13 citations · 17 across the 2 of their papers we have counts for
5 papers
Stealthy Backdoors as Compression Artifacts
Yulong Tian, Fnu Suya, Fengyuan Xu +1
In a backdoor attack on a machine learning model, an adversary produces a model that performs well on normal inputs but outputs targeted misclassifications on inputs containing a s…
Model-Targeted Poisoning Attacks with Provable Convergence
Fnu Suya, Saeed Mahloujifar, Anshuman Suri +2
In a poisoning attack, an adversary with control over a small fraction of the training data attempts to select that data in a way that induces a corrupted model that misbehaves in…
Scalable Attack on Graph Data by Injecting Vicious Nodes
Jihong Wang, Minnan Luo, Fnu Suya +3
Recent studies have shown that graph convolution networks (GCNs) are vulnerable to carefully designed attacks, which aim to cause misclassification of a specific node on the graph…
Hybrid Batch Attacks: Finding Black-box Adversarial Examples with Limited Queries
Fnu Suya, Jianfeng Chi, David Evans +1
We study adversarial examples in a black-box setting where the adversary only has API access to the target model and each query is expensive. Prior work on black-box adversarial ex…
Query-limited Black-box Attacks to Classifiers
Fnu Suya, Yuan Tian, David Evans +1
We study black-box attacks on machine learning classifiers where each query to the model incurs some cost or risk of detection to the adversary. We focus explicitly on minimizing t…