Fetching the paper…
Reading the bibliography…
Adversarial phenomenon has been widely observed in machine learning (ML) systems, especially in those using deep neural networks, describing that ML systems may produce inconsistent and incomprehensible predictions with humans at some particular cases.
Density-based clustering based on hierarchical density estimates
Ricardo JGB Campello, Davoud Moulavi, and Jörg Sander · 2013
Earlier work this paper cites.
Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression
Nilaksh Das, Madhuri Shanbhogue, Shang-Tse Chen, Fred Hohman, Li Chen, Michael E Kounavis, and Duen Horng Chau · 2017
Earlier work this paper cites.
Detecting adversarial samples from artifacts
Reuben Feinman, Ryan R Curtin, Saurabh Shintre, and Andrew B Gardner · 2017
Earlier work this paper cites.
On the (statistical) detection of adversarial examples
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel · 2017
Earlier work this paper cites.
Badnets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Earlier work this paper cites.
Adversarial examples detection in deep networks with convolutional filter statistics
Xin Li and Fuxin Li · 2017
Earlier work this paper cites.
Safetynet: Detecting and rejecting adversarial examples robustly
Jiajun Lu, Theerasit Issaranon, and David Forsyth · 2017
Earlier work this paper cites.
Magnet: a two-pronged defense against adversarial examples
Dongyu Meng and Hao Chen · 2017
Earlier work this paper cites.
On detecting adversarial perturbations
Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff · 2017
Earlier work this paper cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2017
Earlier work this paper cites.
Multimodal machine learning: A survey and taxonomy
Tadas Baltrušaitis, Chaitanya Ahuja, and Louis-Philippe Morency · 2018
Earlier work this paper cites.
Curriculum adversarial training
Qi-Zhi Cai, Chang Liu, and Dawn Song · 2018
Earlier work this paper cites.
Detecting backdoor attacks on deep neural networks by activation clustering
Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava · 2018
Earlier work this paper cites.
Mitigating sybils in federated learning poisoning
Clement Fung, Chris JM Yoon, and Ivan Beschastnikh · 2018
Earlier work this paper cites.
Countering adversarial images using input transformations
Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten · 2018
Earlier work this paper cites.
Defense against adversarial attacks using high-level representation guided denoiser
Fangzhou Liao, Ming Liang, Yinpeng Dong, Tianyu Pang, Xiaolin Hu, and Jun Zhu · 2018
Earlier work this paper cites.
Fine-pruning: Defending against backdooring attacks on deep neural networks
Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg · 2018
Earlier work this paper cites.
Characterizing adversarial subspaces using local intrinsic dimensionality
Xingjun Ma, Bo Li, Yisen Wang, Sarah M Erfani, Sudanthi Wijewickrema, Grant Schoenebeck, Dawn Song, Michael E Houle, and James Bailey · 2018
Earlier work this paper cites.
Towards deep learning models resistant to adversarial attacks
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu · 2018
Earlier work this paper cites.
Divide, denoise, and defend against adversarial attacks
Seyed-Mohsen Moosavi-Dezfooli, Ashish Shrivastava, and Oncel Tuzel · 2018
Earlier work this paper cites.
Deep k-nearest neighbors: Towards confident, interpretable and robust deep learning
Nicolas Papernot and Patrick McDaniel · 2018
Earlier work this paper cites.
Defense-gan: Protecting classifiers against adversarial attacks using generative models
Pouya Samangouei, Maya Kabkab, and Rama Chellappa · 2018
Earlier work this paper cites.
Defense against adversarial attacks with saak transform
Sibo Song, Yueru Chen, Ngai-Man Cheung, and C-C Jay Kuo · 2018
Earlier work this paper cites.
Pixeldefend: Leveraging generative models to understand and defend against adversarial examples
Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman · 2018
Earlier work this paper cites.
Ensemble adversarial training: Attacks and defenses
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian J. Goodfellow, Dan Boneh, and Patrick D. McDaniel · 2018
Earlier work this paper cites.
