{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T17:29:53Z","timestamp":1785605393438,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T00:00:00Z","timestamp":1572998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"ONR","award":["N000141410468, N000141712947"],"award-info":[{"award-number":["N000141410468, N000141712947"]}]},{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["1748764, 1901242, 1910300"],"award-info":[{"award-number":["1748764, 1901242, 1910300"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"DARPA","award":["FA8650-15-C-7562"],"award-info":[{"award-number":["FA8650-15-C-7562"]}]},{"name":"Sandia National Lab","award":["1701331"],"award-info":[{"award-number":["1701331"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,6]]},"DOI":"10.1145\/3319535.3363216","type":"proceedings-article","created":{"date-parts":[[2019,11,7]],"date-time":"2019-11-07T13:08:32Z","timestamp":1573132112000},"page":"1265-1282","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":326,"title":["ABS: Scanning Neural Networks for Back-doors by Artificial Brain Stimulation"],"prefix":"10.1145","author":[{"given":"Yingqi","family":"Liu","sequence":"first","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wen-Chuan","family":"Lee","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guanhong","family":"Tao","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiqing","family":"Ma","sequence":"additional","affiliation":[{"name":"Rutgers University, New Brunswick, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yousra","family":"Aafer","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Purdue University, West Lafayette, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2019,11,6]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"acoomans. 2013. . https:\/\/github.com\/acoomans\/instagram-filters  acoomans. 2013. . https:\/\/github.com\/acoomans\/instagram-filters"},{"key":"e_1_3_2_2_2_1","volume-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420","author":"Athalye Anish","year":"2018"},{"key":"e_1_3_2_2_3_1","volume-title":"Davide Del Testa","author":"Bojarski Mariusz","year":"2016"},{"key":"e_1_3_2_2_4_1","volume-title":"Adversarial patch. arXiv preprint arXiv:1712.09665","author":"Brown Tom B","year":"2017"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196517"},{"key":"e_1_3_2_2_6_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017"},{"key":"e_1_3_2_2_7_1","volume-title":"SentiNet: Detecting Physical Attacks Against Deep Learning Systems. arXiv preprint arXiv:1812.00292","author":"Chou Edward","year":"2018"},{"key":"e_1_3_2_2_8_1","volume-title":"Hardware trojan attacks on neural networks. arXiv preprint arXiv:1806.05768","author":"Clements Joseph","year":"2018"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"crossref","unstructured":"J. Deng W. Dong R. Socher L.-J. Li K. Li and L. Fei-Fei. 2009. ImageNet: A Large-Scale Hierarchical Image Database. In CVPR09 .  J. Deng W. Dong R. Socher L.-J. Li K. Li and L. Fei-Fei. 2009. ImageNet: A Large-Scale Hierarchical Image Database. In CVPR09 .","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274706"},{"key":"e_1_3_2_2_12_1","volume-title":"STRIP: A Defence Against Trojan Attacks on Deep Neural Networks. arXiv preprint arXiv:1902.06531","author":"Gao Yansong","year":"2019"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.169"},{"key":"e_1_3_2_2_14_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243757"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2017.8228656"},{"key":"e_1_3_2_2_19_1","unstructured":"Melissa King. 2019. TrojAI . https:\/\/www.iarpa.gov\/index.php?option=com_content&view=article&id=1142&Itemid=443  Melissa King. 2019. TrojAI . https:\/\/www.iarpa.gov\/index.php?option=com_content&view=article&id=1142&Itemid=443"},{"key":"e_1_3_2_2_21_1","volume-title":"et almbox","author":"LeCun Yann","year":"1998"},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2015.7301352"},{"key":"e_1_3_2_2_23_1","volume-title":"Hu-fu: Hardware and software collaborative attack framework against neural networks. In ISVLSI .","author":"Li Wenshuo","year":"2018"},{"key":"e_1_3_2_2_24_1","volume-title":"Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307","author":"Liao Cong","year":"2018"},{"key":"e_1_3_2_2_25_1","volume-title":"Network