{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T05:39:38Z","timestamp":1757309978623,"version":"3.40.3"},"publisher-location":"Cham","reference-count":64,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031736490"},{"type":"electronic","value":"9783031736506"}],"license":[{"start":{"date-parts":[[2024,11,21]],"date-time":"2024-11-21T00:00:00Z","timestamp":1732147200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,21]],"date-time":"2024-11-21T00:00:00Z","timestamp":1732147200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-73650-6_11","type":"book-chapter","created":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T18:17:15Z","timestamp":1732126635000},"page":"179-197","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["WBP: Training-Time Backdoor Attacks Through Hardware-Based Weight Bit Poisoning"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-3895-6655","authenticated-orcid":false,"given":"Kunbei","family":"Cai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9025-3460","authenticated-orcid":false,"given":"Zhenkai","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5462-2567","authenticated-orcid":false,"given":"Qian","family":"Lou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0360-5641","authenticated-orcid":false,"given":"Fan","family":"Yao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,21]]},"reference":[{"key":"11_CR1","doi-asserted-by":"crossref","unstructured":"Al\u00a0Rafi, M., Feng, Y., Yao, F., Tang, M., Jeon, H.: Decepticon: attacking secrets of transformers. In: IEEE International Symposium on Workload Characterization (IISWC), pp. 128\u2013139 (2023)","DOI":"10.1109\/IISWC59245.2023.00028"},{"key":"11_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1007\/978-3-031-20065-6_7","volume-title":"Computer Vision \u2013 ECCV 2022","author":"J Bai","year":"2022","unstructured":"Bai, J., Gao, K., Gong, D., Xia, S.T., Li, Z., Liu, W.: Hardly perceptible trojan attack against neural networks with bit flips. In: Avidan, S., Brostow, G., Ciss\u00e9, M., Farinella, G.M., Hassner, T. (eds.) ECCV 2022. LNCS, vol. 13665, pp. 104\u2013121. Springer, Cham (2022)"},{"key":"11_CR3","unstructured":"Bai, J., Wu, B., Zhang, Y., Li, Y., Li, Z., Xia, S.: Targeted attack against deep neural networks via flipping limited weight bits. In: International Conference on Learning Representations (ICLR) (2021)"},{"key":"11_CR4","unstructured":"Bickel, P., Doksum, K.: Mathematical Statistics: Basic Ideas and Selected Topics. Prentice Hall (2001)"},{"key":"11_CR5","unstructured":"Brown, T.B., Man\u00e9, D., Roy, A., Abadi, M., Gilmer, J.: Adversarial patch. arXiv preprint arXiv:1712.09665 (2017)"},{"key":"11_CR6","doi-asserted-by":"crossref","unstructured":"Cai, K., Chowdhuryy, M.H.I., Zhang, Z., Yao, F.: Seeds of seed: NMT-stroke: diverting neural machine translation through hardware-based faults. In: International Symposium on Secure and Private Execution Environment Design (SEED), pp. 76\u201382 (2021)","DOI":"10.1109\/SEED51797.2021.00019"},{"key":"11_CR7","doi-asserted-by":"crossref","unstructured":"Cai, K., Chowdhuryy, M.H.I., Zhenkai, Z., Yao, F.: DeepVenom: persistent DNN backdoors exploiting transient weight perturbations in memories. In: 2024 IEEE Symposium on Security and Privacy (SP), p. 244 (2024)","DOI":"10.1109\/SP54263.2024.00223"},{"key":"11_CR8","doi-asserted-by":"crossref","unstructured":"Cai, K., Zhang, Z., Yao, F.: On the feasibility of training-time trojan attacks through hardware-based faults in memory. In: Hardware Oriented Security and Trust (HOST), pp. 133\u2013136 (2022)","DOI":"10.1109\/HOST54066.2022.9840266"},{"key":"11_CR9","unstructured":"Chan, A., Ong, Y.S.: Poison as a cure: detecting & neutralizing variable-sized backdoor attacks in deep neural networks. arXiv preprint arXiv:1911.08040 (2019)"},{"key":"11_CR10","unstructured":"Chen, B., et al.: Detecting backdoor attacks on deep neural networks by activation clustering. In: Workshop on AAAI Conference on Artificial Intelligence (AAAI), vol.