{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,20]],"date-time":"2026-08-20T14:45:58Z","timestamp":1787237158725,"version":"build-2736575974"},"reference-count":161,"publisher":"Association for Computing Machinery (ACM)","issue":"8","license":[{"start":{"date-parts":[[2022,12,23]],"date-time":"2022-12-23T00:00:00Z","timestamp":1671753600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Australia ARC","award":["DP200101374 and LP190100676"],"award-info":[{"award-number":["DP200101374 and LP190100676"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2023,8,31]]},"abstract":"<jats:p>The prosperity of machine learning has been accompanied by increasing attacks on the training process. Among them, poisoning attacks have become an emerging threat during model training. Poisoning attacks have profound impacts on the target models, e.g., making them unable to converge or manipulating their prediction results. Moreover, the rapid development of recent distributed learning frameworks, especially federated learning, has further stimulated the development of poisoning attacks. Defending against poisoning attacks is challenging and urgent. However, the systematic review from a unified perspective remains blank. This survey provides an in-depth and up-to-date overview of poisoning attacks and corresponding countermeasures in both centralized and federated learning. We firstly categorize attack methods based on their goals. Secondly, we offer detailed analysis of the differences and connections among the attack techniques. Furthermore, we present countermeasures in different learning framework and highlight their advantages and disadvantages. Finally, we discuss the reasons for the feasibility of poisoning attacks and address the potential research directions from attacks and defenses perspectives, separately.<\/jats:p>","DOI":"10.1145\/3551636","type":"journal-article","created":{"date-parts":[[2022,7,30]],"date-time":"2022-07-30T07:05:00Z","timestamp":1659164700000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":248,"title":["A Comprehensive Survey on Poisoning Attacks and Countermeasures in Machine Learning"],"prefix":"10.1145","volume":"55","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8905-0941","authenticated-orcid":false,"given":"Zhiyi","family":"Tian","sequence":"first","affiliation":[{"name":"University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1932-1440","authenticated-orcid":false,"given":"Lei","family":"Cui","sequence":"additional","affiliation":[{"name":"Shandong Computer Science Center (National Supercomputer Center in Jinan), Jinan City, Shandong Province, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7179-5208","authenticated-orcid":false,"given":"Jie","family":"Liang","sequence":"additional","affiliation":[{"name":"University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4485-6743","authenticated-orcid":false,"given":"Shui","family":"Yu","sequence":"additional","affiliation":[{"name":"University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,23]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/2996758.2996768"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"e_1_3_1_4_2","first-page":"2938","volume-title":"The 23rd International Conference on Artificial Intelligence and Statistics, AISTATS 2020 (Proceedings of Machine Learning Research)","volume":"108","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In The 23rd International Conference on Artificial Intelligence and Statistics, AISTATS 2020 (Proceedings of Machine Learning Research), Vol. 108. PMLR, 2938\u20132948."},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"e_1_3_1_7_2","first-page":"8632","volume-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019","author":"Baruch Gilad","year":"2019","unstructured":"Gilad Baruch, Moran Baruch, and Yoav Goldberg. 2019. A little is enough: Circumventing defenses for distributed learning. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019. 8632\u20138642."},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3429252"},{"key":"e_1_3_1_9_2","first-page":"634","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019 (Proceedings of Machine Learning Research)","volume":"97","author":"Bhagoji Arjun Nitin","year":"2019","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin B. Calo. 2019. Analyzing federated learning through an adversarial lens. In Proceedings of the 36th International Conference on Machine Learning, ICML 2019 (Proceedings of Machine Learning Research), Vol. 97. PMLR, 634\u2013643."},{"key":"e_1_3_1_10_2","first-page":"42","volume-title":"Structural, Syntactic, and Statistical Pattern Recognition - Joint IAPR International Workshop, S+SSPR 2014 (Lecture Notes in Computer Science)","author":"Biggio Battista","year":"2014","unstructured":"Battista Biggio, Samuel Rota Bul\u00f2, Ignazio Pillai, Michele Mura, Eyasu Zemene Mequanint, Marcello Pelillo, and Fabio Roli. 2014. Poisoning complete-linkage hierarchical clustering. In Structural, Syntactic, and Statistical Pattern Recognition - Joint IAPR International Workshop, S+SSPR 2014 (Lecture Notes in Computer Science), Vol. 8621. Springer, 42\u201352."},{"key":"e_1_3_1_11_2","first-page":"97","volume-title":"Asian Conference on Machine Learning","author":"Biggio Battista","year":"2011","unstructured":"Battista Biggio, Blaine Nelson, and Pavel Laskov. 