{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:45:16Z","timestamp":1784997916963,"version":"3.55.0"},"reference-count":195,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T00:00:00Z","timestamp":1733788800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62272162, 62272150, and 62372121"],"award-info":[{"award-number":["62272162, 62272150, and 62372121"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Cloud Technology Endowed Professorship"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,4,30]]},"abstract":"<jats:p>Since the emergence of security concerns in artificial intelligence (AI), there has been significant attention devoted to the examination of backdoor attacks. Attackers can utilize backdoor attacks to manipulate model predictions, leading to significant potential harm. However, current research on backdoor attacks and defenses in both theoretical and practical fields still has many shortcomings. To systematically analyze these shortcomings and address the lack of comprehensive reviews, this article presents a comprehensive and systematic summary of both backdoor attacks and defenses targeting multi-domain AI models. Simultaneously, based on the design principles and shared characteristics of triggers in different domains and the implementation stages of backdoor defense, this article proposes a new classification method for backdoor attacks and defenses. We use this method to extensively review backdoor attacks in the fields of computer vision and natural language processing, and we also examine the current applications of backdoor attacks in audio recognition, video action recognition, multimodal tasks, time series tasks, generative learning, and reinforcement learning, while critically analyzing the open problems of various backdoor attack techniques and defense strategies. Finally, this article builds upon the analysis of the current state of AI security to further explore potential future research directions for backdoor attacks and defenses.<\/jats:p>","DOI":"10.1145\/3704725","type":"journal-article","created":{"date-parts":[[2024,11,15]],"date-time":"2024-11-15T10:17:58Z","timestamp":1731665878000},"page":"1-35","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":27,"title":["Backdoor Attacks and Defenses Targeting Multi-Domain AI Models: A Comprehensive Review"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7980-9651","authenticated-orcid":false,"given":"Shaobo","family":"Zhang","sequence":"first","affiliation":[{"name":"Hunan University of Science and Technology, Xiangtan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9289-7835","authenticated-orcid":false,"given":"Yimeng","family":"Pan","sequence":"additional","affiliation":[{"name":"Hunan University of Science and Technology, Xiangtan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0236-4513","authenticated-orcid":false,"given":"Qin","family":"Liu","sequence":"additional","affiliation":[{"name":"Hunan University, Changsha, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9697-2108","authenticated-orcid":false,"given":"Zheng","family":"Yan","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xian, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9208-5336","authenticated-orcid":false,"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[{"name":"Department of Information Systems and Cyber Security, The University of Texas at San Antonio, San Antonio, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9875-4182","authenticated-orcid":false,"given":"Guojun","family":"Wang","sequence":"additional","affiliation":[{"name":"Guangzhou University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,10]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"Jacques Bughin. 2018. Marrying artificial intelligence and the sustainable development goals: The global economic impact of AI. https:\/\/www.mckinsey.com\/mgi\/overview\/in-the-news\/marrying-artificial-intelligence-and-thesustainable (Oct. 2018)."},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","unstructured":"Hojjat Aghakhani Dongyu Meng Yu-Xiang Wang Christopher Kruegel and Giovanni Vigna. 2021. Bullseye Polytope: A Scalable Clean-label Poisoning Attack with Improved Transferability. (Mar.2021). DOI:10.1109\/EuroSP51992.2021.00021","DOI":"10.1109\/EuroSP51992.2021.00021"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","unstructured":"William Aiken Hyoungshick Kim and Simon Woo. 2020. Neural Network Laundering: Removing Black-box Backdoor Watermarks from Deep Neural Networks. DOI:10.1016\/j.cose.2021.102277","DOI":"10.1016\/j.cose.2021.102277"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3368754"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/SNAMS53716.2021.9732112"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","unstructured":"Chace Ashcraft and Kiran Karra. 