{"id":"https://openalex.org/W3013170989","doi":"https://doi.org/10.1109/isqed48828.2020.9137011","title":"A Survey on Neural Trojans","display_name":"A Survey on Neural Trojans","publication_year":2020,"publication_date":"2020-03-01","ids":{"openalex":"https://openalex.org/W3013170989","doi":"https://doi.org/10.1109/isqed48828.2020.9137011","mag":"3013170989"},"language":"en","primary_location":{"id":"doi:10.1109/isqed48828.2020.9137011","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isqed48828.2020.9137011","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 21st International Symposium on Quality Electronic Design (ISQED)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100657633","display_name":"Yuntao Liu","orcid":"https://orcid.org/0000-0001-8213-582X"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yuntao Liu","raw_affiliation_strings":["University of Maryland, College Park"],"affiliations":[{"raw_affiliation_string":"University of Maryland, College Park","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013349608","display_name":"Ankit Mondal","orcid":"https://orcid.org/0000-0002-9847-4225"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ankit Mondal","raw_affiliation_strings":["University of Maryland, College Park"],"affiliations":[{"raw_affiliation_string":"University of Maryland, College Park","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102743445","display_name":"Abhishek Chakraborty","orcid":"https://orcid.org/0000-0003-2948-6326"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Abhishek Chakraborty","raw_affiliation_strings":["University of Maryland, College Park"],"affiliations":[{"raw_affiliation_string":"University of Maryland, College Park","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077915520","display_name":"Michael Zuzak","orcid":"https://orcid.org/0000-0003-0356-9393"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michael Zuzak","raw_affiliation_strings":["University of Maryland, College Park"],"affiliations":[{"raw_affiliation_string":"University of Maryland, College Park","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5024917509","display_name":"Nina Jacobsen","orcid":null},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nina Jacobsen","raw_affiliation_strings":["University of Maryland, College Park"],"affiliations":[{"raw_affiliation_string":"University of Maryland, College Park","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5088110281","display_name":"Daniel Xing","orcid":"https://orcid.org/0000-0003-3661-746X"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Daniel Xing","raw_affiliation_strings":["University of Maryland, College Park"],"affiliations":[{"raw_affiliation_string":"University of Maryland, College Park","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5089770783","display_name":"Ankur Srivastava","orcid":"https://orcid.org/0000-0002-5445-904X"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ankur Srivastava","raw_affiliation_strings":["University of Maryland, College Park"],"affiliations":[{"raw_affiliation_string":"University of Maryland, College Park","institution_ids":["https://openalex.org/I66946132"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5100657633"],"corresponding_institution_ids":["https://openalex.org/I66946132"],"apc_list":null,"apc_paid":null,"fwci":1.46859549,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.84472312,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":97,"max":98},"biblio":{"volume":"2020","issue":null,"first_page":"33","last_page":"39"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9613999724388123,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11636","display_name":"Artificial Intelligence in Healthcare and Education","score":0.9363999962806702,"subfield":{"id":"https://openalex.org/subfields/2718","display_name":"Health Informatics"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.9678812026977539},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.749444842338562},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7301600575447083},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5665560960769653},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.42511245608329773},{"id":"https://openalex.org/keywords/replica","display_name":"Replica","score":0.4239400625228882},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3870019018650055},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.07456377148628235}],"concepts":[{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.9678812026977539},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.749444842338562},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7301600575447083},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5665560960769653},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.42511245608329773},{"id":"https://openalex.org/C2775937380","wikidata":"https://www.wikidata.org/wiki/Q1232589","display_name":"Replica","level":2,"score":0.4239400625228882},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3870019018650055},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.07456377148628235},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/isqed48828.2020.9137011","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isqed48828.2020.9137011","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 21st International Symposium on Quality Electronic Design (ISQED)","raw_type":"proceedings-article"},{"id":"mag:3013170989","is_oa":false,"landing_page_url":"https://eprint.iacr.org/2020/201.