2011. Support vector machines under adversarial label noise. In Asian Conference on Machine Learning. PMLR, 97\u2013112."},{"key":"e_1_3_1_12_2","volume-title":"Proceedings of the 29th International Conference on Machine Learning, ICML 2012","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning attacks against support vector machines. In Proceedings of the 29th International Conference on Machine Learning, ICML 2012. icml.cc\/Omnipress."},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/2666652.2666666"},{"key":"e_1_3_1_14_2","first-page":"119","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017. 119\u2013129."},{"key":"e_1_3_1_15_2","volume-title":"Analyzing Social Networks","author":"Borgatti Stephen P.","year":"2018","unstructured":"Stephen P. Borgatti, Martin G. Everett, and Jeffrey C. Johnson. 2018. Analyzing Social Networks. Sage."},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9414862"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-7908-2604-3_16"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS47876.2019.00042"},{"key":"e_1_3_1_19_2","first-page":"267","volume-title":"28th USENIX Security Symposium, USENIX Security 2019","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Chang Liu, \u00dalfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The secret sharer: Evaluating and testing unintended memorization in neural networks. In 28th USENIX Security Symposium, USENIX Security 2019. USENIX Association, 267\u2013284."},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2017.2739145"},{"key":"e_1_3_1_21_2","volume-title":"Workshop on Artificial Intelligence Safety 2019 co-located with the Thirty-Third AAAI Conference on Artificial Intelligence 2019 (AAAI-19) (CEUR Workshop Proceedings)","volume":"2301","author":"Chen Bryant","year":"2019","unstructured":"Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian M. Molloy, and Biplav Srivastava. 2019. Detecting backdoor attacks on deep neural networks by activation clustering. In Workshop on Artificial Intelligence Safety 2019 co-located with the Thirty-Third AAAI Conference on Artificial Intelligence 2019 (AAAI-19) (CEUR Workshop Proceedings), Vol. 2301. CEUR-WS.org."},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3080522"},{"key":"e_1_3_1_23_2","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","volume":"1712","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. CoRR abs\/1712.05526 (2017).","journal-title":"CoRR"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.11"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-75171-7_2"},{"key":"e_1_3_1_26_2","first-page":"6510","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Dai Zihang","year":"2017","unstructured":"Zihang Dai, Zhilin Yang, Fan Yang, William W. Cohen, and Ruslan Salakhutdinov. 2017. Good semi-supervised learning that requires a bad GAN. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017. 6510\u20136520."},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/1864708.1864770"},{"key":"e_1_3_1_28_2","first-page":"321","volume-title":"28th USENIX Security Symposium, USENIX Security 2019","author":"Demontis Ambra","year":"2019","unstructured":"Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In 28th USENIX Security Symposium, USENIX Security 2019. USENIX Association, 321\u2013338."},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_1_30_2","first-page":"1596","volume-title":"International Conference on Machine Learning","author":"Diakonikolas Ilias","year":"2019","unstructured":"Ilias Diakonikolas, Gautam Kamath, Daniel Kane, Jerry Li, Jacob Steinhardt, and Alistair Stewart. 2019. Sever: A robust meta-algorithm for stochastic optimization. In International Conference on Machine Learning. PMLR, 1596\u20131606."},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"e_1_3_1_32_2","first-page":"1080","article-title":"SplitGuard: Detecting and mitigating training-hijacking attacks in split learning","author":"Erdogan Ege","year":"2021","unstructured":"Ege Erdogan, Alptekin K\u00fcp\u00e7\u00fc, and A. Erc\u00fcment \u00c7i\u00e7ek. 2021. SplitGuard: Detecting and mitigating training-hijacking attacks in split learning. IACR Cryptol. ePrint Arch. (2021), 1080.","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"e_1_3_1_33_2","first-page":"1605","volume-title":"29th USENIX Security Symposium, USENIX Security 2020","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong. 2020. Local model poisoning attacks to Byzantine-robust federated learning. In 29th USENIX Security Symposium, USENIX Security 2020. USENIX Association, 1605\u20131622."},{"key":"e_1_3_1_34_2","first-page":"253","article-title":"Robust logistic regression and classification","volume":"27","author":"Feng Jiashi","year":"2014","unstructured":"Jiashi Feng, Huan Xu, Shie Mannor, and Shuicheng Yan. 2014. Robust logistic regression and classification. Advances in Neural Information Processing Systems 27 (2014), 253\u2013261.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_35_2","first-page":"17","volume-title":"Proceedings of the 23rd USENIX Security Symposium","author":"Fredrikson Matthew","year":"2014","unstructured":"Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon M. Lin, David Page, and Thomas Ristenpart. 2014. Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing. In Proceedings of the 23rd USENIX Security Symposium. USENIX Association, 17\u201332."