2021. Poisoning Deep Reinforcement Learning Agents with In-distribution Triggers. DOI:10.48550\/arXiv.2106.07798","DOI":"10.48550\/arXiv.2106.07798"},{"key":"e_1_3_1_8_2","first-page":"2255","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921)","author":"Azizi Ahmadreza","year":"2021","unstructured":"Ahmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar, Jiameng Pu, Mobin Javed, Chandan K. Reddy, and Bimal Viswanath. 2021. T-Miner: A generative approach to defend against Trojan attacks on DNN-based text classification. In Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921). 2255\u20132272."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02288"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","unstructured":"Yonatan Belinkov and Yonatan Bisk. 2018. Synthetic and Natural Noise Both Break Neural Machine Translation. DOI:10.48550\/arXiv.1711.02173","DOI":"10.48550\/arXiv.1711.02173"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/MMSP.2019.8901711"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","unstructured":"Hanbo Cai Pengcheng Zhang Hai Dong Yan Xiao and Shunhui Ji. 2022. PBSM: Backdoor Attack against Keyword Spotting Based on Pitch Boosting and Sound Masking. DOI:10.48550\/arXiv.2211.08697","DOI":"10.48550\/arXiv.2211.08697"},{"key":"e_1_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102277"},{"key":"e_1_3_1_14_2","article-title":"Poison attacks against text datasets with conditional adversarially regularized autoencoder","author":"Chan Alvin","year":"2020","unstructured":"Alvin Chan, Yi Tay, Yew-Soon Ong, and Aston Zhang. 2020. Poison attacks against text datasets with conditional adversarially regularized autoencoder. arXiv preprint arXiv:2010.02684 (2020).","journal-title":"arXiv preprint arXiv:2010.02684"},{"key":"e_1_3_1_15_2","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","author":"Chen Bryant","year":"2018","unstructured":"Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018).","journal-title":"arXiv preprint arXiv:1811.03728"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.105"},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/2985308"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","unstructured":"Kangjie Chen Yuxian Meng Xiaofei Sun Shangwei Guo Tianwei Zhang Jiwei Li and Chun Fan. 2021. BadPre: Task-agnostic Backdoor Attacks to Pre-trained NLP Foundation Models. DOI:10.48550\/arXiv.2110.02467","DOI":"10.48550\/arXiv.2110.02467"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00393"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","unstructured":"Xiaoyi Chen Yinpeng Dong Zeyu Sun Shengfang Zhai Qingni Shen and Zhonghai Wu. 2022. Kallima: A Clean-label Framework for Textual Backdoor Attacks. 447\u2013466. DOI:10.1007\/978-3-031-17140-6_22","DOI":"10.1007\/978-3-031-17140-6_22"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","unstructured":"Xinyun Chen Chang Liu Bo Li Kimberly Lu and Dawn Song. 2017. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. DOI:10.48550\/arXiv.1712.05526","DOI":"10.48550\/arXiv.1712.05526"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1049\/ipr2.12325"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485837"},{"key":"e_1_3_1_25_2","unstructured":"Yanjiao Chen Zhicong Zheng and Xueluan Gong. 2022. MARNET: Backdoor Attacks against Value-decomposition Multi-agent Reinforcement Learning. In Proceedings of the Tenth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=-VsGCG_AQ69"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3175616"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00391"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","unstructured":"Jiazhu Dai Chuanshuai Chen and Yufeng Li. 2019. A Backdoor Attack against LSTM-based Text Classification Systems. 138872\u2013138878. DOI:10.1109\/ACCESS.2019.2941376","DOI":"10.1109\/ACCESS.2019.2941376"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00100"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","unstructured":"Bao Gia Doan Minhui Xue Shiqing Ma Ehsan Abbasnejad and Damith C. Ranasinghe. 2022. TnT Attacks! Universal Naturalistic Adversarial Patches against Deep Neural Network Systems. 3816\u20133830. DOI:10.1109\/TIFS.2022.3198857","DOI":"10.1109\/TIFS.2022.3198857"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCB48548.2020.9304875"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30099"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/1974822"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3103064"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.08.123"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3141077"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.naacl-main.214"},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1155\/2019\/1953839"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","unstructured":"Kuofeng Gao Jiawang Bai Baoyuan Wu Mengxi Ya and Shu-Tao Xia. 2024. Imperceptible and Robust Backdoor Attack in 3D Point Cloud. 