{"id":"https://openalex.org/W4386072159","doi":"https://doi.org/10.1109/cvpr52729.2023.01177","title":"Backdoor Defense via Deconfounded Representation Learning","display_name":"Backdoor Defense via Deconfounded Representation Learning","publication_year":2023,"publication_date":"2023-06-01","ids":{"openalex":"https://openalex.org/W4386072159","doi":"https://doi.org/10.1109/cvpr52729.2023.01177"},"language":"en","primary_location":{"id":"doi:10.1109/cvpr52729.2023.01177","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52729.2023.01177","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5063733770","display_name":"Zaixi Zhang","orcid":"https://orcid.org/0000-0002-0380-6558"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]},{"id":"https://openalex.org/I143868143","display_name":"Anhui University","ror":"https://ror.org/05th6yx34","country_code":"CN","type":"education","lineage":["https://openalex.org/I143868143"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Zaixi Zhang","raw_affiliation_strings":["School of Computer Science and Technology, University of Science and Technology of China,Anhui Province Key Lab of Big Data Analysis and Application","State Key Laboratory of Cognitive Intelligence, Hefei, Anhui, China","Anhui Province Key Lab of Big Data Analysis and Application, School of Computer Science and Technology, University of Science and Technology of China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Science and Technology of China,Anhui Province Key Lab of Big Data Analysis and Application","institution_ids":["https://openalex.org/I126520041"]},{"raw_affiliation_string":"State Key Laboratory of Cognitive Intelligence, Hefei, Anhui, China","institution_ids":["https://openalex.org/I143868143"]},{"raw_affiliation_string":"Anhui Province Key Lab of Big Data Analysis and Application, School of Computer Science and Technology, University of Science and Technology of China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100453144","display_name":"Qi Liu","orcid":"https://orcid.org/0000-0001-5378-6404"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]},{"id":"https://openalex.org/I143868143","display_name":"Anhui University","ror":"https://ror.org/05th6yx34","country_code":"CN","type":"education","lineage":["https://openalex.org/I143868143"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qi Liu","raw_affiliation_strings":["School of Computer Science and Technology, University of Science and Technology of China,Anhui Province Key Lab of Big Data Analysis and Application","State Key Laboratory of Cognitive Intelligence, Hefei, Anhui, China","Anhui Province Key Lab of Big Data Analysis and Application, School of Computer Science and Technology, University of Science and Technology of China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Science and Technology of China,Anhui Province Key Lab of Big Data Analysis and Application","institution_ids":["https://openalex.org/I126520041"]},{"raw_affiliation_string":"State Key Laboratory of Cognitive Intelligence, Hefei, Anhui, China","institution_ids":["https://openalex.org/I143868143"]},{"raw_affiliation_string":"Anhui Province Key Lab of Big Data Analysis and Application, School of Computer Science and Technology, University of Science and Technology of China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102971294","display_name":"Zhicai Wang","orcid":"https://orcid.org/0000-0002-3582-7935"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhicai Wang","raw_affiliation_strings":["University of Science and Technology of China"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology of China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069950706","display_name":"Zepu Lu","orcid":"https://orcid.org/0000-0002-8366-4560"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zepu Lu","raw_affiliation_strings":["University of Science and Technology of China"],"affiliations":[{"raw_affiliation_string":"University of Science and Technology of China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5036921959","display_name":"Qingyong Hu","orcid":"https://orcid.org/0000-0003-0337-9207"},"institutions":[{"id":"https://openalex.org/I200769079","display_name":"Hong Kong University of Science and Technology","ror":"https://ror.org/00q4vv597","country_code":"HK","type":"education","lineage":["https://openalex.org/I200769079"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Qingyong Hu","raw_affiliation_strings":["Hong Kong University of Science and Technology"],"affiliations":[{"raw_affiliation_string":"Hong Kong University of Science and