{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:40:27Z","timestamp":1755823227000,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,21]],"date-time":"2024-11-21T00:00:00Z","timestamp":1732147200000},"content-version":"vor","delay-in-days":372,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-20-1-0074"],"award-info":[{"award-number":["FA9550-20-1-0074"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"name":"AFOSR","award":["FA9550-23-1-0208"],"award-info":[{"award-number":["FA9550-23-1-0208"]}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2153136"],"award-info":[{"award-number":["CNS-2153136"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-23-1-2386"],"award-info":[{"award-number":["N00014-23-1-2386"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623082","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"2232-2246","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["MDTD: A Multi-Domain Trojan Detector for Deep Neural Networks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9050-0129","authenticated-orcid":false,"given":"Arezoo","family":"Rajabi","sequence":"first","affiliation":[{"name":"University of Washington, Seattle, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8559-241X","authenticated-orcid":false,"given":"Surudhi","family":"Asokraj","sequence":"additional","affiliation":[{"name":"University of Washington, Seattle, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-9077-2399","authenticated-orcid":false,"given":"Fengqing","family":"Jiang","sequence":"additional","affiliation":[{"name":"University of Washington, Seattle, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8591-5522","authenticated-orcid":false,"given":"Luyao","family":"Niu","sequence":"additional","affiliation":[{"name":"University of Washington, Seattle, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2166-7838","authenticated-orcid":false,"given":"Bhaskar","family":"Ramasubramanian","sequence":"additional","affiliation":[{"name":"Western Washington University, Bellingham, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6951-5083","authenticated-orcid":false,"given":"James","family":"Ritcey","sequence":"additional","affiliation":[{"name":"University of Washington, Seattle, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0269-8097","authenticated-orcid":false,"given":"Radha","family":"Poovendran","sequence":"additional","affiliation":[{"name":"University of Washington, Seattle, WA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"2018. Amazon Machine learning at AWS. (2018)."},{"key":"e_1_3_2_2_2_1","unstructured":"2018. BigML Inc. Bigml. (2018)."},{"key":"e_1_3_2_2_3_1","unstructured":"2018. Caffe Caffe Model Zoo. (2018)."},{"volume-title":"Handbook of Mathematical Functions with Formulas, Graphs, and Mathematical Tables","author":"Abramowitz Milton","key":"e_1_3_2_2_4_1","unstructured":"Milton Abramowitz and Irene A Stegun. 1964. Handbook of Mathematical Functions with Formulas, Graphs, and Mathematical Tables. Vol. 55."},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102277"},{"key":"e_1_3_2_2_6_1","volume-title":"Spinning Language Models: Risks of Propaganda-as-a-Service and Countermeasures. In 2022 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 1532--1532","author":"Bagdasaryan Eugene","year":"2022","unstructured":"Eugene Bagdasaryan and Vitaly Shmatikov. 2022. Spinning Language Models: Risks of Propaganda-as-a-Service and Countermeasures. In 2022 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 1532--1532."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_8_1","volume-title":"SafeAI Workshop at Association for the Advancement of Artificial Intelligence (AAAI)","author":"Chen Bryant","year":"2018","unstructured":"Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. SafeAI Workshop at Association for the Advancement of Artificial Intelligence (AAAI) (2018)."},{"volume-title":"HopSkipJumpAttack: A query-efficient decision-based attack","author":"Chen Jianbo","key":"e_1_3_2_2_9_1","unstructured":"Jianbo Chen, Michael I Jordan, and Martin J Wainwright. 