{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T11:06:10Z","timestamp":1779793570504,"version":"3.53.1"},"reference-count":59,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T00:00:00Z","timestamp":1773014400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T00:00:00Z","timestamp":1773014400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Leading Goose Research","award":["2023C03180"],"award-info":[{"award-number":["2023C03180"]}]},{"DOI":"10.13039\/501100004731","name":"Natural Science Foundation of Zhejiang Province","doi-asserted-by":"publisher","award":["LQN26F020052"],"award-info":[{"award-number":["LQN26F020052"]}],"id":[{"id":"10.13039\/501100004731","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Laboratory for Sensitive Data Security Protection and Confidentiality Management","award":["2024E10048"],"award-info":[{"award-number":["2024E10048"]}]},{"name":"the Major Breakthrough Project of the Hang zhou Institute for Advanced Study","award":["2024ZZ282130"],"award-info":[{"award-number":["2024ZZ282130"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2026,4]]},"DOI":"10.1007\/s10489-026-07156-7","type":"journal-article","created":{"date-parts":[[2026,3,9]],"date-time":"2026-03-09T08:33:28Z","timestamp":1773045208000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["FBAO: backdoor attack against object detection via frequency noise injection"],"prefix":"10.1007","volume":"56","author":[{"given":"Qiuhua","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haojie","family":"Shen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4261-9146","authenticated-orcid":false,"given":"Lin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lifeng","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yizhi","family":"Ren","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiyuan","family":"Jia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shuochao","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weizhi","family":"Meng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,3,9]]},"reference":[{"key":"7156_CR1","doi-asserted-by":"crossref","unstructured":"Zou Z, Chen K, Shi Z, Guo Y, Ye J (2023) Object detection in 20 years: A survey. In: Proceedings of the IEEE","DOI":"10.1109\/JPROC.2023.3238524"},{"key":"7156_CR2","doi-asserted-by":"crossref","unstructured":"Diwan T, Anirudh G, Tembhurne JV (2023) Object detection using yolo: Challenges, architectural successors, datasets and applications. Multimed Tools Appl","DOI":"10.1007\/s11042-022-13644-y"},{"key":"7156_CR3","doi-asserted-by":"crossref","unstructured":"Zhao Y, Lv W, Xu S, Wei J, Wang G, Dang Q, Liu Y, Chen J (2024) Detrs beat yolos on real-time object detection. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR52733.2024.01605"},{"key":"7156_CR4","doi-asserted-by":"crossref","unstructured":"Wang L, Zhang W, Wu D, Zhu F, Li B (2022) Attack is the best defense: Towards preemptive-protection person re-identification. In: Proceedings of the 30th ACM international conference on multimedia, pp 550\u2013559","DOI":"10.1145\/3503161.3547958"},{"key":"7156_CR5","doi-asserted-by":"crossref","unstructured":"Wang L, Zhang W, Wu D, Hong P, Li B (2022) Prototype-based inter-camera learning for person re-identification. In: ICASSP 2022\u20132022 IEEE international conference on acoustics, speech and signal processing (ICASSP). IEEE, pp 4778\u20134782","DOI":"10.1109\/ICASSP43922.2022.9746640"},{"key":"7156_CR6","doi-asserted-by":"crossref","unstructured":"Gu T, Liu K, DolanGavitt B, Garg S (2019) Badnets: Evaluating backdooring attacks on deep neural networks. IEEE Access","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"7156_CR7","unstructured":"Li Y, Jiang Y, Li Z, Xia S (2022) Backdoor learning: A survey. IEEE Trans Neural Netw Learn Syst"},{"key":"7156_CR8","unstructured":"Nguyen TA, Tran AT (2020) Wanet-imperceptible warping-based backdoor attack. In: International conference on learning representations"},{"key":"7156_CR9","doi-asserted-by":"crossref","unstructured":"Li Y, Bai Y, Jiang Y, Yang Y, Xia S, Li B (2022) Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection. Adv Neural Inf Process Syst","DOI":"10.52202\/068431-0962"},{"key":"7156_CR10","doi-asserted-by":"crossref","unstructured":"Chan S, Dong Y, Zhu J, Zhang X, Zhou J (2022) Baddet: Backdoor attacks on object detection. In: European conference on