{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T10:04:29Z","timestamp":1764842669712,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:00:00Z","timestamp":1665360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102300, 61960206014, 62121001"],"award-info":[{"award-number":["62102300, 61960206014, 62121001"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,10]]},"DOI":"10.1145\/3503161.3548065","type":"proceedings-article","created":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T15:42:46Z","timestamp":1665416566000},"page":"4291-4299","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":13,"title":["Purifier: Plug-and-play Backdoor Mitigation for Pre-trained Models Via Anomaly Activation Suppression"],"prefix":"10.1145","author":[{"given":"Xiaoyu","family":"Zhang","sequence":"first","affiliation":[{"name":"Xidian University &amp; The State Key Laboratory of Cryptology, Xi' an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yulin","family":"Jin","sequence":"additional","affiliation":[{"name":"Xidian University, Xi' an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tao","family":"Wang","sequence":"additional","affiliation":[{"name":"Xidian University, Xi' an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jian","family":"Lou","sequence":"additional","affiliation":[{"name":"Xidian University, Guangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaofeng","family":"Chen","sequence":"additional","affiliation":[{"name":"Xidian University, Xi' an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,10,10]]},"reference":[{"key":"e_1_3_2_2_1_1","first-page":"1505","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Bagdasaryan Eugene","year":"2021","unstructured":"Eugene Bagdasaryan and Vitaly Shmatikov . Blind backdoors in deep learning models . In 30th USENIX Security Symposium (USENIX Security 21) , pages 1505 -- 1521 , 2021 . Eugene Bagdasaryan and Vitaly Shmatikov. Blind backdoors in deep learning models. In 30th USENIX Security Symposium (USENIX Security 21), pages 1505-- 1521, 2021."},{"key":"e_1_3_2_2_2_1","volume-title":"Improving adversarial robustness via channel-wise activation suppressing. arXiv preprint arXiv:2103.08307","author":"Bai Yang","year":"2021","unstructured":"Yang Bai , Yuyuan Zeng , Yong Jiang , Shu-Tao Xia , Xingjun Ma , and Yisen Wang . Improving adversarial robustness via channel-wise activation suppressing. arXiv preprint arXiv:2103.08307 , 2021 . Yang Bai, Yuyuan Zeng, Yong Jiang, Shu-Tao Xia, Xingjun Ma, and Yisen Wang. Improving adversarial robustness via channel-wise activation suppressing. arXiv preprint arXiv:2103.08307, 2021."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"e_1_3_2_2_4_1","volume-title":"Davide Del Testa","author":"Bojarski Mariusz","year":"2016","unstructured":"Mariusz Bojarski , Davide Del Testa , Daniel Dworakowski, Bernhard Firner , Beat Flepp, Prasoon Goyal, Lawrence D Jackel, Mathew Monfort, Urs Muller, Jiakai Zhang, et al. End to end learning for self-driving cars. arXiv preprint arXiv:1604.07316, 2016 . Mariusz Bojarski, Davide Del Testa, Daniel Dworakowski, Bernhard Firner, Beat Flepp, Prasoon Goyal, Lawrence D Jackel, Mathew Monfort, Urs Muller, Jiakai Zhang, et al. End to end learning for self-driving cars. arXiv preprint arXiv:1604.07316, 2016."},{"key":"e_1_3_2_2_5_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen , Chang Liu , Bo Li , Kimberly Lu , and Dawn Song . Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 , 2017 . Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526, 2017."},{"key":"e_1_3_2_2_6_1","volume-title":"Bert: Pretraining of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin , Ming-Wei Chang , Kenton Lee , and Kristina Toutanova . Bert: Pretraining of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 , 2018 . Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. Bert: Pretraining of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805, 2018."