{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,24]],"date-time":"2026-02-24T16:17:56Z","timestamp":1771949876738,"version":"3.50.1"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031723896","type":"print"},{"value":"9783031723902","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-72390-2_42","type":"book-chapter","created":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T10:03:14Z","timestamp":1729591394000},"page":"443-453","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["BAPLe: Backdoor Attacks on\u00a0Medical Foundational Models Using Prompt Learning"],"prefix":"10.1007","author":[{"given":"Asif","family":"Hanif","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fahad","family":"Shamshad","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammad","family":"Awais","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muzammal","family":"Naseer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fahad Shahbaz","family":"Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Karthik","family":"Nandakumar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Salman","family":"Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rao Muhammad","family":"Anwer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,10,23]]},"reference":[{"key":"42_CR1","unstructured":"Awais, M., Naseer, M., Khan, S., Anwer, R.M., Cholakkal, H., Shah, M., Yang, M.H., Khan, F.S.: Foundational models defining a new era in vision: A survey and outlook. arXiv preprint arXiv:2307.13721 (2023)"},{"key":"42_CR2","unstructured":"Azad, B., Azad, R., Eskandari, S., Bozorgpour, A., Kazerouni, A., Rekik, I., Merhof, D.: Foundational models in medical imaging: A comprehensive survey and future vision. arXiv preprint arXiv:2310.18689 (2023)"},{"key":"42_CR3","unstructured":"Bommasani, R., Hudson, D.A., Adeli, E., Altman, R., Arora, S., von Arx, S., Bernstein, M.S., Bohg, J., Bosselut, A., Brunskill, E., et\u00a0al.: On the opportunities and risks of foundation models. arXiv preprint arXiv:2108.07258 (2021)"},{"key":"42_CR4","unstructured":"Carlini, N., Terzis, A.: Poisoning and backdooring contrastive learning. arXiv preprint arXiv:2106.09667 (2021)"},{"key":"42_CR5","doi-asserted-by":"crossref","unstructured":"Feng, Y., Ma, B., Zhang, J., Zhao, S., Xia, Y., Tao, D.: Fiba: Frequency-injection based backdoor attack in medical image analysis. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. pp. 20876\u201320885 (2022)","DOI":"10.1109\/CVPR52688.2022.02021"},{"key":"42_CR6","doi-asserted-by":"crossref","unstructured":"Gamper, J., Alemi\u00a0Koohbanani, N., Benet, K., Khuram, A., Rajpoot, N.: Pannuke: an open pan-cancer histology dataset for nuclei instance segmentation and classification. In: Digital Pathology: 15th European Congress, ECDP 2019, Warwick, UK, April 10\u201313, 2019, Proceedings 15. pp. 11\u201319. Springer (2019)","DOI":"10.1007\/978-3-030-23937-4_2"},{"key":"42_CR7","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)"},{"key":"42_CR8","doi-asserted-by":"crossref","unstructured":"Huang, Z., Bianchi, F., Yuksekgonul, M., Montine, T.J., Zou, J.: A visual\u2013language foundation model for pathology image analysis using medical twitter. Nature medicine 29(9), 2307\u20132316 (2023)","DOI":"10.1038\/s41591-023-02504-3"},{"key":"42_CR9","unstructured":"Ikezogwo, W., Seyfioglu, S., Ghezloo, F., Geva, D., Sheikh\u00a0Mohammed, F., Anand, P.K., Krishna, R., Shapiro, L.: Quilt-1m: One million image-text pairs for histopathology. Advances in Neural Information Processing Systems 36 (2024)"},{"key":"42_CR10","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2023.102965","volume":"90","author":"R Jin","year":"2023","unstructured":"Jin, R., Li, X.: Backdoor attack and defense in federated generative adversarial network-based medical image synthesis. Medical Image Analysis 90, 102965 (2023)","journal-title":"Medical Image Analysis"},{"key":"42_CR11","doi-asserted-by":"crossref","unstructured":"Johnson, A.E., Pollard, T.J., Greenbaum, N.R., Lungren, M.P., Deng, C.y., Peng, Y., Lu, Z., Mark, R.G., Berkowitz, S.J., Horng, S.: Mimic-cxr-jpg, a large publicly available database of labeled chest radiographs. arXiv preprint arXiv:1901.07042 (2019)","DOI":"10.1038\/s41597-019-0322-0"},{"issue":"1","key":"42_CR12","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pmed.1002730","volume":"16","author":"JN Kather","year":"2019","unstructured":"Kather, J.N., Krisam, J., Charoentong, P., Luedde, T., Herpel, E., Weis, C.A., Gaiser, T., Marx, A., Valous, N.A., Ferber, D., et\u00a0al.: Predicting survival from colorectal cancer histology slides using deep learning: A retrospective multicenter study. PLoS medicine 16(1), e1002730 (2019)","journal-title":"PLoS medicine"},{"key":"42_CR13","unstructured":"Li, Y., Jiang, Y., Li, Z., Xia, S.T.: Backdoor learning: A survey. IEEE Transactions on Neural Networks and Learning Systems (2022)"},{"key":"42_CR14","unstructured":"Lian, C., Zhou, H.Y., Yu, Y., Wang, L.: Less could be better: Parameter-efficient