{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T04:46:26Z","timestamp":1770353186510,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:00:00Z","timestamp":1667779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Office of Naval Research Young Investigator Award"},{"name":"Army Research Office Young Investigator Prize"},{"name":"Princeton Gordon Y. S. Wu Fellowship"},{"name":"Schmidt DataX award"},{"name":"Princeton E-ffiliates Award"},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1553437, CNS-1704105"],"award-info":[{"award-number":["CNS-1553437, CNS-1704105"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Princeton First Year Fellowship"},{"name":"ARL?s Army Artificial Intelligence Innovation Institute"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,11,11]]},"DOI":"10.1145\/3560830.3563730","type":"proceedings-article","created":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T22:32:41Z","timestamp":1667428361000},"page":"91-102","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":25,"title":["Just Rotate it: Deploying Backdoor Attacks via Rotation Transformation"],"prefix":"10.1145","author":[{"given":"Tong","family":"Wu","sequence":"first","affiliation":[{"name":"Princeton University, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianhao","family":"Wang","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vikash","family":"Sehwag","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saeed","family":"Mahloujifar","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Prateek","family":"Mittal","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, NJ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio , Blaine Nelson , and Pavel Laskov . 2012. Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 ( 2012 ). Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 (2012)."},{"key":"e_1_3_2_1_2_1","volume-title":"YOLOv4: Optimal Speed and Accuracy of Object Detection. ArXiv","author":"Bochkovskiy Alexey","year":"2020","unstructured":"Alexey Bochkovskiy , Chien-Yao Wang , and Hong-Yuan Mark Liao . 2020. YOLOv4: Optimal Speed and Accuracy of Object Detection. ArXiv , Vol. abs\/ 2004 .10934 ( 2020 ). Alexey Bochkovskiy, Chien-Yao Wang, and Hong-Yuan Mark Liao. 2020. YOLOv4: Optimal Speed and Accuracy of Object Detection. ArXiv , Vol. abs\/2004.10934 (2020)."},{"key":"e_1_3_2_1_3_1","volume-title":"Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy Tradeoff. arXiv preprint arXiv:2011.09527","author":"Borgnia Eitan","year":"2020","unstructured":"Eitan Borgnia , Valeriia Cherepanova , Liam Fowl , Amin Ghiasi , Jonas Geiping , Micah Goldblum , Tom Goldstein , and Arjun Gupta . 2020. Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy Tradeoff. arXiv preprint arXiv:2011.09527 ( 2020 ). Eitan Borgnia, Valeriia Cherepanova, Liam Fowl, Amin Ghiasi, Jonas Geiping, Micah Goldblum, Tom Goldstein, and Arjun Gupta. 2020. Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy Tradeoff. arXiv preprint arXiv:2011.09527 (2020)."},{"key":"e_1_3_2_1_4_1","unstructured":"Tom B Brown Benjamin Mann Nick Ryder Melanie Subbiah Jared Kaplan Prafulla Dhariwal Arvind Neelakantan Pranav Shyam Girish Sastry Amanda Askell etal 2020. Language models are few-shot learners. Arxiv (2020).  Tom B Brown Benjamin Mann Nick Ryder Melanie Subbiah Jared Kaplan Prafulla Dhariwal Arvind Neelakantan Pranav Shyam Girish Sastry Amanda Askell et al. 2020. Language models are few-shot learners. Arxiv (2020)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Qiong Cao Li Shen Weidi Xie Omkar M. Parkhi and Andrew Zisserman. 2018. VGGFace2: A dataset for recognising faces across pose and age. arxiv: 1710.08092 [cs.CV]  Qiong Cao Li Shen Weidi Xie Omkar M. Parkhi and Andrew Zisserman. 