{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T04:00:46Z","timestamp":1778904046878,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:00:00Z","timestamp":1665360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"the Guangdong Basic and Applied Basic Research Foundation","award":["2021A1515110027"],"award-info":[{"award-number":["2021A1515110027"]}]},{"name":"the National Natural Science Foundation of China","award":["U20A20177"],"award-info":[{"award-number":["U20A20177"]}]},{"name":"the National Natural Science Foundation of China","award":["62002127"],"award-info":[{"award-number":["62002127"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,10]]},"DOI":"10.1145\/3503161.3548272","type":"proceedings-article","created":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T15:42:46Z","timestamp":1665416566000},"page":"678-686","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":31,"title":["BadHash: Invisible Backdoor Attacks against Deep Hashing with Clean Label"],"prefix":"10.1145","author":[{"given":"Shengshan","family":"Hu","sequence":"first","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ziqi","family":"Zhou","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yechao","family":"Zhang","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Leo Yu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Deakin University, Melbourne, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yifeng","family":"Zheng","sequence":"additional","affiliation":[{"name":"Harbin Institute of Technology, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuanyuan","family":"He","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hai","family":"Jin","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,10,10]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58452-8_36"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIOT.2018.00015"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"e_1_3_2_2_4_1","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV'17)","author":"Cao Zhangjie","unstructured":"Zhangjie Cao , Mingsheng Long , Jianmin Wang , and Philip S. Yu . 2017. Hashnet: Deep learning to hash by continuation . In Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV'17) . 5608--5617. Zhangjie Cao, Mingsheng Long, Jianmin Wang, and Philip S. Yu. 2017. Hashnet: Deep learning to hash by continuation. In Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV'17). 5608--5617."},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.5555\/3524938.3525087"},{"key":"e_1_3_2_2_7_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen , Chang Liu , Bo Li , Kimberly Lu , and Dawn Song . 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 ( 2017 ). Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_2_8_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS'21)","volume":"34","author":"Doan Khoa","year":"2021","unstructured":"Khoa Doan , Yingjie Lao , and Ping Li . 2021 a. Backdoor Attack with Imperceptible Input and Latent Modification . In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS'21) , Vol. 34 . 18944--18957. Khoa Doan, Yingjie Lao, and Ping Li. 2021a. Backdoor Attack with Imperceptible Input and Latent Modification. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS'21), Vol. 34. 18944--18957."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"e_1_3_2_2_10_1","volume-title":"FIBA: Frequency-Injection based Backdoor Attack in Medical Image Analysis. arXiv preprint arXiv:2112.01148","author":"Feng Yu","year":"2021","unstructured":"Yu Feng , Benteng Ma , Jing Zhang , Shanshan Zhao , Yong Xia , and Dacheng Tao . 2021 . FIBA: Frequency-Injection based Backdoor Attack in Medical Image Analysis. arXiv preprint arXiv:2112.01148 (2021). Yu Feng, Benteng Ma, Jing Zhang, Shanshan Zhao, Yong Xia, and Dacheng Tao. 2021. FIBA: Frequency-Injection based Backdoor Attack in Medical Image Analysis. arXiv preprint arXiv:2112.01148 (2021)."},{"key":"e_1_3_2_2_11_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_2_12_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017). Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475396"},{"key":"e_1_3_2_2_14_1","volume-title":"Proceedings of the 5th International Conference on Learning Representations (ICLR'17)","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin , Ian J Goodfellow , and Samy Bengio . 2017 . Adversarial examples in the physical world . In Proceedings of the 5th International Conference on Learning Representations (ICLR'17) . Chapman and Hall\/CRC, 99--112. Alexey Kurakin, Ian J Goodfellow, and Samy Bengio. 2017. Adversarial examples in the physical world. In Proceedings of the 5th International Conference on Learning Representations (ICLR'17). Chapman and Hall\/CRC, 99--112."},{"key":"e_1_3_2_2_15_1","volume-title":"Invisible Backdoor Attack with Sample-Specific Triggers. arXiv preprint arXiv:2012.03816","author":"Li Yuezun","year":"2020","unstructured":"Yuezun Li , Yiming Li , Baoyuan Wu , Longkang Li , Ran He , and Siwei Lyu . 2020. Invisible Backdoor Attack with Sample-Specific Triggers. arXiv preprint arXiv:2012.03816 ( 2020 ). Yuezun Li, Yiming Li, Baoyuan Wu, Longkang Li, Ran He, and Siwei Lyu. 2020. Invisible Backdoor Attack with Sample-Specific Triggers. arXiv preprint arXiv:2012.03816 (2020)."},{"key":"e_1_3_2_2_16_1","volume-title":"Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307","author":"Liao Cong","year":"2018","unstructured":"Cong Liao , Haoti Zhong , Anna Squicciarini , Sencun Zhu , and David Miller . 