{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T16:15:54Z","timestamp":1774023354580,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T00:00:00Z","timestamp":1572998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["CNS-1527939"],"award-info":[{"award-number":["CNS-1527939"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["CNS-1705042"],"award-info":[{"award-number":["CNS-1705042"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,6]]},"DOI":"10.1145\/3319535.3354209","type":"proceedings-article","created":{"date-parts":[[2019,11,7]],"date-time":"2019-11-07T13:08:32Z","timestamp":1573132112000},"page":"2041-2055","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":249,"title":["Latent Backdoor Attacks on Deep Neural Networks"],"prefix":"10.1145","author":[{"given":"Yuanshun","family":"Yao","sequence":"first","affiliation":[{"name":"University of Chicago, Chicago, IL, USA"}]},{"given":"Huiying","family":"Li","sequence":"additional","affiliation":[{"name":"University of Chicago, Chicago, IL, USA"}]},{"given":"Haitao","family":"Zheng","sequence":"additional","affiliation":[{"name":"University of Chicago, Chicago, IL, USA"}]},{"given":"Ben Y.","family":"Zhao","sequence":"additional","affiliation":[{"name":"University of Chicago, Chicago, IL, USA"}]}],"member":"320","published-online":{"date-parts":[[2019,11,6]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Proc. of ICML.","author":"Athalye Anish","year":"2018"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.565"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196517"},{"key":"e_1_3_2_2_4_1","volume-title":"Defensive distillation is not robust to adversarial examples. arXiv preprint arXiv:1607.04311","author":"Carlini Nicholas","year":"2016"},{"key":"e_1_3_2_2_5_1","volume-title":"Magnet and efficient defenses against adversarial attacks are not robust to adversarial examples. arXiv preprint arXiv:1711.08478","author":"Carlini Nicholas","year":"2017"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_7_1","volume-title":"Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728","author":"Chen Bryant","year":"2018"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2015.55"},{"key":"e_1_3_2_2_9_1","volume-title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017"},{"key":"e_1_3_2_2_10_1","volume-title":"Proc of IJCNN.","author":"Dan C","year":"2012"},{"key":"e_1_3_2_2_11_1","volume-title":"Hardware Trojan Attacks on Neural Networks. arXiv preprint arXiv:1806.05768","author":"Clements Joseph","year":"2018"},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.11"},{"key":"e_1_3_2_2_13_1","volume-title":"Proc. of CVPR.","author":"Eykholt Kevin","year":"2018"},{"key":"e_1_3_2_2_14_1","volume-title":"Proc. of Machine Learning and Computer Security Workshop.","author":"Gu Tianyu","year":"2017"},{"key":"e_1_3_2_2_15_1","volume-title":"BadNets: Evaluating Backdooring Attacks on Deep Neural Networks","author":"Gu Tianyu","year":"2019"},{"key":"e_1_3_2_2_16_1","volume-title":"Proc. of WOOT.","author":"He Warren","year":"2017"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6639348"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00065"},{"key":"e_1_3_2_2_20_1","volume-title":"Adversarial Logit Pairing. arXiv preprint arXiv:1803.06373","author":"Kannan Harini","year":"2018"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W17-2620"},{"key":"e_1_3_2_2_22_1","volume-title":"Proc. of ICLR.","author":"Kurakin Alexey","year":"2017"},{"key":"e_1_3_2_2_23_1","unstructured":"Yann LeCun LD Jackel L\u00e9on Bottou Corinna Cortes John S Denker Harris Drucker Isabelle Guyon Urs A Muller Eduard Sackinger Patrice Simard etal 1995. Learning algorithms for classification: A comparison on handwritten digit recognition. Neural networks: the statistical mechanics perspective (1995).  Yann LeCun LD Jackel L\u00e9on Bottou Corinna Cortes John S Denker Harris Drucker Isabelle Guyon Urs A Muller Eduard Sackinger Patrice Simard et al. 1995. Learning algorithms for classification: A comparison on handwritten digit recognition. Neural networks: the statistical mechanics perspective (1995)."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISVLSI.2018.00093"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_26_1","volume-title":"Proc. of ICLR.","author":"Liu Yanpei","year":"2016"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"e_1_3_2_2_29_1","volume-title":"Proc. of ICLR.","author":"Madry Aleksander","year":"2018"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_3_2_2_31_1","volume-title":"Exploiting similarities among languages for machine translation. arXiv preprint arXiv:1309.4168","author":"Mikolov Tomas","year":"2013"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2012.2209421"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.41"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2011.5981788"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2014.131"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"e_1_3_2_2_40_1","volume-title":"Proc. of NeurIPS.","author":"Ren Shaoqing","year":"2015"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644895"},{"key":"e_1_3_2_2_42_1","volume-title":"Proc. of NeurIPS.","author":"Shafahi Ali","year":"2018"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"e_1_3_2_2_44_1","volume-title":"Proc. of NeurIPS.","author":"Steinhardt Jacob","year":"2017"},{"key":"e_1_3_2_2_45_1","volume-title":"Proc. of NeurIPS.","author":"Tran Brandon","year":"2018"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_2_47_1","volume-title":"Zhao","author":"Wang Bolun","year":"2018"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/APSIPA.2015.7415532"},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"e_1_3_2_2_50_1","volume-title":"Proc. of NeurIPS.","author":"Yosinski Jason","year":"2014"}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354209","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3354209","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3354209","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:24:02Z","timestamp":1750202642000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354209"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,11,6]]},"references-count":50,"alternative-id":["10.1145\/3319535.3354209","10.1145\/3319535"],"URL":"https:\/\/doi.org\/10.1145\/3319535.3354209","relation":{},"subject":[],"published":{"date-parts":[[2019,11,6]]},"assertion":[{"value":"2019-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}