{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,4]],"date-time":"2025-11-04T16:22:57Z","timestamp":1762273377972,"version":"3.40.3"},"publisher-location":"Singapore","reference-count":51,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789819601158"},{"type":"electronic","value":"9789819601165"}],"license":[{"start":{"date-parts":[[2024,11,12]],"date-time":"2024-11-12T00:00:00Z","timestamp":1731369600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,11,12]],"date-time":"2024-11-12T00:00:00Z","timestamp":1731369600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-0116-5_18","type":"book-chapter","created":{"date-parts":[[2024,11,16]],"date-time":"2024-11-16T18:29:54Z","timestamp":1731781794000},"page":"221-235","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["BDEL: A Backdoor Attack Defense Method Based on\u00a0Ensemble Learning"],"prefix":"10.1007","author":[{"given":"Zhihuan","family":"Xing","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuqing","family":"Lan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yin","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yong","family":"Cao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoyi","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yichun","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,11,12]]},"reference":[{"key":"18_CR1","doi-asserted-by":"crossref","unstructured":"Ando, A., Gidaris, S., Bursuc, A., Puy, G., Boulch, A., Marlet, R.: Rangevit: towards vision transformers for 3d semantic segmentation in autonomous driving. In: CVPR 2023, Vancouver, BC, Canada, 17\u201324 June 2023, pp. 5240\u20135250 (2023)","DOI":"10.1109\/CVPR52729.2023.00507"},{"key":"18_CR2","doi-asserted-by":"crossref","unstructured":"Barni, M., Kallas, K., Tondi, B.: A new backdoor attack in CNNS by training set corruption without label poisoning. In: ICIP 2019, pp. 101\u2013105 (2019)","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"18_CR3","doi-asserted-by":"publisher","unstructured":"Bejnordi, B.E., Habibian, A., Porikli, F., Ghodrati, A.: SALISA: saliency-based input sampling for efficient video object detection. In: ECCV 2022. vol. 13670, pp. 300\u2013316. Springer, Heidelberg (2022). https:\/\/doi.org\/10.1007\/978-3-031-20080-9_18","DOI":"10.1007\/978-3-031-20080-9_18"},{"key":"18_CR4","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1007\/BF00058655","volume":"24","author":"L Breiman","year":"1996","unstructured":"Breiman, L.: Bagging predictors. Mach. Learn. 24, 123\u2013140 (1996)","journal-title":"Mach. Learn."},{"key":"18_CR5","doi-asserted-by":"crossref","unstructured":"Chai, J.C.L., Ng, T., Low, C., Park, J., Teoh, A.B.J.: Recognizability embedding enhancement for very low-resolution face recognition and quality estimation. In: CVPR 2023, pp. 9957\u20139967 (2023)","DOI":"10.1109\/CVPR52729.2023.00960"},{"key":"18_CR6","unstructured":"Chen, B., et al.: Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018)"},{"key":"18_CR7","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)"},{"key":"18_CR8","doi-asserted-by":"crossref","unstructured":"Cheng, S., Liu, Y., Ma, S., Zhang, X.: Deep feature space trojan attack of neural networks by controlled detoxification. In: AAAI 2021, pp. 1148\u20131156 (2021)","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"18_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/3-540-45014-9_1","volume-title":"Multiple Classifier Systems","author":"TG Dietterich","year":"2000","unstructured":"Dietterich, T.G.: Ensemble methods in machine learning. In: Kittler, J., Roli, F. (eds.) MCS 2000. LNCS, vol. 1857, pp. 1\u201315. Springer, Heidelberg (2000). https:\/\/doi.org\/10.1007\/3-540-45014-9_1"},{"key":"18_CR10","unstructured":"Doan, K.D., Lao, Y., Li, P.: Backdoor attack with imperceptible input and latent modification. In: Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, NeurIPS 2021, 6\u201314 December 2021, virtual, pp. 18944\u201318957 (2021)"},{"key":"18_CR11","doi-asserted-by":"crossref","unstructured":"Gao, Y., Xu, C., Wang, D., Chen, S., Ranasinghe, D.C., Nepal, S.: STRIP: a defence against trojan attacks on deep neural networks. In: Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC 2019, San Juan, PR, USA, 09\u201313 December 2019, pp. 113\u2013125. ACM","DOI":"10.1145\/3359789.3359790"},{"key":"18_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109512","volume":"139","author":"Y Gao","year":"2023","unstructured":"Gao, Y., Li, Y., Zhu, L., Wu, D., Jiang, Y., Xia, S.: Not all samples are born equal: towards effective clean-label backdoor attacks. Pattern Recogn. 139, 109512 (2023)","journal-title":"Pattern Recogn."},{"key":"18_CR13","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: Badnets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019)","journal-title":"IEEE Access"},{"issue":"10","key":"18_CR14","doi-asserted-by":"publisher","first-page":"993","DOI":"10.1109\/34.58871","volume":"12","author":"LK Hansen","year":"1990","unstructured":"Hansen, L.K., Salamon, P.: Neural network ensembles. IEEE Trans. Pattern Anal. Mach. Intell. 