},{"key":"e_1_3_1_36_2","unstructured":"Clement Fung Chris J. M. Yoon and Ivan Beschastnikh. 2020. The limitations of federated learning in sybil settings. (2020) 301\u2013316."},{"key":"e_1_3_1_37_2","article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","author":"Gao Yansong","year":"2020","unstructured":"Yansong Gao, Bao Gia Doan, Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, and Hyoungshick Kim. 2020. Backdoor attacks and countermeasures on deep learning: A comprehensive review. arXiv preprint arXiv:2007.10760 (2020).","journal-title":"arXiv preprint arXiv:2007.10760"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.5555\/3298483.3298518"},{"key":"e_1_3_1_39_2","volume-title":"5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24\u201326, 2017, Conference Track Proceedings","author":"Goldberger Jacob","year":"2017","unstructured":"Jacob Goldberger and Ehud Ben-Reuven. 2017. Training deep neural-networks using a noise adaptation layer. In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24\u201326, 2017, Conference Track Proceedings. OpenReview.net."},{"key":"e_1_3_1_40_2","article-title":"A field guide to forward-backward splitting with a FASTA implementation","volume":"1411","author":"Goldstein Tom","year":"2014","unstructured":"Tom Goldstein, Christoph Studer, and Richard G. Baraniuk. 2014. A field guide to forward-backward splitting with a FASTA implementation. CoRR abs\/1411.3406 (2014).","journal-title":"CoRR"},{"key":"e_1_3_1_41_2","first-page":"2672","volume-title":"Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems 2014","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron C. Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems 2014. 2672\u20132680."},{"key":"e_1_3_1_42_2","volume-title":"3rd International Conference on Learning Representations, ICLR 2015","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In 3rd International Conference on Learning Representations, ICLR 2015."},{"key":"e_1_3_1_43_2","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","volume":"1708","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. BadNets: Identifying vulnerabilities in the machine learning model supply chain. CoRR abs\/1708.06733 (2017).","journal-title":"CoRR"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2018.05.003"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-84858-7_14"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359824"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/2854157"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22496-7_5"},{"key":"e_1_3_1_49_2","first-page":"10477","volume-title":"Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018","author":"Hendrycks Dan","year":"2018","unstructured":"Dan Hendrycks, Mantas Mazeika, Duncan Wilson, and Kevin Gimpel. 2018. Using trusted data to train deep networks on labels corrupted by severe noise. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018. 10477\u201310486."},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3056664"},{"key":"e_1_3_1_51_2","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020","author":"Huang W. Ronny","year":"2020","unstructured":"W. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor, and Tom Goldstein. 2020. MetaPoison: Practical general-purpose clean-label data poisoning. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020."},{"key":"e_1_3_1_52_2","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/SP.2018.00057","volume-title":"2018 IEEE Symposium on Security and Privacy, SP 2018","author":"Jagielski Matthew","year":"2018","unstructured":"Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li. 2018. Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In 2018 IEEE Symposium on Security and Privacy, SP 2018. IEEE Computer Society, 19\u201335."},{"key":"e_1_3_1_53_2","article-title":"Subpopulation data poisoning attacks","volume":"2006","author":"Jagielski Matthew","year":"2020","unstructured":"Matthew Jagielski, Giorgio Severi, Niklas Pousette Harger, and Alina Oprea. 2020. Subpopulation data poisoning attacks. CoRR abs\/2006.14026 (2020).","journal-title":"CoRR"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"e_1_3_1_56_2","article-title":"Adam: A method for stochastic optimization","author":"Kingma Diederik P.","year":"2014","unstructured":"Diederik P. Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014).","journal-title":"arXiv preprint arXiv:1412.6980"},{"key":"e_1_3_1_57_2","volume-title":"2nd International Conference on Learning Representations, ICLR 2014","author":"Kingma Diederik P.","year":"2014","unstructured":"Diederik P. Kingma and Max Welling. 2014. Auto-encoding Variational Bayes. In 2nd International Conference on Learning Representations, ICLR 2014."},{"key":"e_1_3_1_58_2","first-page":"1885","volume-title":"Proceedings of the 34th International Conference on Machine Learning, ICML 2017 (Proceedings of Machine Learning Research)","volume":"70","author":"Koh Pang Wei","year":"2017","unstructured":"Pang Wei Koh and Percy Liang. 2017. Understanding black-box predictions via influence functions. In Proceedings of the 34th International Conference on Machine Learning, ICML 2017 (Proceedings of Machine Learning Research), Vol. 70. PMLR, 1885\u20131894."},{"key":"e_1_3_1_59_2","article-title":"Stronger data poisoning attacks break data sanitization defenses","volume":"1811","author":"Koh Pang Wei","year":"2018","unstructured":"Pang Wei Koh, Jacob Steinhardt, and Percy Liang. 