{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T04:06:33Z","timestamp":1778904393908,"version":"3.51.4"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"International Conference on Machine Learning"},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U25B2079"],"award-info":[{"award-number":["U25B2079"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Sichuan Science and Technology Program","award":["2024ZHCG0188"],"award-info":[{"award-number":["2024ZHCG0188"]}]},{"name":"Chengdu Science and Technology Program","award":["2023-XT00-00002-GX"],"award-info":[{"award-number":["2023-XT00-00002-GX"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62502075"],"award-info":[{"award-number":["62502075"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62402087"],"award-info":[{"award-number":["62402087"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62502079"],"award-info":[{"award-number":["62502079"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1109\/tdsc.2026.3658111","type":"journal-article","created":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T21:01:44Z","timestamp":1769634104000},"page":"5831-5847","source":"Crossref","is-referenced-by-count":0,"title":["Backdoor Complications: A Comprehensive Analysis and Mitigation of the Unforeseen Consequences of Backdoor Attacks"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6412-9338","authenticated-orcid":false,"given":"Rui","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering (School of Cybersecurity), University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5215-2976","authenticated-orcid":false,"given":"Yun","family":"Shen","sequence":"additional","affiliation":[{"name":"Flexera (UK), Bracknell, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1961-7946","authenticated-orcid":false,"given":"Hongwei","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (School of Cybersecurity), University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4592-8094","authenticated-orcid":false,"given":"Wenbo","family":"Jiang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (School of Cybersecurity), University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9869-8926","authenticated-orcid":false,"given":"Hanxiao","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (School of Cybersecurity), University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7909-9845","authenticated-orcid":false,"given":"Yuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (School of Cybersecurity), University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9764-9345","authenticated-orcid":false,"given":"Guowen","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (School of Cybersecurity), University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3612-7348","authenticated-orcid":false,"given":"Yang","family":"Zhang","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr&#x00FC;cken, DE, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3605943"},{"key":"ref4","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485837"},{"key":"ref7","first-page":"2022","article-title":"BadPre: Task-agnostic backdoor attacks to pre-trained NLP foundation models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chen"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485370"},{"key":"ref9","article-title":"Poisoning and backdooring contrastive learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Carlini","year":"2022"},{"key":"ref10","article-title":"BadLingual: A novel lingual-backdoor attack against large language models","author":"Wang","year":"2025"},{"key":"ref11","first-page":"3454","article-title":"Input-aware dynamic backdoor attack","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Nguyen","year":"2020"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00049"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref14","article-title":"BAAAN: Backdoor attacks against autoencoder and GAN-based machine learning models","author":"Salem","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24287"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i25.34819"},{"key":"ref17","article-title":"BackdoorLLM: A comprehensive benchmark for backdoor attacks and defenses on large language models","author":"Li","year":"2025"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833644"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01298"},{"key":"ref20","article-title":"Backdoor attacks in the supply chain of masked image modeling","author":"Shen","year":"2022"},{"key":"ref21","first-page":"2707","article-title":"Aliasing backdoor attacks on pre-trained models","volume-title":"Proc. USENIX Secur. Symp.","author":"Lee","year":"2023"},{"key":"ref22","article-title":"Don\u2019t trigger me! A triggerless backdoor attack against deep neural networks","author":"Salem","year":"2020"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484576"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1810.04805"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1525\/9780520940420-020"},{"key":"ref26","article-title":"Language models are unsupervised multitask learners","author":"Radford","year":"2019"},{"issue":"140","key":"ref27","first-page":"1","article-title":"Exploring the limits of transfer learning with a unified text-to-text transformer","volume":"21","author":"Raffel","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref29","article-title":"Lifting the veil on the large language model supply chain: Composition, risks, and mitigations","author":"Huang","year":"2024"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3713081.3731747"},{"key":"ref31","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"key":"ref33","article-title":"Combinational backdoor attack against customized text-to-image models","author":"Jiang","year":"2024"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref35","first-page":"1849","article-title":"Instruction backdoor attacks against customized $\\lbrace${LLMs$\\rbrace$}","volume-title":"Proc. USENIX Secur. Symp.","author":"Zhang","year":"2024"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2025.3603639"},{"key":"ref37","first-page":"6103","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Shafahi","year":"2018"},{"key":"ref38","first-page":"30339","article-title":"Adversarial examples make strong poisons","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Fowl","year":"2021"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02342"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.431"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-naacl.94"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833572"},{"key":"ref43","article-title":"Backdooring bias into text-to-image models","author":"Naseh","year":"2024"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.naacl-long.337"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"ref47","article-title":"Transtroj: Transferable backdoor attacks to pre-trained models via embedding indistinguishability","author":"Wang","year":"2024"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1093\/nsr\/nwx105"},{"key":"ref49","first-page":"142","article-title":"Learning word vectors for sentiment analysis","volume-title":"Proc. Annu. Meeting Assoc. Comput. Linguistics","author":"Maas","year":"2011"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D13-1170"},{"key":"ref51","first-page":"649","article-title":"Character-level convolutional networks for text classification","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Zhang","year":"2015"},{"key":"ref52","article-title":"Multi-source social feedback of online news feeds","author":"Moniz","year":"2018"},{"key":"ref53","article-title":"Bbc-news dataset","year":"2020"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00290"},{"key":"ref55","article-title":"Disaster tweets","author":"Stepanenko","year":"2020"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1609\/icwsm.v11i1.14955"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.23"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-short.91"},{"key":"ref59","article-title":"Medical text dataset - cancer doc classification","year":"2022"},{"key":"ref60","article-title":"E-commerce text dataset (version - 2)","year":"2019"},{"key":"ref61","article-title":"Physics vs chemistry vs biology","year":"2021"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2907992"},{"key":"ref63","first-page":"75971","article-title":"The ripple effect: On unforeseen complications of backdoor attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang","year":"2025"},{"key":"ref64","article-title":"ACL 2019 fourth conference on machine translation (WMT19), shared task: Machine translation of news","author":"Foundation","year":"2019"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D19-5409"},{"key":"ref66","article-title":"Qwen3 embedding: Advancing text embedding and reranking through foundation models","author":"Zhang","year":"2025"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00622"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.752"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11517592\/11365953.pdf?arnumber=11365953","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T03:06:50Z","timestamp":1778900810000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11365953\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":65,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2026.3658111","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5]]}}}