1267\u20131282. DOI:10.1109\/TIFS.2023.3333687","DOI":"10.1109\/TIFS.2023.3333687"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","unstructured":"Yansong Gao Yeonjae Kim Bao Gia Doan Zhi Zhang Gongxuan Zhang Surya Nepal Damith C. Ranasinghe and Hyoungshick Kim. 2022. Design and Evaluation of a Multi-domain Trojan Detection Method on Deep Neural Networks. 2349\u20132364. DOI:10.1109\/TDSC.2021.3055844","DOI":"10.1109\/TDSC.2021.3055844"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-2012-0460"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","unstructured":"Xueluan Gong Yanjiao Chen Qian Wang Huayang Huang Lingshuo Meng Chao Shen and Qian Zhang. 2021. Defense-resistant Backdoor Attacks against Deep Neural Networks in Outsourced Cloud Environment. 2617\u20132631. DOI:10.1109\/JSAC.2021.3087237","DOI":"10.1109\/JSAC.2021.3087237"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102814"},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","unstructured":"Tianyu Gu Brendan Dolan-Gavitt and Siddharth Garg. 2019. BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain. DOI:10.48550\/arXiv.1708.06733","DOI":"10.48550\/arXiv.1708.06733"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00433"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2021.01.009"},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","unstructured":"Wenbo Guo Lun Wang Xinyu Xing Min Du and Dawn Song. 2019. TABOR: A Highly Accurate Approach to Inspecting and Restoring Trojan Backdoors in AI Systems. DOI:10.48550\/arXiv.1908.01763","DOI":"10.48550\/arXiv.1908.01763"},{"key":"e_1_3_1_52_2","doi-asserted-by":"crossref","unstructured":"Hasan Abed Al Kader Hammoud Shuming Liu Mohammed Alkhrashi Fahad AlBalawi and Bernard Ghanem. 2023. Look Listen and Attack: Backdoor Attacks against Video Action Recognition. arxiv:2301.00986","DOI":"10.1109\/CVPRW63382.2024.00348"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1002\/ett.4142"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","unstructured":"Xuanli He Jun Wang Qiongkai Xu Pasquale Minervini Pontus Stenetorp Benjamin I. P. Rubinstein and Trevor Cohn. 2024. Transferring Troubles: Cross-lingual Transferability of Backdoor Attacks in LLMs with Instruction Tuning. DOI:10.48550\/arXiv.2404.19597","DOI":"10.48550\/arXiv.2404.19597"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","unstructured":"Hai Huang Zhengyu Zhao Michael Backes Yun Shen and Yang Zhang. 2024. Composite Backdoor Attacks against Large Language Models. DOI:10.48550\/arXiv.2310.07676","DOI":"10.48550\/arXiv.2310.07676"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30110"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","unstructured":"Mohit Iyyer John Wieting Kevin Gimpel and Luke Zettlemoyer. 2018. Adversarial Example Generation with Syntactically Controlled Paraphrase Networks. DOI:10.48550\/arXiv.1804.06059","DOI":"10.48550\/arXiv.1804.06059"},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833644"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2021.3111123"},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","unstructured":"Wei Jiang Xiangyu Wen Jinyu Zhan Xupeng Wang Ziwei Song and Chen Bian. 2024. Critical Path-based Backdoor Detection for Deep Neural Networks. 4032\u20134046. DOI:10.1109\/TNNLS.2022.3201586","DOI":"10.1109\/TNNLS.2022.3201586"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","unstructured":"Yujing Jiang Xingjun Ma Sarah Monazam Erfani and James Bailey. 2023. Backdoor Attacks on Time Series: A Generative Approach. 392\u2013403. DOI:10.1109\/SaTML54575.2023.00034","DOI":"10.1109\/SaTML54575.2023.00034"},{"key":"e_1_3_1_62_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2022.118990"},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","unstructured":"Panagiota Kiourti Kacper Wardega Susmit Jha and Wenchao Li. 2019. TrojDRL: Trojan Attacks on Deep Reinforcement Learning Agents. DOI:10.48550\/arXiv.1903.06638","DOI":"10.48550\/arXiv.1903.06638"},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10096332"},{"key":"e_1_3_1_65_2","doi-asserted-by":"publisher","unstructured":"Yehao Kong and Jiliang Zhang. 2019. Adversarial Audio: A New Information Hiding Method and Backdoor for DNN-based Speech Recognition Models. DOI:10.48550\/arXiv.1904.03829","DOI":"10.48550\/arXiv.1904.03829"},{"key":"e_1_3_1_66_2","doi-asserted-by":"publisher","unstructured":"Keita Kurita Paul Michel and Graham Neubig. 