{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T03:33:33Z","timestamp":1782790413564,"version":"3.54.5"},"publisher-location":"Singapore","reference-count":22,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819682942","type":"print"},{"value":"9789819682959","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-8295-9_21","type":"book-chapter","created":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T17:47:29Z","timestamp":1750355249000},"page":"290-302","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Beyond Uniformity: Robust Backdoor Attacks on\u00a0Deep Neural Networks with\u00a0Trigger Selection"],"prefix":"10.1007","author":[{"given":"Shixiong","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xingyu","family":"Lyu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ning","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tao","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Danjue","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yimin","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,6,20]]},"reference":[{"key":"21_CR1","unstructured":"Wu, B., et al.: Backdoorbench: a comprehensive benchmark of backdoor learning. In: Proceedings of the 36th International Conference on Neural Information Processing Systems, NIPS 2022, Curran Associates Inc., Red Hook, NY, USA (2022)"},{"key":"21_CR2","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/access.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: Badnets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019). https:\/\/doi.org\/10.1109\/access.2019.2909068","journal-title":"IEEE Access"},{"key":"21_CR3","doi-asserted-by":"publisher","unstructured":"Zeng, Y., Park, W., Mao, Z.M., Jia, R.: Rethinking the backdoor attacks\u2019 triggers: a frequency perspective. In: 2021 IEEE\/CVF International Conference on Computer Vision (ICCV). IEEE (Oct 2021). https:\/\/doi.org\/10.1109\/iccv48922.2021.01616","DOI":"10.1109\/iccv48922.2021.01616"},{"key":"21_CR4","doi-asserted-by":"publisher","unstructured":"Wang, T., Yao, Y., Xu, F., An, S., Tong, H., Wang, T.: An Invisible Black-Box Backdoor Attack Through Frequency Domain, pp. 396-413. Springer Nature Switzerland (2022). https:\/\/doi.org\/10.1007\/978-3-031-19778-9_23","DOI":"10.1007\/978-3-031-19778-9_23"},{"key":"21_CR5","doi-asserted-by":"publisher","unstructured":"Li, C., Pang, R., Xi, Z., Du, T., Ji, S., Yao, Y., Wang, T.: An embarrassingly simple backdoor attack on self-supervised learning. In: 2023 IEEE\/CVF International Conference on Computer Vision (ICCV), pp. 4344-4355. IEEE (Oct 2023).https:\/\/doi.org\/10.1109\/iccv51070.2023.00403","DOI":"10.1109\/iccv51070.2023.00403"},{"key":"21_CR6","doi-asserted-by":"publisher","unstructured":"Selvaraju, R.R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., Batra, D.: Grad-cam: visual explanations from deep networks via gradient-based localization. In: 2017 IEEE International Conference on Computer Vision (ICCV), pp. 618-626. IEEE (Oct 2017). https:\/\/doi.org\/10.1109\/iccv.2017.74","DOI":"10.1109\/iccv.2017.74"},{"key":"21_CR7","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning (2017). https:\/\/arxiv.org\/abs\/1712.05526"},{"key":"21_CR8","unstructured":"Turner, A., Tsipras, D., Madry, A.: Label-consistent backdoor attacks (2019). https:\/\/arxiv.org\/abs\/1912.02771"},{"key":"21_CR9","doi-asserted-by":"publisher","unstructured":"Singha, A., Bi, Z., Li, T., Chen, Y., Zhang, Y.: Securing contrastive mmwave-based human activity recognition against adversarial label flipping. In: Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec 2024, pp. 31-41. , ACM (May 2024). https:\/\/doi.org\/10.1145\/3643833.3656123","DOI":"10.1145\/3643833.3656123"},{"key":"21_CR10","doi-asserted-by":"publisher","unstructured":"Guo, H., Chen, X., Guo, J., Xiao, L., Yan, Q.: Masterkey: practical backdoor attack against speaker verification systems. In: Proceedings of the 29th Annual International Conference on Mobile Computing and Networking, ACM MobiCom 2023. pp. 1-15. ACM (Oct 2023). https:\/\/doi.org\/10.1145\/3570361.3613261","DOI":"10.1145\/3570361.3613261"},{"key":"21_CR11","unstructured":"Nguyen, T.A., Tran, T.A.: Input-aware dynamic backdoor attack. In: Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS 2020, Curran Associates Inc., Red Hook, NY, USA (2020)"},{"key":"21_CR12","unstructured":"Hayase, J., Kong, W., Somani, R., Oh, S.: Spectre: defending against backdoor attacks using robust statistics. In: Meila, M., Zhang, T. (eds.) Proceedings of the 38th International Conference on Machine Learning. Proceedings of Machine Learning Research, 18\u201324 Jul, vol.