{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:40:27Z","timestamp":1755823227309,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":17,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Helmholtz Association (HGF)","award":["46.23 Engineering Secure Systems"],"award-info":[{"award-number":["46.23 Engineering Secure Systems"]}]},{"name":"German Federal Ministry of Education and Research (BMBF)","award":["DataChainSec (FKZ FKZ16KIS1700)"],"award-info":[{"award-number":["DataChainSec (FKZ FKZ16KIS1700)"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3624379","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"3612-3614","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Poster: Fooling XAI with Explanation-Aware Backdoors"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1930-8323","authenticated-orcid":false,"given":"Maximilian","family":"Noppel","sequence":"first","affiliation":[{"name":"Karlsruhe Institute of Technology, Karlsruhe, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-1493-9552","authenticated-orcid":false,"given":"Christian","family":"Wressnegger","sequence":"additional","affiliation":[{"name":"Karlsruhe Institute of Technology, Karlsruhe, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"1505","volume-title":"Proc. of the USENIX Security Symposium","author":"Bagdasaryan E.","year":"2021","unstructured":"E. Bagdasaryan and V. Shmatikov. Blind backdoors in deep learning models. In Proc. of the USENIX Security Symposium, pages 1505--1521, 2021."},{"key":"e_1_3_2_1_2_1","volume-title":"Proc. of the IJCAI Workshop of explainable AI (XAI)","author":"Baniecki H.","year":"2023","unstructured":"H. Baniecki and P. Biecek. Adversarial attacks and defenses in explainable artificial intelligence: A survey. In Proc. of the IJCAI Workshop of explainable AI (XAI), 2023."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"e_1_3_2_1_5_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Dombrowski A.-K.","year":"2019","unstructured":"A.-K. Dombrowski, M. Alber, C. Anders, M. Ackermann, K.-R. M\u00fcller, and P. Kessel. Explanations can be manipulated and geometry is to blame. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS), 2019."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i1.19935"},{"key":"e_1_3_2_1_7_1","first-page":"2921","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)","author":"Heo J.","year":"2019","unstructured":"J. Heo, S. Joo, and T. Moon. Fooling neural network interpretations via adversarial model manipulation. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS), pages 2921--2932, 2019."},{"key":"e_1_3_2_1_8_1","first-page":"13","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Ivankay A.","year":"2022","unstructured":"A. Ivankay, I. Girardi, P. Frossard, and C. Marchiori. Fooling explanations in text classifiers. Proc. of the International Conference on Learning Representations (ICLR), page 13, 2022."},{"key":"e_1_3_2_1_9_1","first-page":"807","volume-title":"Proc. of the International Conference on Machine Learning (ICML)","author":"Nair V.","year":"2010","unstructured":"V. Nair and G. E. Hinton. Rectified linear units improve restricted Boltzmann machines. In Proc. of the International Conference on Machine Learning (ICML), pages 807--814, 2010."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00021"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179308"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-019-01228-7"},{"key":"e_1_3_2_1_15_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR)","author":"Simonyan K.","year":"2015","unstructured":"K. Simonyan and A. Zisserman. Very deep convolutional networks for large-scale image recognition. In Proc. of the International Conference on Learning Representations (ICLR), 2015."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_1_17_1","volume-title":"Proc. of the USENIX Security Symposium","author":"Zhang X.","year":"2020","unstructured":"X. Zhang, N. Wang, H. Shen, S. Ji, X. Luo, and T. Wang. Interpretable deep learning under fire. In Proc. of the USENIX Security Symposium, 2020."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Copenhagen Denmark","acronym":"CCS '23"},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3624379","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3624379","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:51:38Z","timestamp":1755741098000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3624379"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":17,"alternative-id":["10.1145\/3576915.3624379","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3624379","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}