. 13, pp. 3521–3526, 2017
2017
Earlier work this paper cites.
R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, and D. Batra, “Grad-cam: Visual explanations from deep networks via gradient-based localization,” in ICCV , 2017
2017
Earlier work this paper cites.
Y. He, X. Zhang, and J. Sun, “Channel pruning for accelerating very deep neural networks,” in ICCV , 2017
2017
Earlier work this paper cites.
L. Wan, Q. Wang, A. Papir, and I. L. Moreno, “Generalized end-to-end loss for speaker verification,” in ICASSP , 2018
2018
Earlier work this paper cites.
K. Liu, B. Dolan-Gavitt, and S. Garg, “Fine-pruning: Defending against backdooring attacks on deep neural networks,” in RAID , 2018
2018
Earlier work this paper cites.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in NeurIPS , 2018
2018
Earlier work this paper cites.
A. Jacot, F. Gabriel, and C. Hongler, “Neural tangent kernel: Convergence and generalization in neural networks,” in NeurIPS , 2018
2018
Earlier work this paper cites.
Q. Cao, L. Shen, W. Xie, O. M. Parkhi, and A. Zisserman, “Vggface2: A dataset for recognising faces across pose and age,” in FG , 2018
2018
Earlier work this paper cites.
T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, “Badnets: Evaluating backdooring attacks on deep neural networks,” IEEE Access , vol. 7, pp. 47 230–47 244, 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao, “Neural cleanse: Identifying and mitigating backdoor attacks in neural networks,” in IEEE S&P , 2019
2019
Earlier work this paper cites.
2019
Earlier work this paper cites.
A. Ilyas, S. Santurkar, D. Tsipras, L. Engstrom, B. Tran, and A. Madry, “Adversarial examples are not bugs, they are features,” in NeurIPS , 2019
2019
Earlier work this paper cites.
Z. He, W. Zuo, M. Kan, S. Shan, and X. Chen, “Attgan: Facial attribute editing by only changing what you want,” IEEE transactions on image processing , vol. 28, no. 11, pp. 5464–5478, 2019
2019
Earlier work this paper cites.
Y.-C. Chen, X. Shen, Z. Lin, X. Lu, I. Pao, J. Jia et al. , “Semantic component decomposition for face attribute manipulation,” in CVPR , 2019
2019
Earlier work this paper cites.
T. A. Nguyen and A. Tran, “Input-aware dynamic backdoor attack,” in NeurIPS , 2020
2020
Earlier work this paper cites.
S. Zhao, X. Ma, X. Zheng, J. Bailey, J. Chen, and Y.-G. Jiang, “Clean-label backdoor attacks on video recognition models,” in CVPR , 2020
2020
Earlier work this paper cites.
J. Guo and C. Liu, “Practical poisoning attacks on neural networks,” in Computer Vision–ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part XXVII 16 . Springer, 2020, pp. 142–158
2020
Earlier work this paper cites.
M. Tancik, B. Mildenhall, and R. Ng, “Stegastamp: Invisible hyperlinks in physical photographs,” in CVPR , 2020
2020
Cited alongside, same era.
E. Chou, F. Tramer, and G. Pellegrino, “Sentinet: Detecting localized universal attack against deep learning systems,” in IEEE S&P Workshop , 2020
2020
Cited alongside, same era.
P. Zhao, P.-Y. Chen, P. Das, K. N. Ramamurthy, and X. Lin, “Bridging mode connectivity in loss landscapes and adversarial robustness,” in ICLR , 2020
2020
Cited alongside, same era.
R. Duan, X. Ma, Y. Wang, J. Bailey, A. K. Qin, and Y. Yang, “Adversarial camouflage: Hiding physical-world attacks with natural styles,” in CVPR , 2020
2020
Cited alongside, same era.
H. Qiu, B. Yu, D. Gong, Z. Li, W. Liu, and D. Tao, “Synface: Face recognition with synthetic data,” in ICCV , 2021
2021
Cited alongside, same era.
Z. Wang, J. Zhai, and S. Ma, “Bppattack: Stealthy and efficient trojan attacks against deep neural networks via image quantization and contrastive adversarial learning,” in CVPR , 2022
2022
Later among the works it cites.
Z. Zhao, X. Chen, Y. Xuan, Y. Dong, D. Wang, and K. Liang, “Defeat: Deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints,” in CVPR , 2022
2022
Later among the works it cites.
R. Zheng, R. Tang, J. Li, and L. Li, “Data-free backdoor removal based on channel lipschitzness,” in ECCV , 2022
2022
Later among the works it cites.
J. Guo, A. Li, and C. Liu, “Aeva: Black-box backdoor detection using adversarial extreme value analysis,” in ICLR , 2022
2022
Later among the works it cites.
Y. Gao, Y. Kim, B. G. Doan, Z. Zhang, G. Zhang, S. Nepal, D. Ranasinghe, and H. Kim, “Design and evaluation of a multi-domain trojan detection method on deep neural networks,” IEEE Transactions on Dependable and Secure Computing , vol. 19, no. 4, pp. 2349–2364, 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Y. Li, T. Zhai, Y. Jiang, Z. Li, and S.-T. Xia, “Backdoor attack in the physical world,” in ICLR Workshop , 2021
2021
Cited alongside, same era.
E. Wenger, J. Passananti, A. N. Bhagoji, Y. Yao, H. Zheng, and B. Y. Zhao, “Backdoor attacks against deep learning systems in the physical world,” in CVPR , 2021
2021
Cited alongside, same era.