Technology","institution_ids":["https://openalex.org/I200769079"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5063733770"],"corresponding_institution_ids":["https://openalex.org/I126520041","https://openalex.org/I143868143"],"apc_list":null,"apc_paid":null,"fwci":5.1379,"has_fulltext":false,"cited_by_count":29,"citation_normalized_percentile":{"value":0.96407085,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"12228","last_page":"12238"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9915000200271606,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9908999800682068,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9938153624534607},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7636582851409912},{"id":"https://openalex.org/keywords/spurious-relationship","display_name":"Spurious relationship","score":0.6745985746383667},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5323171019554138},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5043646097183228},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.39204949140548706},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2650355100631714}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9938153624534607},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7636582851409912},{"id":"https://openalex.org/C97256817","wikidata":"https://www.wikidata.org/wiki/Q1462316","display_name":"Spurious relationship","level":2,"score":0.6745985746383667},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5323171019554138},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5043646097183228},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.39204949140548706},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2650355100631714}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/cvpr52729.2023.01177","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52729.2023.01177","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},{"id":"pmh:oai:repository.hkust.edu.hk:1783.1-133233","is_oa":false,"landing_page_url":"http://repository.hkust.edu.hk/ir/Record/1783.1-133233","pdf_url":null,"source":{"id":"https://openalex.org/S4306401796","display_name":"Rare & Special e-Zone (The Hong Kong University of Science and Technology)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I200769079","host_organization_name":"Hong Kong University of Science and Technology","host_organization_lineage":["https://openalex.org/I200769079"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference paper"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G3424485895","display_name":null,"funder_award_id":"61922073","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":117,"referenced_works":["https://openalex.org/W1607198972","https://openalex.org/W1686946872","https://openalex.org/W2067713319","https://openalex.org/W2108598243","https://openalex.org/W2123713131","https://openalex.org/W2128152674","https://openalex.org/W2143891888","https://openalex.org/W2187089797","https://openalex.org/W2194775991","https://openalex.org/W2739748921","https://openalex.org/W2748789698","https://openalex.org/W2753783305","https://openalex.org/W2774423163","https://openalex.org/W2785678896","https://openalex.org/W2801890059","https://openalex.org/W2803832867","https://openalex.org/W2807363941","https://openalex.org/W2898759955","https://openalex.org/W2916360674","https://openalex.org/W2934843808","https://openalex.org/W2946227741","https://openalex.org/W2962681511","https://openalex.org/W2963305465","https://openalex.org/W2964137095","https://openalex.org/W2966689772","https://openalex.org/W2970335439","https://openalex.org/W2970990331","https://openalex.org/W2971661634","https://openalex.org/W2982223282","https://openalex.org/W2982321964","https://openalex.org/W2982977353","https://openalex.org/W2985913519","https://openalex.org/W2990270730","https://openalex.org/W2996800219","https://openalex.org/W3012113073","https://openalex.org/W3014835904","https://openalex.org/W3023868144","https://openalex.org/W3034258347","https://openalex.org/W3034414373","https://openalex.org/W3035436173","https://openalex.org/W3083185154","https://openalex.org/W3088715381","https://openalex.org/W3093239278","https://openalex.org/W3098528040","https://openalex.org/W3104182862","https://openalex.org/W3107337211","https://openalex.org/W3112001526","https://openalex.org/W3118608800","https://openalex.org/W3119278161","https://openalex.org/W3121478722","https://openalex.org/W3130788031","https://openalex.org/W3135588948","https://openalex.org/W3152758407","https://openalex.org/W3156423484","https://openalex.org/W3166944102","https://openalex.org/W3167334189","https://openalex.org/W3169043433","https://openalex.org/W3170465383","https://openalex.org/W3177934633","https://openalex.org/W3189076644","https://openalex.org/W3199916614","https://openalex.org/W3206057312","https://openalex.org/W3212076252","https://openalex.org/W3213940558","https://openalex.org/W3214636874","https://openalex.org/W3215430231","https://openalex.org/W4214680449","https://openalex.org/W4221141969","https://openalex.org/W4221148936