31 citations · 47 across the 3 of their papers we have counts for
3 papers
cs.LG2021★ 1 cited
Excess Capacity and Backdoor Poisoning
Naren Sarayu Manoj, Avrim Blum
A backdoor data poisoning attack is an adversarial attack wherein the attacker injects several watermarked, mislabeled training examples into a training set. The watermark does not…
cs.LG2020★ 15 cited
Random Smoothing Might be Unable to Certify Robustness for High-Dimensional Images
Avrim Blum, Travis Dick, Naren Manoj +1
We show a hardness result for random smoothing to achieve certified adversarial robustness against attacks in the ball of radius when . Although random smoothing…
stat.ML2019★ 31 cited
Quantifying Perceptual Distortion of Adversarial Examples
Matt Jordan, Naren Manoj, Surbhi Goel +1
Recent work has shown that additive threat models, which only permit the addition of bounded noise to the pixels of an image, are insufficient for fully capturing the space of impe…