{"id":"https://openalex.org/W4416799928","doi":"https://doi.org/10.1109/apsipaasc65261.2025.11248971","title":"Detoxification of Poisoned Recognition Models by Fine-Tuning with Out-of-Distribution Samples","display_name":"Detoxification of Poisoned Recognition Models by Fine-Tuning with Out-of-Distribution Samples","publication_year":2025,"publication_date":"2025-10-22","ids":{"openalex":"https://openalex.org/W4416799928","doi":"https://doi.org/10.1109/apsipaasc65261.2025.11248971"},"language":null,"primary_location":{"id":"doi:10.1109/apsipaasc65261.2025.11248971","is_oa":false,"landing_page_url":"https://doi.org/10.1109/apsipaasc65261.2025.11248971","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Junsuke Takano","orcid":null},"institutions":[{"id":"https://openalex.org/I161296585","display_name":"Tokyo University of Science","ror":"https://ror.org/05sj3n476","country_code":"JP","type":"education","lineage":["https://openalex.org/I161296585"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Junsuke Takano","raw_affiliation_strings":["Tokyo University of Science,Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tokyo University of Science,Japan","institution_ids":["https://openalex.org/I161296585"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5058191809","display_name":"Kazuaki Nakamura","orcid":"https://orcid.org/0000-0002-4859-4624"},"institutions":[{"id":"https://openalex.org/I161296585","display_name":"Tokyo University of Science","ror":"https://ror.org/05sj3n476","country_code":"JP","type":"education","lineage":["https://openalex.org/I161296585"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Kazuaki Nakamura","raw_affiliation_strings":["Tokyo University of Science,Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tokyo University of Science,Japan","institution_ids":["https://openalex.org/I161296585"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.17665969,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"2146","last_page":"2151"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9750000238418579,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9750000238418579,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.004900000058114529,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.00430000014603138,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.5735999941825867},{"id":"https://openalex.org/keywords/detoxification","display_name":"Detoxification (alternative medicine)","score":0.5070000290870667},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.5004000067710876},{"id":"https://openalex.org/keywords/object","display_name":"Object (grammar)","score":0.49570000171661377},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.37400001287460327},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.36160001158714294}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6704000234603882},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.656499981880188},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.5735999941825867},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5394999980926514},{"id":"https://openalex.org/C2780497538","wikidata":"https://www.wikidata.org/wiki/Q1192006","display_name":"Detoxification (alternative medicine)","level":3,"score":0.5070000290870667},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.5004000067710876},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.49570000171661377},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.37400001287460327},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.36160001158714294},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.33889999985694885},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.32089999318122864},{"id":"https://openalex.org/C2778067643","wikidata":"https://www.wikidata.org/wiki/Q166507","display_name":"Interval (graph theory)","level":2,"score":0.28870001435279846},{"id":"https://openalex.org/C59594135","wikidata":"https://www.wikidata.org/wiki/Q5249242","display_name":"Decision model","level":2,"score":0.2849999964237213}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/apsipaasc65261.2025.11248971","is_oa":false,"landing_page_url":"https://doi.org/10.1109/apsipaasc65261.2025.11248971","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":9,"referenced_works":["https://openalex.org/W2194775991","https://openalex.org/W2964043980","https://openalex.org/W2965921687","https://openalex.org/W2989774918","https://openalex.org/W3135231128","https://openalex.org/W4283801341","https://openalex.org/W4288758078","https://openalex.org/W4304782753","https://openalex.org/W4353093982"],"related_works":[],"abstract_inverted_index":{"As":[0],"machine":[1,42],"learning":[2,43,99],"models":[3,12,179],"have":[4],"advanced,":[5],"the":[6,80,136,149,154,187,199,211,240,246,249],"risk":[7],"of":[8,30,39,138,157,165,173,213,248],"attacks":[9],"on":[10,217],"such":[11],"has":[13,143],"also":[14],"increased.":[15],"Typical":[16],"examples":[17],"include":[18],"a":[19,36,40,63,84,114,126,131,139,158,162,170],"poisoning":[20,65],"attack":[21,29,66],"(<tex":[22],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[23,232],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">$\\text{P":[24],"A}$</tex>),":[25],"which":[26,191],"is":[27,61,77,93,192,196],"an":[28,218],"injecting":[31],"some":[32],"\u201cpoisoned\u201d":[33,140],"samples":[34,54,82,104,168,204],"into":[35],"training":[37,103],"dataset":[38,85],"target":[41],"model":[44,141,160],"to":[45,78,95,181,230,239],"degrade":[46],"its":[47,223],"performance.":[48],"In":[49,210],"particular,":[50],"PA":[51,74],"using":[52,161,202],"poisoned":[53,81,159,242],"that":[55,142],"seem":[56],"clean":[57,167],"for":[58,71,134],"human":[59],"eyes":[60],"called":[62],"clean-label":[64],"(CLPA).":[67],"A":[68],"conventional":[69],"approach":[70,92],"defending":[72],"against":[73],"and":[75,169,194],"CLPA":[76],"remove":[79],"from":[83],"before":[86],"training.":[87],"However,":[88],"this":[89,121,123],"prophylactic":[90],"defense":[91,129],"difficult":[94],"implement":[96],"in":[97,113,117],"federated":[98],"(FL)":[100],"environments":[101],"because":[102],"dispersedly":[105],"owned":[106],"by":[107,198,228],"multiple":[108],"clients":[109],"are":[110],"not":[111],"shared":[112],"single":[115],"place":[116],"FL.":[118],"To":[119,146],"address":[120],"problem,":[122],"paper":[124],"proposes":[125],"novel":[127],"therapeutic":[128],"approach:":[130],"\u201cdetoxification\u201d":[132],"method":[133,151,201],"recovering":[135],"performance":[137],"suffered":[144],"CLPA.":[145],"achieve":[147],"detoxification,":[148],"proposed":[150,200,250],"fine-tunes":[152],"only":[153],"network":[155],"head":[156],"small":[163],"set":[164,172],"labeled":[166],"large":[171],"unlabeled":[174],"out-of-distribution":[175],"(OOD)":[176],"samples.":[177],"Poisoned":[178],"tend":[180],"output":[182],"uneven":[183],"confidence":[184],"scores":[185],"near":[186],"ideal":[188],"decision":[189],"boundary,":[190],"undesirable":[193],"therefore":[195],"calibrated":[197],"OOD":[203],"with":[205],"almost":[206],"uniform":[207],"soft":[208],"labels.":[209],"results":[212],"our":[214],"experiments":[215],"conducted":[216],"object":[219],"image":[220],"recognition":[221,224],"model,":[222],"accuracy":[225],"was":[226],"recovered":[227],"up":[229],"<tex":[231],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">$\\text{1":[233],"1.":[234],"9":[235],"8}":[236],"\\%$</tex>":[237],"compared":[238],"original":[241],"model.":[243],"This":[244],"demonstrates":[245],"effectiveness":[247],"method.":[251]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-11-28T00:00:00"}
