Poison Frogs! Targeted Clean-Label Poisoning Attacks on Neural Networks, Ali Shafahi, W. Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, Tom Goldstein, 2018Advances in Neural Information Processing Systems (NeurIPS), Vol. 31 (Curran Associates, Inc.) - 提出一种干净标签投毒攻击方法,使被投毒数据难以区分。
Deep Learning with Differential Privacy, Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, Li Zhang, 2016Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (Association for Computing Machinery)DOI: 10.1145/2976749.2978318 - 将差分隐私应用于深度学习的开创性论文,对数据投毒具有一定鲁棒性。