Adversarial attacks are inference-time, backdoors are training time. This paper isn't the first to propose the idea of backdooring DNNs (I believe our paper [1], concurrently with a couple others [2,3], did that). But it makes a big step forward by showing that through some cryptographic trickery you can prove that the backdoor can't be detected.
[1] https://arxiv.org/abs/1708.06733
[2] https://www.ndss-symposium.org/wp-content/uploads/2018/02/nd...