4 papers
COLLIDER: A Robust Training Framework for Backdoor Data
Hadi M. Dolatabadi, Sarah Erfani, Christopher Leckie
Deep neural network (DNN) classifiers are vulnerable to backdoor attacks. An adversary poisons some of the training data in such attacks by installing a trigger. The goal is to mak…
Black-box Adversarial Example Generation with Normalizing Flows
Hadi M. Dolatabadi, Sarah Erfani, Christopher Leckie
Deep neural network classifiers suffer from adversarial vulnerability: well-crafted, unnoticeable changes to the input data can affect the classifier decision. In this regard, the…
AdvFlow: Inconspicuous Black-box Adversarial Attacks using Normalizing Flows
Hadi M. Dolatabadi, Sarah Erfani, Christopher Leckie
Deep learning classifiers are susceptible to well-crafted, imperceptible variations of their inputs, known as adversarial attacks. In this regard, the study of powerful attack mode…
Invertible Generative Modeling using Linear Rational Splines
Hadi M. Dolatabadi, Sarah Erfani, Christopher Leckie
Normalizing flows attempt to model an arbitrary probability distribution through a set of invertible mappings. These transformations are required to achieve a tractable Jacobian de…