{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:58:56Z","timestamp":1783007936957,"version":"3.54.5"},"reference-count":58,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172233"],"award-info":[{"award-number":["62172233"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472231"],"award-info":[{"award-number":["62472231"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U19B2044"],"award-info":[{"award-number":["U19B2044"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61836011"],"award-info":[{"award-number":["61836011"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Jiangsu Provincial Science and Technology Major Project","award":["BG2024042"],"award-info":[{"award-number":["BG2024042"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tdsc.2025.3596981","type":"journal-article","created":{"date-parts":[[2025,8,8]],"date-time":"2025-08-08T18:43:05Z","timestamp":1754678585000},"page":"7430-7447","source":"Crossref","is-referenced-by-count":3,"title":["Explore the Effect of Data Selection on Poison Efficiency in Backdoor Attacks"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9484-2310","authenticated-orcid":false,"given":"Ziqiang","family":"Li","sequence":"first","affiliation":[{"name":"Engineering Research Center of Digital Forensics, Nanjing University of Information Science and Technology, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8268-2057","authenticated-orcid":false,"given":"Pengfei","family":"Xia","sequence":"additional","affiliation":[{"name":"Huawei Technologies Company Ltd, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9249-5375","authenticated-orcid":false,"given":"Hong","family":"Sun","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yueqi","family":"Zeng","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-5132-7498","authenticated-orcid":false,"given":"Wei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2332-3959","authenticated-orcid":false,"given":"Bin","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Electronic Engineering and Information Science, University of Science and Technology of China, Hefei, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-021-03819-2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3569928"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2024.3485109"},{"key":"ref5","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3638530.3664104"},{"key":"ref7","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref8","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3161477"},{"key":"ref10","article-title":"Large language models are good attackers: Efficient and stealthy textual backdoor attacks","author":"Li","year":"2024"},{"key":"ref11","article-title":"Efficient backdoor attacks for deep neural networks in real-world scenarios","author":"Li","year":"2023"},{"key":"ref12","first-page":"1877","article-title":"Language models are few-shot learners","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Brown"},{"key":"ref13","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Radford"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7299101"},{"key":"ref17","article-title":"Label-consistent backdoor attacks","author":"Turner","year":"2019"},{"key":"ref18","article-title":"WaNet\u2013Imperceptible warping-based backdoor attack","author":"Nguyen","year":"2021"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3380821"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00443"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3233519"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3472510"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109512"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/554"},{"key":"ref25","article-title":"Boosting backdoor attack with a learnable poisoning sample selection strategy","author":"Zhu","year":"2023"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01943"},{"key":"ref27","first-page":"1019","article-title":"Sharp minima can generalize for deep nets","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Dinh"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/IJCB48548.2020.9304875"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref33","article-title":"Check your other door! Establishing backdoor attacks in the frequency domain","volume-title":"Proc. 33rd Brit. Mach. Vis. Conf. Proc.","author":"Hammoud","year":"2022"},{"key":"ref34","first-page":"7276","article-title":"Training deep models faster with robust, approximate importance sampling","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Johnson"},{"key":"ref35","article-title":"An empirical study of example forgetting during deep neural network learning","author":"Toneva","year":"2018"},{"key":"ref36","article-title":"Super-samples from kernel herding","author":"Chen","year":"2012"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/1007352.1007400"},{"key":"ref38","article-title":"Selection via proxy: Efficient data selection for deep learning","author":"Coleman","year":"2019"},{"key":"ref39","first-page":"5464","article-title":"GRAD-MATCH: Gradient matching based data subset selection for efficient deep model training","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Killamsetty"},{"key":"ref40","first-page":"6950","article-title":"Coresets for data-efficient training of machine learning models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Mirzasoleiman"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"key":"ref42","first-page":"2525","article-title":"Not all samples are created equal: Deep learning with importance sampling","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Katharopoulos"},{"key":"ref43","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref44","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1080\/03610918908812806"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/ad13fc"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/MLHPC49564.2019.00012"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00929"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref51","first-page":"649","article-title":"Character-level convolutional networks for text classification","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/2733373.2806390"},{"key":"ref53","article-title":"Facial age prediction","author":"Fremtesci","year":"2020"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref55","article-title":"Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3265535"},{"key":"ref57","article-title":"Domain watermark: Effective and harmless dataset copyright protection is closed at hand","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Guo"},{"key":"ref58","article-title":"Towards faithful XAI evaluation via generalization-limited backdoor watermark","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ya"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11242243\/11119781.pdf?arnumber=11119781","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:00:38Z","timestamp":1763154038000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11119781\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":58,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3596981","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}