Spectral signatures in backdoor attacks
Brandon Tran, Jerry Li, and Aleksander Madry · 2018
Earlier work this paper cites.
Are labels required for improving adversarial robustness?
Jean-Baptiste Alayrac, Jonathan Uesato, Po-Sen Huang, Alhussein Fawzi, Robert Stanforth, and Pushmeet Kohli · 2019
Earlier work this paper cites.
Hilbert-based generative defense for adversarial examples
Yang Bai, Yan Feng, Yisen Wang, Tao Dai, Shu-Tao Xia, and Yong Jiang · 2019
Earlier work this paper cites.
Understanding distributed poisoning attack in federated learning
Di Cao, Shan Chang, Zhijian Lin, Guohua Liu, and Donghong Sun · 2019
Earlier work this paper cites.
Unlabeled data improves adversarial robustness
Yair Carmon, Aditi Raghunathan, Ludwig Schmidt, John C. Duchi, and Percy Liang · 2019
Earlier work this paper cites.
Deepattest: An end-to-end attestation framework for deep neural networks
Huili Chen, Cheng Fu, Bita Darvish Rouhani, Jishen Zhao, and Farinaz Koushanfar · 2019
Earlier work this paper cites.
Deepinspect: a black-box trojan detection and mitigation framework for deep neural networks
Huili Chen, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar · 2019
Earlier work this paper cites.
Convergence of adversarial training in overparametrized neural networks
Ruiqi Gao, Tianle Cai, Haochuan Li, Cho-Jui Hsieh, Liwei Wang, and Jason D. Lee · 2019
Earlier work this paper cites.
Strip: A defence against trojan attacks on deep neural networks
Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith C Ranasinghe, and Surya Nepal · 2019
Earlier work this paper cites.
A new defense against adversarial images: Turning a weakness into a strength
Shengyuan Hu, Tao Yu, Chuan Guo, Wei-Lun Chao, and Kilian Q Weinberger · 2019
Earlier work this paper cites.
Triple wins: Boosting accuracy, robustness and efficiency together by enabling input-adaptive inference
Ting-Kuei Hu, Tianlong Chen, Haotao Wang, and Zhangyang Wang · 2019
Earlier work this paper cites.
Comdefend: An efficient image compression model to defend adversarial examples
Xiaojun Jia, Xingxing Wei, Xiaochun Cao, and Hassan Foroosh · 2019
Earlier work this paper cites.
Ape-gan: Adversarial perturbation elimination with gan
Guoqing Jin, Shiwei Shen, Dongming Zhang, Feng Dai, and Yongdong Zhang · 2019
Earlier work this paper cites.
Prada: protecting against dnn model stealing attacks
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N Asokan · 2019
Earlier work this paper cites.
Abs: Scanning neural networks for back-doors by artificial brain stimulation
Yingqi Liu, Wen-Chuan Lee, Guanhong Tao, Shiqing Ma, Yousra Aafer, and Xiangyu Zhang · 2019
Earlier work this paper cites.
Feature distillation: Dnn-oriented jpeg compression against adversarial examples
Zihao Liu, Qi Liu, Tao Liu, Nuo Xu, Xue Lin, Yanzhi Wang, and Wujie Wen · 2019
Earlier work this paper cites.
Image super-resolution as a defense against adversarial attacks
Aamir Mustafa, Salman H Khan, Munawar Hayat, Jianbing Shen, and Ling Shao · 2019
Earlier work this paper cites.
Learning privacy preserving encodings through adversarial training
Francesco Pittaluga, Sanjeev Koppal, and Ayan Chakrabarti · 2019
Earlier work this paper cites.
Defending neural backdoors via generative distribution modeling
Ximing Qiao, Yukun Yang, and Hai Li · 2019
Earlier work this paper cites.
Adversarial training for free!
Ali Shafahi, Mahyar Najibi, Amin Ghiasi, Zheng Xu, John P. Dickerson, Christoph Studer, Larry S. Davis, Gavin Taylor, and Tom Goldstein · 2019
Earlier work this paper cites.
