{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T16:31:07Z","timestamp":1781022667288,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":83,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["ECCS-1810256 and CMMI-2246672"],"award-info":[{"award-number":["ECCS-1810256 and CMMI-2246672"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690250","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"4435-4449","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Fisher Information guided Purification against Backdoor Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5522-4456","authenticated-orcid":false,"given":"Nazmul","family":"Karim","sequence":"first","affiliation":[{"name":"University of Central Florida, Orlando, Florida, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7017-0158","authenticated-orcid":false,"given":"Abdullah","family":"Al Arafat","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, North Carolina, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5444-8394","authenticated-orcid":false,"given":"Adnan Siraj","family":"Rakin","sequence":"additional","affiliation":[{"name":"Binghamton University (SUNY), Binghamton, New York, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5967-1058","authenticated-orcid":false,"given":"Zhishan","family":"Guo","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, North Carolina, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3434-1359","authenticated-orcid":false,"given":"Nazanin","family":"Rahnavard","sequence":"additional","affiliation":[{"name":"University of Central Florida, Orlando, Florida, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01757"},{"key":"e_1_3_2_1_2_1","volume-title":"Natural gradient works efficiently in learning. Neural computation","author":"Amari Shun-Ichi","year":"1998","unstructured":"Shun-Ichi Amari. 1998. Natural gradient works efficiently in learning. Neural computation, Vol. 10, 2 (1998), 251--276."},{"key":"e_1_3_2_1_3_1","volume-title":"Neural machine translation by jointly learning to align and translate. arXiv preprint arXiv:1409.0473","author":"Bahdanau Dzmitry","year":"2014","unstructured":"Dzmitry Bahdanau, Kyunghyun Cho, and Yoshua Bengio. 2014. Neural machine translation by jointly learning to align and translate. arXiv preprint arXiv:1409.0473 (2014)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"e_1_3_2_1_5_1","volume-title":"Geometric nonlinear functional analysis","author":"Benyamini Yoav","unstructured":"Yoav Benyamini and Joram Lindenstrauss. 1998. Geometric nonlinear functional analysis. Vol. 48. American Mathematical Soc."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/W14-3302"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9414862"},{"key":"e_1_3_2_1_8_1","volume-title":"Convex optimization","author":"Boyd Stephen P","unstructured":"Stephen P Boyd and Lieven Vandenberghe. 2004. Convex optimization. Cambridge university press."},{"key":"e_1_3_2_1_9_1","volume-title":"One-shot Neural Backdoor Erasing via Adversarial Weight Masking. arXiv preprint arXiv:2207.04497","author":"Chai Shuwen","year":"2022","unstructured":"Shuwen Chai and Jinghui Chen. 2022. One-shot Neural Backdoor Erasing via Adversarial Weight Masking. arXiv preprint arXiv:2207.04497 (2022)."},{"key":"e_1_3_2_1_10_1","volume-title":"Clean-image Backdoor: Attacking Multi-label Models with Poisoned Labels Only. In The Eleventh International Conference on Learning Representations.","author":"Chen Kangjie","year":"2023","unstructured":"Kangjie Chen, Xiaoxuan Lou, Guowen Xu, Jiwei Li, and Tianwei Zhang. 2023. Clean-image Backdoor: Attacking Multi-label Models with Poisoned Labels Only. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_11_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"e_1_3_2_1_13_1","volume-title":"international conference on machine learning. PMLR, 1310--1320","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. In international conference on machine learning. PMLR, 1310--1320."