{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:48:37Z","timestamp":1777657717533,"version":"3.51.4"},"reference-count":154,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2025,5,6]],"date-time":"2025-05-06T00:00:00Z","timestamp":1746489600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,5,6]],"date-time":"2025-05-06T00:00:00Z","timestamp":1746489600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2024B1515020095"],"award-info":[{"award-number":["2024B1515020095"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62076213"],"award-info":[{"award-number":["62076213"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017610","name":"Shenzhen Science and Technology Innovation Program","doi-asserted-by":"publisher","award":["RCYX20210609103057050"],"award-info":[{"award-number":["RCYX20210609103057050"]}],"id":[{"id":"10.13039\/501100017610","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017610","name":"Shenzhen Science and Technology Innovation Program","doi-asserted-by":"publisher","award":["62471420"],"award-info":[{"award-number":["62471420"]}],"id":[{"id":"10.13039\/501100017610","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017610","name":"Shenzhen Science and Technology Innovation Program","doi-asserted-by":"publisher","award":["62101351"],"award-info":[{"award-number":["62101351"]}],"id":[{"id":"10.13039\/501100017610","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key R&D Projects of the Ministry of Science and Technology","award":["2023YFC3304800"],"award-info":[{"award-number":["2023YFC3304800"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Comput Vis"],"published-print":{"date-parts":[[2025,8]]},"DOI":"10.1007\/s11263-025-02447-x","type":"journal-article","created":{"date-parts":[[2025,5,6]],"date-time":"2025-05-06T07:21:19Z","timestamp":1746516079000},"page":"5700-5787","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["BackdoorBench: A Comprehensive Benchmark and Analysis of Backdoor Learning"],"prefix":"10.1007","volume":"133","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2183-5990","authenticated-orcid":false,"given":"Baoyuan","family":"Wu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongrui","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingda","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zihao","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shaokui","family":"Wei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Danni","family":"Yuan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingli","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruotong","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Li","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Shen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,5,6]]},"reference":[{"key":"2447_CR1","doi-asserted-by":"crossref","unstructured":"Al\u00a0Kader\u00a0Hammoud, H. A., Bibi, A., Torr, P. H., Ghanem, B. (2023). Don\u2019t freak out: A frequency-inspired approach to detecting backdoor poisoned samples in DNNs. In CVPR.","DOI":"10.1109\/CVPRW59228.2023.00230"},{"key":"2447_CR2","unstructured":"Bagdasaryan, E., & Shmatikov, V. (2021). Blind backdoors in deep learning models. In USENIX security symposium."},{"key":"2447_CR3","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., & Shmatikov, V. (2020). How to backdoor federated learning. In AISTATS."},{"key":"2447_CR4","doi-asserted-by":"crossref","unstructured":"Barni, M., Kallas, K., & Tondi, B. (2019). A new backdoor attack in cnns by training set corruption without label poisoning. In ICIP","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"2447_CR5","unstructured":"Bhagoji, A. N., Chakraborty, S., Mittal, P., & Calo, S. (2019). Analyzing federated learning through an adversarial lens. In ICML."},{"key":"2447_CR6","unstructured":"Brown, T., Mann, B., Ryder, N., Subbiah, M., Kaplan, J. D., Dhariwal, P., Neelakantan, A., Shyam, P., Sastry, G., & Askell, A. (2020). Language models are few-shot learners. In NeurIPS."},{"key":"2447_CR7","doi-asserted-by":"crossref","unstructured":"Cai, K., Zhang, Z., Lou, Q., & Yao, F. (2024). Wbp: Training-time backdoor attacks through hardware-based weight bit poisoning. In ECCV.","DOI":"10.1007\/978-3-031-73650-6_11"},{"key":"2447_CR8","unstructured":"Chen, B., Carvalho, W., Baracaldo, N., Ludwig, H., Edwards, B., Lee, T., Molloy, I., & Srivastava, B. (2019). Detecting backdoor attacks on deep neural networks by activation clustering. In SafeAI."},{"key":"2447_CR9","doi-asserted-by":"crossref","unstructured":"Chen, C., Hong, H., Xiang, T., & Xie, M. (2024a). Anti-backdoor model: A novel algorithm to remove backdoors in a non-invasive way. IEEE Transactions on Information Forensics and Security., 19, 7420\u20137434.","DOI":"10.1109\/TIFS.2024.3436508"},{"key":"2447_CR10","unstructured":"Chen, C.