BagFlip: ACertifiedDefenseagainstDataPoisoning

Neural Information Processing Systems 

Effective attack approaches have been proposed for various domains such as imagerecognition[12],sentimentanalysis[25],andmalwaredetection[30].