{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T15:18:51Z","timestamp":1759936731369,"version":"3.41.2"},"reference-count":39,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472345","62432012","62206207","62121001"],"award-info":[{"award-number":["62472345","62432012","62206207","62121001"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["ZYTS24140"],"award-info":[{"award-number":["ZYTS24140"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies","award":["2022B1212010005"],"award-info":[{"award-number":["2022B1212010005"]}]},{"DOI":"10.13039\/501100018925","name":"Overseas Expertise Introduction Center for Discipline Innovation of Food Nutrition and Human Health","doi-asserted-by":"publisher","award":["B16037"],"award-info":[{"award-number":["B16037"]}],"id":[{"id":"10.13039\/501100018925","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Multimedia"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tmm.2025.3535277","type":"journal-article","created":{"date-parts":[[2025,1,27]],"date-time":"2025-01-27T13:54:42Z","timestamp":1737986082000},"page":"3910-3924","source":"Crossref","is-referenced-by-count":1,"title":["<i>Purifier<\/i>$^{+}$: Plug-and-Play Backdoor Mitigation for Pre-Trained Models via Activation Alignment"],"prefix":"10.1109","volume":"27","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5702-5749","authenticated-orcid":false,"given":"Xiaoyu","family":"Zhang","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks (ISN), Xidian University, Xi&#x0027;an, Shaanxi, China"}]},{"given":"Yulin","family":"Jin","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks (ISN), Xidian University, Xi&#x0027;an, Shaanxi, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5026-6085","authenticated-orcid":false,"given":"Haoyu","family":"Tong","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks (ISN), Xidian University, Xi&#x0027;an, Shaanxi, China"}]},{"given":"Jian","family":"Lou","sequence":"additional","affiliation":[{"name":"School of Software Engineering, Sun Yat-Sen University, Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1852-6364","authenticated-orcid":false,"given":"Kai","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence, Xidian University, Xi&#x0027;an, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5858-5070","authenticated-orcid":false,"given":"Xiaofeng","family":"Chen","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks (ISN), Xidian University, Xi&#x0027;an, Shaanxi, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2021.3121547"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2022.3177942"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2022.3217414"},{"key":"ref4","first-page":"4171","article-title":"Bert: Pre-training of deep bidirectional transformers for language understanding","volume-title":"Proc. NAACL-HLT","author":"Devlin","year":"2019"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3348204"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2941244"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690279"},{"article-title":"Dp-brem: Differentially-private and byzantine-robust federated learning with client momentum","year":"2023","author":"Gu","key":"ref8"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/icde60146.2024.00276"},{"article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","year":"2017","author":"Gu","key":"ref10"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453108"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref18","article-title":"Bridging mode connectivity in loss landscapes and adversarial robustness","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Zhao","year":"2020"},{"key":"ref19","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Li","year":"2021"},{"key":"ref20","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Li","year":"2021"},{"key":"ref21","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Wu","year":"2021"},{"key":"ref22","article-title":"Improving adversarial robustness via channel-wise activation suppressing","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Bai","year":"2021"},{"key":"ref23","first-page":"7614","article-title":"Transferable clean-label poisoning attacks on deep neural nets","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhu","year":"2019"},{"article-title":"Label-consistent backdoor attacks","year":"2019","author":"Turner","key":"ref24"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548065"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","year":"2017","author":"Chen","key":"ref27"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3589335.3651525"},{"key":"ref29","article-title":"Rethinking CNN\u2019s generalization to backdoor attack from frequency domain","volume-title":"Proc. 12th Int. Conf. Learn. Representations","author":"Rao","year":"2024"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00786"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01478"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref33","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur. 21)","author":"Bagdasaryan","year":"2021"},{"key":"ref34","first-page":"97","article-title":"Backdoor embedding in convolutional neural network models via invisible perturbation","volume-title":"Proc. 10th ACM Conf. Data Appl. Secur. Privacy (CODASPY\u201920)","author":"Liao","year":"2018"},{"key":"ref35","article-title":"Wanetimperceptible warping-based backdoor attack","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Nguyen","year":"2021"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00390"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01177"}],"container-title":["IEEE Transactions on Multimedia"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6046\/10844992\/10855544.pdf?arnumber=10855544","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,10]],"date-time":"2025-07-10T17:48:42Z","timestamp":1752169722000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10855544\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":39,"URL":"https:\/\/doi.org\/10.1109\/tmm.2025.3535277","relation":{},"ISSN":["1520-9210","1941-0077"],"issn-type":[{"type":"print","value":"1520-9210"},{"type":"electronic","value":"1941-0077"}],"subject":[],"published":{"date-parts":[[2025]]}}}