{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T05:33:48Z","timestamp":1738388028708,"version":"3.35.0"},"reference-count":31,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2025,2,1]]},"DOI":"10.1587\/transinf.2023edp7160","type":"journal-article","created":{"date-parts":[[2024,9,18]],"date-time":"2024-09-18T22:11:22Z","timestamp":1726697482000},"page":"114-123","source":"Crossref","is-referenced-by-count":0,"title":["Detecting Textual Backdoor Attacks via Class Difference for Text Classification System"],"prefix":"10.1587","volume":"E108.D","author":[{"given":"Hyun","family":"KWON","sequence":"first","affiliation":[{"name":"Department of Artificial Intelligence and Data Science, Korea Military Academy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"LEE","sequence":"additional","affiliation":[{"name":"Division of Computer Information and Science, Hoseo University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"publisher","unstructured":"[1] J. Schmidhuber, \u201cDeep learning in neural networks: An overview,\u201d Neural networks, vol.61, pp.85-117, 2015. 10.1016\/j.neunet.2014.09.003","DOI":"10.1016\/j.neunet.2014.09.003"},{"key":"2","unstructured":"[2] K. Simonyan and A. Zisserman, \u201cVery deep convolutional networks for large-scale image recognition,\u201d International Conference on Learning Representations, 2015."},{"key":"3","doi-asserted-by":"publisher","unstructured":"[3] J. Ma, H. Xu, J. Jiang, X. Mei, and X.-P. Zhang, \u201cDdcgan: A dual-discriminator conditional generative adversarial network for multi-resolution image fusion,\u201d IEEE Trans. Image Process., vol.29, pp.4980-4995, 2020. 10.1109\/tip.2020.2977573","DOI":"10.1109\/TIP.2020.2977573"},{"key":"4","doi-asserted-by":"crossref","unstructured":"[4] W. Shi and V. Demberg, \u201cNext sentence prediction helps implicit discourse relation classification within and across domains,\u201d Proc. 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP), pp.5790-5796, 2019. 10.18653\/v1\/d19-1586","DOI":"10.18653\/v1\/D19-1586"},{"key":"5","doi-asserted-by":"publisher","unstructured":"[5] M. Barreno, B. Nelson, A.D. Joseph, and J.D. Tygar, \u201cThe security of machine learning,\u201d Machine Learning, vol.81, no.2, pp.121-148, 2010. 10.1007\/s10994-010-5188-5","DOI":"10.1007\/s10994-010-5188-5"},{"key":"6","doi-asserted-by":"publisher","unstructured":"[6] H. Ren, T. Huang, and H. Yan, \u201cAdversarial examples: attacks and defenses in the physical world,\u201d International Journal of Machine Learning and Cybernetics, vol.12, no.11, pp.3325-3336, 2021. 10.1007\/s13042-020-01242-z","DOI":"10.1007\/s13042-020-01242-z"},{"key":"7","doi-asserted-by":"crossref","unstructured":"[7] A. Kurakin, I.J. Goodfellow, and S. Bengio, \u201cAdversarial examples in the physical world,\u201d Artificial Intelligence Safety and Security, pp.99-112, 2018. 10.1201\/9781351251389-8","DOI":"10.1201\/9781351251389-8"},{"key":"8","unstructured":"[8] A. Kurakin, I.J. Goodfellow, and S. Bengio, \u201cAdversarial machine learning at scale,\u201d International Conference on Learning Representations (ICLR), 2017."},{"key":"9","doi-asserted-by":"crossref","unstructured":"[9] N. Carlini and D. Wagner, \u201cTowards evaluating the robustness of neural networks,\u201d Security and Privacy (SP), 2017 IEEE Symposium on, pp.39-57, IEEE, 2017. 10.1109\/sp.2017.49","DOI":"10.1109\/SP.2017.49"},{"key":"10","doi-asserted-by":"crossref","unstructured":"[10] D. Meng and H. Chen, \u201cMagnet: a two-pronged defense against adversarial examples,\u201d Proc. 2017 ACM SIGSAC Conference on Computer and Communications Security, pp.135-147, ACM, 2017. 10.1145\/3133956.3134057","DOI":"10.1145\/3133956.3134057"},{"key":"11","unstructured":"[11] S. Shen, G. Jin, K. Gao, and Y. Zhang, \u201cApe-gan: Adversarial perturbation elimination with gan,\u201d ICLR Submission, available on OpenReview, 2017."},{"key":"12","unstructured":"[12] I. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d International Conference on Learning Representations, 2015."},{"key":"13","unstructured":"[13] B. Biggio, B. Nelson, and P. Laskov, \u201cPoisoning attacks against support vector machines,\u201d Proc. 29th International Coference on International Conference on Machine Learning, pp.1467-1474, Omnipress, 2012."},{"key":"14","doi-asserted-by":"publisher","unstructured":"[14] M. Mozaffari-Kermani, S. Sur-Kolay, A. Raghunathan, and N.K. Jha, \u201cSystematic poisoning attacks on and defenses for machine learning in healthcare,\u201d IEEE J. Biomed. Health Inform., vol.19, no.6, pp.1893-1905, 2015. 