{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T17:55:11Z","timestamp":1761760511045,"version":"build-2065373602"},"reference-count":26,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272463","62402117"],"award-info":[{"award-number":["62272463","62402117"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Opening Project of MoE Key Laboratory of Information Technology","award":["20242D001"],"award-info":[{"award-number":["20242D001"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Signal Process. Lett."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/lsp.2025.3617292","type":"journal-article","created":{"date-parts":[[2025,10,3]],"date-time":"2025-10-03T17:28:12Z","timestamp":1759512492000},"page":"3979-3983","source":"Crossref","is-referenced-by-count":0,"title":["IBSD: Iterable Black-Box Self-Defense Against Backdoor Attacks"],"prefix":"10.1109","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7957-0441","authenticated-orcid":false,"given":"Zhengxian","family":"Wu","sequence":"first","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4199-2988","authenticated-orcid":false,"given":"Juan","family":"Wen","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9636-6928","authenticated-orcid":false,"given":"Wanli","family":"Peng","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-6366-9838","authenticated-orcid":false,"given":"Yinghan","family":"Zhou","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6194-2419","authenticated-orcid":false,"given":"Ziwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Information and Electrical Engineering, China Agricultural University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"22769","article-title":"Improved certified defenses against data poisoning with (Deterministic) finite aggregation","volume-title":"Proc. 39th Int. Conf. Mach. Learn. Res.","volume":"162","author":"Wang","year":"2022"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/qrs57517.2022.00086"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/tpami.2022.3162397"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.725"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/msec.2022.3181001"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484576"},{"article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","year":"2017","author":"Chen","key":"ref7"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/access.2019.2941376"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.37"},{"key":"ref10","first-page":"3611","article-title":"Hidden trigger backdoor attack on NLP models via linguistic style manipulation","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Pan","year":"2022"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.431"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.findings-emnlp.40"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.659"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.trustnlp-1.25"},{"key":"ref16","first-page":"61108","article-title":"Defense against backdoor attack on pre-trained language models via head pruning and attention normalization","volume-title":"Proc. 41st Int. Conf. Mach. Learn. Res.","volume":"235","author":"Zhao","year":"2024"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24090"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.798"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.acl-long.441"},{"key":"ref21","first-page":"1631","article-title":"Recursive deep models for semantic compositionality over a sentiment treebank","volume-title":"Proc. Conf. Empirical Methods Natural Lang. Process.","author":"Socher","year":"2013"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/n19-1144"},{"key":"ref23","article-title":"Character-level convolutional networks for text classification","volume-title":"Adv. Neural Inf. Process. Syst.","volume":"28","author":"Zhang","year":"2015"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1810.04805"},{"article-title":"Roberta: A robustly optimized bert pretraining approach","year":"2019","author":"Liu","key":"ref25"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.60"}],"container-title":["IEEE Signal Processing Letters"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/97\/10802935\/11190006.pdf?arnumber=11190006","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,29]],"date-time":"2025-10-29T17:52:01Z","timestamp":1761760321000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11190006\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/lsp.2025.3617292","relation":{},"ISSN":["1070-9908","1558-2361"],"issn-type":[{"type":"print","value":"1070-9908"},{"type":"electronic","value":"1558-2361"}],"subject":[],"published":{"date-parts":[[2025]]}}}