\u00a02301 (2019)"},{"key":"11_CR11","doi-asserted-by":"crossref","unstructured":"Chen, H., Fu, C., Zhao, J., Koushanfar, F.: ProFlip: targeted trojan attack with progressive bit flips. In: IEEE\/CVF International Conference on Computer Vision (ICCV), pp. 7718\u20137727 (2021)","DOI":"10.1109\/ICCV48922.2021.00762"},{"key":"11_CR12","unstructured":"Chen, K., et al.: BadPre: task-agnostic backdoor attacks to pre-trained NLP foundation models. In: International Conference on Learning Representations (ICLR) (2022)"},{"key":"11_CR13","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)"},{"key":"11_CR14","doi-asserted-by":"crossref","unstructured":"Cheng, G., Han, J., Lu, X.: Remote sensing image scene classification: benchmark and state of the art. Proc. IEEE 1865\u20131883 (2017)","DOI":"10.1109\/JPROC.2017.2675998"},{"key":"11_CR15","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: ImageNet: a large-scale hierarchical image database. In: Computer Vision and Pattern Recognition (CVPR), pp. 248\u2013255 (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"11_CR16","doi-asserted-by":"crossref","unstructured":"Fang, H., Dayapule, S.S., Yao, F., Doroslova\u010dki, M., Venkataramani, G.: A noise-resilient detection method against advanced cache timing channel attack. In: Asilomar Conference on Signals, Systems, and Computers. pp. 237\u2013241 (2018)","DOI":"10.1109\/ACSSC.2018.8645322"},{"key":"11_CR17","doi-asserted-by":"crossref","unstructured":"French, R.M.: Catastrophic forgetting in connectionist networks. Trends Cogn. Sci. 128\u2013135 (1999)","DOI":"10.1016\/S1364-6613(99)01294-2"},{"key":"11_CR18","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: Bengio, Y., LeCun, Y. (eds.) International Conference on Learning Representations (ICLR) (2015)"},{"key":"11_CR19","unstructured":"Gretton, A., Borgwardt, K.M., Rasch, M.J., Sch\u00f6lkopf, B., Smola, A.: A kernel two-sample test. J. Mach. Learn. Res. 723\u2013773 (2012)"},{"key":"11_CR20","doi-asserted-by":"crossref","unstructured":"Gruss, D., et al.: Another flip in the wall of Rowhammer defenses. In: 2018 IEEE Symposium on Security and Privacy (SP), pp. 245\u2013261. IEEE (2018)","DOI":"10.1109\/SP.2018.00031"},{"key":"11_CR21","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: BadNets: identifying vulnerabilities in the machine learning model supply chain. CoRR abs\/1708.06733 (2017)"},{"key":"11_CR22","unstructured":"Hayase, J., Kong, W.: SPECTRE: defending against backdoor attacks using robust covariance estimation. In: International Conference on Machine Learning (ICLR) (2020)"},{"key":"11_CR23","doi-asserted-by":"crossref","unstructured":"Helber, P., Bischke, B., Dengel, A., Borth, D.: EuroSAT: a novel dataset and deep learning benchmark for land use and land cover classification. IEEE J. Sel. Top. Appl. Earth Observ. Remote Sens. 2217\u20132226 (2019)","DOI":"10.1109\/JSTARS.2019.2918242"},{"key":"11_CR24","unstructured":"Hestness, J., et al.: Deep learning scaling is predictable. Empirically. arXiv, p.\u00a02 (2017)"},{"key":"11_CR25","doi-asserted-by":"crossref","unstructured":"Houben, S., Stallkamp, J., Salmen, J., Schlipsing, M., Igel, C.: Detection of traffic signs in real-world images: the German Traffic Sign Detection Benchmark. In: International Joint Conference on Neural Networks, No.\u00a01288 (2013)","DOI":"10.1109\/IJCNN.2013.6706807"},{"key":"11_CR26","doi-asserted-by":"crossref","unstructured":"Jattke, P., van\u00a0der Veen, V., Frigo, P., Gunter, S., Razavi, K.: BLACKSMITH: scalable Rowhammering in the frequency domain. In: IEEE Symposium on Security and Privacy (SP), vol.\u00a01 (2022)","DOI":"10.1109\/SP46214.2022.9833772"},{"key":"11_CR27","unstructured":"Jeon, M., Venkataraman, S., Phanishayee, A., Qian, J., Xiao, W., Yang, F.: In: USENIX Annual Technical Conference, pp. 947\u2013960 (2019)"},{"key":"11_CR28","doi-asserted-by":"crossref","unstructured":"Jia, J., Liu, Y., Gong, N.Z.: BadEncoder: backdoor attacks to pre-trained encoders in self-supervised learning. In: IEEE Symposium on Security and Privacy (SP) (2022)","DOI":"10.1109\/SP46214.2022.9833644"},{"key":"11_CR29","doi-asserted-by":"crossref","unstructured":"Kim, Y., et al.: Flipping bits in memory without accessing them: an experimental study of dram disturbance errors. ACM SIGARCH Comput. Architect. News 361\u2013372 (2014)","DOI":"10.1145\/2678373.2665726"},{"key":"11_CR30","unstructured":"Koh, J.Y.: Model zoo: discover open source deep learning code and pretrained