{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T15:38:07Z","timestamp":1778081887652,"version":"3.51.4"},"publisher-location":"Cham","reference-count":83,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031730320","type":"print"},{"value":"9783031730337","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:00:00Z","timestamp":1730332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:00:00Z","timestamp":1730332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-73033-7_15","type":"book-chapter","created":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:03:55Z","timestamp":1730333035000},"page":"262-281","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["UNIT: Backdoor Mitigation via\u00a0Automated Neural Distribution Tightening"],"prefix":"10.1007","author":[{"given":"Siyuan","family":"Cheng","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guangyu","family":"Shen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaiyuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guanhong","family":"Tao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shengwei","family":"An","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hanxi","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shiqing","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiangyu","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,10,31]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"An, S., et\u00a0al.: Elijah: eliminating backdoors injected in diffusion models via distribution shift. In: Proceedings of the AAAI Conference on Artificial Intelligence, pp. 10847\u201310855 (2024)","DOI":"10.1609\/aaai.v38i10.28958"},{"key":"15_CR2","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., Shmatikov, V.: How to backdoor federated learning. In: International Conference on Artificial Intelligence and Statistics, pp. 2938\u20132948. PMLR (2020)"},{"key":"15_CR3","doi-asserted-by":"crossref","unstructured":"Barni, M., Kallas, K., Tondi, B.: A new backdoor attack in CNNs by training set corruption without label poisoning. CoRR abs\/1902.11237 (2019). http:\/\/arxiv.org\/abs\/1902.11237","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"15_CR4","unstructured":"Chen, B., et\u00a0al.: Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018)"},{"key":"15_CR5","unstructured":"Chen, X., Salem, A., Backes, M., Ma, S., Zhang, Y.: BadNL: backdoor attacks against NLP models. In: ICML 2021 Workshop on Adversarial Machine Learning (2021)"},{"key":"15_CR6","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)"},{"key":"15_CR7","doi-asserted-by":"crossref","unstructured":"Cheng, S., Liu, Y., Ma, S., Zhang, X.: Deep feature space trojan attack of neural networks by controlled detoxification. In: Proceedings of the AAAI Conference on Artificial Intelligence, pp. 1148\u20131156 (2021)","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"15_CR8","doi-asserted-by":"crossref","unstructured":"Cheng, S., et\u00a0al.: ODSCAN: backdoor scanning for object detection models. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 118\u2013118. IEEE Computer Society (2024)","DOI":"10.1109\/SP54263.2024.00119"},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Cheng, S., et\u00a0al.: BEAGLE: forensics of deep learning backdoor attack for better defense. arXiv preprint arXiv:2301.06241 (2023)","DOI":"10.14722\/ndss.2023.24944"},{"key":"15_CR10","doi-asserted-by":"crossref","unstructured":"Cheng, S., et\u00a0al.: LOTUS: evasive and resilient backdoor attacks through sub-partitioning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 24798\u201324809 (2024)","DOI":"10.1109\/CVPR52733.2024.02342"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"Chou, S.Y., Chen, P.Y., Ho, T.Y.: How to backdoor diffusion models? In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4015\u20134024 (2023)","DOI":"10.1109\/CVPR52729.2023.00391"},{"key":"15_CR12","unstructured":"Clevert, D.A., Unterthiner, T., Hochreiter, S.: Fast and accurate deep network learning by exponential linear units (ELUS). arXiv preprint arXiv:1511.07289 (2015)"},{"key":"15_CR13","unstructured":"Coates, A., Ng, A., Lee, H.: An analysis of single-layer networks in unsupervised feature learning. In: Proceedings of the fourteenth international conference on artificial intelligence and statistics, pp. 215\u2013223. JMLR Workshop and Conference Proceedings (2011)"},{"key":"15_CR14","doi-asserted-by":"crossref","unstructured":"Doan, B.G., Abbasnejad, E., Ranasinghe, D.C.: Februus: Input purification defense against trojan attacks on deep neural network systems. In: Annual Computer Security Applications Conference, pp. 897\u2013912 (2020)","DOI":"10.1145\/3427228.3427264"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Doan, K., Lao, Y., Zhao, W., Li, P.: LIRA: learnable, imperceptible and robust backdoor attacks. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 11966\u201311976 (2021)","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"15_CR16","unstructured":"Dosovitskiy, A., et\u00a0al.: An image is worth 16$$\\,\\times \\,$$16 words: transformers for image recognition at scale. In: International Conference on Learning Representations (2020)"},{"key":"15_CR17","doi-asserted-by":"crossref","unstructured":"Dubey, S.R., Singh, S.K., Chaudhuri, B.B.: Activation functions in deep learning: a comprehensive survey and benchmark. Neurocomputing (2022)","DOI":"10.1016\/j.neucom.2022.06.111"},{"key":"15_CR18","doi-asserted-by":"crossref","unstructured":"Feng, S., et\u00a0al.: Detecting backdoors in pre-trained encoders. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 16352\u201316362 (2023)","DOI":"10.1109\/CVPR52729.2023.01569"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Gao, Y., Xu, C., Wang, D., Chen, S., Ranasinghe, D.C., Nepal, S.: STRIP: a defence against trojan attacks on deep neural networks. In: Proceedings of the 35th Annual Computer Security Applications Conference, pp. 113\u2013125 (2019)","DOI":"10.1145\/3359789.3359790"},{"key":"15_CR20","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: BadNets: identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)"},{"key":"15_CR21","unstructured":"Guo, W., Wang, L., Xing, X., Du, M., Song, D.: TABOR: a highly accurate approach to inspecting and restoring trojan backdoors in AI systems. arXiv preprint arXiv:1908.01763 (2019)"},{"key":"15_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"195","DOI":"10.1007\/3-540-59497-3_175","volume-title":"From Natural to Artificial Neural Computation","author":"J Han","year":"1995","unstructured":"Han, J., Moraga, C.: The influence of the sigmoid function parameters on the speed of backpropagation learning. In: Mira, J., Sandoval, F. (eds.) IWANN 1995. LNCS, vol. 930, pp. 195\u2013201. Springer, Heidelberg (1995). https:\/\/doi.org\/10.1007\/3-540-59497-3_175"},{"key":"15_CR23","unstructured":"Hayase, J., Kong, W., Somani, R., Oh, S.: SPECTRE: defending against backdoor attacks using robust statistics. arXiv preprint arXiv:2104.11315 (2021)"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"15_CR25","unstructured":"Hinton, G., Vinyals, O., Dean, J.: Distilling the knowledge in a neural network. In: NIPS Deep Learning and Representation Learning Workshop (2015). http:\/\/arxiv.org\/abs\/1503.02531"},{"key":"15_CR26","unstructured":"Howard, A.G., et\u00a0al.: MobileNets: efficient convolutional neural networks for mobile vision applications. arXiv preprint arXiv:1704.04861 (2017)"},{"key":"15_CR27","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der\u00a0Maaten, L., Weinberger, K.Q.: Densely connected convolutional networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 4700\u20134708 (2017)","DOI":"10.1109\/CVPR.2017.243"},{"key":"15_CR28","unstructured":"Huang, K., Li, Y., Wu, B., Qin, Z., Ren, K.: Backdoor defense via decoupling the training process. arXiv preprint arXiv:2202.03423 (2022)"},{"key":"15_CR29","doi-asserted-by":"crossref","unstructured":"Huynh, T., Nguyen, D., Pham, T., Tran, A.: COMBAT: alternated training for effective clean-label backdoor attacks. In: Proceedings of the AAAI Conference on Artificial Intelligence, pp. 2436\u20132444 (2024)","DOI":"10.1609\/aaai.v38i3.28019"},{"key":"15_CR30","doi-asserted-by":"crossref","unstructured":"Jia, J., Liu, Y., Gong, N.Z.: BadEncoder: backdoor attacks to pre-trained encoders in self-supervised learning. arXiv preprint arXiv:2108.00352 (2021)","DOI":"10.1109\/SP46214.2022.9833644"},{"issue":"13","key":"15_CR31","doi-asserted-by":"publisher","first-page":"3521","DOI":"10.1073\/pnas.1611835114","volume":"114","author":"J Kirkpatrick","year":"2017","unstructured":"Kirkpatrick, J., et al.: Overcoming catastrophic forgetting in neural networks. Proc. Nat. Acad. Sci. 114(13), 3521\u20133526 (2017)","journal-title":"Proc. Nat. Acad. Sci."