{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T12:12:04Z","timestamp":1774872724473,"version":"3.50.1"},"reference-count":53,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,3,1]],"date-time":"2020-03-01T00:00:00Z","timestamp":1583020800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,3]]},"DOI":"10.1109\/isqed48828.2020.9137011","type":"proceedings-article","created":{"date-parts":[[2020,7,9]],"date-time":"2020-07-09T20:46:45Z","timestamp":1594327605000},"page":"33-39","source":"Crossref","is-referenced-by-count":46,"title":["A Survey on Neural Trojans"],"prefix":"10.1109","author":[{"given":"Yuntao","family":"Liu","sequence":"first","affiliation":[]},{"given":"Ankit","family":"Mondal","sequence":"additional","affiliation":[]},{"given":"Abhishek","family":"Chakraborty","sequence":"additional","affiliation":[]},{"given":"Michael","family":"Zuzak","sequence":"additional","affiliation":[]},{"given":"Nina","family":"Jacobsen","sequence":"additional","affiliation":[]},{"given":"Daniel","family":"Xing","sequence":"additional","affiliation":[]},{"given":"Ankur","family":"Srivastava","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","article-title":"TBT: Targeted Neural Network Attack with Bit Trojan","author":"rakin","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref30","first-page":"227","article-title":"SIN 2: Stealth infection on neural network-a low-cost agile neural trojan attack methodology","author":"liu","year":"0","journal-title":"2018 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref36","article-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref35","first-page":"17","author":"nelson","year":"2009","journal-title":"Misleading Learners Co-opting Your Spam Filter"},{"key":"ref34","first-page":"2871","article-title":"Using Machine Teaching to Identify Optimal Training-Set Attacks on Machine Learners","author":"mei","year":"2015","journal-title":"AAAI"},{"key":"ref28","article-title":"Backdoor embedding in convolutional neural network models via invisible perturbation","author":"liao","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2018.00093"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354245"},{"key":"ref1","first-page":"1615","article-title":"Turning your weakness into a strength: Watermarking deep neural networks by backdooring","volume":"18","author":"adi","year":"0","journal-title":"27th USENIX Security Symposium ( USENIX Security 18)"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240862"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00486"},{"key":"ref21","article-title":"TA-BOR: A Highly Accurate Approach to Inspecting and Restoring Trojan Backdoors in AI Systems","author":"guo","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2017.8228656"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"ref26","article-title":"Invisible Backdoor Attacks Against Deep Neural Networks","author":"li","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref25","article-title":"Universal Litmus Patterns: Revealing Backdoor Attacks in CNNs","author":"kolouri","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref50","article-title":"Generative Poisoning Attack Method Against Neural Networks","author":"yang","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref51","article-title":"Design of intentional backdoors in sequential models","author":"yang","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2018.8659362"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref10","first-page":"4658","article-title":"DeepIn-spect: A Black-box Trojan Detection and Mitigation Framework for Deep Neural Networks","author":"chen","year":"0","journal-title":"Proceedings of the 28th International Joint Conference on Artificial Intelligence"},{"key":"ref11","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"chen","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref40","article-title":"Hidden Trigger Backdoor Attacks","author":"saha","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2018.8646335"},{"key":"ref13","article-title":"Hardware trojan attacks on neural networks","author":"clements","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref14","article-title":"Deep-Cleanse: A Black-box Input SanitizationFramework Against Backdoor Attacks on DeepNeural Networks","author":"doan","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref15","article-title":"Design and Evaluation of a Multi-Domain Trojan Detection Method on Deep Neural Networks","author":"gao","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref16","article-title":"STRIP: A Defence Against Trojan Attacks on Deep Neural Networks","author":"yansong","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2012-0460"},{"key":"ref18","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICIOT.2018.00015"},{"key":"ref6","article-title":"Poisoning attacks against support vector machines","author":"biggio","year":"2012","journal-title":"ArXiv Preprint"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2013.57"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2019.2944586"},{"key":"ref7","author":"chakarov","year":"2016","journal-title":"Debugging machine learning tasks"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/2966986.2967074"},{"key":"ref9","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","author":"chen","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref45","article-title":"Model Agnostic Defence against Backdoor Attacks in Machine Learning","author":"udeshi","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref48","article-title":"Detecting AI Trojans Using Meta Neural Analysis","author":"xu","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref47","article-title":"Revealing Backdoors, Post-Training, in DNN Classifiers via Novel Inference on Optimized Perturbations Inducing Group Misclassification","author":"xiang","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref42","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"ArXiv Preprint"},{"key":"ref41","article-title":"Using Honeypots to Catch Adversarial Attacks on Neural Networks","author":"shan","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref44","first-page":"8000","article-title":"Spectral signatures in backdoor attacks","author":"tran","year":"2018","journal-title":"Advances in neural information processing systems"},{"key":"ref43","article-title":"Bypassing Backdoor Detection Algorithms in Deep Learning","author":"lester tan","year":"2019","journal-title":"ArXiv Preprint"}],"event":{"name":"2020 21st International Symposium on Quality Electronic Design (ISQED)","location":"Santa Clara, CA, USA","start":{"date-parts":[[2020,3,25]]},"end":{"date-parts":[[2020,3,26]]}},"container-title":["2020 21st International Symposium on Quality Electronic Design (ISQED)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9131689\/9136966\/09137011.pdf?arnumber=9137011","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,28]],"date-time":"2022-06-28T21:52:38Z","timestamp":1656453158000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9137011\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3]]},"references-count":53,"URL":"https:\/\/doi.org\/10.1109\/isqed48828.2020.9137011","relation":{},"subject":[],"published":{"date-parts":[[2020,3]]}}}