{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T17:07:36Z","timestamp":1777568856993,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":86,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,6]],"date-time":"2024-11-06T00:00:00Z","timestamp":1730851200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"German Fed- eral Ministry of Education and Research (BMBF)","award":["DataChainSec (FKZ 16KIS1700)"],"award-info":[{"award-number":["DataChainSec (FKZ 16KIS1700)"]}]},{"name":"SAP S.E.","award":["DE-2020-021"],"award-info":[{"award-number":["DE-2020-021"]}]},{"name":"Helmholtz Association (HGF)","award":["46.23 Engineering Secure Systems"],"award-info":[{"award-number":["46.23 Engineering Secure Systems"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,11,6]]},"DOI":"10.1145\/3689932.3694763","type":"proceedings-article","created":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T06:24:01Z","timestamp":1732256641000},"page":"77-88","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Adversarially Robust Anti-Backdoor Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0944-8058","authenticated-orcid":false,"given":"Qi","family":"Zhao","sequence":"first","affiliation":[{"name":"KASTEL Security Research Labs, Karlsruhe Institute of Technology (KIT), Karlsruhe, Baden-Wuerttemberg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-1493-9552","authenticated-orcid":false,"given":"Christian","family":"Wressnegger","sequence":"additional","affiliation":[{"name":"KASTEL Security Research Labs, Karlsruhe Institute of Technology (KIT), Karlsruhe, Baden-Wuerttemberg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proc. of the National Conference on Artificial Intelligence (AAAI).","author":"Aniruddha Saha Hamed Pirsiavash","year":"2019","unstructured":"Hamed Pirsiavash Aniruddha Saha, Akshayvarun Subramanya. 2019. Hidden Trigger Backdoor Attacks. In Proc. of the National Conference on Artificial Intelligence (AAAI)."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102717"},{"key":"e_1_3_2_1_3_1","volume-title":"2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML).","author":"Apruzzese G.","unstructured":"G. Apruzzese, H. S. Anderson, S. Dambra, D. Freeman, F. Pierazzi, and K. Roundy. 2023. 'Real Attackers Don't Compute Gradients': Bridging the Gap Between Adversarial ML Research and Practice. In 2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)."},{"key":"e_1_3_2_1_4_1","unstructured":"Eugene Bagdasaryan and Vitaly Shmatikov. 2020. Blind Backdoors in Deep Learning Models. In usenix."},{"key":"e_1_3_2_1_5_1","volume-title":"2019 IEEE International Conference on Image Processing (ICIP).","author":"Barni M.","unstructured":"M. Barni, K. Kallas, and B. Tondi. 2019. A New Backdoor Attack in CNNS by Training Set Corruption Without Label Poisoning. In 2019 IEEE International Conference on Image Processing (ICIP)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"crossref","unstructured":"Nicholas Carlini Matthew Jagielski Christopher A. Choquette-Choo Daniel Paleka Will Pearce Hyrum Anderson Andreas Terzis Kurt Thomas and Florian Tram\u00e8r. 2023. Poisoning Web-Scale Training Datasets is Practical. arxiv: 2302.10149 [cs.CR]","DOI":"10.1109\/SP54263.2024.00179"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_9_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Chai Shuwen","year":"2022","unstructured":"Shuwen Chai and Jinghui Chen. 2022. One-shot Neural Backdoor Erasing via Adversarial Weight Masking. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_10_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Chen Weixin","year":"2022","unstructured":"Weixin Chen, Baoyuan Wu, and Haoqian Wang. 2022. Effective Backdoor Defense by Exploiting Sensitivity of Poisoned Samples. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_11_1","volume-title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. CoRR","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. CoRR, Vol. abs\/1712.05526 (2017)."},{"key":"e_1_3_2_1_12_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Coleman Cody","year":"2020","unstructured":"Cody Coleman, Christopher Yeh, Stephen Mussmann, Baharan Mirzasoleiman, Peter Bailis, Percy Liang, Jure Leskovec, and Matei Zaharia. 