-L., Golubchik, L., & Paolieri, M. (2020). Backdoor attacks on federated meta-learning. arXiv e-prints."},{"key":"2447_CR11","unstructured":"Chen, W., Wu, B., & Wang, H. (2022). Effective backdoor defense by exploiting sensitivity of poisoned samples. In NeurIPS."},{"key":"2447_CR12","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., & Song, D. (2017). Targeted backdoor attacks on deep learning systems using data poisoning. arXiv:1712.05526."},{"key":"2447_CR13","doi-asserted-by":"crossref","unstructured":"Chen, Y., Wu, H., & Zhou, J. (2024b). Progressive poisoned data isolation for training-time backdoor defense. AAAI, 38, 11425\u201311433.","DOI":"10.1609\/aaai.v38i10.29023"},{"key":"2447_CR14","doi-asserted-by":"crossref","unstructured":"Cheng, S., Shen, G., Zhang, K., Tao, G., An, S., Guo, H., Ma, S., & Zhang, X. (2025). Unit: Backdoor mitigation via automated neural distribution tightening. In ECCV (pp. 262\u2013281). Springer.","DOI":"10.1007\/978-3-031-73033-7_15"},{"key":"2447_CR15","doi-asserted-by":"crossref","unstructured":"Cheng, S., Tao, G., Liu, Y., Shen, G., An, S., Feng, S., Xu, X., Zhang, K., Ma, S., & Zhang, X. (2024). Lotus: Evasive and resilient backdoor attacks through sub-partitioning. In CVPR.","DOI":"10.1109\/CVPR52733.2024.02342"},{"key":"2447_CR16","doi-asserted-by":"crossref","unstructured":"Chou, E., Tramer, F., & Pellegrino, G. (2020). Sentinet: Detecting localized universal attacks against deep learning systems. In SPW.","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"2447_CR17","unstructured":"Croce, F., Andriushchenko, M., Sehwag, V., Debenedetti, E., Flammarion, N., Chiang, M., Mittal, P., & Hein, M. (2021). Robustbench: A standardized adversarial robustness benchmark. In NeurIPS D &B Track."},{"issue":"9","key":"2447_CR18","doi-asserted-by":"publisher","first-page":"10850","DOI":"10.1109\/TPAMI.2023.3261988","volume":"45","author":"F-A Croitoru","year":"2023","unstructured":"Croitoru, F.-A., Hondru, V., Ionescu, R. T., & Shah, M. (2023). Diffusion models in vision: A survey. IEEE TPAMI, 45(9), 10850\u201310869.","journal-title":"IEEE TPAMI"},{"key":"2447_CR19","unstructured":"Cui, G., Yuan, L., He, B., Chen, Y., Liu, Z., & Sun, M. (2022). A unified evaluation of textual backdoor learning: Frameworks and benchmarks. In NeurIPS."},{"key":"2447_CR20","unstructured":"Doan, K., Lao, Y., & Li, P. (2021a). Backdoor attack with imperceptible input and latent modification. In NeurIPS."},{"key":"2447_CR21","doi-asserted-by":"crossref","unstructured":"Doan, K., Lao, Y., Zhao, W., & Li, P. (2021b). Lira: Learnable, imperceptible and robust backdoor attacks. In ICCV","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"2447_CR22","unstructured":"Doan, K. D., Lao, Y., & Li, P. (2022). Marksman backdoor: Backdoor attacks with arbitrary target class. In NeurIPS."},{"key":"2447_CR23","doi-asserted-by":"crossref","unstructured":"Dong, Y., Fu, Q.-A., Yang, X., Pang, T., Su, H., Xiao, Z., & Zhu, J. (2020). Benchmarking adversarial robustness on image classification. In CVPR.","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"2447_CR24","unstructured":"Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., & Gelly, S. (2021). An image is worth 16 $$\\times $$ 16 words: Transformers for image recognition at scale. In ICLR."},{"key":"2447_CR25","unstructured":"Du, M., Jia, R., & Song, D. (2020). Robust anomaly detection and backdoor attack detection via differential privacy. In ICLR."},{"key":"2447_CR26","doi-asserted-by":"crossref","unstructured":"Duan, Q., Hua, Z., Liao, Q., Zhang, Y., & Zhang, L. Y. (2024). Conditional backdoor attack via jpeg compression. In AAAI.","DOI":"10.1609\/aaai.v38i18.29957"},{"key":"2447_CR27","unstructured":"Fung, C., Yoon, C. J., & Beschastnikh, I. (2020). The limitations of federated learning in sybil settings. In RAID."},{"key":"2447_CR28","doi-asserted-by":"publisher","first-page":"1267","DOI":"10.1109\/TIFS.2023.3333687","volume":"19","author":"K Gao","year":"2023","unstructured":"Gao, K., Bai, J., Wu, B., Ya, M., & Xia, S.-T. (2023). Imperceptible and robust backdoor attack in 3d point cloud. IEEE Transactions on Information Forensics and Security, 19, 1267\u20131282.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"2447_CR29","doi-asserted-by":"crossref","unstructured":"Gao, Y., Chen, H., Sun, P., Li, J., Zhang, A., Wang, Z., & Liu, W. (2024a). A dual stealthy backdoor: From both spatial and frequency perspectives. In AAAI.","DOI":"10.1609\/aaai.v38i3.27954"},{"key":"2447_CR30","doi-asserted-by":"crossref","unstructured":"Gao, Y., Li, Y., Gong, X., Li, Z., Xia, S.