},{"key":"15_CR32","unstructured":"Klambauer, G., Unterthiner, T., Mayr, A., Hochreiter, S.: Self-normalizing neural networks. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"15_CR33","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"key":"15_CR34","first-page":"14900","volume":"34","author":"Y Li","year":"2021","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Anti-backdoor learning: training clean models on poisoned data. Adv. Neural. Inf. Process. Syst. 34, 14900\u201314912 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"15_CR35","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Neural attention distillation: erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930 (2021)"},{"key":"15_CR36","unstructured":"Li, Y., Lyu, X., Ma, X., Koren, N., Lyu, L., Li, B., Jiang, Y.G.: Reconstructive neuron pruning for backdoor defense. In: International Conference on Machine Learning, pp. 19837\u201319854. PMLR (2023)"},{"key":"15_CR37","doi-asserted-by":"crossref","unstructured":"Li, Y., Li, Y., Wu, B., Li, L., He, R., Lyu, S.: Invisible backdoor attack with sample-specific triggers. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 16463\u201316472 (2021)","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"15_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"K Liu","year":"2018","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) RAID 2018. LNCS, vol. 11050, pp. 273\u2013294. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13"},{"key":"15_CR39","doi-asserted-by":"crossref","unstructured":"Liu, Y., Lee, W.C., Tao, G., Ma, S., Aafer, Y., Zhang, X.: ABS: scanning neural networks for back-doors by artificial brain stimulation. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 1265\u20131282 (2019)","DOI":"10.1145\/3319535.3363216"},{"key":"15_CR40","doi-asserted-by":"crossref","unstructured":"Liu, Y., et\u00a0al.: Trojaning attack on neural networks. NDSS (2017)","DOI":"10.14722\/ndss.2018.23291"},{"key":"15_CR41","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1007\/978-3-030-58607-2_11","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Y Liu","year":"2020","unstructured":"Liu, Y., Ma, X., Bailey, J., Lu, F.: Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12355, pp. 182\u2013199. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58607-2_11"},{"key":"15_CR42","unstructured":"Lundberg, S.M., Lee, S.I.: A unified approach to interpreting model predictions. In: Guyon, I., Luxburg, U.V., Bengio, S., Wallach, H., Fergus, R., Vishwanathan, S., Garnett, R. (eds.) Advances in Neural Information Processing Systems 30, pp. 4765\u20134774. Curran Associates, Inc. (2017). http:\/\/papers.nips.cc\/paper\/7062-a-unified-approach-to-interpreting-model-predictions.pdf"},{"key":"15_CR43","unstructured":"Maas, A.L., Hannun, A.Y., Ng, A.Y., et\u00a0al.: Rectifier nonlinearities improve neural network acoustic models. In: Proceedings of International Conference on Machine Learning, p.\u00a03. Atlanta, Georgia, USA (2013)"},{"issue":"3","key":"15_CR44","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1016\/0098-3004(93)90090-R","volume":"19","author":"A Ma\u0107kiewicz","year":"1993","unstructured":"Ma\u0107kiewicz, A., Ratajczak, W.: Principal components analysis (PCA). Comput. Geosci. 19(3), 303\u2013342 (1993)","journal-title":"Comput. Geosci."},{"key":"15_CR45","unstructured":"Min, R., Qin, Z., Shen, L., Cheng, M.: Towards stable backdoor purification through feature shift tuning. In: Advances in Neural Information Processing Systems, vol. 36 (2024)"},{"key":"15_CR46","unstructured":"Nair, V., Hinton, G.E.: Rectified linear units improve restricted Boltzmann machines. In: Proceedings of the 27th International Conference on Machine Learning (ICML-10), pp. 807\u2013814 (2010)"},{"key":"15_CR47","unstructured":"Nguyen, A., Tran, A.: WaNet\u2013imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369 (2021)"},{"key":"15_CR48","first-page":"3454","volume":"33","author":"TA Nguyen","year":"2020","unstructured":"Nguyen, T.A., Tran, A.: Input-aware dynamic backdoor attack. Adv. Neural. Inf. Process. Syst. 33, 3454\u20133464 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"15_CR49","unstructured":"PyTorch: Tanhshrink. https:\/\/pytorch.org\/docs\/stable\/generated\/torch.nn.Tanhshrink.html"},{"key":"15_CR50","doi-asserted-by":"crossref","unstructured":"Qi, F., et\u00a0al.: Hidden Killer: invisible textual backdoor attacks with syntactic trigger. arXiv preprint arXiv:2105.12400 (2021)","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"15_CR51","unstructured":"Qi, X., Xie, T., Li, Y., Mahloujifar, S., Mittal, P.: Revisiting the assumption of latent separability for backdoor defenses. In: The Eleventh International Conference on Learning Representations (2022)"},{"key":"15_CR52","doi-asserted-by":"crossref","unstructured":"Saha, A., Subramanya, A., Pirsiavash, H.: Hidden trigger backdoor attacks. In: Proceedings of the AAAI Conference on Artificial Intelligence, pp. 11957\u201311965 (2020)","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"15_CR53","unstructured":"Salem, A., Wen, R., Backes, M., Ma, S., Zhang, Y.: Dynamic backdoor attacks against machine learning models. arXiv preprint arXiv:2003.03675 (2020)"},{"key":"15_CR54","unstructured":"Sha, Z., He, X., Berrang, P., Humbert, M., Zhang, Y.: Fine-tuning is all you need to mitigate backdoor attacks. arXiv preprint arXiv:2212.09067 (2022)"},{"key":"15_CR55","unstructured":"Shen, G., et\u00a0al.: Django: Detecting trojans in object detection models via gaussian focus calibration. In: Advances in Neural Information Processing Systems, vol. 36 (2024)"},{"key":"15_CR56","unstructured":"Shen, G., et\u00a0al.: Backdoor scanning for deep neural networks through K-arm optimization. In: International Conference on Machine Learning, pp. 9525\u20139536. PMLR (2021)"},{"key":"15_CR57","unstructured":"Shen, G., et\u00a0al.: Constrained optimization with dynamic bound-scaling for effective NLP backdoor defense. In: International Conference on Machine Learning, pp. 19879\u201319892. PMLR (2022)"},{"key":"15_CR58","doi-asserted-by":"publisher","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition (2014)https:\/\/doi.org\/10.48550\/ARXIV.1409.1556","DOI":"10.48550\/ARXIV.1409.1556"},{"key":"15_CR59","unstructured":"Souri, H., Fowl, L., Chellappa, R., Goldblum, M., Goldstein, T.: Sleeper Agent: scalable hidden trigger backdoors for neural networks trained from scratch. arXiv preprint arXiv:2106.08970 (2021)"},{"key":"15_CR60","doi-asserted-by":"crossref","unstructured":"Stallkamp, J., Schlipsing, M., Salmen, J., Igel, C.: Man vs. Computer: benchmarking machine learning algorithms for traffic sign recognition. Neural Netw. 32, 323\u2013332 (2012)","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"15_CR61","unstructured":"Tao, G., et\u00a0al.: DECK: model hardening for defending pervasive backdoors. arXiv preprint arXiv:2206.09272 (2022)"},{"key":"15_CR62","doi-asserted-by":"crossref","unstructured":"Tao, G., et\u00a0al.: Model orthogonalization: class distance hardening in neural networks for better security. In: 2022 IEEE Symposium on Security and Privacy (SP), vol.\u00a03. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833688"},{"key":"15_CR63","unstructured":"Tao, G., et\u00a0al.: Backdoor vulnerabilities in normally trained deep learning models. arXiv preprint arXiv:2211.15929 (2022)"},{"key":"15_CR64","unstructured":"Tran, B., Li, J., Madry, A.: Spectral signatures in backdoor attacks. In: Advances in Neural Information Processing Systems, vol. 31 (2018)"},{"key":"15_CR65","unstructured":"Turner, A., Tsipras, D., Madry, A.: Clean-label backdoor attacks. OpenReview (2018)"},{"key":"15_CR66","doi-asserted-by":"crossref","unstructured":"Wang, B., et\u00a0al.: Neural Cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 707\u2013723. IEEE (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"15_CR67","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1007\/978-3-030-58592-1_14","volume-title":"Computer Vision \u2013 ECCV 2020","author":"R Wang","year":"2020","unstructured":"Wang, R., Zhang, G., Liu, S., Chen, P.-Y., Xiong, J., Wang, M.: Practical detection of trojan neural networks: data-limited and data-free cases. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12368, pp. 222\u2013238. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58592-1_14"},{"key":"15_CR68","first-page":"36396","volume":"35","author":"Z Wang","year":"2022","unstructured":"Wang, Z., Ding, H., Zhai, J., Ma, S.: Training with more confidence: mitigating injected and natural backdoors during training. Adv. Neural. Inf. Process. Syst. 35, 36396\u201336410 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"15_CR69","first-page":"16913","volume":"34","author":"D Wu","year":"2021","unstructured":"Wu, D., Wang, Y.: Adversarial neuron pruning purifies backdoored deep models. Adv. Neural. Inf. Process. Syst. 34, 16913\u201316925 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"15_CR70","doi-asserted-by":"crossref","unstructured":"Xu, Q., et\u00a0al.: MEDIC: remove model backdoors via importance driven cloning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 20485\u201320494 (2023)","DOI":"10.1109\/CVPR52729.2023.01962"},{"key":"15_CR71","doi-asserted-by":"crossref","unstructured":"Xu, X., Wang, Q., Li, H., Borisov, N., Gunter, C.A., Li, B.: Detecting AI trojans using meta neural analysis. In: 2021 IEEE Symposium on Security and Privacy (SP), pp. 103\u2013120 (2021)","DOI":"10.1109\/SP40001.2021.00034"},{"key":"15_CR72","unstructured":"Yan, L., et\u00a0al.: $$d^3$$: detoxing deep learning dataset. In: NeurIPS 2023 Workshop on Backdoors in Deep Learning-The Good, the Bad, and the Ugly (2023)"},{"key":"15_CR73","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., Komodakis, N.: Wide residual networks. arXiv preprint arXiv:1605.07146 (2016)","DOI":"10.5244\/C.30.87"},{"key":"15_CR74","unstructured":"Zeng, Y., Chen, S., Park, W., Mao, Z.M., Jin, M., Jia, R.: Adversarial unlearning of backdoors via implicit hypergradient. arXiv preprint arXiv:2110.03735 (2021)"},{"key":"15_CR75","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Pan, M., Just, H.A., Lyu, L., Qiu, M., Jia, R.: Narcissus: a practical clean-label backdoor attack with limited information. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pp. 771\u2013785 (2023)","DOI":"10.1145\/3576915.3616617"},{"key":"15_CR76","doi-asserted-by":"crossref","unstructured":"Zhang, K., et\u00a0al.: Exploring the orthogonality and linearity of backdoor attacks. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 225\u2013225. IEEE Computer Society (2024)","DOI":"10.1109\/SP54263.2024.00225"},{"key":"15_CR77","unstructured":"Zhang, K., et\u00a0al.: FLIP: a provable defense framework for backdoor mitigation in federated learning. arXiv preprint arXiv:2210.12873 (2022)"},{"key":"15_CR78","unstructured":"Zhang, Z., et\u00a0al.: Neurotoxin: durable backdoors in federated learning. In: International Conference on Machine Learning, pp. 26429\u201326446. PMLR (2022)"},{"key":"15_CR79","doi-asserted-by":"crossref","unstructured":"Zheng, H., Yang, Z., Liu, W., Liang, J., Li, Y.: Improving deep neural networks using softplus units. In: 2015 International joint conference on neural networks (IJCNN), pp.\u00a01\u20134. IEEE (2015)","DOI":"10.1109\/IJCNN.2015.7280459"},{"key":"15_CR80","doi-asserted-by":"publisher","unstructured":"Zheng, R., Tang, R., Li, J., Liu, L.: Data-free backdoor removal based on\u00a0channel lipschitzness. In: Avidan, S., Brostow, G., Ciss\u00e9, M., Farinella, G.M., Hassner, T. (eds.) Computer Vision \u2013 ECCV 2022: 17th European Conference, Tel Aviv, Israel, October 23\u201327, 2022, Proceedings, Part V, pp. 175\u2013191. Springer Nature Switzerland, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-20065-6_11","DOI":"10.1007\/978-3-031-20065-6_11"},{"key":"15_CR81","first-page":"18667","volume":"35","author":"R Zheng","year":"2022","unstructured":"Zheng, R., Tang, R., Li, J., Liu, L.: Pre-activation distributions expose backdoor neurons. Adv. Neural. Inf. Process. Syst. 35, 18667\u201318680 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"15_CR82","doi-asserted-by":"crossref","unstructured":"Zhu, M., Wei, S., Shen, L., Fan, Y., Wu, B.: Enhancing fine-tuning based backdoor defense with sharpness-aware minimization. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 4466\u20134477 (2023)","DOI":"10.1109\/ICCV51070.2023.00412"},{"key":"15_CR83","doi-asserted-by":"crossref","unstructured":"Zhu, R., Tang, D., Tang, S., Wang, X., Tang, H.: Selective Amnesia: on efficient, high-fidelity and blind suppression of backdoor effects in trojaned machine learning models. arXiv preprint arXiv:2212.04687 (2022)","DOI":"10.1109\/SP46215.2023.10351028"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-73033-7_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:38:09Z","timestamp":1730335089000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-73033-7_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,31]]},"ISBN":["9783031730320","9783031730337"],"references-count":83,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-73033-7_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,31]]},"assertion":[{"value":"31 October 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}