{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,20]],"date-time":"2025-12-20T22:06:30Z","timestamp":1766268390065,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,11,2]],"date-time":"2020-11-02T00:00:00Z","timestamp":1604275200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,11,2]]},"DOI":"10.1145\/3400302.3415671","type":"proceedings-article","created":{"date-parts":[[2020,12,18]],"date-time":"2020-12-18T01:19:19Z","timestamp":1608254359000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":17,"title":["CleaNN"],"prefix":"10.1145","author":[{"given":"Mojan","family":"Javaheripi","sequence":"first","affiliation":[{"name":"UC San Diego"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Samragh","sequence":"additional","affiliation":[{"name":"UC San Diego"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gregory","family":"Fields","sequence":"additional","affiliation":[{"name":"UC San Diego"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tara","family":"Javidi","sequence":"additional","affiliation":[{"name":"UC San Diego"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Farinaz","family":"Koushanfar","sequence":"additional","affiliation":[{"name":"UC San Diego"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,12,17]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Sparse and redundant modeling of image content using an image-signature-dictionary. &lt;u&gt;SIAM Journal on Imaging Sciences&lt;\/u&gt","author":"Aharon Michal","year":"2008","unstructured":"Michal Aharon and Michael Elad . 2008. Sparse and redundant modeling of image content using an image-signature-dictionary. &lt;u&gt;SIAM Journal on Imaging Sciences&lt;\/u&gt ; 1, 3 ( 2008 ), 228--247. Michal Aharon and Michael Elad. 2008. Sparse and redundant modeling of image content using an image-signature-dictionary. &lt;u&gt;SIAM Journal on Imaging Sciences&lt;\/u&gt; 1, 3 (2008), 228--247."},{"key":"e_1_3_2_1_2_1","volume-title":"K-SVD: An algorithm for designing overcomplete dictionaries for sparse representation. &lt;u&gt","author":"Aharon Michal","year":"2006","unstructured":"Michal Aharon , Michael Elad , and Alfred Bruckstein . 2006. K-SVD: An algorithm for designing overcomplete dictionaries for sparse representation. &lt;u&gt ; IEEE Transactions on signal processing&lt;\/u&gt; 54, 11 ( 2006 ), 4311--4322. Michal Aharon, Michael Elad, and Alfred Bruckstein. 2006. K-SVD: An algorithm for designing overcomplete dictionaries for sparse representation. &lt;u&gt;IEEE Transactions on signal processing&lt;\/u&gt; 54, 11 (2006), 4311--4322."},{"volume-title":"Learning from untrusted data. In &lt;u&gt;Proceedings of the 49th Annual ACM SIGACT Symposium on Theory of Computing.&lt;\/u&gt","author":"Charikar Moses","key":"e_1_3_2_1_3_1","unstructured":"Moses Charikar , Jacob Steinhardt , and Gregory Valiant . 2017. Learning from untrusted data. In &lt;u&gt;Proceedings of the 49th Annual ACM SIGACT Symposium on Theory of Computing.&lt;\/u&gt ; 47--60. Moses Charikar, Jacob Steinhardt, and Gregory Valiant. 2017. Learning from untrusted data. In &lt;u&gt;Proceedings of the 49th Annual ACM SIGACT Symposium on Theory of Computing.&lt;\/u&gt; 47--60."},{"key":"e_1_3_2_1_4_1","volume-title":"Detecting backdoor attacks on deep neural networks by activation clustering. &lt;u&gt;arXiv preprint arXiv:1811.03728&lt;\/u&gt","author":"Chen Bryant","year":"2018","unstructured":"Bryant Chen , Wilka Carvalho , Nathalie Baracaldo , Heiko Ludwig , Benjamin Edwards , Taesung Lee , Ian Molloy , and Biplav Srivastava . 2018. Detecting backdoor attacks on deep neural networks by activation clustering. &lt;u&gt;arXiv preprint arXiv:1811.03728&lt;\/u&gt ; ( 2018 ). Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. &lt;u&gt;arXiv preprint arXiv:1811.03728&lt;\/u&gt; (2018)."},{"key":"e_1_3_2_1_5_1","volume-title":"Deepinspect: A black-box trojan detection and mitigation framework for deep neural networks. In &lt;u&gt;Proceedings of the 28th International Joint Conference on Artificial Intelligence","author":"Chen Huili","year":"2019","unstructured":"Huili Chen , Cheng Fu , Jishen Zhao , and Farinaz Koushanfar . 2019 . Deepinspect: A black-box trojan detection and mitigation framework for deep neural networks. In &lt;u&gt;Proceedings of the 28th International Joint Conference on Artificial Intelligence . AAAI Press .&lt;\/u&gt; 4658--4664. Huili Chen, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar. 2019. Deepinspect: A black-box trojan detection and mitigation framework for deep neural networks. In &lt;u&gt;Proceedings of the 28th International Joint Conference on Artificial Intelligence. AAAI Press.&lt;\/u&gt; 4658--4664."},{"key":"e_1_3_2_1_6_1","volume-title":"Sentinet: Detecting physical attacks against deep learning systems. &lt;u&gt;arXiv preprint arXiv:1812.00292&lt;\/u&gt","author":"Chou Edward","year":"2018","unstructured":"Edward Chou , Florian Tram\u00e8r , Giancarlo Pellegrino , and Dan Boneh . 2018 . Sentinet: Detecting physical attacks against deep learning systems. &lt;u&gt;arXiv preprint arXiv:1812.00292&lt;\/u&gt ; (2018). Edward Chou, Florian Tram\u00e8r, Giancarlo Pellegrino, and Dan Boneh. 2018. Sentinet: Detecting physical attacks against deep learning systems. &lt;u&gt;arXiv preprint arXiv:1812.00292&lt;\/u&gt; (2018)."},{"key":"e_1_3_2_1_7_1","volume-title":"Adaptive time-frequency decompositions. &lt;u&gt;Optical engineering&lt;\/u&gt","author":"Davis Geoffrey M","year":"1994","unstructured":"Geoffrey M Davis , Stephane G Mallat , and Zhifeng Zhang . 1994. Adaptive time-frequency decompositions. &lt;u&gt;Optical engineering&lt;\/u&gt ; 33, 7 ( 1994 ), 2183--2192. Geoffrey M Davis, Stephane G Mallat, and Zhifeng Zhang. 1994. Adaptive time-frequency decompositions. &lt;u&gt;Optical engineering&lt;\/u&gt; 33, 7 (1994), 2183--2192."},{"key":"e_1_3_2_1_8_1","volume-title":"Februus: Input purification defence against trojan attacks on deep neural network systems.","author":"Doan Bao Gia","year":"2019","unstructured":"Bao Gia Doan , Ehsan Abbasnejad , and Damith C Ranasinghe . 2019 . Februus: Input purification defence against trojan attacks on deep neural network systems. (2019). Bao Gia Doan, Ehsan Abbasnejad, and Damith C Ranasinghe. 2019. Februus: Input purification defence against trojan attacks on deep neural network systems. (2019)."},{"key":"e_1_3_2_1_9_1","volume-title":"Optimally sparse representation in general (nonorthogonal) dictionaries via L1 minimization. &lt;u&gt;Proceedings of the National Academy of Sciences&lt;\/u&gt","author":"Donoho David L","year":"2003","unstructured":"David L Donoho and Michael Elad . 2003. Optimally sparse representation in general (nonorthogonal) dictionaries via L1 minimization. &lt;u&gt;Proceedings of the National Academy of Sciences&lt;\/u&gt ; 100, 5 ( 2003 ), 2197--2202. David L Donoho and Michael Elad. 2003. Optimally sparse representation in general (nonorthogonal) dictionaries via L1 minimization. &lt;u&gt;Proceedings of the National Academy of Sciences&lt;\/u&gt; 100, 5 (2003), 2197--2202."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings. ICASSP99 (Cat. No. 99CH36258)","volume":"5","author":"Engan Kjersti","year":"1999","unstructured":"Kjersti Engan , Sven Ole Aase , and J Hakon Husoy . 