Y. Li, Y. Li, B. Wu, L. Li, R. He, and S. Lyu, “Invisible backdoor attack with sample-specific triggers,” in ICCV , 2021
2021
Cited alongside, same era.
A. Nguyen and A. Tran, “Wanet–imperceptible warping-based backdoor attack,” in ICLR , 2021
2021
Cited alongside, same era.
T. Zhai, Y. Li, Z. Zhang, B. Wu, Y. Jiang, and S.-T. Xia, “Backdoor attack against speaker verification,” in ICASSP , 2021
2021
Cited alongside, same era.
Z. Xi, R. Pang, S. Ji, and T. Wang, “Graph backdoor,” in USENIX Security , 2021
2021
Cited alongside, same era.
Z. Xiang, D. J. Miller, S. Chen, X. Li, and G. Kesidis, “A backdoor attack against 3d point cloud classifiers,” in ICCV , 2021
2021
Cited alongside, same era.
2022
Later among the works it cites.
Y. Li, L. Zhu, X. Jia, Y. Jiang, S.-T. Xia, and X. Cao, “Defending against model stealing via verifying embedded external features,” in AAAI , 2022
2022
Later among the works it cites.
T. Wei, D. Chen, W. Zhou, J. Liao, Z. Tan, L. Yuan, W. Zhang, and N. Yu, “Hairclip: Design your hair by text and reference image,” in CVPR , 2022
2022
Later among the works it cites.
R. Zheng, R. Tang, J. Li, and L. Liu, “Data-free backdoor removal based on channel lipschitzness,” in ECCV , 2022
2022
Later among the works it cites.
P. Cheng, Y. Wu, Y. Hong, Z. Ba, F. Lin, L. Lu, and K. Ren, “Uniap: Protecting speech privacy with non-targeted universal adversarial perturbations,” IEEE Transactions on Dependable and Secure Computing , 2023
2023
Closest in time.
X. Gong, Y. Chen, H. Huang, W. Kong, Z. Wang, C. Shen, and Q. Wang, “Kerbnet: A qoe-aware kernel-based backdoor attack framework,” IEEE Transactions on Dependable and Secure Computing , 2023
2023
Closest in time.
W. Jiang, H. Li, G. Xu, and T. Zhang, “Color backdoor: A robust poisoning attack in color space,” in CVPR , 2023
2023
Closest in time.
X. Gong, Z. Wang, Y. Chen, M. Xue, Q. Wang, and C. Shen, “Kaleidoscope: Physical backdoor attacks against deep neural networks with rgb filters,” IEEE Transactions on Dependable and Secure Computing , 2023
2023
Closest in time.
Y. Gao, Y. Li, L. Zhu, D. Wu, Y. Jiang, and S.-T. Xia, “Not all samples are born equal: Towards effective clean-label backdoor attacks,” Pattern Recognition , vol. 139, p. 109512, 2023
2023
Closest in time.
J. Guo, A. Li, L. Wang, and C. Liu, “Policycleanse: Backdoor detection and mitigation for competitive reinforcement learning,” in Proceedings of the IEEE/CVF International Conference on Computer Vision , 2023, pp. 4699–4708
2023
Closest in time.
X. Qi, T. Xie, Y. Li, S. Mahloujifar, and P. Mittal, “Revisiting the assumption of latent separability for backdoor defenses,” in ICLR , 2023
2023
Closest in time.
J. Guo, Y. Li, X. Chen, H. Guo, L. Sun, and C. Liu, “SCALE-UP: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency,” in ICLR , 2023
2023
Closest in time.
Y. Li, M. Ya, Y. Bai, Y. Jiang, and S.-T. Xia, “Backdoorbox: A python toolbox for backdoor learning,” in ICLR Workshop , 2023
2023
Closest in time.
S. Yang, Y. Li, Y. Jiang, and S.-T. Xia, “Backdoor defense via suppressing model shortcuts,” in ICASSP , 2023
2023
Closest in time.
B. He, J. Liu, Y. Li, S. Liang, J. Li, X. Jia, and X. Cao, “Generating transferable 3d adversarial point cloud via random perturbation factorization,” in AAAI , 2023
2023
Closest in time.
C. Wei, Y. Wang, K. Gao, S. Shao, Y. Li, Z. Wang, and Z. Qin, “Pointncbw: Towards dataset ownership verification for point clouds via negative clean-label backdoor watermark,” IEEE Transactions on Information Forensics and Security , 2024
2024
Closest in time.
H. Cai, P. Zhang, H. Dong, Y. Xiao, S. Koffas, and Y. Li, “Toward stealthy backdoor attacks against speech recognition via elements of sound,” IEEE Transactions on Information Forensics and Security , vol. 19, pp. 5852–5866, 2024
2024
Closest in time.
Y. Gao, Y. Li, X. Gong, Z. Li, S.-T. Xia, and Q. Wang, “Backdoor attack with sparse and invisible trigger,” IEEE Transactions on Information Forensics and Security , 2024
2024
Closest in time.
B. Li, Y. Cai, H. Li, F. Xue, Z. Li, and Y. Li, “Nearest is not dearest: Towards practical defense against quantization-conditioned backdoor attacks,” in CVPR , 2024
2024
Closest in time.
X. Xu, K. Huang, Y. Li, Z. Qin, and K. Ren, “Towards reliable and efficient backdoor trigger inversion via decoupling benign features,” in ICLR , 2024
2024
Closest in time.
L. Hou, R. Feng, Z. Hua, W. Luo, L. Y. Zhang, and Y. Li, “Ibd-psc: Input-level backdoor detection via parameter-oriented scaling consistency,” in ICML , 2024
2024
Closest in time.