Fetching the paper…
Reading the bibliography…
Practitioners commonly download pretrained machine learning models from open repositories and finetune them to fit specific applications.
Toward semantics-based answer pinpointing
Hovy, E., Gerber, L., Hermjakob, U., Lin, C.-Y., and Ravichandran, D · 2001
Earlier work this paper cites.
Learning question classifiers
Li, X. and Roth, D · 2002
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Dwork, C., McSherry, F., Nissim, K., and Smith, A · 2006
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A · 2009
Earlier work this paper cites.
Understanding the difficulty of training deep feedforward neural networks
Glorot, X. and Bengio, Y · 2010
Earlier work this paper cites.
Cats and dogs
Parkhi, O. M., Vedaldi, A., Zisserman, A., and Jawahar, C. V · 2012
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Dwork, C., Roth, A., et al · 2014
Earlier work this paper cites.
The composition theorem for differential privacy
Kairouz, P., Oh, S., and Viswanath, P · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
He, K., Zhang, X., Ren, S., and Sun, J · 2016
Earlier work this paper cites.
Gaussian error linear units (GELUs)
Hendrycks, D. and Gimpel, K · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction { \{ APIs } \}
Tramèr, F., Zhang, F., Juels, A., Reiter, M. K., and Ristenpart, T · 2016
Earlier work this paper cites.
BadNets: Identifying vulnerabilities in the machine learning model supply chain
Gu, T., Dolan-Gavitt, B., and Garg, S · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
Shokri, R., Stronati, M., Song, C., and Shmatikov, V · 2017
Earlier work this paper cites.
Machine learning models that remember too much
Song, C., Ristenpart, T., and Shmatikov, V · 2017
Earlier work this paper cites.
Attention is all you need
Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, Ł., and Polosukhin, I · 2017
Earlier work this paper cites.
Privacy amplification by iteration
Feldman, V., Mironov, I., Talwar, K., and Thakurta, A · 2018
Cited alongside, same era.
Trojaning attack on neural networks
Liu, Y., Ma, S., Aafer, Y., Lee, W.-C., Zhai, J., Wang, W., and Zhang, X · 2018
Cited alongside, same era.
Privacy-preserving deep learning via additively homomorphic encryption
Phong, L. T., Aono, Y., Hayashi, T., Wang, L., and Moriai, S · 2018
Cited alongside, same era.
BERT: Pre-training of deep bidirectional transformers for language understanding, 2019
Devlin, J., Chang, M.-W., Lee, K., and Toutanova, K · 2019
Cited alongside, same era.
Renyi differential privacy of the sampled gaussian mechanism
Mironov, I., Talwar, K., and Zhang, L · 2019
Cited alongside, same era.
Understanding and improving layer normalization
Xu, J., Sun, X., Zhang, Z., Zhao, G., and Lin, J · 2019
LoRA: Low-rank adaptation of large language models
Hu, E. J., Shen, Y., Wallis, P., Allen-Zhu, Z., Li, Y., Wang, S., Wang, L., and Chen, W · 2021
Later among the works it cites.
Adversary instantiation: Lower bounds for differentially private machine learning
Nasr, M., Songi, S., Thakurta, A., Papernot, N., and Carlin, N · 2021
Later among the works it cites.
Opacus: User-friendly differential privacy library in PyTorch
Yousefpour, A., Shilov, I., Sablayrolles, A., Testuggine, D., Prasad, K., Malek, M., Nguyen, J., Ghosh, S., Bharadwaj, A., Zhao, J., Cormode, G., and Mironov, I · 2021
Later among the works it cites.
Decepticons: Corrupted transformers breach privacy in federated learning for language models
Fowl, L., Geiping, J., Reich, S., Wen, Y., Czaja, W., Goldblum, M., and Goldstein, T · 2022
Later among the works it cites.
Handcrafted backdoors in deep neural networks
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Cited alongside, same era.
Cryptanalytic extraction of neural network models
Carlini, N., Jagielski, M., and Mironov, I · 2020
Cited alongside, same era.
An image is worth 16x16 words: Transformers for image recognition at scale
Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., Gelly, S., et al · 2020
Cited alongside, same era.
Auditing differentially private machine learning: How private is private SGD?
Jagielski, M., Ullman, J., and Oprea, A · 2020
Cited alongside, same era.
Training production language models without memorizing user data
Ramaswamy, S., Thakkar, O., Mathews, R., Andrew, G., McMahan, H. B., and Beaufays, F · 2020
Cited alongside, same era.
Reverse-engineering deep relu networks
Rolnick, D. and Kording, K · 2020
Cited alongside, same era.
Differentially private learning needs better features (or much more data)
Tramer, F. and Boneh, D · 2020
Cited alongside, same era.
Hong, S., Carlini, N., and Kurakin, A · 2022
Later among the works it cites.
Truth serum: Poisoning machine learning models to reveal their secrets
Tramèr, F., Shokri, R., San Joaquin, A., Le, H., Jagielski, M., Hong, S., and Carlini, N · 2022
Later among the works it cites.
Fishing for user data in large-batch federated learning via gradient magnification
Wen, Y., Geiping, J., Fowl, L., Goldblum, M., and Goldstein, T · 2022
Later among the works it cites.
When the curious abandon honesty: Federated learning is not private
Boenisch, F., Dziedzic, A., Schuster, R., Shamsabadi, A. S., Shumailov, I., and Papernot, N · 2023
Later among the works it cites.
Extracting training data from diffusion models
Carlini, N., Hayes, J., Nasr, M., Jagielski, M., Sehwag, V., Tramer, F., Balle, B., Ippolito, D., and Wallace, E · 2023
Later among the works it cites.
Teach GPT to phish
Panda, A., Zhang, Z., Yang, Y., and Mittal, P · 2023
Later among the works it cites.
Polynomial time cryptanalytic extraction of neural network models
Shamir, A., Canales-Martinez, I., Hambitzer, A., Chavez-Saab, J., Rodrigez-Henriquez, F., and Satpute, N · 2023
Later among the works it cites.
Privacy auditing with one (1) training run
Steinke, T., Nasr, M., and Jagielski, M · 2023
Later among the works it cites.
Loki: Large-scale data reconstruction attack against federated learning through model manipulation
Zhao, J. C., Sharma, A., Elkordy, A. R., Ezzeldin, Y. H., Avestimehr, S., and Bagchi, S · 2023
Later among the works it cites.
Precurious: How innocent pre-trained language models turn into privacy traps
Liu, R., Wang, T., Cao, Y., and Xiong, L · 2024
Closest in time.
Privacy backdoors: Enhancing membership inference through poisoning pre-trained models, 2024
Wen, Y., Marchyok, L., Hong, S., Geiping, J., Goldstein, T., and Carlini, N · 2024
Closest in time.