2018. VGGFace2: A dataset for recognising faces across pose and age. arxiv: 1710.08092 [cs.CV]","DOI":"10.1109\/FG.2018.00020"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_7_1","volume-title":"BadDet: Backdoor Attacks on Object Detection. ArXiv","author":"Chan Shih-Han","year":"2022","unstructured":"Shih-Han Chan , Yinpeng Dong , Junyi Zhu , Xiaolu Zhang , and Jun Zhou . 2022. BadDet: Backdoor Attacks on Object Detection. ArXiv , Vol. abs\/ 2205 .14497 ( 2022 ). Shih-Han Chan, Yinpeng Dong, Junyi Zhu, Xiaolu Zhang, and Jun Zhou. 2022. BadDet: Backdoor Attacks on Object Detection. ArXiv , Vol. abs\/2205.14497 (2022)."},{"key":"e_1_3_2_1_8_1","volume-title":"Detecting backdoor attacks on deep neural networks by activation clustering. Arxiv","author":"Chen Bryant","year":"2018","unstructured":"Bryant Chen , Wilka Carvalho , Nathalie Baracaldo , Heiko Ludwig , Benjamin Edwards , Taesung Lee , Ian Molloy , and Biplav Srivastava . 2018. Detecting backdoor attacks on deep neural networks by activation clustering. Arxiv ( 2018 ). Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. Arxiv (2018)."},{"key":"e_1_3_2_1_9_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. Arxiv","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen , Chang Liu , Bo Li , Kimberly Lu , and Dawn Song . 2017. Targeted backdoor attacks on deep learning systems using data poisoning. Arxiv ( 2017 ). Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. Arxiv (2017)."},{"key":"e_1_3_2_1_10_1","volume-title":"Taylor","author":"Devries Terrance","year":"2017","unstructured":"Terrance Devries and Graham W . Taylor . 2017 . Improved Regularization of Convolutional Neural Networks with Cutout. ArXiv , Vol. abs\/ 1708 .04552 (2017). Terrance Devries and Graham W. Taylor. 2017. Improved Regularization of Convolutional Neural Networks with Cutout. ArXiv , Vol. abs\/1708.04552 (2017)."},{"key":"e_1_3_2_1_11_1","unstructured":"Alexey Dosovitskiy Lucas Beyer Alexander Kolesnikov Dirk Weissenborn Xiaohua Zhai Thomas Unterthiner Mostafa Dehghani Matthias Minderer Georg Heigold Sylvain Gelly etal 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020).  Alexey Dosovitskiy Lucas Beyer Alexander Kolesnikov Dirk Weissenborn Xiaohua Zhai Thomas Unterthiner Mostafa Dehghani Matthias Minderer Georg Heigold Sylvain Gelly et al. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)."},{"key":"e_1_3_2_1_12_1","volume-title":"Exploring the Landscape of Spatial Robustness. In International Conference on Machine Learning. 1802--1811","author":"Engstrom Logan","year":"2019","unstructured":"Logan Engstrom , Brandon Tran , Dimitris Tsipras , Ludwig Schmidt , and Aleksander Madry . 2019 . Exploring the Landscape of Spatial Robustness. In International Conference on Machine Learning. 1802--1811 . Logan Engstrom, Brandon Tran, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry. 2019. Exploring the Landscape of Spatial Robustness. In International Conference on Machine Learning. 1802--1811."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-009-0275-4"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_2_1_15_1","volume-title":"Manitest: Are classifiers really invariant?. In BMVC.","author":"Fawzi Alhussein","year":"2015","unstructured":"Alhussein Fawzi and Pascal Frossard . 2015 . Manitest: Are classifiers really invariant?. In BMVC. Alhussein Fawzi and Pascal Frossard. 2015. Manitest: Are classifiers really invariant?. In BMVC."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"e_1_3_2_1_17_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. Arxiv","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. Arxiv (2017). Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. Arxiv (2017)."},{"key":"e_1_3_2_1_18_1","volume-title":"Check Your Other Door! Establishing Backdoor Attacks in the Frequency Domain. ArXiv","author":"Al Kader Hammoud Hasan Abed","year":"2021","unstructured":"Hasan Abed Al Kader Hammoud and Bernard Ghanem . 2021. Check Your Other Door! Establishing Backdoor Attacks in the Frequency Domain. ArXiv , Vol. abs\/ 2109 .05507 ( 2021 ). Hasan Abed Al Kader Hammoud and Bernard Ghanem. 