1999 . Method of optimal directions for frame design. In &lt;u&gt;1999 IEEE International Conference on Acoustics, Speech, and Signal Processing . Proceedings. ICASSP99 (Cat. No. 99CH36258) &lt;\/u&gt;, Vol. 5 . IEEE, 2443--2446. Kjersti Engan, Sven Ole Aase, and J Hakon Husoy. 1999. Method of optimal directions for frame design. In &lt;u&gt;1999 IEEE International Conference on Acoustics, Speech, and Signal Processing. Proceedings. ICASSP99 (Cat. No. 99CH36258)&lt;\/u&gt;, Vol. 5. IEEE, 2443--2446."},{"volume-title":"Model inversion attacks that exploit confidence information and basic countermeasures. In &lt;u&gt;Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security.&lt;\/u&gt","author":"Fredrikson Matt","key":"e_1_3_2_1_11_1","unstructured":"Matt Fredrikson , Somesh Jha , and Thomas Ristenpart . 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In &lt;u&gt;Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security.&lt;\/u&gt ; 1322--1333. Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In &lt;u&gt;Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security.&lt;\/u&gt; 1322--1333."},{"key":"e_1_3_2_1_12_1","volume-title":"Strip: A defence against trojan attacks on deep neural networks. In &lt;u&gt;Proceedings of the 35th Annual Computer Security Applications Conference.&lt;\/u&gt","author":"Gao Yansong","year":"2019","unstructured":"Yansong Gao , Change Xu , Derui Wang , Shiping Chen , Damith C Ranasinghe , and Surya Nepal . 2019 . Strip: A defence against trojan attacks on deep neural networks. In &lt;u&gt;Proceedings of the 35th Annual Computer Security Applications Conference.&lt;\/u&gt ; 113--125. Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith C Ranasinghe, and Surya Nepal. 2019. Strip: A defence against trojan attacks on deep neural networks. In &lt;u&gt;Proceedings of the 35th Annual Computer Security Applications Conference.&lt;\/u&gt; 113--125."},{"key":"e_1_3_2_1_13_1","unstructured":"Gene H Golub and Charles F Van Loan. 2012. &lt;u&gt;Matrix computations.&lt;\/u&gt; Vol. 3. John Hopkins University Press.  Gene H Golub and Charles F Van Loan. 2012. &lt;u&gt;Matrix computations.&lt;\/u&gt; Vol. 3. John Hopkins University Press."},{"key":"e_1_3_2_1_14_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. &lt;u&gt;arXiv preprint arXiv:1708.06733&lt;\/u&gt","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. &lt;u&gt;arXiv preprint arXiv:1708.06733&lt;\/u&gt ; (2017). Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. &lt;u&gt;arXiv preprint arXiv:1708.06733&lt;\/u&gt; (2017)."},{"key":"e_1_3_2_1_15_1","volume-title":"Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems. &lt;u&gt;arXiv preprint arXiv:1908.01763&lt;\/u&gt","author":"Guo Wenbo","year":"2019","unstructured":"Wenbo Guo , Lun Wang , Xinyu Xing , Min Du , and Dawn Song . 2019 . Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems. &lt;u&gt;arXiv preprint arXiv:1908.01763&lt;\/u&gt ; (2019). Wenbo Guo, Lun Wang, Xinyu Xing, Min Du, and Dawn Song. 2019. Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in ai systems. &lt;u&gt;arXiv preprint arXiv:1908.01763&lt;\/u&gt; (2019)."},{"key":"e_1_3_2_1_16_1","unstructured":"Gary B. Huang Marwan Mattar Honglak Lee and Erik Learned-Miller. 2012. Learning to Align from Scratch. In &lt;u&gt;NIPS.&lt;\/u&gt;  Gary B. Huang Marwan Mattar Honglak Lee and Erik Learned-Miller. 2012. Learning to Align from Scratch. In &lt;u&gt;NIPS.&lt;\/u&gt;"},{"volume-title":"FastWave: Accelerating Autoregressive Convolutional Neural Networks on FPGA. In &lt;u&gt;2019 IEEE\/ACM International Conference on Computer-Aided Design (ICCAD).