2018. Stronger data poisoning attacks break data sanitization defenses. CoRR abs\/1811.00741 (2018). http:\/\/arxiv.org\/abs\/1811.00741.","journal-title":"CoRR"},{"key":"e_1_3_1_60_2","volume-title":"5th International Conference on Learning Representations, ICLR 2017","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio. 2017. Adversarial examples in the physical world. In 5th International Conference on Learning Representations, ICLR 2017. OpenReview.net."},{"key":"e_1_3_1_61_2","first-page":"203","volume-title":"Concurrency: The Works of Leslie Lamport","author":"Lamport Leslie","year":"2019","unstructured":"Leslie Lamport, Robert E. Shostak, and Marshall C. Pease. 2019. The Byzantine generals problem. In Concurrency: The Works of Leslie Lamport. ACM, 203\u2013226."},{"key":"e_1_3_1_62_2","first-page":"21","volume-title":"Proceedings of the 1988 Connectionist Models Summer School","volume":"1","author":"LeCun Yann","year":"1988","unstructured":"Yann LeCun, D. Touresky, G. Hinton, and T. Sejnowski. 1988. A theoretical framework for back-propagation. In Proceedings of the 1988 Connectionist Models Summer School, Vol. 1. 21\u201328."},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3094824"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-35288-2"},{"key":"e_1_3_1_65_2","article-title":"Learning to detect malicious clients for robust federated learning","author":"Li Suyi","year":"2020","unstructured":"Suyi Li, Yong Cheng, Wei Wang, Yang Liu, and Tianjian Chen. 2020. Learning to detect malicious clients for robust federated learning. arXiv preprint arXiv:2002.00211 (2020).","journal-title":"arXiv preprint arXiv:2002.00211"},{"key":"e_1_3_1_66_2","article-title":"Hidden backdoors in human-centric language models","volume":"2105","author":"Li Shaofeng","year":"2021","unstructured":"Shaofeng Li, Hui Liu, Tian Dong, Benjamin Zi Hao Zhao, Minhui Xue, Haojin Zhu, and Jialiang Lu. 2021. Hidden backdoors in human-centric language models. CoRR abs\/2105.00164 (2021).","journal-title":"CoRR"},{"key":"e_1_3_1_67_2","article-title":"Backdoor learning: A survey","volume":"2007","author":"Li Yiming","year":"2020","unstructured":"Yiming Li, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2020. Backdoor learning: A survey. CoRR abs\/2007.08745 (2020).","journal-title":"CoRR"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.211"},{"key":"e_1_3_1_69_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"e_1_3_1_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2003.1167344"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140447"},{"key":"e_1_3_1_72_2","first-page":"273","volume-title":"Research in Attacks, Intrusions, and Defenses - 21st International Symposium, RAID 2018 (Lecture Notes in Computer Science)","author":"Liu Kang","year":"2018","unstructured":"Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2018. Fine-pruning: Defending against backdooring attacks on deep neural networks. In Research in Attacks, Intrusions, and Defenses - 21st International Symposium, RAID 2018 (Lecture Notes in Computer Science), Vol. 11050. Springer, 273\u2013294."},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2015.2456899"},{"key":"e_1_3_1_74_2","first-page":"6226","volume-title":"Proceedings of the 37th International Conference on Machine Learning, ICML 2020 (Proceedings of Machine Learning Research)","volume":"119","author":"Liu Yang","year":"2020","unstructured":"Yang Liu and Hongyi Guo. 2020. Peer loss functions: Learning from noisy labels without knowing noise rates. In Proceedings of the 37th International Conference on Machine Learning, ICML 2020 (Proceedings of Machine Learning Research), Vol. 119. PMLR, 6226\u20136236."},{"key":"e_1_3_1_75_2","volume-title":"25th Annual Network and Distributed System Security Symposium, NDSS 2018","author":"Liu Yingqi","year":"2018","unstructured":"Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang. 2018. Trojaning attack on neural networks. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018. The Internet Society."},{"key":"e_1_3_1_76_2","first-page":"406","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Ma Liqian","year":"2017","unstructured":"Liqian Ma, Xu Jia, Qianru Sun, Bernt Schiele, Tinne Tuytelaars, and Luc Van Gool. 2017. Pose guided person image generation. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017. 406\u2013416."},{"key":"e_1_3_1_77_2","first-page":"960","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Malach Eran","year":"2017","unstructured":"Eran Malach and Shai Shalev-Shwartz. 2017. Decoupling \u201cwhen to update\u201d from \u201chow to update\u201d. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017. 960\u2013970."},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1007\/BF02478259"},{"key":"e_1_3_1_79_2","first-page":"1273","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017 (Proceedings of Machine Learning Research)","volume":"54","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017 (Proceedings of Machine Learning Research), Vol. 54. PMLR, 1273\u20131282."},{"key":"e_1_3_1_80_2","first-page":"1273","volume-title":"Artificial Intelligence and Statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics. PMLR, 1273\u20131282."