2020. Selection via Proxy: Efficient Data Selection for Deep Learning. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_13_1","volume-title":"Proc. of the International Conference on Artificial Intelligence and Statistics (AISTATS).","author":"Croce Francesco","year":"2019","unstructured":"Francesco Croce, Maksym Andriushchenko, and Matthias Hein. 2019. Provable Robustness of ReLU networks via Maximization of Linear Regions. In Proc. of the International Conference on Artificial Intelligence and Statistics (AISTATS)."},{"key":"e_1_3_2_1_14_1","volume-title":"Proc. of the International Conference on Machine Learning (ICML).","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Minimally distorted Adversarial Examples with a Fast Adaptive Boundary Attack. In Proc. of the International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_15_1","volume-title":"Proc. of the International Conference on Machine Learning (ICML).","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In Proc. of the International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_16_1","volume-title":"Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR).","author":"Cubuk Ekin Dogus","unstructured":"Ekin Dogus Cubuk, Barret Zoph, Dandelion Man\u00e9, Vijay Vasudevan, and Quoc V. Le. 2019. AutoAugment: Learning Augmentation Policies from Data. In Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00359"},{"key":"e_1_3_2_1_18_1","volume-title":"Proc. of the Annual Computer Security Applications Conference (ACSAC)","author":"Doan Bao Gia","unstructured":"Bao Gia Doan, Ehsan Abbasnejad, and Damith C. Ranasinghe. 2020. Februus: Input Purification Defense Against Trojan Attacks on Deep Neural Network Systems. In Proc. of the Annual Computer Security Applications Conference (ACSAC) (Austin, TX, USA)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"e_1_3_2_1_20_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Du Min","year":"2020","unstructured":"Min Du, Ruoxi Jia,, and Dawn Song. 2020. Robust Anomaly Detection and Backdoor Attack Detection via Differential Privacy. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_21_1","volume-title":"Proc. of the International Conference on Machine Learning (ICML).","author":"Ducoffe Melanie","year":"2018","unstructured":"Melanie Ducoffe and Frederic Precioso. 2018. Adversarial Active Learning for Deep Networks: a Margin Based Approach. In Proc. of the International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_22_1","volume-title":"Proc. of the International Conference on Intelligent Transportation Systems (ITSC)","author":"Feng Di","year":"2018","unstructured":"Di Feng, Lars Rosenbaum, and Klaus C. J. Dietmayer. 2018. Towards Safe Autonomous Driving: Capture Uncertainty in the Deep Neural Network For Lidar 3D Vehicle Detection. Proc. of the International Conference on Intelligent Transportation Systems (ITSC) (2018), 3266--3273."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00390"},{"key":"e_1_3_2_1_24_1","volume-title":"On the Effectiveness of Adversarial Training Against Backdoor Attacks","author":"Gao Yinghua","year":"2023","unstructured":"Yinghua Gao, Dongxian Wu, Jingfeng Zhang, Guanhao Gan, Shu-Tao Xia, Gang Niu, and Masashi Sugiyama. 2023. On the Effectiveness of Adversarial Training Against Backdoor Attacks. IEEE Transactions on Neural Networks and Learning Systems (2023)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"e_1_3_2_1_26_1","volume-title":"Proc. of the National Conference on Artificial Intelligence (AAAI).","author":"Goldblum Micah","year":"2019","unstructured":"Micah Goldblum, Liam Fowl, Soheil Feizi, and Tom Goldstein. 2019. Adversarially Robust Distillation. In Proc. of the National Conference on Artificial Intelligence (AAAI)."},{"key":"e_1_3_2_1_27_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_28_1","volume-title":"Proceeding of Machine Learning and Computer Security Workshop","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain. Proceeding of Machine Learning and Computer Security Workshop (2017)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01300"},{"key":"e_1_3_2_1_30_1","volume-title":"DeepCore: A Comprehensive Library for\u00a0Coreset Selection in\u00a0Deep Learning","author":"Guo Chengcheng","unstructured":"Chengcheng Guo, Bo Zhao, and Yanbing Bai. 2022. DeepCore: A Comprehensive Library for\u00a0Coreset Selection in\u00a0Deep Learning. In Database and Expert Systems Applications, Christine Strauss, Alfredo Cuzzocrea, Gabriele Kotsis, A. Min Tjoa, and Ismail Khalil (Eds.). Springer International Publishing, Cham, 181--195."