2020. Weight Poisoning Attacks on Pre-trained Models. DOI:10.48550\/arXiv.2004.06660","DOI":"10.48550\/arXiv.2004.06660"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3032411"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-021-11135-0"},{"key":"e_1_3_1_69_2","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/2938386"},{"key":"e_1_3_1_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00148"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","unstructured":"Haoran Li Yulin Chen Zihao Zheng Qi Hu Chunkit Chan Heshan Liu and Yangqiu Song. 2024. Backdoor Removal for Generative Large Language Models. DOI:10.48550\/arXiv.2405.07667","DOI":"10.48550\/arXiv.2405.07667"},{"key":"e_1_3_1_72_2","first-page":"9694","volume-title":"Advances in Neural Information Processing Systems","author":"Li Junnan","year":"2021","unstructured":"Junnan Li, Ramprasaath Selvaraju, Akhilesh Gotmare, Shafiq Joty, Caiming Xiong, and Steven Chu Hong Hoi. 2021. Align before fuse: Vision and language representation learning with momentum distillation. In Advances in Neural Information Processing Systems, Vol. 34, M. Ranzato, A. Beygelzimer, Y. Dauphin, P. S. Liang, and J. Wortman Vaughan (Eds.). Curran Associates, Inc., 9694\u20139705."},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","unstructured":"Jiazhao Li Yijin Yang Zhuofeng Wu V. G. Vinod Vydiswaran and Chaowei Xiao. 2023. ChatGPT as an Attack Tool: Stealthy Textual Backdoor Attack via Blackbox Generative Model Trigger. DOI:10.48550\/arXiv.2304.14475","DOI":"10.48550\/arXiv.2304.14475"},{"key":"e_1_3_1_74_2","doi-asserted-by":"publisher","unstructured":"Linyang Li Demin Song Xiaonan Li Jiehang Zeng Ruotian Ma and Xipeng Qiu. 2021. Backdoor Attacks on Pre-trained Models by Layerwise Weight Poisoning. DOI:10.48550\/arXiv.2108.13888","DOI":"10.48550\/arXiv.2108.13888"},{"key":"e_1_3_1_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSCWD49262.2021.9437669"},{"key":"e_1_3_1_76_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484576"},{"key":"e_1_3_1_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01618"},{"key":"e_1_3_1_79_2","doi-asserted-by":"publisher","unstructured":"Yiming Li Yong Jiang Zhifeng Li and Shu-Tao Xia. 2024. Backdoor learning: A survey. IEEE Trans. Neural Netw. Learn. Syst. 35 1 (2024) 5\u201322. DOI:10.1109\/TNNLS.2022.3182979","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"e_1_3_1_80_2","doi-asserted-by":"publisher","unstructured":"Yanzhou Li Tianlin Li Kangjie Chen Jian Zhang Shangqing Liu Wenhan Wang Tianwei Zhang and Yang Liu. 2024. BadEdit: Backdooring Large Language Models by Model Editing. DOI:10.48550\/arXiv.2403.13355","DOI":"10.48550\/arXiv.2403.13355"},{"key":"e_1_3_1_81_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"e_1_3_1_82_2","article-title":"Multi-target backdoor attacks for code pre-trained models","author":"Li Yanzhou","year":"2023","unstructured":"Yanzhou Li, Shangqing Liu, Kangjie Chen, Xiaofei Xie, Tianwei Zhang, and Yang Liu. 2023. Multi-target backdoor attacks for code pre-trained models. arXiv preprint arXiv:2306.08350 (2023).","journal-title":"arXiv preprint arXiv:2306.08350"},{"key":"e_1_3_1_83_2","doi-asserted-by":"publisher","unstructured":"Yiming Li Tongqing Zhai Yong Jiang Zhifeng Li and Shu-Tao Xia. 2021. Backdoor Attack in the Physical World. DOI:10.48550\/arXiv.2104.02361","DOI":"10.48550\/arXiv.2104.02361"},{"key":"e_1_3_1_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2022.3173642"},{"key":"e_1_3_1_85_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"e_1_3_1_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigData52589.2021.9671964"},{"key":"e_1_3_1_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3204283"},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_1_89_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"e_1_3_1_90_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_1_91_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_1_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833579"},{"key":"e_1_3_1_93_2","doi-asserted-by":"publisher","unstructured":"Dong Lu Tianyu Pang Chao Du Qian Liu Xianjun Yang and Min Lin. 2024. Test-time Backdoor Attacks on Multimodal Large Language Models. DOI:10.48550\/arXiv.2402.08577","DOI":"10.48550\/arXiv.2402.08577"},{"key":"e_1_3_1_94_2","doi-asserted-by":"publisher","DOI":"10.32604\/cmc.2022.022748"},{"key":"e_1_3_1_95_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23415"},{"key":"e_1_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/P14-5010"},{"key":"e_1_3_1_97_2","doi-asserted-by":"publisher","DOI":"10.3390\/app122412564"},{"key":"e_1_3_1_98_2","doi-asserted-by":"publisher","unstructured":"Kai Mei Zheng Li Zhenting Wang Yang Zhang and Shiqing