-T., & Wang, Q. (2024b). Backdoor attack with sparse and invisible trigger. IEEE Transactions on Information Forensics and Security, 19, 6364\u20136376.","DOI":"10.1109\/TIFS.2024.3411936"},{"key":"2447_CR31","doi-asserted-by":"crossref","unstructured":"Gao, Y., Xu, C., Wang, D., Chen, S., Ranasinghe, D. C., & Nepal, S. (2019). Strip: A defence against trojan attacks on deep neural networks. In ACSAC.","DOI":"10.1145\/3359789.3359790"},{"key":"2447_CR32","unstructured":"Goodfellow, I., Shlens, J., & Szegedy, C. (2015). Explaining and harnessing adversarial examples. In ICLR."},{"key":"2447_CR33","unstructured":"Goodman, D., Xin, H., Yang, W., Yuesheng, W., Junfeng, X., & Huan, Z. (2020). Advbox: A toolbox to generate adversarial examples that fool neural networks. arXiv:2001.05574."},{"key":"2447_CR34","doi-asserted-by":"crossref","unstructured":"Guan, J., Liang, J., & He, R. (2024). Backdoor defense via test-time detecting and repairing. In CVPR (pp. 24564\u201324573).","DOI":"10.1109\/CVPR52733.2024.02319"},{"key":"2447_CR35","doi-asserted-by":"crossref","unstructured":"Guan, J., Tu, Z., He, R., & Tao, D. (2022). Few-shot backdoor defense using shapley estimation. In CVPR.","DOI":"10.1109\/CVPR52688.2022.01300"},{"key":"2447_CR36","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., & Garg, S. (2019). Badnets: Evaluating backdooring attacks on deep neural networks. IEEE Access, 7, 47230\u201347244.","journal-title":"IEEE Access"},{"key":"2447_CR37","unstructured":"Guo, J., Li, A., & Liu, C. (2022). Aeva: Black-box backdoor detection using adversarial extreme value analysis. In ICLR."},{"key":"2447_CR38","unstructured":"Guo, J., Li, Y., Chen, X., Guo, H., Sun, L., & Liu, C. (2023a). Scale-up: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency. In ICLR."},{"key":"2447_CR39","doi-asserted-by":"crossref","unstructured":"Guo, W., Tondi, B., & Barni, M. (2023b). Universal detection of backdoor attacks via density-based clustering and centroids analysis. IEEE Transactions on Information Forensics and Security., 19, 970\u2013984.","DOI":"10.1109\/TIFS.2023.3329426"},{"key":"2447_CR40","unstructured":"Hayase, J., & Kong, W. (2021). Spectre: Defending against backdoor attacks using robust covariance estimation. In ICML."},{"key":"2447_CR41","unstructured":"Hayase, J., Kong, W., Somani, R., & Oh, S. (2021). Spectre: Defending against backdoor attacks using robust statistics. In ICML."},{"key":"2447_CR42","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., & Sun, J. (2016). Identity mappings in deep residual networks. In ECCV.","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"2447_CR43","unstructured":"He, P., Xu, H., Ren, J., Cui, Y., Zeng, S., Liu, H., Aggarwal, C. C., & Tang, J. (2024). Sharpness-aware data poisoning attack. In ICLR."},{"key":"2447_CR44","unstructured":"Heusel, M., Ramsauer, H., Unterthiner, T., Nessler, B., & Hochreiter, S. (2017). Gans trained by a two time-scale update rule converge to a local nash equilibrium. In NeurIPS."},{"key":"2447_CR45","unstructured":"Hinton, G. E., & Roweis, S. (2002). Stochastic neighbor embedding. In NeurIPS (Vol. 15)."},{"issue":"1","key":"2447_CR46","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1162\/neco.1997.9.1.1","volume":"9","author":"S Hochreiter","year":"1997","unstructured":"Hochreiter, S., & Schmidhuber, J. (1997). Flat minima. Neural Computation, 9(1), 1\u201342.","journal-title":"Neural Computation"},{"key":"2447_CR47","unstructured":"Hou, L., Feng, R., Hua, Z., Luo, W., Zhang, L. Y., & Li, Y. (2024). Ibd-psc: Input-level backdoor detection via parameter-oriented scaling consistency. In ICML."},{"key":"2447_CR48","doi-asserted-by":"crossref","unstructured":"Houben, S., Stallkamp, J., Salmen, J., Schlipsing, M., & Igel, C. (2013). Detection of traffic signs in real-world images: The German traffic sign detection benchmark. In IJCNN.","DOI":"10.1109\/IJCNN.2013.6706807"},{"key":"2447_CR49","unstructured":"Huang, D., & Bu, Q. (2024). Adversarial feature map pruning for backdoor. In ICLR."},{"key":"2447_CR50","doi-asserted-by":"crossref","unstructured":"Huang, H., Wang, Q., Gong, X., & Wang, T. (2023). Orion: Online backdoor sample detection via evolution deviance. In IJCAI.","DOI":"10.24963\/ijcai.2023\/96"},{"key":"2447_CR51","unstructured":"Huang, K., Li, Y., Wu, B., Qin, Z., & Ren, K. (2022). Backdoor defense via decoupling the training process. In ICLR."},{"key":"2447_CR52","doi-asserted-by":"crossref","unstructured":"Huynh, T., Tran, A., Doan, K. D., & Pham, T. (2024). Data poisoning quantization backdoor attack. In ECCV.","DOI":"10.1007\/978-3-031-72907-2_3"},{"key":"2447_CR53","unstructured":"Jha, R. D., Hayase, J., & Oh, S. (2023). Label poisoning is all you need. In NeurIPS."