2020. HopSkipJumpAttack: A query-efficient decision-based attack. In IEEE S & P. 1277--1294."},{"key":"e_1_3_2_2_10_1","first-page":"9727","article-title":"Effective backdoor defense by exploiting sensitivity of poisoned samples","volume":"35","author":"Chen Weixin","year":"2022","unstructured":"Weixin Chen, Baoyuan Wu, and Haoqian Wang. 2022. Effective backdoor defense by exploiting sensitivity of poisoned samples. Advances in Neural Information Processing Systems 35 (2022), 9727--9737.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_11_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_2_12_1","volume-title":"International Conference on Machine Learning. PMLR","author":"Choquette-Choo Christopher A","year":"2021","unstructured":"Christopher A Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In International Conference on Machine Learning. PMLR, 1964--1974."},{"key":"e_1_3_2_2_13_1","volume-title":"International Conference on Machine Learning. PMLR, 1310--1320","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. In International Conference on Machine Learning. PMLR, 1310--1320."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"volume-title":"Deep learning","author":"Goodfellow Ian","key":"e_1_3_2_2_16_1","unstructured":"Ian Goodfellow, Yoshua Bengio, and Aaron Courville. 2016. Deep learning. MIT press."},{"key":"e_1_3_2_2_17_1","volume-title":"Int. Conf. on Learning Representations.","author":"Goodfellow Ian J","year":"2015","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. Int. Conf. on Learning Representations. (2015)."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1002\/rob.21918"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-01588-5"},{"key":"e_1_3_2_2_21_1","volume-title":"Representation learning on graphs: Methods and applications. arXiv preprint arXiv:1709.05584","author":"Hamilton William L","year":"2017","unstructured":"William L Hamilton, Rex Ying, and Jure Leskovec. 2017. Representation learning on graphs: Methods and applications. arXiv preprint arXiv:1709.05584 (2017)."},{"key":"e_1_3_2_2_22_1","volume-title":"Detection of Traffic Signs in Real-World Images: The German Traffic Sign Detection Benchmark. In Int. Joint Conf. on Neural Networks.","author":"Houben Sebastian","year":"2013","unstructured":"Sebastian Houben, Johannes Stallkamp, Jan Salmen, Marc Schlipsing, and Christian Igel. 2013. Detection of Traffic Signs in Real-World Images: The German Traffic Sign Detection Benchmark. In Int. Joint Conf. on Neural Networks."},{"key":"e_1_3_2_2_23_1","volume-title":"International Conference on Learning Representations.","author":"Huang Kunzhe","year":"2022","unstructured":"Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, and Kui Ren. 2022. Backdoor Defense via Decoupling the Training Process. In International Conference on Learning Representations."},{"volume-title":"An introduction to statistical learning","author":"James Gareth","key":"e_1_3_2_2_24_1","unstructured":"Gareth James, Daniela Witten, Trevor Hastie, and Robert Tibshirani. 2013. An introduction to statistical learning. Vol. 112. Springer."},{"key":"e_1_3_2_2_25_1","volume-title":"Defending Against Backdoor Attack on Graph Neural Network by Explainability. arXiv preprint arXiv:2209.02902","author":"Jiang Bingchen","year":"2022","unstructured":"Bingchen Jiang and Zhao Li. 2022. Defending Against Backdoor Attack on Graph Neural Network by Explainability. arXiv preprint arXiv:2209.02902 (2022)."},{"key":"e_1_3_2_2_26_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. Technical Report University of Toronto (2009)."},{"volume-title":"Artificial Intelligence Safety and Security","author":"Kurakin Alexey","key":"e_1_3_2_2_27_1","unstructured":"Alexey Kurakin, Ian J Goodfellow, and Samy Bengio. 2018. Adversarial examples in the physical world. In Artificial Intelligence Safety and Security. Chapman and Hall\/CRC, 99--112."},{"key":"e_1_3_2_2_28_1","volume-title":"Weight poisoning attacks on pre-trained models. arXiv preprint arXiv:2004.06660","author":"Kurita Keita","year":"2020","unstructured":"Keita Kurita, Paul Michel, and Graham Neubig. 