2021. Check Your Other Door! Establishing Backdoor Attacks in the Frequency Domain. ArXiv , Vol. abs\/2109.05507 (2021)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_20_1","volume-title":"Detection of Traffic Signs in Real-World Images: The German Traffic Sign Detection Benchmark. In International Joint Conference on Neural Networks.","author":"Houben Sebastian","year":"2013","unstructured":"Sebastian Houben , Johannes Stallkamp , Jan Salmen , Marc Schlipsing , and Christian Igel . 2013 . Detection of Traffic Signs in Real-World Images: The German Traffic Sign Detection Benchmark. In International Joint Conference on Neural Networks. Sebastian Houben, Johannes Stallkamp, Jan Salmen, Marc Schlipsing, and Christian Igel. 2013. Detection of Traffic Signs in Real-World Images: The German Traffic Sign Detection Benchmark. In International Joint Conference on Neural Networks."},{"key":"e_1_3_2_1_21_1","volume-title":"Densely Connected Convolutional Networks. 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Huang Gao","year":"2017","unstructured":"Gao Huang , Zhuang Liu , and Kilian Q. Weinberger . 2017 . Densely Connected Convolutional Networks. 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) ( 2017 ), 2261--2269. Gao Huang, Zhuang Liu, and Kilian Q. Weinberger. 2017. Densely Connected Convolutional Networks. 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2017), 2261--2269."},{"key":"e_1_3_2_1_22_1","volume-title":"Geometric Robustness of Deep Networks: Analysis and Improvement. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Kanbak Can","year":"2018","unstructured":"Can Kanbak , Seyed-Mohsen Moosavi-Dezfooli , and Pascal Frossard . 2018 . Geometric Robustness of Deep Networks: Analysis and Improvement. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2018), 4441--4449. Can Kanbak, Seyed-Mohsen Moosavi-Dezfooli, and Pascal Frossard. 2018. Geometric Robustness of Deep Networks: Analysis and Improvement. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2018), 4441--4449."},{"key":"e_1_3_2_1_23_1","volume-title":"Learning Multiple Layers of Features from Tiny Images","author":"Krizhevsky Alex","unstructured":"Alex Krizhevsky . 2012. Learning Multiple Layers of Features from Tiny Images . University of Toronto (2012) . Alex Krizhevsky. 2012. Learning Multiple Layers of Features from Tiny Images. University of Toronto (2012)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/DASA54658.2022.9765252"},{"key":"e_1_3_2_1_25_1","unstructured":"Xinke Li Zhirui Chen Yue Zhao Zekun Tong Yabang Zhao Andrew Lim and Joey Tianyi Zhou. 2021a. PointBA: Towards Backdoor Attacks in 3D Point Cloud. https:\/\/doi.org\/10.48550\/ARXIV.2103.16074    10.48550\/ARXIV.2103.16074\nXinke Li Zhirui Chen Yue Zhao Zekun Tong Yabang Zhao Andrew Lim and Joey Tianyi Zhou. 2021a. PointBA: Towards Backdoor Attacks in 3D Point Cloud. https:\/\/doi.org\/10.48550\/ARXIV.2103.16074"},{"key":"e_1_3_2_1_26_1","volume-title":"Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. ArXiv","author":"Li Yige","year":"2021","unstructured":"Yige Li , Nodens Koren , L. Lyu , Xixiang Lyu , Bo Li , and Xingjun Ma. 2021b. Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. ArXiv , Vol. abs\/ 2101 .05930 ( 2021 ). Yige Li, Nodens Koren, L. Lyu, Xixiang Lyu, Bo Li, and Xingjun Ma. 2021b. Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. ArXiv , Vol. abs\/2101.05930 (2021)."},{"key":"e_1_3_2_1_27_1","volume-title":"Backdoor Learning: A Survey. ArXiv","author":"Li Yiming","year":"2020","unstructured":"Yiming Li , Baoyuan Wu , Yong Jiang , Zhifeng Li , and Shutao Xia . 2020 . Backdoor Learning: A Survey. ArXiv , Vol. abs\/ 2007 .08745 (2020). Yiming Li, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shutao Xia. 2020. Backdoor Learning: A Survey. ArXiv , Vol. abs\/2007.08745 (2020)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"e_1_3_2_1_29_1","unstructured":"Tsung-Yi Lin Michael Maire Serge J. Belongie James Hays Pietro Perona Deva Ramanan Piotr Doll\u00e1r and C. Lawrence Zitnick. 