{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T11:12:46Z","timestamp":1783768366919,"version":"3.55.0"},"reference-count":54,"publisher":"Springer Science and Business Media LLC","issue":"9","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100019981","name":"South-Central Minzu University","doi-asserted-by":"crossref","award":["XTZ24003"],"award-info":[{"award-number":["XTZ24003"]}],"id":[{"id":"10.13039\/501100019981","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100019981","name":"South-Central Minzu University","doi-asserted-by":"crossref","award":["PTZ24001"],"award-info":[{"award-number":["PTZ24001"]}],"id":[{"id":"10.13039\/501100019981","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1007\/s10489-026-07328-5","type":"journal-article","created":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T14:05:31Z","timestamp":1782482731000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["DFB: A Data-Free, Low-Budget, and High-EfficacyClean-Label Backdoor Attack"],"prefix":"10.1007","volume":"56","author":[{"given":"Binhao","family":"Ma","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiahui","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dejun","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Meng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,26]]},"reference":[{"key":"7328_CR1","doi-asserted-by":"publisher","unstructured":"Krizhevsky A, Sutskever I, Hinton GE (2012) Imagenet classification with deep convolutional neural networks. Adv Neural Inf Process Syst 25. https:\/\/doi.org\/10.1145\/3065386","DOI":"10.1145\/3065386"},{"key":"7328_CR2","doi-asserted-by":"publisher","unstructured":"He K, Zhang X, Ren S, et al (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 770\u2013778, https:\/\/doi.org\/10.1109\/cvpr.2016.90","DOI":"10.1109\/cvpr.2016.90"},{"issue":"2","key":"7328_CR3","doi-asserted-by":"publisher","first-page":"592","DOI":"10.28991\/ESJ-2024-08-02-014","volume":"8","author":"KW Goh","year":"2024","unstructured":"Goh KW, Surono S, Afiatin MF et al (2024) Comparison of activation functions in convolutional neural network for poisson noisy image classification. Emerging Science Journal 8(2):592\u2013602","journal-title":"Emerging Science Journal"},{"issue":"109","key":"7328_CR4","first-page":"573","volume":"139","author":"I Iqbal","year":"2025","unstructured":"Iqbal I, Ullah I, Peng T et al (2025) An end-to-end deep convolutional neural network-based data-driven fusion framework for identification of human induced pluripotent stem cell-derived endothelial cells in photomicrographs. Eng Appl Artif Intell 139(109):573","journal-title":"Eng Appl Artif Intell"},{"issue":"10","key":"7328_CR5","doi-asserted-by":"publisher","first-page":"697","DOI":"10.1080\/08839514.2021.1922841","volume":"35","author":"I Iqbal","year":"2021","unstructured":"Iqbal I, Odesanmi GA, Wang J et al (2021) Comparative investigation of learning algorithms for image classification with small dataset. Appl Artif Intell 35(10):697\u2013716","journal-title":"Appl Artif Intell"},{"key":"7328_CR6","unstructured":"Devlin J, Chang MW, Lee K, et al (2018) Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv:1810.04805"},{"key":"7328_CR7","doi-asserted-by":"publisher","unstructured":"Silver D, Huang A, Maddison CJ, et al (2016) Mastering the game of go with deep neural networks and tree search. nature 529(7587):484\u2013489. https:\/\/doi.org\/10.1038\/nature16961","DOI":"10.1038\/nature16961"},{"key":"7328_CR8","unstructured":"Silver D, Hubert T, Schrittwieser J, et al (2017) Mastering chess and shogi by self-play with a general reinforcement learning algorithm. arXiv:1712.01815"},{"key":"7328_CR9","unstructured":"Dosovitskiy A, Beyer L, Kolesnikov A, et al (2020) An image is worth 16x16 words: Transformers for image recognition at scale. arXiv:2010.11929"},{"key":"7328_CR10","unstructured":"Tan M (2019) Efficientnet: Rethinking model scaling for convolutional neural networks. arXiv:1905.11946"},{"key":"7328_CR11","doi-asserted-by":"publisher","unstructured":"Ribeiro M, Grolinger K, Capretz MA (2015) Mlaas: Machine learning as a service. In: 2015 IEEE 14th international conference on machine learning and applications (ICMLA), IEEE, pp 