Ma. 2023. NOTABLE: Transferable Backdoor Attacks against Prompt-based NLP Models. DOI:10.48550\/arXiv.2305.17826","DOI":"10.48550\/arXiv.2305.17826"},{"key":"e_1_3_1_99_2","doi-asserted-by":"publisher","unstructured":"Anh Nguyen and Anh Tran. 2021. WaNet\u2014Imperceptible Warping-based Backdoor Attack. DOI:10.48550\/arXiv.2102.10369","DOI":"10.48550\/arXiv.2102.10369"},{"key":"e_1_3_1_100_2","first-page":"3454","volume-title":"Advances in Neural Information Processing Systems","author":"Nguyen Tuan Anh","year":"2020","unstructured":"Tuan Anh Nguyen and Anh Tran. 2020. Input-aware dynamic backdoor attack. In Advances in Neural Information Processing Systems, Vol. 33. H. Larochelle, M. Ranzato, R. Hadsell, M. F. Balcan, and H. Lin (Eds.). Curran Associates, Inc., 3454\u20133464."},{"key":"e_1_3_1_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488902"},{"key":"e_1_3_1_102_2","article-title":"Backdoor learning for NLP: Recent advances, challenges, and future research directions","author":"Omar Marwan","year":"2023","unstructured":"Marwan Omar. 2023. Backdoor learning for NLP: Recent advances, challenges, and future research directions. arXiv preprint arXiv:2302.06801 (2023).","journal-title":"arXiv preprint arXiv:2302.06801"},{"key":"e_1_3_1_103_2","first-page":"3611","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922)","author":"Pan Xudong","year":"2022","unstructured":"Xudong Pan, Mi Zhang, Beina Sheng, Jiaming Zhu, and Min Yang. 2022. Hidden trigger backdoor attack on NLP models via linguistic style manipulation. In Proceedings of the 31st USENIX Security Symposium (USENIX Security\u201922). USENIX Association, 3611\u20133628."},{"key":"e_1_3_1_104_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01176"},{"key":"e_1_3_1_105_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417253"},{"key":"e_1_3_1_106_2","doi-asserted-by":"publisher","DOI":"10.1186\/s13635-020-00104-z"},{"key":"e_1_3_1_107_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66415-2_4"},{"key":"e_1_3_1_108_2","doi-asserted-by":"publisher","unstructured":"Danish Pruthi Bhuwan Dhingra and Zachary C. Lipton. 2019. Combating Adversarial Misspellings with Robust Word Recognition. DOI:10.48550\/arXiv.1905.11268","DOI":"10.48550\/arXiv.1905.11268"},{"key":"e_1_3_1_109_2","doi-asserted-by":"publisher","unstructured":"Fanchao Qi Yangyi Chen Mukai Li Yuan Yao Zhiyuan Liu and Maosong Sun. 2021. ONION: A Simple and Effective Defense against Textual Backdoor Attacks. DOI:10.48550\/arXiv.2011.10369","DOI":"10.48550\/arXiv.2011.10369"},{"key":"e_1_3_1_110_2","doi-asserted-by":"publisher","unstructured":"Fanchao Qi Yangyi Chen Xurui Zhang Mukai Li Zhiyuan Liu and Maosong Sun. 2021. Mind the Style of Text! Adversarial and Backdoor Attacks Based on Text Style Transfer. DOI:10.48550\/arXiv.2110.07139","DOI":"10.48550\/arXiv.2110.07139"},{"key":"e_1_3_1_111_2","doi-asserted-by":"publisher","unstructured":"Fanchao Qi Mukai Li Yangyi Chen Zhengyan Zhang Zhiyuan Liu Yasheng Wang and Maosong Sun. 2021. Hidden Killer: Invisible Textual Backdoor Attacks with Syntactic Trigger. DOI:10.48550\/arXiv.2105.12400","DOI":"10.48550\/arXiv.2105.12400"},{"key":"e_1_3_1_112_2","doi-asserted-by":"publisher","unstructured":"Fanchao Qi Yuan Yao Sophia Xu Zhiyuan Liu and Maosong Sun. 2021. Turn the Combination Lock: Learnable Textual Backdoor Attacks via Word Substitution. DOI:10.48550\/arXiv.2106.06361","DOI":"10.48550\/arXiv.2106.06361"},{"key":"e_1_3_1_113_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"e_1_3_1_114_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR56361.2022.9956690"},{"key":"e_1_3_1_115_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17143-7_41"},{"key":"e_1_3_1_116_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_1_117_2","doi-asserted-by":"publisher","unstructured":"Ahmed Salem Yannick Sautter Michael Backes Mathias Humbert and Yang Zhang. 2020. BAAAN: Backdoor Attacks against Autoencoder and GAN-based Machine Learning Models. DOI:10.48550\/arXiv.2010.03007","DOI":"10.48550\/arXiv.2010.03007"},{"key":"e_1_3_1_118_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00049"},{"key":"e_1_3_1_119_2","doi-asserted-by":"publisher","unstructured":"Esha Sarkar Hadjer Benkraouda and Michail Maniatakos. 2020. FaceHack: Triggering Backdoored Facial Recognition Systems Using Facial Characteristics. DOI:10.48550\/arXiv.2006.11623","DOI":"10.48550\/arXiv.2006.11623"},{"key":"e_1_3_1_120_2","first-page":"1559","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921)","author":"Schuster Roei","year":"2021","unstructured":"Roei Schuster, Congzheng Song, Eran Tromer, and Vitaly Shmatikov. 2021. You autocomplete me: Poisoning vulnerabilities in veural code completion. In Proceedings of the 30th USENIX Security Symposium (USENIX Security\u201921). USENIX Association, 1559\u20131575. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/schuster"},{"key":"e_1_3_1_121_2","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","volume":"31","author":"Shafahi Ali","year":"2018","unstructured":"Ali Shafahi, W. Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018. Poison frogs! Targeted clean-label poisoning attacks on neural networks. Advan. Neural Inf. Process. Syst. 31 (2018).","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_1_122_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102433"},{"key":"e_1_3_1_123_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102730"},{"key":"e_1_3_1_124_2","article-title":"Backdoor pre-trained models can transfer to all","author":"Shen Lujia","year":"2021","unstructured":"Lujia Shen, Shouling Ji, Xuhong Zhang, Jinfeng Li, Jing Chen, Jie Shi, Chengfang Fang, Jianwei Yin, and Ting Wang. 2021. Backdoor pre-trained models can transfer to all. arXiv preprint arXiv:2111.00197 (2021).","journal-title":"arXiv preprint arXiv:2111.00197"},{"key":"e_1_3_1_125_2","first-page":"61836","article-title":"On the exploitability of instruction tuning","volume":"36","author":"Shu Manli","year":"2023","unstructured":"Manli Shu, Jiongxiao Wang, Chen Zhu, Jonas Geiping, Chaowei Xiao, and Tom Goldstein. 2023. On the exploitability of instruction tuning. Advan. Neural Inf. Process. Syst. 36 (2023), 61836\u201361856.","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_1_126_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00423"},{"key":"e_1_3_1_127_2","doi-asserted-by":"publisher","unstructured":"Yang Sui Huy Phan Jinqi Xiao Tianfang Zhang Zijie Tang Cong Shi Yan Wang Yingying Chen and Bo Yuan. 2024. DisDet: Exploring Detectability of Backdoor Attack on Diffusion Models. DOI:10.48550\/arXiv.2402.02739","DOI":"10.48550\/arXiv.2402.02739"},{"key":"e_1_3_1_128_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25656"},{"key":"e_1_3_1_129_2","article-title":"Instance-level Trojan attacks on visual question answering via adversarial learning in neuron activation space","author":"Sun Yuwei","year":"2023","unstructured":"Yuwei Sun, Hideya Ochiai, and Jun Sakuma. 2023. Instance-level Trojan attacks on visual question answering via adversarial learning in neuron activation space. arXiv preprint arXiv:2304.00436 (2023).","journal-title":"arXiv preprint arXiv:2304.00436"},{"key":"e_1_3_1_130_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00019"},{"key":"e_1_3_1_131_2","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"e_1_3_1_132_2","doi-asserted-by":"publisher","unstructured":"Guiyu Tian Wenhao Jiang Wei Liu and Yadong Mu. 2021. Poisoning MorphNet for Clean-label Backdoor Attack to Point Clouds. DOI:10.48550\/arXiv.2105.04839","DOI":"10.48550\/arXiv.2105.04839"},{"key":"e_1_3_1_133_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3160359"},{"key":"e_1_3_1_134_2","article-title":"Spectral signatures in backdoor attacks","volume":"31","author":"Tran Brandon","year":"2018","unstructured":"Brandon Tran, Jerry Li, and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. Advan. Neural Inf. Process. Syst. 31 (2018).","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_1_135_2","doi-asserted-by":"publisher","unstructured":"Alexander Turner Dimitris Tsipras and Aleksander Madry. 2019. Label-consistent Backdoor Attacks. DOI:10.48550\/arXiv.1912.02771","DOI":"10.48550\/arXiv.1912.02771"},{"key":"e_1_3_1_136_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2022.3159784"},{"key":"e_1_3_1_137_2","article-title":"Universal adversarial triggers for attacking and analyzing NLP","author":"Wallace Eric","year":"2019","unstructured":"Eric Wallace, Shi Feng, Nikhil Kandpal, Matt Gardner, and Sameer Singh. 2019. Universal adversarial triggers for attacking and analyzing NLP. arXiv preprint arXiv:1908.07125 (2019).","journal-title":"arXiv preprint arXiv:1908.07125"},{"key":"e_1_3_1_138_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01494"},{"key":"e_1_3_1_139_2","first-page":"35413","volume-title":"Proceedings of the 40th International Conference on Machine Learning (Proceedings of Machine Learning Research)","author":"Wan Alexander","year":"2023","unstructured":"Alexander Wan, Eric Wallace, Sheng Shen, and Dan Klein. 2023. Poisoning language models during instruction tuning. In Proceedings of the 40th International Conference on Machine Learning (Proceedings of Machine Learning Research), Vol. 202, Andreas Krause, Emma Brunskill, Kyunghyun Cho, Barbara Engelhardt, Sivan Sabato, and Jonathan Scarlett (Eds.). PMLR, 35413\u201335425."