{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:03:40Z","timestamp":1780589020335,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":74,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"National Science Foundation","award":["OIA-1946231"],"award-info":[{"award-number":["OIA-1946231"]}]},{"name":"National Science Foundation","award":["CNS-2117785"],"award-info":[{"award-number":["CNS-2117785"]}]},{"name":"National Science Foundation","award":["OIA-2229752"],"award-info":[{"award-number":["OIA-2229752"]}]},{"name":"National Science Foundation","award":["CMMI-2510512"],"award-info":[{"award-number":["CMMI-2510512"]}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2231682"],"award-info":[{"award-number":["CNS-2231682"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3785283","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"608-624","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Purified Distillation Slimming (PDS) for Robust Backdoor Defense"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2489-8671","authenticated-orcid":false,"given":"Liqun","family":"Shan","sequence":"first","affiliation":[{"name":"University of Louisiana at Lafayette, Lafayette, LA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-7548-7472","authenticated-orcid":false,"given":"Kaiying","family":"Han","sequence":"additional","affiliation":[{"name":"University of Louisiana at Lafayette, Lafayette, LA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7640-1829","authenticated-orcid":false,"given":"Yazhou","family":"Tu","sequence":"additional","affiliation":[{"name":"Auburn University, Auburn, AL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2672-1132","authenticated-orcid":false,"given":"Insup","family":"Lee","sequence":"additional","affiliation":[{"name":"University of Pennsylvania, Philadelphia, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2438-5430","authenticated-orcid":false,"given":"Xiali","family":"Hei","sequence":"additional","affiliation":[{"name":"University of Louisiana at Lafayette, Lafayette, LA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Bagdasaryan Eugene","year":"2021","unstructured":"Eugene Bagdasaryan and Vitaly Shmatikov. 2021. Blind backdoors in deep learning models. In 30th USENIX Security Symposium (USENIX Security 21). 1505\u20131521."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","first-page":"22285","DOI":"10.52202\/068431-1619","article-title":"One-shot neural backdoor erasing via adversarial weight masking","volume":"35","author":"Chai Shuwen","year":"2022","unstructured":"Shuwen Chai and Jinghui Chen. 2022. One-shot neural backdoor erasing via adversarial weight masking. Advances in Neural Information Processing Systems 35 (2022), 22285\u201322299.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_4_1","volume-title":"Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728","author":"Chen Bryant","year":"2018","unstructured":"Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava. 2018. Detecting backdoor attacks on deep neural networks by activation clustering. arXiv preprint arXiv:1811.03728 (2018)."},{"key":"e_1_3_2_1_5_1","first-page":"8","article-title":"DeepInspect: A Black-box Trojan Detection and Mitigation Framework for Deep Neural Networks","volume":"2","author":"Chen Huili","year":"2019","unstructured":"Huili Chen, Cheng Fu, Jishen Zhao, and Farinaz Koushanfar. 2019. DeepInspect: A Black-box Trojan Detection and Mitigation Framework for Deep Neural Networks. In IJCAI, Vol. 2. 8.","journal-title":"IJCAI"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0707"},{"key":"e_1_3_2_1_7_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_10_1","volume-title":"Februus: Input purification defense against trojan attacks on deep neural network systems. In Annual computer security applications conference. 897\u2013912.","author":"Doan Bao Gia","year":"2020","unstructured":"Bao Gia Doan, Ehsan Abbasnejad, and Damith C Ranasinghe. 2020. Februus: Input purification defense against trojan attacks on deep neural network systems. In Annual computer security applications conference. 897\u2013912."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01617"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 20876\u201320885","author":"Feng Yu","year":"2022","unstructured":"Yu Feng, Benteng Ma, Jing Zhang, Shanshan Zhao, Yong Xia, and Dacheng Tao. 2022. Fiba: Frequency-injection based backdoor attack in medical image analysis. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 20876\u201320885."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3340531.3412130"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475254"},{"key":"e_1_3_2_1_17_1","volume-title":"2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 755\u2013772","author":"Gong Xueluan","year":"2023","unstructured":"Xueluan Gong, Yanjiao Chen, Wang Yang, Qian Wang, Yuzhe Gu, Huayang Huang, and Chao Shen. 2023. REDEEM MYSELF: Purifying backdoors in deep learning models using self attention distillation. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 755\u2013772."},{"key":"e_1_3_2_1_18_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_1_19_1","unstructured":"Jonathan Hayase Weihao Kong Raghav Somani and Sewoong Oh. 2021. Defense against backdoor attacks via robust covariance estimation. In ICML. 4129\u20134139."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_21_1","volume-title":"Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531","author":"Hinton Geoffrey","year":"2015","unstructured":"Geoffrey Hinton, Oriol Vinyals, and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531 (2015)."},{"key":"e_1_3_2_1_22_1","first-page":"9782","article-title":"Dynabert: Dynamic bert with adaptive width and depth","volume":"33","author":"Hou Lu","year":"2020","unstructured":"Lu Hou, Zhiqi Huang, Lifeng Shang, Xin Jiang, Xiao Chen, and Qun Liu. 2020. Dynabert: Dynamic bert with adaptive width and depth. Advances in Neural Information Processing Systems 33 (2020), 9782\u20139793.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Sebastian Houben Johannes Stallkamp Jan Salmen Marc Schlipsing and Christian Igel. 2013. Detection of traffic signs in real-world images: The German Traffic Sign Detection Benchmark. In The 2013 international joint conference on neural networks (IJCNN). Ieee 1\u20138.","DOI":"10.1109\/IJCNN.2013.6706807"},{"key":"e_1_3_2_1_24_1","volume-title":"Adversarial Feature Map Pruning for Backdoor. In International Conference on Learning Representations (ICLR).","author":"Huang Dong","year":"2024","unstructured":"Dong Huang and Qingwen Bu. 2024. Adversarial Feature Map Pruning for Backdoor. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_25_1","volume-title":"Neuroninspect: Detecting backdoors in neural networks via output explanations. arXiv preprint arXiv:1911.07399","author":"Huang Xijie","year":"2019","unstructured":"Xijie Huang, Moustafa Alzantot, and Mani Srivastava. 2019. Neuroninspect: Detecting backdoors in neural networks via output explanations. arXiv preprint arXiv:1911.07399 (2019)."},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","volume":"38","author":"Huynh Tran","year":"2024","unstructured":"Tran Huynh, Dang Nguyen, Tung Pham, and Anh Tran. 2024. COMBAT: Alternated Training for Effective Clean-Label Backdoor Attacks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38. 2436\u20132444."},{"key":"e_1_3_2_1_27_1","volume-title":"2023 IEEE Conference on Secure and Trustworthy Machine Learning(SaTML). IEEE, 392\u2013403","author":"Jiang Yujing","year":"2023","unstructured":"Yujing Jiang, Xingjun Ma, Sarah Monazam Erfani, and James Bailey. 2023. Backdoor attacks on time series: A generative approach. In 2023 IEEE Conference on Secure and Trustworthy Machine Learning(SaTML). IEEE, 392\u2013403."},{"key":"e_1_3_2_1_28_1","volume-title":"International Conference on Machine Learning. PMLR, 16216\u201316236","author":"Khaddaj Alaa","year":"2023","unstructured":"Alaa Khaddaj, Guillaume Leclerc, Aleksandar Makelov, Kristian Georgiev, Hadi Salman, Andrew Ilyas, and Aleksander Madry. 2023. Rethinking backdoor attacks. In International Conference on Machine Learning. PMLR, 16216\u201316236."},{"key":"e_1_3_2_1_29_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_30_1","volume-title":"Block pruning for faster transformers. arXiv preprint arXiv:2109.04838","author":"Lagunas Fran\u00e7ois","year":"2021","unstructured":"Fran\u00e7ois Lagunas, Ella Charlaix, Victor Sanh, and Alexander M Rush. 2021. Block pruning for faster transformers. arXiv preprint arXiv:2109.04838 (2021)."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"e_1_3_2_1_32_1","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume":"34","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Anti-backdoor learning: Training clean models on poisoned data. Advances in Neural Information Processing Systems 34(2021), 14900\u201314912.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_33_1","volume-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930","author":"Li Yige","year":"2021","unstructured":"Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li, and Xingjun Ma. 2021. Neural attention distillation: Erasing backdoor triggers from deep neural networks. arXiv preprint arXiv:2101.05930 (2021)."},{"key":"e_1_3_2_1_34_1","volume-title":"Reconstructive Neuron Pruning for Backdoor Defense. arXiv preprint arXiv:2305.14876","author":"Li Yige","year":"2023","unstructured":"Yige Li, Xixiang Lyu, Xingjun Ma, Nodens Koren, Lingjuan Lyu, Bo Li, and Yu-Gang Jiang. 