{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:57:27Z","timestamp":1783439847628,"version":"3.54.6"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2022ZD0118100"],"award-info":[{"award-number":["2022ZD0118100"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62025604"],"award-info":[{"award-number":["62025604"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62261160653"],"award-info":[{"award-number":["62261160653"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004826","name":"Beijing Natural Science Foundation","doi-asserted-by":"publisher","award":["L212004"],"award-info":[{"award-number":["L212004"]}],"id":[{"id":"10.13039\/501100004826","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3380821","type":"journal-article","created":{"date-parts":[[2024,3,22]],"date-time":"2024-03-22T18:00:11Z","timestamp":1711130411000},"page":"4560-4571","source":"Crossref","is-referenced-by-count":5,"title":["Minimalism is King! High-Frequency Energy-Based Screening for Data-Efficient Backdoor Attacks"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-7069-9816","authenticated-orcid":false,"given":"Yuan","family":"Xun","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2018-9344","authenticated-orcid":false,"given":"Xiaojun","family":"Jia","sequence":"additional","affiliation":[{"name":"Cyber Security Research Centre &#x0040; NTU, Nanyang Technological University, Jurong West, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0574-0129","authenticated-orcid":false,"given":"Jindong","family":"Gu","sequence":"additional","affiliation":[{"name":"Department of Engineering Science, Torr Vision Group, University of Oxford, Oxford, U.K"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinwei","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0974-9299","authenticated-orcid":false,"given":"Qing","family":"Guo","sequence":"additional","affiliation":[{"name":"Institute of High Performance Computing (IHPC) and the Centre for Frontier AI Research (CFAR), Agency for Science, Technology and Research (A&#x0040;STAR), Fusionopolis, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7141-708X","authenticated-orcid":false,"given":"Xiaochun","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shenzhen Campus, Sun Yat-sen University, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"issue":"2","key":"ref1","first-page":"84","article-title":"ImageNet classification with deep convolutional neural networks","volume":"60","author":"Krizhevsky","year":"2012","journal-title":"Commun. ACM"},{"key":"ref2","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref3","first-page":"1","article-title":"Going deeper with convolutions","volume-title":"Proc. IEEE Conf. Comput. Vis. Pattern Recognit.","author":"Szegedy"},{"key":"ref4","article-title":"Deep neural networks for object detection","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Szegedy"},{"issue":"3","key":"ref5","doi-asserted-by":"crossref","first-page":"257","DOI":"10.1109\/JPROC.2023.3238524","article-title":"Object detection in 20 years: A survey","volume":"111","author":"Zou","year":"2023","journal-title":"Proc. IEEE"},{"issue":"11","key":"ref6","doi-asserted-by":"crossref","first-page":"3212","DOI":"10.1109\/TNNLS.2018.2876865","article-title":"Object detection with deep learning: A review","volume":"30","author":"Zhao","year":"2019","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref7","first-page":"3431","article-title":"Fully convolutional networks for semantic segmentation","volume-title":"Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Long"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.1997.609407"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"ref10","doi-asserted-by":"crossref","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","article-title":"BadNets: Evaluating backdooring attacks on deep neural networks","volume":"7","author":"Gu","year":"2019","journal-title":"IEEE Access"},{"key":"ref11","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2018.23291","article-title":"Trojaning attack on neural networks","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Liu"},{"key":"ref12","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/554"},{"key":"ref14","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-030-36708-4_22","article-title":"Training behavior of deep neural network in frequency domain","volume-title":"Proc. Int. Conf. Neural Inf. Process.","author":"Xu"},{"key":"ref15","article-title":"Frequency principle: Fourier analysis sheds light on deep neural networks","author":"John Xu","year":"2019","journal-title":"arXiv:1901.06523"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.4208\/csiam-am.so-2020-0005"},{"key":"ref17","article-title":"Explicitizing an implicit bias of the frequency principle in two-layer neural networks","author":"Zhang","year":"2019","journal-title":"arXiv:1905.10264"},{"key":"ref18","article-title":"A Fourier perspective on model robustness in computer vision","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Yin"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00871"},{"key":"ref20","article-title":"On the spectral bias of neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rahaman"},{"key":"ref21","first-page":"16453","article-title":"Rethinking the backdoor attacks\u2019 triggers: A frequency perspective","volume-title":"Proc. IEEE\/CVF Int. Conf. Comput. Vis. (ICCV)","author":"Zeng"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref23","first-page":"2088","article-title":"Invisible backdoor