{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T06:47:26Z","timestamp":1765262846146,"version":"3.46.0"},"reference-count":105,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFE0209800"],"award-info":[{"award-number":["2023YFE0209800"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["T2341003","62521002","62376210","62161160337","62132011","U24B20185","U21B2018","62206217"],"award-info":[{"award-number":["T2341003","62521002","62376210","62161160337","62132011","U24B20185","U21B2018","62206217"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shaanxi Province Key Industry Innovation Program","award":["2023-ZDLGY-38"],"award-info":[{"award-number":["2023-ZDLGY-38"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3632218","type":"journal-article","created":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T18:40:34Z","timestamp":1762972834000},"page":"12827-12840","source":"Crossref","is-referenced-by-count":0,"title":["De\n                    <sup>2<\/sup>\n                    Trojan: Deployable Trojan Analysis Tool and Benchmark for the Machine Learning Lifecycle via Decoupling"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2777-7392","authenticated-orcid":false,"given":"Shiwei","family":"Wang","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, Shaanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-9227-1884","authenticated-orcid":false,"given":"Chenyang","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, Shaanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6265-7345","authenticated-orcid":false,"given":"Chenhao","family":"Lin","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, Shaanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0745-4294","authenticated-orcid":false,"given":"Zhengyu","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, Shaanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zheng","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, Shaanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8967-8525","authenticated-orcid":false,"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6959-0569","authenticated-orcid":false,"given":"Chao","family":"Shen","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, Shaanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8826-0362","authenticated-orcid":false,"given":"Xiaohong","family":"Guan","sequence":"additional","affiliation":[{"name":"School of Electronic and Information Engineering, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, Shaanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"The trojai software framework: An opensource tool for embedding trojans into deep learning models","author":"Karra","year":"2020","journal-title":"arXiv:2003.07233"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00048"},{"key":"ref3","article-title":"BackdoorBench: A comprehensive benchmark of backdoor learning","author":"Wu","year":"2022","journal-title":"arXiv:2206.12654"},{"key":"ref4","article-title":"BackdoorBox: A Python toolbox for backdoor learning","author":"Li","year":"2023","journal-title":"arXiv:2302.01762"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3182979"},{"key":"ref6","article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","author":"Gao","year":"2020","journal-title":"arXiv:2007.10760"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.312"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1146\/annurev-bioeng071516-044442"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2020.106384"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref11","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/IJCB48548.2020.9304875"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"ref15","first-page":"66","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","volume-title":"Proc. AAAI Workshop","volume":"2301","author":"Chen"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00038"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.softx.2023.101387"},{"issue":"362","key":"ref21","first-page":"5009","article-title":"A unified evaluation of textual backdoor learning: Frameworks and benchmarks","volume-title":"Proc. NeurIPS","volume":"35","author":"Cui"},{"key":"ref22","article-title":"Attacks in adversarial machine learning: A systematic survey from the life-cycle perspective","author":"Wu","year":"2023","journal-title":"arXiv:2302.09457"},{"volume-title":"Mlops: Continuous Delivery and Automation Pipelines in Machine Learning","year":"2023","author":"Cloud","key":"ref23"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3453444"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3613082"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"issue":"86","key":"ref27","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref29","article-title":"Label-consistent backdoor attacks","author":"Turner","year":"2019","journal-title":"arXiv:1912.02771"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref31","first-page":"1","article-title":"WaNet\u2014Imperceptible warping-based backdoor attack","volume-title":"Proc. ICLR","author":"Nguyen"},{"key":"ref32","article-title":"Distilling cognitive backdoor patterns within an image","author":"Huang","year":"2023","journal-title":"arXiv:2301.10908"},{"issue":"707","key":"ref33","first-page":"9727","article-title":"Effective backdoor defense by exploiting sensitivity of poisoned samples","volume-title":"Proc. NeurIPS","volume":"35","author":"Chen"},{"key":"ref34","first-page":"8011","article-title":"Spectral signatures in backdoor attacks","volume-title":"Proc. NeurIPS","author":"Tran"},{"key":"ref35","first-page":"9525","article-title":"Backdoor scanning for deep neural networks through k-arm optimization","volume-title":"Proc. ICML","volume":"139","author":"Shen"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01301"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3108407"},{"key":"ref38","first-page":"14004","article-title":"Defending neural backdoors via generative distribution