},{"key":"2447_CR54","doi-asserted-by":"crossref","unstructured":"Jiang, W., Li, H., Xu, G., & Zhang, T. (2023). Color backdoor: A robust poisoning attack in color space. In CVPR.","DOI":"10.1109\/CVPR52729.2023.00786"},{"key":"2447_CR55","doi-asserted-by":"crossref","unstructured":"Karim, N., Arafat, A. A., Khalid, U., Guo, Z., & Rahnavard, N. (2025). Augmented neural fine-tuning for efficient backdoor purification. In: ECCV (pp. 401\u2013418). Springer.","DOI":"10.1007\/978-3-031-72989-8_23"},{"key":"2447_CR56","unstructured":"Karra, K., Ashcraft, C., & Fendley, N. (2020). The trojai software framework: An opensource tool for embedding trojans into deep learning models. arXiv:2003.07233."},{"key":"2447_CR57","unstructured":"Keskar, N. S., Mudigere, D., Nocedal, J., Smelyanskiy, M., & Tang, P. T. P. (2017). On large-batch training for deep learning: Generalization gap and sharp minima. In ICLR."},{"key":"2447_CR58","unstructured":"Krizhevsky, A., & Hinton, G. (2009). Learning multiple layers of features from tiny images."},{"key":"2447_CR59","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I. J., & Bengio, S. (2017). Adversarial examples in the physical world. In ICLR.","DOI":"10.1201\/9781351251389-8"},{"key":"2447_CR60","unstructured":"Le, Y., & Yang, X. (2015a). Tiny imagenet visual recognition challenge. In CS 231N."},{"key":"2447_CR61","unstructured":"Le, Y., & Yang, X. S. (2015b). Tiny imagenet visual recognition challenge."},{"key":"2447_CR62","doi-asserted-by":"crossref","unstructured":"Li, C., Pang, R., Xi, Z., Du, T., Ji, S., Yao, Y., & Wang, T. (2023a). An embarrassingly simple backdoor attack on self-supervised learning. In ICCV.","DOI":"10.1109\/ICCV51070.2023.00403"},{"key":"2447_CR63","doi-asserted-by":"crossref","unstructured":"Li, S., Xue, M., Zhao, B., Zhu, H., & Zhang, X. (2020a). Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Transactions on Dependable and Secure Computing, 18, 2088\u20132105.","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"2447_CR64","doi-asserted-by":"crossref","unstructured":"Li, Y., Li, Y., Wu, B., Li, L., He, R., & Lyu, S. (2021a). Invisible backdoor attack with sample-specific triggers. In ICCV.","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"2447_CR65","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., & Ma, X. (2020b). Neural attention distillation: Erasing backdoor triggers from deep neural networks. In ICLR."},{"key":"2447_CR66","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., & Ma, X. (2021b). Anti-backdoor learning: Training clean models on poisoned data. In NeurIPS."},{"key":"2447_CR67","unstructured":"Li, Y., Lyu, X., Ma, X., Koren, N., Lyu, L., Li, B., & Jiang, Y.-G. (2023b). Reconstructive neuron pruning for backdoor defense. In ICML."},{"key":"2447_CR68","doi-asserted-by":"crossref","unstructured":"Li, Y., Ma, H., Zhang, Z., Gao, Y., Abuadbba, A., Xue, M., Fu, A., Zheng, Y., Al-Sarawi, S. F., & Abbott, D. (2023c). Ntd: Non-transferability enabled deep learning backdoor detection. IEEE Transactions on Information Forensics and Security, 19, 104\u2013119.","DOI":"10.1109\/TIFS.2023.3312973"},{"key":"2447_CR69","doi-asserted-by":"crossref","unstructured":"Liang, S., Zhu, M., Liu, A., Wu, B., Cao, X., & Chang, E.-C. (2024). Badclip: Dual-embedding guided backdoor attack on multimodal contrastive learning. In CVPR.","DOI":"10.1109\/CVPR52733.2024.02327"},{"key":"2447_CR70","unstructured":"Lin, W., Liu, L., Wei, S., Li, J., & Xiong, H. (2023). Unveiling and mitigating backdoor vulnerabilities based on unlearning weight changes and backdoor activeness. In NIPS."},{"key":"2447_CR71","unstructured":"Liu, J., Bai, Y., Jiang, G., Chen, T., & Wang, H. (2020a). Understanding why neural networks generalize well through gsnr of parameters. In ICLR."},{"key":"2447_CR72","doi-asserted-by":"crossref","unstructured":"Liu, K., Dolan-Gavitt, B., & Garg, S. (2018a). Fine-pruning: Defending against backdooring attacks on deep neural networks. In RAID.","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"2447_CR73","doi-asserted-by":"crossref","unstructured":"Liu, M., Sangiovanni-Vincentelli, A., & Yue, X. (2023a). Beating backdoor attack at its own game. In ICCV.","DOI":"10.1109\/ICCV51070.2023.00426"},{"key":"2447_CR74","doi-asserted-by":"crossref","unstructured":"Liu, X., Li, M., Wang, H., Hu, S., Ye, D., Jin, H., Wu, L., & Xiao, C. (2023b). Detecting backdoors during the inference stage based on corruption robustness consistency. In CVPR.","DOI":"10.1109\/CVPR52729.2023.01570"},{"key":"2447_CR75","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, S., Aafer, Y., Lee, W.