},{"key":"e_1_3_2_1_31_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Guo Junfeng","year":"2023","unstructured":"Junfeng Guo, Yiming Li, Xun Chen, Hanqing Guo, Lichao Sun, and Cong Liu. 2023. SCALE-UP: An Efficient Black-box Input-level Backdoor Detection via Analyzing Scaled Prediction Consistency. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_32_1","volume-title":"Proc. of the International Conference on Machine Learning (ICML).","author":"Hayase Jonathan","year":"2021","unstructured":"Jonathan Hayase, Weihao Kong, Raghav Somani, and Sewoong Oh. 2021. SPECTRE: defending against backdoor attacks using robust statistics. In Proc. of the International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_34_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Hendrycks Dan","year":"2020","unstructured":"Dan Hendrycks, Norman Mu, Ekin D. Cubuk, Barret Zoph, Justin Gilmer, and Balaji Lakshminarayanan. 2020. AugMix: A Simple Data Processing Method to Improve Robustness and Uncertainty. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_35_1","volume-title":"Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR).","author":"Huang Gao","unstructured":"Gao Huang, Zhuang Liu, and Laurens van der Maaten. 2017. Densely Connected Convolutional Networks. In Proc. of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR)."},{"key":"e_1_3_2_1_36_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Huang Kunzhe","year":"2022","unstructured":"Kunzhe Huang, Yiming Li, Baoyuan Wu, Zhan Qin, and Kui Ren. 2022. Backdoor Defense via Decoupling the Training Process. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_37_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial Examples Are Not Bugs, They Are Features. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_38_1","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. 2008. CIFAR (Canadian Institute for Advanced Research). http:\/\/www.cs.toronto.edu\/ kriz\/cifar.html"},{"key":"e_1_3_2_1_39_1","volume-title":"Tiny imagenet visual recognition challenge. CS 231N","author":"Le Ya","year":"2015","unstructured":"Ya Le and Xuan Yang. 2015. Tiny imagenet visual recognition challenge. CS 231N (2015)."},{"key":"e_1_3_2_1_40_1","volume-title":"Backdoor learning: A survey","author":"Li Yiming","year":"2022","unstructured":"Yiming Li, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2022. Backdoor learning: A survey. IEEE Transactions on Neural Networks and Learning Systems (2022)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"e_1_3_2_1_42_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Anti-Backdoor Learning: Training Clean Models on Poisoned Data. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_43_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102847"},{"key":"e_1_3_2_1_47_1","volume-title":"The Twelfth International Conference on Learning Representations.","author":"Losch Max","year":"2024","unstructured":"Max Losch, Mohamed Omran, David Stutz, Mario Fritz, and Bernt Schiele. 2024. On Adversarial Training without Perturbing all Examples. In The Twelfth International Conference on Learning Representations."},{"key":"e_1_3_2_1_48_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01963"},{"key":"e_1_3_2_1_51_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS),, H. Larochelle, M. Ranzato, R. Hadsell, M.F. Balcan, and H. Lin (Eds.). 3454--3464","author":"Nguyen Tuan Anh","year":"2020","unstructured":"Tuan Anh Nguyen and Anh Tran. 2020. Input-Aware Dynamic Backdoor Attack. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS),, H. Larochelle, M. Ranzato, R. Hadsell, M.F. Balcan, and H. Lin (Eds.). 3454--3464."},{"key":"e_1_3_2_1_52_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Nguyen Tuan Anh","year":"2021","unstructured":"Tuan Anh Nguyen and Anh Tuan Tran. 2021. WaNet - Imperceptible Warping-based Backdoor Attack. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.1979.4310076"},{"key":"e_1_3_2_1_54_1","volume-title":"Backdoor Secrets Unveiled: Identifying Backdoor Data with Optimized Scaled Prediction Consistency. In The Twelfth International Conference on Learning Representations.","author":"Pal Soumyadeep","year":"2024","unstructured":"Soumyadeep Pal, Yuguang Yao, Ren Wang, Bingquan Shen, and Sijia Liu. 2024. Backdoor Secrets Unveiled: Identifying Backdoor Data with Optimized Scaled Prediction Consistency. In The Twelfth International Conference on Learning Representations."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_56_1","volume-title":"NeurIPS 2022 Workshop.","author":"Park Dongmin","year":"2022","unstructured":"Dongmin Park, Dimitris Papailiopoulos, and Kangwook Lee. 2022. Active Learning is a Strong Baseline for Data Subset Selection. In Has it Trained Yet? NeurIPS 2022 Workshop."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453108"},{"key":"e_1_3_2_1_58_1","volume-title":"Dynamic Backdoor Attacks Against Machine Learning Models. CoRR","author":"Salem Ahmed","year":"2020","unstructured":"Ahmed Salem, Rui Wen, Michael Backes, Shiqing Ma, and Yang Zhang. 2020. Dynamic Backdoor Attacks Against Machine Learning Models. CoRR, Vol. abs\/2003.03675 (2020)."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_2_1_60_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Shafahi Ali","year":"2018","unstructured":"Ali Shafahi, W. Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018. Poison Frogs! Targeted Clean-Label Poisoning Attacks on Neural Networks. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_61_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS),, H. Wallach, H. Larochelle, A. Beygelzimer, F. dtextquotesingle Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.).","author":"Shafahi Ali","year":"2019","unstructured":"Ali Shafahi, Mahyar Najibi, Mohammad Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S Davis, Gavin Taylor, and Tom Goldstein. 2019. Adversarial training for free!. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS),, H. Wallach, H. Larochelle, A. Beygelzimer, F. dtextquotesingle Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.)."},{"key":"e_1_3_2_1_62_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_63_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Souri Hossein","year":"2022","unstructured":"Hossein Souri, Micah Goldblum, Liam Fowl, Rama Chellappa, and Tom Goldstein. 2022. Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"crossref","unstructured":"J. Stallkamp M. Schlipsing J. Salmen and C. Igel. 2012. Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition. Neural Networks (2012).","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_1_65_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing Properties of Neural Networks. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_66_1","volume-title":"Label-Consistent Backdoor Attacks. arxiv","author":"Turner Alexander","year":"1912","unstructured":"Alexander Turner, Dimitris Tsipras, and Aleksander Madry. 2019. Label-Consistent Backdoor Attacks. arxiv: 1912.02771"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2022.3159784"},{"key":"e_1_3_2_1_68_1","volume-title":"Bhargava","author":"Villarreal-Vasquez Miguel","year":"2020","unstructured":"Miguel Villarreal-Vasquez and Bharat K. Bhargava. 2020. ConFoc: Content-Focus Protection Against Trojan Attacks on Neural Networks. ArXiv (2020)."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103433"},{"key":"e_1_3_2_1_70_1","volume-title":"Proc. of the IEEE Symposium on Security and Privacy.","author":"Wang Bolun","unstructured":"Bolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao. 2019. Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks. In Proc. of the IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00041"},{"key":"e_1_3_2_1_72_1","unstructured":"Zhenting Wang Kai Mei Hailun Ding Juan Zhai and Shiqing Ma. 2022. Rethinking the Reverse-engineering of Trojan Triggers. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_1_73_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Wang Zhenting","year":"2023","unstructured":"Zhenting Wang, Kai Mei, Juan Zhai, and Shiqing Ma. 2023. UNICORN: A Unified Backdoor Trigger Inversion Framework. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_74_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Weng Cheng-Hsin","year":"2021","unstructured":"Cheng-Hsin Weng, Yan-Ting Lee, and Shan-Hung (Brandon) Wu. 2021. On the Trade-off between Adversarial and Backdoor Robustness. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_75_1","volume-title":"Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS).","author":"Wu Dongxian","year":"2021","unstructured":"Dongxian Wu and Yisen Wang. 2021. Adversarial Neuron Pruning Purifies Backdoored Deep Models. In Proc. of the Annual Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_76_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Xiao Chaowei","year":"2018","unstructured":"Chaowei Xiao, Jun-Yan Zhu, Bo Li, Warren He, Mingyan Liu, and Dawn Song. 2018. Spatially Transformed Adversarial Examples. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_77_1","volume-title":"Adversarial Examples for Semantic Segmentation and Object Detection. In International Conference on Computer Vision.","author":"Xie Cihang","year":"2017","unstructured":"Cihang Xie, Jianyu Wang, Zhishuai Zhang, Yuyin Zhou, Lingxi Xie, and Alan Yuille. 2017. Adversarial Examples for Semantic Segmentation and Object Detection. In International Conference on Computer Vision."},{"key":"e_1_3_2_1_78_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Zeng Yi","year":"2021","unstructured":"Yi Zeng, Si Chen, Won Park, Zhuoqing Mao, Ming Jin, and Ruoxi Jia. 2021. Adversarial Unlearning of Backdoors via Implicit Hypergradient. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_79_1","volume-title":"Proc. of the International Conference on Machine Learning (ICML).","author":"Zhang Hongyang","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric P. Xing, Laurent El Ghaoui, and Michael I. Jordan. 2019. Theoretically Principled Trade-off between Robustness and Accuracy. In Proc. of the International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_1_80_1","unstructured":"Jingfeng Zhang Xilie Xu Bo Han Gang Niu Lizhen Cui Masashi Sugiyama and Mohan Kankanhalli. 2020. Attacks Which Do Not Kill Training Make Adversarial Learning Stronger. In ICML."},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01177"},{"key":"e_1_3_2_1_82_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Zhao Pu","year":"2020","unstructured":"Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin. 2020. Bridging Mode Connectivity in Loss Landscapes and Adversarial Robustness. In Proc. of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_83_1","volume-title":"Proc. of the IEEE\/CVF International Conference on Computer Vision (ICCV).","author":"Zhao Shihao","year":"2023","unstructured":"Shihao Zhao, Xingjun Ma, Xiang Zheng, James Bailey, Jingjing Chen, and Yu-Gang Jiang. 2023. Clean-Label Backdoor Attacks on Video Recognition Models. In Proc. of the IEEE\/CVF International Conference on Computer Vision (ICCV)."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_11"},{"key":"e_1_3_2_1_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00021"},{"key":"e_1_3_2_1_86_1","volume-title":"Proc. of the International Conference on Learning Representations (ICLR).","author":"Zhu Zihao","year":"2024","unstructured":"Zihao Zhu, Mingda Zhang, Shaokui Wei, Bingzhe Wu, and Baoyuan Wu. 2024. VDC: Versatile Data Cleanser based on Visual-Linguistic Inconsistency by Multimodal Large Language Models. In Proc. of the International Conference on Learning Representations (ICLR)."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689932.3694763","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689932.3694763","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T02:08:51Z","timestamp":1755914931000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689932.3694763"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,6]]},"references-count":86,"alternative-id":["10.1145\/3689932.3694763","10.1145\/3689932"],"URL":"https:\/\/doi.org\/10.1145\/3689932.3694763","relation":{},"subject":[],"published":{"date-parts":[[2024,11,6]]},"assertion":[{"value":"2024-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}