&lt;\/u&gt","author":"Hussain Shehzeen","key":"e_1_3_2_1_17_1","unstructured":"Shehzeen Hussain , Mojan Javaheripi , Paarth Neekhara , Ryan Kastner , and Farinaz Koushanfar . 2019. FastWave: Accelerating Autoregressive Convolutional Neural Networks on FPGA. In &lt;u&gt;2019 IEEE\/ACM International Conference on Computer-Aided Design (ICCAD).&lt;\/u&gt ; IEEE , 1--8. Shehzeen Hussain, Mojan Javaheripi, Paarth Neekhara, Ryan Kastner, and Farinaz Koushanfar. 2019. FastWave: Accelerating Autoregressive Convolutional Neural Networks on FPGA. In &lt;u&gt;2019 IEEE\/ACM International Conference on Computer-Aided Design (ICCAD).&lt;\/u&gt; IEEE, 1--8."},{"key":"e_1_3_2_1_18_1","volume-title":"Bita Darvish Rouhani, and Farinaz Koushanfar","author":"Javaheripi Mojan","year":"2019","unstructured":"Mojan Javaheripi , Bita Darvish Rouhani, and Farinaz Koushanfar . 2019 . SWNet: Small- World Neural Networks and Rapid Convergence . &lt;u&gt;arXiv preprint arXiv:1904.04862&lt;\/u&gt; (2019). Mojan Javaheripi, Bita Darvish Rouhani, and Farinaz Koushanfar. 2019. SWNet: Small-World Neural Networks and Rapid Convergence. &lt;u&gt;arXiv preprint arXiv:1904.04862&lt;\/u&gt; (2019)."},{"key":"e_1_3_2_1_19_1","unstructured":"Yann LeCun Corinna Cortes and Christopher JC Burges. 1998. The MNIST database of handwritten digits. (1998).  Yann LeCun Corinna Cortes and Christopher JC Burges. 1998. The MNIST database of handwritten digits. (1998)."},{"volume-title":"Robust linear regression against training data poisoning. In &lt;u&gt;Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security.&lt;\/u&gt","author":"Liu Chang","key":"e_1_3_2_1_20_1","unstructured":"Chang Liu , Bo Li , Yevgeniy Vorobeychik , and Alina Oprea . 2017. Robust linear regression against training data poisoning. In &lt;u&gt;Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security.&lt;\/u&gt ; 91--102. Chang Liu, Bo Li, Yevgeniy Vorobeychik, and Alina Oprea. 2017. Robust linear regression against training data poisoning. In &lt;u&gt;Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security.&lt;\/u&gt; 91--102."},{"key":"e_1_3_2_1_21_1","volume-title":"Fine-pruning: Defending against backdooring attacks on deep neural networks. In &lt;u&gt;International Symposium on Research in Attacks, Intrusions, and Defenses.&lt;\/u&gt","author":"Liu Kang","year":"2018","unstructured":"Kang Liu , Brendan Dolan-Gavitt , and Siddharth Garg . 2018 . Fine-pruning: Defending against backdooring attacks on deep neural networks. In &lt;u&gt;International Symposium on Research in Attacks, Intrusions, and Defenses.&lt;\/u&gt ; Springer , 273--294. Kang Liu, Brendan Dolan-Gavitt, and Siddharth Garg. 2018. Fine-pruning: Defending against backdooring attacks on deep neural networks. In &lt;u&gt;International Symposium on Research in Attacks, Intrusions, and Defenses.&lt;\/u&gt; Springer, 273--294."},{"key":"e_1_3_2_1_22_1","volume-title":"ABS: Scanning neural networks for back-doors by artificial brain stimulation. In &lt;u&gt;Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security.&lt;\/u&gt","author":"Liu Yingqi","year":"2019","unstructured":"Yingqi Liu , Wen-Chuan Lee , Guanhong Tao , Shiqing Ma , Yousra Aafer , and Xiangyu Zhang . 2019 . ABS: Scanning neural networks for back-doors by artificial brain stimulation. In &lt;u&gt;Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security.&lt;\/u&gt ; 1265--1282. Yingqi Liu, Wen-Chuan Lee, Guanhong Tao, Shiqing Ma, Yousra Aafer, and Xiangyu Zhang. 2019. ABS: Scanning neural networks for back-doors by artificial brain stimulation. In &lt;u&gt;Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security.