{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T13:45:51Z","timestamp":1782481551940,"version":"3.54.5"},"reference-count":50,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["W2531009"],"award-info":[{"award-number":["W2531009"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Pattern Recognition"],"published-print":{"date-parts":[[2026,12]]},"DOI":"10.1016\/j.patcog.2026.114247","type":"journal-article","created":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T16:32:47Z","timestamp":1781541167000},"page":"114247","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PC","title":["AdaPT: Adaptive position trigger for improving backdoor attacks in transfer learning"],"prefix":"10.1016","volume":"180","author":[{"given":"Chun","family":"Zhou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hua","family":"Meng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhiguo","family":"Long","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mingxing","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0228-7119","authenticated-orcid":false,"given":"Zhengchun","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"1","key":"10.1016\/j.patcog.2026.114247_b1","doi-asserted-by":"crossref","first-page":"8645","DOI":"10.1038\/s41598-024-58421-z","article-title":"The application of improved densenet algorithm in accurate image recognition","volume":"14","author":"Hou","year":"2024","journal-title":"Sci. Rep."},{"issue":"3","key":"10.1016\/j.patcog.2026.114247_b2","doi-asserted-by":"crossref","first-page":"2233","DOI":"10.1007\/s00521-021-06526-1","article-title":"A real-time and high-precision method for small traffic-signs recognition","volume":"34","author":"Chen","year":"2022","journal-title":"Neural Comput. Appl."},{"key":"10.1016\/j.patcog.2026.114247_b3","doi-asserted-by":"crossref","unstructured":"H. Dhake, A. Agarwal, Unravelling Robustness of Deep Face Recognition Networks Against Illicit Drug Abuse Images, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, CVPRW, 2024, pp. 4842\u20134848.","DOI":"10.1109\/CVPRW63382.2024.00487"},{"key":"10.1016\/j.patcog.2026.114247_b4","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111227","article-title":"Local and global feature attention fusion network for face recognition","volume":"161","author":"Wang","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.114247_b5","doi-asserted-by":"crossref","DOI":"10.1016\/j.compbiomed.2023.107777","article-title":"Medical image identification methods: A review","volume":"169","author":"Li","year":"2024","journal-title":"Comput. Biol. Med."},{"issue":"4","key":"10.1016\/j.patcog.2026.114247_b6","doi-asserted-by":"crossref","first-page":"635","DOI":"10.1162\/neco_a_01740","article-title":"Spiking neuron-astrocyte networks for image recognition","volume":"37","author":"Lorenzo","year":"2025","journal-title":"Neural Comput."},{"key":"10.1016\/j.patcog.2026.114247_b7","article-title":"A comprehensive approach for image quality assessment using quality-centric embedding and ranking networks","author":"Haider","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.114247_b8","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2024.102303","article-title":"Adversarial attacks and defenses in explainable artificial intelligence: A survey","volume":"107","author":"Baniecki","year":"2024","journal-title":"Inf. Fusion"},{"key":"10.1016\/j.patcog.2026.114247_b9","doi-asserted-by":"crossref","DOI":"10.1016\/j.trc.2024.104750","article-title":"Data poisoning attacks in intelligent transportation systems: A survey","volume":"165","author":"Wang","year":"2024","journal-title":"Transp. Res. Part C: Emerg. Technol."},{"issue":"1","key":"10.1016\/j.patcog.2026.114247_b10","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1109\/TNNLS.2022.3182979","article-title":"Backdoor learning: A survey","volume":"35","author":"Li","year":"2024","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"10.1016\/j.patcog.2026.114247_b11","unstructured":"X. Hu, X. Lin, M. Cogswell, Y. Yao, S. Jha, C. Chen, Trigger Hunting with a Topological Prior for Trojan Detection, in: Proceedings of the International Conference on Learning Representations, ICLR, 2022, pp. 1\u201317."