Can you really backdoor federated learning?
Ziteng Sun, Peter Kairouz, Ananda Theertha Suresh, and H Brendan McMahan · 2019
Earlier work this paper cites.
Adversarial training and robustness for multiple perturbations
Florian Tramèr and Dan Boneh · 2019
Earlier work this paper cites.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao · 2019
Earlier work this paper cites.
Neural cleanse: Identifying and mitigating backdoor attacks in neural networks
Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao · 2019
Earlier work this paper cites.
On the convergence and robustness of adversarial training
Yisen Wang, Xingjun Ma, James Bailey, Jinfeng Yi, Bowen Zhou, and Quanquan Gu · 2019
Earlier work this paper cites.
Skip connections matter: On the transferability of adversarial examples generated with ResNets
Dongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey, and Xingjun Ma · 2019
Earlier work this paper cites.
Dba: Distributed backdoor attacks against federated learning
Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li · 2019
Earlier work this paper cites.
Intriguing properties of adversarial training at scale
Cihang Xie and Alan Yuille · 2019
Earlier work this paper cites.
You only propagate once: Accelerating adversarial training via maximal principle
Dinghuai Zhang, Tianyuan Zhang, Yiping Lu, Zhanxing Zhu, and Bin Dong · 2019
Earlier work this paper cites.
Theoretically principled trade-off between robustness and accuracy
Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P. Xing, Laurent El Ghaoui, and Michael I. Jordan · 2019
Earlier work this paper cites.
The adversarial attack and detection under the fisher information metric
Chenxiao Zhao, P Thomas Fletcher, Mixue Yu, Yaxin Peng, Guixu Zhang, and Chaomin Shen · 2019
Earlier work this paper cites.
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov · 2020
Earlier work this paper cites.
Defending against universal attacks through selective feature regeneration
Tejas Borkar, Felix Heide, and Lina Karam · 2020
Earlier work this paper cites.
Anti-bandit neural architecture search for model defense
Hanlin Chen, Baochang Zhang, Song Xue, Xuan Gong, Hong Liu, Rongrong Ji, and David Doermann · 2020
Earlier work this paper cites.
Stateful detection of black-box adversarial attacks
Steven Chen, Nicholas Carlini, and David Wagner · 2020
Earlier work this paper cites.
A simple framework for contrastive learning of visual representations
Ting Chen, Simon Kornblith, Mohammad Norouzi, and Geoffrey Hinton · 2020
Earlier work this paper cites.
Sentinet: Detecting localized universal attacks against deep learning systems
Edward Chou, Florian Tramer, and Giancarlo Pellegrino · 2020
Earlier work this paper cites.
Detecting adversarial samples using influence functions and nearest neighbors
Gilad Cohen, Guillermo Sapiro, and Raja Giryes · 2020
Earlier work this paper cites.
Privacy-preserving feature extraction via adversarial training
Xiaofeng Ding, Hongbiao Fang, Zhilin Zhang, Kim-Kwang Raymond Choo, and Hai Jin · 2020
Earlier work this paper cites.
Adversarially robust neural architectures
Minjing Dong, Yanxi Li, Yunhe Wang, and Chang Xu · 2020
Earlier work this paper cites.
Adversarial distributional training for robust deep learning
Yinpeng Dong, Zhijie Deng, Tianyu Pang, Jun Zhu, and Hang Su · 2020
Earlier work this paper cites.
Robust anomaly detection and backdoor attack detection via differential privacy
Min Du, Ruoxi Jia, and Dawn Song · 2020
Earlier work this paper cites.
Backdoor attacks and countermeasures on deep learning: A comprehensive review
Yansong Gao, Bao Gia Doan, Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, and Hyoungshick Kim · 2020
Earlier work this paper cites.
When nas meets robustness: In search of robust architectures against adversarial attacks
Minghao Guo, Yuzhe Yang, Rui Xu, Ziwei Liu, and Dahua Lin · 2020
Earlier work this paper cites.