},{"key":"e_1_3_1_81_2","doi-asserted-by":"publisher","DOI":"10.5555\/2886521.2886721"},{"key":"e_1_3_1_82_2","volume-title":"CEAS 2004 - First Conference on Email and Anti-Spam, July 30\u201331, 2004","author":"Meyer Tony A.","year":"2004","unstructured":"Tony A. Meyer and Brendon Whateley. 2004. SpamBayes: Effective open-source, Bayesian based, email classification system. In CEAS 2004 - First Conference on Email and Anti-Spam, July 30\u201331, 2004."},{"key":"e_1_3_1_83_2","first-page":"3518","volume-title":"Proceedings of the 35th International Conference on Machine Learning, ICML 2018 (Proceedings of Machine Learning Research)","volume":"80","author":"Mhamdi El Mahdi El","year":"2018","unstructured":"El Mahdi El Mhamdi, Rachid Guerraoui, and S\u2019ebastien Rouault. 2018. The hidden vulnerability of distributed learning in Byzantium. In Proceedings of the 35th International Conference on Machine Learning, ICML 2018 (Proceedings of Machine Learning Research), Vol. 80. PMLR, 3518\u20133527."},{"key":"e_1_3_1_84_2","volume-title":"1st International Conference on Learning Representations, ICLR 2013, Workshop Track Proceedings","author":"Mikolov Tom\u00e1s","year":"2013","unstructured":"Tom\u00e1s Mikolov, Kai Chen, Greg Corrado, and Jeffrey Dean. 2013. Efficient estimation of word representations in vector space. In 1st International Conference on Learning Representations, ICLR 2013, Workshop Track Proceedings."},{"key":"e_1_3_1_85_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140451"},{"key":"e_1_3_1_86_2","article-title":"Poisoning attacks with generative adversarial nets","volume":"1906","author":"Mu\u00f1oz-Gonz\u00e1lez Luis","year":"2019","unstructured":"Luis Mu\u00f1oz-Gonz\u00e1lez, Bjarne Pfitzner, Matteo Russo, Javier Carnerero-Cano, and Emil C. Lupu. 2019. Poisoning attacks with generative adversarial nets. CoRR abs\/1906.07773 (2019).","journal-title":"CoRR"},{"key":"e_1_3_1_87_2","volume-title":"Machine Learning: A Probabilistic Perspective","author":"Murphy Kevin P.","year":"2012","unstructured":"Kevin P. Murphy. 2012. Machine Learning: A Probabilistic Perspective. MIT Press."},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"e_1_3_1_89_2","first-page":"1196","article-title":"Learning with noisy labels","volume":"26","author":"Natarajan Nagarajan","year":"2013","unstructured":"Nagarajan Natarajan, Inderjit S. Dhillon, Pradeep K. Ravikumar, and Ambuj Tewari. 2013. Learning with noisy labels. Advances in Neural Information Processing Systems 26 (2013), 1196\u20131204.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_1_90_2","volume-title":"First USENIX Workshop on Large-Scale Exploits and Emergent Threats, LEET\u201908","author":"Nelson Blaine","year":"2008","unstructured":"Blaine Nelson, Marco Barreno, Fuching Jack Chi, Anthony D. Joseph, Benjamin I. P. Rubinstein, Udam Saini, Charles Sutton, J. Doug Tygar, and Kai Xia. 2008. Exploiting machine learning to subvert your spam filter. In First USENIX Workshop on Large-Scale Exploits and Emergent Threats, LEET\u201908. USENIX Association."},{"key":"e_1_3_1_91_2","doi-asserted-by":"publisher","DOI":"10.1145\/2666652.2666661"},{"key":"e_1_3_1_92_2","first-page":"81","volume-title":"Recent Advances in Intrusion Detection, 9th International Symposium, RAID 2006 (Lecture Notes in Computer Science)","author":"Newsome James","year":"2006","unstructured":"James Newsome, Brad Karp, and Dawn Xiaodong Song. 2006. Paragraph: Thwarting signature learning by training maliciously. In Recent Advances in Intrusion Detection, 9th International Symposium, RAID 2006 (Lecture Notes in Computer Science), Vol. 4219. Springer, 81\u2013105."},{"key":"e_1_3_1_93_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"e_1_3_1_94_2","doi-asserted-by":"crossref","first-page":"399","DOI":"10.1109\/EuroSP.2018.00035","volume-title":"2018 IEEE European Symposium on Security and Privacy (EuroS&P)","author":"Papernot Nicolas","year":"2018","unstructured":"Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael P. Wellman. 2018. SoK: Security and privacy in machine learning. In 2018 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 399\u2013414."},{"key":"e_1_3_1_95_2","article-title":"Practical black-box attacks against deep learning systems using adversarial examples","volume":"1602","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick D. McDaniel, Ian J. Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2016. Practical black-box attacks against deep learning systems using adversarial examples. CoRR abs\/1602.02697 (2016).","journal-title":"CoRR"},{"key":"e_1_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.1145\/3055004.3055006"},{"key":"e_1_3_1_97_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485259"},{"key":"e_1_3_1_98_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.240"},{"key":"e_1_3_1_99_2","article-title":"Detection of adversarial training examples in poisoning attacks through anomaly detection","author":"Paudice Andrea","year":"2018","unstructured":"Andrea Paudice, Luis Mu\u00f1oz-Gonz\u00e1lez, Andras Gyorgy, and Emil C. Lupu. 2018. Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv preprint arXiv:1802.03041 (2018).","journal-title":"arXiv preprint arXiv:1802.03041"},{"key":"e_1_3_1_100_2","first-page":"5","volume-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","author":"Paudice Andrea","year":"2018","unstructured":"Andrea Paudice, Luis Mu\u00f1oz-Gonz\u00e1lez, and Emil C. Lupu. 2018. Label sanitization against label flipping poisoning attacks. In Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 5\u201315."