896\u2013902, https:\/\/doi.org\/10.1109\/icmla.2015.152","DOI":"10.1109\/icmla.2015.152"},{"key":"7328_CR12","doi-asserted-by":"publisher","unstructured":"Subbiah U, Ramachandran M, Mahmood Z (2019) Software engineering approach to bug prediction models using machine learning as a service (mlaas). In: Icsoft 2018-proceedings of the 13th international conference on software technologies, pp 879\u2013887, https:\/\/doi.org\/10.5220\/0006926308790887","DOI":"10.5220\/0006926308790887"},{"key":"7328_CR13","doi-asserted-by":"crossref","unstructured":"Philipp R, Mladenow A, Strauss C, et al (2020) Machine learning as a service: Challenges in research and applications. In: Proceedings of the 22nd International Conference on Information Integration and Web-based Applications & Services, pp 396\u2013406","DOI":"10.1145\/3428757.3429152"},{"issue":"5","key":"7328_CR14","doi-asserted-by":"publisher","first-page":"3149","DOI":"10.1109\/tdsc.2021.3085988","volume":"19","author":"J Weng","year":"2021","unstructured":"Weng J, Weng J, Cai C et al (2021) Golden grain: Building a secure and decentralized model marketplace for mlaas. IEEE Trans Dependable Secure Comput 19(5):3149\u20133167. https:\/\/doi.org\/10.1109\/tdsc.2021.3085988","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"7328_CR15","unstructured":"Rietzler A, Stabinger S, Opitz P, et al (2019) Adapt or get left behind: Domain adaptation through bert language model finetuning for aspect-target sentiment classification. arXiv:1908.11860"},{"key":"7328_CR16","doi-asserted-by":"publisher","unstructured":"Van Horn G, Branson S, Farrell R, et al (2015) Building a bird recognition app and large scale dataset with citizen scientists: The fine print in fine-grained dataset collection. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 595\u2013604, https:\/\/doi.org\/10.1109\/cvpr.2015.7298658","DOI":"10.1109\/cvpr.2015.7298658"},{"key":"7328_CR17","first-page":"1877","volume":"33","author":"T Brown","year":"2020","unstructured":"Brown T, Mann B, Ryder N et al (2020) Language models are few-shot learners. Adv Neural Inf Process Syst 33:1877\u20131901","journal-title":"Adv Neural Inf Process Syst"},{"key":"7328_CR18","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv:1412.6572"},{"key":"7328_CR19","unstructured":"Kurakin A, Goodfellow I, Bengio S (2016) Adversarial machine learning at scale. arXiv:1611.01236"},{"key":"7328_CR20","unstructured":"Gu T, Dolan-Gavitt B, Garg S (2017) Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv:1708.06733"},{"key":"7328_CR21","unstructured":"Ma B, Zheng T, Hu H, et al (2024) Releasing malevolence from benevolence: The menace of benign data on machine unlearning. arXiv:2407.05112"},{"key":"7328_CR22","unstructured":"Chen X, Liu C, Li B, et al (2017) Targeted backdoor attacks on deep learning systems using data poisoning. arXiv:1712.05526"},{"key":"7328_CR23","unstructured":"Turner A, Tsipras D, Madry A (2019) Label-consistent backdoor attacks. arXiv:1912.02771"},{"key":"7328_CR24","doi-asserted-by":"publisher","unstructured":"Saha A, Subramanya A, Pirsiavash H (2020) Hidden trigger backdoor attacks. In: Proceedings of the AAAI conference on artificial intelligence, pp 11,957\u201311,965, https:\/\/doi.org\/10.1609\/aaai.v34i07.6871","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"7328_CR25","doi-asserted-by":"publisher","unstructured":"Zeng Y, Pan M, Just HA, et al (2023) Narcissus: A practical clean-label backdoor attack with limited information. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pp 771\u2013785, https:\/\/doi.org\/10.1145\/3576915.3616617","DOI":"10.1145\/3576915.3616617"},{"key":"7328_CR26","doi-asserted-by":"publisher","unstructured":"Wang B, Yao Y, Shan S, et al (2019) Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP), IEEE, pp 707\u2013723, https:\/\/doi.org\/10.1109\/sp.2019.00031","DOI":"10.1109\/sp.2019.00031"},{"key":"7328_CR27","doi-asserted-by":"publisher","unstructured":"Liu K, Dolan-Gavitt B, Garg S (2018) Fine-pruning: Defending against backdooring attacks on deep neural networks. In: International symposium on research in attacks, intrusions, and defenses, Springer, pp 273\u2013294. https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"7328_CR28","doi-asserted-by":"crossref","unstructured":"Gao