fine-tuning advances medical vision foundation models. arXiv preprint arXiv:2401.12215 (2024)"},{"key":"42_CR15","unstructured":"Nguyen, A., Tran, A.: Wanet\u2013imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369 (2021)"},{"key":"42_CR16","unstructured":"of\u00a0North\u00a0America, R.S.: RSNA pneumonia detection challenge (2018). https:\/\/www.rsna.org\/rsnai\/ai-image-challenge\/rsna-pneumonia-detection-challenge-2018 (2018)"},{"key":"42_CR17","unstructured":"Nwadike, M., Miyawaki, T., Sarkar, E., Maniatakos, M., Shamout, F.: Explainability matters: Backdoor attacks on medical imaging. arXiv preprint arXiv:2101.00008 (2020)"},{"key":"42_CR18","doi-asserted-by":"crossref","unstructured":"Rahman, T., Khandakar, A., Qiblawey, Y., Tahir, A., Kiranyaz, S., Kashem, S.B.A., Islam, M.T., Al\u00a0Maadeed, S., Zughaier, S.M., Khan, M.S., et\u00a0al.: Exploring the effect of image enhancement techniques on covid-19 detection using chest x-ray images. Computers in biology and medicine 132, 104319 (2021)","DOI":"10.1016\/j.compbiomed.2021.104319"},{"key":"42_CR19","doi-asserted-by":"crossref","unstructured":"Schlarmann, C., Hein, M.: On the adversarial robustness of multi-modal foundation models. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision. pp. 3677\u20133685 (2023)","DOI":"10.1109\/ICCVW60793.2023.00395"},{"key":"42_CR20","unstructured":"Silva-Rodriguez, J., Chakor, H., Kobbi, R., Dolz, J., Ayed, I.B.: A foundation language-image model of the retina (flair): Encoding expert knowledge in text supervision. arXiv preprint arXiv:2308.07898 (2023)"},{"key":"42_CR21","doi-asserted-by":"crossref","unstructured":"Uzair\u00a0Khattak, M., Rasheed, H., Maaz, M., Khan, S., Shahbaz\u00a0Khan, F.: Maple: Multi-modal prompt learning. arXiv e-prints pp. arXiv\u20132210 (2022)","DOI":"10.1109\/CVPR52729.2023.01832"},{"key":"42_CR22","doi-asserted-by":"crossref","unstructured":"Wang, Z., Wu, Z., Agarwal, D., Sun, J.: Medclip: Contrastive learning from unpaired medical images and text. arXiv preprint arXiv:2210.10163 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.256"},{"key":"42_CR23","unstructured":"Wu, C., Zhang, X., Zhang, Y., Wang, Y., Xie, W.: Towards generalist foundation model for radiology. arXiv preprint arXiv:2308.02463 (2023)"},{"key":"42_CR24","doi-asserted-by":"crossref","unstructured":"Zhang, J., Kapse, S., Ma, K., Prasanna, P., Saltz, J., Vakalopoulou, M., Samaras, D.: Prompt-mil: Boosting multi-instance learning schemes via task-specific prompt tuning. arXiv preprint arXiv:2303.12214 (2023)","DOI":"10.1007\/978-3-031-43993-3_60"},{"key":"42_CR25","doi-asserted-by":"publisher","unstructured":"Zhang, S., Xu, Y., Usuyama, N., Bagga, J., Tinn, R., Preston, S., Rao, R., Wei, M., Valluri, N., Wong, C., Lungren, M., Naumann, T., Poon, H.: Large-scale domain-specific pretraining for biomedical vision-language processing (2023). https:\/\/doi.org\/10.48550\/ARXIV.2303.00915, https:\/\/arxiv.org\/abs\/2303.00915","DOI":"10.48550\/ARXIV.2303.00915"},{"key":"42_CR26","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Gao, J., Zhou, M., Wang, X., Qiao, Y., Zhang, S., Wang, D.: Text-guided foundation model adaptation for pathological image classification. In: International Conference on Medical Image Computing and Computer-Assisted Intervention. pp. 272\u2013282. Springer (2023)","DOI":"10.1007\/978-3-031-43904-9_27"},{"key":"42_CR27","unstructured":"Zhao, Z., Liu, Y., Wu, H., Li, Y., Wang, S., Teng, L., Liu, D., Li, X., Cui, Z., Wang, Q., et\u00a0al.: Clip in medical imaging: A comprehensive survey. arXiv preprint arXiv:2312.07353 (2023)"},{"key":"42_CR28","doi-asserted-by":"crossref","unstructured":"Zhou, K., Yang, J., Loy, C.C., Liu, Z.: Learning to prompt for vision-language models. International Journal of Computer Vision (IJCV) (2022)","DOI":"10.1007\/s11263-022-01653-1"}],"container-title":["Lecture Notes in Computer Science","Medical Image Computing and Computer Assisted Intervention \u2013 MICCAI 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-72390-2_42","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T10:10:50Z","timestamp":1729591850000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-72390-2_42"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031723896","9783031723902"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-72390-2_42","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"23 October 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"MICCAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Medical Image Computing and Computer-Assisted Intervention","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Marrakesh","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Morocco","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 October 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"11 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"miccai2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/conferences.miccai.org\/2024\/en\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}