2018. Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307 ( 2018 ). Cong Liao, Haoti Zhong, Anna Squicciarini, Sencun Zhu, and David Miller. 2018. Backdoor embedding in convolutional neural network models via invisible perturbation. arXiv preprint arXiv:1808.10307 (2018)."},{"key":"e_1_3_2_2_17_1","volume-title":"Proceedings of the 13th European Conference on Computer Vision (ECCV'14)","author":"Lin Tsung-Yi","unstructured":"Tsung-Yi Lin , Michael Maire , Serge Belongie , James Hays , Pietro Perona , Deva Ramanan , Piotr Doll\u00e1r , and C. Lawrence Zitnick . 2014. Microsoft coco: Common objects in context . In Proceedings of the 13th European Conference on Computer Vision (ECCV'14) . 740--755. Tsung-Yi Lin, Michael Maire, Serge Belongie, James Hays, Pietro Perona, Deva Ramanan, Piotr Doll\u00e1r, and C. Lawrence Zitnick. 2014. Microsoft coco: Common objects in context. In Proceedings of the 13th European Conference on Computer Vision (ECCV'14). 740--755."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_2_2_19_1","volume-title":"Conditional generative adversarial nets. arXiv preprint arXiv:1411.1784","author":"Mirza Mehdi","year":"2014","unstructured":"Mehdi Mirza and Simon Osindero . 2014. Conditional generative adversarial nets. arXiv preprint arXiv:1411.1784 ( 2014 ). Mehdi Mirza and Simon Osindero. 2014. Conditional generative adversarial nets. arXiv preprint arXiv:1411.1784 (2014)."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_2_21_1","volume-title":"Hinton","author":"M\u00fcller Rafael","year":"2019","unstructured":"Rafael M\u00fcller , Simon Kornblith , and Geoffrey E . Hinton . 2019 . When does label smoothing help?. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS '19). 4696--4705. Rafael M\u00fcller, Simon Kornblith, and Geoffrey E. Hinton. 2019. When does label smoothing help?. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS'19). 4696--4705."},{"key":"e_1_3_2_2_22_1","volume-title":"WaNet--Imperceptible Warping-based Backdoor Attack. arXiv preprint arXiv:2102.10369","author":"Nguyen Anh","year":"2021","unstructured":"Anh Nguyen and Anh Tran . 2021. WaNet--Imperceptible Warping-based Backdoor Attack. arXiv preprint arXiv:2102.10369 ( 2021 ). Anh Nguyen and Anh Tran. 2021. WaNet--Imperceptible Warping-based Backdoor Attack. arXiv preprint arXiv:2102.10369 (2021)."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488902"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-020-10035-z"},{"key":"e_1_3_2_2_27_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 ( 2013 ). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_2_28_1","volume-title":"Label-consistent backdoor attacks. arXiv preprint arXiv:1912.02771","author":"Turner Alexander","year":"2019","unstructured":"Alexander Turner , Dimitris Tsipras , and Aleksander Madry . 2019. Label-consistent backdoor attacks. arXiv preprint arXiv:1912.02771 ( 2019 ). Alexander Turner, Dimitris Tsipras, and Aleksander Madry. 2019. Label-consistent backdoor attacks. arXiv preprint arXiv:1912.02771 (2019)."},{"key":"e_1_3_2_2_29_1","article-title":"Visualizing data using t-SNE","volume":"9","author":"der Maaten Laurens Van","year":"2008","unstructured":"Laurens Van der Maaten and Geoffrey Hinton . 2008 . Visualizing data using t-SNE . Journal of Machine Learning Research , Vol. 9 , 11 (2008). Laurens Van der Maaten and Geoffrey Hinton. 2008. Visualizing data using t-SNE. Journal of Machine Learning Research, Vol. 9, 11 (2008).","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2699960"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3404835.3463233"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01609"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00197"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2018.2882908"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00315"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"e_1_3_2_2_37_1","volume-title":"Targeted Attack of Deep Hashing via Prototype-supervised Adversarial Networks","author":"Zhang Zheng","year":"2021","unstructured":"Zheng Zhang , Xunguang Wang , Guangming Lu , Fumin Shen , and Lei Zhu . 2021. Targeted Attack of Deep Hashing via Prototype-supervised Adversarial Networks . IEEE Transactions on Multimedia ( 2021 ). Zheng Zhang, Xunguang Wang, Guangming Lu, Fumin Shen, and Lei Zhu. 2021. Targeted Attack of Deep Hashing via Prototype-supervised Adversarial Networks. IEEE Transactions on Multimedia (2021)."},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.5121\/ijcsit.2012.4304"}],"event":{"name":"MM '22: The 30th ACM International Conference on Multimedia","location":"Lisboa Portugal","acronym":"MM '22","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 30th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548272","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3503161.3548272","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:42Z","timestamp":1750186842000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548272"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,10]]},"references-count":40,"alternative-id":["10.1145\/3503161.3548272","10.1145\/3503161"],"URL":"https:\/\/doi.org\/10.1145\/3503161.3548272","relation":{},"subject":[],"published":{"date-parts":[[2022,10,10]]},"assertion":[{"value":"2022-10-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}