{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T15:59:19Z","timestamp":1783007959705,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3485881","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"634-645","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Understanding the Threats of Trojaned Quantized Neural Network in Model Supply Chains"],"prefix":"10.1145","author":[{"given":"Xudong","family":"Pan","sequence":"first","affiliation":[{"name":"Fudan University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yifan","family":"Yan","sequence":"additional","affiliation":[{"name":"Fudan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Min","family":"Yang","sequence":"additional","affiliation":[{"name":"Fudan University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n.d.]. Android Demo Apps - PyTorch. https:\/\/github.com\/pytorch\/android-demo-app. Accessed: 2021-05-21."},{"key":"e_1_3_2_1_2_1","unstructured":"[n.d.]. Available Models-PaddleLite. https:\/\/paddle-lite.readthedocs.io\/zh\/latest\/introduction\/support_model_list.html. Accessed: 2021-05-21."},{"key":"e_1_3_2_1_3_1","unstructured":"[n.d.]. Models - Machine Learing - Apple Developer. https:\/\/developer.apple.com\/machine-learning\/models\/. Accessed: 2021-05-21."},{"key":"e_1_3_2_1_4_1","unstructured":"[n.d.]. Quantization-PyTorch. https:\/\/pytorch.org\/docs\/stable\/quantization.html. Accessed: 2021-05-21."},{"key":"e_1_3_2_1_5_1","unstructured":"[n.d.]. Quantization-Tensorflow. https:\/\/www.tensorflow.org\/model_optimization\/guide\/quantization\/post_training. Accessed: 2021-05-21."},{"key":"e_1_3_2_1_6_1","unstructured":"[n.d.]. US Government\u2019s TrojAI Program. https:\/\/www.iarpa.gov\/index.php\/research-programs\/trojai. Accessed: 2021-02-01."},{"key":"e_1_3_2_1_7_1","unstructured":"Mart\u00edn Abadi P. Barham J. Chen and et al.2016. TensorFlow: A system for large-scale machine learning. In OSDI."},{"key":"e_1_3_2_1_8_1","volume-title":"Blind Backdoors in Deep Learning Models. USENIX Security Symposium(2021)","author":"Bagdasaryan E.","year":"2021","unstructured":"E. Bagdasaryan and Vitaly Shmatikov. 2021. Blind Backdoors in Deep Learning Models. USENIX Security Symposium(2021)."},{"key":"e_1_3_2_1_9_1","unstructured":"E. Bagdasaryan Andreas Veit Yiqing Hua D. Estrin and Vitaly Shmatikov. 2020. How To Backdoor Federated Learning. In AISTATS."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3437526"},{"key":"e_1_3_2_1_11_1","volume-title":"Towards Evaluating the Robustness of Neural Networks. 2017 IEEE Symposium on Security and Privacy (SP)","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David\u00a0A. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. 2017 IEEE Symposium on Security and Privacy (SP) (2017), 39\u201357."},{"key":"e_1_3_2_1_12_1","unstructured":"Bryant Chen Wilka Carvalho Nathalie Baracaldo Heiko Ludwig Ben Edwards Taesung Lee Ian Molloy and B. Srivastava. 2019. Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering. ArXiv abs\/1811.03728(2019)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Huili Chen Cheng Fu J. Zhao and F. Koushanfar. 2019. DeepInspect: A Black-box Trojan Detection and Mitigation Framework for Deep Neural Networks. In IJCAI.","DOI":"10.24963\/ijcai.2019\/647"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2019.2921977"},{"key":"e_1_3_2_1_15_1","unstructured":"X. Chen Chang Liu Bo Li Kimberly Lu and D. Song. 2017. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. ArXiv (2017)."},{"key":"e_1_3_2_1_16_1","unstructured":"Matthieu Courbariaux Yoshua Bengio and J. David. 2015. BinaryConnect: Training Deep Neural Networks with binary weights during propagations. In NIPS."},{"key":"e_1_3_2_1_17_1","volume-title":"Binarized Neural Networks: Training Deep Neural Networks with Weights and Activations Constrained to +1 or -1. NeurIPS","author":"Courbariaux Matthieu","year":"2016","unstructured":"Matthieu Courbariaux, Itay Hubara, Daniel Soudry, Ran El-Yaniv, and Yoshua Bengio. 2016. Binarized Neural Networks: Training Deep Neural Networks with Weights and Activations Constrained to +1 or -1. NeurIPS (2016)."