{"id":"https://openalex.org/W4410536435","doi":"https://doi.org/10.1109/access.2025.3571995","title":"Survey on Backdoor Attacks on Deep Learning: Current Trends, Categorization, Applications, Research Challenges, and Future Prospects","display_name":"Survey on Backdoor Attacks on Deep Learning: Current Trends, Categorization, Applications, Research Challenges, and Future Prospects","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4410536435","doi":"https://doi.org/10.1109/access.2025.3571995"},"language":"en","primary_location":{"id":"doi:10.1109/access.2025.3571995","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3571995","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1109/access.2025.3571995","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100647460","display_name":"Muhammad Abdullah Hanif","orcid":"https://orcid.org/0000-0001-9841-6132"},"institutions":[{"id":"https://openalex.org/I120250893","display_name":"New York University Abu Dhabi","ror":"https://ror.org/00e5k0821","country_code":"AE","type":"education","lineage":["https://openalex.org/I120250893","https://openalex.org/I57206974"]},{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["AE","US"],"is_corresponding":true,"raw_author_name":"Muhammad Abdullah Hanif","raw_affiliation_strings":["eBrain Laboratory, Division of Engineering, New York University (NYU) Abu Dhabi, Abu Dhabi, United Arab Emirates","eBrain Lab, Division of Engineering, New York University (NYU), Abu Dhabi, UAE"],"affiliations":[{"raw_affiliation_string":"eBrain Laboratory, Division of Engineering, New York University (NYU) Abu Dhabi, Abu Dhabi, United Arab Emirates","institution_ids":["https://openalex.org/I120250893"]},{"raw_affiliation_string":"eBrain Lab, Division of Engineering, New York University (NYU), Abu Dhabi, UAE","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071802339","display_name":"Nandish Chattopadhyay","orcid":"https://orcid.org/0000-0002-1611-9378"},"institutions":[{"id":"https://openalex.org/I120250893","display_name":"New York University Abu Dhabi","ror":"https://ror.org/00e5k0821","country_code":"AE","type":"education","lineage":["https://openalex.org/I120250893","https://openalex.org/I57206974"]},{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["AE","US"],"is_corresponding":false,"raw_author_name":"Nandish Chattopadhyay","raw_affiliation_strings":["eBrain Laboratory, Division of Engineering, New York University (NYU) Abu Dhabi, Abu Dhabi, United Arab Emirates","eBrain Lab, Division of Engineering, New York University (NYU), Abu Dhabi, UAE"],"affiliations":[{"raw_affiliation_string":"eBrain Laboratory, Division of Engineering, New York University (NYU) Abu Dhabi, Abu Dhabi, United Arab Emirates","institution_ids":["https://openalex.org/I120250893"]},{"raw_affiliation_string":"eBrain Lab, Division of Engineering, New York University (NYU), Abu Dhabi, UAE","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051699271","display_name":"Bassem Ouni","orcid":null},"institutions":[{"id":"https://openalex.org/I4210087059","display_name":"Technology Innovation Institute","ror":"https://ror.org/001kv2y39","country_code":"AE","type":"facility","lineage":["https://openalex.org/I4210087059"]},{"id":"https://openalex.org/I4210110242","display_name":"Digital Science (United States)","ror":"https://ror.org/020h4b682","country_code":"US","type":"company","lineage":["https://openalex.org/I4210110242","https://openalex.org/I4210112888","https://openalex.org/I4210118830"]}],"countries":["AE","US"],"is_corresponding":false,"raw_author_name":"Bassem Ouni","raw_affiliation_strings":["AI and Digital Science Research Center, Technology Innovation Institute (TII), Abu Dhabi, United Arab Emirates","AI and Digital Science Research Center, Technology Innovation Institute (TII), Abu Dhabi, UAE"],"affiliations":[{"raw_affiliation_string":"AI and Digital Science Research Center, Technology Innovation Institute (TII), Abu Dhabi, United Arab Emirates","institution_ids":["https://openalex.org/I4210087059"]},{"raw_affiliation_string":"AI and Digital Science Research Center, Technology Innovation Institute (TII), Abu Dhabi, UAE","institution_ids":["https://openalex.org/I4210087059","https://openalex.org/I4210110242"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5005190949","display_name":"Muhammad Shafique","orcid":"https://orcid.org/0000-0002-2607-8135"},"institutions":[{"id":"https://openalex.org/I120250893","display_name":"New York University Abu Dhabi","ror":"https://ror.org/00e5k0821","country_code":"AE","type":"education","lineage":["https://openalex.org/I120250893","https://openalex.org/I57206974"]},{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["AE","US"],"is_corresponding":false,"raw_author_name":"Muhammad Shafique","raw_affiliation_strings":["eBrain Laboratory, Division of Engineering, New York University (NYU) Abu Dhabi, Abu Dhabi, United Arab Emirates","eBrain Lab, Division of Engineering, New York University (NYU), Abu Dhabi, UAE"],"affiliations":[{"raw_affiliation_string":"eBrain Laboratory, Division of Engineering, New York University (NYU) Abu Dhabi, Abu Dhabi, United Arab Emirates","institution_ids":["https://openalex.org/I120250893"]},{"raw_affiliation_string":"eBrain Lab, Division of Engineering, New York University (NYU), Abu Dhabi, UAE","institution_ids":["https://openalex.org/I57206974"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5100647460"],"corresponding_institution_ids":["https://openalex.org/I120250893","https://openalex.org/I57206974"],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":17.0485,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.98870397,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":99},"biblio":{"volume":"13","issue":null,"first_page":"93190","last_page":"93221"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9948999881744385,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9905999898910522,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9527091979980469},{"id":"https://openalex.org/keywords/categorization","display_name":"Categorization","score":0.7061710357666016},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6836511492729187},{"id":"https://openalex.org/keywords/current","display_name":"Current (fluid)","score":0.5754419565200806},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.48858246207237244},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.47796177864074707},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.39269453287124634},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3098317086696625},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.11356949806213379},{"id":"https://openalex.org/keywords/electrical-engineering","display_name":"Electrical engineering","score":0.06471633911132812}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9527091979980469},{"id":"https://openalex.org/C94124525","wikidata":"https://www.wikidata.org/wiki/Q912550","display_name":"Categorization","level":2,"score":0.7061710357666016},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6836511492729187},{"id":"https://openalex.org/C148043351","wikidata":"https://www.wikidata.org/wiki/Q4456944","display_name":"Current (fluid)","level":2,"score":0.5754419565200806},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.48858246207237244},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.47796177864074707},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39269453287124634},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3098317086696625},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.11356949806213379},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.06471633911132812}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2025.3571995","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3571995","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:97358c77d0234c0f9cb2f8a69d5b916c","is_oa":true,"landing_page_url":"https://doaj.org/article/97358c77d0234c0f9cb2f8a69d5b916c","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 13, Pp 93190-93221 (2025)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2025.3571995","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2025.3571995","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":157,"referenced_works":["https://openalex.org/W2753783305","https://openalex.org/W2794284562","https://openalex.org/W2807363941","https://openalex.org/W2897865027","https://openalex.org/W2919115771","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2962677625","https://openalex.org/W2963542245","https://openalex.org/W2970335439","https://openalex.org/W2981207549","https://openalex.org/W2986013765","https://openalex.org/W2990270730","https://openalex.org/W2996800219","https://openalex.org/W3010216907","https://openalex.org/W3012113073","https://openalex.org/W3016889634","https://openalex.org/W3034258347","https://openalex.org/W3034414373","https://openalex.org/W3034579202","https://openalex.org/W3035424951","https://openalex.org/W3036480850","https://openalex.org/W3041840141","https://openalex.org/W3042368254","https://openalex.org/W3043819440","https://openalex.org/W3047587361","https://openalex.org/W3081178496","https://openalex.org/W3083185154","https://openalex.org/W3086802555","https://openalex.org/W3090898103","https://openalex.org/W3096024389","https://openalex.org/W3097631606","https://openalex.org/W3106646114","https://openalex.org/W3107337211","https://openalex.org/W3114838227","https://openalex.org/W3115279145","https://openalex.org/W3117572899","https://openalex.org/W3119557883","https://openalex.org/W3119570222","https://openalex.org/W3121099749","https://openalex.org/W3152758407","https://openalex.org/W3155871095","https://openalex.org/W3156790900","https://openalex.org/W3159196909","https://openalex.org/W3163168187","https://openalex.org/W3166022359","https://openalex.org/W3175215793","https://openalex.org/W3178326529","https://openalex.org/W3188772578","https://openalex.org/W3195614649","https://openalex.org/W3197880668","https://openalex.org/W3199693999","https://openalex.org/W3212158867","https://openalex.org/W3215055455","https://openalex.org/W3215147048","https://openalex.org/W4200031816","https://openalex.org/W4206244849","https://openalex.org/W4214564822","https://openalex.org/W4214680449","https://openalex.org/W4214737857","https://openalex.org/W4221136457","https://openalex.org/W4223940398","https://openalex.org/W4224924081","https://openalex.org/W4224952101","https://openalex.org/W4226313456","https://openalex.org/W4226394973","https://openalex.org/W4251660045","https://openalex.org/W4252979261","https://openalex.org/W4283375572","https://openalex.org/W4285206772","https://openalex.org/W4285605767","https://openalex.org/W4286904258","https://openalex.org/W4288758078","https://openalex.org/W4293704294","https://openalex.org/W4294691495","https://openalex.org/W4295956424","https://openalex.org/W4307964213","https://openalex.org/W4308338624","https://openalex.org/W4312233756","https://openalex.org/W4312329299","https://openalex.org/W4312351352","https://openalex.org/W4312406341","https://openalex.org/W4312700692","https://openalex.org/W4320736757","https://openalex.org/W4365148808","https://openalex.org/W4365807860","https://openalex.org/W4372260097","https://openalex.org/W4372260517","https://openalex.org/W4372266914","https://openalex.org/W4383221538","https://openalex.org/W4384664508","https://openalex.org/W4386057740","https://openalex.org/W4386075644","https://openalex.org/W4386075825","https://openalex.org/W4386083011","https://openalex.org/W4387359750","https://openalex.org/W4387363711","https://openalex.org/W4390969331","https://openalex.org/W4391620743","https://openalex.org/W4393160907","https://openalex.org/W4393241390","https://openalex.org/W4402604263","https://openalex.org/W4403488749","https://openalex.org/W4403790152","https://openalex.org/W6681673350","https://openalex.org/W6729756640","https://openalex.org/W6743581629","https://openalex.org/W6746897123","https://openalex.org/W6750462152","https://openalex.org/W6756074407","https://openalex.org/W6756333562","https://openalex.org/W6759622168","https://openalex.org/W6762100871","https://openalex.org/W6762718338","https://openalex.org/W6766253520","https://openalex.org/W6766336336","https://openalex.org/W6770897281","https://openalex.org/W6776469819","https://openalex.org