attacks on deep neural networks via steganography and regularization","volume":"18","author":"Li","year":"2019","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"ref24","first-page":"14431","article-title":"Clean-label backdoor attacks on video recognition models","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Zhao"},{"key":"ref25","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref26","first-page":"101","article-title":"A new backdoor attack in CNNs by training set corruption without label poisoning","volume-title":"Proc. IEEE Int. Conf. Image Process. (ICIP)","author":"Barni"},{"issue":"3","key":"ref27","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1109\/TBIOM.2021.3132132","article-title":"FaceHack: Attacking facial recognition systems using malicious facial characteristics","volume":"4","author":"Sarkar","year":"2022","journal-title":"IEEE Trans. Biometrics, Behav., Identity Sci."},{"key":"ref28","first-page":"16443","article-title":"Invisible backdoor attack with sample-specific triggers","volume-title":"Proc. IEEE\/CVF Int. Conf. Comput. Vis. (ICCV)","author":"Li"},{"key":"ref29","article-title":"Sleeper agent: Scalable hidden trigger backdoors for neural networks trained from scratch","author":"Souri","year":"2021","journal-title":"arXiv:2106.08970"},{"key":"ref30","article-title":"Blind backdoors in deep learning models","volume-title":"Proc. USENIX Secur. Symp.","author":"Bagdasaryan"},{"key":"ref31","article-title":"Input-aware dynamic backdoor attack","author":"Nguyen","year":"2020","journal-title":"arXiv:2010.08138"},{"key":"ref32","article-title":"Backdoor attack with imperceptible input and latent modification","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Doan"},{"key":"ref33","first-page":"11946","article-title":"LIRA: Learnable, imperceptible and robust backdoor attacks","volume-title":"Proc. IEEE\/CVF Int. Conf. Comput. Vis. (ICCV)","author":"Doan"},{"key":"ref34","article-title":"WaNet\u2014Imperceptible warping-based backdoor attack","volume-title":"Proc. 9th Int. Conf. Learn. Represent. (ICLR)","author":"Nguyen"},{"key":"ref35","doi-asserted-by":"crossref","DOI":"10.1145\/3374664.3375751","article-title":"Backdoor embedding in convolutional neural network models via invisible perturbation","volume-title":"Proc. 10th ACM Conf. Data Appl. Secur. Privacy","author":"Zhong"},{"key":"ref36","first-page":"86","article-title":"Universal adversarial perturbations","volume-title":"Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Moosavi-Dezfooli"},{"key":"ref37","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-031-19778-9_23","article-title":"An invisible black-box backdoor attack through frequency domain","volume-title":"Proc. Eur. Conf. Comput. Vis.","author":"Wang"},{"key":"ref38","article-title":"Check your other door! Creating backdoor attacks in the frequency domain","author":"Hammoud","year":"2109","journal-title":"arXiv:2109.05507"},{"key":"ref39","article-title":"Backdoor attack through frequency domain","author":"Wang","year":"2021","journal-title":"arXiv:2111.10991"},{"key":"ref40","first-page":"2338","article-title":"Don\u2019t FREAK out: A frequency-inspired approach to detecting backdoor poisoned samples in DNNs","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. Workshops (CVPRW)","author":"Al Kader Hammoud"},{"key":"ref41","article-title":"Backdoor learning: A survey","author":"Li","year":"2022","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref42","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref43","first-page":"248","article-title":"ImageNet: A large-scale hierarchical image database","volume-title":"Proc. IEEE Conf. Comput. Vis. Pattern Recognit.","author":"Deng"},{"key":"ref44","article-title":"Label-consistent backdoor attacks","author":"Turner","year":"2019","journal-title":"arXiv:1912.02771"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref46","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","author":"Li","year":"2021","journal-title":"arXiv:2101.05930"},{"key":"ref47","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","author":"Chen","year":"2018","journal-title":"arXiv:1811.03728"},{"key":"ref48","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref49","article-title":"Spectral signatures in backdoor attacks","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Tran"},{"key":"ref50","article-title":"Learning both weights and connections for efficient neural network","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Han"},{"key":"ref51","article-title":"BackdoorBench: A comprehensive benchmark of backdoor learning","author":"Wu","year":"2022","journal-title":"arXiv:2206.12654"},{"key":"ref52","first-page":"707","article-title":"Neural cleanse: Identifying and mitigating backdoor attacks in neural networks","volume-title":"Proc. IEEE Symp. Secur. Privacy (SP)","author":"Wang"},{"key":"ref53","article-title":"AEVA: Black-box backdoor detection using adversarial extreme value analysis","author":"Guo","year":"2021","journal-title":"arXiv:2110.14880"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_32"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/10319981\/10478135.pdf?arnumber=10478135","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,3]],"date-time":"2024-09-03T04:39:01Z","timestamp":1725338341000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10478135\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":54,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3380821","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}