{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T21:44:11Z","timestamp":1786139051164,"version":"3.56.0"},"reference-count":100,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/100009950","name":"Ministry of Education","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100009950","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100009318","name":"Helmholtz Association","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100009318","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179308","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"664-681","source":"Crossref","is-referenced-by-count":24,"title":["Disguising Attacks with Explanation-Aware Backdoors"],"prefix":"10.1109","author":[{"given":"Maximilian","family":"Noppel","sequence":"first","affiliation":[{"name":"Karlsruhe Institute of Technology,KASTEL Security Research Labs,Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lukas","family":"Peter","sequence":"additional","affiliation":[{"name":"Karlsruhe Institute of Technology,KASTEL Security Research Labs,Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Wressnegger","sequence":"additional","affiliation":[{"name":"Karlsruhe Institute of Technology,KASTEL Security Research Labs,Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"9525","article-title":"Sanity checks for saliency maps","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Adebayo"},{"key":"ref2","first-page":"161","article-title":"Fairwashing: The risk of rationalization","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"A\u00efvodji"},{"key":"ref3","volume-title":"AWS Deep Learning-AMIs"},{"key":"ref4","first-page":"314","article-title":"Fairwashing explanations with off-manifold detergent","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Anders"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23247"},{"key":"ref6","article-title":"Dos and don\u2019ts of machine learning in computer security","volume-title":"Proc. of the USENIX Security Symposium","author":"Arp"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0130140"},{"key":"ref8","first-page":"1803","article-title":"How to explain individual classification decisions","volume":"11","author":"Baehrens","year":"2010","journal-title":"Journal of Machine Learning Research (JMLR)"},{"key":"ref9","first-page":"342","article-title":"The shattered gradients problem: If resnets are the answer, then what is the question?","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Balduzzi"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.cviu.2012.09.006"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/8996.003.0015"},{"key":"ref13","article-title":"Adversarial patch","volume":"abs\/1712.09665","author":"Brown","year":"2017","journal-title":"CoRR"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2018.00097"},{"key":"ref17","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","volume":"abs\/1712.05526","author":"Chen","year":"2017","journal-title":"CoRR"},{"key":"ref18","article-title":"SentiNet: Detecting physical attacks against deep learning systems","volume":"abs\/1812.00292","author":"Chou","year":"2018","journal-title":"CoRR"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"ref20","first-page":"63","article-title":"You shouldn\u2019t trust me: Learning models which conceal unfairness from multiple explanation methods","volume-title":"Proc. of the Workshop on Artificial Intelligence Safety","volume":"2560","author":"Dimanov"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"ref22","first-page":"13567","article-title":"Explanations can be manipulated and geometry is to blame","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Dombrowski"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108194"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/iccv48922.2021"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2017.12.012"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i1.19935"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207637"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.371"},{"key":"ref29","first-page":"113","volume-title":"Proc. of the Annual Computer Security Applications Conference (ACSAC)","author":"Gao"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013681"},{"key":"ref31","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Goodfellow"},{"key":"ref32","article-title":"Google Cloud Machine Learning Engine"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref35","first-page":"5767","article-title":"Improved training of wasserstein gans","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Gulrajani"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref37","article-title":"Bridging nonlinearities and stochastic regularizers with gaussian error linear units","volume":"abs\/1606.08415","author":"Hendrycks","year":"2016","journal-title":"CoRR"},{"key":"ref38","first-page":"2921","article-title":"Fooling neural network interpretations via adversarial model manipulation","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Heo"},{"key":"ref39","article-title":"NeuronInspect: Detecting backdoors in neural networks via output explanations","volume":"abs\/1911.07399","author":"Huang","year":"2019","journal-title":"CoRR"},{"key":"ref40","article-title":"On relating explanations and adversarial examples","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Ignatiev"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3072959.3073659"},{"key":"ref42","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Ilyas"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833644"},{"key":"ref45","article-title":"Investigating the influence of noise and distractors on the interpretation of neural networks","volume-title":"Proc. of the NIPS Workshop on Interpretable Machine Learning in Complex Systems","author":"Kindermans"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-28954-6_14"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1406.3269"},{"key":"ref48","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009","journal-title":"Technical report"},{"key":"ref49","volume-title":"CIFAR (canadian institute for advanced research)","author":"Krizhevsky"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9206780"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-019-08987-4"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01470"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref56","article-title":"A Unified Approach to Interpreting Model Predictions","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Lundberg"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00979"},{"key":"ref59","volume-title":"Azure Batch AI Training"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2016.11.008"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref62","first-page":"807","article-title":"Rectified linear units improve restricted boltzmann machines","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Nair"},{"key":"ref63","article-title":"Input-aware dynamic backdoor attack","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Nguyen"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref66","first-page":"729","article-title":"TESSER-ACT: eliminating experimental bias in malware classification across space and time","volume-title":"Proc. of the USENIX Security Symposium","author":"Pendlebury"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00024"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N16-3020"},{"key":"ref70","first-page":"9389","article-title":"Just how toxic is data poisoning? A unified benchmark for backdoor and data poisoning attacks","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Schwarzschild"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref72","first-page":"1487","article-title":"Explanation-guided backdoor poisoning attacks against malware classifiers","volume-title":"Proc. of the USENIX Security Symposium","author":"Severi"},{"key":"ref73","first-page":"6106","article-title":"Poison Frogs! Targeted clean-label poisoning attacks on neural networks","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Shafahi"},{"key":"ref74","first-page":"3353","article-title":"Adversarial training for free!","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Shafahi"},{"key":"ref75","article-title":"Not just a black box: Learning important features through propagating activation differences","volume":"abs\/1605.01713","author":"Shrikumar","year":"2016","journal-title":"CoRR"},{"key":"ref76","first-page":"3145","article-title":"Learning important features through propagating activation differences","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Shrikumar"},{"key":"ref77","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Simonyan"},{"key":"ref78","article-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Simonyan"},{"key":"ref79","article-title":"When Explanations Lie: Why Many Modified BP Attributions Fail","volume":"abs\/1912.09818","author":"Sixt","year":"2020","journal-title":"CoRR"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/3375627.3375830"},{"key":"ref81","article-title":"SmoothGrad: Removing noise by adding noise","volume":"abs\/1706.03825","author":"Smilkov","year":"2017","journal-title":"CoRR"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00211"},{"key":"ref84","first-page":"3319","article-title":"Axiomatic attribution for deep networks","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Sundararajan"},{"key":"ref85","article-title":"Intriguing properties of neural networks","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Szegedy"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"ref87","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Tram\u00e8r"},{"key":"ref88","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Tram\u00e8r"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00402"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00020"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp48549.2020.00018"},{"key":"ref94","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Xie"},{"key":"ref95","first-page":"2041","volume-title":"Proc. of the ACM Conference on Computer and Communications Security (CCS)","author":"Yao"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"ref97","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Zhang"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467405"},{"key":"ref99","first-page":"1659","article-title":"Interpretable deep learning under fire","volume-title":"Proc. of the USENIX Security Symposium","author":"Zhang"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179308.pdf?arnumber=10179308","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:18:24Z","timestamp":1721452704000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179308\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":100,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179308","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}