in network. arXiv preprint arXiv:1312.4400","author":"Lin Min","year":"2013"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_27_1","volume-title":"Trojaning Attack on Neural Networks. In 25nd Annual Network and Distributed System Security Symposium, NDSS 2018","author":"Liu Yingqi","year":"2018"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"e_1_3_2_2_29_1","volume-title":"NIC: Detecting Adversarial Samples with Neural Network Invariant Checking. In 26th Annual Network and Distributed System Security Symposium, NDSS .","author":"Ma Shiqing","year":"2019"},{"key":"e_1_3_2_2_30_1","volume-title":"An Equivalence of Fully Connected Layer and Convolutional Layer. arXiv preprint arXiv:1712.01252","author":"Ma Wei","year":"2017"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ITSC.2014.6957882"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_2_36_1","volume-title":"et almbox","author":"Parkhi Omkar M","year":"2015"},{"key":"e_1_3_2_2_37_1","volume-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 5--15","author":"Paudice Andrea","year":"2018"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"e_1_3_2_2_39_1","volume-title":"et almbox","author":"Russakovsky Olga","year":"2015"},{"key":"e_1_3_2_2_40_1","unstructured":"Ali Shafahi W Ronny Huang Mahyar Najibi Octavian Suciu Christoph Studer Tudor Dumitras and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. In NeuralIPS .  Ali Shafahi W Ronny Huang Mahyar Najibi Octavian Suciu Christoph Studer Tudor Dumitras and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. In NeuralIPS ."},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00211"},{"key":"e_1_3_2_2_42_1","volume-title":"Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556","author":"Simonyan Karen","year":"2014"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"e_1_3_2_2_44_1","volume-title":"Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural networks","author":"Stallkamp Johannes","year":"2012"},{"key":"e_1_3_2_2_45_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013"},{"key":"e_1_3_2_2_46_1","volume-title":"Attacks meet interpretability: Attribute-steered detection of adversarial samples. In Advances in Neural Information Processing Systems. 7717--7728","author":"Tao Guanhong","year":"2018"},{"key":"e_1_3_2_2_47_1","unstructured":"Alexander Turner Dimitris Tsipras and Aleksander Madry. 2018. Clean-Label Backdoor Attacks. (2018).  Alexander Turner Dimitris Tsipras and Aleksander Madry. 2018. Clean-Label Backdoor Attacks. (2018)."},{"key":"e_1_3_2_2_48_1","volume-title":"Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks","author":"Wang Bolun"},{"key":"e_1_3_2_2_49_1","volume-title":"et almbox","author":"Wang Zhou","year":"2004"},{"key":"e_1_3_2_2_50_1","unstructured":"wikipedia. 2019. Electrical brain stimulation - Wikipedia . https:\/\/en.wikipedia.org\/wiki\/Electrical_brain_stimulation  wikipedia. 2019. Electrical brain stimulation - Wikipedia . https:\/\/en.wikipedia.org\/wiki\/Electrical_brain_stimulation"},{"key":"e_1_3_2_2_51_1","volume-title":"Reinforcing adversarial robustness using model confidence induced by adversarial training. arXiv preprint arXiv:1711.08001","author":"Wu Xi","year":"2017"},{"key":"e_1_3_2_2_52_1","volume-title":"Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155","author":"Xu Weilin","year":"2017"},{"key":"e_1_3_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134642"},{"key":"e_1_3_2_2_54_1","volume-title":"Potrojan: powerful neural-level trojan designs in deep learning models. arXiv preprint arXiv:1802.03043","author":"Zou Minhui","year":"2018"}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3363216","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3363216","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3363216","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:44:33Z","timestamp":1750203873000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3363216"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,11,6]]},"references-count":52,"alternative-id":["10.1145\/3319535.3363216","10.1145\/3319535"],"URL":"https:\/\/doi.org\/10.1145\/3319535.3363216","relation":{},"subject":[],"published":{"date-parts":[[2019,11,6]]},"assertion":[{"value":"2019-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}