{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:42:47Z","timestamp":1777657367112,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":60,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,26]],"date-time":"2023-10-26T00:00:00Z","timestamp":1698278400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Shanghai Trusted Industry Internet Software Collaborative Innovation Center"},{"name":"Natural Science Foundation of China","award":["62272170"],"award-info":[{"award-number":["62272170"]}]},{"name":"Digital Silk Road Shanghai International Joint Lab of Trustworthy Intelligent Software","award":["22510750100"],"award-info":[{"award-number":["22510750100"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,26]]},"DOI":"10.1145\/3581783.3612415","type":"proceedings-article","created":{"date-parts":[[2023,10,27]],"date-time":"2023-10-27T07:27:40Z","timestamp":1698391660000},"page":"8869-8880","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Model-Contrastive Learning for Backdoor Elimination"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0955-9049","authenticated-orcid":false,"given":"Zhihao","family":"Yue","sequence":"first","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0245-8499","authenticated-orcid":false,"given":"Jun","family":"Xia","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9705-1987","authenticated-orcid":false,"given":"Zhiwei","family":"Ling","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5058-4660","authenticated-orcid":false,"given":"Ming","family":"Hu","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7223-8849","authenticated-orcid":false,"given":"Ting","family":"Wang","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9566-7814","authenticated-orcid":false,"given":"Xian","family":"Wei","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3922-0989","authenticated-orcid":false,"given":"Mingsong","family":"Chen","sequence":"additional","affiliation":[{"name":"East China Normal University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,10,27]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9414862"},{"key":"e_1_3_2_2_3_1","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy (S&P). 39--57","author":"Carlini Nicholas","unstructured":"Nicholas Carlini and David A. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. In Proceedings of the IEEE Symposium on Security and Privacy (S&P). 39--57."},{"key":"e_1_3_2_2_4_1","volume-title":"Proceedings of the International Conference on Machine Learning (ICML). 1597--1607","author":"Chen Ting","year":"2020","unstructured":"Ting Chen, Simon Kornblith, Mohammad Norouzi, and Geoffrey Hinton. 2020a. A simple framework for contrastive learning of visual representations. In Proceedings of the International Conference on Machine Learning (ICML). 1597--1607."},{"key":"e_1_3_2_2_5_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 22243--22255","author":"Chen Ting","year":"2020","unstructured":"Ting Chen, Simon Kornblith, Kevin Swersky, Mohammad Norouzi, and Geoffrey E Hinton. 2020b. Big self-supervised models are strong semi-supervised learners. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 22243--22255."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00068"},{"key":"e_1_3_2_2_7_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 9727--9737","author":"Chen Weixin","year":"2022","unstructured":"Weixin Chen, Baoyuan Wu, and Haoqian Wang. 2022a. Effective Backdoor Defense by Exploiting Sensitivity of Poisoned Samples. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 9727--9737."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01549"},{"key":"e_1_3_2_2_9_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_17"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01617"},{"key":"e_1_3_2_2_12_1","volume-title":"Nature","volume":"542","author":"Esteva Andre","year":"2017","unstructured":"Andre Esteva, Brett Kuprel, Roberto A Novoa, Justin Ko, Susan M Swetter, Helen M Blau, and Sebastian Thrun. 2017. Dermatologist-level classification of skin cancer with deep neural networks. Nature, Vol. 542, 7639 (2017), 115--118."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_2_14_1","volume-title":"Proceedings of the International Conference on Machine Learning (ICML). 4129--4139","author":"Hayase Jonathan","year":"2021","unstructured":"Jonathan Hayase and Weihao Kong. 2021. SPECTRE: Defending against backdoor attacks using robust covariance estimation. In Proceedings of the International Conference on Machine Learning (ICML). 4129--4139."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_17_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR).","author":"Huang Kunzhe","year":"2022","unstructured":"Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, and Kui Ren. 2022. Backdoor Defense via Decoupling the Training Process. In Proceedings of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475171"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.2992393"},{"key":"e_1_3_2_2_20_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. In Citeseer."},{"key":"e_1_3_2_2_21_1","volume-title":"Proceedings of the Advances in Artificial Intelligence, Software and Systems Engineering (AHFE). 521--527","author":"Langstrand Jens-Patrick","year":"2020","unstructured":"Jens-Patrick Langstrand, Hoa Thi Nguyen, and Robert McDonald. 2020. Applying Deep Learning to Solve Alarm Flooding in Digital Nuclear Power Plant Control Rooms. In Proceedings of the Advances in Artificial Intelligence, Software and Systems Engineering (AHFE). 521--527."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01057"},{"key":"e_1_3_2_2_23_1","unstructured":"Yige Li. 2021. Source code. https:\/\/github.com\/bboylyg\/NAD"},{"key":"e_1_3_2_2_24_1","volume-title":"Backdoor learning: A survey","author":"Li Yiming","year":"2022","unstructured":"Yiming Li, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2022. Backdoor learning: A survey. IEEE Transactions on Neural Networks and Learning Systems (TNNLS) (2022), 1--18."},{"key":"e_1_3_2_2_25_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 14900--14912","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021b. Anti-backdoor learning: Training clean models on poisoned data. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 14900--14912."