12(10), 993\u20131001 (1990)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"18_CR15","doi-asserted-by":"crossref","unstructured":"Hu, X., et al.: Practical attacks on deep neural networks by memory trojaning. IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 40(6), 1230\u20131243 (2021)","DOI":"10.1109\/TCAD.2020.2995347"},{"key":"18_CR16","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der\u00a0Maaten, L., Weinberger, K.Q.: Densely connected convolutional networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 4700\u20134708 (2017)","DOI":"10.1109\/CVPR.2017.243"},{"key":"18_CR17","doi-asserted-by":"crossref","unstructured":"Jia, J., Cao, X., Gong, N.Z.: Intrinsic certified robustness of bagging against data poisoning attacks. In: AAAI 2021, vol.\u00a035, pp. 7961\u20137969 (2021)","DOI":"10.1609\/aaai.v35i9.16971"},{"key":"18_CR18","unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)"},{"issue":"2","key":"18_CR19","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1023\/A:1022859003006","volume":"51","author":"LI Kuncheva","year":"2003","unstructured":"Kuncheva, L.I., Whitaker, C.J.: Measures of diversity in classifier ensembles and their relationship with the ensemble accuracy. Mach. Learn. 51(2), 181\u2013207 (2003)","journal-title":"Mach. Learn."},{"issue":"11","key":"18_CR20","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun, Y., Bottou, L., Bengio, Y., Haffner, P.: Gradient-based learning applied to document recognition. Proc. IEEE 86(11), 2278\u20132324 (1998)","journal-title":"Proc. IEEE"},{"issue":"5","key":"18_CR21","first-page":"2088","volume":"18","author":"S Li","year":"2021","unstructured":"Li, S., Xue, M., Zhao, B.Z.H., Zhu, H., Zhang, X.: Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Trans. Dependable Secur. Comput. 18(5), 2088\u20132105 (2021)","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"18_CR22","first-page":"14900","volume":"34","author":"Y Li","year":"2021","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Anti-backdoor learning: training clean models on poisoned data. Adv. Neural. Inf. Process. Syst. 34, 14900\u201314912 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"18_CR23","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Neural attention distillation: erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930 (2021)"},{"key":"18_CR24","unstructured":"Li, Y., et al.: Reconstructive neuron pruning for backdoor defense. In: ICML, pp. 19837\u201319854 (2023)"},{"key":"18_CR25","doi-asserted-by":"crossref","unstructured":"Li, Y.: Poisoning-based backdoor attacks in computer vision. In: AAAI (2023)","DOI":"10.1609\/aaai.v37i13.26921"},{"key":"18_CR26","unstructured":"Li, Y., Zhai, T., Wu, B., Jiang, Y., Li, Z., Xia, S.: Rethinking the trigger of backdoor attack. CoRR arxiv:2004.04692 (2020)"},{"key":"18_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"K Liu","year":"2018","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: defending against backdooring attacks on deep neural networks. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) RAID 2018. LNCS, vol. 11050, pp. 273\u2013294. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13"},{"key":"18_CR28","doi-asserted-by":"crossref","unstructured":"Liu, Y., Lee, W., Tao, G., Ma, S., Aafer, Y., Zhang, X.: ABS: scanning neural networks for back-doors by artificial brain stimulation. In: CCS 2019, pp. 1265\u20131282 (2019)","DOI":"10.1145\/3319535.3363216"},{"key":"18_CR29","doi-asserted-by":"publisher","unstructured":"Liu, Y., Ma, X., Bailey, J., Lu, F.: Reflection backdoor: a natural backdoor attack on deep neural networks. In: ECCV 2020, vol. 12355, pp. 182\u2013199. Springer, Heidelberg (2020). https:\/\/doi.org\/10.1007\/978-3-030-58607-2_11","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"18_CR30","unstructured":"Nguyen, A., Tran, A.: Wanet\u2013imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369 (2021)"},{"key":"18_CR31","unstructured":"Nguyen, T.A., Tran, A.T.: Input-aware dynamic backdoor attack. In: Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, 6\u201312 December 2020, virtual (2020)"},{"key":"18_CR32","unstructured":"Pang, T., Xu, K., Du, C., Chen, N., Zhu, J.: Improving adversarial robustness via promoting ensemble diversity. In: ICML, pp. 4970\u20134979 (2019)"},{"key":"18_CR33","unstructured":"Qi, X., Xie, T., Li, Y., Mahloujifar, S., Mittal, P.: Circumventing backdoor defenses that are based on latent separability. arXiv preprint arXiv:2205.13613 (2022)"},{"key":"18_CR34","doi-asserted-by":"crossref","unstructured":"Ren, Y., Li, L., Zhou, J.: Simtrojan: stealthy backdoor attack. In: ICIP 2021, pp. 819\u2013823 (2021)","DOI":"10.1109\/ICIP42928.2021.9506313"},{"key":"18_CR35","unstructured":"Shokri, R., et\u00a0al.: Bypassing backdoor detection algorithms in deep learning. In: 2020 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 175\u2013183. IEEE (2020)"},{"key":"18_CR36","doi-asserted-by":"crossref","unstructured":"Sinha, S., Bharadhwaj, H., Goyal, A., Larochelle, H., Garg, A., Shkurti, F.: Dibs: diversity inducing information bottleneck in model ensembles. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a035, pp. 9666\u20139674 (2021)","DOI":"10.1609\/aaai.v35i11.17163"},{"key":"18_CR37","doi-asserted-by":"crossref","unstructured":"Szegedy, C., et al.: Going deeper with convolutions. In: CVPR 2015, pp.