-C., Zhai, J., Wang, W., & Zhang, X. (2018b). Trojaning attack on neural networks. In NDSS.","DOI":"10.14722\/ndss.2018.23291"},{"key":"2447_CR76","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, X., Bailey, J., & Lu, F. (2020b). Reflection backdoor: A natural backdoor attack on deep neural networks. In ECCV (pp. 182\u2013199).","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"2447_CR77","unstructured":"Liu, Z., Koffas, S., Yu, S., & Picek, S. (2023c). Ban: Detecting backdoors activated by neuron noise. In NIPS."},{"key":"2447_CR78","doi-asserted-by":"crossref","unstructured":"Liu, Z., Mao, H., Wu, C.-Y., Feichtenhofer, C., Darrell, T., & Xie, S. (2022). A convnet for the 2020s. In CVPR.","DOI":"10.1109\/CVPR52688.2022.01167"},{"key":"2447_CR79","doi-asserted-by":"crossref","unstructured":"Liu, Z., Wang, T., Huai, M., & Miao, C. (2024). Backdoor attacks via machine unlearning. In AAAI.","DOI":"10.1609\/aaai.v38i13.29321"},{"key":"2447_CR80","unstructured":"Lundberg, S. (2017). A unified approach to interpreting model predictions. arXiv preprint arXiv:1705.07874."},{"key":"2447_CR81","doi-asserted-by":"crossref","unstructured":"Lyu, W., Pang, L., Ma, T., Ling, H., & Chen, C. (2024). Trojvlm: Backdoor attack against vision language models. In ECCV.","DOI":"10.1007\/978-3-031-73650-6_27"},{"key":"2447_CR82","doi-asserted-by":"crossref","unstructured":"Ma, W., Wang, D., Sun, R., Xue, M., Wen, S., & Xiang, Y. (2023). The \u201cbeatrix\u201d resurrections: Robust backdoor detection via gram matrices. In NDSS.","DOI":"10.14722\/ndss.2023.23069"},{"key":"2447_CR83","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. In ICLR"},{"issue":"29","key":"2447_CR84","doi-asserted-by":"publisher","first-page":"861","DOI":"10.21105\/joss.00861","volume":"3","author":"L McInnes","year":"2018","unstructured":"McInnes, L., Healy, J., Saul, N., & Gro\u00dfberger, L. (2018). Umap: Uniform manifold approximation and projection. Journal of Open Source Software, 3(29), 861.","journal-title":"Journal of Open Source Software"},{"key":"2447_CR85","unstructured":"Min, R., Qin, Z., Shen, L., & Cheng, M. (2023). Towards stable backdoor purification through feature shift tuning. In NeurIPS."},{"issue":"12","key":"2447_CR86","doi-asserted-by":"publisher","first-page":"4695","DOI":"10.1109\/TIP.2012.2214050","volume":"21","author":"A Mittal","year":"2012","unstructured":"Mittal, A., Moorthy, A. K., & Bovik, A. C. (2012). No-reference image quality assessment in the spatial domain. IEEE Transactions on Image Processing, 21(12), 4695\u20134708.","journal-title":"IEEE Transactions on Image Processing"},{"key":"2447_CR87","unstructured":"Neyshabur, B., Bhojanapalli, S., McAllester, D., & Srebro, N. (2017). Exploring generalization in deep learning. In NeurIPS."},{"key":"2447_CR88","unstructured":"Nguyen, D. T., Nguyen, T. M., Tran, A. T., Doan, K. D., & Wong, K. S. (2023). Iba: Towards irreversible backdoor attacks in federated learning. In NeurIPS."},{"key":"2447_CR89","unstructured":"Nguyen, T. A., & Tran, A. (2020). Input-aware dynamic backdoor attack. In NeurIPS."},{"key":"2447_CR90","unstructured":"Nguyen, T. A., & Tran, A. T. (2021). Wanet: Imperceptible warping-based backdoor attack. In ICLR."},{"key":"2447_CR91","unstructured":"Nicolae, M.-I., Sinn, M., Tran, M. N., Buesser, B., Rawat, A., Wistuba, M., Zantedeschi, V., Baracaldo, N., Chen, B., & Ludwig, H. (2018). Adversarial robustness toolbox v1. 0.0. arXiv e-prints."},{"key":"2447_CR92","unstructured":"Pal, S., Yao, Y., Wang, R., Shen, B., & Liu, S. (2024). Backdoor secrets unveiled: Identifying backdoor data with optimized scaled prediction consistency. In ICLR."},{"key":"2447_CR93","unstructured":"Pan, M., Zeng, Y., Lyu, L., Lin, X., & Jia, R. (2023). Asset: Robust backdoor data detection across a multiplicity of deep learning paradigms. In USENIX security symposium."},{"key":"2447_CR94","doi-asserted-by":"crossref","unstructured":"Pang, R., Zhang, Z., Gao, X., Xi, Z., Ji, S., Cheng, P., & Wang, T. (2022). Trojanzoo: Towards unified, holistic, and practical evaluation of neural backdoors. In SP.","DOI":"10.1109\/EuroSP53844.2022.00048"},{"key":"2447_CR95","unstructured":"Papernot, N., Goodfellow, I., Sheatsley, R., Feinman, R., & McDaniel, P. (2016). Cleverhans v1.0.0: An adversarial machine learning library. arXiv e-prints."},{"key":"2447_CR96","doi-asserted-by":"crossref","unstructured":"Phan, H., Xiao, J., Sui, Y., Zhang, T., Tang, Z., Shi, C., Wang, Y., Chen, Y., & Yuan, B. (2025). Clean and compact: Efficient data-free backdoor defense with model compactness. In ECCV (pp. 273\u2013290). Springer.","DOI":"10.1007\/978-3-031-73027-6_16"},{"key":"2447_CR97","unstructured":"Qi, X., Xie, T., Li, Y., Mahloujifar, S., & Mittal, P. (2023a). Revisiting the assumption of latent separability for backdoor defenses. In ICLR."