{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,27]],"date-time":"2025-10-27T16:23:40Z","timestamp":1761582220865,"version":"build-2065373602"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,12,1]],"date-time":"2023-12-01T00:00:00Z","timestamp":1701388800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Swarnajayanti Fellowship"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Artif. Intell."],"published-print":{"date-parts":[[2023,12]]},"DOI":"10.1109\/tai.2022.3206259","type":"journal-article","created":{"date-parts":[[2022,9,14]],"date-time":"2022-09-14T15:38:16Z","timestamp":1663169896000},"page":"1484-1493","source":"Crossref","is-referenced-by-count":5,"title":["IBAttack: Being Cautious About Data Labels"],"prefix":"10.1109","volume":"4","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7362-4752","authenticated-orcid":false,"given":"Akshay","family":"Agarwal","sequence":"first","affiliation":[{"name":"Department of Data Science and Engineering, IISER Bhopal, Bhopal, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4060-4573","authenticated-orcid":false,"given":"Richa","family":"Singh","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, IIT Jodhpur, Jodhpur, Rajasthan, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5952-2274","authenticated-orcid":false,"given":"Mayank","family":"Vatsa","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, IIT Jodhpur, Jodhpur, Rajasthan, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7913-5722","authenticated-orcid":false,"given":"Nalini","family":"Ratha","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Electrical Engineering, University at Buffalo, Buffalo, NY, USA"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"article-title":"Fashion-mnist: A novel image dataset for benchmarking machine learning algorithms","year":"2017","author":"xiao","key":"ref35"},{"key":"ref12","first-page":"1","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","author":"gu","year":"0","journal-title":"Proc Mach Learn Comput Secur Workshop"},{"key":"ref34","article-title":"The challenges and opportunities of explainable AI","volume":"12","author":"wierzynski","year":"2018","journal-title":"Comp Intel"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2020.07.133"},{"key":"ref37","first-page":"1","article-title":"The limitations of adversarial training and the blind-spot attack","author":"zhang","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref36","article-title":"Wide residual networks","author":"zagoruyko","year":"0","journal-title":"Proc Brit Mach Vis Conf"},{"key":"ref31","first-page":"5866","article-title":"Adversarial training and robustness for multiple perturbations","volume":"32","author":"tramer","year":"2019","journal-title":"Adv Neural Inf Process Syst"},{"key":"ref30","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref11","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/833"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00250"},{"article-title":"Label-consistent backdoor attacks","year":"2019","author":"turner","key":"ref32"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2021.01.032"},{"key":"ref1","first-page":"265","article-title":"{TensorFlow}: A. system for {Large-Scale} machine learning","author":"abadi","year":"0","journal-title":"Proc 12th USENIX Symp Operating Syst Des Implementation"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"krizhevsky","key":"ref17"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"article-title":"Adam: A method for stochastic optimization","year":"2014","author":"kingma","key":"ref16"},{"article-title":"Alignedreid: Surpassing human-level performance in person re-identification","year":"2017","author":"zhang","key":"ref38"},{"key":"ref19","first-page":"2088","article-title":"Invisible backdoor attacks on deep neural networks via steganography and regularization","volume":"18","author":"li","year":"2021","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484576"},{"key":"ref24","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref23","first-page":"182","article-title":"Reflection backdoor: A natural backdoor attack on deep neural networks","author":"liu","year":"0","journal-title":"Proc Eur Conf Comput Vis"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3234150"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"article-title":"Rethinking the trigger of backdoor attack","year":"2020","author":"li","key":"ref20"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3236386.3241340"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.374"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00049"},{"article-title":"R interface to Keras","year":"2017","author":"chollet","key":"ref8"},{"article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","year":"2017","author":"chen","key":"ref7"},{"article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","year":"2020","author":"gao","key":"ref9"},{"key":"ref4","first-page":"1","article-title":"On evaluating adversarial robustness","author":"carlini","year":"0","journal-title":"Proc Annu Conf Neural Inf Process Syst"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP42928.2021.9506180"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"}],"container-title":["IEEE Transactions on Artificial Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9078688\/10330793\/09891832.pdf?arnumber=9891832","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,23]],"date-time":"2025-10-23T18:02:14Z","timestamp":1761242534000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9891832\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12]]},"references-count":40,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tai.2022.3206259","relation":{},"ISSN":["2691-4581"],"issn-type":[{"type":"electronic","value":"2691-4581"}],"subject":[],"published":{"date-parts":[[2023,12]]}}}