/W6779272815","https://openalex.org/W6780152303","https://openalex.org/W6781420246","https://openalex.org/W6783051176","https://openalex.org/W6783931880","https://openalex.org/W6784558051","https://openalex.org/W6787653732","https://openalex.org/W6788774739","https://openalex.org/W6788876066","https://openalex.org/W6789325072","https://openalex.org/W6792327856","https://openalex.org/W6793958797","https://openalex.org/W6796067509","https://openalex.org/W6797144289","https://openalex.org/W6797364105","https://openalex.org/W6800099408","https://openalex.org/W6803053407","https://openalex.org/W6803329306","https://openalex.org/W6803329705","https://openalex.org/W6803620494","https://openalex.org/W6804995136","https://openalex.org/W6805016613","https://openalex.org/W6809173602","https://openalex.org/W6809890637","https://openalex.org/W6810162380","https://openalex.org/W6810462909","https://openalex.org/W6810593300","https://openalex.org/W6839044539","https://openalex.org/W6839126366","https://openalex.org/W6839137985","https://openalex.org/W6839161594","https://openalex.org/W6839201962","https://openalex.org/W6841443663","https://openalex.org/W6845081173","https://openalex.org/W6845749207","https://openalex.org/W6845886309","https://openalex.org/W6850353503","https://openalex.org/W6855216781","https://openalex.org/W6857558525"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W4401407399"],"abstract_inverted_index":{"Deep":[0],"Neural":[1],"Networks":[2],"(DNNs)":[3],"have":[4],"emerged":[5],"as":[6,57,160],"a":[7,20,42,58,126,136],"prominent":[8],"set":[9,128],"of":[10,23,38,45,54,74,90,109,129,220,227,233],"algorithms":[11],"for":[12,33,64,68,82,100,125],"complex":[13,69],"real-world":[14,34,242],"applications.":[15,70],"However,":[16],"state-of-the-art":[17,212],"DNNs":[18],"require":[19],"significant":[21],"amount":[22,44],"data":[24,92],"and":[25,30,47,97,165,169,207,210,230,240],"computational":[26,46,96],"resources":[27,49,63],"to":[28,159,171,186,215],"train":[29],"generalize":[31],"well":[32],"scenarios.":[35],"This":[36],"dependence":[37],"DNN":[39],"training":[40,65],"on":[41],"large":[43,66,88],"memory":[48,98],"has":[50,93],"increased":[51],"the":[52,72,75,95,104,107,118,141,178,198,218,221,225,234],"use":[53],"Machine":[55],"Learning":[56],"Service":[59],"(MLaaS)":[60],"or":[61,162],"third-party":[62,112],"models":[67],"Specifically,":[71],"drift":[73],"deep":[76],"learning":[77,81,83,194],"community":[78],"towards":[79],"self-supervised":[80],"better":[84],"representations":[85],"directly":[86],"from":[87,135],"amounts":[89],"unlabeled":[91],"amplified":[94],"requirements":[99],"machine":[101,193],"learning.":[102],"On":[103,117],"one":[105],"hand,":[106,120],"availability":[108],"MLaaS":[110],"(or":[111],"resources)":[113],"alleviates":[114],"this":[115,174],"issue.":[116],"other":[119],"it":[121],"opens":[122],"up":[123],"avenues":[124],"new":[127],"vulnerabilities,":[130],"where":[131],"an":[132],"adversary":[133],"(someone":[134],"third":[137],"party)":[138],"can":[139,183],"infect":[140],"model":[142],"with":[143,150],"malicious":[144,189],"functionality":[145,190],"that":[146,182],"is":[147],"triggered":[148],"only":[149],"specific":[151],"input":[152],"patterns.":[153],"Such":[154],"attacks":[155,164,199,206],"are":[156,166],"usually":[157],"referred":[158],"Trojan":[161],"backdoor":[163,243],"very":[167],"stealthy":[168,239],"hard":[170],"detect.":[172],"In":[173],"paper,":[175],"we":[176,223],"highlight":[177,224],"complete":[179],"attack":[180],"surface":[181],"be":[184],"exploited":[185],"inject":[187],"hidden":[188],"(backdoors)":[191],"in":[192,237],"models.":[195],"We":[196],"classify":[197],"into":[200],"two":[201],"major":[202],"categories,":[203],"i.e.,":[204],"poisoning":[205],"non-poisoning":[208],"attacks,":[209],"present":[211],"works":[213],"related":[214],"each.":[216],"Towards":[217],"end":[219],"article,":[222],"limitations":[226],"existing":[228],"techniques":[229],"cover":[231],"some":[232],"key":[235],"challenges":[236],"developing":[238],"robust":[241],"attacks.":[244]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