One-pixel signature: Characterizing cnn models for backdoor detection
Shanjiaoyang Huang, Weiqi Peng, Zhiwei Jia, and Zhuowen Tu · 2020
Earlier work this paper cites.
Universal litmus patterns: Revealing backdoor attacks in cnns
Soheil Kolouri, Aniruddha Saha, Hamed Pirsiavash, and Heiko Hoffmann · 2020
Earlier work this paper cites.
Adversarial vertex mixup: Toward better adversarially robust generalization
Saehyung Lee, Hyungyu Lee, and Sungroh Yoon · 2020
Earlier work this paper cites.
Learning to detect malicious clients for robust federated learning
Suyi Li, Yong Cheng, Wei Wang, Yang Liu, and Tianjian Chen · 2020
Earlier work this paper cites.
Adversarial robustness against the union of multiple perturbation models
Pratyush Maini, Eric Wong, and J. Zico Kolter · 2020
Earlier work this paper cites.
A self-supervised approach for adversarial robustness
Muzammal Naseer, Salman Khan, Munawar Hayat, Fahad Shahbaz Khan, and Fatih Porikli · 2020
Earlier work this paper cites.
Overfitting in adversarially robust deep learning
Leslie Rice, Eric Wong, and Zico Kolter · 2020
Earlier work this paper cites.
Denoised smoothing: A provable defense for pretrained classifiers
Hadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor, and J Zico Kolter · 2020
Earlier work this paper cites.
Online adversarial purification based on self-supervised learning
Changhao Shi, Chester Holtz, and Gal Mishne · 2020
Earlier work this paper cites.
Attack of the tails: Yes, you really can backdoor federated learning
Hongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris Papailiopoulos · 2020
Earlier work this paper cites.
Practical detection of trojan neural networks: Data-limited and data-free cases
Ren Wang, Gaoyuan Zhang, Sijia Liu, Pin-Yu Chen, Jinjun Xiong, and Meng Wang · 2020
Cited alongside, same era.
Improving adversarial robustness requires revisiting misclassified examples
Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu · 2020
Cited alongside, same era.
On the trade-off between adversarial and backdoor robustness
Cheng-Hsin Weng, Yan-Ting Lee, and Shan-Hung Brandon Wu · 2020
Cited alongside, same era.
Fast is better than free: Revisiting adversarial training
Eric Wong, Leslie Rice, and J. Zico Kolter · 2020
Cited alongside, same era.
Adversarial weight perturbation helps robust generalization
Dongxian Wu, Shu-Tao Xia, and Yisen Wang · 2020
Cited alongside, same era.
Smooth adversarial training
Cihang Xie, Mingxing Tan, Boqing Gong, Alan Yuille, and Quoc V. Le · 2020
Adversarial training with informed data selection
Marcele OK Mendonça, Javier Maroto, Pascal Frossard, and Paulo SR Diniz · 2022
Later among the works it cites.
Dad: Data-free adversarial defense at test time
Gaurav Kumar Nayak, Ruchit Rawal, and Anirban Chakraborty · 2022
Later among the works it cites.
Diffusion models for adversarial purification
Weili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao, Arash Vahdat, and Animashree Anandkumar · 2022
Later among the works it cites.
Improving robustness against stealthy weight bit-flip attacks by output code matching
Ozan Özdenizci and Robert Legenstein · 2022
Later among the works it cites.
Robustness and accuracy could be reconcilable by (proper) definition
Tianyu Pang, Min Lin, Xiao Yang, Jun Zhu, and Shuicheng Yan · 2022
Later among the works it cites.
Towards adversarial robustness with early exit ensembles
Lorena Qendro and Cecilia Mascolo · 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
DVERGE: diversifying vulnerabilities for enhanced robust generation of ensembles
Huanrui Yang, Jingyang Zhang, Hongliang Dong, Nathan Inkawhich, Andrew Gardner, Andrew Touchet, Wesley Wilkes, Heath Berry, and Hai Li · 2020
Cited alongside, same era.
