{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:32:21Z","timestamp":1783791141490,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,12]],"date-time":"2020-10-12T00:00:00Z","timestamp":1602460800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Commonwealth Cyber Initiative"},{"DOI":"10.13039\/100007297","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-20-1-2065"],"award-info":[{"award-number":["N00014-20-1-2065"]}],"id":[{"id":"10.13039\/100007297","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Science Foundation","award":["CNS-1828593, OAC-1829771, EEC-1840458, CNS- 1745632, CCF-1850045"],"award-info":[{"award-number":["CNS-1828593, OAC-1829771, EEC-1840458, CNS- 1745632, CCF-1850045"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,12]]},"DOI":"10.1145\/3394171.3413546","type":"proceedings-article","created":{"date-parts":[[2020,10,12]],"date-time":"2020-10-12T12:27:38Z","timestamp":1602505658000},"page":"3173-3181","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":52,"title":["GangSweep"],"prefix":"10.1145","author":[{"given":"Liuwan","family":"Zhu","sequence":"first","affiliation":[{"name":"Old Dominion University, Norfolk, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rui","family":"Ning","sequence":"additional","affiliation":[{"name":"Old Dominion University, Norfolk, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cong","family":"Wang","sequence":"additional","affiliation":[{"name":"Old Dominion University, Norfolk, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chunsheng","family":"Xin","sequence":"additional","affiliation":[{"name":"Old Dominion University, Norfolk, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongyi","family":"Wu","sequence":"additional","affiliation":[{"name":"Old Dominion University, Norfolk, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,10,12]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Proceedings of 2017 IEEE Symposium on Security and Privacy (SP). 39--57","author":"Carlini N."},{"key":"e_1_3_2_2_2_1","volume-title":"The Thirty-Third AAAI Conference on Artificial Intelligence Safety Workshop","author":"Chen Bryant","year":"2019"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_2_4_1","volume-title":"Proceedings of the 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 1625--1634","author":"Eykholt K."},{"key":"e_1_3_2_2_5_1","volume-title":"Proceedings of Advances in Neural Information Processing Systems(NeurIPS). 2672--2680","author":"Goodfellow Ian","year":"2014"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"crossref","unstructured":"T. Gu K. Liu B. Dolan-Gavitt and S. Garg. 2019. BadNets: Evaluating Backdooring Attacks on Deep Neural Networks. IEEE Access (2019) 47230--47244.  T. Gu K. Liu B. Dolan-Gavitt and S. Garg. 2019. BadNets: Evaluating Backdooring Attacks on Deep Neural Networks. IEEE Access (2019) 47230--47244.","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_2_7_1","volume-title":"Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems. arXiv preprint arXiv:1908.01763","author":"Guo Wenbo","year":"2019"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1974.10482962"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3350936"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46475-6_43"},{"key":"e_1_3_2_2_12_1","volume-title":"Adam: A Method for Stochastic Optimization. International Conference on Learning Representations","author":"Kingma Diederik","year":"2014"},{"key":"e_1_3_2_2_13_1","unstructured":"Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images. University of Toronto (2009).  Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images. University of Toronto (2009)."},{"key":"e_1_3_2_2_14_1","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016).  Alexey Kurakin Ian Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)."},{"key":"e_1_3_2_2_15_1","unstructured":"Yann LeCun LD Jackel L\u00e9on Bottou Corinna Cortes John S Denker Harris Drucker Isabelle Guyon Urs A Muller Eduard Sackinger Patrice Simard et almbox. 1995. Learning algorithms for classification: A comparison on handwritten digit recognition. Neural networks: the statistical mechanics perspective (1995) 276.  Yann LeCun LD Jackel L\u00e9on Bottou Corinna Cortes John S Denker Harris Drucker Isabelle Guyon Urs A Muller Eduard Sackinger Patrice Simard et almbox. 1995. Learning algorithms for classification: A comparison on handwritten digit recognition. Neural networks: the statistical mechanics perspective (1995) 276."},{"key":"e_1_3_2_2_16_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 6389--6399","author":"Li Hao","year":"2018"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3350871"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.41"},{"key":"e_1_3_2_2_22_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems(NeurIPS). 14004--14013","author":"Qiao Ximing","year":"2019"},{"key":"e_1_3_2_2_23_1","volume-title":"Reliable Machine Learning in the Wild Workshop, 34th International Conference on Machine Learning. http:\/\/arxiv.org\/abs\/1707","author":"Rauber Jonas","year":"2017"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_2_2_26_1","unstructured":"Ahmed Salem Rui Wen Michael Backes Shiqing Ma and Yang Zhang. 2020. Dynamic Backdoor Attacks Against Machine Learning Models. arXiv preprint arXiv:2003.03675 (2020).  Ahmed Salem Rui Wen Michael Backes Shiqing Ma and Yang Zhang. 2020. Dynamic Backdoor Attacks Against Machine Learning Models. arXiv preprint arXiv:2003.03675 (2020)."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"crossref","unstructured":"Johannes Stallkamp Marc Schlipsing Jan Salmen and Christian Igel. 2012. Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural networks Vol. 32 (2012) 323--332.  Johannes Stallkamp Marc Schlipsing Jan Salmen and Christian Igel. 2012. Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural networks Vol. 32 (2012) 323--332.","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00714"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SNPD.2017.8022758"},{"key":"e_1_3_2_2_30_1","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013).  Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.1991.139758"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_2_33_1","unstructured":"Haohan Wang Xindi Wu Pengcheng Yin and Eric P Xing. 2019 a. High frequency component helps explain the generalization of convolutional neural networks. arXiv preprint arXiv:1905.13545 (2019).  Haohan Wang Xindi Wu Pengcheng Yin and Eric P Xing. 2019 a. High frequency component helps explain the generalization of convolutional neural networks. arXiv preprint arXiv:1905.13545 (2019)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"crossref","unstructured":"Chaowei Xiao Bo Li Jun-Yan Zhu Warren He Mingyan Liu and Dawn Song. 2018. Generating adversarial examples with adversarial networks. arXiv preprint arXiv:1801.02610 (2018).  Chaowei Xiao Bo Li Jun-Yan Zhu Warren He Mingyan Liu and Dawn Song. 2018. Generating adversarial examples with adversarial networks. arXiv preprint arXiv:1801.02610 (2018).","DOI":"10.24963\/ijcai.2018\/543"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.244"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240508.3240616"}],"event":{"name":"MM '20: The 28th ACM International Conference on Multimedia","location":"Seattle WA USA","acronym":"MM '20","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 28th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394171.3413546","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3394171.3413546","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3394171.3413546","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:47:13Z","timestamp":1750193233000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394171.3413546"}},"subtitle":["Sweep out Neural Backdoors by GAN"],"short-title":[],"issued":{"date-parts":[[2020,10,12]]},"references-count":37,"alternative-id":["10.1145\/3394171.3413546","10.1145\/3394171"],"URL":"https:\/\/doi.org\/10.1145\/3394171.3413546","relation":{},"subject":[],"published":{"date-parts":[[2020,10,12]]},"assertion":[{"value":"2020-10-12","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}