{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T16:32:11Z","timestamp":1777307531683,"version":"3.51.4"},"reference-count":40,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100004829","name":"Science and Technology Department of Sichuan Province","doi-asserted-by":"publisher","award":["2022ZDZX0004,2025ZHRG0006"],"award-info":[{"award-number":["2022ZDZX0004,2025ZHRG0006"]}],"id":[{"id":"10.13039\/501100004829","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004829","name":"Science and Technology Department of Sichuan Province","doi-asserted-by":"publisher","award":["2023YFG0374"],"award-info":[{"award-number":["2023YFG0374"]}],"id":[{"id":"10.13039\/501100004829","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2333207,62472020"],"award-info":[{"award-number":["U2333207,62472020"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62271128"],"award-info":[{"award-number":["62271128"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Information Fusion"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.inffus.2026.104308","type":"journal-article","created":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T15:12:02Z","timestamp":1774883522000},"page":"104308","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Defending against high-poisoning backdoor attacks by exploiting loss divergence"],"prefix":"10.1016","volume":"133","author":[{"given":"Yuzhuo","family":"Jin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ruijin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Na","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Donglin","family":"He","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiquan","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"issue":"11","key":"10.1016\/j.inffus.2026.104308_bib0001","doi-asserted-by":"crossref","first-page":"116","DOI":"10.1109\/MCOM.001.1900091","article-title":"Data security issues in deep learning: attacks, countermeasures, and opportunities","volume":"57","author":"Xu","year":"2019","journal-title":"IEEE Commun. Mag."},{"key":"10.1016\/j.inffus.2026.104308_bib0002","doi-asserted-by":"crossref","first-page":"4566","DOI":"10.1109\/ACCESS.2020.3045078","article-title":"Privacy and security issues in deep learning: a survey","volume":"9","author":"Liu","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.inffus.2026.104308_bib0003","unstructured":"Y. Gao, B.G. Doan, Z. Zhang, S. Ma, J. Zhang, A. Fu, S. Nepal, H. Kim, Backdoor attacks and countermeasures on deep learning: A comprehensive review, arXiv: 2007.10760(2020)."},{"key":"10.1016\/j.inffus.2026.104308_bib0004","unstructured":"X. Chen, C. Liu, B. Li, K. Lu, D. Song, Targeted backdoor attacks on deep learning systems using data poisoning, arXiv: 1712.05526(2017)."},{"issue":"1","key":"10.1016\/j.inffus.2026.104308_bib0005","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/TII.2022.3198481","article-title":"Data poisoning attacks in internet-of-vehicle networks: taxonomy, state-of-the-art, and future directions","volume":"19","author":"Chen","year":"2022","journal-title":"IEEE Trans. Ind. Inf."},{"key":"10.1016\/j.inffus.2026.104308_bib0006","series-title":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","first-page":"23","article-title":"Backstabber\u2019s knife collection: a review of open source software supply chain attacks","author":"Ohm","year":"2020"},{"key":"10.1016\/j.inffus.2026.104308_bib0007","article-title":"Measuring and preventing supply chain attacks on package managers","author":"Duan","year":"2020","journal-title":"CoRR"},{"key":"10.1016\/j.inffus.2026.104308_bib0008","doi-asserted-by":"crossref","DOI":"10.1016\/j.rineng.2024.103295","article-title":"A comprehensive analysis of model poisoning attacks in federated learning for autonomous vehicles: a benchmark study","volume":"24","author":"Almutairi","year":"2024","journal-title":"Results in Engineering"},{"key":"10.1016\/j.inffus.2026.104308_bib0009","doi-asserted-by":"crossref","first-page":"80674","DOI":"10.52202\/079017-2565","article-title":"Mitigating backdoor attack by injecting proactive defensive backdoor","volume":"37","author":"Wei","year":"2024","journal-title":"Adv. Neural Inf Process. Syst."