modeling","volume-title":"Proc. NeurIPS","volume":"32","author":"Qiao"},{"article-title":"Adversarial neuron pruning purifies backdoored deep models","volume-title":"Proc. NeurIPS","author":"Wu","key":"ref39"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00412"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref41"},{"issue":"7","key":"ref42","first-page":"3","article-title":"Tiny ImageNet visual recognition challenge","volume":"7","author":"Le","year":"2015","journal-title":"CS 231N"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"volume-title":"ImageNette: A Smaller Subset of 10 Easily Classified Classes From ImageNet","year":"2020","key":"ref45"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref48","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. ICLR","author":"Simonyan"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref50","article-title":"Automatic differentiation in Pytorch","volume-title":"Proc. NIPS, Autodiff Workshop","author":"Paszke","year":"2017"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2022.3216868"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3603705"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2021.01.009"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3201472"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"ref58","first-page":"18944","article-title":"Backdoor attack with imperceptible input and latent modification","volume-title":"Proc. NeurIPS","author":"Doan"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref60","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"Proc. USENIX Secur.","author":"Bagdasaryan"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00024"},{"key":"ref62","first-page":"443","article-title":"Seeing is not believing: Camouflage attacks on image scaling algorithms","volume-title":"Proc. USENIX Secur.","author":"Xiao"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00786"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i18.29957"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref66","first-page":"259","article-title":"Check your other door! Creating backdoor attacks in the frequency domain","volume-title":"Proc. BMVC","author":"Hammoud"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19778-9_23"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3412130"},{"key":"ref73","first-page":"1","article-title":"How to inject backdoors with better consistency: Logit anchoring on clean data","volume-title":"Proc. ICLR","author":"Zhang"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00035"},{"key":"ref75","article-title":"Subnet replacement: Deployment-stage backdoor attack against deep neural networks in gray-box setting","author":"Qi","year":"2021","journal-title":"arXiv:2107.07240"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"ref77","first-page":"1541","article-title":"Demon in the variant: Statistical analysis of DNNs for robust backdoor contamination detection","volume-title":"Proc. USENIX Secur.","author":"Tang"},{"key":"ref78","article-title":"SPECTRE: Defending against backdoor attacks using robust statistics","author":"Hayase","year":"2021","journal-title":"arXiv:2104.11315"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"ref80","article-title":"A unified framework for analyzing and detecting malicious examples of DNN models","author":"Jin","year":"2020","journal-title":"arXiv:2006.14871"},{"key":"ref81","first-page":"1","article-title":"Robust anomaly detection and backdoor attack detection via differential privacy","volume-title":"Proc. ICLR","author":"Du"},{"key":"ref82","first-page":"1","article-title":"CleaNN: Accelerated trojan shield for embedded neural networks","volume-title":"Proc. IEEE\/ACM Int. Conf. Comput. Aided Design (ICCAD)","author":"Javaheripi"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.3041202"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00784"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413546"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102277"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01617"},{"key":"ref90","first-page":"1","article-title":"AEVA: Black-box backdoor detection using adversarial extreme value analysis","volume-title":"Proc. ICLR","author":"Guo"},{"key":"ref91","article-title":"Overcoming catastrophic forgetting in neural networks","author":"Kirkpatrick","year":"2016","journal-title":"arXiv:1612.00796"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref93","first-page":"1","article-title":"Adversarial unlearning of backdoors via implicit hypergradient","volume-title":"Proc. ICLR","author":"Zeng"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1145\/3411508.3421375"},{"key":"ref97","first-page":"1","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"Proc. ICLR","author":"Li"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179375"},{"key":"ref99","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. ICML","author":"Cohen"},{"key":"ref100","article-title":"On certifying robustness against backdoor attacks via randomized smoothing","author":"Wang","year":"2020","journal-title":"arXiv:2002.11750"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179451"},{"key":"ref102","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16971"},{"key":"ref103","first-page":"1","article-title":"Deep partition aggregation: Provable defenses against general poisoning attacks","volume-title":"Proc. ICLR","author":"Levine"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i9.21191"},{"volume-title":"Backdoor Toolbox","year":"2022","author":"Xie","key":"ref105"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11242156.pdf?arnumber=11242156","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,9]],"date-time":"2025-12-09T06:43:14Z","timestamp":1765262594000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11242156\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":105,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3632218","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2025]]}}}