{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T04:03:13Z","timestamp":1778040193603,"version":"3.51.4"},"reference-count":72,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00412","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"4328-4338","source":"Crossref","is-referenced-by-count":1,"title":["Backdoor Attacks on Neural Networks Via One-Bit Flip"],"prefix":"10.1109","author":[{"given":"Xiang","family":"Li","sequence":"first","affiliation":[{"name":"George Mason University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lannan","family":"Luo","sequence":"additional","affiliation":[{"name":"George Mason University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiang","family":"Zeng","sequence":"additional","affiliation":[{"name":"George Mason University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Lpips implementation"},{"key":"ref2","volume-title":"Ssim implementation"},{"key":"ref3","volume-title":"Resnet implementation."},{"key":"ref4","volume-title":"Vision transformer implementation"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02343"},{"key":"ref6","article-title":"Targeted attack against deep neural networks via flipping limited weight bits","volume-title":"International Conference on Learning Representations","author":"Bai","year":"2021"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_7"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00223"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00762"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0707"},{"key":"ref13","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"CoRR"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230419"},{"key":"ref15","article-title":"SMASH: synchronized many-sided rowhammer attacks from javascript","volume-title":"USENIX Security Symposium","author":"De Ridder","year":"2021"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00432"},{"key":"ref19","article-title":"An image is worth 16x16 words: Transformers for image recognition at scale","volume-title":"International Conference on Learning Representations","author":"Dosovitskiy","year":"2021"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00031"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref22","article-title":"AEVA: black-box backdoor detection using adversarial extreme value analysis","volume-title":"International Conference on Learning Representations","author":"Guo","year":"2022"},{"key":"ref23","article-title":"SCALE-UP: an efficient black-box input-level backdoor detection via analyzing scaled prediction consistency","volume-title":"International Conference on Learning Representations","author":"Guo","year":"2023"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM50108.2020.00025"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref26","article-title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","volume-title":"USENIX Security Symposium","author":"Hong","year":"2019"},{"key":"ref27","article-title":"Distilling cognitive backdoor patterns within an image","volume-title":"International Conference on Learning Representations","author":"Huang","year":"2023"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833772"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00786"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-64171-8_24"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2014.6853210"},{"key":"ref32","author":"Krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images."},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00020"},{"key":"ref34","article-title":"Yes, one-bit-flip matters! universal DNN model inference depletion with runtime code fault injection","volume-title":"USENIX Security Symposium","author":"Li","year":"2024"},{"key":"ref35","article-title":"Rowhammer-based trojan injection: One bit flip is sufficient for backdooring DNNs","volume-title":"USENIX Security Symposium","author":"Li","year":"2025"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref37","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"International Conference on Learning Representations","author":"Li","year":"2021"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2017.8203770"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23069"},{"key":"ref44","article-title":"8-bit inference with tensorrt","volume-title":"GPU technology conference","author":"Migacz","year":"2017"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01963"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/2485922.2485927"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref48","article-title":"Wanet - imperceptible warping-based backdoor attack","volume-title":"International Conference on Learning Representations","author":"Nguyen","year":"2021"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01176"},{"key":"ref50","article-title":"Revisiting the assumption of latent separability for backdoor defenses","volume-title":"International Conference on Learning Representations","author":"Qi","year":"2023"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453108"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"ref54","article-title":"Deep-dup: An adversarial weight duplication attack framework to crush deep neural network in multi-tenant FPGA","volume-title":"USENIX Security Symposium","author":"Siraj Rakin","year":"2021"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"ref56","article-title":"T-BFA: targeted bit-flip adversarial weight attack","author":"Siraj Rakin","year":"2022","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"ref57","article-title":"Flip feng shui: Hammering a needle in the software stack","volume-title":"USENIX Security Symposium","author":"Razavi","year":"2016"},{"key":"ref58","article-title":"Backdoor scanning for deep neural networks through karm optimization","volume-title":"International Conference on Machine Learning","author":"Shen","year":"2021"},{"key":"ref59","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"International Conference on Learning Representations","author":"Simonyan","year":"2015"},{"key":"ref60","article-title":"Throwhammer: Rowhammer attacks over the network and defenses","volume-title":"USENIX Annual Technical Conference","author":"Tatar","year":"2018"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833802"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00023"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978406"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_14"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19778-9_23"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"ref68","article-title":"Adversarial neuron pruning purifies backdoored deep models","author":"Wu","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/554"},{"key":"ref70","article-title":"Deephammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips","volume-title":"USENIX Security Symposium","author":"Yao","year":"2020"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00392"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11445676.pdf?arnumber=11445676","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T05:02:58Z","timestamp":1777611778000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11445676\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":72,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00412","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}