},{"key":"e_1_3_2_1_18_1","volume-title":"Februus: Input Purification Defense Against Trojan Attacks on Deep Neural Network Systems. ACSAC","author":"Doan Bao\u00a0Gia","year":"2020","unstructured":"Bao\u00a0Gia Doan, Ehsan Abbasnejad, and D. Ranasinghe. 2020. Februus: Input Purification Defense Against Trojan Attacks on Deep Neural Network Systems. ACSAC (2020)."},{"key":"e_1_3_2_1_19_1","unstructured":"Min Du R. Jia and D. Song. 2020. Robust Anomaly Detection and Backdoor Attack Detection Via Differential Privacy. ICLR (2020)."},{"key":"e_1_3_2_1_20_1","volume-title":"Relative Robustness of Quantized Neural Networks Against Adversarial Attacks. 2020 International Joint Conference on Neural Networks (IJCNN)","author":"Duncan Kirsty","year":"2020","unstructured":"Kirsty Duncan, E. Komendantskaya, Rob Stewart, and M. Lones. 2020. Relative Robustness of Quantized Neural Networks Against Adversarial Attacks. 2020 International Joint Conference on Neural Networks (IJCNN) (2020), 1\u20138."},{"key":"e_1_3_2_1_21_1","unstructured":"Yansong Gao Chang Xu Derui Wang S. Chen D. Ranasinghe and S. Nepal. 2019. STRIP: a defence against trojan attacks on deep neural networks. ACSAC (2019)."},{"key":"e_1_3_2_1_22_1","unstructured":"Amir Gholami Sehoon Kim Zhen Dong Zhewei Yao M. Mahoney and K. Keutzer. 2021. A Survey of Quantization Methods for Efficient Neural Network Inference. ArXiv abs\/2103.13630(2021)."},{"key":"e_1_3_2_1_23_1","volume-title":"Deep Learning","author":"Goodfellow Ian","unstructured":"Ian Goodfellow, Yoshua Bengio, and Aaron Courville. 2016. Deep Learning. MIT Press. http:\/\/www.deeplearningbook.org."},{"key":"e_1_3_2_1_24_1","unstructured":"I. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. CoRR abs\/1412.6572(2015)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/18.720541"},{"key":"e_1_3_2_1_26_1","unstructured":"Tianyu Gu K. Liu Brendan Dolan-Gavitt and S. Garg. 2019. BadNets: Evaluating Backdooring Attacks on Deep Neural Networks. IEEE Access (2019)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Wenbo Guo Lun Wang Yan Xu Xinyu Xing Min Du and D. Song. 2020. Towards Inspecting and Eliminating Trojan Backdoors in Deep Neural Networks. ICDM (2020).","DOI":"10.1109\/ICDM50108.2020.00025"},{"key":"e_1_3_2_1_28_1","unstructured":"Kartik Gupta and Thalaiyasingam Ajanthan. 2020. Improved Gradient based Adversarial Attacks for Quantized Networks. ArXiv abs\/2003.13511(2020)."},{"key":"e_1_3_2_1_29_1","volume-title":"Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault Attacks. In USENIX Security Symposium.","author":"Hong Sanghyun","unstructured":"Sanghyun Hong, Pietro Frigo, Yigitcan Kaya, Cristiano Giuffrida, and T. Dumitras. 2019. Terminal Brain Damage: Exposing the Graceless Degradation in Deep Neural Networks Under Hardware Fault Attacks. In USENIX Security Symposium."},{"key":"e_1_3_2_1_30_1","volume-title":"Quantization and Training of Neural Networks for Efficient Integer-Arithmetic-Only Inference. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Jacob Benoit","year":"2018","unstructured":"Benoit Jacob, S. Kligys, Bo Chen, Menglong Zhu, Matthew Tang, Andrew\u00a0G. Howard, Hartwig Adam, and D. Kalenichenko. 2018. Quantization and Training of Neural Networks for Efficient Integer-Arithmetic-Only Inference. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2018), 2704\u20132713."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243757"},{"key":"e_1_3_2_1_32_1","unstructured":"Elias\u00a0Boutros Khalil Amrita Gupta and B. Dilkina. 2019. Combinatorial Attacks on Binarized Neural Networks. ICLR (2019)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2014.6853210"},{"key":"e_1_3_2_1_34_1","volume-title":"Kingma and Jimmy Ba","author":"P.","year":"2015","unstructured":"Diederik\u00a0P. Kingma and Jimmy Ba. 2015. Adam: A Method for Stochastic Optimization. CoRR abs\/1412.6980(2015)."},{"key":"e_1_3_2_1_35_1","unstructured":"Raghuraman Krishnamoorthi. 2018. Quantizing deep convolutional networks for efficient inference: A whitepaper. ArXiv abs\/1806.08342(2018)."},{"key":"e_1_3_2_1_36_1","unstructured":"A. Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","unstructured":"Yann LeCun L\u00e9on Bottou Yoshua Bengio 1998. Gradient-based learning applied to document recognition.","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_38_1","volume-title":"Ternary Weight Networks. NeurIPS","author":"Li Fengfu","year":"2016","unstructured":"Fengfu Li and Bin Liu. 2016. Ternary Weight Networks. NeurIPS (2016)."},{"key":"e_1_3_2_1_39_1","volume-title":"Invisible Backdoor Attacks on Deep Neural Networks via Steganography and Regularization. TDSC","author":"Li Shaofeng","year":"2019","unstructured":"Shaofeng Li, Minhui Xue, B. Zhao, H. Zhu, and Xinpeng Zhang. 2019. Invisible Backdoor Attacks on Deep Neural Networks via Steganography and Regularization. TDSC (2019)."},{"key":"e_1_3_2_1_40_1","volume-title":"Defensive Quantization: When Efficiency Meets Robustness. ArXiv abs\/1904.08444(2019).","author":"Lin Ji","year":"2019","unstructured":"Ji Lin, Chuang Gan, and Song Han. 2019. Defensive Quantization: When Efficiency Meets Robustness. ArXiv abs\/1904.08444(2019)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"K. Liu Brendan Dolan-Gavitt and S. Garg. 2018. Fine-Pruning: Defending Against Backdooring Attacks on Deep Neural Networks. In RAID.","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_43_1","volume-title":"ABS: Scanning Neural Networks for Back-doors by Artificial Brain Stimulation. CCS","author":"Liu Y.","year":"2019","unstructured":"Y. Liu, Wen-Chuan Lee, Guanhong Tao, Shiqing Ma, Yousra Aafer, and X. Zhang. 2019. ABS: Scanning Neural Networks for Back-doors by Artificial Brain Stimulation. CCS (2019)."},{"key":"e_1_3_2_1_44_1","unstructured":"Yingqi Liu Shiqing Ma Yousra Aafer W. Lee Juan Zhai Weihang Wang and X. Zhang. 2018. Trojaning Attack on Neural Networks. NDSS (2018)."},{"key":"e_1_3_2_1_45_1","first-page":"2579","article-title":"Visualizing Data using t-SNE","volume":"9","author":"Maaten D.","year":"2008","unstructured":"L.\u00a0V.\u00a0D. Maaten and Geoffrey\u00a0E. Hinton. 2008. Visualizing Data using t-SNE. Journal of Machine Learning Research 9 (2008), 2579\u20132605.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_1_46_1","unstructured":"Alberto\u00a0G. Matachana Kenneth\u00a0T. Co Luis Mu\u00f1oz-Gonz\u00e1lez David Mart\u00ednez and Emil\u00a0C. Lupu. 2020. Robustness and Transferability of Universal Attacks on Compressed Models. ArXiv abs\/2012.06024(2020)."},{"key":"e_1_3_2_1_47_1","unstructured":"A. Nguyen and A. Tran. 2020. Input-Aware Dynamic Backdoor Attack. NeurIPS (2020)."},{"key":"e_1_3_2_1_48_1","volume-title":"2019. PyTorch: An Imperative Style","author":"Paszke Adam","unstructured":"Adam Paszke, S. Gross, Francisco Massa, and et al.2019. PyTorch: An Imperative Style, High-Performance Deep Learning Library. In NeurIPS."},{"key":"e_1_3_2_1_49_1","unstructured":"Ximing Qiao Yukun Yang and Hongbing Li. 2019. Defending Neural Backdoors via Generative Distribution Modeling. In NeurIPS."},{"key":"e_1_3_2_1_50_1","volume-title":"Bit-Flip Attack: Crushing Neural Network With Progressive Bit Search. 2019 IEEE\/CVF International Conference on Computer Vision (ICCV)","author":"Rakin S.","year":"2019","unstructured":"A.\u00a0S. Rakin, Zhezhi He, and Deliang Fan. 2019. Bit-Flip Attack: Crushing Neural Network With Progressive Bit Search. 2019 IEEE\/CVF International Conference on Computer Vision (ICCV) (2019), 1211\u20131220."},{"key":"e_1_3_2_1_51_1","volume-title":"TBT: Targeted Neural Network Attack With Bit Trojan. 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Rakin S.","year":"2020","unstructured":"A.\u00a0S. Rakin, Zhezhi He, and Deliang Fan. 2020. TBT: Targeted Neural Network Attack With Bit Trojan. 2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (2020), 13195\u201313204."},{"key":"e_1_3_2_1_52_1","volume-title":"USENIX Security Symposium.","author":"Razavi Kaveh","unstructured":"Kaveh Razavi, Ben Gras, E. Bosman, B. Preneel, Cristiano Giuffrida, and H. Bos. 2016. Flip Feng Shui: Hammering a Needle in the Software Stack. In USENIX Security Symposium."