Excess Capacity and Backdoor Poisoning

Neural Information Processing Systems 

From a computational standpoint, we show that under certain assumptions, adversarial training can detect the presence of backdoors in a training set.