},{"key":"e_1_3_1_101_2","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_1_102_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66415-2_4"},{"key":"e_1_3_1_103_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2019.100199"},{"key":"e_1_3_1_104_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"e_1_3_1_105_2","first-page":"8230","volume-title":"International Conference on Machine Learning","author":"Rosenfeld Elan","year":"2020","unstructured":"Elan Rosenfeld, Ezra Winston, Pradeep Ravikumar, and Zico Kolter. 2020. Certified robustness to label-flipping attacks via randomized smoothing. In International Conference on Machine Learning. PMLR, 8230\u20138241."},{"key":"e_1_3_1_106_2","article-title":"BrainTorrent: A peer-to-peer environment for decentralized federated learning","author":"Roy Abhijit Guha","year":"2019","unstructured":"Abhijit Guha Roy, Shayan Siddiqui, Sebastian P\u00f6lsterl, Nassir Navab, and Christian Wachinger. 2019. BrainTorrent: A peer-to-peer environment for decentralized federated learning. arXiv preprint arXiv:1905.06731 (2019).","journal-title":"arXiv preprint arXiv:1905.06731"},{"key":"e_1_3_1_107_2","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644895"},{"key":"e_1_3_1_108_2","doi-asserted-by":"publisher","DOI":"10.1038\/323533a0"},{"key":"e_1_3_1_109_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_1_110_2","volume-title":"26th Annual Network and Distributed System Security Symposium, NDSS 2019","author":"Salem Ahmed","year":"2019","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2019. ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models. In 26th Annual Network and Distributed System Security Symposium, NDSS 2019. The Internet Society."},{"key":"e_1_3_1_111_2","doi-asserted-by":"publisher","DOI":"10.1147\/rd.33.0210"},{"key":"e_1_3_1_112_2","first-page":"6106","volume-title":"Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018","author":"Shafahi Ali","year":"2018","unstructured":"Ali Shafahi, W. Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018. Poison frogs! Targeted clean-label poisoning attacks on neural networks. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018. 6106\u20136116."},{"key":"e_1_3_1_113_2","article-title":"Biscotti: A ledger for private and secure peer-to-peer machine learning","author":"Shayan Muhammad","year":"2018","unstructured":"Muhammad Shayan, Clement Fung, Chris J. M. Yoon, and Ivan Beschastnikh. 2018. Biscotti: A ledger for private and secure peer-to-peer machine learning. arXiv preprint arXiv:1811.09904 (2018).","journal-title":"arXiv preprint arXiv:1811.09904"},{"key":"e_1_3_1_114_2","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991125"},{"key":"e_1_3_1_115_2","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1109\/SP.2017.41","volume-title":"2017 IEEE Symposium on Security and Privacy, SP 2017","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In 2017 IEEE Symposium on Security and Privacy, SP 2017. IEEE Computer Society, 3\u201318."},{"key":"e_1_3_1_116_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2006.231"},{"key":"e_1_3_1_117_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.344"},{"key":"e_1_3_1_118_2","first-page":"3517","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Steinhardt Jacob","year":"2017","unstructured":"Jacob Steinhardt, Pang Wei Koh, and Percy Liang. 2017. Certified defenses for data poisoning attacks. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017. 3517\u20133529."},{"key":"e_1_3_1_119_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04274-4_91"},{"key":"e_1_3_1_120_2","first-page":"1299","volume-title":"27th USENIX Security Symposium, USENIX Security 2018","author":"Suciu Octavian","year":"2018","unstructured":"Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daum\u00e9 III, and Tudor Dumitras. 2018. When does machine learning FAIL? Generalized transferability for evasion and poisoning attacks. In 27th USENIX Security Symposium, USENIX Security 2018. USENIX Association, 1299\u20131316."},{"key":"e_1_3_1_121_2","first-page":"10000","volume-title":"Proceedings of the 38th International Conference on Machine Learning, ICML 2021 (Proceedings of Machine Learning Research)","volume":"139","author":"Suya Fnu","year":"2021","unstructured":"Fnu Suya, Saeed Mahloujifar, Anshuman Suri, David Evans, and Yuan Tian. 2021. Model-targeted poisoning attacks with provable convergence. In Proceedings of the 38th International Conference on Machine Learning, ICML 2021 (Proceedings of Machine Learning Research), Vol. 139. PMLR, 10000\u201310010."},{"key":"e_1_3_1_122_2","volume-title":"2nd International Conference on Learning Representations, ICLR 2014","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In 2nd International Conference on Learning Representations, ICLR 2014."},{"key":"e_1_3_1_123_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-020-04831-9"},{"key":"e_1_3_1_124_2","first-page":"480","volume-title":"Computer Security - ESORICS 2020-25th European Symposium on Research in Computer Security, ESORICS 2020 (Lecture Notes in Computer Science)","author":"Tolpegin Vale","year":"2020","unstructured":"Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu. 2020. Data poisoning attacks against federated learning systems. In Computer Security - ESORICS 2020-25th European Symposium on Research in Computer Security, ESORICS 2020 (Lecture Notes in Computer Science), Vol. 12308. Springer, 480\u2013501."