models. https:\/\/modelzoo.co\/"},{"key":"11_CR31","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"key":"11_CR32","doi-asserted-by":"crossref","unstructured":"Li, L., Song, D., Li, X., Zeng, J., Ma, R., Qiu, X.: Backdoor attacks on pre-trained models by layerwise weight poisoning. In: Empirical Methods in Natural Language Processing (EMNLP) (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.241"},{"key":"11_CR33","doi-asserted-by":"crossref","unstructured":"Liu, F., Yarom, Y., Ge, Q., Heiser, G., Lee, R.B.: Last-level cache side-channel attacks are practical. In: IEEE Symposium on Security and Privacy (SP), pp. 605\u2013622 (2015)","DOI":"10.1109\/SP.2015.43"},{"key":"11_CR34","unstructured":"Liu, Q., Yin, J., Wen, W., Yang, C., Sha, S.: $$\\{$$NeuroPots$$\\}$$: realtime proactive defense against $$\\{$$Bit-Flip$$\\}$$ attacks in neural networks. In: USENIX Security Symposium, pp. 6347\u20136364 (2023)"},{"key":"11_CR35","doi-asserted-by":"crossref","unstructured":"Liu, Y., et al.: Trojaning attack on neural networks. In: Network and Distributed System Security Symposium (NDSS) (2018)","DOI":"10.14722\/ndss.2018.23291"},{"key":"11_CR36","doi-asserted-by":"crossref","unstructured":"Liu, Y., Xie, Y., Srivastava, A.: Neural trojans. In: International Conference on Computer Design (ICCD), pp. 45\u201348 (2017)","DOI":"10.1109\/ICCD.2017.16"},{"key":"11_CR37","doi-asserted-by":"crossref","unstructured":"McCloskey, M., Cohen, N.J.: Catastrophic interference in connectionist networks: the sequential learning problem. In: Psychology of Learning and Motivation, pp. 109\u2013165 (1989)","DOI":"10.1016\/S0079-7421(08)60536-8"},{"key":"11_CR38","doi-asserted-by":"crossref","unstructured":"McKeen, F., et al.: Intel\u00ae software guard extensions (intel\u00ae SGX) support for dynamic memory management inside an enclave. In: Hardware and Architectural Support for Security and Privacy (HASP), pp.\u00a01\u20139 (2016)","DOI":"10.1145\/2948618.2954331"},{"key":"11_CR39","unstructured":"monkeydoodle@gmail.com: The Oxford-IIIT pet dataset dataset (2022). https:\/\/universe.roboflow.com\/monkeydoodle-gmail-com\/the-oxford-iiit-pet-dataset"},{"key":"11_CR40","unstructured":"Netzer, Y., Wang, T., Coates, A., Bissacco, A., Wu, B., Ng, A.Y.: Reading digits in natural images with unsupervised feature learning (2011)"},{"key":"11_CR41","doi-asserted-by":"crossref","unstructured":"Nilsback, M.E., Zisserman, A.: Automated flower classification over a large number of classes. In: Indian Conference on Computer Vision, Graphics & Image Processing, pp. 722\u2013729 (2008)","DOI":"10.1109\/ICVGIP.2008.47"},{"key":"11_CR42","doi-asserted-by":"crossref","unstructured":"Pan, S.J., Yang, Q.: A survey on transfer learning. IEEE Trans. Knowl. Data Eng. 1345\u20131359 (2009)","DOI":"10.1109\/TKDE.2009.191"},{"key":"11_CR43","doi-asserted-by":"crossref","unstructured":"Rakin, A.S., Chowdhuryy, M.H.I., Yao, F., Fan, D.: DeepSteal: advanced model extractions leveraging efficient weight stealing in memories. In: IEEE Security and Privacy (SP), pp. 1157\u20131174 (2022)","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"11_CR44","doi-asserted-by":"crossref","unstructured":"Rakin, A.S., He, Z., Fan, D.: Bit-flip attack: crushing neural network with progressive bit search. In: International Conference on Computer Vision (ICCV), pp. 1211\u20131220 (2019)","DOI":"10.1109\/ICCV.2019.00130"},{"key":"11_CR45","doi-asserted-by":"crossref","unstructured":"Rakin, A.S., He, Z., Fan, D.: TBT: targeted neural network attack with bit trojan. In: Computer Vision and Pattern Recognition (CVPR), pp. 13195\u201313204 (2020)","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"11_CR46","doi-asserted-by":"crossref","unstructured":"Rakin, A.S., He, Z., Li, J., Yao, F., Chakrabarti, C., Fan, D.: T-BFA: targeted bit-flip adversarial weight attack. IEEE Trans. Pattern Anal. Mach. Intell. 