},{"key":"2447_CR98","unstructured":"Qi, X., Xie, T., Wang, T., Wu, T., Mahloujifar, S., & Mittal, P. (2023b). Towards a proactive ml approach for detecting backdoor poison samples. In USENIX security symposium."},{"key":"2447_CR99","doi-asserted-by":"crossref","unstructured":"Qiu, H., Sun, J., Zhang, M., Pan, X., & Yang, M. (2024). Belt: Old-school backdoor attacks can evade the state-of-the-art defense with backdoor exclusivity lifting. In SP.","DOI":"10.1109\/SP54263.2024.00226"},{"key":"2447_CR100","unstructured":"Radford, A., Kim, J. W., Hallacy, C., Ramesh, D. A., Goh, G., Agarwal, S., Sastry, G., Askell, A., Mishkin, P., & Clark, J. (2021). Learning transferable visual models from natural language supervision. In ICML."},{"key":"2447_CR101","unstructured":"Rauber, J., Brendel, W., & Bethge, M. (2017). Foolbox: A python toolbox to benchmark the robustness of machine learning models. In ICML."},{"key":"2447_CR102","doi-asserted-by":"publisher","first-page":"2607","DOI":"10.21105\/joss.02607","volume":"5","author":"J Rauber","year":"2020","unstructured":"Rauber, J., Zimmermann, R., Bethge, M., & Brendel, W. (2020). Foolbox native: Fast adversarial attacks to benchmark the robustness of machine learning models in pytorch, tensorflow, and jax. Journal of Open Source Software, 5, 2607.","journal-title":"Journal of Open Source Software"},{"key":"2447_CR103","first-page":"361","volume":"4","author":"E Sarkar","year":"2022","unstructured":"Sarkar, E., Benkraouda, H., Krishnan, G., Gamil, H., & Maniatakos, M. (2022). Facehack: Attacking facial recognition systems using malicious facial characteristics. IEEE Transactions on Biometrics: Behavior, and Identity Science., 4, 361\u2013372.","journal-title":"IEEE Transactions on Biometrics: Behavior, and Identity Science."},{"key":"2447_CR104","doi-asserted-by":"crossref","unstructured":"Selvaraju, R.R., Cogswell, M., Das, A., Vedantam, R., Parikh, D., & Batra, D. (2017). Grad-cam: Visual explanations from deep networks via gradient-based localization. In ICCV.","DOI":"10.1109\/ICCV.2017.74"},{"key":"2447_CR105","unstructured":"Shi, Y., Du, M., Wu, X., Guan, Z., & Liu, N. (2023). Black-box backdoor defense via zero-shot image purification. In NeurIPS."},{"key":"2447_CR106","unstructured":"Simonyan, K., & Zisserman, A. (2015). Very deep convolutional networks for large-scale image recognition. In ICLR."},{"key":"2447_CR107","doi-asserted-by":"crossref","unstructured":"Song, Z., Li, Y., Yuan, D., Liu, L., Wei, S., & Wu, B. (2024). Wpda: Frequency-based backdoor attack with wavelet packet decomposition. arXiv:2401.13578.","DOI":"10.1016\/j.neunet.2025.108074"},{"key":"2447_CR108","unstructured":"Souri, H., Fowl, L., Chellappa, R., Goldblum, M., & Goldstein, T. (2022). Sleeper agent: Scalable hidden trigger backdoors for neural networks trained from scratch. In NeurIPS."},{"key":"2447_CR109","unstructured":"Tang, D., Wang, X., Tang, H., & Zhang, K. (2021a). Demon in the variant: Statistical analysis of DNNs for robust backdoor contamination detection. In USENIX security symposium (pp. 1541\u20131558)."},{"key":"2447_CR110","unstructured":"Tang, S., Gong, R., Wang, Y., Liu, A., Wang, J., Chen, X., Yu, F., Liu, X., Song, D., & Yuille, A. (2021b). Robustart: Benchmarking robustness on architecture design and training techniques. arXiv e-prints."},{"key":"2447_CR111","unstructured":"Toneva, M., Sordoni, A., Combes, R.T., Trischler, A., Bengio, Y., & Gordon, G. J. (2019). An empirical study of example forgetting during deep neural network learning. In ICLR."},{"key":"2447_CR112","unstructured":"Tran, B., Li, J., & Madry, A. (2018). Spectral signatures in backdoor attacks. In NeurIPS (Vol. 31)."},{"key":"2447_CR113","unstructured":"Turner, A., Tsipras, D., & Madry, A. (2019). Label-consistent backdoor attacks. arXiv e-prints."},{"key":"2447_CR114","doi-asserted-by":"crossref","unstructured":"Wang, B., Yao, Y., Shan, S., Li, H., Viswanath, B., Zheng, H., & Zhao, B. Y. (2019). Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In IEEE SP (pp. 707\u2013723).","DOI":"10.1109\/SP.2019.00031"},{"key":"2447_CR115","unstructured":"Wang, H., Sreenivasan, K., Rajput, S., Vishwakarma, H., Agarwal, S., Sohn, J.-y., Lee, K., & Papailiopoulos, D. (2020). Attack of the tails: Yes, you really can backdoor federated learning. In NeurIPS."