2014. Microsoft COCO: Common Objects in Context. In ECCV.  Tsung-Yi Lin Michael Maire Serge J. Belongie James Hays Pietro Perona Deva Ramanan Piotr Doll\u00e1r and C. Lawrence Zitnick. 2014. Microsoft COCO: Common Objects in Context. In ECCV."},{"key":"e_1_3_2_1_30_1","volume-title":"Berg","author":"Liu W.","year":"2016","unstructured":"W. Liu , Dragomir Anguelov , D. Erhan , Christian Szegedy , Scott E. Reed , Cheng-Yang Fu , and Alexander C . Berg . 2016 . SSD : Single Shot MultiBox Detector. In ECCV. W. Liu, Dragomir Anguelov, D. Erhan, Christian Szegedy, Scott E. Reed, Cheng-Yang Fu, and Alexander C. Berg. 2016. SSD: Single Shot MultiBox Detector. In ECCV."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"e_1_3_2_1_32_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 ( 2017 ). Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_1_33_1","unstructured":"Naren Sarayu Manoj and Avrim Blum. 2021. Excess Capacity and Backdoor Poisoning. arxiv: 2109.00685 [cs.LG]  Naren Sarayu Manoj and Avrim Blum. 2021. Excess Capacity and Backdoor Poisoning. arxiv: 2109.00685 [cs.LG]"},{"key":"e_1_3_2_1_34_1","volume-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot , Patrick McDaniel , and Ian Goodfellow . 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 ( 2016 ). Nicolas Papernot, Patrick McDaniel, and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Omkar M. Parkhi Andrea Vedaldi and Andrew Zisserman. 2015. Deep Face Recognition. In BMVC.  Omkar M. Parkhi Andrea Vedaldi and Andrew Zisserman. 2015. Deep Face Recognition. In BMVC.","DOI":"10.5244\/C.29.41"},{"key":"e_1_3_2_1_36_1","volume-title":"PyTorch: An Imperative Style","author":"Paszke Adam","unstructured":"Adam Paszke , Sam Gross , Francisco Massa , Adam Lerer , James Bradbury , Gregory Chanan , Trevor Killeen , Zeming Lin , Natalia Gimelshein , Luca Antiga , Alban Desmaison , Andreas K\u00f6pf , Edward Yang , Zach DeVito , Martin Raison , Alykhan Tejani , Sasank Chilamkurthy , Benoit Steiner , Lu Fang , Junjie Bai , and Soumith Chintala . 2019. PyTorch: An Imperative Style , High-Performance Deep Learning Library . In NeurIPS. Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, Alban Desmaison, Andreas K\u00f6pf, Edward Yang, Zach DeVito, Martin Raison, Alykhan Tejani, Sasank Chilamkurthy, Benoit Steiner, Lu Fang, Junjie Bai, and Soumith Chintala. 2019. PyTorch: An Imperative Style, High-Performance Deep Learning Library. In NeurIPS."},{"key":"e_1_3_2_1_37_1","volume-title":"Circumventing Backdoor Defenses That Are Based on Latent Separability. ArXiv","author":"Qi Xiangyu","year":"2022","unstructured":"Xiangyu Qi , Ting Xie , Saeed Mahloujifar , and Prateek Mittal . 2022. Circumventing Backdoor Defenses That Are Based on Latent Separability. ArXiv ( 2022 ). Xiangyu Qi, Ting Xie, Saeed Mahloujifar, and Prateek Mittal. 2022. Circumventing Backdoor Defenses That Are Based on Latent Separability. ArXiv (2022)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Olga Russakovsky Jia Deng Hao Su Jonathan Krause Sanjeev Satheesh Sean Ma Zhiheng Huang Andrej Karpathy Aditya Khosla Michael Bernstein etal 2015. Imagenet large scale visual recognition challenge. International journal of computer vision Vol. 115 3 (2015) 211--252.  Olga Russakovsky Jia Deng Hao Su Jonathan Krause Sanjeev Satheesh Sean Ma Zhiheng Huang Andrej Karpathy Aditya Khosla Michael Bernstein et al. 2015. Imagenet large scale visual recognition challenge. International journal of computer vision Vol. 115 3 (2015) 211--252.","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"e_1_3_2_1_42_1","volume-title":"Haitao Zheng, and Ben Y. Zhao.","author":"Shan Shawn","year":"2021","unstructured":"Shawn Shan , Arjun Nitin Bhagoji , Haitao Zheng, and Ben Y. Zhao. 2021 . Traceback of Data Poisoning Attacks in Neural Networks. ArXiv , Vol. abs\/ 2110 .06904 (2021). Shawn Shan, Arjun Nitin Bhagoji, Haitao Zheng, and Ben Y. Zhao. 2021. Traceback of Data Poisoning Attacks in Neural Networks. ArXiv , Vol. abs\/2110.06904 (2021)."