{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,8]],"date-time":"2026-04-08T16:25:41Z","timestamp":1775665541875,"version":"3.50.1"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61876019"],"award-info":[{"award-number":["61876019"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1936218"],"award-info":[{"award-number":["U1936218"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072037"],"award-info":[{"award-number":["62072037"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61802383"],"award-info":[{"award-number":["61802383"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Research Project of Guangzhou University","award":["RQ2021007"],"award-info":[{"award-number":["RQ2021007"]}]},{"name":"Pazhou Lab for Excellent Young Scholars","award":["PZL2021KF0024"],"award-info":[{"award-number":["PZL2021KF0024"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2023,5,1]]},"DOI":"10.1109\/tdsc.2022.3164073","type":"journal-article","created":{"date-parts":[[2022,4,1]],"date-time":"2022-04-01T19:57:42Z","timestamp":1648843062000},"page":"1789-1798","source":"Crossref","is-referenced-by-count":17,"title":["Stealthy and Flexible Trojan in Deep Learning Framework"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0962-4464","authenticated-orcid":false,"given":"Yajie","family":"Wang","sequence":"first","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2439-3518","authenticated-orcid":false,"given":"Kongyang","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6404-8853","authenticated-orcid":false,"given":"Yu-an","family":"Tan","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuxin","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wencong","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1931-366X","authenticated-orcid":false,"given":"Yuanzhang","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3116431"},{"key":"ref57","article-title":"LeNet-5, convolutional neural networks","author":"lecun","year":"2015"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2020.3000900"},{"key":"ref56","article-title":"Imagenette","author":"howard","year":"2021"},{"key":"ref15","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"gu","year":"2017"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3103064"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref52","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3112100"},{"key":"ref55","first-page":"142","article-title":"Learning word vectors for sentiment analysis","author":"maas","year":"2011","journal-title":"Proc 49th Annu Meeting Assoc Comput Linguistics Hum Lang Technol"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3108434"},{"key":"ref54","article-title":"Labeled faces in the wild: A database forstudying face recognition in unconstrained environments","author":"huang","year":"2008","journal-title":"Proc Workshop Faces &#x2019;Real-Life&#x2019; Images Detection Alignment Recognit"},{"key":"ref17","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"chen","year":"2017"},{"key":"ref16","article-title":"Trojaning attack on neural networks","author":"liu","year":"2017"},{"key":"ref19","article-title":"Blind backdoors in deep learning models","author":"bagdasaryan","year":"2020"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref51","article-title":"The MNIST database of handwritten digits","author":"lecun","year":"1998"},{"key":"ref50","first-page":"265","article-title":"TensorFlow: A system for large-scale machine learning","author":"abadi","year":"2016","journal-title":"Proc 12th USENIX Symp Oper Syst Des Implementation"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.3041202"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2021.3111123"},{"key":"ref48","article-title":"AI hub","year":"2021"},{"key":"ref47","article-title":"SageMaker","year":"2021"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00038"},{"key":"ref43","article-title":"Bridging mode connectivity in loss landscapes and adversarial robustness","author":"zhao","year":"2020"},{"key":"ref49","first-page":"8026","article-title":"PyTorch: An imperative style, high-performance deep learning library","author":"paszke","year":"2019","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref8","article-title":"Backdoor learning: A survey","author":"li","year":"2020"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3094824"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TASLP.2014.2339736"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6638947"},{"key":"ref6","article-title":"Deep face recognition","author":"parkhi","year":"2021"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/72.554195"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3028448"},{"key":"ref35","article-title":"Dynamic backdoor attacks against machine learning models","author":"salem","year":"2020"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00520"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_5"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.312"},{"key":"ref39","first-page":"227","article-title":"SIN: Stealth infection on neural network&#x2014;A low-cost agile neural trojan attack methodology","author":"liu","year":"2018","journal-title":"Proc IEEE Int Symp Hardware Oriented Secur Trust"},{"key":"ref38","first-page":"2088","article-title":"Invisible backdoor attacks on deep neural networks via steganography and regularization","volume":"18","author":"li","year":"2021","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9414862"},{"key":"ref23","article-title":"On the effectiveness of mitigating data poisoning attacks with gradient shaping","author":"hong","year":"2020"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3412130"},{"key":"ref63","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"devlin","year":"2018"},{"key":"ref22","article-title":"Robust anomaly detection and backdoor attack detection via differential privacy","author":"du","year":"2019"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"ref28","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"ref29","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2016"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00060"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10126099\/09747995.pdf?arnumber=9747995","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,19]],"date-time":"2023-06-19T18:28:46Z","timestamp":1687199326000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9747995\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,1]]},"references-count":63,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2022.3164073","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,1]]}}}