{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T23:24:11Z","timestamp":1781306651510,"version":"3.54.1"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031708787","type":"print"},{"value":"9783031708794","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-70879-4_5","type":"book-chapter","created":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T19:02:20Z","timestamp":1725476540000},"page":"85-104","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Have You Poisoned My Data? Defending Neural Networks Against Data Poisoning"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9718-1044","authenticated-orcid":false,"given":"Fabio","family":"De Gaspari","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5686-3831","authenticated-orcid":false,"given":"Dorjan","family":"Hitaj","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4859-2191","authenticated-orcid":false,"given":"Luigi V.","family":"Mancini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,9,5]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"Aghakhani, H., Meng, D., Wang, Y.X., Kruegel, C., Vigna, G.: Bullseye polytope: a scalable clean-label poisoning attack with improved transferability. In: IEEE European Symposium on Security and Privacy, EuroS &P, pp. 159\u2013178 (2021)","DOI":"10.1109\/EuroSP51992.2021.00021"},{"key":"5_CR2","doi-asserted-by":"crossref","unstructured":"Borgnia, E., et al.: Strong data augmentation sanitizes poisoning and backdoor attacks without an accuracy tradeoff. In: IEEE International Conference on Acoustics, Speech and Signal Processing. ICASSP, pp. 3855\u20133859 (2021)","DOI":"10.1109\/ICASSP39728.2021.9414862"},{"key":"5_CR3","unstructured":"Chen, B., et al.: Detecting backdoor attacks on deep neural networks by activation clustering. In: AAAI\u2019s Workshop on Artificial Intelligence Safety. SafeAI (2018)"},{"issue":"13s","key":"5_CR4","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3585385","volume":"55","author":"AE Cin\u00e0","year":"2023","unstructured":"Cin\u00e0, A.E., et al.: Wild patterns reloaded: a survey of machine learning security against training data poisoning. ACM Comput. Surv. 55(13s), 1\u201339 (2023)","journal-title":"ACM Comput. Surv."},{"key":"5_CR5","unstructured":"Darlow, L.N., Crowley, E.J., Antoniou, A., Storkey, A.J.: CINIC-10 is not imagenet or CIFAR-10. arXiv preprint arXiv:1810.03505 (2018)"},{"issue":"14","key":"5_CR6","doi-asserted-by":"publisher","first-page":"12077","DOI":"10.1007\/s00521-022-07096-6","volume":"34","author":"F De Gaspari","year":"2022","unstructured":"De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., Mancini, L.V.: Evading behavioral classifiers: a comprehensive analysis on evading ransomware detection techniques. Neural Comput. Appl. 34(14), 12077\u201312096 (2022)","journal-title":"Neural Comput. Appl."},{"issue":"22","key":"5_CR7","doi-asserted-by":"publisher","first-page":"20379","DOI":"10.1007\/s00521-022-07586-7","volume":"34","author":"F De Gaspari","year":"2022","unstructured":"De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., Mancini, L.V.: Reliable detection of compressed and encrypted data. Neural Comput. Appl. 34(22), 20379\u201320393 (2022)","journal-title":"Neural Comput. Appl."},{"key":"5_CR8","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: ImageNet: a large-scale hierarchical image database. In: IEEE Conference on Computer Vision and Pattern Recognition, CVPR, pp. 248\u2013255 (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"5_CR9","unstructured":"Fowl, L., Geiping, J., Somepalli, G., Goldstein, T., Taylor, G.: Industrial scale data poisoning (2023). https:\/\/github.com\/JonasGeiping\/data-poisoning"},{"key":"5_CR10","unstructured":"Geiping, J., Fowl, L., Somepalli, G., Goldblum, M., Moeller, M., Goldstein, T.: What doesn\u2019t kill you makes you robust (ER): how to adversarially train against data poisoning. In: ICLR Workshop on Security and Safety in Machine Learning Systems (2021)"},{"key":"5_CR11","unstructured":"Geiping, J., et al.: Witches\u2019 brew: industrial scale data poisoning via gradient matching. In: International Conference on Learning Representations. ICLR (2020)"},{"key":"5_CR12","unstructured":"Hitaj, D., et al.: Do you