Y, Xu C, Wang D, et al (2019) Strip: A defence against trojan attacks on deep neural networks. In: Proceedings of the 35th Annual Computer Security Applications Conference, pp 113\u2013125","DOI":"10.1145\/3359789.3359790"},{"key":"7328_CR29","unstructured":"Chou E, Tram\u00e8r F, Pellegrino G (2018) Sentinet: Detecting localized universal attacks against deep learning systems. arXiv:1812.00292"},{"key":"7328_CR30","unstructured":"Nguyen A, Tran A (2021) Wanet\u2013imperceptible warping-based backdoor attack. arXiv:2102.10369"},{"key":"7328_CR31","doi-asserted-by":"publisher","unstructured":"Li Y, Li Y, Wu B, et al (2021) Invisible backdoor attack with sample-specific triggers. In: Proceedings of the IEEE\/CVF international conference on computer vision, pp 16,463\u201316,472. https:\/\/doi.org\/10.1109\/iccv48922.2021.01615","DOI":"10.1109\/iccv48922.2021.01615"},{"key":"7328_CR32","first-page":"3454","volume":"33","author":"TA Nguyen","year":"2020","unstructured":"Nguyen TA, Tran A (2020) Input-aware dynamic backdoor attack. Adv Neural Inf Process Syst 33:3454\u20133464","journal-title":"Adv Neural Inf Process Syst"},{"key":"7328_CR33","doi-asserted-by":"publisher","unstructured":"Liu Y, Ma X, Bailey J, et al (2020) Reflection backdoor: A natural backdoor attack on deep neural networks. In: Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part X 16, Springer, pp 182\u2013199. https:\/\/doi.org\/10.1007\/978-3-030-58607-2_11","DOI":"10.1007\/978-3-030-58607-2_11"},{"issue":"103","key":"7328_CR34","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1016\/j.cose.2023.103212","volume":"129","author":"B Ma","year":"2023","unstructured":"Ma B, Zhao C, Wang D et al (2023) Dihba: Dynamic, invisible and high attack success rate boundary backdoor attack with low poison ratio. Computers & Security 129(103):212. https:\/\/doi.org\/10.1016\/j.cose.2023.103212","journal-title":"Computers & Security"},{"key":"7328_CR35","doi-asserted-by":"publisher","unstructured":"Sarkar E, Benkraouda H, Maniatakos M (2020) Facehack: Triggering backdoored facial recognition systems using facial characteristics. arXiv:2006.11623. https:\/\/doi.org\/10.1109\/tbiom.2021.3132132","DOI":"10.1109\/tbiom.2021.3132132"},{"key":"7328_CR36","unstructured":"Zheng T, Lan H, Li B (2023) Be careful with pypi packages: You may unconsciously spread backdoor model weights. Proceedings of Machine Learning and Systems 5"},{"key":"7328_CR37","unstructured":"Lv P, Yue C, Liang R, et al (2023) A data-free backdoor injection approach in neural networks. In: 32nd USENIX security symposium (USENIX Security 23), pp 2671\u20132688"},{"key":"7328_CR38","doi-asserted-by":"crossref","unstructured":"Cao B, Jia J, Hu C, et al (2024) Data free backdoor attacks. Advances in Neural Information Processing Systems 37:23,881\u201323,911","DOI":"10.52202\/079017-0753"},{"key":"7328_CR39","unstructured":"Xu K, Liu S, Chen PY, et al (2020) Defending against backdoor attack on deep neural networks. arXiv:2002.12162"},{"key":"7328_CR40","unstructured":"Qiao X, Yang Y, Li H (2019) Defending neural backdoors via generative distribution modeling. Advances in neural information processing systems 32"},{"key":"7328_CR41","doi-asserted-by":"publisher","unstructured":"Guo W, Wang L, Xu Y, et al (2020) Towards inspecting and eliminating trojan backdoors in deep neural networks. In: 2020 IEEE International Conference on Data Mining (ICDM), IEEE, pp 162\u2013171. https:\/\/doi.org\/10.1109\/icdm50108.2020.00025","DOI":"10.1109\/icdm50108.2020.00025"},{"key":"7328_CR42","doi-asserted-by":"publisher","unstructured":"Wang R, Zhang G, Liu S, et al (2020) Practical detection of trojan neural networks: Data-limited and data-free cases. In: Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part XXIII 16, Springer, pp 222\u2013238, https:\/\/doi.org\/10.1007\/978-3-030-58592-1_14","DOI":"10.1007\/978-3-030-58592-1_14"},{"key":"7328_CR43","doi-asserted-by":"publisher","unstructured":"Ma B, Wang J, Wang D et al (2023) Multidomain active defense: Detecting multidomain backdoor poisoned samples via all-to-all decoupling training without clean datasets. Neural