},{"key":"2447_CR116","doi-asserted-by":"crossref","unstructured":"Wang, J., Chan, K. C., & Loy, C. C. (2023). Exploring clip for assessing the look and feel of images. In AAAI.","DOI":"10.1609\/aaai.v37i2.25353"},{"key":"2447_CR117","doi-asserted-by":"crossref","unstructured":"Wang, R., Guo, Q., Li, H., & Wan, R. (2024). Event trojan: Asynchronous event-based backdoor attacks. In ECCV.","DOI":"10.1007\/978-3-031-72667-5_18"},{"key":"2447_CR118","doi-asserted-by":"crossref","unstructured":"Wang, T., Yao, Y., Xu, F., An, S., Tong, H., & Wang, T. (2022a). An invisible black-box backdoor attack through frequency domain. In ECCV.","DOI":"10.1007\/978-3-031-19778-9_23"},{"key":"2447_CR119","doi-asserted-by":"crossref","unstructured":"Wang, Z., Simoncelli, E. P., & Bovik, A. C. (2003). Multiscale structural similarity for image quality assessment. In ACSSC.","DOI":"10.1109\/ACSSC.2003.1292216"},{"key":"2447_CR120","doi-asserted-by":"crossref","unstructured":"Wang, Z., Zhai, J., & Ma, S. (2022b). Bppattack: Stealthy and efficient trojan attacks against deep neural networks via image quantization and contrastive adversarial learning. In CVPR.","DOI":"10.1109\/CVPR52688.2022.01465"},{"key":"2447_CR121","unstructured":"Wei, S., Zha, H., & Wu, B. (2024). Mitigating backdoor attack by injecting proactive defensive backdoor. In NeurIPS."},{"key":"2447_CR122","unstructured":"Wei, S., Zhang, M., Zha, H., & Wu, B. (2023). Shared adversarial unlearning: Backdoor mitigation by unlearning shared adversarial examples. In NeurIPS."},{"key":"2447_CR123","unstructured":"Wu, B., Chen, H., Zhang, M., Zhu, Z., Wei, S., Yuan, D., & Shen, C. (2022). Backdoorbench: A comprehensive benchmark of backdoor learning. In NeurIPS D &B Track."},{"key":"2447_CR124","unstructured":"Wu, B., Wei, S., Zhu, M., Zheng, M., Zhu, Z., Zhang, M., Chen, H., Yuan, D., Liu, L., & Liu, Q. (2023a). Defenses in adversarial machine learning: A survey. arXiv:2312.08890."},{"key":"2447_CR125","unstructured":"Wu, B., Zhu, Z., Liu, L., Liu, Q., He, Z., & Lyu, S. (2023b). Attacks in adversarial machine learning: A systematic survey from the life-cycle perspective. arXiv:2302.09457."},{"key":"2447_CR126","unstructured":"Wu, D., & Wang, Y. (2021). Adversarial neuron pruning purifies backdoored deep models. In NeurIPS."},{"key":"2447_CR127","unstructured":"Xia, J., Yue, Z., Zhou, Y., Ling, Z., Wei, X., & Chen, M. (2024). Waveattack: Asymmetric frequency obfuscation-based backdoor attacks against deep neural networks. In NeurIPS."},{"key":"2447_CR128","unstructured":"Xie, C., Huang, K., Chen, P.-Y., & Li, B. (2019). Dba: Distributed backdoor attacks against federated learning. In ICLR."},{"key":"2447_CR129","unstructured":"Xie, T., Qi, X., He, P., Li, Y., Wang, J. T., & Mittal, P. (2024). Badexpert: Extracting backdoor functionality for accurate backdoor input detection. In ICLR."},{"key":"2447_CR130","unstructured":"Xu, Y., Yao, J., Shu, M., Sun, Y., Wu, Z., Yu, N., Goldstein, T., & Huang, F. (2024). Shadowcast: Stealthy data poisoning attacks against vision-language models. In NeurIPS."},{"key":"2447_CR131","unstructured":"Yang, Y., Jia, C., Yan, D., Hu, M., Li, T., Xie, X., Wei, X., & Chen, M. (2023). Sampdetox: Black-box backdoor defense via perturbation-based sample detoxification. In NIPS."},{"key":"2447_CR132","doi-asserted-by":"crossref","unstructured":"Yao, Z., Gholami, A., Keutzer, K., & Mahoney, M. W. (2020). Pyhessian: Neural networks through the lens of the hessian. In IEEE ICBD (pp. 581\u2013590).","DOI":"10.1109\/BigData50022.2020.9378171"},{"key":"2447_CR133","doi-asserted-by":"crossref","unstructured":"Yin, W., Lou, J., Zhou, P., Xie, Y., Feng, D., Sun, Y., Zhang, T., & Sun, L. (2024). Physical backdoor: Towards temperature-based backdoor attacks in the physical world. I: CVPR.","DOI":"10.1109\/CVPR52733.2024.01210"},{"key":"2447_CR134","unstructured":"Yu, L., Liu, S., Miao, Y., Gao, X.-S., & Zhang, L. (2024). Generalization bound and new algorithm for clean-label backdoor attack. In ICML."},{"key":"2447_CR135","doi-asserted-by":"crossref","unstructured":"Yu, Y., Wang, Y., Yang, W., Lu, S., Tan, Y.-P., & Kot, A. C. (2023). Backdoor attacks against deep image compression via adaptive frequency trigger. In CVPR.","DOI":"10.1109\/CVPR52729.2023.01179"},{"key":"2447_CR136","unstructured":"Yuan, D., Wei, S., Zhang, M., Liu, L., & Wu, B. (2025). Activation gradient based poisoned sample detection against backdoor attacks. In ICLR."},{"key":"2447_CR137","unstructured":"Zeng, Y., Chen, S., Park, W., Mao, Z., Jin, M., & Jia, R. (2022). Adversarial unlearning of backdoors via implicit hypergradient. In ICLR."