trust your model? Emerging malware threats in the deep learning ecosystem. arXiv preprint arXiv:2403.03593 (2024)"},{"key":"5_CR13","doi-asserted-by":"crossref","unstructured":"Hitaj, D., Pagnotta, G., Hitaj, B., Mancini, L.V., Perez-Cruz, F.: MaleficNet: hiding malware into deep neural networks using spread-spectrum channel coding. In: European Symposium on Research in Computer Security, ESORIC, pp. 425\u2013444S (2022)","DOI":"10.1007\/978-3-031-17143-7_21"},{"key":"5_CR14","doi-asserted-by":"publisher","first-page":"1695","DOI":"10.1109\/TDSC.2023.3288215","volume":"21","author":"D Hitaj","year":"2023","unstructured":"Hitaj, D., Pagnotta, G., Hitaj, B., Perez-Cruz, F., Mancini, L.V.: FedComm: federated learning as a medium for covert communication. IEEE Trans. Depend. Secure Comput. 21, 1695\u20131707 (2023)","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"5_CR15","unstructured":"Hong, S., Chandrasekaran, V., Kaya, Y., Dumitra\u015f, T., Papernot, N.: On the effectiveness of mitigating data poisoning attacks with gradient shaping. arXiv preprint arXiv:2002.11497 (2020)"},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"Koh, P.W., Steinhardt, J., Liang, P.: Stronger data poisoning attacks break data sanitization defenses. Mach. Learning, 1\u201347 (2022)","DOI":"10.1007\/s10994-021-06119-y"},{"key":"5_CR17","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"key":"5_CR18","unstructured":"Levine, A., Feizi, S.: Deep partition aggregation: provable defenses against general poisoning attacks. In: International Conference on Learning Representations. ICLR (2020)"},{"key":"5_CR19","first-page":"14900","volume":"34","author":"Y Li","year":"2021","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Anti-backdoor learning: training clean models on poisoned data. Adv. Neural. Inf. Process. Syst. 34, 14900\u201314912 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"5_CR20","doi-asserted-by":"crossref","unstructured":"Liu, Y., et al.: Trojaning attack on neural networks. In: 25th Annual Network And Distributed System Security Symposium, NDSS (2018)","DOI":"10.14722\/ndss.2018.23291"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Ma, Y., Zhu, X., Hsu, J.: Data poisoning against differentially-private learners: attacks and defenses. In: Proceedings of the 28th International Joint Conference on Artificial Intelligence, pp. 4732\u20134738. AAAI (2019)","DOI":"10.24963\/ijcai.2019\/657"},{"key":"5_CR22","unstructured":"Meta: Code llama (2023). https:\/\/github.com\/facebookresearch\/llama"},{"key":"5_CR23","unstructured":"Meta: Llama 2 (2023). https:\/\/github.com\/facebookresearch\/llama"},{"issue":"3","key":"5_CR24","doi-asserted-by":"publisher","first-page":"402","DOI":"10.1109\/JPROC.2020.2970615","volume":"108","author":"DJ Miller","year":"2020","unstructured":"Miller, D.J., Xiang, Z., Kesidis, G.: Adversarial learning targeting deep neural network classification: a comprehensive review of defenses against attacks. Proc. IEEE 108(3), 402\u2013433 (2020)","journal-title":"Proc. IEEE"},{"key":"5_CR25","unstructured":"Nguyen, T.A., Tran, A.: Input-aware dynamic backdoor attack. Adv. Neural Inf. Process. Syst., 3454\u20133464 (2020)"},{"key":"5_CR26","doi-asserted-by":"publisher","first-page":"5890","DOI":"10.1109\/TIFS.2023.3318964","volume":"18","author":"G Pagnotta","year":"2023","unstructured":"Pagnotta, G., De Gaspari, F., Hitaj, D., Andreolini, M., Colajanni, M., Mancini, L.V.: DOLOS: a novel architecture for moving target defense. IEEE Trans. Inf. Forensics Secur. 18, 5890\u20135905 (2023)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"Pagnotta, G., Hitaj, D., De\u00a0Gaspari, F., Mancini, L.V.: PassFlow: guessing passwords with generative flows. In: 2022 52nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), pp. 251\u2013262. IEEE (2022)","DOI":"10.1109\/DSN53405.2022.00035"},{"key":"5_CR28","doi-asserted-by":"crossref","unstructured":"Paudice, A., Mu\u00f1oz-Gonz\u00e1lez, L., Lupu, E.C.: Label sanitization against label flipping poisoning attacks. In: ECML PKDD 2018 Workshops, pp. 5\u201315. ECML PKDD (2019)","DOI":"10.1007\/978-3-030-13453-2_1"},{"key":"5_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1007\/978-3-030-66415-2_4","volume-title":"Computer Vision \u2013 ECCV 2020 Workshops","author":"N Peri","year":"2020","unstructured":"Peri, N., et al.: Deep k-NN defense against clean-label data poisoning attacks. In: Bartoli, A., Fusiello, A. (eds.) ECCV 2020. LNCS, vol. 12535, pp. 55\u201370. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-66415-2_4"},{"key":"5_CR30","doi-asserted-by":"crossref","unstructured":"Piskozub, M., De\u00a0Gaspari, F., Barr-Smith, F., Mancini, L., Martinovic, I.: MalPhase: fine-grained malware detection using network flow data. In: ACM Asia Conference on Computer and Communications Security, ASIACCS, pp. 774\u2013786 (2021)","DOI":"10.1145\/3433210.3453101"},{"key":"5_CR31","unstructured":"Schwarzschild, A., Goldblum, M., Gupta, A., Dickerson, J.P., Goldstein, T.: Just how toxic is data poisoning? A unified benchmark for backdoor and data poisoning attacks. In: International Conference on Machine Learning. ICML (2021)"},{"key":"5_CR32","unstructured":"Shafahi, A., et al.: Poison frogs! Targeted clean-label poisoning attacks on neural networks. In: Advances in Neural Information Processing Systems. NIPS (2018)"},{"key":"5_CR33","doi-asserted-by":"crossref","unstructured":"Shejwalkar, V., Houmansadr, A., Kairouz, P., Ramage, D.: Back to the drawing board: a critical evaluation of poisoning attacks on production federated learning. In: IEEE Symposium on Security and Privacy, pp. 1354\u20131371 (2022)","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"5_CR34","unstructured":"Shokri, R., et\u00a0al.: Bypassing backdoor detection algorithms in deep learning. In: IEEE European Symposium on Security and Privacy, EuroS &P, pp. 175\u2013183 (2020)"},{"key":"5_CR35","unstructured":"Steinhardt, J., Koh, P.W.W., Liang, P.S.: Certified defenses for data poisoning attacks. Adv. Neural Inf. Process. Syst. 30 (2017)"},{"issue":"8","key":"5_CR36","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3551636","volume":"55","author":"Z Tian","year":"2022","unstructured":"Tian, Z., Cui, L., Liang, J., Yu, S.: A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Comput. Surv. 55(8), 1\u201335 (2022)","journal-title":"ACM Comput. Surv."},{"key":"5_CR37","unstructured":"Touvron, H., et\u00a0al.: LLaMA: open and efficient foundation language models. arXiv preprint arXiv:2302.13971 (2023)"},{"key":"5_CR38","unstructured":"Tran, B., Li, J., Madry, A.: Spectral signatures in backdoor attacks. In: Advances in Neural Information Processing Systems. NIPS (2018)"},{"key":"5_CR39","doi-asserted-by":"crossref","unstructured":"Weber, M., Xu, X., Karla\u0161, B., Zhang, C., Li, B.: RAB: provable robustness against backdoor attacks. In: IEEE Symposium on Security and Privacy, pp. 1311\u20131328. S &P (2023)","DOI":"10.1109\/SP46215.2023.10179451"},{"key":"5_CR40","unstructured":"Yang, Y., Liu, T.Y., Mirzasoleiman, B.: Not all poisons are created equal: robust training against data poisoning. In: International Conference on Machine Learning. ICML (2022)"},{"key":"5_CR41","doi-asserted-by":"crossref","unstructured":"Yin, H., et al.: Dreaming to distill: data-free knowledge transfer via deepinversion. In: IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 8715\u20138724. CVPR (2020)","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"5_CR42","unstructured":"Zhu, C., Huang, W.R., Li, H., Taylor, G., Studer, C., Goldstein, T.: Transferable clean-label poisoning attacks on deep neural nets. In: International Conference on Machine Learning, pp. 7614\u20137623. ICML (2019)"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-70879-4_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T19:03:47Z","timestamp":1725476627000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-70879-4_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031708787","9783031708794"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-70879-4_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"5 September 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bydgoszcz","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Poland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 September 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2024.org","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}