},{"key":"e_1_3_1_125_2","first-page":"8011","volume-title":"Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018","author":"Tran Brandon","year":"2018","unstructured":"Brandon Tran, Jerry Li, and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, NeurIPS 2018. 8011\u20138021."},{"key":"e_1_3_1_126_2","article-title":"Demystifying membership inference attacks in machine learning as a service","author":"Truex Stacey","year":"2019","unstructured":"Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Lei Yu, and Wenqi Wei. 2019. Demystifying membership inference attacks in machine learning as a service. IEEE Transactions on Services Computing (2019).","journal-title":"IEEE Transactions on Services Computing"},{"key":"e_1_3_1_127_2","doi-asserted-by":"crossref","first-page":"707","DOI":"10.1109\/SP.2019.00031","volume-title":"2019 IEEE Symposium on Security and Privacy, SP 2019","author":"Wang Bolun","year":"2019","unstructured":"Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao. 2019. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In 2019 IEEE Symposium on Security and Privacy, SP 2019. IEEE, 707\u2013723."},{"key":"e_1_3_1_128_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_14"},{"key":"e_1_3_1_129_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2020.2987064"},{"key":"e_1_3_1_130_2","first-page":"1","volume-title":"29th IEEE\/ACM International Symposium on Quality of Service, IWQOS 2021","author":"Xi Binhan","year":"2021","unstructured":"Binhan Xi, Shaofeng Li, Jiachun Li, Hui Liu, Hong Liu, and Haojin Zhu. 2021. BatFL: Backdoor detection on federated learning in e-Health. In 29th IEEE\/ACM International Symposium on Quality of Service, IWQOS 2021. IEEE, 1\u201310."},{"key":"e_1_3_1_131_2","doi-asserted-by":"publisher","DOI":"10.1145\/3437963.3441829"},{"key":"e_1_3_1_132_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9054581"},{"key":"e_1_3_1_133_2","first-page":"1689","volume-title":"Proceedings of the 32nd International Conference on Machine Learning, ICML 2015 (JMLR Workshop and Conference Proceedings)","volume":"37","author":"Xiao Huang","year":"2015","unstructured":"Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli. 2015. Is feature selection secure against training data poisoning? In Proceedings of the 32nd International Conference on Machine Learning, ICML 2015 (JMLR Workshop and Conference Proceedings), Vol. 37. JMLR.org, 1689\u20131698."},{"key":"e_1_3_1_134_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2014.08.081"},{"key":"e_1_3_1_135_2","first-page":"870","volume-title":"ECAI 2012-20th European Conference on Artificial Intelligence. Including Prestigious Applications of Artificial Intelligence (PAIS-2012) System Demonstrations Track (Frontiers in Artificial Intelligence and Applications)","volume":"242","author":"Xiao Han","year":"2012","unstructured":"Han Xiao, Huang Xiao, and Claudia Eckert. 2012. Adversarial label flips attack on support vector machines. In ECAI 2012-20th European Conference on Artificial Intelligence. Including Prestigious Applications of Artificial Intelligence (PAIS-2012) System Demonstrations Track (Frontiers in Artificial Intelligence and Applications), Vol. 242. IOS Press, 870\u2013875."},{"key":"e_1_3_1_136_2","first-page":"2691","volume-title":"IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2015","author":"Xiao Tong","year":"2015","unstructured":"Tong Xiao, Tian Xia, Yi Yang, Chang Huang, and Xiaogang Wang. 2015. Learning from massive noisy labeled data for image classification. In IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2015. IEEE Computer Society, 2691\u20132699."},{"key":"e_1_3_1_137_2","volume-title":"8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26\u201330, 2020","author":"Xie Chulin","year":"2020","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2020. DBA: Distributed backdoor attacks against federated learning. In 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26\u201330, 2020. OpenReview.net."},{"key":"e_1_3_1_138_2","first-page":"261","volume-title":"Proceedings of the Thirty-Fifth Conference on Uncertainty in Artificial Intelligence, UAI 2019 (Proceedings of Machine Learning Research)","volume":"115","author":"Xie Cong","year":"2019","unstructured":"Cong Xie, Oluwasanmi Koyejo, and Indranil Gupta. 2019. Fall of empires: Breaking Byzantine-tolerant SGD by inner product manipulation. In Proceedings of the Thirty-Fifth Conference on Uncertainty in Artificial Intelligence, UAI 2019 (Proceedings of Machine Learning Research), Vol. 115. AUAI Press, 261\u2013270."},{"key":"e_1_3_1_139_2","first-page":"671","volume-title":"Proceedings of the 22nd USENIX Security Symposium","author":"Xing Xinyu","year":"2013","unstructured":"Xinyu Xing, Wei Meng, Dan Doozan, Alex C. Snoeren, Nick Feamster, and Wenke Lee. 2013. Take this personally: Pollution attacks on personalized services. In Proceedings of the 22nd USENIX Security Symposium. USENIX Association, 671\u2013686."},{"key":"e_1_3_1_140_2","volume-title":"7th International Conference on Learning Representations, ICLR 2019","author":"Xu Keyulu","year":"2019","unstructured":"Keyulu Xu, Weihua Hu, Jure Leskovec, and Stefanie Jegelka. 