},{"key":"e_1_3_2_2_26_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR).","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021c. Neural attention distillation: Erasing backdoor triggers from deep neural networks. In Proceedings of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796974"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548165"},{"key":"e_1_3_2_2_32_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR).","author":"Micikevicius Paulius","year":"2018","unstructured":"Paulius Micikevicius, Sharan Narang, Jonah Alben, Gregory Diamos, Erich Elsen, David Garcia, Boris Ginsburg, Michael Houston, Oleksii Kuchaiev, Ganesh Venkatesh, et al. 2018. Mixed precision training. In Proceedings of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_33_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR).","author":"Nguyen Tuan Anh","year":"2021","unstructured":"Tuan Anh Nguyen and Anh Tuan Tran. 2021. WaNet - Imperceptible Warping-based Backdoor Attack. In Proceedings of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_2_35_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 8024--8035","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et al. 2019. Pytorch: An imperative style, high-performance deep learning library. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 8024--8035."},{"key":"e_1_3_2_2_36_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 14004--14013","author":"Qiao Ximing","year":"2019","unstructured":"Ximing Qiao, Yukun Yang, and Hai Li. 2019. Defending neural backdoors via generative distribution modeling. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 14004--14013."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.15837\/ijccc.2022.1.4714"},{"key":"e_1_3_2_2_38_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 1849--1857","author":"Sohn Kihyuk","year":"2016","unstructured":"Kihyuk Sohn. 2016. Improved Deep Metric Learning with Multi-class N-pair Loss Objective. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 1849--1857."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3005969"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_2_41_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security). 1541--1558","author":"Tang Di","year":"2021","unstructured":"Di Tang, XiaoFeng Wang, Haixu Tang, and Kehuan Zhang. 2021. Demon in the Variant: Statistical Analysis of DNNs for Robust Backdoor Contamination Detection. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). 1541--1558."},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01301"},{"key":"e_1_3_2_2_43_1","volume-title":"Label-consistent backdoor attacks. arXiv preprint arXiv:1912.02771","author":"Turner Alexander","year":"2019","unstructured":"Alexander Turner, Dimitris Tsipras, and Aleksander Madry. 2019. Label-consistent backdoor attacks. arXiv preprint arXiv:1912.02771 (2019)."},{"key":"e_1_3_2_2_44_1","article-title":"Visualizing data using t-SNE","volume":"9","author":"der Maaten Laurens Van","year":"2008","unstructured":"Laurens Van der Maaten and Geoffrey Hinton. 2008. Visualizing data using t-SNE. Journal of Machine Learning Research (JMLR), Vol. 9, 11 (2008).","journal-title":"Journal of Machine Learning Research (JMLR)"},{"key":"e_1_3_2_2_45_1","unstructured":"Bolun Wang. 2018. Source code. https:\/\/github.com\/bolunwang\/backdoor"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_2_47_1","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 3462--3471","author":"Wang Xiaosong","unstructured":"Xiaosong Wang, Yifan Peng, Le Lu, Zhiyong Lu, Mohammadhadi Bagheri, and Ronald M. Summers. 2017. ChestX-Ray8: Hospital-Scale Chest X-Ray Database and Benchmarks on Weakly-Supervised Classification and Localization of Common Thorax Diseases. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 3462--3471."},{"key":"e_1_3_2_2_48_1","unstructured":"Jiayu Wu Qixiang Zhang and Guoxi Xu. 2017. Tiny imagenet challenge. Technical Report (2017)."},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/206"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3161477"},{"key":"e_1_3_2_2_51_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR).","author":"Xiang Zhen","year":"2022","unstructured":"Zhen Xiang, David J Miller, and George Kesidis. 2022. Post-Training Detection of Backdoor Attacks for Two-Class and Multi-Attack Scenarios. In Proceedings of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"e_1_3_2_2_53_1","unstructured":"Yi Zeng. 2021. Source code. https:\/\/github.com\/YiZeng623\/I-BAU"},{"key":"e_1_3_2_2_54_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR).","author":"Zeng Yi","year":"2022","unstructured":"Yi Zeng, Si Chen, Won Park, Z Morley Mao, Ming Jin, and Ruoxi Jia. 2022. Adversarial Unlearning of Backdoors via Implicit Hypergradient. In Proceedings of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238187"},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548115"},{"key":"e_1_3_2_2_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548065"},{"key":"e_1_3_2_2_59_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 17258--17272","author":"Zheng Songzhu","year":"2021","unstructured":"Songzhu Zheng, Yikai Zhang, Hubert Wagner, Mayank Goswami, and Chao Chen. 2021. Topological Detection of Trojaned Neural Networks. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS). 17258--17272."},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"}],"event":{"name":"MM '23: The 31st ACM International Conference on Multimedia","location":"Ottawa ON Canada","acronym":"MM '23","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 31st ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3581783.3612415","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3581783.3612415","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:02:41Z","timestamp":1755820961000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3581783.3612415"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,26]]},"references-count":60,"alternative-id":["10.1145\/3581783.3612415","10.1145\/3581783"],"URL":"https:\/\/doi.org\/10.1145\/3581783.3612415","relation":{},"subject":[],"published":{"date-parts":[[2023,10,26]]},"assertion":[{"value":"2023-10-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}