},{"key":"e_1_3_2_2_7_1","volume-title":"Dermatologist-level classification of skin cancer with deep neural networks. nature, 542(7639):115--118","author":"Esteva Andre","year":"2017","unstructured":"Andre Esteva , Brett Kuprel , Roberto A Novoa , Justin Ko , SusanMSwetter, Helen M Blau , and Sebastian Thrun . Dermatologist-level classification of skin cancer with deep neural networks. nature, 542(7639):115--118 , 2017 . Andre Esteva, Brett Kuprel, Roberto A Novoa, Justin Ko, SusanMSwetter, HelenM Blau, and Sebastian Thrun. Dermatologist-level classification of skin cancer with deep neural networks. nature, 542(7639):115--118, 2017."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3412130"},{"key":"e_1_3_2_2_10_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 , 2017 . Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733, 2017."},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_12_1","first-page":"34","article-title":"Training clean models on poisoned data","author":"Li Yige","year":"2021","unstructured":"Yige Li , Xixiang Lyu , Nodens Koren , Lingjuan Lyu , Bo Li , and Xingjun Ma. Anti-backdoor learning : Training clean models on poisoned data . Advances in Neural Information Processing Systems , 34 , 2021 . Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. Anti-backdoor learning: Training clean models on poisoned data. Advances in Neural Information Processing Systems, 34, 2021.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_13_1","volume-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930","author":"Li Yige","year":"2021","unstructured":"Yige Li , Xixiang Lyu , Nodens Koren , Lingjuan Lyu , Bo Li , and Xingjun Ma . Neural attention distillation: Erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930 , 2021 . Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. Neural attention distillation: Erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930, 2021."},{"key":"e_1_3_2_2_14_1","volume-title":"Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307","author":"Liao Cong","year":"2018","unstructured":"Cong Liao , Haoti Zhong , Anna Squicciarini , Sencun Zhu , and David Miller . Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307 , 2018 . Cong Liao, Haoti Zhong, Anna Squicciarini, Sencun Zhu, and David Miller. Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307, 2018."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00773"},{"key":"e_1_3_2_2_16_1","volume-title":"Trojaning attack on neural networks","author":"Liu Yingqi","year":"2017","unstructured":"Yingqi Liu , Shiqing Ma , Yousra Aafer , Wen-Chuan Lee , Juan Zhai , Weihang Wang , and Xiangyu Zhang . Trojaning attack on neural networks . 2017 . Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang. Trojaning attack on neural networks. 2017."},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59016-1_28"},{"key":"e_1_3_2_2_21_1","first-page":"182","volume-title":"European Conference on Computer Vision","author":"Liu Yunfei","year":"2020","unstructured":"Yunfei Liu , Xingjun Ma , James Bailey , and Feng Lu. Reflection backdoor : A natural backdoor attack on deep neural networks . In European Conference on Computer Vision , pages 182 -- 199 . Springer , 2020 . Yunfei Liu, Xingjun Ma, James Bailey, and Feng Lu. Reflection backdoor: A natural backdoor attack on deep neural networks. In European Conference on Computer Vision, pages 182--199. Springer, 2020."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2018.12.015"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2022.3167434"},{"key":"e_1_3_2_2_24_1","volume-title":"Wanet--imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369","author":"Nguyen Anh","year":"2021","unstructured":"Anh Nguyen and Anh Tran . Wanet--imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369 , 2021 . Anh Nguyen and Anh Tran. Wanet--imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369, 2021."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453108"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_2_2_27_1","volume-title":"Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems, 31","author":"Shafahi Ali","year":"2018","unstructured":"Ali Shafahi , W Ronny Huang , Mahyar Najibi , Octavian Suciu , Christoph Studer , Tudor Dumitras , and Tom Goldstein . Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems, 31 , 2018 . Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems, 31, 2018."