2019. How powerful are graph neural networks?. In 7th International Conference on Learning Representations, ICLR 2019. OpenReview.net."},{"key":"e_1_3_1_141_2","first-page":"6222","volume-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019","author":"Xu Yilun","year":"2019","unstructured":"Yilun Xu, Peng Cao, Yuqing Kong, and Yizhou Wang. 2019. L_DMI: A novel information-theoretic loss function for training deep nets robust to label noise. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019. 6222\u20136233."},{"key":"e_1_3_1_142_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i12.17263"},{"key":"e_1_3_1_143_2","article-title":"Generative poisoning attack method against neural networks","volume":"1703","author":"Yang Chaofei","year":"2017","unstructured":"Chaofei Yang, Qing Wu, Hai Li, and Yiran Chen. 2017. Generative poisoning attack method against neural networks. CoRR abs\/1703.01340 (2017).","journal-title":"CoRR"},{"key":"e_1_3_1_144_2","volume-title":"24th Annual Network and Distributed System Security Symposium, NDSS 2017","author":"Yang Guolei","year":"2017","unstructured":"Guolei Yang, Neil Zhenqiang Gong, and Ying Cai. 2017. Fake co-visitation injection attacks to recommender systems. In 24th Annual Network and Distributed System Security Symposium, NDSS 2017. The Internet Society."},{"key":"e_1_3_1_145_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_3_1_146_2","volume-title":"Proceedings of the 29th International Conference on Machine Learning, ICML 2012","author":"Yang Tianbao","year":"2012","unstructured":"Tianbao Yang, Mehrdad Mahdavi, Rong Jin, Lijun Zhang, and Yang Zhou. 2012. Multiple kernel learning from noisy labels by stochastic programming. In Proceedings of the 29th International Conference on Machine Learning, ICML 2012. icml.cc\/Omnipress."},{"key":"e_1_3_1_147_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"e_1_3_1_148_2","first-page":"5636","volume-title":"Proceedings of the 35th International Conference on Machine Learning, ICML 2018 (Proceedings of Machine Learning Research)","volume":"80","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Kannan Ramchandran, and Peter L. Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In Proceedings of the 35th International Conference on Machine Learning, ICML 2018 (Proceedings of Machine Learning Research), Vol. 80. PMLR, 5636\u20135645."},{"key":"e_1_3_1_149_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460427"},{"key":"e_1_3_1_150_2","doi-asserted-by":"publisher","DOI":"10.1109\/TMI.2019.2922960"},{"key":"e_1_3_1_151_2","volume-title":"5th International Conference on Learning Representations, ICLR 2017","author":"Zhang Chiyuan","year":"2017","unstructured":"Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals. 2017. Understanding deep learning requires rethinking generalization. In 5th International Conference on Learning Representations, ICLR 2017. OpenReview.net."},{"key":"e_1_3_1_152_2","doi-asserted-by":"publisher","DOI":"10.1145\/3446776"},{"key":"e_1_3_1_153_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3023126"},{"key":"e_1_3_1_154_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM50108.2020.00088"},{"key":"e_1_3_1_155_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"e_1_3_1_156_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2986205"},{"key":"e_1_3_1_157_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/551"},{"key":"e_1_3_1_158_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2019.2960824"},{"key":"e_1_3_1_159_2","first-page":"595","volume-title":"International Conference on Algorithms and Architectures for Parallel Processing","author":"Zhao Ying","year":"2019","unstructured":"Ying Zhao, Junjun Chen, Jiale Zhang, Di Wu, Jian Teng, and Shui Yu. 2019. PDGAN: A novel poisoning defense method in federated learning using generative adversarial network. In International Conference on Algorithms and Architectures for Parallel Processing. Springer, 595\u2013609."},{"key":"e_1_3_1_160_2","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879193"},{"key":"e_1_3_1_161_2","first-page":"7614","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019 (Proceedings of Machine Learning Research)","volume":"97","author":"Zhu Chen","year":"2019","unstructured":"Chen Zhu, W. Ronny Huang, Hengduo Li, Gavin Taylor, Christoph Studer, and Tom Goldstein. 2019. Transferable clean-label poisoning attacks on deep neural nets. In Proceedings of the 36th International Conference on Machine Learning, ICML 2019 (Proceedings of Machine Learning Research), Vol. 97. PMLR, 7614\u20137623."},{"key":"e_1_3_1_162_2","first-page":"14747","volume-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019. 14747\u201314756."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551636","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3551636","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T15:00:26Z","timestamp":1750172426000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3551636"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,23]]},"references-count":161,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2023,8,31]]}},"alternative-id":["10.1145\/3551636"],"URL":"https:\/\/doi.org\/10.1145\/3551636","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,23]]},"assertion":[{"value":"2022-01-05","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-07-18","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}