},{"key":"10.1016\/j.inffus.2026.104308_bib0010","series-title":"European Symposium on Research in Computer Security","first-page":"85","article-title":"Have you poisoned my data? defending neural networks against data poisoning","author":"De Gaspari","year":"2024"},{"issue":"6","key":"10.1016\/j.inffus.2026.104308_bib0011","doi-asserted-by":"crossref","first-page":"902","DOI":"10.1109\/TSUSC.2024.3374049","article-title":"Fedpkr: federated learning with non-iid data via periodic knowledge review in edge computing","volume":"9","author":"Wang","year":"2024","journal-title":"IEEE Trans. Sustainable Comput."},{"key":"10.1016\/j.inffus.2026.104308_bib0012","unstructured":"A. Levine, S. Feizi, Deep partition aggregation: Provable defense against general poisoning attacks, arXiv: 2006.14768(2020)."},{"key":"10.1016\/j.inffus.2026.104308_bib0013","series-title":"33Rd USENIX Security Symposium (USENIX Security 24)","first-page":"4157","article-title":"Lurking in the shadows: unveiling stealthy backdoor attacks against personalized federated learning","author":"Lyu","year":"2024"},{"key":"10.1016\/j.inffus.2026.104308_bib0014","article-title":"Certified defenses for data poisoning attacks","volume":"30","author":"Steinhardt","year":"2017","journal-title":"Adv. Neural Inf. Process Syst."},{"key":"10.1016\/j.inffus.2026.104308_bib0015","article-title":"Spectral signatures in backdoor attacks","volume":"31","author":"Tran","year":"2018","journal-title":"Adv. Neural Inf. Process Syst."},{"key":"10.1016\/j.inffus.2026.104308_bib0016","unstructured":"B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, T. Lee, I. Molloy, B. Srivastava, Detecting backdoor attacks on deep neural networks by activation clustering, arXiv: 1811.03728(2018)."},{"key":"10.1016\/j.inffus.2026.104308_bib0017","series-title":"32Nd USENIX Security Symposium (USENIX Security 23)","first-page":"1667","article-title":"{Meta-Sift}: How to sift out a clean subset in the presence of data poisoning?","author":"Zeng","year":"2023"},{"issue":"3","key":"10.1016\/j.inffus.2026.104308_bib0018","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3381028","article-title":"Outlier detection: methods, models, and classification","volume":"53","author":"Boukerche","year":"2020","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"10.1016\/j.inffus.2026.104308_bib0019","series-title":"2008 IEEE Symposium on Security and Privacy (Sp 2008)","first-page":"81","article-title":"Casting out demons: sanitizing training data for anomaly sensors","author":"Cretu","year":"2008"},{"key":"10.1016\/j.inffus.2026.104308_bib0020","unstructured":"A. Paudice, L. Mu\u00f1oz-Gonz\u00e1lez, A. Gyorgy, E.C. Lupu, Detection of adversarial training examples in poisoning attacks through anomaly detection, arXiv: 1802.03041(2018a)."},{"key":"10.1016\/j.inffus.2026.104308_bib0021","series-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","first-page":"5","article-title":"Label sanitization against label flipping poisoning attacks","author":"Paudice","year":"2018"},{"key":"10.1016\/j.inffus.2026.104308_bib0022","series-title":"2020 IEEE International Conference on Teaching, Assessment, and Learning for Engineering (TALE)","first-page":"9","article-title":"Nearest centroid: a bridge between statistics and machine learning","author":"Thulasidas","year":"2020"},{"key":"10.1016\/j.inffus.2026.104308_bib0023","series-title":"Proceedings of the 22Nd ACM SIGSAC Conference on Computer and Communications Security","first-page":"1322","article-title":"Model inversion attacks that exploit confidence information and basic countermeasures","author":"Fredrikson","year":"2015"},{"key":"10.1016\/j.inffus.2026.104308_bib0024","first-page":"14900","article-title":"Anti-backdoor learning: training clean models on poisoned data","volume":"34","author":"Li","year":"2021","journal-title":"Adv. Neural Inf. Process Syst."