Adversarial machine learning
Attacks on how models learn and decide: adversarial examples, evasion, data poisoning and backdoors in trained models.
- All items
- 108
- Last 90 days
- 47
- Change
- +114%vs 22 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 1 |
| Sep 2025 | 1 |
| Oct 2025 | 1 |
| Nov 2025 | 1 |
| Dec 2025 | 6 |
| Jan 2026 | 4 |
| Feb 2026 | 6 |
| Mar 2026 | 11 |
| Apr 2026 | 8 |
| May 2026 | 10 |
| Jun 2026 | 9 |
| Jul 2026 | 8 |
| Aug 2026 | 3 |
| Sep 2026 | 24 |
| Oct 2026 | 12 |
108 items
Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers
Dec 9, 2025InfoResearchPeer-reviewedSecurityResearchResearchers introduce the Visible, Semantic, Sample-specific, and Compatible (VSSC) trigger for backdoor attacks on deep neural networks. They present an automated pipeline that selects triggers with large language models, inserts them into images with generative models, and checks insertion quality with vision-language models. The authors report that VSSC stays effective under visual distortions and works in physical scenarios using corresponding real-world objects.
IEEE Xplore (Security & AI Journals)Investigating the Robustness of Fuzzy Deep Learning on Noisy Medical Images
Nov 24, 2025InfoResearchPeer-reviewedResearchSecurityThis research tests a deep neuro-fuzzy system (DNFS) for medical image classification under six noise types and adversarial attacks. The DNFS matched state-of-the-art models on original images across seven biomedical datasets and showed superior average accuracy on noisy data. It was also tested for susceptibility to adversarial perturbations, which the authors report exposes weaknesses in deep learning.
IEEE Xplore (Security & AI Journals)Action-Perturbation Backdoor Attacks on Partially Observable Multiagent Systems
Oct 13, 2025InfoResearchPeer-reviewedSecurityResearchResearchers study backdoor attacks on reinforcement learning agents in partially observable multiagent systems. Instead of modifying a victim's observations directly, an adversary agent uses its own actions to affect what other agents observe, and a trained trigger policy, guided by auxiliary rewards, lets it activate their backdoors with few actions. Experiments show the method triggers others' backdoors efficiently, and the authors also study defenses.
IEEE Xplore (Security & AI Journals)AI-Shielder: Exploiting Backdoors to Defend Against Adversarial Attacks
Sep 29, 2025InfoResearchPeer-reviewedSecurityResearchAI-Shielder is a defense that deliberately embeds backdoors in a DNN so that adversarial perturbations fail while the main task keeps working. Evaluated against sixteen adversarial example generation approaches, it reduces the attack success rate from 91.8% to 3.8%, outperforming state-of-the-art works by 37.2%, with a 0.6% decline in clean data accuracy and 1.43% overhead to model prediction time.
IEEE Xplore (Security & AI Journals)Certified Local Transferability for Evaluating Adversarial Attacks
Aug 27, 2025InfoResearchPeer-reviewedSecurityResearchResearchers introduce the certified local transferable region, a connected area of inputs where a single adversarial perturbation is mathematically guaranteed to fool a deep neural network. They propose reverse attack oracle-based search (RAOS) to estimate the maximum size of this region, using a minimal distance attack and state-of-the-art verifiers at each step. The region's size serves as a metric for the local transferability of perturbations across model structures and adversarial training scenarios.
IEEE Xplore (Security & AI Journals)CVE-2024-5185: EmbedAI data poisoning through CSRF via malicious webpage
May 29, 2024HighVulnerabilitySecurityCVE-2024-5185CVE-2024-5185 affects the EmbedAI application, which is susceptible to security issues enabling Data Poisoning attacks. The flaw stems from a CSRF vulnerability, enabled by the absence of secure session management and weak CORS policies. An attacker who lures a user to a malicious webpage can trick that user into uploading and integrating incorrect data into the application's language model.
NVD/CVE DatabaseUsing Microsoft Counterfit to create adversarial examples for Husky AI
Aug 16, 2021InfoNewsSecurityResearchThe author evaluates Microsoft Counterfit, a command-line tool for testing machine learning models and endpoints against adversarial attacks. Counterfit hosts attack modules from the Adversarial Robustness Toolbox and TextAttacks, and it can be extended with new attacks and targets. The author builds a custom Husky AI target that loads a Keras model and sample images, with the goal of turning Shadowbunny into a husky through adversarial examples.
Embrace The RedMachine Learning Attack Series: Adversarial Robustness Toolbox Basics
Oct 22, 2020InfoNewsSecurityResearchJohann Rehberger (wunderwuzzi23) demonstrates the Adversarial Robustness Toolbox (ART), originally created by IBM and moved to the Linux AI Foundation in July 2020, to generate adversarial examples against his Husky AI binary image classifier. Using ART's FastGradientMethod with targeted=True and eps=0.04, he perturbs an image of a plush bunny so the model's prediction shifts from about 0.002 to 66% husky. The post presents this as an easier alternative to his earlier manual perturbation attacks.
Embrace The Red
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.