computer vision","DOI":"10.1007\/978-3-031-25056-9_26"},{"key":"7156_CR11","unstructured":"Cheng Y, Hu W, Cheng M (2023) Backdoor attack against object detection with clean annotation. arXiv preprint arXiv:2307.10487"},{"key":"7156_CR12","doi-asserted-by":"crossref","unstructured":"Ma H, Li Y, Gao Y, Zhang Z, Abuadbba A, Fu A, AlSarawi SF, Surya N, Abbott D (2022) Macab: Model-agnostic clean-annotation backdoor to object detection with natural trigger in real-world. arXiv preprint arXiv:2209.02339","DOI":"10.1109\/SRDS60354.2023.00018"},{"key":"7156_CR13","unstructured":"Chen X, Liu C, Li B, Lu K, Song D (2017) Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526"},{"key":"7156_CR14","doi-asserted-by":"crossref","unstructured":"Li Y, Li Y, Wu B, Li L, He R, Lyu S (2021) Invisible backdoor attack with sample-specific triggers. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"7156_CR15","doi-asserted-by":"crossref","unstructured":"Liu Y, Ma X, Bailey J, Lu F (2020) Reflection backdoor: A natural backdoor attack on deep neural networks. In: European Conference on Computer Vision","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"7156_CR16","doi-asserted-by":"crossref","unstructured":"Liang M, Su J, Schulter S, Garg S, Zhao S, Wu Y, Chandraker M (2024) Aide: An automatic data engine for object detection in autonomous driving. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR52733.2024.01392"},{"key":"7156_CR17","doi-asserted-by":"crossref","unstructured":"Althoupety A, Wang L, Feng W, Rekabdar B (2024) Daff: Dual attentive feature fusion for multispectral pedestrian detection. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPRW63382.2024.00305"},{"key":"7156_CR18","doi-asserted-by":"crossref","unstructured":"Ouardirhi Z, Mahmoudi SA, Zbakh M (2024) Enhancing object detection in smart video surveillance: A survey of occlusion-handling approaches. Electronics","DOI":"10.3390\/electronics13030541"},{"key":"7156_CR19","unstructured":"Viola P, Jones M (2001) Rapid object detection using a boosted cascade of simple features. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition"},{"key":"7156_CR20","unstructured":"Dalal N, Triggs B (2005) Histograms of oriented gradients for human detection. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition"},{"key":"7156_CR21","doi-asserted-by":"crossref","unstructured":"Felzenszwalb P, McAllester D, Ramanan D (2008) A discriminatively trained, multiscale, deformable part model. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR.2008.4587597"},{"key":"7156_CR22","doi-asserted-by":"crossref","unstructured":"Felzenszwalb PF, Girshick RB, McAllester D (2010) Cascade object detection with deformable part models. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR.2010.5539906"},{"key":"7156_CR23","doi-asserted-by":"crossref","unstructured":"Malisiewicz, T., Gupta, A., Efros, A.A.: Ensemble of exemplar-svms for object detection and beyond. In: 2011 International Conference on Computer Vision (2011)","DOI":"10.1109\/ICCV.2011.6126229"},{"key":"7156_CR24","unstructured":"Ren S, He K, Girshick R, Sun J (2015) Faster r-cnn: Towards real-time object detection with region proposal networks. Adv Neural Inf Process Syst"},{"key":"7156_CR25","unstructured":"Dai J, Li Y, He K, Sun J (2016) R-fcn: Object detection via region-based fully convolutional networks. Adv Neural Inf Process Syst"},{"key":"7156_CR26","doi-asserted-by":"crossref","unstructured":"He K, Gkioxari G, Doll\u00e1r P, Girshick R (2017) Mask r-cnn. In: Proceedings of the IEEE international conference on computer vision","DOI":"10.1109\/ICCV.2017.322"},{"key":"7156_CR27","doi-asserted-by":"crossref","unstructured":"Redmon J, Divvala S, Girshick R, Farhadi A (2016) You only look once: Unified, real-time object detection. In: Proceedings of the IEEE conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR.2016.91"},{"key":"7156_CR28","unstructured":"Redmon J, Farhadi A (2018) Yolov3: An incremental improvement. arXiv preprint arXiv:1804.02767"},{"key":"7156_CR29","unstructured":"Bochkovskiy A, Wang C, Liao HM (2020) Yolov4: Optimal speed and accuracy of object detection. arXiv preprint arXiv:2004.10934"},{"key":"7156_CR30","doi-asserted-by":"crossref","unstructured":"Liu W, Anguelov D, Erhan D, Szegedy C, Reed S, Fu C, Berg AC (2016) Ssd: Single shot multibox detector. In: European conference on computer