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3123586"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428437"},{"key":"e_1_3_2_2_30_1","volume-title":"Clean-label backdoor attacks","author":"Turner Alexander","year":"2018","unstructured":"Alexander Turner , Dimitris Tsipras , and Aleksander Madry . Clean-label backdoor attacks . 2018 . Alexander Turner, Dimitris Tsipras, and Aleksander Madry. Clean-label backdoor attacks. 2018."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.87"},{"key":"e_1_3_2_2_32_1","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume":"34","author":"Wu Dongxian","year":"2021","unstructured":"Dongxian Wu and Yisen Wang . Adversarial neuron pruning purifies backdoored deep models . Advances in Neural Information Processing Systems , 34 : 16913 -- 16925 , 2021 . Dongxian Wu and Yisen Wang. Adversarial neuron pruning purifies backdoored deep models. Advances in Neural Information Processing Systems, 34:16913--16925, 2021.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_33_1","volume-title":"30th {USENIX} Security Symposium ({USENIX} Security 21)","author":"Xi Zhaohan","year":"2021","unstructured":"Zhaohan Xi , Ren Pang , Shouling Ji , and Ting Wang . Graph backdoor . In 30th {USENIX} Security Symposium ({USENIX} Security 21) , 2021 . Zhaohan Xi, Ren Pang, Shouling Ji, and Ting Wang. Graph backdoor. In 30th {USENIX} Security Symposium ({USENIX} Security 21), 2021."},{"key":"e_1_3_2_2_34_1","volume-title":"Xlnet: Generalized autoregressive pretraining for language understanding. Advances in neural information processing systems, 32","author":"Yang Zhilin","year":"2019","unstructured":"Zhilin Yang , Zihang Dai , Yiming Yang , Jaime Carbonell , Russ R Salakhutdinov , and Quoc V Le . Xlnet: Generalized autoregressive pretraining for language understanding. Advances in neural information processing systems, 32 , 2019 . Zhilin Yang, Zihang Dai, Yiming Yang, Jaime Carbonell, Russ R Salakhutdinov, and Quoc V Le. Xlnet: Generalized autoregressive pretraining for language understanding. Advances in neural information processing systems, 32, 2019."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238187"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2941244"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.10.010"},{"key":"e_1_3_2_2_39_1","volume-title":"Karthikeyan Natesan Ramamurthy, and Xue Lin. Bridging mode connectivity in loss landscapes and adversarial robustness. arXiv preprint arXiv:2005.00060","author":"Zhao Pu","year":"2020","unstructured":"Pu Zhao , Pin-Yu Chen , Payel Das , Karthikeyan Natesan Ramamurthy, and Xue Lin. Bridging mode connectivity in loss landscapes and adversarial robustness. arXiv preprint arXiv:2005.00060 , 2020 . Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin. Bridging mode connectivity in loss landscapes and adversarial robustness. arXiv preprint arXiv:2005.00060, 2020."},{"key":"e_1_3_2_2_40_1","first-page":"7614","volume-title":"International Conference on Machine Learning","author":"Zhu Chen","year":"2019","unstructured":"Chen Zhu , W Ronny Huang , Hengduo Li , Gavin Taylor , Christoph Studer , and Tom Goldstein . Transferable clean-label poisoning attacks on deep neural nets . In International Conference on Machine Learning , pages 7614 -- 7623 . PMLR, 2019 . Chen Zhu, W Ronny Huang, Hengduo Li, Gavin Taylor, Christoph Studer, and Tom Goldstein. Transferable clean-label poisoning attacks on deep neural nets. In International Conference on Machine Learning, pages 7614--7623. PMLR, 2019."}],"event":{"name":"MM '22: The 30th ACM International Conference on Multimedia","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Lisboa Portugal","acronym":"MM '22"},"container-title":["Proceedings of the 30th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548065","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3503161.3548065","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:02:30Z","timestamp":1750186950000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548065"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,10]]},"references-count":40,"alternative-id":["10.1145\/3503161.3548065","10.1145\/3503161"],"URL":"https:\/\/doi.org\/10.1145\/3503161.3548065","relation":{},"subject":[],"published":{"date-parts":[[2022,10,10]]},"assertion":[{"value":"2022-10-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}