{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T04:59:14Z","timestamp":1776056354479,"version":"3.50.1"},"reference-count":58,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/OAPA.html"},{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/OAPA.html"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1801495"],"award-info":[{"award-number":["1801495"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2019]]},"DOI":"10.1109\/access.2019.2909068","type":"journal-article","created":{"date-parts":[[2019,4,22]],"date-time":"2019-04-22T21:47:42Z","timestamp":1555969662000},"page":"47230-47244","source":"Crossref","is-referenced-by-count":960,"title":["BadNets: Evaluating Backdooring Attacks on Deep Neural Networks"],"prefix":"10.1109","volume":"7","author":[{"given":"Tianyu","family":"Gu","sequence":"first","affiliation":[]},{"given":"Kang","family":"Liu","sequence":"additional","affiliation":[]},{"given":"Brendan","family":"Dolan-Gavitt","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6158-9512","authenticated-orcid":false,"given":"Siddharth","family":"Garg","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991125"},{"key":"ref38","first-page":"8011","article-title":"Spectral signatures in backdoor attacks","author":"tran","year":"2018","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref33","author":"evtimov","year":"2017","journal-title":"Robust physical-world attacks on deep learning models"},{"key":"ref32","first-page":"1765","article-title":"Universal adversarial perturbations","author":"moosavi-dezfooli","year":"2016","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit"},{"key":"ref31","first-page":"506","article-title":"Practical black-box attacks against machine learning","author":"papernot","year":"2016","journal-title":"Proc ACM Asia Conf Comput Commun Secur"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"ref37","author":"wang","year":"2019","journal-title":"Neural Cleanse Identifying and Mitigating Backdoor Attacks in Neural Networks"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref35","author":"chen","year":"2018","journal-title":"Targeted backdoor attacks on deep learning systems using data poisoning"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74320-0_13"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_4"},{"key":"ref29","first-page":"1467","article-title":"Poisoning attacks against support vector machines","author":"biggio","year":"2012","journal-title":"Proc Int Conf Int Conf Mach Learn"},{"key":"ref2","year":"2012","journal-title":"Imagenet Large Scale Visual Recognition Competition"},{"key":"ref1","first-page":"1","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","author":"gu","year":"2017","journal-title":"Proc Neural Inf Process Symp Workshop Mach Learn Secur (MLSec)"},{"key":"ref20","author":"goodfellow","year":"2014","journal-title":"Explaining and Harnessing Adversarial Examples"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"ref24","first-page":"1","article-title":"Good word attacks on statistical spam filters","author":"lowd","year":"2005","journal-title":"Proc of the Conf on Email and Anti-Spam"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_5"},{"key":"ref25","first-page":"1","article-title":"On attacking statistical spam filters","author":"wittel","year":"2004","journal-title":"Proc of the Conf on Email and Anti-Spam"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.312"},{"key":"ref51","first-page":"91","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","author":"ren","year":"2015","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866315"},{"key":"ref57","year":"0","journal-title":"Network in Network Imagenet Model"},{"key":"ref56","author":"yu","year":"0","journal-title":"A Comprehensive guide to Fine-tuning Deep Learning Models in Keras (Part II)"},{"key":"ref55","author":"ruder","year":"0","journal-title":"Transfer Learning&#x2013;Machine Learning&#x2019;s Next Frontier"},{"key":"ref54","author":"karpathy","year":"0","journal-title":"Transfer Learning and Fine-Tuning Convolutional Neural Networks"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.3390\/a10040127"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ITSC.2014.6957882"},{"key":"ref10","year":"2019","journal-title":"Azure Batch AI Training"},{"key":"ref11","year":"2019","journal-title":"Deep Learning AMI Amazon Linux Version"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140451"},{"key":"ref12","year":"2019","journal-title":"Caffe Model Zoo"},{"key":"ref13","year":"2019","journal-title":"Keras Pre-trained Models"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2014.131"},{"key":"ref15","first-page":"647","article-title":"Decaf: A deep convolutional activation feature for generic visual recognition","author":"donahue","year":"2014","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref16","first-page":"1097","article-title":"Imagenet classification with deep convolutional neural networks","author":"krizhevsky","year":"2012","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref17","author":"simonyan","year":"2014","journal-title":"Very Deep Convolutional Networks for Large-scale Image Recognition"},{"key":"ref18","first-page":"2818","article-title":"Rethinking the inception architecture for computer vision","author":"szegedy","year":"2015","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit"},{"key":"ref19","author":"szegedy","year":"2013","journal-title":"Intriguing properties of neural networks"},{"key":"ref4","first-page":"1","article-title":"Multilingual distributed representations without word alignment","author":"hermann","year":"2014","journal-title":"Proc ICLR"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6638947"},{"key":"ref6","author":"mnih","year":"2013","journal-title":"Playing atari with deep reinforcement learning"},{"key":"ref5","author":"bahdanau","year":"2014","journal-title":"Neural machine translation by jointly learning to align and translate"},{"key":"ref8","author":"karpathy","year":"2014","journal-title":"What I Learned From Competing Against a Convnet on-ImageNet"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1038\/nature16961"},{"key":"ref49","author":"zhang","year":"2016","journal-title":"Convolutional neural network"},{"key":"ref9","year":"2019","journal-title":"Google Cloud Machine Learning Engine"},{"key":"ref46","first-page":"513","article-title":"Domain adaptation for large-scale sentiment classification: A deep learning approach","author":"glorot","year":"2011","journal-title":"Proc 28th Int Conf Mach Learn (ICML)"},{"key":"ref45","first-page":"3320","article-title":"How transferable are features in deep neural networks?","author":"yosinski","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref48","first-page":"276","article-title":"Learning algorithms for classification: A comparison on handwritten digit recognition","volume":"261","author":"lecun","year":"1995","journal-title":"Neural Networks The Statistical Mechanics Perspective"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1049\/iet-cvi.2010.0040"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2014.09.003"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243757"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2009.191"},{"key":"ref43","first-page":"494","article-title":"Training a 3-node neural network is NP-complete","author":"blum","year":"1989","journal-title":"Proc Adv Neural Inf Process Syst"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielaam\/6287639\/8600701\/8685687-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8600701\/08685687.pdf?arnumber=8685687","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,8]],"date-time":"2022-04-08T18:53:50Z","timestamp":1649444030000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8685687\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"references-count":58,"URL":"https:\/\/doi.org\/10.1109\/access.2019.2909068","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]}}}