{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T20:50:45Z","timestamp":1773089445266,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":19,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819698714","type":"print"},{"value":"9789819698721","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-9872-1_18","type":"book-chapter","created":{"date-parts":[[2025,7,23]],"date-time":"2025-07-23T14:35:12Z","timestamp":1753281312000},"page":"216-226","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Frequency-Aware Purification: A Black-Box Defense Against Backdoor Attacks"],"prefix":"10.1007","author":[{"given":"Jie","family":"Sun","sequence":"first","affiliation":[]},{"given":"Xu","family":"Ma","sequence":"additional","affiliation":[]},{"given":"Xiaoyu","family":"Zhang","sequence":"additional","affiliation":[]},{"given":"Youmei","family":"Wang","sequence":"additional","affiliation":[]},{"given":"Zhenzhi","family":"Teng","sequence":"additional","affiliation":[]},{"given":"Lingling","family":"Xu","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2025,7,24]]},"reference":[{"key":"#cr-split#-18_CR1.1","doi-asserted-by":"crossref","unstructured":"Wang, B., Yao, Y., Shan, S. et al.: Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In 2019 IEEE Symposium on Security and Privacy","DOI":"10.1109\/SP.2019.00031"},{"key":"#cr-split#-18_CR1.2","unstructured":"(SP) (pp. 707-723). IEEE. (2019)"},{"key":"18_CR2","doi-asserted-by":"publisher","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: defending against backdooring attacks on deep neural networks. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) Research in Attacks, Intrusions, and Defenses. RAID 2018. Lecture Notes in Computer Science, vol. 11050, pp. 273\u2013294. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"18_CR3","unstructured":"Pan, M., Zeng, Y., Lyu, L. et al.: ASSET: robust backdoor data detection across a multiplicity of deep learning paradigms. In: Proceedings of the 32nd USENIX Security Symposium (USENIX Security 2023), pp. 2725\u20132742 (2023)"},{"key":"18_CR4","doi-asserted-by":"publisher","first-page":"350","DOI":"10.1016\/j.neunet.2023.09.036","volume":"168","author":"B Ma","year":"2023","unstructured":"Ma, B., Wang, J., Wang, D., Meng, B.: Multidomain active defense: detecting multidomain backdoor poisoned samples via ALL-to-ALL decoupling training without clean datasets. Neural Netw. 168, 350\u2013362 (2023)","journal-title":"Neural Netw."},{"key":"18_CR5","first-page":"57336","volume":"36","author":"Y Shi","year":"2023","unstructured":"Shi, Y., Du, M., Wu, X., et al.: Black-box backdoor defense via zero-shot image purification. Adv. Neural. Inf. Process. Syst. 36, 57336\u201357366 (2023)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"18_CR6","doi-asserted-by":"crossref","unstructured":"Zhou, J., Lv, P., Lan, Y. et al.: DataElixir: purifying poisoned dataset to mitigate backdoor attacks via diffusion models. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 38(19), pp. 21850\u201321858 (2024)","DOI":"10.1609\/aaai.v38i19.30186"},{"key":"18_CR7","unstructured":"Li, Y., Zhai, T., Wu, B., et al.: Rethinking the trigger of backdoor attack. arXiv preprint arXiv:2004.04692 (2020)"},{"key":"18_CR8","unstructured":"Liu, Z., Zhao, Z., Larson, M.: Image shortcut squeezing: countering perturbative availability poisons with compression. In: International Conference on Machine Learning, pp. 22473\u201322487. PMLR (2023)"},{"key":"18_CR9","unstructured":"Petsiuk, V., Das, A., Saenko, K.: RISE: Randomized input sampling for explanation of black-box models. arXiv preprint arXiv:1806.07421. (2018)"},{"key":"18_CR10","first-page":"6840","volume":"33","author":"J Ho","year":"2020","unstructured":"Ho, J., Jain, A., Abbeel, P.: Denoising diffusion probabilistic models. Adv. Neural. Inf. Process. Syst. 33, 6840\u20136851 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"18_CR11","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: BadNets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019)","journal-title":"IEEE Access"},{"key":"18_CR12","unstructured":"Bagdasaryan, E., Shmatikov, V.: Blind backdoors in deep learning models. In: Proceedings of the 30th USENIX Security Symposium (USENIX Security 2021), pp. 1505\u20131521 (2021)"},{"key":"18_CR13","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, S., Aafer, Y., et al.: Trojaning attack on neural networks. In: Proceedings of the 25th Annual Network and Distributed System Security Symposium (NDSS 2018). Internet Soc. (2018)","DOI":"10.14722\/ndss.2018.23291"},{"key":"18_CR14","doi-asserted-by":"crossref","unstructured":"Barni, M., Kallas, K., Tondi, B.: A new backdoor attack in CNNs by training set corruption without label poisoning. In: Proceedings of the 2019 IEEE International Conference on Image Processing (ICIP), pp. 101\u2013105. IEEE (2019)","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"18_CR15","doi-asserted-by":"crossref","unstructured":"Li, Y., Li, Y., Wu, B. et al.: Invisible backdoor attack with sample-specific triggers. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 16463\u201316472 (2021)","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"18_CR16","unstructured":"Nguyen, A., Tran, A.: WaNet\u2014Imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369 (2021)"},{"key":"18_CR17","doi-asserted-by":"crossref","unstructured":"Wang, Z., Zhai, J., Ma, S.: BppAttack: stealthy and efficient Trojan attacks against deep neural networks via image quantization and contrastive adversarial learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 15074\u201315084 (2022)","DOI":"10.1109\/CVPR52688.2022.01465"},{"key":"18_CR18","first-page":"3454","volume":"33","author":"TA Nguyen","year":"2020","unstructured":"Nguyen, T.A., Tran, A.: Input-aware dynamic backdoor attack. Adv. Neural. Inf. Process. Syst. 33, 3454\u20133464 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."}],"container-title":["Lecture Notes in Computer Science","Advanced Intelligent Computing Technology and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-9872-1_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T06:23:24Z","timestamp":1770186204000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-9872-1_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819698714","9789819698721"],"references-count":19,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-9872-1_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"24 July 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICIC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Intelligent Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Ningbo","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icic2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ic-icc.cn\/icg\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}