{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T16:23:35Z","timestamp":1776097415460,"version":"3.50.1"},"reference-count":72,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20A20178"],"award-info":[{"award-number":["U20A20178"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62171248"],"award-info":[{"award-number":["62171248"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20B2049"],"award-info":[{"award-number":["U20B2049"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21B2018"],"award-info":[{"award-number":["U21B2018"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"Shenzhen Science and Technology Program","doi-asserted-by":"publisher","award":["JCYJ20220818101012025"],"award-info":[{"award-number":["JCYJ20220818101012025"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Peng Cheng National Laboratory (PCNL) KEY Project","award":["PCL2023AS6-1"],"award-info":[{"award-number":["PCL2023AS6-1"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3411936","type":"journal-article","created":{"date-parts":[[2024,6,10]],"date-time":"2024-06-10T17:21:57Z","timestamp":1718040117000},"page":"6364-6376","source":"Crossref","is-referenced-by-count":32,"title":["Backdoor Attack With Sparse and Invisible Trigger"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7158-2613","authenticated-orcid":false,"given":"Yinghua","family":"Gao","sequence":"first","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2258-265X","authenticated-orcid":false,"given":"Yiming","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2190-8117","authenticated-orcid":false,"given":"Xueluan","family":"Gong","sequence":"additional","affiliation":[{"name":"School of Computer Science, Wuhan University, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9653-7907","authenticated-orcid":false,"given":"Zhifeng","family":"Li","sequence":"additional","affiliation":[{"name":"Tencent Data Platform, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8639-982X","authenticated-orcid":false,"given":"Shu-Tao","family":"Xia","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8967-8525","authenticated-orcid":false,"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/11744047_29"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2807705"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3177960"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3114024"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3087237"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00432"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3239225"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"ref11","volume-title":"Available"},{"key":"ref12","article-title":"WaNet\u2014Imperceptible warping-based backdoor attack","volume-title":"Proc. ICLR","author":"Nguyen"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"ref14","article-title":"Few-shot backdoor attacks on visual object tracking","volume-title":"Proc. ICLR","author":"Li"},{"key":"ref15","article-title":"Revisiting the assumption of latent separability for backdoor defenses","volume-title":"Proc. ICLR","author":"Qi"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref19","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref20","article-title":"Backdoor attack in the physical world","volume-title":"Proc. ICLR Workshop","author":"Li"},{"key":"ref21","first-page":"13238","article-title":"Untargeted backdoor watermark: Towards harmless and stealthy dataset copyright protection","volume-title":"Proc. NeurIPS","author":"Li"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10095980"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00393"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3265535"},{"key":"ref25","article-title":"Domain watermark: Effective and harmless dataset copyright protection is closed at hand","volume-title":"Proc. NeurIPS","author":"Guo"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467213"},{"key":"ref27","article-title":"Towards faithful XAI evaluation via generalization-limited backdoor watermark","volume-title":"Proc. ICLR","author":"Ya"},{"key":"ref28","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","author":"Chen","year":"2018","journal-title":"arXiv:1811.03728"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref30","first-page":"4129","article-title":"SPECTRE: Defending against backdoor attacks using robust statistics","volume-title":"Proc. ICML","author":"Hayase"},{"key":"ref31","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume-title":"Proc. NeurIPS","author":"Li"},{"key":"ref32","article-title":"Backdoor defense via decoupling the training process","volume-title":"Proc. ICLR","author":"Huang"},{"key":"ref33","first-page":"73191","article-title":"Setting the trap: Capturing and defeating backdoor threats in PLMS through honeypots","volume-title":"Proc. NeurIPS","author":"Tang"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref35","article-title":"Adversarial unlearning of backdoors via implicit hypergradient","volume-title":"Proc. ICLR","author":"Zeng"},{"key":"ref36","first-page":"24523","article-title":"Nearest is not dearest: Towards practical defense against quantization-conditioned backdoor attacks","volume-title":"Proc. CVPR","author":"Li"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3055844"},{"key":"ref39","article-title":"Scale-up: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency","volume-title":"Proc. ICLR","author":"Guo"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"ref41","article-title":"Towards reliable and efficient backdoor trigger inversion via decoupling benign features","volume-title":"Proc. ICLR","author":"Xu"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58542-6_3"},{"key":"ref43","first-page":"12868","article-title":"Sparse and imperceptible adversarial attack via a homotopy algorithm","volume-title":"Proc. ICML","author":"Zhu"},{"key":"ref44","first-page":"27222","article-title":"Sparse invariant risk minimization","volume-title":"Proc. ICML","author":"Zhou"},{"key":"ref45","article-title":"Sparse mixture-of-experts are domain generalizable learners","volume-title":"Proc. ICLR","author":"Li"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2006.873139"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2005.862083"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/18.720544"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00410"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00225"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00482"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2005.858979"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2012.2197412"},{"issue":"3","key":"ref54","first-page":"1081","article-title":"Analysis of multi-stage convex relaxation for sparse regularization","volume":"11","author":"Zhang","year":"2010","journal-title":"J. Mach. Learn. Res."},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1137\/120869778"},{"key":"ref56","first-page":"685","article-title":"On iterative hard thresholding methods for high-dimensional M-estimation","volume-title":"Proc. NeurIPS","author":"Jain"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/s10107-013-0714-4"},{"key":"ref58","first-page":"11226","article-title":"GreedyFool: Distortion-aware sparse adversarial attack","volume-title":"Proc. NeurIPS","author":"Dong"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/IJCB48548.2020.9304875"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref67","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref69","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014","journal-title":"arXiv:1412.6980"},{"key":"ref70","first-page":"38260","article-title":"Marksman backdoor: Backdoor attacks with arbitrary target class","volume-title":"Proc. NeurIPS","author":"Doan"},{"key":"ref71","article-title":"Adversarial patch","author":"Brown","year":"2017","journal-title":"arXiv:1712.09665"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58601-0_24"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10319981\/10552303.pdf?arnumber=10552303","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,27]],"date-time":"2024-06-27T05:17:55Z","timestamp":1719465475000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10552303\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":72,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3411936","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}