Ml-loo: Detecting adversarial examples with feature attribution
Puyudi Yang, Jianbo Chen, Cho-Jui Hsieh, Jane-Ling Wang, and Michael Jordan · 2020
Cited alongside, same era.
Attacks which do not kill training make adversarial learning stronger
Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan S. Kankanhalli · 2020
Cited alongside, same era.
Bridging mode connectivity in loss landscapes and adversarial robustness
Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin · 2020
Cited alongside, same era.
Bert loses patience: Fast and robust inference with early exit
Wangchunshu Zhou, Canwen Xu, Tao Ge, Julian McAuley, Ke Xu, and Furu Wei · 2020
Cited alongside, same era.
Adversarial example detection using latent neighborhood graph
Ahmed Abusnaina, Yuhang Wu, Sunpreet Arora, Yizhen Wang, Fei Wang, Hao Yang, and David Mohaisen · 2021
Cited alongside, same era.
Later among the works it cites.
A survey of robust adversarial training in pattern recognition: Fundamental, theory, and methodologies
Zhuang Qian, Kaizhu Huang, Qiu-Feng Wang, and Xu-Yao Zhang · 2022
Later among the works it cites.
Backdoor attacks-resilient aggregation based on robust filtering of outliers in federated learning for image classification
Nuria Rodríguez-Barroso, Eugenio Martínez-Cámara, M Victoria Luzón, and Francisco Herrera · 2022
Later among the works it cites.
On the adversarial robustness of vision transformers
Rulin Shao, Zhouxing Shi, Jinfeng Yi, Pin-Yu Chen, and Cho-jui Hsieh · 2022
Later among the works it cites.
Better trigger inversion optimization in backdoor scanning
Guanhong Tao, Guangyu Shen, Yingqi Liu, Shengwei An, Qiuling Xu, Shiqing Ma, Pan Li, and Xiangyu Zhang · 2022
Later among the works it cites.
Dual-key multimodal backdoors for visual question answering
Matthew Walmer, Karan Sikka, Indranil Sur, Abhinav Shrivastava, and Susmit Jha · 2022
Later among the works it cites.
Self-ensemble adversarial training for improved robustness
Hongjun Wang and Yisen Wang · 2022
Later among the works it cites.
Physically adversarial attacks and defenses in computer vision: a survey
Xingxing Wei, Bangzheng Pu, Jiefan Lu, and Baoyuan Wu · 2022
Later among the works it cites.
Post-training detection of backdoor attacks for two-class and multi-attack scenarios
Zhen Xiang, David Miller, and George Kesidis · 2022
Later among the works it cites.
Why do artificially generated data help adversarial robustness
Yue Xing, Qifan Song, and Guang Cheng · 2022
Later among the works it cites.
Infoat: Improving adversarial training using the information bottleneck principle
Mengting Xu, Tao Zhang, Zhongnian Li, and Daoqiang Zhang · 2022
Later among the works it cites.
Robust weight perturbation for adversarial training
Chaojian Yu, Bo Han, Mingming Gong, Li Shen, Shiming Ge, Du Bo, and Tongliang Liu · 2022
Later among the works it cites.
Effective, efficient and robust neural architecture search
Zhixiong Yue, Baijiong Lin, Yu Zhang, and Christy Liang · 2022
Later among the works it cites.
Adversarial unlearning of backdoors via implicit hypergradient
Yi Zeng, Si Chen, Won Park, Zhuoqing Mao, Ming Jin, and Ruoxi Jia · 2022
Later among the works it cites.
Purifier: Plug-and-play backdoor mitigation for pre-trained models via anomaly activation suppression
Xiaoyu Zhang, Yulin Jin, Tao Wang, Jian Lou, and Xiaofeng Chen · 2022
Later among the works it cites.
Data-free backdoor removal based on channel lipschitzness
Runkai Zheng, Rongjun Tang, Jianze Li, and Li Liu · 2022
Later among the works it cites.
