{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T16:52:38Z","timestamp":1777654358646,"version":"3.51.4"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24A20337"],"award-info":[{"award-number":["U24A20337"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372228"],"award-info":[{"award-number":["62372228"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shenzhen-Hong Kong-Macau Technology Research Program","award":["SGDX20230821091559018"],"award-info":[{"award-number":["SGDX20230821091559018"]}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["14380029"],"award-info":[{"award-number":["14380029"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001321","name":"National Research Foundation, Singapore, and Defence Science Organisation (DSO) National Laboratories under the AI Singapore Program","doi-asserted-by":"publisher","award":["AISG2-GC-2023-008"],"award-info":[{"award-number":["AISG2-GC-2023-008"]}],"id":[{"id":"10.13039\/501100001321","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3550062","type":"journal-article","created":{"date-parts":[[2025,3,18]],"date-time":"2025-03-18T17:32:07Z","timestamp":1742319127000},"page":"3414-3428","source":"Crossref","is-referenced-by-count":8,"title":["Mutual Information Guided Backdoor Mitigation for Pre-Trained Encoders"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1821-611X","authenticated-orcid":false,"given":"Tingxu","family":"Han","sequence":"first","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9236-8264","authenticated-orcid":false,"given":"Weisong","family":"Sun","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Nanyang, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-8336-7516","authenticated-orcid":false,"given":"Ziqi","family":"Ding","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, University of New South Wales, Kensington, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9930-7111","authenticated-orcid":false,"given":"Chunrong","family":"Fang","sequence":"additional","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-9524-1411","authenticated-orcid":false,"given":"Hanwei","family":"Qian","sequence":"additional","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8267-8968","authenticated-orcid":false,"given":"Jiaxun","family":"Li","sequence":"additional","affiliation":[{"name":"School of Mathematical Sciences, Soochow University, Suzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9592-7022","authenticated-orcid":false,"given":"Zhenyu","family":"Chen","sequence":"additional","affiliation":[{"name":"State Key Laboratory for Novel Software Technology and Shenzhen Research Institute, Nanjing University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9544-2500","authenticated-orcid":false,"given":"Xiangyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Sciences, Purdue University, West Lafayette, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1038\/s41551-022-00914-1"},{"key":"ref2","first-page":"1","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","volume-title":"Proc. 9th Int. Conf. Learn. Represent.","author":"Dosovitskiy"},{"key":"ref3","article-title":"On the opportunities and risks of foundation models","author":"Bommasani","year":"2021","journal-title":"arXiv:2108.07258"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.167"},{"key":"ref5","first-page":"6510","article-title":"Good semi-supervised learning that requires a bad GAN","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Dai"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"ref7","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Radford"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.5555\/3495724.3497510"},{"key":"ref9","article-title":"Learning deep representations by mutual information estimation and maximization","author":"Hjelm","year":"2018","journal-title":"arXiv:1808.06670"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2006.100"},{"key":"ref11","first-page":"1","article-title":"Improving language understanding by generative pre-training","volume-title":"Proc. 32nd Conf. Neural Inf. Process. Syst.","author":"Radford"},{"key":"ref12","first-page":"67","article-title":"Learning visual features from large weakly supervised data","volume-title":"Proc. 40th IEEE Conf. Comput. Vis. Pattern Recognit.","author":"Joulin"},{"key":"ref13","first-page":"18583","article-title":"Measuring robustness to natural distribution shifts in image classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Taori"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833644"},{"key":"ref15","first-page":"1","article-title":"Poisoning and backdooring contrastive learning","volume-title":"Proc. 10th Int. Conf. Learn. Represent.","author":"Carlini"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01298"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-022-1377-5"},{"key":"ref18","first-page":"1","article-title":"Demystifying self-supervised trojan attacks","author":"Li","year":"2022","journal-title":"CoRR"},{"key":"ref19","article-title":"On the effectiveness of distillation in mitigating backdoors in pre-trained encoder","author":"Han","year":"2024","journal-title":"arXiv:2403.03846"},{"key":"ref20","article-title":"Mutual information guided backdoor mitigation for pre-trained encoders","author":"Han","year":"2024","journal-title":"arXiv:2406.03508"},{"key":"ref21","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref22","first-page":"1","article-title":"Trojaning attack on neural networks","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Liu"},{"key":"ref23","article-title":"CorruptEncoder: Data poisoning based backdoor attacks to contrastive learning","author":"Zhang","year":"2022","journal-title":"arXiv:2211.08229"},{"key":"ref24","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume-title":"Proc. 35th Annu. Conf. