{"id":"https://openalex.org/W4408324888","doi":"https://doi.org/10.1109/globecom52923.2024.10901530","title":"Bad-Tuning: Backdooring Vision Transformer Parameter-Efficient Fine-Tuning","display_name":"Bad-Tuning: Backdooring Vision Transformer Parameter-Efficient Fine-Tuning","publication_year":2024,"publication_date":"2024-12-08","ids":{"openalex":"https://openalex.org/W4408324888","doi":"https://doi.org/10.1109/globecom52923.2024.10901530"},"language":"en","primary_location":{"id":"doi:10.1109/globecom52923.2024.10901530","is_oa":false,"landing_page_url":"https://doi.org/10.1109/globecom52923.2024.10901530","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"GLOBECOM 2024 - 2024 IEEE Global Communications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101809713","display_name":"Denghui Li","orcid":"https://orcid.org/0009-0006-7347-206X"},"institutions":[{"id":"https://openalex.org/I181326427","display_name":"Donghua University","ror":"https://ror.org/035psfh38","country_code":"CN","type":"education","lineage":["https://openalex.org/I181326427"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Denghui Li","raw_affiliation_strings":["Donghua University,School of Computer Science and Technology,Shanghai,China"],"affiliations":[{"raw_affiliation_string":"Donghua University,School of Computer Science and Technology,Shanghai,China","institution_ids":["https://openalex.org/I181326427"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101979274","display_name":"Shan Chang","orcid":"https://orcid.org/0000-0002-2911-5624"},"institutions":[{"id":"https://openalex.org/I181326427","display_name":"Donghua University","ror":"https://ror.org/035psfh38","country_code":"CN","type":"education","lineage":["https://openalex.org/I181326427"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shan Chang","raw_affiliation_strings":["Donghua University,School of Computer Science and Technology,Shanghai,China"],"affiliations":[{"raw_affiliation_string":"Donghua University,School of Computer Science and Technology,Shanghai,China","institution_ids":["https://openalex.org/I181326427"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071050711","display_name":"Hongzi Zhu","orcid":"https://orcid.org/0000-0001-8657-5064"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hongzi Zhu","raw_affiliation_strings":["Shanghai Jiao Tong University,Department of Computer Science and Engineering,Shanghai,China"],"affiliations":[{"raw_affiliation_string":"Shanghai Jiao Tong University,Department of Computer Science and Engineering,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5115597990","display_name":"Jie Xu","orcid":"https://orcid.org/0009-0003-4539-6387"},"institutions":[{"id":"https://openalex.org/I181326427","display_name":"Donghua University","ror":"https://ror.org/035psfh38","country_code":"CN","type":"education","lineage":["https://openalex.org/I181326427"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jie Xu","raw_affiliation_strings":["Donghua University,School of Computer Science and Technology,Shanghai,China"],"affiliations":[{"raw_affiliation_string":"Donghua University,School of Computer Science and Technology,Shanghai,China","institution_ids":["https://openalex.org/I181326427"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5036476208","display_name":"Minghui Dai","orcid":"https://orcid.org/0000-0001-9396-5781"},"institutions":[{"id":"https://openalex.org/I181326427","display_name":"Donghua University","ror":"https://ror.org/035psfh38","country_code":"CN","type":"education","lineage":["https://openalex.org/I181326427"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Minghui Dai","raw_affiliation_strings":["Donghua University,School of Computer Science and Technology,Shanghai,China"],"affiliations":[{"raw_affiliation_string":"Donghua University,School of Computer Science and Technology,Shanghai,China","institution_ids":["https://openalex.org/I181326427"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5101809713"],"corresponding_institution_ids":["https://openalex.org/I181326427"],"apc_list":null,"apc_paid":null,"fwci":0.222,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.57800837,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"3889","last_page":"3894"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11992","display_name":"CCD and CMOS Imaging Sensors","score":0.9876999855041504,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11992","display_name":"CCD and CMOS Imaging Sensors","score":0.9876999855041504,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12389","display_name":"Infrared Target Detection Methodologies","score":0.9472000002861023,"subfield":{"id":"https://openalex.org/subfields/2202","display_name":"Aerospace Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11408","display_name":"Advanced Optical Imaging Technologies","score":0.9377999901771545,"subfield":{"id":"https://openalex.org/subfields/2214","display_name":"Media Technology"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.6005777716636658},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.5755066871643066},{"id":"https://openalex.org/keywords/control-theory","display_name":"Control