},{"key":"e_1_3_2_1_53_1","volume-title":"Fault Model Analysis of Laser-Induced Faults in SRAM Memory Cells. 2013 Workshop on Fault Diagnosis and Tolerance in Cryptography","author":"Roscian Cyril","year":"2013","unstructured":"Cyril Roscian, A. Sarafianos, J. Dutertre, and A. Tria. 2013. Fault Model Analysis of Laser-Induced Faults in SRAM Memory Cells. 2013 Workshop on Fault Diagnosis and Tolerance in Cryptography (2013), 89\u201398."},{"key":"e_1_3_2_1_54_1","unstructured":"A. Salem Rui Wen M. Backes Shiqing Ma and Y. Zhang. 2020. Dynamic Backdoor Attacks Against Machine Learning Models. ArXiv (2020)."},{"key":"e_1_3_2_1_55_1","unstructured":"K. Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. CoRR abs\/1409.1556(2015)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","unstructured":"J. Stallkamp Marc Schlipsing J. Salmen and C. Igel. 2012. Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural networks : the official journal of the International Neural Network Society 32(2012) 323\u201332.","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_1_57_1","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna D. Erhan I. Goodfellow and R. Fergus. 2014. Intriguing properties of neural networks. CoRR abs\/1312.6199(2014)."},{"key":"e_1_3_2_1_58_1","unstructured":"Brandon Tran Jerry Li and A. Madry. 2018. Spectral Signatures in Backdoor Attacks. In NeurIPS."},{"key":"e_1_3_2_1_59_1","unstructured":"Alexander Turner D. Tsipras and A. Madry. 2019. Label-Consistent Backdoor Attacks. ArXiv (2019)."},{"key":"e_1_3_2_1_60_1","volume-title":"Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. Security & Privacy","author":"Wang Bolun","year":"2019","unstructured":"Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, B. Viswanath, H. Zheng, and B. Zhao. 2019. Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. Security & Privacy (2019)."},{"key":"e_1_3_2_1_61_1","volume-title":"Quantized Convolutional Neural Networks for Mobile Devices. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Wu Jiaxiang","year":"2016","unstructured":"Jiaxiang Wu, C. Leng, Yuhang Wang, Q. Hu, and Jian Cheng. 2016. Quantized Convolutional Neural Networks for Mobile Devices. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2016), 4820\u20134828."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSII.2020.2973007"},{"key":"e_1_3_2_1_63_1","volume-title":"Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures. USENIX Security","author":"Yan Mengjia","year":"2020","unstructured":"Mengjia Yan, Christopher\u00a0W. Fletcher, and J. Torrellas. 2020. Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures. USENIX Security (2020)."},{"key":"e_1_3_2_1_64_1","volume-title":"MedMNIST Classification Decathlon: A Lightweight AutoML Benchmark for Medical Image Analysis. 2021 IEEE 18th International Symposium on Biomedical Imaging (ISBI)","author":"Yang Jiancheng","year":"2021","unstructured":"Jiancheng Yang, R. Shi, and Bingbing Ni. 2021. MedMNIST Classification Decathlon: A Lightweight AutoML Benchmark for Medical Image Analysis. 2021 IEEE 18th International Symposium on Biomedical Imaging (ISBI) (2021), 191\u2013195."},{"key":"e_1_3_2_1_65_1","volume-title":"USENIX Security Symposium.","author":"Yao Fan","year":"2020","unstructured":"Fan Yao, A.\u00a0S. Rakin, and Deliang Fan. 2020. DeepHammer: Depleting the Intelligence of Deep Neural Networks through Targeted Chain of Bit Flips. In USENIX Security Symposium."},{"key":"e_1_3_2_1_66_1","unstructured":"Yuanshun Yao Huiying Li H. Zheng and B. Zhao. 2019. Latent Backdoor Attacks on Deep Neural Networks. CCS (2019)."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300274"}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485881","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485881","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:14:52Z","timestamp":1755890092000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485881"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":67,"alternative-id":["10.1145\/3485832.3485881","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3485881","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}