},{"key":"e_1_3_1_140_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_1_141_2","doi-asserted-by":"publisher","unstructured":"Jiongxiao Wang Zichen Liu Keun Hee Park Zhuojun Jiang Zhaoheng Zheng Zhuofeng Wu Muhao Chen and Chaowei Xiao. 2023. Adversarial Demonstration Attacks on Large Language Models. DOI:10.48550\/arXiv.2305.14950","DOI":"10.48550\/arXiv.2305.14950"},{"key":"e_1_3_1_142_2","doi-asserted-by":"publisher","unstructured":"Jun Wang Chang Xu Francisco Guzman Ahmed El-Kishky Yuqing Tang Benjamin I. P. Rubinstein and Trevor Cohn. 2021. Putting Words into the System\u2019s Mouth: A Targeted Attack on Neural Machine Translation Using Monolingual Data Poisoning. DOI:10.48550\/arXiv.2107.05243","DOI":"10.48550\/arXiv.2107.05243"},{"key":"e_1_3_1_143_2","doi-asserted-by":"publisher","unstructured":"Jun Wang Qiongkai Xu Xuanli He Benjamin I. P. Rubinstein and Trevor Cohn. 2024. Backdoor Attack on Multilingual Machine Translation. DOI:10.48550\/arXiv.2404.02393","DOI":"10.48550\/arXiv.2404.02393"},{"key":"e_1_3_1_144_2","doi-asserted-by":"publisher","unstructured":"Lun Wang Zaynah Javed Xian Wu Wenbo Guo Xinyu Xing and Dawn Song. 2021. BACKDOORL: Backdoor Attack against Competitive Reinforcement Learning. DOI:10.48550\/arXiv.2105.00579","DOI":"10.48550\/arXiv.2105.00579"},{"key":"e_1_3_1_145_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3114024"},{"key":"e_1_3_1_146_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3325634"},{"key":"e_1_3_1_147_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3202687"},{"key":"e_1_3_1_148_2","doi-asserted-by":"publisher","DOI":"10.1145\/3477244.3477611"},{"key":"e_1_3_1_149_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"e_1_3_1_150_2","doi-asserted-by":"publisher","unstructured":"Zhen Xiang Fengqing Jiang Zidi Xiong Bhaskar Ramasubramanian Radha Poovendran and Bo Li. 2024. BadChain: Backdoor Chain-of-thought Prompting for Large Language Models. DOI:10.48550\/arXiv.2401.12242","DOI":"10.48550\/arXiv.2401.12242"},{"key":"e_1_3_1_151_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00750"},{"key":"e_1_3_1_152_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP43922.2022.9747194"},{"key":"e_1_3_1_153_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102280"},{"key":"e_1_3_1_154_2","doi-asserted-by":"publisher","DOI":"10.1002\/int.22785"},{"key":"e_1_3_1_155_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Xie Chulin","year":"2019","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2019. DBA: Distributed backdoor attacks against federated learning. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_1_156_2","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450034"},{"key":"e_1_3_1_157_2","doi-asserted-by":"publisher","unstructured":"Jiashu Xu Mingyu Derek Ma Fei Wang Chaowei Xiao and Muhao Chen. 2024. Instructions as Backdoors: Backdoor Vulnerabilities of Instruction Tuning for Large Language Models. DOI:10.48550\/arXiv.2305.14710","DOI":"10.48550\/arXiv.2305.14710"},{"key":"e_1_3_1_158_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.findings-naacl.137"},{"key":"e_1_3_1_159_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2022.3177442"},{"key":"e_1_3_1_160_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"e_1_3_1_161_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-020-01031-z"},{"key":"e_1_3_1_162_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3028448"},{"key":"e_1_3_1_163_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102726"},{"key":"e_1_3_1_164_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2987435"},{"key":"e_1_3_1_165_2","article-title":"Backdoor attacks against voice recognition systems: A survey","author":"Yan Baochen","year":"2023","unstructured":"Baochen Yan, Jiahe Lan, and Zheng Yan. 2023. Backdoor attacks against voice recognition systems: A survey. arXiv preprint arXiv:2307.13643 (2023).","journal-title":"arXiv preprint arXiv:2307.13643"},{"key":"e_1_3_1_166_2","doi-asserted-by":"publisher","unstructured":"Jun Yan Vansh Gupta and Xiang Ren. 2023. BITE: Textual Backdoor Attacks with Iterative Trigger Injection. DOI:10.48550\/arXiv.2205.12700","DOI":"10.48550\/arXiv.2205.12700"},{"key":"e_1_3_1_167_2","doi-asserted-by":"publisher","unstructured":"Wenkai Yang Lei Li Zhiyuan Zhang Xuancheng Ren Xu Sun and Bin He. 2021. Be Careful about Poisoned Word Embeddings: Exploring the Vulnerability of the Embedding Layers in NLP Models. DOI:10.48550\/arXiv.2103.15543","DOI":"10.48550\/arXiv.2103.15543"},{"key":"e_1_3_1_168_2","doi-asserted-by":"publisher","unstructured":"Wenkai Yang Yankai Lin Peng Li Jie Zhou and Xu Sun. 2021. RAP: Robustness-Aware Perturbations for Defending against Backdoor Attacks on NLP Models. DOI:10.48550\/arXiv.2110.07831","DOI":"10.48550\/arXiv.2110.07831"},{"key":"e_1_3_1_169_2","doi-asserted-by":"publisher","unstructured":"Zhou Yang Bowen Xu Jie M. Zhang Hong Jin Kang Jieke Shi Junda He and David Lo. 2024. Stealthy Backdoor Attack for Code Models. 