← Search

David J. Miller

9 accepted papers

2023

Training Set Cleansing of Backdoor Poisoning by Self-Supervised Representation Learning

ICASSP 2023accepted

A backdoor or Trojan attack is an important type of data poisoning attack against deep neural network (DNN) classifiers, wherein the training dataset is poisoned with a small number of samples that each possess the backdoor pattern (usually a pattern that is either imperceptible or innocuous) and wh…

Cited by 0SourceScholar
2022

Detecting Backdoor Attacks against Point Cloud Classifiers

ICASSP 2022accepted

Backdoor attacks (BA) are an emerging threat to deep neural network classifiers. A classifier being attacked will predict to the attacker’s target class when a test sample from a source class is embedded with the backdoor pattern (BP). Recently, the first BA against point cloud (PC) classifiers was…

Cited by 0SourceScholar
2022

Test-Time Detection of Backdoor Triggers for Poisoned Deep Neural Networks

ICASSP 2022accepted

Backdoor (Trojan) attacks are emerging threats against deep neural networks (DNN). A DNN being attacked will predict to an attacker-desired target class whenever a test sample from any source class is embedded with a backdoor pattern, while correctly classifying clean (attack-free) test samples. Exi…

Cited by 0SourceScholar
2021

A Backdoor Attack Against 3D Point Cloud Classifiers

ICCV 2021poster

Vulnerability of 3D point cloud (PC) classifiers has become a grave concern due to the popularity of 3D sensors in safety-critical applications. Existing adversarial attacks against 3D PC classifiers are all test-time evasion (TTE) attacks that aim to induce test-time misclassifications using knowle…

Cited by 94PDFcodeScholar
2021

L-Red: Efficient Post-Training Detection of Imperceptible Backdoor Attacks Without Access to the Training Set

ICASSP 2021accepted

Backdoor attacks (BAs) are an emerging form of adversarial attack typically against deep neural network image classifiers. The attacker aims to have the classifier learn to classify to a target class when test images from one or more source classes contain a backdoor pattern, while maintaining high…

Cited by 0SourceScholar
2020

Revealing Backdoors, Post-Training, in DNN Classifiers via Novel Inference on Optimized Perturbations Inducing Group Misclassification

ICASSP 2020accepted

Recently, a special type of data poisoning (DP) attack against deep neural network (DNN) classifiers, known as a backdoor, was proposed. These attacks do not seek to degrade classification accuracy, but rather to have the classifier learn to classify to a target class whenever the backdoor pattern i…

Cited by 0SourceScholar
2019

When Not to Classify: Detection of Reverse Engineering Attacks on DNN Image Classifiers

ICASSP 2019accepted

This paper addresses detection of a reverse engineering (RE) attack targeting a deep neural network (DNN) image classifier; by querying, RE's aim is to discover the classifier's decision rule. RE can enable test-time evasion attacks, which require knowledge of the classifier. Recently, we proposed a…

Cited by 0SourceScholar
2016

Graphical Time Warping for Joint Alignment of Multiple Curves

NeurIPS 2016poster

Dynamic time warping (DTW) is a fundamental technique in time series analysis for comparing one curve to another using a flexible time-warping function. However, it was designed to compare a single pair of curves. In many applications, such as in metabolomics and image series analysis, alignment is…

Cited by 16SourcePDFScholar