},{"key":"2447_CR138","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Park, W., Mao, Z.M., & Jia, R. (2021). Rethinking the backdoor attacks\u2019 triggers: A frequency perspective. In ICCV.","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"2447_CR139","doi-asserted-by":"crossref","unstructured":"Zhang, J., Dongdong, C., Huang, Q., Liao, J., Zhang, W., Feng, H., Hua, G., & Yu, N. (2022a). Poison ink: Robust and invisible backdoor attack. IEEE Transactions on Image Processing, 31, 5691\u20135705.","DOI":"10.1109\/TIP.2022.3201472"},{"key":"2447_CR140","doi-asserted-by":"crossref","unstructured":"Zhang, X., Jin, Y., Wang, T., Lou, J., & Chen, X. (2022b). Purifier: Plug-and-play backdoor mitigation for pre-trained models via anomaly activation suppression. In ACMMM.","DOI":"10.1145\/3503161.3548065"},{"key":"2447_CR141","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Liu, Q., Wang, Z., Lu, Z., & Hu, Q. (2023). Backdoor defense via deconfounded representation learning. In CVPR.","DOI":"10.1109\/CVPR52729.2023.01177"},{"key":"2447_CR142","unstructured":"Zhang, Z., Panda, A., Song, L., Yang, Y., Mahoney, M., Mittal, P., Kannan, R., & Gonzalez, J. (2022c). Neurotoxin: durable backdoors in federated learning. In ICML."},{"key":"2447_CR143","unstructured":"Zhao, P., Chen, P.-Y., Das, P., Ramamurthy, K. N., & Lin, X. (2020a). Bridging mode connectivity in loss landscapes and adversarial robustness. In ICLR."},{"key":"2447_CR144","doi-asserted-by":"crossref","unstructured":"Zhao, S., Ma, X., Zheng, X., Bailey, J., Chen, J., & Jiang, Y.-G. (2020b). Clean-label backdoor attacks on video recognition models. In CVPR.","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"2447_CR145","unstructured":"Zheng, M., Yan, X., Zhu, Z., Chen, H., & Wu, B. (2023). Blackboxbench: A comprehensive benchmark of black-box adversarial attacks. arXiv:2312.16979."},{"key":"2447_CR146","doi-asserted-by":"crossref","unstructured":"Zheng, R., Tang, R., Li, J., & Liu, L. (2022a). Data-free backdoor removal based on channel lipschitzness. In ECCV.","DOI":"10.1007\/978-3-031-20065-6_11"},{"key":"2447_CR147","unstructured":"Zheng, R., Tang, R., Li, J., & Liu, L. (2022b). Pre-activation distributions expose backdoor neurons. In NeurIPS."},{"key":"2447_CR148","doi-asserted-by":"crossref","unstructured":"Zhou, J., Lv, P., Lan, Y., Meng, G., Chen, K., & Ma, H. (2024). Dataelixir: Purifying poisoned dataset to mitigate backdoor attacks via diffusion models. AAAI, 38, 21850\u201321858.","DOI":"10.1609\/aaai.v38i19.30186"},{"key":"2447_CR149","doi-asserted-by":"crossref","unstructured":"Zhu, H., Zhao, Y., Zhang, S., & Chen, K. (2024a). Neuralsanitizer: Detecting backdoors in neural networks. IEEE Transactions on Information Forensics and Security., 19, 4970\u20134985.","DOI":"10.1109\/TIFS.2024.3390599"},{"key":"2447_CR150","unstructured":"Zhu, M., Liang, S., & Wu, B. (2024b). Breaking the false sense of security in backdoor defense through re-activation attack. In NeurIPS."},{"key":"2447_CR151","doi-asserted-by":"crossref","unstructured":"Zhu, M., Wei, S., Shen, L., Fan, Y., & Wu, B. (2023a). Enhancing fine-tuning based backdoor defense with sharpness-aware minimization. In ICCV.","DOI":"10.1109\/ICCV51070.2023.00412"},{"key":"2447_CR152","unstructured":"Zhu, M., Wei, S., Zha, H., & Wu, B. (2023b). Neural polarizer: A lightweight and effective backdoor defense via purifying poisoned features. In NeurIPS."},{"key":"2447_CR153","unstructured":"Zhu, Z., Zhang, M., Wei, S., Wu, B., & Wu, B. (2024c). Vdc: Versatile data cleanser for detecting dirty samples via visual-linguistic inconsistency. In ICLR."},{"key":"2447_CR154","unstructured":"Zhuang, H., Yu, M., Wang, H., Hua, Y., Li, J., & Yuan, X. (2024). Backdoor federated learning by poisoning backdoor-critical layers. In ICLR."}],"container-title":["International Journal of Computer Vision"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-025-02447-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11263-025-02447-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-025-02447-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,6]],"date-time":"2025-09-06T13:23:08Z","timestamp":1757164988000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11263-025-02447-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,6]]},"references-count":154,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2025,8]]}},"alternative-id":["2447"],"URL":"https:\/\/doi.org\/10.1007\/s11263-025-02447-x","relation":{},"ISSN":["0920-5691","1573-1405"],"issn-type":[{"value":"0920-5691","type":"print"},{"value":"1573-1405","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,6]]},"assertion":[{"value":"5 November 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 March 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 May 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"All codes for our benchmark could be freely downloaded from .","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Code availability"}}]}}