2020. Weight poisoning attacks on pre-trained models. arXiv preprint arXiv:2004.06660 (2020)."},{"key":"e_1_3_2_2_29_1","article-title":"Robust statistical modeling using the t-distribution","volume":"84","author":"Lange Kenneth L","year":"1989","unstructured":"Kenneth L Lange, Roderick JA Little, and Jeremy MG Taylor. 1989. Robust statistical modeling using the t-distribution. J. Amer. Statist. Assoc. 84, 408 (1989).","journal-title":"J. Amer. Statist. Assoc."},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179303"},{"key":"e_1_3_2_2_31_1","volume-title":"Annual Network and Distributed System Security Symposium (NDSS)","author":"Li Shaofeng","year":"2019","unstructured":"Shaofeng Li, Benjamin Zi Hao Zhao, Jiahao Yu, Minhui Xue, Dali Kaafar, and Haojin Zhu. 2019. Invisible backdoor attacks against deep neural networks. Annual Network and Distributed System Security Symposium (NDSS) (2019)."},{"key":"e_1_3_2_2_32_1","volume-title":"Backdoor Learning: A Survey","author":"Li Yiming","year":"2022","unstructured":"Yiming Li, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2022. Backdoor Learning: A Survey. IEEE Transactions on Neural Networks and Learning Systems (2022), 1--18."},{"key":"e_1_3_2_2_33_1","volume-title":"ROUGE: A package for automatic evaluation of summaries. In Text Summarization Branches Out. 74--81.","author":"Lin Chin-Yew","year":"2004","unstructured":"Chin-Yew Lin. 2004. ROUGE: A package for automatic evaluation of summaries. In Text Summarization Branches Out. 74--81."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_2_36_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. International Conference on Learning Representations (ICLR). (2018)."},{"volume-title":"Probability and Computing: Randomization and Probabilistic Techniques in Algorithms and Data Analysis","author":"Mitzenmacher Michael","key":"e_1_3_2_2_37_1","unstructured":"Michael Mitzenmacher and Eli Upfal. 2017. Probability and Computing: Randomization and Probabilistic Techniques in Algorithms and Data Analysis. Cambridge University Press."},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484796"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.172"},{"key":"e_1_3_2_2_42_1","volume-title":"NIPS Workshop on Deep Learning and Unsupervised Feature Learning","author":"Yuval","year":"2011","unstructured":"Yuval Netzer et al. 2011. Reading digits in natural images with unsupervised feature learning. NIPS Workshop on Deep Learning and Unsupervised Feature Learning (2011)."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICVGIP.2008.47"},{"key":"e_1_3_2_2_44_1","volume-title":"International Conference on Learning Representations.","author":"Qi Xiangyu","year":"2023","unstructured":"Xiangyu Qi, Tinghao Xie, Yiming Li, Saeed Mahloujifar, and Prateek Mittal. 2023. Revisiting the assumption of latent separability for backdoor defenses. In International Conference on Learning Representations."},{"volume-title":"Testing statistical hypotheses","author":"Romano Joseph P","key":"e_1_3_2_2_45_1","unstructured":"Joseph P Romano and EL Lehmann. 2005. Testing statistical hypotheses. Springer."},{"key":"e_1_3_2_2_46_1","volume-title":"International Conference on Machine Learning. PMLR, 9525--9536","author":"Shen Guangyu","year":"2021","unstructured":"Guangyu Shen, Yingqi Liu, Guanhong Tao, Shengwei An, Qiuling Xu, Siyuan Cheng, Shiqing Ma, and Xiangyu Zhang. 2021. Backdoor scanning for deep neural networks through k-arm optimization. In International Conference on Machine Learning. PMLR, 9525--9536."},{"key":"e_1_3_2_2_47_1","volume-title":"A Survey on Backdoor Attack and Defense in Natural Language Processing. arXiv preprint arXiv:2211.11958","author":"Sheng Xuan","year":"2022","unstructured":"Xuan Sheng, Zhaoyang Han, Piji Li, and Xiangmao Chang. 2022. A Survey on Backdoor Attack and Defense in Natural Language Processing. arXiv preprint arXiv:2211.11958 (2022)."},{"volume-title":"Economic control of quality of manufactured product","author":"Shewhart Walter Andrew","key":"e_1_3_2_2_48_1","unstructured":"Walter Andrew Shewhart. 1931. Economic control of quality of manufactured product. Macmillan And Co Ltd, London."