vision","DOI":"10.1007\/978-3-319-46448-0_2"},{"key":"7156_CR31","doi-asserted-by":"crossref","unstructured":"Lin T, Goyal P, Girshick R, He K, Doll\u00e1r P (2017) Focal loss for dense object detection. In: Proceedings of the IEEE international conference on computer vision","DOI":"10.1109\/ICCV.2017.324"},{"key":"7156_CR32","doi-asserted-by":"crossref","unstructured":"Fan J, Yan Q, Li M, Qu G, Xiao Y (2022) A survey on data poisoning attacks and defenses. In: IEEE international conference on data science in cyberspace (DSC)","DOI":"10.1109\/DSC55868.2022.00014"},{"key":"7156_CR33","doi-asserted-by":"crossref","unstructured":"Wang L, Zhang W, Wu D, Zhu F, Li B (2022) Attack is the best defense: Towards preemptive-protection person re-identification. In: Proceedings of the 30th ACM international conference on multimedia","DOI":"10.1145\/3503161.3547958"},{"key":"7156_CR34","doi-asserted-by":"crossref","unstructured":"Chakraborty A, Alam M, Dey V, Chattopadhyay A, Mukhopadhyay D (2021) A survey on adversarial attacks and defences. CAAI Tran Intell Technol","DOI":"10.1049\/cit2.12028"},{"key":"7156_CR35","unstructured":"Zhang K, Tao G, Xu Q, Cheng S, An S, Liu Y, Feng S, Shen G, Chen P, Ma S et al (2023) Flip: A provable defense framework for backdoor mitigation in federated learning. In: International conference on learning representations"},{"key":"7156_CR36","unstructured":"Jiang W, Zhang T, Qiu H, Li H, Xu G (2022) Incremental learning, incremental backdoor threats. IEEE Trans Depend Secure Comput"},{"key":"7156_CR37","doi-asserted-by":"crossref","unstructured":"Bharti S, Zhang X, Singla A, Zhu J (2022) Provable defense against backdoor policies in reinforcement learning. Adv Neural Inf Process Syst","DOI":"10.52202\/068431-1069"},{"key":"7156_CR38","doi-asserted-by":"crossref","unstructured":"Liu Y, Lee W, Tao G, Ma S, Aafer Y, Zhang X (2019) Abs: Scanning neural networks for backdoors by artificial brain stimulation. In: Proceedings of the ACM SIGSAC conference on computer and communications security","DOI":"10.1145\/3319535.3363216"},{"key":"7156_CR39","doi-asserted-by":"crossref","unstructured":"Cheng S, Liu Y, Ma S, Zhang X (2021) Deep feature space trojan attack of neural networks by controlled detoxification. In: Proceedings of the AAAI conference on artificial intelligence","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"7156_CR40","doi-asserted-by":"crossref","unstructured":"Zhu J, Park T, Isola P, Efros AA (2017) Unpaired image-to-image translation using cycle-consistent adversarial networks. In: Proceedings of the IEEE international conference on computer vision","DOI":"10.1109\/ICCV.2017.244"},{"key":"7156_CR41","doi-asserted-by":"crossref","unstructured":"Feng Y, Ma B, Zhang J, Zhao S, Xia Y, Tao D (2022) Fiba: Frequency-injection based backdoor attack in medical image analysis. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR52688.2022.02021"},{"key":"7156_CR42","doi-asserted-by":"crossref","unstructured":"Li S, Xue M, Zhao BZH, Zhu H, Zhang X (2020) Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Trans Depend Secure Comput","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"7156_CR43","unstructured":"Chen K, Lou X, Xu G, Li J, Zhang T (2022) Clean-image backdoor: Attacking multi-label models with poisoned labels only. In: The eleventh international conference on learning representations"},{"key":"7156_CR44","doi-asserted-by":"crossref","unstructured":"Long Y, Zhang Q, Zeng B, Gao L, Liu X, Zhang J, Song J (2022) Frequency domain model augmentation for adversarial attack. In: European conference on computer vision. Springer, pp 549\u2013566","DOI":"10.1007\/978-3-031-19772-7_32"},{"key":"7156_CR45","doi-asserted-by":"crossref","unstructured":"Jia S, Ma C, Yao T, Yin B, Ding S, Yang X (2022) Exploring frequency adversarial attacks for face forgery detection. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 4103\u20134112","DOI":"10.1109\/CVPR52688.2022.00407"},{"key":"7156_CR46","doi-asserted-by":"crossref","unstructured":"Luo C, Lin Q, Xie W, Wu B, Xie J, Shen L (2022) Frequency-driven imperceptible adversarial attack on semantic similarity. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 15315\u201315324","DOI":"10.1109\/CVPR52688.2022.01488"},{"key":"7156_CR47","doi-asserted-by":"crossref","unstructured":"Liu Q, Chen C, Qin J, Dou Q, Heng P (2021) Feddg: Federated domain generalization on medical image segmentation via episodic learning in continuous frequency space. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR46437.2021.00107"},{"key":"7156_CR48","doi-asserted-by":"crossref","unstructured":"Yang Y, Soatto S (2020) Fda: Fourier domain adaptation for semantic segmentation. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","DOI":"10.1109\/CVPR42600.2020.00414"},{"key":"7156_CR49","doi-asserted-by":"crossref","unstructured":"Lin T, Maire M, Belongie S, Hays J, Perona P, Ramanan D, Doll\u00e1r P, Zitnick CL (2014) Microsoft coco: Common objects in context. In: European conference on computer vision","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"7156_CR50","unstructured":"Everingham M (2009) The pascal visual object classes challenge 2007. http:\/\/www.Pascal-network.org\/challenges\/VOC\/voc2007\/workshop\/index.Html"},{"key":"7156_CR51","unstructured":"Everingham M, Van Gool L, Williams CK, Winn J, Zisserman A (2012) The pascal visual object classes challenge 2012 (voc2012). In: Results"},{"key":"7156_CR52","doi-asserted-by":"crossref","unstructured":"Stallkamp J, Schlipsing M, Salmen J, Igel C (2011) The german traffic sign recognition benchmark: a multi-class classification competition. In: The 2011 international joint conference on neural networks. IEEE, pp 1453\u20131460","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"7156_CR53","doi-asserted-by":"crossref","unstructured":"HuynhThu Q, Ghanbari M (2008) Scope of validity of psnr in image\/video quality assessment. Electronics letters","DOI":"10.1049\/el:20080522"},{"key":"7156_CR54","unstructured":"Wang Z, Bovik AC, Sheikh HR, Simoncelli EP (2004) Image quality assessment: from error visibility to structural similarity. IEEE Trans Image Process"},{"key":"7156_CR55","doi-asserted-by":"crossref","unstructured":"Liu K, Dolan-Gavitt B, Garg S (2018) Fine-pruning: Defending against backdooring attacks on deep neural networks. In: International symposium on research in attacks, intrusions, and defenses. Springer, pp 273\u2013294","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"7156_CR56","doi-asserted-by":"crossref","unstructured":"Gao Y, Xu C, Wang D, Chen S, Ranasinghe DC, Nepal S (2019) Strip: A defence against trojan attacks on deep neural networks. In: Proceedings of the 35th annual computer security applications conference, pp 113\u2013125","DOI":"10.1145\/3359789.3359790"},{"key":"7156_CR57","doi-asserted-by":"crossref","unstructured":"Kim G, Kim J, Lee J-S (2024) Exploring adversarial robustness of vision transformers in the spectral perspective. In: Proceedings of the IEEE\/CVF winter conference on applications of computer vision, pp 3976\u20133985","DOI":"10.1109\/WACV57701.2024.00393"},{"key":"7156_CR58","doi-asserted-by":"crossref","unstructured":"Sun J, Ma X, Zhang X, Wang Y, Teng Z, Xu L (2025) Frequency-aware purification: A black-box defense against backdoor attacks. In: International conference on intelligent computing. Springer, pp 216\u2013226","DOI":"10.1007\/978-981-96-9872-1_18"},{"key":"7156_CR59","doi-asserted-by":"crossref","unstructured":"Qiao Y, Liu D, Wang R, Liang K (2025) Low-frequency black-box backdoor attack via evolutionary algorithm. In: 2025 IEEE\/CVF winter conference on applications of computer vision (WACV). IEEE, pp 7582\u20137592","DOI":"10.1109\/WACV61041.2025.00737"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-026-07156-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-026-07156-7","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-026-07156-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T10:51:33Z","timestamp":1779792693000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-026-07156-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,9]]},"references-count":59,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2026,4]]}},"alternative-id":["7156"],"URL":"https:\/\/doi.org\/10.1007\/s10489-026-07156-7","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,9]]},"assertion":[{"value":"13 September 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 February 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 March 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"No potential conflict of interest was reported by the authors.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of Interest"}}],"article-number":"134"}}