},{"key":"e_1_3_2_1_14_1","volume-title":"Imagenet: A large-scale hierarchical image database","author":"Deng Jia","year":"2009","unstructured":"Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009. Imagenet: A large-scale hierarchical image database. In CVPR. IEEE, 248--255."},{"key":"e_1_3_2_1_15_1","volume-title":"International Conference on Machine Learning. PMLR, 1596--1606","author":"Diakonikolas Ilias","year":"2019","unstructured":"Ilias Diakonikolas, Gautam Kamath, Daniel Kane, Jerry Li, Jacob Steinhardt, and Alistair Stewart. 2019. Sever: A robust meta-algorithm for stochastic optimization. In International Conference on Machine Learning. PMLR, 1596--1606."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"e_1_3_2_1_18_1","unstructured":"Alexey Dosovitskiy Lucas Beyer Alexander Kolesnikov Dirk Weissenborn Xiaohua Zhai Thomas Unterthiner Mostafa Dehghani Matthias Minderer Georg Heigold Sylvain Gelly et al. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)."},{"key":"e_1_3_2_1_19_1","volume-title":"Robust anomaly detection and backdoor attack detection via differential privacy. arXiv preprint arXiv:1911.07116","author":"Du Min","year":"2019","unstructured":"Min Du, Ruoxi Jia, and Dawn Song. 2019. Robust anomaly detection and backdoor attack detection via differential privacy. arXiv preprint arXiv:1911.07116 (2019)."},{"key":"e_1_3_2_1_20_1","volume-title":"Christopher KI Williams, John Winn, and Andrew Zisserman.","author":"Everingham Mark","year":"2010","unstructured":"Mark Everingham, Luc Van Gool, Christopher KI Williams, John Winn, and Andrew Zisserman. 2010. The pascal visual object classes (voc) challenge. International journal of computer vision, Vol. 88 (2010), 303--338."},{"key":"e_1_3_2_1_21_1","unstructured":"M. Everingham L. Van Gool C. K. I. Williams J. Winn and A. Zisserman. [n. d.]. The PASCAL Visual Object Classes Challenge 2012 (VOC2012) Results. http:\/\/www.pascal-network.org\/challenges\/VOC\/voc2012\/workshop\/index.html."},{"key":"e_1_3_2_1_22_1","volume-title":"Sharpness-aware Minimization for Efficiently Improving Generalization. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=6Tm1mposlrM","author":"Foret Pierre","year":"2021","unstructured":"Pierre Foret, Ariel Kleiner, Hossein Mobahi, and Behnam Neyshabur. 2021. Sharpness-aware Minimization for Efficiently Improving Generalization. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=6Tm1mposlrM"},{"key":"e_1_3_2_1_23_1","volume-title":"International conference on machine learning. PMLR, 1243--1252","author":"Gehring Jonas","year":"2017","unstructured":"Jonas Gehring, Michael Auli, David Grangier, Denis Yarats, and Yann N Dauphin. 2017. Convolutional sequence to sequence learning. In International conference on machine learning. PMLR, 1243--1252."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"e_1_3_2_1_26_1","volume-title":"On the effectiveness of mitigating data poisoning attacks with gradient shaping. arXiv preprint arXiv:2002.11497","author":"Hong Sanghyun","year":"2020","unstructured":"Sanghyun Hong, Varun Chandrasekaran, Yiugitcan Kaya, Tudor Dumitracs, and Nicolas Papernot. 2020. On the effectiveness of mitigating data poisoning attacks with gradient shaping. arXiv preprint arXiv:2002.11497 (2020)."},{"key":"e_1_3_2_1_27_1","volume-title":"Backdoor defense via decoupling the training process. arXiv preprint arXiv:2202.03423","author":"Huang Kunzhe","year":"2022","unstructured":"Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, and Kui Ren. 2022. Backdoor defense via decoupling the training process. arXiv preprint arXiv:2202.03423 (2022)."},{"key":"e_1_3_2_1_28_1","volume-title":"The break-even point on optimization trajectories of deep neural networks. arXiv preprint arXiv:2002.09572","author":"Jastrzebski Stanislaw","year":"2020","unstructured":"Stanislaw Jastrzebski, Maciej Szymczak, Stanislav Fort, Devansh Arpit, Jacek Tabor, Kyunghyun Cho, and Krzysztof Geras. 2020. The break-even point on optimization trajectories of deep neural networks. arXiv preprint arXiv:2002.09572 (2020)."