10.1109\/jbhi.2014.2344095","DOI":"10.1109\/JBHI.2014.2344095"},{"key":"15","unstructured":"[15] C. Yang, Q. Wu, H. Li, and Y. Chen, \u201cGenerative poisoning attack method against neural networks,\u201d arXiv preprint arXiv:1703.01340, 2017."},{"key":"16","doi-asserted-by":"crossref","unstructured":"[16] B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B.Y. Zhao, \u201cNeural cleanse: Identifying and mitigating backdoor attacks in neural networks,\u201d Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural Networks, pp.707-723, 2019. 10.1109\/sp.2019.00031","DOI":"10.1109\/SP.2019.00031"},{"key":"17","unstructured":"[17] S. Li, B.Z.H. Zhao, J. Yu, M. Xue, D. Kaafar, and H. Zhu, \u201cInvisible backdoor attacks against deep neural networks,\u201d arXiv preprint arXiv:1909.02742, 2019."},{"key":"18","doi-asserted-by":"crossref","unstructured":"[18] F. Qi, Y. Chen, M. Li, Y. Yao, Z. Liu, and M. Sun, \u201cOnion: A simple and effective defense against textual backdoor attacks,\u201d arXiv preprint arXiv:2011.10369, 2020.","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"19","doi-asserted-by":"publisher","unstructured":"[19] K. Shao, J. Yang, Y. Ai, H. Liu, and Y. Zhang, \u201cBddr: An effective defense against textual backdoor attacks,\u201d Computers &amp; Security, vol.110, p.102433, 2021. 10.1016\/j.cose.2021.102433","DOI":"10.1016\/j.cose.2021.102433"},{"key":"20","unstructured":"[20] A. Maas, R. Daly, P. Pham, D. Huang, A. Ng, and C. Potts, \u201cLarge movie review dataset,\u201d 2011."},{"key":"21","unstructured":"[21] J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, \u201cBert: Pre-training of deep bidirectional transformers for language understanding,\u201d Proc. 2019 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, vol.1 (Long and Short Papers), pp.4171-4186, 2019. 10.18653\/v1\/N19-1423"},{"key":"22","doi-asserted-by":"publisher","unstructured":"[22] L. Floridi and M. Chiriatti, \u201cGpt-3: Its nature, scope, limits, and consequences,\u201d Minds and Machines, vol.30, no.4, pp.681-694, 2020. 10.1007\/s11023-020-09548-1","DOI":"10.1007\/s11023-020-09548-1"},{"key":"23","unstructured":"[23] T. Gu, B. Dolan-Gavitt, and S. Garg, \u201cBadnets: Identifying vulnerabilities in the machine learning model supply chain,\u201d arXiv preprint arXiv:1708.06733, 2017."},{"key":"24","doi-asserted-by":"crossref","unstructured":"[24] Y. Liu, S. Ma, Y. Aafer, W.-C. Lee, J. Zhai, W. Wang, and X. Zhang, \u201cTrojaning attack on neural networks,\u201d NDSS, 2018. 10.14722\/ndss.2018.23291","DOI":"10.14722\/ndss.2018.23291"},{"key":"25","doi-asserted-by":"crossref","unstructured":"[25] J. Clements and Y. Lao, \u201cHardware trojan attacks on neural networks,\u201d arXiv preprint arXiv:1806.05768, 2018.","DOI":"10.1109\/ISCAS.2019.8702493"},{"key":"26","unstructured":"[26] Y. LeCun, C. Cortes, and C.J. Burges, \u201cMnist handwritten digit database,\u201d AT&amp;T Labs, http:\/\/yann.lecun.com\/exdb\/mnist, vol.2, 2010."},{"key":"27","doi-asserted-by":"publisher","unstructured":"[27] H. Kwon and S. Lee, \u201cTextual backdoor attack for the text classification system,\u201d Security and Communication Networks, vol.2021, pp.1-11, 2021. 10.1155\/2021\/2938386","DOI":"10.1155\/2021\/2938386"},{"key":"28","unstructured":"[28] M. Abadi, P. Barham, J. Chen, Z. Chen, A. Davis, J. Dean, M. Devin, S. Ghemawat, G. Irving, M. Isard, et al., \u201cTensorflow: A system for large-scale machine learning,\u201d OSDI, pp.265-283, 2016."},{"key":"29","doi-asserted-by":"publisher","unstructured":"[29] K. Eckle and J. Schmidt-Hieber, \u201cA comparison of deep networks with relu activation function and linear spline-type methods,\u201d Neural Networks, vol.110, pp.232-242, 2019. 10.1016\/j.neunet.2018.11.005","DOI":"10.1016\/j.neunet.2018.11.005"},{"key":"30","unstructured":"[30] D. Kingma and J. Ba, \u201cAdam: A method for stochastic optimization,\u201d The International Conference on Learning Representations (ICLR), 2015."},{"key":"31","unstructured":"[31] https:\/\/buly.kr\/DlG2jRr"}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/2\/E108.D_2023EDP7160\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T03:30:49Z","timestamp":1738380649000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/2\/E108.D_2023EDP7160\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,1]]},"references-count":31,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2023edp7160","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"type":"print","value":"0916-8532"},{"type":"electronic","value":"1745-1361"}],"subject":[],"published":{"date-parts":[[2025,2,1]]},"article-number":"2023EDP7160"}}