721\u2013741. DOI:10.1109\/TSE.2024.3361661","DOI":"10.1109\/TSE.2024.3361661"},{"key":"e_1_3_1_170_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP48485.2024.10446267"},{"key":"e_1_3_1_171_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"e_1_3_1_172_2","doi-asserted-by":"publisher","DOI":"10.3390\/app12125786"},{"key":"e_1_3_1_173_2","doi-asserted-by":"publisher","unstructured":"Wencong You Zayd Hammoudeh and Daniel Lowd. 2023. Large Language Models Are Better Adversaries: Exploring Generative Clean-label Backdoor Attacks against Text Classifiers. DOI:10.48550\/arXiv.2310.18603","DOI":"10.48550\/arXiv.2310.18603"},{"key":"e_1_3_1_174_2","first-page":"49","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918)","author":"Yuan Xuejing","year":"2018","unstructured":"Xuejing Yuan, Yuxuan Chen, Yue Zhao, Yunhui Long, Xiaokang Liu, Kai Chen, Shengzhi Zhang, Heqing Huang, Xiaofeng Wang, and Carl A. Gunter. 2018. CommanderSong: A systematic approach for practical adversarial voice recognition. In Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918). 49\u201364."},{"key":"e_1_3_1_175_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616617"},{"key":"e_1_3_1_176_2","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612108"},{"key":"e_1_3_1_177_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413468"},{"key":"e_1_3_1_178_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134052"},{"key":"e_1_3_1_179_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-022-01434-0"},{"key":"e_1_3_1_180_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3201472"},{"key":"e_1_3_1_181_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464809"},{"key":"e_1_3_1_182_2","doi-asserted-by":"publisher","DOI":"10.1049\/cje.2021.00.126"},{"key":"e_1_3_1_183_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.05.054"},{"key":"e_1_3_1_184_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2842470"},{"key":"e_1_3_1_185_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2023.102899"},{"key":"e_1_3_1_186_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00022"},{"key":"e_1_3_1_187_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-022-1377-5"},{"key":"e_1_3_1_188_2","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/4593002"},{"key":"e_1_3_1_189_2","doi-asserted-by":"publisher","unstructured":"Shuai Zhao Meihuizi Jia Luu Anh Tuan Fengjun Pan and Jinming Wen. 2024. Universal Vulnerabilities in Large Language Models: Backdoor Attacks for In-context Learning. DOI:10.48550\/arXiv.2401.05949","DOI":"10.48550\/arXiv.2401.05949"},{"key":"e_1_3_1_190_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"e_1_3_1_191_2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.2000265"},{"key":"e_1_3_1_192_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.09.060"},{"key":"e_1_3_1_193_2","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"},{"key":"e_1_3_1_194_2","first-page":"7614","volume-title":"Proceedings of the 36th International Conference on Machine Learning (Proceedings of Machine Learning Research)","author":"Zhu Chen","year":"2019","unstructured":"Chen Zhu, W. Ronny Huang, Hengduo Li, Gavin Taylor, Christoph Studer, and Tom Goldstein. 2019. Transferable clean-label poisoning attacks on deep neural nets. In Proceedings of the 36th International Conference on Machine Learning (Proceedings of Machine Learning Research), Vol. 97, Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.). PMLR, 7614\u20137623."},{"key":"e_1_3_1_195_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3217322"},{"key":"e_1_3_1_196_2","doi-asserted-by":"publisher","unstructured":"Minhui Zou Yang Shi Chengliang Wang Fangyu Li WenZhan Song and Yu Wang. 2019. PoTrojan: Powerful Neural-level Trojan Designs in Deep Learning Models. DOI:10.48550\/arXiv.1802.03043","DOI":"10.48550\/arXiv.1802.03043"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3704725","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3704725","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:17:58Z","timestamp":1750295878000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3704725"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,10]]},"references-count":195,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,4,30]]}},"alternative-id":["10.1145\/3704725"],"URL":"https:\/\/doi.org\/10.1145\/3704725","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,10]]},"assertion":[{"value":"2023-10-19","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-11","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-10","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}