Pre-activation distributions expose backdoor neurons
Runkai Zheng, Rongjun Tang, Jianze Li, and Li Liu · 2022
Later among the works it cites.
Don’t freak out: A frequency-inspired approach to detecting backdoor poisoned samples in dnns
Hasan Abed Al Kader Hammoud, Adel Bibi, Philip HS Torr, and Bernard Ghanem · 2023
Closest in time.
Cleanclip: Mitigating data poisoning attacks in multimodal contrastive learning
Hritik Bansal, Nishad Singhi, Yu Yang, Fan Yin, Aditya Grover, and Kai-Wei Chang · 2023
Closest in time.
Towards building more robust models with frequency bias
Qingwen Bu, Dong Huang, and Heming Cui · 2023
Closest in time.
Neural architecture search for wide spectrum adversarial robustness
Zhi Cheng, Yanxi Li, Minjing Dong, Xiu Su, Shan You, and Chang Xu · 2023
Closest in time.
Detecting backdoors in pre-trained encoders
Shiwei Feng, Guanhong Tao, Siyuan Cheng, Guangyu Shen, Xiangzhe Xu, Yingqi Liu, Kaiyuan Zhang, Shiqing Ma, and Xiangyu Zhang · 2023
Closest in time.
Backdoor defense via adaptively splitting poisoned dataset
Kuofeng Gao, Yang Bai, Jindong Gu, Yong Yang, and Shu-Tao Xia · 2023
Closest in time.
On the effectiveness of adversarial training against backdoor attacks
Yinghua Gao, Dongxian Wu, Jingfeng Zhang, Guanhao Gan, Shu-Tao Xia, Gang Niu, and Masashi Sugiyama · 2023
Closest in time.
Scale-up: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency
Junfeng Guo, Yiming Li, Xun Chen, Hanqing Guo, Lichao Sun, and Cong Liu · 2023
Closest in time.
Domain watermark: Effective and harmless dataset copyright protection is closed at hand
Junfeng Guo, Yiming Li, Lixu Wang, Shu-Tao Xia, Heng Huang, Cong Liu, and Bo Li · 2023
Closest in time.
Generalizable lightweight proxy for robust NAS against diverse perturbations
Hyeonjeong Ha, Minseon Kim, and Sung Ju Hwang · 2023
Closest in time.
Towards attack-tolerant federated learning via critical parameter analysis
Sungwon Han, Sungwon Park, Fangzhao Wu, Sundong Kim, Bin Zhu, Xing Xie, and Meeyoung Cha · 2023
Closest in time.
Orion: Online backdoor sample detection via evolution deviance
Huayang Huang, Qian Wang, Xueluan Gong, and Tao Wang · 2023
Closest in time.
Multi-metrics adaptively identifies backdoors in federated learning
Siquan Huang, Yijiang Li, Chong Chen, Leyu Shi, and Ying Gao · 2023
Closest in time.
Fedgame: A game-theoretic defense against backdoor attacks in federated learning
Jinyuan Jia, Zhuowen Yuan, Dinuka Sahabandu, Luyao Niu, Arezoo Rajabi, Bhaskar Ramasubramanian, Bo Li, and Radha Poovendran · 2023
Closest in time.
Randomized adversarial training via taylor expansion
Gaojie Jin, Xinping Yi, Dengyu Wu, Ronghui Mu, and Xiaowei Huang · 2023
Closest in time.
One-vs-the-rest loss to focus on important samples in adversarial training
Sekitoshi Kanai, Shin’Ya Yamaguchi, Masanori Yamada, Hiroshi Takahashi, Kentaro Ohno, and Yasutoshi Ida · 2023
Closest in time.
Data augmentation alone can improve adversarial training
Lin Li and Michael W. Spratling · 2023
Closest in time.
Less is more: Data pruning for faster adversarial training
Yize Li, Pu Zhao, Xue Lin, Bhavya Kailkhura, and Ryan Goldh · 2023
Closest in time.
