{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T15:21:22Z","timestamp":1787066482930,"version":"build-2736575974"},"publisher-location":"Cham","reference-count":31,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_41","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T18:03:15Z","timestamp":1710180195000},"page":"700-718","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Backdoor Attacks Leveraging Latent Representation in\u00a0Competitive Learning"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0749-3613","authenticated-orcid":false,"given":"Kazuki","family":"Iwahana","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0817-6188","authenticated-orcid":false,"given":"Naoto","family":"Yanai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Toru","family":"Fujiwara","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"41_CR1","unstructured":"Chen, B., et al.: Detecting backdoor attacks on deep neural networks by activation clustering. In: Proceedings of SafeAI 2019 (2019)"},{"key":"41_CR2","unstructured":"Doan, K., Lao, Y., Li, P.: Backdoor attack with imperceptible input and latent modification. In: Proceedings of NeurIPS 2021. vol.\u00a034, pp. 18944\u201318957. Curran Associates, Inc. (2021). https:\/\/proceedings.neurips.cc\/paper\/2021\/file\/9d99197e2ebf03fc388d09f1e94af89b-Paper.pdf"},{"key":"41_CR3","doi-asserted-by":"crossref","unstructured":"Gao, Y., Xu, C., Wang, D., Chen, S., Ranasinghe, D.C., Nepal, S.: Strip: A defence against trojan attacks on deep neural networks. In: Proceedings of ACSAC 2019, pp. 113\u2013125. ACM (2019)","DOI":"10.1145\/3359789.3359790"},{"key":"41_CR4","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: BadNets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019)","journal-title":"IEEE Access"},{"issue":"346","key":"41_CR5","doi-asserted-by":"publisher","first-page":"383","DOI":"10.1080\/01621459.1974.10482962","volume":"69","author":"FR Hampel","year":"1974","unstructured":"Hampel, F.R.: The influence curve and its role in robust estimation. J. Am. Stat. Assoc. 69(346), 383\u2013393 (1974)","journal-title":"J. Am. Stat. Assoc."},{"key":"41_CR6","doi-asserted-by":"crossref","unstructured":"He, C., Xue, M., Wang, J., Liu, W.: Embedding backdoors as the facial features: Invisible backdoor attacks against face recognition systems. In: Proceedings of TURC 2020, pp. 231\u2013235. ACM (2020)","DOI":"10.1145\/3393527.3393567"},{"key":"41_CR7","doi-asserted-by":"crossref","unstructured":"Jebreel, N.M., Li, Y., Domingo-Ferrer, J., Xia, S.T.: Detecting backdoor attacks via layer-wise feature analysis (2023). https:\/\/openreview.net\/forum?id=gncu27b4elL","DOI":"10.1007\/978-3-031-33377-4_33"},{"key":"41_CR8","doi-asserted-by":"crossref","unstructured":"Ji, Y., Zhang, X., Ji, S., Luo, X., Wang, T.: Model-reuse attacks on deep learning systems. In: Proceedings of CCS 2018, pp. 349\u2013363. ACM (2018)","DOI":"10.1145\/3243734.3243757"},{"key":"41_CR9","doi-asserted-by":"crossref","unstructured":"Li, S., et al.: Hidden backdoors in human-centric language models. In: Proceedings of CCS 2021, pp. 3123\u20133140. ACM (2021)","DOI":"10.1145\/3460120.3484576"},{"issue":"5","key":"41_CR10","first-page":"2088","volume":"18","author":"S Li","year":"2021","unstructured":"Li, S., Xue, M., Zhao, B.Z.H., Zhu, H., Zhang, X.: Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Trans. Dependable Secure Comput. 18(5), 2088\u20132105 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"41_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"K Liu","year":"2018","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: defending against backdooring attacks on deep neural networks. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) RAID 2018. LNCS, vol. 11050, pp. 273\u2013294. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13"},{"key":"41_CR12","doi-asserted-by":"crossref","unstructured":"Liu, Z., Li, F., Li, Z., Luo, B.: LoneNeuron: a highly-effective feature-domain neural trojan using invisible and polymorphic watermarks. In: Proceedings of CCS 2022, pp. 2129\u20132143. ACM (2022)","DOI":"10.1145\/3548606.3560678"},{"issue":"20","key":"41_CR13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.3390\/app11209556","volume":"11","author":"Y Matsuo","year":"2021","unstructured":"Matsuo, Y., Takemoto, K.: Backdoor attacks to deep neural network-based system for COVID-19 detection from chest X-ray images. Appl. Sci. 11(20), 1\u201310 (2021)","journal-title":"Appl. Sci."},{"key":"41_CR14","unstructured":"Nguyen, T.A., Tran, A.: Input-aware dynamic backdoor attack. In: Proceedings of NeurIPS 2020. vol.