Netw. https:\/\/doi.org\/10.1016\/j.neunet.2023.09.036","DOI":"10.1016\/j.neunet.2023.09.036"},{"key":"7328_CR44","doi-asserted-by":"publisher","unstructured":"Selvaraju RR, Cogswell M, Das A, et al (2017) Grad-cam: Visual explanations from deep networks via gradient-based localization. In: Proceedings of the IEEE international conference on computer vision, pp 618\u2013626. https:\/\/doi.org\/10.1109\/iccv.2017.74","DOI":"10.1109\/iccv.2017.74"},{"issue":"1","key":"7328_CR45","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/2481528.2481532","volume":"42","author":"F Schomm","year":"2013","unstructured":"Schomm F, Stahl F, Vossen G (2013) Marketplaces for data: an initial survey. ACM SIGMOD Rec 42(1):15\u201326. https:\/\/doi.org\/10.1145\/2481528.2481532","journal-title":"ACM SIGMOD Rec"},{"key":"7328_CR46","doi-asserted-by":"crossref","unstructured":"Ronneberger O, Fischer P, Brox T (2015) U-net: Convolutional networks for biomedical image segmentation. In: Medical image computing and computer-assisted intervention\u2013MICCAI 2015: 18th International Conference, Munich, Germany, October 5-9, 2015, Proceedings, Part III 18, Springer, pp 234\u2013241","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"7328_CR47","unstructured":"Simonyan K, Zisserman A (2014) Very deep convolutional networks for large-scale image recognition. arXiv:1409.1556"},{"key":"7328_CR48","unstructured":"Krizhevsky A, Hinton G, et al (2009) Learning multiple layers of features from tiny images. Tech. rep"},{"key":"7328_CR49","unstructured":"Le Y, Yang X (2015) Tiny imagenet visual recognition challenge. CS 231N 7(7):3"},{"key":"7328_CR50","doi-asserted-by":"publisher","unstructured":"Dewi C, Chen RC, Liu YT, et al (2020) Taiwan stop sign recognition with customize anchor. In: Proceedings of the 12th international conference on computer modeling and simulation, pp 51\u201355. https:\/\/doi.org\/10.1145\/3408066.3408078","DOI":"10.1145\/3408066.3408078"},{"key":"7328_CR51","doi-asserted-by":"publisher","unstructured":"Stallkamp J, Schlipsing M, Salmen J, et al (2011) The german traffic sign recognition benchmark: a multi-class classification competition. In: The 2011 international joint conference on neural networks, IEEE, pp 1453\u20131460. https:\/\/doi.org\/10.1109\/ijcnn.2011.6033395","DOI":"10.1109\/ijcnn.2011.6033395"},{"key":"7328_CR52","doi-asserted-by":"publisher","unstructured":"Zhang R, Isola P, Efros AA, et al (2018) The unreasonable effectiveness of deep features as a perceptual metric. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 586\u2013595. https:\/\/doi.org\/10.1109\/cvpr.2018.00068","DOI":"10.1109\/cvpr.2018.00068"},{"key":"7328_CR53","unstructured":"Heusel M, Ramsauer H, Unterthiner T, et al (2017) Gans trained by a two time-scale update rule converge to a local nash equilibrium. Advances in neural information processing systems 30"},{"key":"7328_CR54","doi-asserted-by":"crossref","unstructured":"Szegedy C, Liu W, Jia Y, et al (2015) Going deeper with convolutions. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 1\u20139","DOI":"10.1109\/CVPR.2015.7298594"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-026-07328-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-026-07328-5","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-026-07328-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T10:40:00Z","timestamp":1783766400000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-026-07328-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":54,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2026,6]]}},"alternative-id":["7328"],"URL":"https:\/\/doi.org\/10.1007\/s10489-026-07328-5","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"21 September 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"All the authors declare that they have no competing financial interests or personal relationships that could influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}},{"value":"This article does not contain studies with human participants or animals. Statement of informed consent is not applicable since the manuscript does not contain any patient data.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical and Informed Consent for Data Used"}}],"article-number":"320"}}