Badclip: Dual-embedding guided backdoor attack on multimodal contrastive learning
Siyuan Liang, Mingli Zhu, Aishan Liu, Baoyuan Wu, Xiaochun Cao, and Ee-Chien Chang · 2023
Closest in time.
Exploring the relationship between architectural design and adversarially robust generalization
Aishan Liu, Shiyu Tang, Siyuan Liang, Ruihao Gong, Boxi Wu, Xianglong Liu, and Dacheng Tao · 2023
Closest in time.
Generating robust dnn with resistance to bit-flip based adversarial weight attack
Liang Liu, Yanan Guo, Yueqiang Cheng, Youtao Zhang, and Jun Yang · 2023
Closest in time.
Backdoor defense with non-adversarial backdoor
Min Liu, Alberto Sangiovanni-Vincentelli, and Xiangyu Yue · 2023
Closest in time.
Detecting backdoors during the inference stage based on corruption robustness consistency
Xiaogeng Liu, Minghui Li, Haoyu Wang, Shengshan Hu, Dengpan Ye, Hai Jin, Libing Wu, and Chaowei Xiao · 2023
Closest in time.
The "beatrix" resurrections: Robust backdoor detection via gram matrices
Wanlun Ma, Derui Wang, Ruoxi Sun, Minhui Xue, Sheng Wen, and Yang Xiang · 2023
Closest in time.
Towards stable backdoor purification through feature shift tuning
Rui Min, Zeyu Qin, Li Shen, and Minhao Cheng · 2023
Closest in time.
Progressive backdoor erasing via connecting backdoor and adversarial attacks
Bingxu Mu, Zhenxing Niu, Le Wang, Xue Wang, Qiguang Miao, Rong Jin, and Gang Hua · 2023
Closest in time.
ASSET: robust backdoor data detection across a multiplicity of deep learning paradigms
Minzhou Pan, Yi Zeng, Lingjuan Lyu, Xue Lin, and Ruoxi Jia · 2023
Closest in time.
Backdoor cleansing with unlabeled data
Lu Pang, Tao Sun, Haibin Ling, and Chao Chen · 2023
Closest in time.
Robust principles: Architectural design principles for adversarially robust CNNs
ShengYun Peng, Weilin Xu, Cory Cornelius, Matthew Hull, Kevin Li, Rahul Duggal, Mansi Phute, Jason Martin, and Duen Horng Chau · 2023
Closest in time.
RobArch: Designing robust architectures against adversarial attacks
ShengYun Peng, Weilin Xu, Cory Cornelius, Kevin Li, Rahul Duggal, Duen Horng Chau, and Jason Martin · 2023
Closest in time.
Are you copying my model? protecting the copyright of large language models for eaas via backdoor watermark
Wenjun Peng, Jingwei Yi, Fangzhao Wu, Shangxi Wu, Bin Zhu, Lingjuan Lyu, Binxing Jiao, Tong Xu, Guangzhong Sun, and Xing Xie · 2023
Closest in time.
Towards a proactive ml approach for detecting backdoor poison samples
Xiangyu Qi, Tinghao Xie, Tianhao Wang, Tong Wu, Saeed Mahloujifar, and Prateek Mittal · 2023
Closest in time.
A survey of bit-flip attacks on deep neural network and corresponding defense methods
Cheng Qian, Ming Zhang, Yuanping Nie, Shuaibing Lu, and Huayang Cao · 2023
Closest in time.
Black-box backdoor defense via zero-shot image purification
Yucheng Shi, Mengnan Du, Xuansheng Wu, Zihan Guan, and Ninghao Liu · 2023
Closest in time.
Single image backdoor inversion via robust smoothed classifiers
Mingjie Sun and Zico Kolter · 2023
Closest in time.
Setting the trap: Capturing and defeating backdoors in pretrained language models through honeypots
Ruixiang Tang, Jiayi Yuan, Yiming Li, Zirui Liu, Rui Chen, and Xia Hu · 2023
Closest in time.
