activity
20192022
most citedAdversarial Examples Make Strong Poisons

33 citations · 71 across the 9 of their papers we have counts for

collaborators

15 papers

cs.LG20222 cited

K-SAM: Sharpness-Aware Minimization at the Speed of SGD

Renkun Ni, Ping-yeh Chiang, Jonas Geiping +3

Sharpness-Aware Minimization (SAM) has recently emerged as a robust technique for improving the accuracy of deep neural networks. However, SAM incurs a high computational cost in p…

cs.LG20226 cited

Thinking Two Moves Ahead: Anticipating Other Users Improves Backdoor Attacks in Federated Learning

Yuxin Wen, Jonas Geiping, Liam Fowl +4

Federated learning is particularly susceptible to model poisoning and backdoor attacks because individual users have direct control over the training data and model updates. At the…

cs.CV2022

A Simple Strategy to Provable Invariance via Orbit Mapping

Kanchana Vaishnavi Gandikota, Jonas Geiping, Zorah Lähner +2

Many applications require robustness, or ideally invariance, of neural networks to certain transformations of input data. Most commonly, this requirement is addressed by training d…

cs.LG20222 cited

Poisons that are learned faster are more effective

Pedro Sandoval-Segura, Vasu Singla, Liam Fowl +4

Imperceptible poisoning attacks on entire datasets have recently been touted as methods for protecting data privacy. However, among a number of defenses preventing the practical us…

cs.LG202133 cited

Adversarial Examples Make Strong Poisons

Liam Fowl, Micah Goldblum, Ping-yeh Chiang +3

The adversarial machine learning literature is largely partitioned into evasion attacks on testing data and poisoning attacks on training data. In this work, we show that adversari…

cs.CV2021

Training or Architecture? How to Incorporate Invariance in Neural Networks

Kanchana Vaishnavi Gandikota, Jonas Geiping, Zorah Lähner +2

Many applications require the robustness, or ideally the invariance, of a neural network to certain transformations of input data. Most commonly, this requirement is addressed by e…