},{"key":"10.1016\/j.patcog.2026.114247_b12","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111262","article-title":"A trigger-perceivable backdoor attack framework driven by image steganography","volume":"161","author":"Tang","year":"2025","journal-title":"Pattern Recognit."},{"issue":"3","key":"10.1016\/j.patcog.2026.114247_b13","doi-asserted-by":"crossref","first-page":"1674","DOI":"10.1109\/TPAMI.2024.3507873","article-title":"Robust and transferable backdoor attacks against deep image compression with selective frequency prior","volume":"47","author":"Yu","year":"2025","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.patcog.2026.114247_b14","doi-asserted-by":"crossref","first-page":"4071","DOI":"10.1109\/TIFS.2025.3556346","article-title":"CapsuleBD: A backdoor attack method against federated learning under heterogeneous models","volume":"20","author":"Liao","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.patcog.2026.114247_b15","doi-asserted-by":"crossref","unstructured":"J. He, W. Jiang, G. Hou, W. Fan, R. Zhang, H. Li, Watch out for your guidance on generation! exploring conditional backdoor attacks against large language models, in: Proceedings of the AAAI Conference on Artificial Intelligence, AAAI, 2025, pp. 26220\u201326228.","DOI":"10.1609\/aaai.v39i25.34819"},{"key":"10.1016\/j.patcog.2026.114247_b16","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.112336","article-title":"Backdoor defense based on adversarial prediction proximity and contrastive knowledge distillation","volume":"172","author":"Huang","year":"2026","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.114247_b17","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.112485","article-title":"Perturbation distillation and backdoor feature induction for universal defense in deep vision models","volume":"172","author":"Zeng","year":"2026","journal-title":"Pattern Recognit."},{"issue":"5","key":"10.1016\/j.patcog.2026.114247_b18","doi-asserted-by":"crossref","first-page":"5870","DOI":"10.1007\/s11227-023-05685-3","article-title":"Protecting IoT devices from security attacks using effective decision-making strategy of appropriate features","volume":"80","author":"Ullah","year":"2024","journal-title":"J. Supercomput."},{"key":"10.1016\/j.patcog.2026.114247_b19","doi-asserted-by":"crossref","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","article-title":"BadNets: Evaluating backdooring attacks on deep neural networks","volume":"7","author":"Gu","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.patcog.2026.114247_b20","series-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"10.1016\/j.patcog.2026.114247_b21","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.125892","article-title":"Black-box backdoor attack with everyday physical object in mobile crowdsourcing","volume":"265","author":"Chen","year":"2025","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.patcog.2026.114247_b22","doi-asserted-by":"crossref","first-page":"2318","DOI":"10.1109\/TIFS.2023.3265535","article-title":"Black-box dataset ownership verification via backdoor watermarking","volume":"18","author":"Li","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.patcog.2026.114247_b23","doi-asserted-by":"crossref","unstructured":"K. Doan, Y. Lao, W. Zhao, P. Li, LIRA: Learnable, Imperceptible and Robust Backdoor Attacks, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, ICCV, 2021, pp. 11946\u201311956.","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"10.1016\/j.patcog.2026.114247_b24","unstructured":"K. Doan, Y. Lao, P. Li, Backdoor Attack with Imperceptible Input and Latent Modification, in: Proceedings of the Conference on Neural Information Processing Systems, NeurIPS, 2021, pp. 18944\u201318957."},{"key":"10.1016\/j.patcog.2026.114247_b25","unstructured":"H.A.A.K. Hammoud, B. Ghanem, Check Your Other Door! Creating Backdoor Attacks in the Frequency Domain, in: Proceedings of the British Machine Vision Conference, BMVC, 2022."