Aegis: Mitigating targeted bit-flip attacks against deep neural networks
Jialai Wang, Ziyuan Zhang, Meiqi Wang, Han Qiu, Tianwei Zhang, Qi Li, Zongpeng Li, Tao Wei, and Chao Zhang · 2023
Closest in time.
Unicorn: A unified backdoor trigger inversion framework
Zhenting Wang, Kai Mei, Juan Zhai, and Shiqing Ma · 2023
Closest in time.
Unicorn: A unified backdoor trigger inversion framework
Zhenting Wang, Kai Mei, Juan Zhai, and Shiqing Ma · 2023
Closest in time.
Rab: Provable robustness against backdoor attacks
Maurice Weber, Xiaojun Xu, Bojan Karlaš, Ce Zhang, and Bo Li · 2023
Closest in time.
Shared adversarial unlearning: Backdoor mitigation by unlearning shared adversarial examples
Shaokui Wei, Mingda Zhang, Hongyuan Zha, and Baoyuan Wu · 2023
Closest in time.
Adversarial machine learning: A systematic survey of backdoor attack, weight attack and adversarial example
Baoyuan Wu, Li Liu, Zihao Zhu, Qingshan Liu, Zhaofeng He, and Siwei Lyu · 2023
Closest in time.
A unified detection framework for inference-stage backdoor defenses
Xun Xian, Ganghua Wang, Jayanth Srinivasa, Ashish Kundu, Xuan Bi, Mingyi Hong, and Jie Ding · 2023
Closest in time.
RobustMQ: Benchmarking robustness of quantized models
Yisong Xiao, Aishan Liu, Tianyuan Zhang, Haotong Qin, Jinyang Guo, and Xianglong Liu · 2023
Closest in time.
Adversarially robust neural architecture search for graph neural networks
Beini Xie, Heng Chang, Ziwei Zhang, Xin Wang, Daixin Wang, Zhiqiang Zhang, Rex Ying, and Wenwu Zhu · 2023
Closest in time.
On the connection between invariant learning and adversarial training for out-of-distribution generalization
Shiji Xin, Yifei Wang, Jingtong Su, and Yisen Wang · 2023
Closest in time.
Watermarking graph neural networks based on backdoor attacks
Jing Xu, Stefanos Koffas, Oğuzhan Ersoy, and Stjepan Picek · 2023
Closest in time.
Improving adversarial robustness by putting more regularizations on less robust samples
Dongyoon Yang, Insung Kong, and Yongdai Kim · 2023
Closest in time.
Backdoor defense via suppressing model shortcuts
Sheng Yang, Yiming Li, Yong Jiang, and Shu-Tao Xia · 2023
Closest in time.
Fed-FA: Theoretically modeling client data divergence for federated language backdoor defense
Zhiyuan Zhang, Deli Chen, Hao Zhou, Fandong Meng, Jie Zhou, and Xu Sun · 2023
Closest in time.
Backdoor defense via deconfounded representation learning
Zaixi Zhang, Qi Liu, Zhicai Wang, Zepu Lu, and Qingyong Hu · 2023
Closest in time.
Copyright protection and accountability of generative ai: Attack, watermarking and attribution
Haonan Zhong, Jiamin Chang, Ziyue Yang, Tingmin Wu, Pathum Chamikara Mahawaga Arachchige, Chehara Pathmabandu, and Minhui Xue · 2023
Closest in time.
Improving generalization of adversarial training via robust critical fine-tuning
Kaijie Zhu, Xixu Hu, Jindong Wang, Xing Xie, and Ge Yang · 2023
Closest in time.
Enhancing fine-tuning based backdoor defense with sharpness-aware minimization
Mingli Zhu, Shaokui Wei, Li Shen, Yanbo Fan, and Baoyuan Wu · 2023
Closest in time.
Neural polarizer: A lightweight and effective backdoor defense via purifying poisoned features
Mingli Zhu, Shaokui Wei, Hongyuan Zha, and Baoyuan Wu · 2023
Closest in time.
Robust neural architecture search
Xunyu Zhu, Jian Li, Yong Liu, and Weiping Wang · 2023
Closest in time.