{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T18:41:15Z","timestamp":1766083275236,"version":"3.48.0"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62206238"],"award-info":[{"award-number":["62206238"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004608","name":"Natural Science Foundation of Jiangsu Province","doi-asserted-by":"publisher","award":["BK20251911"],"award-info":[{"award-number":["BK20251911"]}],"id":[{"id":"10.13039\/501100004608","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2025T180438"],"award-info":[{"award-number":["2025T180438"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3640880","type":"journal-article","created":{"date-parts":[[2025,12,5]],"date-time":"2025-12-05T18:37:35Z","timestamp":1764959855000},"page":"13159-13172","source":"Crossref","is-referenced-by-count":0,"title":["<i>SSLDefender<\/i>\n                    : Backdoor Defense in Self-Supervised Learning via Distillation-Guided Unlearning"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2143-5666","authenticated-orcid":false,"given":"Jiale","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Information and Artificial Intelligence, Yangzhou University, Yangzhou, China"}]},{"given":"Wanquan","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Information and Artificial Intelligence, Yangzhou University, Yangzhou, China"}]},{"given":"Kai","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Information and Artificial Intelligence, Yangzhou University, Yangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-4082-0803","authenticated-orcid":false,"given":"Chengcheng","family":"Zhu","sequence":"additional","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5165-5080","authenticated-orcid":false,"given":"Xiaobing","family":"Sun","sequence":"additional","affiliation":[{"name":"School of Information and Artificial Intelligence, Yangzhou University, Yangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4384-5786","authenticated-orcid":false,"given":"Weizhi","family":"Meng","sequence":"additional","affiliation":[{"name":"School of Computing and Communications, Lancaster University, Lancaster, U.K."}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9082-3208","authenticated-orcid":false,"given":"Xiapu","family":"Luo","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hong Kong, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.5555\/3524938.3525087"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2006.100"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01549"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01604"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.218"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3095381"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/1143844.1143865"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/761"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01298"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.5555\/3495724.3497510"},{"key":"ref11","article-title":"EmInspector: Combating backdoor attacks in federated self-supervised learning through embedding inspection","author":"Qian","year":"2024","journal-title":"arXiv:2405.13080"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01569"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583386"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01178"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2024.3417279"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref19","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Wu"},{"article-title":"Bridging mode connectivity in loss landscapes and adversarial robustness","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Zhao","key":"ref20"},{"article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Li","key":"ref21"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179375"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i6.25879"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00156"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00674"},{"key":"ref26","first-page":"15663","article-title":"Using self-supervised learning can improve model robustness and uncertainty","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Hendrycks"},{"key":"ref27","first-page":"22243","article-title":"Big self-supervised models are strong semi-supervised learners","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02103"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW63382.2024.00251"},{"key":"ref30","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"139","author":"Radford"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00403"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.5121\/ijmpict.2013.4203"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02299"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833644"},{"article-title":"Poisoning and backdooring contrastive learning","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Carlini","key":"ref35"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00029"},{"key":"ref37","first-page":"18944","article-title":"Backdoor attack with imperceptible input and latent modification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Doan"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1111\/j.2517-6161.1991.tb01857.x"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73021-4_24"},{"key":"ref40","first-page":"14004","article-title":"Defending neural backdoors via generative distribution modeling","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Qiao"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01090"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i8.28678"},{"key":"ref44","first-page":"261","article-title":"Generalized sliced Wasserstein distances","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Kolouri"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11278744.pdf?arnumber=11278744","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T18:32:23Z","timestamp":1766082743000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11278744\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3640880","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2025]]}}}