\u00a033, pp. 3454\u20133464. Curran Associates, Inc. (2020). https:\/\/proceedings.neurips.cc\/paper\/2020\/file\/234e691320c0ad5b45ee3c96d0d7b8f8-Paper.pdf"},{"key":"41_CR15","doi-asserted-by":"crossref","unstructured":"Ning, R., Li, J., Xin, C., Wu, H.: Invisible poison: A blackbox clean label backdoor attack to deep neural networks. In: Proceeding of INFOCOM 2021, pp. 1\u201310. IEEE (2021)","DOI":"10.1109\/INFOCOM42981.2021.9488902"},{"key":"41_CR16","unstructured":"Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J.P., Goldstein, T.: Just how toxic is data poisoning? A unified benchmark for backdoor and data poisoning attacks. CoRR abs\/2006.12557 (2020). https:\/\/arxiv.org\/abs\/2006.12557"},{"key":"41_CR17","unstructured":"Sun, W., et al.: Invisible backdoor attack with dynamic triggers against person re-identification. CoRR abs\/2211.10933 (2022). https:\/\/doi.org\/10.48550\/arXiv.2211.10933"},{"key":"41_CR18","doi-asserted-by":"crossref","unstructured":"Tan, T.J.L., Shokri, R.: Bypassing backdoor detection algorithms in deep learning. In: Proceedings of EuroS &P 2020, pp. 175\u2013183. IEEE (2020)","DOI":"10.1109\/EuroSP48549.2020.00019"},{"key":"41_CR19","unstructured":"Tang, D., Wang, X., Tang, H., Zhang, K.: Demon in the variant: statistical analysis of DNNs for robust backdoor contamination detection. In: Proceedings of USENIX Security 2021, pp. 1541\u20131558. USENIX Association (2021)"},{"key":"41_CR20","doi-asserted-by":"crossref","unstructured":"Tian, Z., Cui, L., Liang, J., Yu, S.: A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Comput. Surv. 55(8), 1\u201335 (2022)","DOI":"10.1145\/3551636"},{"key":"41_CR21","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: IEEE S &P 2019, pp. 707\u2013723. IEEE (2019)","DOI":"10.1109\/SP.2019.00031"},{"issue":"3","key":"41_CR22","doi-asserted-by":"publisher","first-page":"1526","DOI":"10.1109\/TSC.2020.3000900","volume":"15","author":"S Wang","year":"2022","unstructured":"Wang, S., Nepal, S., Rudolph, C., Grobler, M., Chen, S., Chen, T.: Backdoor attacks against transfer learning with pre-trained deep learning models. IEEE Trans. Serv. Comput. 15(3), 1526\u20131539 (2022)","journal-title":"IEEE Trans. Serv. Comput."},{"key":"41_CR23","unstructured":"Wu, D., Wang, Y.: Adversarial neuron pruning purifies backdoored deep models. In: Proceeding of NeurIPS 2021. vol. 34, pp. 16913\u201316925. Curran Associates, Inc. (2021)"},{"issue":"3","key":"41_CR24","doi-asserted-by":"publisher","first-page":"1458","DOI":"10.1007\/s12083-020-01031-z","volume":"14","author":"M Xue","year":"2021","unstructured":"Xue, M., He, C., Wang, J., Liu, W.: Backdoors hidden in facial features: a novel invisible backdoor attack against face recognition systems. Peer-to-Peer Netw. Appl. 14(3), 1458\u20131474 (2021)","journal-title":"Peer-to-Peer Netw. Appl."},{"key":"41_CR25","doi-asserted-by":"crossref","unstructured":"Yao, Y., Li, H., Zheng, H., Zhao, B.Y.: Latent backdoor attacks on deep neural networks, pp. 2041\u20132055. Association for Computing Machinery (2019)","DOI":"10.1145\/3319535.3354209"},{"key":"41_CR26","unstructured":"Yosinski, J., Clune, J., Bengio, Y., Lipson, H.: How transferable are features in deep neural networks? In: Proceedings of NIPS 2014, pp. 3320\u20133328. MIT Press (2014)"},{"key":"41_CR27","unstructured":"Zeng, Y., Chen, S., Park, W., Mao, Z., Jin, M., Jia, R.: Adversarial unlearning of backdoors via implicit hypergradient. In: International Conference on Learning Representations (2022). https:\/\/openreview.net\/forum?id=MeeQkFYVbzW"},{"key":"41_CR28","doi-asserted-by":"publisher","first-page":"5691","DOI":"10.1109\/TIP.2022.3201472","volume":"31","author":"J Zhang","year":"2022","unstructured":"Zhang, J., et al.: Poison ink: robust and invisible backdoor attack. IEEE Trans. Image Process. 31, 5691\u20135705 (2022)","journal-title":"IEEE Trans. Image Process."},{"key":"41_CR29","doi-asserted-by":"crossref","unstructured":"Zhao, Z., Chen, X., Xuan, Y., Dong, Y., Wang, D., Liang, K.: DEFEAT: deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints. In: Proceedings of CVPR 2022, pp. 15213\u201315222 (2022)","DOI":"10.1109\/CVPR52688.2022.01478"},{"key":"41_CR30","doi-asserted-by":"crossref","unstructured":"Zhong, N., Qian, Z., Zhang, X.: Imperceptible backdoor attack: from input space to feature representation. In: Raedt, L.D. (ed.) Proceedings of IJCAI 2022, pp. 1736\u20131742. IJCAI Organization (2022)","DOI":"10.24963\/ijcai.2022\/242"},{"key":"41_CR31","doi-asserted-by":"crossref","unstructured":"Zhu, L., Ning, R., Wang, C., Xin, C., Wu, H.: GangSweep: sweep out neural backdoors by GAN. In: Proceedings of MM 2020, pp. 3173\u20133181. ACM (2020)","DOI":"10.1145\/3394171.3413546"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_41","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T18:08:33Z","timestamp":1710180513000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_41"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_41","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Our code is publicly available via GitHub (\n                      \n                      ).","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Code Availability"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}