{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T11:48:37Z","timestamp":1773316117263,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":36,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819562084","type":"print"},{"value":"9789819562091","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-6209-1_13","type":"book-chapter","created":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T02:25:23Z","timestamp":1767320723000},"page":"231-249","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Transferable Dormant Backdoor: Covertly Embedding Transferable Backdoor via\u00a0Knowledge Distillation in\u00a0Pre-trained Models"],"prefix":"10.1007","author":[{"given":"Zhenzhi","family":"Teng","sequence":"first","affiliation":[]},{"given":"Xu","family":"Ma","sequence":"additional","affiliation":[]},{"given":"Xiaoyu","family":"Zhang","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2026,1,2]]},"reference":[{"key":"13_CR1","unstructured":"Ba, L., Caruana, R.: Do deep nets really need to be deep. arXiv:\u00a0Learning (2013)"},{"key":"13_CR2","doi-asserted-by":"crossref","unstructured":"Bucilu\u01ce, C., Caruana, R., Niculescu-Mizil, A.: Model compression. In: Proceedings of the 12th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (2006)","DOI":"10.1145\/1150402.1150464"},{"key":"13_CR3","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Cheng, S., Liu, Y., Ma, S., Zhang, X.: Deep feature space trojan attack of neural networks by controlled detoxification. In: Proceedings of the AAAI Conference on Artificial Intelligence, pp. 1148\u20131156 (2022)","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"13_CR5","first-page":"18944","volume":"34","author":"K Doan","year":"2021","unstructured":"Doan, K., Lao, Y., Li, P.: Backdoor attack with imperceptible input and latent modification. Adv. Neural. Inf. Process. Syst. 34, 18944\u201318957 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"13_CR6","doi-asserted-by":"crossref","unstructured":"Gao, Y., Xu, C., Wang, D., Chen, S., Ranasinghe, D.C., Nepal, S.: STRIP: a defence against trojan attacks on deep neural networks. In: Proceedings of the 35th Annual Computer Security Applications Conference, pp. 113\u2013125 (2019)","DOI":"10.1145\/3359789.3359790"},{"key":"13_CR7","doi-asserted-by":"crossref","unstructured":"Ge, Y., et al.: Anti-distillation backdoor attacks: backdoors can really survive in knowledge distillation. In: Proceedings of the 29th ACM International Conference on Multimedia (2021)","DOI":"10.1145\/3474085.3475254"},{"key":"13_CR8","unstructured":"Gong, X., et al.: Redeem myself: purifying backdoors in deep learning models using self attention distillation"},{"key":"13_CR9","doi-asserted-by":"crossref","unstructured":"Gou, J., Yu, B., Maybank, S.J., Tao, D.: Knowledge distillation: a survey. Int. J. Comput. Vis., 1789\u20131819 (2021)","DOI":"10.1007\/s11263-021-01453-z"},{"key":"13_CR10","doi-asserted-by":"crossref","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: BadNets: evaluating backdooring attacks on deep neural networks. IEEE Access, 47230\u201347244 (2019)","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"He, Y., Xiao, L.: Structured pruning for deep convolutional neural networks: a survey. IEEE Trans. Pattern Anal. Mach. Intell. (2023)","DOI":"10.1109\/TPAMI.2023.3334614"},{"key":"13_CR12","unstructured":"Hinton, G., Vinyals, O., Dean, J.: Distilling the knowledge in a neural network. arXiv:\u00a0Machine Learning (2015)"},{"key":"13_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2024.107677","volume":"166","author":"J Huang","year":"2025","unstructured":"Huang, J., Ma, X., Ma, Y., Chen, K., Zhang, X.: Dual-channel meta-federated graph learning with robust aggregation and privacy enhancement. Futur. Gener. Comput. Syst. 166, 107677 (2025)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"13_CR14","doi-asserted-by":"crossref","unstructured":"Jiang, W., Li, H., Xu, G., Zhang, T.: Color backdoor: a robust poisoning attack in color space. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 8133\u20138142 (2023)","DOI":"10.1109\/CVPR52729.2023.00786"},{"key":"13_CR15","doi-asserted-by":"crossref","unstructured":"Leng, Y., et al.: FastCorrect: fast error correction with edit alignment for automatic speech recognition. Neural Information Processing Systems (2021)","DOI":"10.18653\/v1\/2021.findings-emnlp.367"},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Li, S., Xue, M., Zhao, B., Zhu, H., Zhang, X.: Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Trans. Dependable Secure Comput., 1 (2020)","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"13_CR17","first-page":"1839","volume":"57","author":"S Li","year":"2020","unstructured":"Li, S.: TensorFlow lite: on-device machine learning framework. J. Comput. Res. Dev 57, 1839 (2020)","journal-title":"J. Comput. Res. Dev"},{"key":"13_CR18","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Neural attention distillation: erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930 (2021)"},{"key":"13_CR19","unstructured":"Li, Y., Jiang, Y., Li, Z., Xia, S.T.: Backdoor learning: a survey. IEEE Trans. Neural Netw. Learn. Syst., 1\u201318 (2022)"},{"key":"13_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"K Liu","year":"2018","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: defending against backdooring attacks on deep neural networks. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) RAID 2018. LNCS, vol. 11050, pp. 273\u2013294. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13"},{"key":"13_CR21","doi-asserted-by":"crossref","unstructured":"Liu, Y., et al.: Trojaning attack on neural networks. In: Proceedings 2018 Network and Distributed System Security Symposium (2018)","DOI":"10.14722\/ndss.2018.23291"},{"key":"13_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1007\/978-3-030-58607-2_11","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Y Liu","year":"2020","unstructured":"Liu, Y., Ma, X., Bailey, J., Lu, F.: Reflection backdoor: a natural backdoor attack on deep neural networks. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020, Part X. LNCS, vol. 12355, pp. 182\u2013199. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58607-2_11"},{"key":"13_CR23","unstructured":"Ma, H., Chen, T., Hu, T.K., You, C., Xie, X., Wang, Z.: Undistillable: making a nasty teacher that cannot teach students. In: International Conference on Learning Representations (2021)"},{"issue":"12","key":"13_CR24","doi-asserted-by":"publisher","first-page":"3690","DOI":"10.1109\/TPDS.2022.3167434","volume":"33","author":"X Ma","year":"2022","unstructured":"Ma, X., Sun, X., Wu, Y., Liu, Z., Chen, X., Dong, C.: Differentially private byzantine-robust federated learning. IEEE Trans. Parallel Distrib. Syst. 33(12), 3690\u20133701 (2022)","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"13_CR25","unstructured":"Nayak, G., Mopuri, K., Shaj, V., Radhakrishnan, V., Chakraborty, A.: Zero-shot knowledge distillation in deep networks. In: International Conference on Machine Learning (2019)"},{"key":"13_CR26","doi-asserted-by":"crossref","unstructured":"Peng, B., et al.: Correlation congruence for knowledge distillation. In: 2019 IEEE\/CVF International Conference on Computer Vision (ICCV) (2019)","DOI":"10.1109\/ICCV.2019.00511"},{"key":"13_CR27","doi-asserted-by":"crossref","unstructured":"Qin, H., Gong, R., Liu, X., Bai, X., Song, J., Sebe, N.: Binary neural networks: a survey. Pattern Recognit., 107281 (2020)","DOI":"10.1016\/j.patcog.2020.107281"},{"key":"13_CR28","doi-asserted-by":"crossref","unstructured":"Ren, Y., Li, L., Zhou, J.: Simtrojan: stealthy backdoor attack. In: 2021 IEEE International Conference on Image Processing (ICIP) (2021)","DOI":"10.1109\/ICIP42928.2021.9506313"},{"key":"13_CR29","unstructured":"Romero, A., Ballas, N., Kahou, S., Chassang, A., Gatta, C., Bengio, Y.: FitNets: hints for thin deep nets. arXiv:\u00a0Learning (2014)"},{"issue":"07","key":"13_CR30","first-page":"3897","volume":"10","author":"K Sharifani","year":"2023","unstructured":"Sharifani, K., Amini, M.: Machine learning and deep learning: a review of methods and applications. World Inf. Technol. Eng. J. 10(07), 3897\u20133904 (2023)","journal-title":"World Inf. Technol. Eng. J."},{"key":"13_CR31","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP) (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"13_CR32","doi-asserted-by":"crossref","unstructured":"Wang, H., Xiang, Z., Miller, D.J., Kesidis, G.: MM-BD: post-training detection of backdoor attacks with arbitrary backdoor pattern types using a maximum margin statistic. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 1994\u20132012. IEEE (2024)","DOI":"10.1109\/SP54263.2024.00015"},{"key":"13_CR33","doi-asserted-by":"crossref","unstructured":"Yao, Y., Li, H., Zheng, H., Zhao, B.Y.: Latent backdoor attacks on deep neural networks. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 2041\u20132055 (2019)","DOI":"10.1145\/3319535.3354209"},{"issue":"4","key":"13_CR34","doi-asserted-by":"publisher","first-page":"141","DOI":"10.2299\/jsp.24.141","volume":"24","author":"K Yoshida","year":"2020","unstructured":"Yoshida, K., Fujino, T.: Countermeasure against backdoor attack on neural networks utilizing knowledge distillation. J. Signal Process. 24(4), 141\u2013144 (2020)","journal-title":"J. Signal Process."},{"key":"13_CR35","doi-asserted-by":"crossref","unstructured":"Zhao, Z., Chen, X., Xuan, Y., Dong, Y., Wang, D., Liang, K.: DEFEAT: deep hidden feature backdoor attacks by imperceptible perturbation and latent representation constraints. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 15213\u201315222 (2022)","DOI":"10.1109\/CVPR52688.2022.01478"},{"key":"13_CR36","doi-asserted-by":"crossref","unstructured":"Zhong, H., Liao, C., Squicciarini, A.C., Zhu, S., Miller, D.: Backdoor embedding in convolutional neural network models via invisible perturbation. In: Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy (2020)","DOI":"10.1145\/3374664.3375751"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-6209-1_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T17:42:25Z","timestamp":1773250945000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-6209-1_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819562084","9789819562091"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-6209-1_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"2 January 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Inscrypt","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security and Cryptology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Xi'an","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cisc22025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/inscrypt2025.xidian.edu.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}