","https://openalex.org/W4226392681","https://openalex.org/W4251465078","https://openalex.org/W4287117242","https://openalex.org/W4287640040","https://openalex.org/W4290948380","https://openalex.org/W4293469690","https://openalex.org/W4293846201","https://openalex.org/W4296338020","https://openalex.org/W4298140072","https://openalex.org/W4304699884","https://openalex.org/W4312280786","https://openalex.org/W4312996082","https://openalex.org/W6637108112","https://openalex.org/W6681673350","https://openalex.org/W6729906282","https://openalex.org/W6741832134","https://openalex.org/W6743581629","https://openalex.org/W6746897123","https://openalex.org/W6748582592","https://openalex.org/W6750462152","https://openalex.org/W6752051073","https://openalex.org/W6754587887","https://openalex.org/W6756046586","https://openalex.org/W6756074407","https://openalex.org/W6756333562","https://openalex.org/W6766336336","https://openalex.org/W6767439381","https://openalex.org/W6770046844","https://openalex.org/W6771747359","https://openalex.org/W6782868315","https://openalex.org/W6783399553","https://openalex.org/W6784392697","https://openalex.org/W6784558051","https://openalex.org/W6784706293","https://openalex.org/W6788785544","https://openalex.org/W6788876066","https://openalex.org/W6789325072","https://openalex.org/W6789730115","https://openalex.org/W6794566239","https://openalex.org/W6795961950","https://openalex.org/W6797239318","https://openalex.org/W6802320626","https://openalex.org/W6803053407","https://openalex.org/W6803432384","https://openalex.org/W6805087021","https://openalex.org/W6809890637","https://openalex.org/W6809905531","https://openalex.org/W6846765560"],"related_works":["https://openalex.org/W2961085424","https://openalex.org/W4306674287","https://openalex.org/W3046775127","https://openalex.org/W3107602296","https://openalex.org/W3170094116","https://openalex.org/W4386462264","https://openalex.org/W4364306694","https://openalex.org/W4312192474","https://openalex.org/W4283697347","https://openalex.org/W4210805261"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"are":[4],"recently":[5],"shown":[6],"to":[7,10,38,72,119,133,143],"be":[8,57],"vulnerable":[9],"backdoor":[11,84,188],"attacks,":[12],"where":[13],"attackers":[14],"embed":[15],"hidden":[16],"backdoors":[17,42],"in":[18,186,194],"the":[19,29,74,83,88,95,102,109,114,135,145,151,155,159],"DNN":[20],"model":[21,55,73,103,129,141,161],"by":[22,108,149],"injecting":[23],"a":[24,52,69,127,164],"few":[25],"poisoned":[26,61,78],"examples":[27],"into":[28],"training":[30],"dataset.":[31],"While":[32],"extensive":[33],"efforts":[34],"have":[35],"been":[36],"made":[37],"detect":[39],"and":[40,80,98,162],"remove":[41],"from":[43,60,158],"backdoored":[44,128,160],"DNNs,":[45],"it":[46],"is":[47,130,184,211],"still":[48],"not":[49],"clear":[50],"whether":[51],"backdoor-free":[53],"clean":[54,140],"can":[56,203],"directly":[58],"obtained":[59],"datasets.":[62],"In":[63],"this":[64],"paper,":[65],"we":[66,112],"first":[67],"construct":[68],"causal":[70,110,147],"graph":[71],"generation":[75],"process":[76],"of":[77],"data":[79],"find":[81],"that":[82,179,201],"attack":[85],"acts":[86],"as":[87],"confounder,":[89],"which":[90],"brings":[91],"spurious":[92],"associations":[93],"between":[94],"input":[96],"images":[97],"target":[99],"labels,":[100],"making":[101],"predictions":[104],"less":[105],"reliable.":[106],"Inspired":[107],"understanding,":[111],"propose":[113],"Causality-inspired":[115],"Backdoor":[116],"Defense":[117],"(CBD),":[118],"learn":[120],"deconfounded":[121],"representations":[122,157],"for":[123],"reliable":[124],"classification.":[125],"Specifically,":[126],"intentionally":[131],"trained":[132],"capture":[134],"confounding":[136,156],"effects.":[137],"The":[138,209],"other":[139],"dedicates":[142],"capturing":[144],"desired":[146],"effects":[148],"minimizing":[150],"mutual":[152],"information":[153],"with":[154],"employing":[163],"sample-wise":[165],"re-weighting":[166],"scheme.":[167],"Extensive":[168],"experiments":[169],"on":[170],"multiple":[171],"benchmark":[172],"datasets":[173],"against":[174],"6":[175],"state-of-the-art":[176],"attacks":[177],"verify":[178],"our":[180],"proposed":[181],"defense":[182],"method":[183],"effective":[185],"reducing":[187],"threats":[189],"while":[190],"maintaining":[191],"high":[192],"accuracy":[193],"predicting":[195],"benign":[196],"samples.":[197],"Further":[198],"analysis":[199],"shows":[200],"CBD":[202],"also":[204],"resist":[205],"potential":[206],"adaptive":[207],"attacks.":[208],"code":[210],"available":[212],"at":[213],"https://github.com/zaixizhang/CBD.":[214]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":15},{"year":2024,"cited_by_count":10},{"year":2023,"cited_by_count":2}],"updated_date":"2026-03-12T08:34:05.389933","created_date":"2025-10-10T00:00:00"}