2023. Reconstructive Neuron Pruning for Backdoor Defense. arXiv preprint arXiv:2305.14876 (2023)."},{"key":"e_1_3_2_1_35_1","volume-title":"Homodistil: Homotopic task-agnostic distillation of pre-trained transformers. arXiv preprint arXiv:2302.09632","author":"Liang Chen","year":"2023","unstructured":"Chen Liang, Haoming Jiang, Zheng Li, Xianfeng Tang, Bin Yin, and Tuo Zhao. 2023. Homodistil: Homotopic task-agnostic distillation of pre-trained transformers. arXiv preprint arXiv:2302.09632 (2023)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_2_1_40_1","first-page":"20373","article-title":"Excess capacity and backdoor poisoning","volume":"34","author":"Manoj Naren","year":"2021","unstructured":"Naren Manoj and Avrim Blum. 2021. Excess capacity and backdoor poisoning. Advances in Neural Information Processing Systems 34 (2021), 20373\u201320384.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_41_1","volume-title":"Are sixteen heads really better than one? Advances in neural information processing systems 32","author":"Michel Paul","year":"2019","unstructured":"Paul Michel, Omer Levy, and Graham Neubig. 2019. Are sixteen heads really better than one? Advances in neural information processing systems 32 (2019)."},{"key":"e_1_3_2_1_42_1","volume-title":"Wanet-imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369","author":"Nguyen Anh","year":"2021","unstructured":"Anh Nguyen and Anh Tran. 2021. Wanet-imperceptible warping-based backdoor attack. arXiv preprint arXiv:2102.10369 (2021)."},{"key":"e_1_3_2_1_43_1","first-page":"3454","article-title":"Input-aware dynamic backdoor attack","volume":"33","author":"Nguyen Tuan Anh","year":"2020","unstructured":"Tuan Anh Nguyen and Anh Tran. 2020. Input-aware dynamic backdoor attack. Advances in Neural Information Processing Systems 33 (2020), 3454\u20133464.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_44_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Qi Xiangyu","year":"2023","unstructured":"Xiangyu Qi, Tinghao Xie, Yiming Li, Saeed Mahloujifar, and Prateek Mittal. 2023. Revisiting the assumption of latent separability for backdoor defenses. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01299"},{"key":"e_1_3_2_1_46_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Qi Xiangyu","year":"2023","unstructured":"Xiangyu Qi, Tinghao Xie, Jiachen T Wang, Tong Wu, Saeed Mahloujifar, and Prateek Mittal. 2023. Towards a proactive ML approach for detecting backdoor poison samples. In 32nd USENIX Security Symposium (USENIX Security 23). 1685\u20131702."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_2_1_48_1","volume-title":"Fine-tuning is all you need to mitigate backdoor attacks. arXiv preprint arXiv:2212.09067","author":"Sha Zeyang","year":"2022","unstructured":"Zeyang Sha, Xinlei He, Pascal Berrang, Mathias Humbert, and Yang Zhang. 2022. Fine-tuning is all you need to mitigate backdoor attacks. arXiv preprint arXiv:2212.09067 (2022)."},{"key":"e_1_3_2_1_49_1","volume-title":"Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems 31","author":"Shafahi Ali","year":"2018","unstructured":"Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems 31 (2018)."},{"key":"e_1_3_2_1_50_1","first-page":"18021","article-title":"Manipulating SGD with data ordering attacks","volume":"34","author":"Shumailov Ilia","year":"2021","unstructured":"Ilia Shumailov, Zakhar Shumaylov, Dmitry Kazhdan, Yiren Zhao, Nicolas Papernot, Murat A Erdogdu, and Ross J Anderson. 2021. Manipulating SGD with data ordering attacks. Advances in Neural Information Processing Systems 34 (2021), 18021\u201318032.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_51_1","volume-title":"Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014)."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"e_1_3_2_1_53_1","volume-title":"International conference on machine learning. PMLR, 6105\u20136114","author":"Tan Mingxing","year":"2019","unstructured":"Mingxing Tan and Quoc Le. 2019. Efficientnet: Rethinking model scaling for convolutional neural networks. In International conference on machine learning. PMLR, 6105\u20136114."},{"key":"e_1_3_2_1_54_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Tang Di","year":"2021","unstructured":"Di Tang, XiaoFeng Wang, Haixu Tang, and Kehuan Zhang. 2021. Demon in the variant: Statistical analysis of {DNNs} for robust backdoor contamination detection. In 30th USENIX Security Symposium (USENIX Security 21). 1541\u20131558."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833688"},{"key":"e_1_3_2_1_56_1","volume-title":"Spectral signatures in backdoor attacks. Advances in neural information processing systems 31","author":"Tran Brandon","year":"2018","unstructured":"Brandon Tran, Jerry Li, and Aleksander Madry. 