{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T06:20:25Z","timestamp":1778048425167,"version":"3.51.4"},"reference-count":73,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T00:00:00Z","timestamp":1772755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T00:00:00Z","timestamp":1772755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,3,6]]},"DOI":"10.1109\/wacv61042.2026.00806","type":"proceedings-article","created":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T19:59:32Z","timestamp":1778011172000},"page":"8353-8363","source":"Crossref","is-referenced-by-count":0,"title":["UltraClean: A Simple Framework to Train Robust Neural Networks against Backdoor Attacks"],"prefix":"10.1109","author":[{"given":"Bingyin","family":"Zhao","sequence":"first","affiliation":[{"name":"Pixocial Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yingjie","family":"Lao","sequence":"additional","affiliation":[{"name":"Tufts University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"TensorFlow: Large-scale machine learning on heterogeneous systems","author":"Abadi","year":"2015"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref3","article-title":"Poisoning attacks against support vector machines","volume-title":"Proceedings of the 29th International Conference on Machine Learning, ICML","author":"Biggio"},{"key":"ref4","article-title":"End to end learning for self-driving cars","author":"Bojarski","year":"2016","journal-title":"CoRR"},{"key":"ref5","article-title":"Language models are fewshot learners","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems NeurIPS","author":"Brown"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2005.38"},{"key":"ref7","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","volume-title":"Workshop on Artificial Intelligence Safety 2019 co-located with the Thirty-Third AAAI Conference on Artificial Intelligence AAAI","author":"Chen"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"ref9","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"CoRR"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.24818\/ida-ql\/2019.5"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"ref15","first-page":"18944","article-title":"Backdoor attack with imperceptible input and latent modification","volume-title":"Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, NeurIPS 2021, December 6-14, 2021, virtual","author":"Doan"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"ref17","article-title":"An image is worth 16x16 words: Transformers for image recognition at scale","volume-title":"9th International Conference on Learning Representations, ICLR","author":"Dosovitskiy"},{"key":"ref18","article-title":"Robust anomaly detection and backdoor attack detection via differential privacy","volume-title":"8th International Conference on Learning Representations, ICLR","author":"Du"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref20","article-title":"Witches\u2019 brew: Industrial scale data poisoning via gradient matching","volume-title":"9th International Conference on Learning Representations, ICLR","author":"Geiping"},{"key":"ref21","article-title":"Dataset security for machine learning: Data poisoning, backdoor attacks, and defenses","author":"Goldblum","year":"2020","journal-title":"CoRR"},{"key":"ref22","article-title":"Explaining and harnessing adversarial examples","volume-title":"3rd International Conference on Learning Representations, ICLR","author":"Goodfellow"},{"key":"ref23","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM50108.2020.00025"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.01787"},{"key":"ref26","article-title":"SPECTRE: defending against backdoor attacks using robust statistics","author":"Hayase","year":"2021","journal-title":"CoRR"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref28","article-title":"On the effectiveness of mitigating data poisoning attacks with gradient shaping","author":"Hong","year":"2020","journal-title":"CoRR"},{"key":"ref29","article-title":"Backdoor defense via decoupling the training process","author":"Huang","year":"2022","journal-title":"CoRR"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58583-9_20"},{"key":"ref31","article-title":"Neuroninspect: Detecting backdoors in neural networks via output explanations","author":"Huang","year":"2019","journal-title":"CoRR"},{"key":"ref32","first-page":"1","article-title":"Cleann: Accelerated trojan shield for embedded neural networks","volume-title":"2020 IEEE\/ACM International Conference On Computer Aided Design (ICCAD)","author":"Javaheripi"},{"key":"ref33","article-title":"A unified framework for analyzing and detecting malicious examples of dnn models","author":"Jin","year":"2020"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00038"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref36","article-title":"Backdoor learning: A survey","author":"Li","year":"2020","journal-title":"CoRR"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref38","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"9th International Conference on Learning Representations, ICLR","author":"Li"},{"key":"ref39","article-title":"Anti-backdoor learning: Training clean models on poisoned data","author":"Li","year":"2021","journal-title":"CoRR"},{"key":"ref40","article-title":"Defensive quantization: When efficiency meets robustness","volume-title":"7th International Conference on Learning Representations, ICLR","author":"Lin"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref45","article-title":"Input-aware dynamic backdoor attack","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6-12, 2020, virtual","author":"Nguyen"},{"key":"ref46","article-title":"Wanet - imperceptible warping-based backdoor attack","volume-title":"9th International Conference on Learning Representations, ICLR","author":"Nguyen"},{"key":"ref47","first-page":"8026","article-title":"Pytorch: An imperative style, high-performance deep learning library","volume":"32","author":"Paszke","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref48","article-title":"Label sanitization against label flipping poisoning attacks","author":"Paudice","year":"2018","journal-title":"CoRR"},{"key":"ref49","first-page":"14004","article-title":"Defending neural backdoors via generative distribution modeling","author":"Qiao","year":"2019","journal-title":"Advances in Neural Information Processing Systems 32, NeurIPS"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453108"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00024"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1038\/nature16961"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1393"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"ref56","first-page":"1541","article-title":"Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection","volume-title":"30th USENIX Security Symposium, USENIX Security","author":"Tang"},{"key":"ref57","first-page":"8011","article-title":"Spectral signatures in backdoor attacks","author":"Tran","year":"2018","journal-title":"NeurIPS"},{"key":"ref58","article-title":"Label-consistent backdoor attacks","author":"Turner","year":"2019","journal-title":"CoRR"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/tr.2022.3159784"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2020.10.081"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_14"},{"key":"ref63","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume":"34","author":"Wu","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2018.8659362"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20902"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00230"},{"key":"ref71","article-title":"Bridging mode connectivity in loss landscapes and adversarial robustness","volume-title":"8th International Conference on Learning Representations, ICLR","author":"Zhao"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413546"}],"event":{"name":"2026 IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV)","location":"Tucson, AZ, USA","start":{"date-parts":[[2026,3,6]]},"end":{"date-parts":[[2026,3,10]]}},"container-title":["2026 IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11491838\/11491925\/11492610.pdf?arnumber=11492610","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T06:04:15Z","timestamp":1778047455000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11492610\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,6]]},"references-count":73,"URL":"https:\/\/doi.org\/10.1109\/wacv61042.2026.00806","relation":{},"subject":[],"published":{"date-parts":[[2026,3,6]]}}}