&lt;\/u&gt; 1265--1282."},{"key":"e_1_3_2_1_23_1","unstructured":"Yingqi Liu Shiqing Ma Yousra Aafer Wen-Chuan Lee Juan Zhai Weihang Wang and Xiangyu Zhang. 2017. Trojaning attack on neural networks. (2017).  Yingqi Liu Shiqing Ma Yousra Aafer Wen-Chuan Lee Juan Zhai Weihang Wang and Xiangyu Zhang. 2017. Trojaning attack on neural networks. (2017)."},{"volume-title":"Neural trojans. In &lt;u&gt;2017 IEEE International Conference on Computer Design (ICCD).&lt;\/u&gt","author":"Liu Yuntao","key":"e_1_3_2_1_24_1","unstructured":"Yuntao Liu , Yang Xie , and Ankur Srivastava . 2017. Neural trojans. In &lt;u&gt;2017 IEEE International Conference on Computer Design (ICCD).&lt;\/u&gt ; IEEE , 45--48. Yuntao Liu, Yang Xie, and Ankur Srivastava. 2017. Neural trojans. In &lt;u&gt;2017 IEEE International Conference on Computer Design (ICCD).&lt;\/u&gt; IEEE, 45--48."},{"key":"e_1_3_2_1_25_1","volume-title":"Nic: Detecting adversarial samples with neural network invariant checking. In &lt;u&gt;Proceedings of the 26th Network and Distributed System Security Symposium (NDSS","author":"Ma Shiqing","year":"2019","unstructured":"Shiqing Ma and Yingqi Liu . 2019 . Nic: Detecting adversarial samples with neural network invariant checking. In &lt;u&gt;Proceedings of the 26th Network and Distributed System Security Symposium (NDSS 2019).&lt;\/u&gt; Shiqing Ma and Yingqi Liu. 2019. Nic: Detecting adversarial samples with neural network invariant checking. In &lt;u&gt;Proceedings of the 26th Network and Distributed System Security Symposium (NDSS 2019).&lt;\/u&gt;"},{"key":"e_1_3_2_1_26_1","unstructured":"Peter Mattson Christine Cheng Cody Coleman Greg Diamos Paulius Micikevicius David Patterson Hanlin Tang Gu-Yeon Wei Peter Bailis Victor Bittorf etal 2019. Mlperf training benchmark. &lt;u&gt;arXiv preprint arXiv:1910.01500&lt;\/u&gt; (2019).  Peter Mattson Christine Cheng Cody Coleman Greg Diamos Paulius Micikevicius David Patterson Hanlin Tang Gu-Yeon Wei Peter Bailis Victor Bittorf et al. 2019. Mlperf training benchmark. &lt;u&gt;arXiv preprint arXiv:1910.01500&lt;\/u&gt; (2019)."},{"key":"e_1_3_2_1_27_1","volume-title":"RankMap: A Framework for Distributed Learning From Dense Data Sets. &lt;u&gt","author":"Mirhoseini Azalia","year":"2017","unstructured":"Azalia Mirhoseini , Eva L Dyer , Ebrahim M Songhori , Richard Baraniuk , and Farinaz Koushanfar . 2017. RankMap: A Framework for Distributed Learning From Dense Data Sets. &lt;u&gt ; IEEE transactions on neural networks and learning systems&lt;\/u&gt; 29, 7 ( 2017 ), 2717--2730. Azalia Mirhoseini, Eva L Dyer, Ebrahim M Songhori, Richard Baraniuk, and Farinaz Koushanfar. 2017. RankMap: A Framework for Distributed Learning From Dense Data Sets. &lt;u&gt;IEEE transactions on neural networks and learning systems&lt;\/u&gt; 29, 7 (2017), 2717--2730."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Omkar M Parkhi Andrea Vedaldi and Andrew Zisserman. 2015. Deep face recognition. (2015).  Omkar M Parkhi Andrea Vedaldi and Andrew Zisserman. 2015. Deep face recognition. (2015).","DOI":"10.5244\/C.29.41"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240791"},{"volume-title":"the complete reference.&lt;\/u&gt","author":"Salomon David","key":"e_1_3_2_1_30_1","unstructured":"David Salomon . 2004. &lt;u&gt; Data compression : the complete reference.&lt;\/u&gt ; Springer Science & Business Media . David Salomon. 2004. &lt;u&gt;Data compression: the complete reference.&lt;\/u&gt; Springer Science & Business Media."},{"key":"e_1_3_2_1_31_1","unstructured":"Mohammad Samragh mojan javaheripi and Farinaz Koushanfar. [n. d.]