\u00a01\u20139 (2015)","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"18_CR38","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., Wojna, Z.: Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2818\u20132826 (2016)","DOI":"10.1109\/CVPR.2016.308"},{"key":"18_CR39","unstructured":"Tran, B., Li, J., Madry, A.: Spectral signatures in backdoor attacks. Adv. Neural Inf. Process. Syst. 31 (2018)"},{"key":"18_CR40","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, 19\u201323 May 2019, pp. 707\u2013723 (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"18_CR41","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 707\u2013723. IEEE (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"18_CR42","first-page":"36026","volume":"35","author":"H Wang","year":"2022","unstructured":"Wang, H., Hong, J., Zhang, A., Zhou, J., Wang, Z.: Trap and replace: defending backdoor attacks by trapping them into an easy-to-replace subnetwork. Adv. Neural. Inf. Process. Syst. 35, 36026\u201336039 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"18_CR43","unstructured":"Wen, Y., Tran, D., Ba, J.: Batchensemble: an alternative approach to efficient ensemble and lifelong learning. In: 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, 26\u201330 April 2020. OpenReview.net (2020)"},{"key":"18_CR44","first-page":"10546","volume":"35","author":"B Wu","year":"2022","unstructured":"Wu, B., et al.: Backdoorbench: a comprehensive benchmark of backdoor learning. Adv. Neural. Inf. Process. Syst. 35, 10546\u201310559 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"18_CR45","first-page":"16913","volume":"34","author":"D Wu","year":"2021","unstructured":"Wu, D., Wang, Y.: Adversarial neuron pruning purifies backdoored deep models. Adv. Neural. Inf. Process. Syst. 34, 16913\u201316925 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"issue":"3","key":"18_CR46","doi-asserted-by":"publisher","first-page":"1562","DOI":"10.1109\/TDSC.2020.3028448","volume":"19","author":"M Xue","year":"2020","unstructured":"Xue, M., He, C., Wang, J., Liu, W.: One-to-n & n-to-one: two advanced backdoor attacks against deep learning models. IEEE Trans. Dependable Secure Comput. 19(3), 1562\u20131578 (2020)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"17","key":"18_CR47","doi-asserted-by":"publisher","first-page":"20402","DOI":"10.1007\/s10489-023-04575-8","volume":"53","author":"M Xue","year":"2023","unstructured":"Xue, M., Wang, X., Sun, S., Zhang, Y., Wang, J., Liu, W.: Compression-resistant backdoor attack against deep neural networks. Appl. Intell. 53(17), 20402\u201320417 (2023)","journal-title":"Appl. Intell."},{"key":"18_CR48","doi-asserted-by":"crossref","unstructured":"Yu, Y., Wang, Y., Yang, W., Lu, S., Tan, Y., Kot, A.C.: Backdoor attacks against deep image compression via adaptive frequency trigger. In: CVPR 2023, pp. 12250\u201312259 (2023)","DOI":"10.1109\/CVPR52729.2023.01179"},{"key":"18_CR49","doi-asserted-by":"publisher","first-page":"5691","DOI":"10.1109\/TIP.2022.3201472","volume":"31","author":"J Zhang","year":"2022","unstructured":"Zhang, J., et al.: Poison ink: robust and invisible backdoor attack. IEEE Trans. Image Process. 31, 5691\u20135705 (2022)","journal-title":"IEEE Trans. Image Process."},{"key":"18_CR50","unstructured":"Zhao, P., Chen, P., Das, P., Ramamurthy, K.N., Lin, X.: Bridging mode connectivity in loss landscapes and adversarial robustness. In: 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia 26\u201330 April 2020. OpenReview.net (2020)"},{"key":"18_CR51","doi-asserted-by":"crossref","unstructured":"Zhong, H., Liao, C., Squicciarini, A.C., Zhu, S., Miller, D.J.: Backdoor embedding in convolutional neural network models via invisible perturbation. In: CODASPY \u201920: Tenth ACM Conference on Data and Application Security and Privacy, New Orleans, LA, USA, 16\u201318 March 2020, pp. 97\u2013108 (2020)","DOI":"10.1145\/3374664.3375751"}],"container-title":["Lecture Notes in Computer Science","PRICAI 2024: Trends in Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-0116-5_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,16]],"date-time":"2024-11-16T19:13:55Z","timestamp":1731784435000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-0116-5_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,12]]},"ISBN":["9789819601158","9789819601165"],"references-count":51,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-0116-5_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024,11,12]]},"assertion":[{"value":"12 November 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"PRICAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Pacific Rim International Conference on Artificial Intelligence","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Kyoto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 November 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 November 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"pricai2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.pricai.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}