BagFlip: A Certified Defense against Data Poisoning

Neural Information Processing Systems 

Consider the malware detection setting.