{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T16:24:26Z","timestamp":1774023866103,"version":"3.50.1"},"reference-count":37,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100000923","name":"Australian Research Council","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/access.2021.3101289","type":"journal-article","created":{"date-parts":[[2021,7,30]],"date-time":"2021-07-30T20:23:55Z","timestamp":1627676635000},"page":"135856-135867","source":"Crossref","is-referenced-by-count":11,"title":["Cassandra: Detecting Trojaned Networks From Adversarial Perturbations"],"prefix":"10.1109","volume":"9","author":[{"given":"Xiaoyu","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9068-7429","authenticated-orcid":false,"given":"Rohit","family":"Gupta","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5206-3842","authenticated-orcid":false,"given":"Ajmal","family":"Mian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nazanin","family":"Rahnavard","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8216-1128","authenticated-orcid":false,"given":"Mubarak","family":"Shah","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref33","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2018","journal-title":"Int Conf Learn Represent"},{"key":"ref32","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref31","year":"2020","journal-title":"NIST TrojAI Round 0 Dataset"},{"key":"ref30","year":"2020","journal-title":"NIST TrojAI Round 0 Dataset"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_14"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref10","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc 3rd Int Conf Learn Represent (ICLR)"},{"key":"ref11","article-title":"On the (statistical) detection of adversarial examples","author":"grosse","year":"2017","journal-title":"arXiv 1702 06280"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref13","article-title":"TABOR: A highly accurate approach to inspecting and restoring Trojan backdoors in AI systems","author":"guo","year":"2019","journal-title":"arXiv 1908 01763"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1974.10482962"},{"key":"ref15","article-title":"Early methods for detecting adversarial images","author":"hendrycks","year":"2016","journal-title":"arXiv 1608 00530"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00140"},{"key":"ref17","article-title":"NeuronInspect: Detecting backdoors in neural networks via output explanations","author":"huang","year":"2019","journal-title":"arXiv 1911 07399"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00893"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00038"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref3","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","author":"chen","year":"2018","journal-title":"arXiv 1811 03728"},{"key":"ref6","article-title":"SentiNet: Detecting localized universal attacks against deep learning systems","author":"chou","year":"2018","journal-title":"arXiv 1812 00292"},{"key":"ref29","article-title":"Fast feature fool: A data independent approach to universal adversarial perturbations","author":"mopuri","year":"2017","journal-title":"arXiv 1707 05572 [cs]"},{"key":"ref5","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"chen","year":"2017","journal-title":"arXiv 1712 05526"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref7","article-title":"Odyssey: Creation, analysis and detection of Trojan models","author":"edraki","year":"2020","journal-title":"arXiv 2007 08142"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref9","article-title":"Detecting adversarial samples from artifacts","author":"feinman","year":"2017","journal-title":"arXiv 1703 00410"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00357"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.56"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ISQED48828.2020.9137011"},{"key":"ref26","article-title":"On detecting adversarial perturbations","author":"metzen","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9312710\/09502110.pdf?arnumber=9502110","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,17]],"date-time":"2021-12-17T19:57:18Z","timestamp":1639771038000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9502110\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":37,"URL":"https:\/\/doi.org\/10.1109\/access.2021.3101289","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}