},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings of the 23rd ACM SIGSAC Conference on Computer and Communications Security. https:\/\/doi.org\/10","author":"Sharif Mahmood","unstructured":"Mahmood Sharif , Sruti Bhagavatula , Lujo Bauer , and Michael K. Reiter . 2016. Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition . In Proceedings of the 23rd ACM SIGSAC Conference on Computer and Communications Security. https:\/\/doi.org\/10 .1145\/2976749.2978392 10.1145\/2976749.2978392 Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter. 2016. Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. In Proceedings of the 23rd ACM SIGSAC Conference on Computer and Communications Security. https:\/\/doi.org\/10.1145\/2976749.2978392"},{"key":"e_1_3_2_1_44_1","unstructured":"Mingjie Sun Siddhant Agarwal and J Zico Kolter. 2021. Poisoned classifiers are not only backdoored they are fundamentally broken. https:\/\/openreview.net\/forum?id=zsKWh2pRSBK  Mingjie Sun Siddhant Agarwal and J Zico Kolter. 2021. Poisoned classifiers are not only backdoored they are fundamentally broken. https:\/\/openreview.net\/forum?id=zsKWh2pRSBK"},{"key":"e_1_3_2_1_45_1","volume-title":"Intriguing properties of neural networks. CoRR","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , D. Erhan , Ian J. Goodfellow , and Rob Fergus . 2014. Intriguing properties of neural networks. CoRR , Vol. abs\/ 1312 .6199 ( 2014 ). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, D. Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. CoRR , Vol. abs\/1312.6199 (2014)."},{"key":"e_1_3_2_1_46_1","volume-title":"Le","author":"Tan Mingxing","year":"2019","unstructured":"Mingxing Tan and Quoc V . Le . 2019 . EfficientNet: Rethinking Model Scaling for Convolutional Neural Networks . arxiv: 1905.11946 [cs.LG] Mingxing Tan and Quoc V. Le. 2019. EfficientNet: Rethinking Model Scaling for Convolutional Neural Networks. arxiv: 1905.11946 [cs.LG]"},{"key":"e_1_3_2_1_47_1","unstructured":"Brandon Tran Jerry Li and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. In NeurIPS.  Brandon Tran Jerry Li and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. In NeurIPS."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_1_49_1","volume-title":"You Only Learn One Representation: Unified Network for Multiple Tasks. ArXiv","author":"Wang Chien-Yao","year":"2021","unstructured":"Chien-Yao Wang , I- Hau Yeh , and Hongpeng Liao . 2021b. You Only Learn One Representation: Unified Network for Multiple Tasks. ArXiv , Vol. abs\/ 2105 .04206 ( 2021 ). Chien-Yao Wang, I-Hau Yeh, and Hongpeng Liao. 2021b. You Only Learn One Representation: Unified Network for Multiple Tasks. ArXiv , Vol. abs\/2105.04206 (2021)."},{"key":"e_1_3_2_1_50_1","volume-title":"Backdoor Attack through Frequency Domain. ArXiv","author":"Wang Tong","year":"2021","unstructured":"Tong Wang , Yuan Yao , Feng Xu , Shengwei An , Hanghang Tong , and Ting Wang . 2021a. Backdoor Attack through Frequency Domain. ArXiv , Vol. abs\/ 2111 .10991 ( 2021 ). Tong Wang, Yuan Yao, Feng Xu, Shengwei An, Hanghang Tong, and Ting Wang. 2021a. Backdoor Attack through Frequency Domain. ArXiv , Vol. abs\/2111.10991 (2021)."},{"key":"e_1_3_2_1_51_1","volume-title":"Backdoor attacks on facial recognition in the physical world. arXiv preprint arXiv:2006.14580","author":"Wenger Emily","year":"2020","unstructured":"Emily Wenger , Josephine Passananti , Yuanshun Yao , Haitao Zheng , and Ben Y Zhao . 