1. Bullseye polytope: a scalable clean-label poisoning attack with improved transferability;Aghakhani,2021
2. Influence functions in deep learning are fragile;Basu,2020
3. Support vector machines under adversarial label noise;Biggio,2011
4. Poisoning attacks against support vector machines;Biggio,2012
5. Salient feature extractor for adversarial defense on deep neural networks;Chen;Inf. Sci.,2022