{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T05:44:37Z","timestamp":1782798277747,"version":"3.54.5"},"reference-count":38,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/infocom59046.2026.11571574","type":"proceedings-article","created":{"date-parts":[[2026,6,29]],"date-time":"2026-06-29T19:38:15Z","timestamp":1782761895000},"page":"1-10","source":"Crossref","is-referenced-by-count":0,"title":["TrojanEdge: Mutual Information-Enhanced Robust and Persistent Backdoor Attacks for Edge and On-Device Deployments"],"prefix":"10.1109","author":[{"given":"Zemin","family":"Chen","sequence":"first","affiliation":[{"name":"Old Dominion University,VA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jian","family":"Li","sequence":"additional","affiliation":[{"name":"Old Dominion University,VA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Miao","family":"Lin","sequence":"additional","affiliation":[{"name":"Old Dominion University,VA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Austin","family":"Mao","sequence":"additional","affiliation":[{"name":"Swarthmore College,PA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lusi","family":"Li","sequence":"additional","affiliation":[{"name":"Old Dominion University,VA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rui","family":"Ning","sequence":"additional","affiliation":[{"name":"Old Dominion University,VA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"ChunSheng","family":"Xin","sequence":"additional","affiliation":[{"name":"Iowa State University,Ames,IA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongyi","family":"Wu","sequence":"additional","affiliation":[{"name":"The University of Arizona,Tucson,AZ,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.3390\/app12188972"},{"key":"ref2","author":"Yin","year":"2017","journal-title":"Comparative study of cnn and rnn for natural language processing"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2015-270"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref5","author":"Chen","year":"2017","journal-title":"Targeted backdoor attacks on deep learning systems using data poisoning"},{"key":"ref6","author":"Nguyen","year":"2021","journal-title":"Wanet-imperceptible warping-based backdoor attack"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488902"},{"key":"ref8","author":"Chen","year":"2018","journal-title":"Detecting backdoor attacks on deep neural networks by activation clustering"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i7.28611"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00366"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02340"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i9.21272"},{"issue":"Mar","key":"ref16","first-page":"1415","article-title":"Feature extraction by non-parametric mutual information maximization","volume":"3","author":"Torkkola","year":"2003","journal-title":"Journal ofMachine Learning Research"},{"key":"ref17","author":"Hjelm","year":"2018","journal-title":"Learning deep representations by mutual information estimation and maximization"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/WACV61041.2025.00737"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref23","author":"Turner","year":"2019","journal-title":"Label-consistent backdoor attacks"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616617"},{"key":"ref26","first-page":"345","article-title":"Input-aware dynamic backdoor attack","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS)","volume":"33","author":"Nguyen"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.52202\/079017-0753"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref29","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS)","volume":"34","author":"Wu"},{"key":"ref30","author":"Li","year":"2021","journal-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/206"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01301"},{"key":"ref33","author":"Guo","year":"2023","journal-title":"Scale-up: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency"},{"key":"ref34","author":"Guo","year":"2021","journal-title":"Aeva: Black-box backdoor detection using adversarial extreme value analysis"},{"key":"ref35","author":"Sha","year":"2022","journal-title":"Fine-tuning is all you need to mitigate backdoor attacks"},{"issue":"10","key":"ref36","first-page":"5587","article-title":"Mitigating backdoor attacks through fine-tuning with data augmentation","volume":"33","author":"Chen","year":"2022","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737381"},{"key":"ref38","first-page":"1929","article-title":"Dropout: A simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"Journal of Machine Learning Research"}],"event":{"name":"IEEE INFOCOM 2026 - IEEE Conference on Computer Communications","location":"Tokyo, Japan","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["IEEE INFOCOM 2026 - IEEE Conference on Computer Communications"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11571071\/11571169\/11571574.pdf?arnumber=11571574","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T05:12:57Z","timestamp":1782796377000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11571574\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/infocom59046.2026.11571574","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}