7928\u20137939 (2021)","DOI":"10.1109\/TPAMI.2021.3112932"},{"key":"11_CR47","unstructured":"Ruder, S.: An overview of gradient descent optimization algorithms. arXiv preprint arXiv:1609.04747 (2016)"},{"key":"11_CR48","unstructured":"Seaborn, M., Dullien, T.: Exploiting the dram Rowhammer bug to gain kernel privileges. Black Hat 71 (2015)"},{"key":"11_CR49","unstructured":"Shen, G., et al.: Backdoor scanning for deep neural networks through k-arm optimization. In: International Conference on Machine Learning (ICML) (2021)"},{"key":"11_CR50","doi-asserted-by":"crossref","unstructured":"Shen, L., et al.: Backdoor pre-trained models can transfer to all. In: ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 3141\u20133158 (2021)","DOI":"10.1145\/3460120.3485370"},{"key":"11_CR51","unstructured":"Singhal, A., et\u00a0al.: Modern information retrieval: a brief overview. IEEE Data Eng. Bull. 35\u201343 (2001)"},{"key":"11_CR52","doi-asserted-by":"crossref","unstructured":"Tol, M.C., Islam, S., Adiletta, A.J., Sunar, B., Zhang, Z.: Don\u2019t knock! Rowhammer at the backdoor of DNN models. In: Dependable Systems and Networks (DSN), pp. 109\u2013122 (2023)","DOI":"10.1109\/DSN58367.2023.00023"},{"key":"11_CR53","doi-asserted-by":"crossref","unstructured":"Tolpegin, V., Truex, S., Gursoy, M.E., Liu, L.: Data poisoning attacks against federated learning systems. In: European Symposium on Research in Computer Security (ESORICS), pp. 480\u2013501 (2020)","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"11_CR54","unstructured":"Tran, B., Li, J., Madry, A.: Spectral signatures in backdoor attacks. In: Advances in Neural Information Processing Systems (NeurIPS), vol. 31 (2018)"},{"key":"11_CR55","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: IEEE Symposium on Security and Privacy (SP), pp. 707\u2013723 (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"11_CR56","unstructured":"Wang, J., et al.: Aegis: mitigating targeted bit-flip attacks against deep neural networks. In: USENIX Security Symposium, pp. 2329\u20132346 (2023)"},{"key":"11_CR57","doi-asserted-by":"crossref","unstructured":"Wang, S., Nepal, S., Rudolph, C., Grobler, M., Chen, S., Chen, T.: Backdoor attacks against transfer learning with pre-trained deep learning models. IEEE Trans. Serv. Comput. (TSC) 1526\u20131539 (2020)","DOI":"10.1109\/TSC.2020.3000900"},{"key":"11_CR58","unstructured":"Wolf, T., et al.: Huggingface\u2019s transformers: state-of-the-art natural language processing. CoRR (2019)"},{"key":"11_CR59","doi-asserted-by":"crossref","unstructured":"Yao, F., Fang, H., Doroslova\u010dki, M., Venkataramani, G.: COTSknight: practical defense against cache timing channel attacks using cache monitoring and partitioning technologies. In: Hardware Oriented Security and Trust (HOST), pp. 121\u2013130 (2019)","DOI":"10.1109\/HST.2019.8740835"},{"key":"11_CR60","unstructured":"Yao, F., Rakin, A.S., Fan, D.: DeepHammer: depleting the intelligence of deep neural networks through targeted chain of bit flips. In: USENIX Security Symposium, pp. 1463\u20131480 (2020)"},{"key":"11_CR61","doi-asserted-by":"crossref","unstructured":"Yao, F., Venkataramani, G., Doroslova\u010dki, M.: Covert timing channels exploiting non-uniform memory access based architectures. In: Proceedings of the on Great Lakes Symposium on VLSI 2017, pp. 155\u2013160 (2017)","DOI":"10.1145\/3060403.3060417"},{"key":"11_CR62","doi-asserted-by":"crossref","unstructured":"Yao, Y., Li, H., Zheng, H., Zhao, B.Y.: Latent backdoor attacks on deep neural networks. In: ACM SIGSAC Conference on Computer and Communications Security (CCS), pp. 2041\u20132055 (2019)","DOI":"10.1145\/3319535.3354209"},{"key":"11_CR63","unstructured":"Yosinski, J., Clune, J., Bengio, Y., Lipson, H.: How transferable are features in deep neural networks? In: Advances in Neural Information Processing Systems (NeurIPS), vol. 27 (2014)"},{"key":"11_CR64","doi-asserted-by":"crossref","unstructured":"Zhang, Z., et al.: Red alarm for pre-trained models: universal vulnerability to neuron-level backdoor attacks. Mach. Intell. Res. 180\u2013193 (2023)","DOI":"10.1007\/s11633-022-1377-5"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-73650-6_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,20]],"date-time":"2024-11-20T19:04:06Z","timestamp":1732129446000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-73650-6_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,21]]},"ISBN":["9783031736490","9783031736506"],"references-count":64,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-73650-6_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024,11,21]]},"assertion":[{"value":"21 November 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}