{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T17:06:07Z","timestamp":1776099967477,"version":"3.50.1"},"reference-count":58,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2024,8,1]],"date-time":"2024-08-01T00:00:00Z","timestamp":1722470400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,8,1]],"date-time":"2024-08-01T00:00:00Z","timestamp":1722470400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,8,1]],"date-time":"2024-08-01T00:00:00Z","timestamp":1722470400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"ONR","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Cisco"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Knowl. Data Eng."],"published-print":{"date-parts":[[2024,8]]},"DOI":"10.1109\/tkde.2024.3365548","type":"journal-article","created":{"date-parts":[[2024,2,14]],"date-time":"2024-02-14T00:02:05Z","timestamp":1707868925000},"page":"3697-3711","source":"Crossref","is-referenced-by-count":7,"title":["BIC-Based Mixture Model Defense Against Data Poisoning Attacks on Classifiers: A Comprehensive Study"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2768-8717","authenticated-orcid":false,"given":"Xi","family":"Li","sequence":"first","affiliation":[{"name":"School of Electrical Engineering and Computer Science, Pennsylvania State University, State College, PA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8848-1643","authenticated-orcid":false,"given":"David J.","family":"Miller","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, Pennsylvania State University, State College, PA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4284-2041","authenticated-orcid":false,"given":"Zhen","family":"Xiang","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, Pennsylvania State University, State College, PA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7947-8127","authenticated-orcid":false,"given":"George","family":"Kesidis","sequence":"additional","affiliation":[{"name":"School of Electrical Engineering and Computer Science, Pennsylvania State University, State College, PA, USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.5555\/3016100.3016102"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref3","first-page":"97","article-title":"Support vector machines under adversarial label noise","volume-title":"Proc. Asian Conf. Mach. Learn.","author":"Biggio"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3264418"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3318464.3389772"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3080522"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.5555\/3524938.3525087"},{"key":"ref8","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref9","first-page":"215","article-title":"An analysis of single-layer networks in unsupervised feature learning","volume-title":"Proc. 14th Int. Conf. Artif. Intell. Statist.","author":"Coates"},{"key":"ref10","article-title":"TREC 2005 spam public corpora","author":"Cormack","year":"2005"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/BF00994018"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.2307\/2984875"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.5555\/1248547.1248548"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"ref15","first-page":"1596","article-title":"Sever: A robust meta-algorithm for stochastic optimization","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Diakonikolas"},{"key":"ref16","volume-title":"Pattern Classification, 2nd ed","author":"Duda","year":"1999"},{"key":"ref17","first-page":"253","article-title":"Robust logistic regression and classification","volume-title":"Proc. 27th Int. Conf. Neural Inf. Process. Syst.","author":"Feng"},{"key":"ref18","first-page":"449","article-title":"Variational inference for Bayesian mixtures of factor analysers","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Ghahramani"},{"key":"ref19","article-title":"The EM algorithm for mixtures of factor analyzers","author":"Ghahramani","year":"1996"},{"key":"ref20","article-title":"Unsupervised representation learning by predicting image rotations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Gidaris"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2006.870586"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"ref25","article-title":"On the effectiveness of mitigating data poisoning attacks with gradient shaping","author":"Hong","year":"2020"},{"key":"ref26","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref27","article-title":"Curie: A method for protecting SVM classifier from poisoning attack","author":"Laishram","year":"2016"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/B978-1-55860-377-6.50048-7"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1111\/j.1751-5823.2001.tb00456.x"},{"key":"ref30","article-title":"Deep partition aggregation: Provable defenses against general poisoning attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Levine"},{"key":"ref31","first-page":"1885","article-title":"Data poisoning attacks on factorization-based collaborative filtering","volume-title":"Proc. 30th Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3078755"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-61725-7_31"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/657"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1002\/0471721182"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.2970615"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140451"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.2307\/2344614"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-88735-7_2"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-28954-6_7"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-13453-2_1"},{"key":"ref45","article-title":"Certified defenses against adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Raghunathan"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1016\/0005-1098(78)90005-5"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1214\/aos\/1176344136"},{"key":"ref48","first-page":"6106","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","volume-title":"Proc. 32nd Int. Conf. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3448016.3457271"},{"key":"ref50","first-page":"3517","article-title":"Certified defenses for data poisoning attacks","volume-title":"Proc. 31st Int. Conf. Neural Inf. Process. Syst.","author":"Steinhardt"},{"key":"ref51","first-page":"20827","article-title":"Out-of-distribution detection with deep nearest neighbors","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sun"},{"key":"ref52","first-page":"22769","article-title":"Improved certified defenses against data poisoning with (deterministic) finite aggregation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wang"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3035685"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2014.08.081"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2877701"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00822"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3102110"},{"key":"ref58","first-page":"7614","article-title":"Transferable clean-label poisoning attacks on deep neural nets","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Zhu"}],"container-title":["IEEE Transactions on Knowledge and Data Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/69\/10589999\/10433691.pdf?arnumber=10433691","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,18]],"date-time":"2024-07-18T05:18:13Z","timestamp":1721279893000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10433691\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8]]},"references-count":58,"journal-issue":{"issue":"8"},"URL":"https:\/\/doi.org\/10.1109\/tkde.2024.3365548","relation":{},"ISSN":["1041-4347","1558-2191","2326-3865"],"issn-type":[{"value":"1041-4347","type":"print"},{"value":"1558-2191","type":"electronic"},{"value":"2326-3865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8]]}}}