{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:02:00Z","timestamp":1782975720479,"version":"3.54.5"},"reference-count":82,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100006785","name":"Google","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006785","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100016443","name":"Amazon","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100016443","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100004358","name":"Samsung","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100004358","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000185","name":"DARPA","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00097","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"233-251","source":"Crossref","is-referenced-by-count":0,"title":["Your Compiler is Backdooring Your Model: Understanding and Exploiting Compilation Inconsistency Vulnerabilities in Deep Learning Compilers"],"prefix":"10.1109","author":[{"given":"Simin","family":"Chen","sequence":"first","affiliation":[{"name":"Columbia University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinjun","family":"Peng","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yixin","family":"He","sequence":"additional","affiliation":[{"name":"University of Southern California"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junfeng","family":"Yang","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Baishakhi","family":"Ray","sequence":"additional","affiliation":[{"name":"Columbia University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"578","article-title":"TVM: An automated End-to-End optimizing compiler for deep learning","volume-title":"Proceedings of the 13th USENIX Symposium on Operating Systems Design and Implementation (OSDI)","author":"Chen","year":"2018"},{"key":"ref2","volume-title":"Facebook glow"},{"key":"ref3","volume-title":"ONNXRuntime"},{"key":"ref4","volume-title":"TensorFlow Lite"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/94"},{"key":"ref6","first-page":"863","article-title":"Ansor: Generating high-performance tensor programs for deep learning","volume-title":"Proceedings of the 14th USENIX Conference on Operating Systems Design and Implementation (OSDI)","author":"Zheng","year":"2020"},{"key":"ref7","first-page":"848","article-title":"DietCode: Automatic optimization for dynamic tensor programs","volume-title":"Proceedings of the 5th Machine Learning and Systems (MLSys)","author":"Zheng","year":"2022"},{"key":"ref8","first-page":"38","article-title":"Cortex: A compiler for recursive deep learning models","volume-title":"Proceedings of the 4th Machine Learning and Systems (MLSys)","author":"Fegade","year":"2021"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14778\/3489496.3489500"},{"key":"ref10","volume-title":"Compiler and runtime techniques for optimizing deep learning applications","author":"Lyubomirsky","year":"2022"},{"key":"ref11","first-page":"8024","article-title":"Pytorch: An imperative style, high-performance deep learning library","volume-title":"Proceedings of the 33rd Advances in Neural Information Processing Systems (NeurIPS)","author":"Paszke","year":"2019"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML59370.2024.00024"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3508035"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598082"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE62328.2024.00018"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/103162.103163"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ieeestd.2008.4610935"},{"key":"ref18","doi-asserted-by":"crossref","DOI":"10.1137\/1.9780898718072","volume-title":"Numerical computing with IEEE floating point arithmetic","author":"Overton","year":"2001"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00048"},{"key":"ref20","article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","author":"Gao","year":"2020","journal-title":"arXiv preprint"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.52202\/079017-1319"},{"key":"ref23","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv preprint"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02355"},{"key":"ref25","first-page":"3454","article-title":"Input-aware dynamic backdoor attack","volume-title":"Proceedings of the 34th Advances in Neural Information Processing Systems (NeurIPS)","author":"Nguyen","year":"2020"},{"key":"ref26","article-title":"Label-consistent backdoor attacks","author":"Turner","year":"2019","journal-title":"arXiv preprint"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.52202\/079017-2652"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690279"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01533"},{"key":"ref30","first-page":"2117","article-title":"Blacklight: Scalable defense for neural networks against QueryBased Black-Box attacks","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security)","author":"Li","year":"2022"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3385003.3410925"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.00957"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02356"},{"key":"ref34","article-title":"Architectural backdoors for within-batch data stealing and model inference manipulation","author":"K\u00fcchler","year":"2025","journal-title":"arXiv preprint"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00060"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485881"},{"key":"ref37","first-page":"9303","article-title":"Qu-ANTI-zation: Exploiting quantization artifacts for achieving adversarial outcomes","volume-title":"Proceedings of the 35th Advances in Neural Information Processing Systems (NeuIPS)","author":"Hong","year":"2021"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3271956"},{"key":"ref39","article-title":"Hardware and software platform inference","volume-title":"Proceedings of the 42nd International Conference on Machine Learning (ICML)","author":"Zhang","year":"2024"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS59052.2023.00021"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS62706.2024.00019"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3582016.3582047"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3460945.3464953"},{"key":"ref44","article-title":"A survey of large-scale deep learning serving system optimization: Challenges and opportunities","author":"Yu","year":"2021","journal-title":"arXiv preprint"},{"key":"ref45","first-page":"265","article-title":"TensorFlow: A system for large-scale machine learning","volume-title":"Proceedings of the 12th USENIX Symposium on Operating Systems Design and Implementation, (OSDI)","author":"Abadi","year":"2016"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP63933.2026.00044"},{"key":"ref47","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv preprint"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00226"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00225"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref52","first-page":"1541","article-title":"Demon in the variant: Statistical analysis of DNNs for robust backdoor contamination detection","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security)","author":"Tang","year":"2021"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00015"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v30i1.10139"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549102"},{"key":"ref57","first-page":"2463","article-title":"An empirical study of pretrained model reuse in the hugging face deep learning model registry","volume-title":"Proceedings of the 45th IEEE\/ACM International Conference on Software Engineering (ICSE)","author":"Jiang","year":"2023"},{"key":"ref58","article-title":"The ML supply chain in the era of software 2.0: Lessons learned from Hugging Face","author":"Stalnaker","year":"2025","journal-title":"arXiv preprint"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-13188-2_19"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3650212.3680374"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/ASE56229.2023.00120"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE55347.2025.00025"},{"key":"ref63","first-page":"1","article-title":"Scuzer: A scheduling optimization fuzzer for TVM","volume":"34","author":"Chen","year":"2025","journal-title":"ACM Transactions on Software Engineering and Methodology (TOSEM)"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/QRS60937.2023.00066"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-8311-7_15"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE55347.2025.00037"},{"key":"ref67","article-title":"OODTE: A differential testing engine for the ONNX optimizer","author":"Louloudakis","year":"2025","journal-title":"arXiv preprint"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3713081.3731731"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616337"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3575693.3575707"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598105"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3689757"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464843"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115662"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00024"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/2345156.2254118"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/2555243.2555265"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510095"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/3192366.3192411"},{"key":"ref80","first-page":"414","article-title":"A tale of two models: Constructing evasive attacks on edge models","volume-title":"Proceedings of the 5th Conference on Machine Learning and Systems (MLSys)","author":"Hao","year":"2022"},{"key":"ref81","article-title":"The new IEEE-754 standard for floating point arithmetic","volume-title":"Dagstuhl Seminar Proceedings","author":"Markstein","year":"2008"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1145\/3446804.3446848"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573546.pdf?arnumber=11573546","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:31:08Z","timestamp":1782970268000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573546\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":82,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00097","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}