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S2764847869","display_name":"IACR Cryptology ePrint Archive","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":["https://openalex.org/P4322614454"],"host_organization_lineage_names":["Cryptology ePrint Archive"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IACR Cryptology ePrint Archive","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":50,"referenced_works":["https://openalex.org/W1534499320","https://openalex.org/W2095577883","https://openalex.org/W2144906988","https://openalex.org/W2180612164","https://openalex.org/W2536560766","https://openalex.org/W2603766943","https://openalex.org/W2753783305","https://openalex.org/W2775907600","https://openalex.org/W2807363941","https://openalex.org/W2892908011","https://openalex.org/W2899585792","https://openalex.org/W2901232240","https://openalex.org/W2914712270","https://openalex.org/W2921624216","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2947864246","https://openalex.org/W2948833786","https://openalex.org/W2962939738","https://openalex.org/W2970335439","https://openalex.org/W2977663466","https://openalex.org/W2985913519","https://openalex.org/W2986013765","https://openalex.org/W2989358546","https://openalex.org/W4252979261","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6676935882","https://openalex.org/W6696889897","https://openalex.org/W6714069269","https://openalex.org/W6734354522","https://openalex.org/W6746897123","https://openalex.org/W6747838042","https://openalex.org/W6752765571","https://openalex.org/W6754587887","https://openalex.org/W6756074407","https://openalex.org/W6756333562","https://openalex.org/W6760072027","https://openalex.org/W6765584535","https://openalex.org/W6766253520","https://openalex.org/W6766908529","https://openalex.org/W6766938892","https://openalex.org/W6767031719","https://openalex.org/W6767346468","https://openalex.org/W6767631518","https://openalex.org/W6767870943","https://openalex.org/W6768126957","https://openalex.org/W6769209188","https://openalex.org/W6769860221","https://openalex.org/W6770375775"],"related_works":["https://openalex.org/W3041840141","https://openalex.org/W2774423163","https://openalex.org/W2772825438","https://openalex.org/W3034579202","https://openalex.org/W2798312912","https://openalex.org/W2962939738","https://openalex.org/W2782017703","https://openalex.org/W2400831429","https://openalex.org/W3146432957","https://openalex.org/W3161920451","https://openalex.org/W3107337211","https://openalex.org/W2990270730","https://openalex.org/W2889233174","https://openalex.org/W2753783305","https://openalex.org/W2748789698","https://openalex.org/W3181659975","https://openalex.org/W2403270168","https://openalex.org/W2891115613","https://openalex.org/W2019393140","https://openalex.org/W3013345136"],"abstract_inverted_index":{"Neural":[0],"networks":[1],"have":[2,115,208],"become":[3],"increasingly":[4],"prevalent":[5],"in":[6,75,218,264],"many":[7],"real-world":[8],"applications":[9],"including":[10],"security":[11],"critical":[12],"ones.":[13],"Due":[14],"to":[15,23,33,90,179,250],"the":[16,40,43,57,76,84,119,129,133,154,157,169,175,181,185,193,200,205,219,226,230,236,258],"high":[17],"hardware":[18],"requirement":[19],"and":[20,111,160,234,261],"time":[21],"consumption":[22],"train":[24],"high-performance":[25],"neural":[26,98,108,125,182,201,216,231,245],"network":[27,78,183,232],"models,":[28],"users":[29],"often":[30],"outsource":[31],"training":[32,58,147,194],"a":[34,61,66,105,124,138,161],"machine-learning-as-a-service":[35],"(MLaaS)":[36],"provider.":[37],"This":[38],"puts":[39],"integrity":[41],"of":[42,65,93,107,142,163,254],"trained":[44,77],"model":[45,220],"at":[46,204],"risk.":[47],"In":[48,100,123,149],"2017,":[49],"Liu":[50],"et":[51],"al.":[52],"found":[53],"that,":[54],"by":[55,83],"mixing":[56],"data":[59,172],"with":[60,146,199],"few":[62,121],"malicious":[63,95],"samples":[64],"certain":[67],"trigger":[68,85,168,223],"pattern,":[69],"hidden":[70,94],"functionality":[71,96,159,228],"can":[72,80,131,247],"be":[73,81,132,248],"embedded":[74],"which":[79],"evoked":[82],"pattern":[86],"[33].":[87],"We":[88,256],"refer":[89],"this":[91,101,265],"kind":[92],"as":[97],"Trojans.":[99],"paper,":[102],"we":[103],"survey":[104],"myriad":[106],"Trojan":[109,126,186,188,222],"attack":[110,260],"defense":[112,262],"techniques":[113,213],"that":[114,166,191,242],"been":[116,210],"proposed":[117],"over":[118],"last":[120],"years.":[122],"insertion":[127],"attack,":[128],"attacker":[130,155],"MLaaS":[134],"provider":[135],"itself":[136],"or":[137,144,196],"third":[139],"party":[140],"capable":[141],"adding":[143],"tampering":[145],"data.":[148],"most":[150,176],"research":[151],"on":[152],"attacks,":[153],"selects":[156],"Trojan's":[158,227],"set":[162],"input":[164],"patterns":[165],"will":[167],"Trojan.":[170,237],"Training":[171],"poisoning":[173],"is":[174],"common":[177],"way":[178],"make":[180],"acquire":[184],"functionality.":[187],"embedding":[189],"methods":[190],"modify":[192],"algorithm":[195],"directly":[197],"interfere":[198],"network's":[202],"execution":[203],"binary":[206],"level":[207],"also":[209,240],"studied.":[211],"Defense":[212],"include":[214],"detecting":[215],"Trojans":[217,246],"and/or":[221],"patterns,":[224],"erasing":[225],"from":[229],"model,":[233],"bypassing":[235],"It":[238],"was":[239],"shown":[241],"carefully":[243],"crafted":[244],"used":[249],"mitigate":[251],"other":[252],"types":[253],"attacks.":[255],"systematize":[257],"above":[259],"approaches":[263],"paper.":[266]},"counts_by_year":[{"year":2021,"cited_by_count":5},{"year":2020,"cited_by_count":5}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