2018. Spectral signatures in backdoor attacks. Advances in neural information processing systems 31 (2018)."},{"key":"e_1_3_2_1_57_1","unstructured":"Alexander Turner Dimitris Tsipras and Aleksander Madry. 2018. Clean-label backdoor attacks. (2018)."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2022.3159784"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_1_60_1","volume-title":"2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 15\u201315","author":"Wang Hang","year":"2023","unstructured":"Hang Wang, Zhen Xiang, David J Miller, and George Kesidis. 2023. Mm-bd: Post-training detection of backdoor attacks with arbitrary backdoor pattern types using a maximum margin statistic. In 2024 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 15\u201315."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"crossref","first-page":"1526","DOI":"10.1109\/TSC.2020.3000900","article-title":"Backdoor attacks against transfer learning with pre-trained deep learning models","volume":"15","author":"Wang Shuo","year":"2020","unstructured":"Shuo Wang, Surya Nepal, Carsten Rudolph, Marthie Grobler, Shangyu Chen, and Tianle Chen. 2020. Backdoor attacks against transfer learning with pre-trained deep learning models. IEEE Transactions on Services Computing 15, 3 (2020), 1526\u20131539.","journal-title":"IEEE Transactions on Services Computing"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"e_1_3_2_1_63_1","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume":"34","author":"Wu Dongxian","year":"2021","unstructured":"Dongxian Wu and Yisen Wang. 2021. Adversarial neuron pruning purifies backdoored deep models. Advances in Neural Information Processing Systems 34 (2021), 16913\u201316925.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_64_1","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume":"33","author":"Wu Dongxian","year":"2020","unstructured":"Dongxian Wu, Shu-Tao Xia, and Yisen Wang. 2020. Adversarial weight perturbation helps robust generalization. Advances in Neural Information Processing Systems 33 (2020), 2958\u20132969.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_65_1","volume-title":"Structured pruning learns compact and accurate models. arXiv preprint arXiv:2204.00408","author":"Xia Mengzhou","year":"2022","unstructured":"Mengzhou Xia, Zexuan Zhong, and Danqi Chen. 2022. Structured pruning learns compact and accurate models. arXiv preprint arXiv:2204.00408 (2022)."},{"key":"e_1_3_2_1_66_1","volume-title":"Jinxi Zhao, and Zhibin Xiao.","author":"Xu Dongkuan","year":"2021","unstructured":"Dongkuan Xu, Ian EH Yen, Jinxi Zhao, and Zhibin Xiao. 2021. Rethinking Network Pruning-under the Pre-train and Fine-tune Paradigm. arXiv preprint arXiv:2104.08682 (2021)."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"e_1_3_2_1_68_1","volume-title":"Adversarial unlearning of backdoors via implicit hypergradient. arXiv preprint arXiv:2110.03735","author":"Zeng Yi","year":"2021","unstructured":"Yi Zeng, Si Chen, Won Park, Z Morley Mao, Ming Jin, and Ruoxi Jia. 2021. Adversarial unlearning of backdoors via implicit hypergradient. arXiv preprint arXiv:2110.03735 (2021)."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616617"},{"key":"e_1_3_2_1_70_1","volume-title":"Proceedings of the IEEE\/CVF international conference on computer vision. 16473\u201316481","author":"Zeng Yi","year":"2021","unstructured":"Yi Zeng, Won Park, Z Morley Mao, and Ruoxi Jia. 2021. Rethinking the backdoor attacks' triggers: A frequency perspective. In Proceedings of the IEEE\/CVF international conference on computer vision. 16473\u201316481."},{"key":"e_1_3_2_1_71_1","volume-title":"Adaptive Robust Learning Against Backdoor Attacks in Smart Homes","author":"Zhang Jiahui","year":"2024","unstructured":"Jiahui Zhang, Zhuzhu Wang, Zhuoran Ma, and Jianfeng Ma. 2024. Adaptive Robust Learning Against Backdoor Attacks in Smart Homes. IEEE Internet of Things Journal (2024)."},{"key":"e_1_3_2_1_72_1","volume-title":"Karthikeyan Natesan Ramamurthy, and Xue Lin","author":"Zhao Pu","year":"2020","unstructured":"Pu Zhao, Pin-Yu Chen, Payel Das, Karthikeyan Natesan Ramamurthy, and Xue Lin. 2020. Bridging mode connectivity in loss landscapes and adversarial robustness. arXiv preprint arXiv:2005.00060 (2020)."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01478"}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785283","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785283","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:42:00Z","timestamp":1780587720000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3785283"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":74,"alternative-id":["10.1145\/3779208.3785283","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3785283","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}