theory (sociology)","score":0.41568389534950256},{"id":"https://openalex.org/keywords/electronic-engineering","display_name":"Electronic engineering","score":0.32954972982406616},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.31336909532546997},{"id":"https://openalex.org/keywords/voltage","display_name":"Voltage","score":0.21618828177452087},{"id":"https://openalex.org/keywords/electrical-engineering","display_name":"Electrical engineering","score":0.20217016339302063},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.1802806556224823}],"concepts":[{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.6005777716636658},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5755066871643066},{"id":"https://openalex.org/C47446073","wikidata":"https://www.wikidata.org/wiki/Q5165890","display_name":"Control theory (sociology)","level":3,"score":0.41568389534950256},{"id":"https://openalex.org/C24326235","wikidata":"https://www.wikidata.org/wiki/Q126095","display_name":"Electronic engineering","level":1,"score":0.32954972982406616},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.31336909532546997},{"id":"https://openalex.org/C165801399","wikidata":"https://www.wikidata.org/wiki/Q25428","display_name":"Voltage","level":2,"score":0.21618828177452087},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.20217016339302063},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.1802806556224823},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/globecom52923.2024.10901530","is_oa":false,"landing_page_url":"https://doi.org/10.1109/globecom52923.2024.10901530","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"GLOBECOM 2024 - 2024 IEEE Global Communications Conference","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Affordable and clean energy","score":0.6299999952316284,"id":"https://metadata.un.org/sdg/7"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320309612","display_name":"Natural Science Foundation of Shanghai","ror":null},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W2942091739","https://openalex.org/W2970335439","https://openalex.org/W3107337211","https://openalex.org/W3217804443","https://openalex.org/W4280647927","https://openalex.org/W4312569687","https://openalex.org/W4312651322","https://openalex.org/W4386066003","https://openalex.org/W4386075825","https://openalex.org/W4386159930","https://openalex.org/W6746897123","https://openalex.org/W6784333009","https://openalex.org/W6785440099","https://openalex.org/W6789325072","https://openalex.org/W6838701581"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"Parameter-efficient":[0],"fine-tuning":[1,100],"(PEFT)":[2],"on":[3,168,210],"pre-trained":[4,19,74],"models":[5],"is":[6],"a":[7,18,25,47,58,117],"new":[8,48],"paradigm":[9],"for":[10,50,82],"model":[11,20],"training,":[12],"where":[13],"the":[14,42,63,72,80,83,87,92,97,122,139,143,162,172,206],"majority":[15],"parameters":[16,32],"of":[17,28,86,102,154,164,177,193],"are":[21,107,201],"frozen,":[22],"left":[23],"only":[24,197],"small":[26],"number":[27],"unfrozen":[29,93],"(or":[30],"additional)":[31],"to":[33,160],"be":[34,113,125],"tuned.":[35],"PEFT":[36,111],"demonstrates":[37],"its":[38],"effectiveness":[39],"in":[40],"fitting":[41],"downstream":[43],"tasks,":[44],"while":[45],"introducing":[46],"surface":[49],"backdoor":[51,60,134,208],"attacks.":[52],"In":[53],"this":[54],"paper,":[55],"we":[56],"design":[57],"novel":[59],"attack":[61,189],"towards":[62],"Vision":[64],"Transformer":[65],"(ViT)":[66],"PEFT,":[67],"called":[68],"Bad-Tuning.":[69],"To":[70,136],"mislead":[71],"target":[73],"model,":[75,88],"Bad-Tuning":[76,141,178,185,204],"first":[77],"purposefully":[78],"tailors":[79],"trigger":[81,98,123,144],"frozen":[84],"portion":[85],"and":[89,156,175,182,213],"then":[90],"backdoors":[91],"part":[94],"by":[95,128,145],"injecting":[96],"into":[99],"samples":[101,200],"PEFT.":[103],"The":[104],"main":[105],"challenges":[106],"two-fold.":[108],"First,":[109],"backdooring":[110],"should":[112,124],"highly":[114],"efficient":[115],"with":[116,138],"few":[118],"backdoored":[119,199],"samples.":[120],"Second,":[121],"hardly":[126],"noticed":[127],"human":[129],"beings":[130],"as":[131,133],"well":[132],"scanners.":[135],"deal":[137],"challenges,":[140],"optimizes":[142],"learning":[146],"CLS":[147],"sequences":[148],"which":[149],"represent":[150],"rich":[151],"deep":[152],"semantics":[153],"samples,":[155],"introduces":[157],"color":[158],"loss":[159],"evaluate":[161],"invisibility":[163,176,214],"triggers.":[165],"Extensive":[166],"experiments":[167],"different":[169],"datasets":[170],"demonstrate":[171],"effectiveness,":[173],"efficiency":[174],"under":[179],"both":[180,211],"white-box":[181],"gray-box":[183],"scenarios.":[184],"achieves":[186],"an":[187],"average":[188],"success":[190],"rate":[191],"(ASR)":[192],"over":[194],"99.9%":[195],"even":[196],"0.1%":[198],"injected.":[202],"Moreover,":[203],"outperforms":[205],"SOTA":[207],"attacks":[209],"ASR":[212],"(SSIM).":[215]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-12-23T23:11:35.936235","created_date":"2025-10-10T00:00:00"}