2020. Backdoor attacks on facial recognition in the physical world. arXiv preprint arXiv:2006.14580 ( 2020 ). Emily Wenger, Josephine Passananti, Yuanshun Yao, Haitao Zheng, and Ben Y Zhao. 2020. Backdoor attacks on facial recognition in the physical world. arXiv preprint arXiv:2006.14580 (2020)."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2011.5995566"},{"key":"e_1_3_2_1_53_1","volume-title":"Adversarial Neuron Pruning Purifies Backdoored Deep Models. ArXiv","author":"Wu Dongxian","year":"2021","unstructured":"Dongxian Wu and Yisen Wang . 2021. Adversarial Neuron Pruning Purifies Backdoored Deep Models. ArXiv , Vol. abs\/ 2110 .14430 ( 2021 ). Dongxian Wu and Yisen Wang. 2021. Adversarial Neuron Pruning Purifies Backdoored Deep Models. ArXiv , Vol. abs\/2110.14430 (2021)."},{"key":"e_1_3_2_1_54_1","volume-title":"ObjectSeeker: Certifiably Robust Object Detection against Patch Hiding Attacks via Patch-agnostic Masking. ArXiv","author":"Xiang Chong","year":"1811","unstructured":"Chong Xiang , Alexander Valtchanov , Saeed Mahloujifar , and Prateek Mittal . 2022. ObjectSeeker: Certifiably Robust Object Detection against Patch Hiding Attacks via Patch-agnostic Masking. ArXiv , Vol. abs\/ 2202 .0 1811 (2022). Chong Xiang, Alexander Valtchanov, Saeed Mahloujifar, and Prateek Mittal. 2022. ObjectSeeker: Certifiably Robust Object Detection against Patch Hiding Attacks via Patch-agnostic Masking. ArXiv , Vol. abs\/2202.01811 (2022)."},{"key":"e_1_3_2_1_55_1","volume-title":"Sanghyuk Chun, Junsuk Choe, and Youngjoon Yoo.","author":"Yun Sangdoo","year":"2019","unstructured":"Sangdoo Yun , Dongyoon Han , Seong Joon Oh , Sanghyuk Chun, Junsuk Choe, and Youngjoon Yoo. 2019 . Cutmix : Regularization strategy to train strong classifiers with localizable features. In ICCV. 6023--6032. Sangdoo Yun, Dongyoon Han, Seong Joon Oh, Sanghyuk Chun, Junsuk Choe, and Youngjoon Yoo. 2019. Cutmix: Regularization strategy to train strong classifiers with localizable features. In ICCV. 6023--6032."},{"key":"e_1_3_2_1_56_1","volume-title":"Rethinking the Backdoor Attacks' Triggers: A Frequency Perspective. 2021 IEEE\/CVF International Conference on Computer Vision (ICCV)","author":"Zeng Yi","year":"2021","unstructured":"Yi Zeng , Won Park , Zhuoqing Morley Mao , and R. Jia . 2021 . Rethinking the Backdoor Attacks' Triggers: A Frequency Perspective. 2021 IEEE\/CVF International Conference on Computer Vision (ICCV) ( 2021 ), 16453--16461. Yi Zeng, Won Park, Zhuoqing Morley Mao, and R. Jia. 2021. Rethinking the Backdoor Attacks' Triggers: A Frequency Perspective. 2021 IEEE\/CVF International Conference on Computer Vision (ICCV) (2021), 16453--16461."},{"key":"e_1_3_2_1_57_1","volume-title":"mixup: Beyond empirical risk minimization. arXiv preprint arXiv:1710.09412","author":"Zhang Hongyi","year":"2017","unstructured":"Hongyi Zhang , Moustapha Cisse , Yann N Dauphin , and David Lopez-Paz . 2017. mixup: Beyond empirical risk minimization. arXiv preprint arXiv:1710.09412 ( 2017 ). io Hongyi Zhang, Moustapha Cisse, Yann N Dauphin, and David Lopez-Paz. 2017. mixup: Beyond empirical risk minimization. arXiv preprint arXiv:1710.09412 (2017). io"}],"event":{"name":"CCS '22: 2022 ACM SIGSAC Conference on Computer and Communications Security","location":"Los Angeles CA USA","acronym":"CCS '22","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560830.3563730","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3560830.3563730","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3560830.3563730","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:34Z","timestamp":1750186834000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560830.3563730"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,7]]},"references-count":57,"alternative-id":["10.1145\/3560830.3563730","10.1145\/3560830"],"URL":"https:\/\/doi.org\/10.1145\/3560830.3563730","relation":{},"subject":[],"published":{"date-parts":[[2022,11,7]]},"assertion":[{"value":"2022-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}