},{"key":"e_1_3_2_1_29_1","volume-title":"Relationship between nonsmoothness in adversarial training, constraints of attacks, and flatness in the input space","author":"Kanai Sekitoshi","year":"2023","unstructured":"Sekitoshi Kanai, Masanori Yamada, Hiroshi Takahashi, Yuki Yamanaka, and Yasutoshi Ida. 2023. Relationship between nonsmoothness in adversarial training, constraints of attacks, and flatness in the input space. IEEE Transactions on Neural Networks and Learning Systems (2023)."},{"key":"e_1_3_2_1_30_1","volume-title":"Augmented Neural Fine-Tuning for Efficient Backdoor Purification. In The 18th European Conference on Computer Vision (ECCV).","author":"Karim Nazmul","year":"2024","unstructured":"Nazmul Karim, Abdullah Al Arafat, Umar Khalid, Zhishan Guo, and Nazanin Rahnavard. 2024. Augmented Neural Fine-Tuning for Efficient Backdoor Purification. In The 18th European Conference on Computer Vision (ECCV)."},{"key":"e_1_3_2_1_31_1","volume-title":"International Conference on Learning Representations.","author":"Keskar Nitish Shirish","year":"2017","unstructured":"Nitish Shirish Keskar, Dheevatsa Mudigere, Jorge Nocedal, Mikhail Smelyanskiy, and Ping Tak Peter Tang. 2017. On large-batch training for deep learning: Generalization gap and sharp minima. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_32_1","volume-title":"International conference on machine learning. PMLR","author":"Koh Pang Wei","year":"2017","unstructured":"Pang Wei Koh and Percy Liang. 2017. Understanding black-box predictions via influence functions. In International conference on machine learning. PMLR, 1885--1894."},{"key":"e_1_3_2_1_33_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2011.6126543"},{"key":"e_1_3_2_1_35_1","volume-title":"International Conference on Machine Learning. PMLR, 5905--5914","author":"Kwon Jungmin","year":"2021","unstructured":"Jungmin Kwon, Jeongseop Kim, Hyunseo Park, and In Kwon Choi. 2021. Asam: Adaptive sharpness-aware minimization for scale-invariant learning of deep neural networks. In International Conference on Machine Learning. PMLR, 5905--5914."},{"key":"e_1_3_2_1_36_1","volume-title":"Tiny imagenet visual recognition challenge. CS 231N","author":"Le Ya","year":"2015","unstructured":"Ya Le and Xuan Yang. 2015. Tiny imagenet visual recognition challenge. CS 231N, Vol. 7, 7 (2015), 3."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01618"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"e_1_3_2_1_39_1","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume":"34","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Anti-backdoor learning: Training clean models on poisoned data. Advances in Neural Information Processing Systems, Vol. 34 (2021), 14900--14912.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_40_1","volume-title":"International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=9l0K4OM-oXE","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021 d. Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=9l0K4OM-oXE"},{"key":"e_1_3_2_1_41_1","volume-title":"Reconstructive Neuron Pruning for Backdoor Defense. arXiv preprint arXiv:2305.14876","author":"Li Yige","year":"2023","unstructured":"Yige Li, Xixiang Lyu, Xingjun Ma, Nodens Koren, Lingjuan Lyu, Bo Li, and Yu-Gang Jiang. 2023. Reconstructive Neuron Pruning for Backdoor Defense. arXiv preprint arXiv:2305.14876 (2023)."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Junyu Lin Lei Xu Yingqi Liu and Xiangyu Zhang. 2020. Composite backdoor attack for deep neural network by mixing existing benign features. In CCS. 113--131.","DOI":"10.1145\/3372297.3423362"},{"key":"e_1_3_2_1_43_1","volume-title":"Proceedings, Part V 13","author":"Lin Tsung-Yi","year":"2014","unstructured":"Tsung-Yi Lin, Michael Maire, Serge Belongie, James Hays, Pietro Perona, Deva Ramanan, Piotr Doll\u00e1r, and C Lawrence Zitnick. 2014. Microsoft coco: Common objects in context. In Computer Vision--ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6--12, 2014, Proceedings, Part V 13. Springer, 740--755."},{"key":"e_1_3_2_1_44_1","first-page":"21476","article-title":"On the loss landscape of adversarial training: Identifying challenges and how to overcome them","volume":"33","author":"Liu Chen","year":"2020","unstructured":"Chen Liu, Mathieu Salzmann, Tao Lin, Ryota Tomioka, and Sabine S\u00fcsstrunk. 