. EncoDeep: Realizing Bit-Flexible Encoding for Deep Neural Networks. &lt;u&gt;ACM Transaction on Embedded Computing Systems (TECS)&lt;\/u&gt; ([n. d.]).  Mohammad Samragh mojan javaheripi and Farinaz Koushanfar. [n. d.]. EncoDeep: Realizing Bit-Flexible Encoding for Deep Neural Networks. &lt;u&gt;ACM Transaction on Embedded Computing Systems (TECS)&lt;\/u&gt; ([n. d.])."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_1_33_1","volume":"201","author":"Stellato Bartolomeo","unstructured":"Bartolomeo Stellato , Bart PG Van Parys , and Paul J Goulart. 201 7. Multivariate Chebyshev inequality with estimated mean and variance. &lt;u&gt;The American Statistician&lt;\/u&gt; 71, 2 (2017), 123--127. Bartolomeo Stellato, Bart PG Van Parys, and Paul J Goulart. 2017. Multivariate Chebyshev inequality with estimated mean and variance. &lt;u&gt;The American Statistician&lt;\/u&gt; 71, 2 (2017), 123--127.","journal-title":"Paul J Goulart."},{"key":"e_1_3_2_1_34_1","unstructured":"Brandon Tran Jerry Li and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. In &lt;u&gt;Advances in Neural Information Processing Systems.&lt;\/u&gt; 8000--8010.  Brandon Tran Jerry Li and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. In &lt;u&gt;Advances in Neural Information Processing Systems.&lt;\/u&gt; 8000--8010."},{"key":"e_1_3_2_1_35_1","volume-title":"The sample complexity of dictionary learning. &lt;u&gt;Journal of Machine Learning Research&lt;\/u&gt","author":"Vainsencher Daniel","year":"2011","unstructured":"Daniel Vainsencher , Shie Mannor , and Alfred M Bruckstein . 2011. The sample complexity of dictionary learning. &lt;u&gt;Journal of Machine Learning Research&lt;\/u&gt ; 12, Nov ( 2011 ), 3259--3281. Daniel Vainsencher, Shie Mannor, and Alfred M Bruckstein. 2011. The sample complexity of dictionary learning. &lt;u&gt;Journal of Machine Learning Research&lt;\/u&gt; 12, Nov (2011), 3259--3281."},{"volume-title":"Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In &lt;u&gt;2019 IEEE Symposium on Security and Privacy (SP).&lt;\/u&gt","author":"Wang Bolun","key":"e_1_3_2_1_36_1","unstructured":"Bolun Wang , Yuanshun Yao , Shawn Shan , Huiying Li , Bimal Viswanath , Haitao Zheng , and Ben Y Zhao . 2019. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In &lt;u&gt;2019 IEEE Symposium on Security and Privacy (SP).&lt;\/u&gt ; IEEE , 707--723. Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao. 2019. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. In &lt;u&gt;2019 IEEE Symposium on Security and Privacy (SP).&lt;\/u&gt; IEEE, 707--723."}],"event":{"name":"ICCAD '20: IEEE\/ACM International Conference on Computer-Aided Design","sponsor":["SIGDA ACM Special Interest Group on Design Automation","IEEE CAS","IEEE CEDA","IEEE CS"],"location":"Virtual Event USA","acronym":"ICCAD '20"},"container-title":["Proceedings of the 39th International Conference on Computer-Aided Design"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3400302.3415671","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3400302.3415671","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:02:52Z","timestamp":1750197772000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3400302.3415671"}},"subtitle":["accelerated trojan shield for embedded neural networks"],"short-title":[],"issued":{"date-parts":[[2020,11,2]]},"references-count":36,"alternative-id":["10.1145\/3400302.3415671","10.1145\/3400302"],"URL":"https:\/\/doi.org\/10.1145\/3400302.3415671","relation":{},"subject":[],"published":{"date-parts":[[2020,11,2]]},"assertion":[{"value":"2020-12-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}