\u00a0139, pp. 4129\u20134139. PMLR (2021). https:\/\/proceedings.mlr.press\/v139\/hayase21a.html"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Ma, W., Wang, D., Sun, R., Xue, M., Wen, S., Xiang, Y.: The \"beatrix\" resurrections: robust backdoor detection via gram matrices. In: 30th Annual Network and Distributed System Security Symposium, NDSS (2023)","DOI":"10.14722\/ndss.2023.23069"},{"key":"21_CR14","unstructured":"Pan, M., Zeng, Y., Lyu, L., Lin, X., Jia, R.: ASSET: robust backdoor data detection across a multiplicity of deep learning paradigms. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 2725\u20132742. USENIX Association, Anaheim, CA (Aug 2023). https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/pan"},{"key":"21_CR15","doi-asserted-by":"publisher","unstructured":"Wang, N., Xiao, Y., Chen, Y., Hu, Y., Lou, W., Hou, Y.T.: Flare: defending federated learning against model poisoning attacks via latent space representations. In: Proceedings of the 2022 ACM on Asia Conference on Computer and Communications Security, ASIA CCS 2022, pp. 946-958. ACM (May 2022). https:\/\/doi.org\/10.1145\/3488932.3517395","DOI":"10.1145\/3488932.3517395"},{"key":"21_CR16","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Neural attention distillation: erasing backdoor triggers from deep neural networks. In: International Conference on Learning Representations (2021). https:\/\/openreview.net\/forum?id=9l0K4OM-oXE"},{"key":"21_CR17","unstructured":"Zheng, R., Tang, R., Li, J., Liu, L.: Pre-activation distributions expose backdoor neurons. In: Koyejo, S., Mohamed, S., Agarwal, A., Belgrave, D., Cho, K., Oh, A. (eds.) Advances in Neural Information Processing Systems, vol.\u00a035, pp. 18667\u201318680. Curran Associates, Inc. (2022)"},{"key":"21_CR18","doi-asserted-by":"publisher","unstructured":"Gao, K., Bai, Y., Gu, J., Yang, Y., Xia, S.T.: Backdoor defense via adaptively splitting poisoned dataset. In: 2023 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE (Jun 2023). https:\/\/doi.org\/10.1109\/cvpr52729.2023.00390","DOI":"10.1109\/cvpr52729.2023.00390"},{"key":"21_CR19","unstructured":"Guo, J., Li, Y., Chen, X., Guo, H., Sun, L., Liu, C.: SCALE-UP: an efficient black-box input-level backdoor detection via analyzing scaled prediction consistency. In: The Eleventh International Conference on Learning Representations (2023). https:\/\/openreview.net\/forum?id=o0LFPcoFKnr"},{"key":"21_CR20","doi-asserted-by":"publisher","unstructured":"Eberhart, R., Kennedy, J.: A new optimizer using particle swarm theory. In: MHS 1995. Proceedings of the Sixth International Symposium on Micro Machine and Human Science, MHS 1995, pp. 39-43. IEEE. https:\/\/doi.org\/10.1109\/mhs.1995.494215","DOI":"10.1109\/mhs.1995.494215"},{"key":"21_CR21","unstructured":"Nguyen, T.A., Tran, A.T.: Wanet - imperceptible warping-based backdoor attack. In: International Conference on Learning Representations (2021). https:\/\/openreview.net\/forum?id=eEn8KTtJOx"},{"key":"21_CR22","doi-asserted-by":"publisher","unstructured":"Wang, Z., Zhai, J., Ma, S.: Bppattack: stealthy and efficient trojan attacks against deep neural networks via image quantization and contrastive adversarial learning. In: 2022 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 15054-15063. IEEE (Jun 2022). https:\/\/doi.org\/10.1109\/cvpr52688.2022.01465","DOI":"10.1109\/cvpr52688.2022.01465"}],"container-title":["Lecture Notes in Computer Science","Data Science: Foundations and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-8295-9_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T17:47:35Z","timestamp":1750355255000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-8295-9_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819682942","9789819682959"],"references-count":22,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-8295-9_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"20 June 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"PAKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Pacific-Asia Conference on Knowledge Discovery and Data Mining","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sydney, NSW","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 June 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 June 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"pakdd2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/pakdd2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}