},{"key":"10.1016\/j.patcog.2026.114247_b26","doi-asserted-by":"crossref","first-page":"5852","DOI":"10.1109\/TIFS.2024.3404885","article-title":"Toward stealthy backdoor attacks against speech recognition via elements of sound","volume":"19","author":"Cai","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"3","key":"10.1016\/j.patcog.2026.114247_b27","doi-asserted-by":"crossref","first-page":"1526","DOI":"10.1109\/TSC.2020.3000900","article-title":"Backdoor attacks against transfer learning with pre-trained deep learning models","volume":"15","author":"Wang","year":"2022","journal-title":"IEEE Trans. Serv. Comput."},{"key":"10.1016\/j.patcog.2026.114247_b28","doi-asserted-by":"crossref","unstructured":"H. Wang, S. Guo, J. He, H. Liu, T. Zhang, T. Xiang, Model Supply Chain Poisoning: Backdooring Pre-trained Models via Embedding Indistinguishability, in: Proceedings of the Web Conference, 2025, pp. 840\u2013851.","DOI":"10.1145\/3696410.3714624"},{"key":"10.1016\/j.patcog.2026.114247_b29","doi-asserted-by":"crossref","unstructured":"B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, B.Y. Zhao, Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks, in: Proceedings of the IEEE Symposium on Security and Privacy, SP, 2019, pp. 707\u2013723.","DOI":"10.1109\/SP.2019.00031"},{"key":"10.1016\/j.patcog.2026.114247_b30","doi-asserted-by":"crossref","unstructured":"R.R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, D. Batra, Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, ICCV, 2017, pp. 618\u2013626.","DOI":"10.1109\/ICCV.2017.74"},{"key":"10.1016\/j.patcog.2026.114247_b31","unstructured":"Y. Li, H. Zhong, X. Ma, Y. Jiang, S.-T. Xia, Few-Shot Backdoor Attacks on Visual Object Tracking, in: Proceedings of the International Conference on Learning Representations, ICLR, 2022, pp. 1\u201321."},{"key":"10.1016\/j.patcog.2026.114247_b32","unstructured":"X. Qi, T. Xie, Y. Li, S. Mahloujifar, P. Mittal, Revisiting the assumption of latent separability for backdoor defenses, in: Proceedings of the International Conference on Learning Representations, ICLR, 2023, pp. 1\u201320."},{"key":"10.1016\/j.patcog.2026.114247_b33","doi-asserted-by":"crossref","unstructured":"Y. Liu, X. Ma, J. Bailey, F. Lu, Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks, in: Proceedings of the European Conference on Computer Vision, ECCV, 2020, pp. 182\u2013199.","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"10.1016\/j.patcog.2026.114247_b34","doi-asserted-by":"crossref","unstructured":"Y. Li, Y. Li, B. Wu, L. Li, R. He, S. Lyu, Invisible backdoor attack with sample-specific triggers, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, ICCV, 2021, pp. 16463\u201316472.","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"10.1016\/j.patcog.2026.114247_b35","doi-asserted-by":"crossref","first-page":"6364","DOI":"10.1109\/TIFS.2024.3411936","article-title":"Backdoor attack with sparse and invisible trigger","volume":"19","author":"Gao","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.patcog.2026.114247_b36","doi-asserted-by":"crossref","unstructured":"X. Xu, Q. Wang, H. Li, N. Borisov, C.A. Gunter, B. Li, Detecting AI Trojans Using Meta Neural Analysis, in: Proceedings of the IEEE Symposium on Security and Privacy, 2021, pp. 103\u2013120.","DOI":"10.1109\/SP40001.2021.00034"},{"key":"10.1016\/j.patcog.2026.114247_b37","unstructured":"X. Xu, K. Huang, Y. Li, Z. Qin, K. Ren, Towards Reliable and Efficient Backdoor Trigger Inversion via Decoupling Benign Features, in: Proceedings of the International Conference on Learning Representations, ICLR, 2024, pp. 1\u201325."},{"key":"10.1016\/j.patcog.2026.114247_b38","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102280","article-title":"Reverse engineering imperceptible backdoor attacks on deep neural networks for detection and training set cleansing","volume":"106","author":"Xiang","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.patcog.2026.114247_b39","doi-asserted-by":"crossref","unstructured":"Z. Wang, K. Mei, H. Ding, J. Zhai, S. Ma, Rethinking the reverse-engineering of trojan triggers, in: Proceedings of the Conference on Neural Information Processing Systems, NeurIPS, 2022, pp. 9738\u20139753.","DOI":"10.52202\/068431-0708"},{"key":"10.1016\/j.patcog.2026.114247_b40","doi-asserted-by":"crossref","unstructured":"Y. Gao, C. Xu, D. Wang, S. Chen, D.C. Ranasinghe, S. Nepal, STRIP: A defence against trojan attacks on deep neural networks, in: Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC, 2019, pp. 113\u2013125.","DOI":"10.1145\/3359789.3359790"},{"key":"10.1016\/j.patcog.2026.114247_b41","doi-asserted-by":"crossref","unstructured":"E. Chou, F. Tram\u00e8r, G. Pellegrino, SentiNet: Detecting Localized Universal Attacks Against Deep Learning Systems, in: Proceedings of the IEEE Security and Privacy Workshops, SPW, 2020, pp. 48\u201354.","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"10.1016\/j.patcog.2026.114247_b42","unstructured":"A. Nguyen, A. Tran, WANet\u2013imperceptible warping-based backdoor attack, in: Proceedings of the International Conference on Learning Representations, ICLR, 2021, pp. 1\u201316."},{"key":"10.1016\/j.patcog.2026.114247_b43","doi-asserted-by":"crossref","unstructured":"Z. Zhao, X. Chen, Y. Xuan, Y. Dong, D. Wang, K. Liang, DEFEAT: Deep Hidden Feature Backdoor Attacks by Imperceptible Perturbation and Latent Representation Constraints, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2022, pp. 15192\u201315201.","DOI":"10.1109\/CVPR52688.2022.01478"},{"key":"10.1016\/j.patcog.2026.114247_b44","doi-asserted-by":"crossref","unstructured":"J. Bai, K. Gao, S. Min, S.-T. Xia, Z. Li, W. Liu, BadCLIP: Trigger-Aware Prompt Learning for Backdoor Attacks on CLIP, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2024, pp. 24239\u201324250.","DOI":"10.1109\/CVPR52733.2024.02288"},{"key":"10.1016\/j.patcog.2026.114247_b45","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104101","article-title":"Precision strike: Precise backdoor attack with dynamic trigger","volume":"148","author":"Li","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.patcog.2026.114247_b46","series-title":"Learning Multiple Layers of Features from Tiny Images","author":"Krizhevsky","year":"2009"},{"key":"10.1016\/j.patcog.2026.114247_b47","doi-asserted-by":"crossref","unstructured":"J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, L. Fei-Fei, ImageNet: A large-scale hierarchical image database, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2009, pp. 248\u2013255.","DOI":"10.1109\/CVPR.2009.5206848"},{"issue":"1","key":"10.1016\/j.patcog.2026.114247_b48","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1016\/j.cviu.2005.09.012","article-title":"Learning generative visual models from few training examples: An incremental Bayesian approach tested on 101 object categories","volume":"106","author":"Fei-Fei","year":"2007","journal-title":"Comput. Vis. Image Underst."},{"key":"10.1016\/j.patcog.2026.114247_b49","doi-asserted-by":"crossref","unstructured":"K. He, X. Zhang, S. Ren, J. Sun, Deep residual learning for image recognition, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2016, pp. 770\u2013778.","DOI":"10.1109\/CVPR.2016.90"},{"key":"10.1016\/j.patcog.2026.114247_b50","series-title":"International Symposium on Research in Attacks, Intrusions, and Defenses","first-page":"273","article-title":"Fine-pruning: Defending against backdooring attacks on deep neural networks","author":"Liu","year":"2018"}],"container-title":["Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326012124?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326012124?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T12:47:53Z","timestamp":1782478073000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0031320326012124"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,12]]},"references-count":50,"alternative-id":["S0031320326012124"],"URL":"https:\/\/doi.org\/10.1016\/j.patcog.2026.114247","relation":{},"ISSN":["0031-3203"],"issn-type":[{"value":"0031-3203","type":"print"}],"subject":[],"published":{"date-parts":[[2026,12]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"AdaPT: Adaptive position trigger for improving backdoor attacks in transfer learning","name":"articletitle","label":"Article Title"},{"value":"Pattern Recognition","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.patcog.2026.114247","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"114247"}}