},{"key":"10.1016\/j.inffus.2026.104308_bib0025","series-title":"2022 14Th International Conference on COMmunication Systems & NETworkS (COMSNETS)","first-page":"1","article-title":"Influence based defense against data poisoning attacks in online learning","author":"Seetharaman","year":"2022"},{"key":"10.1016\/j.inffus.2026.104308_bib0026","doi-asserted-by":"crossref","unstructured":"R. Xiao, Y. Dong, H. Wang, L. Feng, R. Wu, G. Chen, J. Zhao, Promix: Combating label noise via maximizing clean sample utility, arXiv: 2207.10276(2022).","DOI":"10.24963\/ijcai.2023\/494"},{"key":"10.1016\/j.inffus.2026.104308_bib0027","unstructured":"H. Xia, H. Hong, R. Wang, CBPF: Filtering Poisoned Data Based on Composite Backdoor Attack, arXiv: 2406.16125(2024)."},{"key":"10.1016\/j.inffus.2026.104308_bib0028","series-title":"Network and Distributed System Security Symposium (NDSS)","article-title":"Try to poison my deep learning data? nowhere to hide your trajectory spectrum!","author":"Gao","year":"2025"},{"key":"10.1016\/j.inffus.2026.104308_bib0029","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"155","article-title":"The victim and the beneficiary: exploiting a poisoned model to train a clean model on poisoned data","author":"Zhu","year":"2023"},{"key":"10.1016\/j.inffus.2026.104308_bib0030","series-title":"Proceedings of the IEEE International Conference on Computer Vision","first-page":"618","article-title":"Grad-cam: visual explanations from deep networks via gradient-based localization","author":"Selvaraju","year":"2017"},{"key":"10.1016\/j.inffus.2026.104308_bib0031","doi-asserted-by":"crossref","unstructured":"D. Yoon, J. Jang, S. Kim, M. Seo, Gradient ascent post-training enhances language model generalization, arXiv: 2306.07052(2023).","DOI":"10.18653\/v1\/2023.acl-short.74"},{"key":"10.1016\/j.inffus.2026.104308_bib0032","unstructured":"A. Krizhevsky, G. Hinton, et al., Learning multiple layers of features from tiny images (2009)."},{"key":"10.1016\/j.inffus.2026.104308_bib0033","doi-asserted-by":"crossref","first-page":"323","DOI":"10.1016\/j.neunet.2012.02.016","article-title":"Man vs. computer: benchmarking machine learning algorithms for traffic sign recognition","volume":"32","author":"Stallkamp","year":"2012","journal-title":"Neural networks"},{"key":"10.1016\/j.inffus.2026.104308_bib0034","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.inffus.2026.104308_bib0035","unstructured":"S. Zagoruyko, N. Komodakis, Wide residual networks, arXiv: 1605.07146(2016)."},{"key":"10.1016\/j.inffus.2026.104308_bib0036","unstructured":"T. Gu, B. Dolan-Gavitt, S. Garg, Badnets: Identifying vulnerabilities in the machine learning model supply chain, arXiv: 1708.06733(2017)."},{"key":"10.1016\/j.inffus.2026.104308_bib0037","series-title":"2019 IEEE International Conference on Image Processing (ICIP)","first-page":"101","article-title":"A new backdoor attack in cnns by training set corruption without label poisoning","author":"Barni","year":"2019"},{"key":"10.1016\/j.inffus.2026.104308_bib0038","unstructured":"A. Turner, D. Tsipras, A. Madry, Label-consistent backdoor attacks, arXiv: 1912.02771(2019)."},{"key":"10.1016\/j.inffus.2026.104308_bib0039","unstructured":"A. Nguyen, A. Tran, Wanet\u2013imperceptible warping-based backdoor attack, arXiv: 2102.10369(2021)."},{"key":"10.1016\/j.inffus.2026.104308_bib0040","series-title":"International Conference on Machine Learning","first-page":"4129","article-title":"Spectre: defending against backdoor attacks using robust statistics","author":"Hayase","year":"2021"}],"container-title":["Information Fusion"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1566253526001879?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1566253526001879?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T15:33:09Z","timestamp":1777303989000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1566253526001879"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":40,"alternative-id":["S1566253526001879"],"URL":"https:\/\/doi.org\/10.1016\/j.inffus.2026.104308","relation":{},"ISSN":["1566-2535"],"issn-type":[{"value":"1566-2535","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Defending against high-poisoning backdoor attacks by exploiting loss divergence","name":"articletitle","label":"Article Title"},{"value":"Information Fusion","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.inffus.2026.104308","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104308"}}