{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,29]],"date-time":"2025-11-29T06:56:28Z","timestamp":1764399388866,"version":"3.46.0"},"reference-count":19,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T00:00:00Z","timestamp":1761091200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,22]],"date-time":"2025-10-22T00:00:00Z","timestamp":1761091200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,22]]},"DOI":"10.1109\/apsipaasc65261.2025.11248971","type":"proceedings-article","created":{"date-parts":[[2025,11,28]],"date-time":"2025-11-28T18:40:26Z","timestamp":1764355226000},"page":"2146-2151","source":"Crossref","is-referenced-by-count":0,"title":["Detoxification of Poisoned Recognition Models by Fine-Tuning with Out-of-Distribution Samples"],"prefix":"10.1109","author":[{"given":"Junsuke","family":"Takano","sequence":"first","affiliation":[{"name":"Tokyo University of Science,Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kazuaki","family":"Nakamura","sequence":"additional","affiliation":[{"name":"Tokyo University of Science,Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3551636"},{"key":"ref2","first-page":"6106","article-title":"Poison frogs! targeted clean-label poisoning attacks on neural networks","volume":"31","author":"Shafahi","year":"2018","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref3","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume":"30","author":"Blanchard","year":"2017","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref4","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proceedings of the 35th International Conference on Machine Learning. Pmlr","author":"Yin","year":"2018"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/670"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20903"},{"journal-title":"Byzantine-robust federated machine learning through adaptive model averaging","year":"2019","author":"Mu\u00f1oz-Gonz\u00e1lez","key":"ref7"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3030072"},{"key":"ref9","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics. PMLR","author":"McMahan","year":"2017"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-35166-3_34"},{"journal-title":"Generative poisoning attack method against neural networks","year":"2017","author":"Yang","key":"ref11"},{"key":"ref12","article-title":"A little is enough: Circumventing defenses for distributed learning","volume":"32","author":"Baruch","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.03.124"},{"key":"ref14","first-page":"97","article-title":"Support vector machines under adversarial label noise","volume-title":"Proceedings of the 3rd Asian Conference on Machine Learning. PMLR","author":"Biggio","year":"2011"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140451"},{"journal-title":"Detection of adversarial training examples in poisoning attacks through anomaly detection","year":"2018","author":"Paudice","key":"ref16"},{"journal-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1111\/exsy.13161"}],"event":{"name":"2025 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)","start":{"date-parts":[[2025,10,22]]},"location":"Singapore, Singapore","end":{"date-parts":[[2025,10,24]]}},"container-title":["2025 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11248853\/11248968\/11248971.pdf?arnumber=11248971","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,29]],"date-time":"2025-11-29T06:52:44Z","timestamp":1764399164000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11248971\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,22]]},"references-count":19,"URL":"https:\/\/doi.org\/10.1109\/apsipaasc65261.2025.11248971","relation":{},"subject":[],"published":{"date-parts":[[2025,10,22]]}}}