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref26","first-page":"1132","article-title":"Neural polarizer: A lightweight and effective backdoor defense via purifying poisoned features","volume-title":"Proc. 37th Adv. Neural Inf. Process. Syst.","author":"Zhu"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01962"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833688"},{"key":"ref30","first-page":"9525","article-title":"Backdoor scanning for deep neural networks through K-arm optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Shen"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833579"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01569"},{"key":"ref33","article-title":"TABOR: A highly accurate approach to inspecting and restoring trojan backdoors in AI systems","author":"Guo","year":"2019","journal-title":"arXiv:1908.01763"},{"key":"ref34","first-page":"1","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"Proc. 9th Int. Conf. Learn. Represent.","author":"Li"},{"key":"ref35","first-page":"1481","article-title":"Eliminating backdoor triggers for deep neural networks using attention relation graph distillation","volume-title":"Proc. 31st Int. Joint Conf. Artif. Intell.","author":"Xia"},{"key":"ref36","first-page":"117","article-title":"Disabling backdoor and identifying poison data by using knowledge distillation in backdoor attacks on deep neural networks","volume-title":"Proc. 13th ACM Workshop Artif. Intell. Security","author":"Yoshida"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.5555\/3524938.3525087"},{"key":"ref38","first-page":"9575","article-title":"Certified robustness of nearest neighbors against data poisoning and backdoor attacks","volume-title":"Proc. 34th Conf. Neural Inf. Process. Syst.","author":"Jia"},{"key":"ref39","article-title":"Representation learning with contrastive predictive coding","author":"Oord","year":"2018","journal-title":"arXiv:1807.03748"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.3390\/technologies9010002"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"issue":"5","key":"ref42","first-page":"1038","article-title":"Survey on backdoor attacks and countermeasures in deep neural network","volume":"17","author":"Qian","year":"2023","journal-title":"J. Frontiers Comput. Sci. Technol."},{"key":"ref43","first-page":"554","article-title":"BadNL: Backdoor attacks against NLP models with semantic-preserving improvements","volume-title":"Proc. Annu. Comput. Secur. Appl. Conf.","author":"Chen"},{"key":"ref44","first-page":"9692","article-title":"Backdooring neural code search","volume-title":"Proc. 61st Annu. Meeting Assoc. Comput. Linguistics","author":"Sun"},{"key":"ref45","first-page":"1","article-title":"UNICORN: A unified backdoor trigger inversion framework","volume-title":"Proc. 11th Int. Conf. Learn. Represent.","author":"Wang"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref47","first-page":"531","article-title":"Mutual information neural estimation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Belghazi"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"issue":"13","key":"ref49","doi-asserted-by":"crossref","first-page":"3521","DOI":"10.1073\/pnas.1611835114","article-title":"Overcoming catastrophic forgetting in neural networks","volume":"114","author":"James","year":"2017","journal-title":"Proc. Nat. Acad. Sci. USA"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01065"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-41676-7_28"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref53","volume-title":"Information Theory and Statistics","author":"Kullback","year":"1997"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref55","first-page":"1","article-title":"Paying more attention to attention: Improving the performance of convolutional neural networks via attention transfer","volume-title":"Proc. 5th Int. Conf. Learn. Represent.","author":"Zagoruyko"},{"key":"ref56","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref57","first-page":"215","article-title":"An analysis of single-layer networks in unsupervised feature learning","volume-title":"Proc. 14th Int. Conf. Artif. Intell. Statist.","volume":"15","author":"Coates"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref60","article-title":"Backdoor defense via decoupling the training process","author":"Huang","year":"2022","journal-title":"arXiv:2202.03423"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.26421\/QIC12.5-6-4"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10930652.pdf?arnumber=10930652","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,31]],"date-time":"2025-03-31T23:24:27Z","timestamp":1743463467000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10930652\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3550062","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}