{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:20:13Z","timestamp":1785543613109,"version":"3.56.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,8,20]],"date-time":"2020-08-20T00:00:00Z","timestamp":1597881600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"DARPA","award":["N66001-17-2-4031"],"award-info":[{"award-number":["N66001-17-2-4031"]}]},{"name":"NSF","award":["IIS-1900990"],"award-info":[{"award-number":["IIS-1900990"]}]},{"name":"NSF","award":["CNS-1816497"],"award-info":[{"award-number":["CNS-1816497"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,8,23]]},"DOI":"10.1145\/3394486.3403064","type":"proceedings-article","created":{"date-parts":[[2020,8,20]],"date-time":"2020-08-20T23:15:22Z","timestamp":1597965322000},"page":"218-228","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":141,"title":["An Embarrassingly Simple Approach for Trojan Attack in Deep Neural Networks"],"prefix":"10.1145","author":[{"given":"Ruixiang","family":"Tang","sequence":"first","affiliation":[{"name":"Texas A&amp;M University, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mengnan","family":"Du","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ninghao","family":"Liu","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fan","family":"Yang","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xia","family":"Hu","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University, College Station, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,8,20]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n.d.]. Amazon Machine Learning. https:\/\/aws.amazon.com\/machine-learning\/.Accessed: 2019-01-31.  [n.d.]. Amazon Machine Learning. https:\/\/aws.amazon.com\/machine-learning\/.Accessed: 2019-01-31."},{"key":"e_1_3_2_1_2_1","unstructured":"[n.d.]. BigML. https:\/\/bigml.com\/. Accessed: 2019-01-31.  [n.d.]. BigML. https:\/\/bigml.com\/. Accessed: 2019-01-31."},{"key":"e_1_3_2_1_3_1","unstructured":"[n.d.]. Speech Recognition with the Caffe deep learning framework. https:\/\/github.com\/pannous\/caffe-speech-recognition. Accessed: 2019-01-31.  [n.d.]. Speech Recognition with the Caffe deep learning framework. https:\/\/github.com\/pannous\/caffe-speech-recognition. Accessed: 2019-01-31."},{"key":"e_1_3_2_1_4_1","volume-title":"27th USENIX Security Symposium ($$USENIX$$ Security 18)","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi , Carsten Baum , Moustapha Cisse , Benny Pinkas , and Joseph Keshet . 2018 . Turning your weakness into a strength: Watermarking deep neural networks by backdooring . In 27th USENIX Security Symposium ($$USENIX$$ Security 18) . 1615--1631. Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX Security Symposium ($$USENIX$$ Security 18). 1615--1631."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/1553374.1553380"},{"key":"e_1_3_2_1_6_1","volume-title":"Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728","author":"Chen Bryant","year":"2018","unstructured":"Bryant Chen , Wilka Carvalho , Nathalie Baracaldo , Heiko Ludwig , Benjamin Edwards , Taesung Lee , Ian Molloy , and Biplav Srivastava . 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 ( 2018 ). Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.312"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"e_1_3_2_1_9_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen , Chang Liu , Bo Li , Kimberly Lu , and Dawn Song . 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 ( 2017 ). Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359786"},{"key":"e_1_3_2_1_12_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6638947"},{"key":"e_1_3_2_1_14_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017). Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_1_15_1","volume-title":"Explainable artificial intelligence (xai)","author":"Gunning David","year":"2017","unstructured":"David Gunning . 2017. Explainable artificial intelligence (xai) . Defense Advanced Research Projects Agency (DARPA) , nd Web, Vol. 2 ( 2017 ). David Gunning. 2017. Explainable artificial intelligence (xai). Defense Advanced Research Projects Agency (DARPA), nd Web, Vol. 2 (2017)."},{"key":"e_1_3_2_1_16_1","volume-title":"Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems. arXiv preprint arXiv:1908.01763","author":"Guo Wenbo","year":"2019","unstructured":"Wenbo Guo , Lun Wang , Xinyu Xing , Min Du , and Dawn Song . 2019 . Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems. arXiv preprint arXiv:1908.01763 (2019). Wenbo Guo, Lun Wang, Xinyu Xing, Min Du, and Dawn Song. 2019. Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems. arXiv preprint arXiv:1908.01763 (2019)."},{"key":"e_1_3_2_1_17_1","volume-title":"NeuronInspect: Detecting Backdoors in Neural Networks via Output Explanations. arXiv preprint arXiv:1911.07399","author":"Huang Xijie","year":"2019","unstructured":"Xijie Huang , Moustafa Alzantot , and Mani Srivastava . 2019. NeuronInspect: Detecting Backdoors in Neural Networks via Output Explanations. arXiv preprint arXiv:1911.07399 ( 2019 ). Xijie Huang, Moustafa Alzantot, and Mani Srivastava. 2019. NeuronInspect: Detecting Backdoors in Neural Networks via Output Explanations. arXiv preprint arXiv:1911.07399 (2019)."},{"key":"e_1_3_2_1_18_1","volume-title":"Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980","author":"Kingma Diederik P","year":"2014","unstructured":"Diederik P Kingma and Jimmy Ba . 2014 . Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014). Diederik P Kingma and Jimmy Ba. 2014. Adam: A method for stochastic optimization. arXiv preprint arXiv:1412.6980 (2014)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2009.5459250"},{"key":"e_1_3_2_1_20_1","volume-title":"Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 ( 2016 ). Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 (2016)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jesp.2013.03.013"},{"key":"e_1_3_2_1_22_1","volume-title":"Jiahao Yu, Minhui Xue, Dali Kaafar, and Haojin Zhu.","author":"Li Shaofeng","year":"2019","unstructured":"Shaofeng Li , Benjamin Zi Hao Zhao , Jiahao Yu, Minhui Xue, Dali Kaafar, and Haojin Zhu. 2019 . Invisible Backdoor Attacks Against Deep Neural Networks . arXiv preprint arXiv:1909.02742 (2019). Shaofeng Li, Benjamin Zi Hao Zhao, Jiahao Yu, Minhui Xue, Dali Kaafar, and Haojin Zhu. 2019. Invisible Backdoor Attacks Against Deep Neural Networks. arXiv preprint arXiv:1909.02742 (2019)."},{"key":"e_1_3_2_1_23_1","volume-title":"Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307","author":"Liao Cong","year":"2018","unstructured":"Cong Liao , Haoti Zhong , Anna Squicciarini , Sencun Zhu , and David Miller . 2018. Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307 ( 2018 ). Cong Liao, Haoti Zhong, Anna Squicciarini, Sencun Zhu, and David Miller. 2018. Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307 (2018)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_25_1","unstructured":"Yingqi Liu Shiqing Ma Yousra Aafer Wen-Chuan Lee Juan Zhai Weihang Wang and Xiangyu Zhang. 2017. Trojaning attack on neural networks. (2017).  Yingqi Liu Shiqing Ma Yousra Aafer Wen-Chuan Lee Juan Zhai Weihang Wang and Xiangyu Zhang. 2017. Trojaning attack on neural networks. (2017)."},{"key":"e_1_3_2_1_26_1","volume-title":"Deep learning for healthcare: review, opportunities and challenges. Briefings in bioinformatics","author":"Miotto Riccardo","year":"2018","unstructured":"Riccardo Miotto , Fei Wang , Shuang Wang , Xiaoqian Jiang , and Joel T Dudley . 2018. Deep learning for healthcare: review, opportunities and challenges. Briefings in bioinformatics , Vol. 19 , 6 ( 2018 ), 1236--1246. Riccardo Miotto, Fei Wang, Shuang Wang, Xiaoqian Jiang, and Joel T Dudley. 2018. Deep learning for healthcare: review, opportunities and challenges. Briefings in bioinformatics, Vol. 19, 6 (2018), 1236--1246."},{"key":"e_1_3_2_1_27_1","unstructured":"NHTSA. 2016. Tesla Crash Preliminary Evaluation Report. Technical report. National Highway Traffic Safety Administration U.S. Department of Transportation.  NHTSA. 2016. Tesla Crash Preliminary Evaluation Report. Technical report. National Highway Traffic Safety Administration U.S. Department of Transportation."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Omkar M Parkhi Andrea Vedaldi and Andrew Zisserman. 2015. Deep face recognition. (2015).  Omkar M Parkhi Andrea Vedaldi and Andrew Zisserman. 2015. Deep face recognition. (2015).","DOI":"10.5244\/C.29.41"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2011.5981788"},{"key":"e_1_3_2_1_30_1","volume-title":"Explainable artificial intelligence: Understanding, visualizing and interpreting deep learning models. arXiv preprint arXiv:1708.08296","author":"Samek Wojciech","year":"2017","unstructured":"Wojciech Samek , Thomas Wiegand , and Klaus-Robert M\u00fcller . 2017. Explainable artificial intelligence: Understanding, visualizing and interpreting deep learning models. arXiv preprint arXiv:1708.08296 ( 2017 ). Wojciech Samek, Thomas Wiegand, and Klaus-Robert M\u00fcller. 2017. Explainable artificial intelligence: Understanding, visualizing and interpreting deep learning models. arXiv preprint arXiv:1708.08296 (2017)."},{"key":"e_1_3_2_1_31_1","unstructured":"Ali Shafahi W Ronny Huang Mahyar Najibi Octavian Suciu Christoph Studer Tudor Dumitras and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. In Advances in Neural Information Processing Systems. 6103--6113.  Ali Shafahi W Ronny Huang Mahyar Najibi Octavian Suciu Christoph Studer Tudor Dumitras and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. In Advances in Neural Information Processing Systems. 6103--6113."},{"key":"#cr-split#-e_1_3_2_1_32_1.1","doi-asserted-by":"crossref","unstructured":"J. Stallkamp M. Schlipsing J. Salmen and C. Igel. 2012. Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural Networks 0 (2012) --. https:\/\/doi.org\/10.1016\/j.neunet.2012.02.016 10.1016\/j.neunet.2012.02.016","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"#cr-split#-e_1_3_2_1_32_1.2","doi-asserted-by":"crossref","unstructured":"J. Stallkamp M. Schlipsing J. Salmen and C. Igel. 2012. Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural Networks 0 (2012) --. https:\/\/doi.org\/10.1016\/j.neunet.2012.02.016","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_1_33_1","unstructured":"Brandon Tran Jerry Li and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. In Advances in Neural Information Processing Systems. 8000--8010.  Brandon Tran Jerry Li and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. In Advances in Neural Information Processing Systems. 8000--8010."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2011.5995566"}],"event":{"name":"KDD '20: The 26th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Virtual Event CA USA","acronym":"KDD '20","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 26th ACM SIGKDD International Conference on Knowledge Discovery &amp; Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394486.3403064","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3394486.3403064","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3394486.3403064","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:41:38Z","timestamp":1750200098000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3394486.3403064"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,20]]},"references-count":36,"alternative-id":["10.1145\/3394486.3403064","10.1145\/3394486"],"URL":"https:\/\/doi.org\/10.1145\/3394486.3403064","relation":{},"subject":[],"published":{"date-parts":[[2020,8,20]]},"assertion":[{"value":"2020-08-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}