2020. On the loss landscape of adversarial training: Identifying challenges and how to overcome them. Advances in Neural Information Processing Systems, Vol. 33 (2020), 21476--21487.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_46_1","unstructured":"Yingqi Liu Shiqing Ma Yousra Aafer Wen-Chuan Lee Juan Zhai Weihang Wang and Xiangyu Zhang. 2017. Trojaning attack on neural networks. (2017)."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23415"},{"key":"e_1_3_2_1_50_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_1_51_1","first-page":"20373","article-title":"Excess capacity and backdoor poisoning","volume":"34","author":"Manoj Naren","year":"2021","unstructured":"Naren Manoj and Avrim Blum. 2021. Excess capacity and backdoor poisoning. Advances in Neural Information Processing Systems, Vol. 34 (2021), 20373--20384.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_52_1","volume-title":"WaNet--Imperceptible Warping-based Backdoor Attack. arXiv preprint arXiv:2102.10369","author":"Nguyen Anh","year":"2021","unstructured":"Anh Nguyen and Anh Tran. 2021. WaNet--Imperceptible Warping-based Backdoor Attack. arXiv preprint arXiv:2102.10369 (2021)."},{"key":"e_1_3_2_1_53_1","first-page":"3454","article-title":"Input-aware dynamic backdoor attack","volume":"33","author":"Nguyen Tuan Anh","year":"2020","unstructured":"Tuan Anh Nguyen and Anh Tran. 2020. Input-aware dynamic backdoor attack. Advances in Neural Information Processing Systems, Vol. 33 (2020), 3454--3464.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_54_1","volume-title":"Pointnet: Deep hierarchical feature learning on point sets in a metric space. Advances in neural information processing systems","author":"Qi Charles Ruizhongtai","year":"2017","unstructured":"Charles Ruizhongtai Qi, Li Yi, Hao Su, and Leonidas J Guibas. 2017. Pointnet: Deep hierarchical feature learning on point sets in a metric space. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00012"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01298"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.physd.2019.132306"},{"key":"e_1_3_2_1_59_1","volume-title":"Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014)."},{"key":"e_1_3_2_1_60_1","volume-title":"Certifiable Distributional Robustness with Principled Adversarial Training. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Hk6kPgZA-","author":"Sinha Aman","year":"2018","unstructured":"Aman Sinha, Hongseok Namkoong, and John Duchi. 2018. Certifiable Distributional Robustness with Principled Adversarial Training. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=Hk6kPgZA-"},{"key":"e_1_3_2_1_61_1","volume-title":"Amir Roshan Zamir, and Mubarak Shah","author":"Soomro Khurram","year":"2012","unstructured":"Khurram Soomro, Amir Roshan Zamir, and Mubarak Shah. 2012. UCF101: A dataset of 101 human actions classes from videos in the wild. arXiv preprint arXiv:1212.0402 (2012)."},{"key":"e_1_3_2_1_62_1","volume-title":"The 2011 international joint conference on neural networks","author":"Stallkamp Johannes","unstructured":"Johannes Stallkamp, Marc Schlipsing, Jan Salmen, and Christian Igel. 2011. The German traffic sign recognition benchmark: a multi-class classification competition. In The 2011 international joint conference on neural networks. IEEE, 1453--1460."},{"key":"e_1_3_2_1_63_1","volume-title":"Pang Wei W Koh, and Percy S Liang","author":"Steinhardt Jacob","year":"2017","unstructured":"Jacob Steinhardt, Pang Wei W Koh, and Percy S Liang. 2017. Certified defenses for data poisoning attacks. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25656"},{"key":"e_1_3_2_1_65_1","volume-title":"International conference on machine learning. PMLR, 6105--6114","author":"Tan Mingxing","year":"2019","unstructured":"Mingxing Tan and Quoc Le. 2019. Efficientnet: Rethinking model scaling for convolutional neural networks. In International conference on machine learning. PMLR, 6105--6114."