},{"key":"e_1_3_2_2_49_1","volume-title":"Sequence to sequence learning with neural networks. Neural Information Processing Systems 27","author":"Sutskever Ilya","year":"2014","unstructured":"Ilya Sutskever, Oriol Vinyals, and Quoc V Le. 2014. Sequence to sequence learning with neural networks. Neural Information Processing Systems 27 (2014)."},{"volume-title":"Model orthogonalization: Class distance hardening in neural networks for better security","author":"Tao Guanhong","key":"e_1_3_2_2_50_1","unstructured":"Guanhong Tao, Yingqi Liu, Guangyu Shen, Qiuling Xu, Shengwei An, Zhuo Zhang, and Xiangyu Zhang. 2022. Model orthogonalization: Class distance hardening in neural networks for better security. In IEEE S & P."},{"key":"e_1_3_2_2_51_1","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. Advances in Neural Information Processing Systems (NeurIPS) 33 (2020), 1633--1645.","journal-title":"Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"e_1_3_2_2_52_1","volume-title":"Spectral signatures in backdoor attacks. Advances in Neural Information Processing Systems 31","author":"Tran Brandon","year":"2018","unstructured":"Brandon Tran, Jerry Li, and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. Advances in Neural Information Processing Systems 31 (2018)."},{"key":"e_1_3_2_2_53_1","article-title":"Visualizing data using t-SNE","volume":"9","author":"der Maaten Laurens Van","year":"2008","unstructured":"Laurens Van der Maaten and Geoffrey Hinton. 2008. Visualizing data using t-SNE. Journal of Machine Learning Research 9, 11 (2008).","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_2_54_1","volume-title":"ConFoc: Content-focus protection against Trojan attacks on neural networks. arXiv:2007.00711","author":"Villarreal-Vasquez Miguel","year":"2020","unstructured":"Miguel Villarreal-Vasquez and Bharat Bhargava. 2020. ConFoc: Content-focus protection against Trojan attacks on neural networks. arXiv:2007.00711 (2020)."},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_2_56_1","volume-title":"Speech commands: A dataset for limited-vocabulary speech recognition. arXiv preprint arXiv:1804.03209","author":"Warden Pete","year":"2018","unstructured":"Pete Warden. 2018. Speech commands: A dataset for limited-vocabulary speech recognition. arXiv preprint arXiv:1804.03209 (2018)."},{"key":"e_1_3_2_2_57_1","unstructured":"Pete Warden. 2019-05-11.. Launching the speech commands dataset. (2019-05-11.). https:\/\/ai.googleblog.com\/2017\/08\/launching-speech-commands-dataset.html"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/669"},{"key":"e_1_3_2_2_59_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Xi Zhaohan","year":"2021","unstructured":"Zhaohan Xi, Ren Pang, Shouling Ji, and Ting Wang. 2021. Graph backdoor. In 30th USENIX Security Symposium (USENIX Security 21). 1523--1540."},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"e_1_3_2_2_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/2783258.2783417"},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41551-018-0305-z"},{"key":"e_1_3_2_2_63_1","doi-asserted-by":"crossref","unstructured":"Sergey Zagoruyko and Nikos Komodakis. 2016. Wide Residual Networks. In BMVC.","DOI":"10.5244\/C.30.87"},{"key":"e_1_3_2_2_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"key":"e_1_3_2_2_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413546"},{"key":"e_1_3_2_2_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3209978.3210080"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Copenhagen Denmark","acronym":"CCS '23"},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623082","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623082","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623082","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:40:15Z","timestamp":1755740415000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623082"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":67,"alternative-id":["10.1145\/3576915.3623082","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623082","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}