},{"key":"e_1_3_2_1_66_1","volume-title":"Spectral signatures in backdoor attacks. Advances in neural information processing systems","author":"Tran Brandon","year":"2018","unstructured":"Brandon Tran, Jerry Li, and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. Advances in neural information processing systems, Vol. 31 (2018)."},{"key":"e_1_3_2_1_67_1","unstructured":"Alexander Turner Dimitris Tsipras and Aleksander Madry. 2018. Clean-label backdoor attacks. (2018)."},{"key":"e_1_3_2_1_68_1","volume-title":"Attention is all you need. Advances in neural information processing systems","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, \u0141ukasz Kaiser, and Illia Polosukhin. 2017. Attention is all you need. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01465"},{"key":"e_1_3_2_1_71_1","first-page":"10546","article-title":"Backdoorbench: A comprehensive benchmark of backdoor learning","volume":"35","author":"Wu Baoyuan","year":"2022","unstructured":"Baoyuan Wu, Hongrui Chen, Mingda Zhang, Zihao Zhu, Shaokui Wei, Danni Yuan, and Chao Shen. 2022. Backdoorbench: A comprehensive benchmark of backdoor learning. Advances in Neural Information Processing Systems, Vol. 35 (2022), 10546--10559.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_72_1","unstructured":"Dongxian Wu and Yisen Wang. 2021. Adversarial Neuron Pruning Purifies Backdoored Deep Models. In NeurIPS."},{"key":"e_1_3_2_1_73_1","volume-title":"Proceedings of the IEEE conference on computer vision and pattern recognition. 1912--1920","author":"Wu Zhirong","year":"2015","unstructured":"Zhirong Wu, Shuran Song, Aditya Khosla, Fisher Yu, Linguang Zhang, Xiaoou Tang, and Jianxiong Xiao. 2015. 3d shapenets: A deep representation for volumetric shapes. In Proceedings of the IEEE conference on computer vision and pattern recognition. 1912--1920."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00750"},{"key":"e_1_3_2_1_75_1","volume-title":"Adversarial unlearning of backdoors via implicit hypergradient. arXiv preprint arXiv:2110.03735","author":"Zeng Yi","year":"2021","unstructured":"Yi Zeng, Si Chen, Won Park, Z Morley Mao, Ming Jin, and Ruoxi Jia. 2021. Adversarial unlearning of backdoors via implicit hypergradient. arXiv preprint arXiv:2110.03735 (2021)."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464809"},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"crossref","unstructured":"Zaixi Zhang Qi Liu Zhicai Wang Zepu Lu and Qingyong Hu. 2023. Backdoor Defense via Deconfounded Representation Learning. arxiv: 2303.06818 [cs.AI]","DOI":"10.1109\/CVPR52729.2023.01177"},{"key":"e_1_3_2_1_79_1","volume-title":"Karthikeyan Natesan Ramamurthy, and Xue Lin","author":"Zhao Pu","year":"2020","unstructured":"Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin. 2020. Bridging mode connectivity in loss landscapes and adversarial robustness. arXiv preprint arXiv:2005.00060 (2020)."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"e_1_3_2_1_81_1","volume-title":"Proceedings, Part V. Springer, 175--191","author":"Zheng Runkai","year":"2022","unstructured":"Runkai Zheng, Rongjun Tang, Jianze Li, and Li Liu. 2022. Data-free backdoor removal based on channel lipschitzness. In Computer Vision--ECCV 2022: 17th European Conference, Tel Aviv, Israel, October 23--27, 2022, Proceedings, Part V. Springer, 175--191."},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"},{"key":"e_1_3_2_1_83_1","volume-title":"Enhancing Fine-Tuning Based Backdoor Defense with Sharpness-Aware Minimization. arXiv preprint arXiv:2304.11823","author":"Zhu Mingli","year":"2023","unstructured":"Mingli Zhu, Shaokui Wei, Li Shen, Yanbo Fan, and Baoyuan Wu. 2023. Enhancing Fine-Tuning Based Backdoor Defense with Sharpness-Aware Minimization. arXiv preprint arXiv:2304.11823 (2023)."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690250","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690250","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:22:50Z","timestamp":1755843770000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690250"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":83,"alternative-id":["10.1145\/3658644.3690250","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690250","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}