{"id":"https://openalex.org/W4392607802","doi":"https://doi.org/10.1109/tai.2024.3373720","title":"A Subspace Projective Clustering Approach for Backdoor Attack Detection and Mitigation in Deep Neural Networks","display_name":"A Subspace Projective Clustering Approach for Backdoor Attack Detection and Mitigation in Deep Neural Networks","publication_year":2024,"publication_date":"2024-03-08","ids":{"openalex":"https://openalex.org/W4392607802","doi":"https://doi.org/10.1109/tai.2024.3373720"},"language":"en","primary_location":{"id":"doi:10.1109/tai.2024.3373720","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tai.2024.3373720","pdf_url":null,"source":{"id":"https://openalex.org/S4210169448","display_name":"IEEE Transactions on Artificial Intelligence","issn_l":"2691-4581","issn":["2691-4581"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056854495","display_name":"Yue Wang","orcid":"https://orcid.org/0000-0002-9260-3970"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yue Wang","raw_affiliation_strings":["Department of Electrical and Computer Engineering, Tandon School of Engineering, New York University, Brooklyn, NY, USA","Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA"],"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, Tandon School of Engineering, New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]},{"raw_affiliation_string":"Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027023288","display_name":"Wenqing Li","orcid":"https://orcid.org/0000-0001-5612-9899"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wenqing Li","raw_affiliation_strings":["Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE"],"affiliations":[{"raw_affiliation_string":"Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054288765","display_name":"Esha Sarkar","orcid":"https://orcid.org/0000-0002-4473-7368"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Esha Sarkar","raw_affiliation_strings":["Department of Electrical and Computer Engineering, Tandon School of Engineering, New York University, Brooklyn, NY, USA","Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA"],"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, Tandon School of Engineering, New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]},{"raw_affiliation_string":"Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005190949","display_name":"Muhammad Shafique","orcid":"https://orcid.org/0000-0002-2607-8135"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Muhammad Shafique","raw_affiliation_strings":["Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE","Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA"],"affiliations":[{"raw_affiliation_string":"Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE","institution_ids":[]},{"raw_affiliation_string":"Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043325974","display_name":"Michail Maniatakos","orcid":"https://orcid.org/0000-0001-6899-0651"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michail Maniatakos","raw_affiliation_strings":["Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE","Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA"],"affiliations":[{"raw_affiliation_string":"Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE","institution_ids":[]},{"raw_affiliation_string":"Department of Electrical and Computer Engineering, Tandon school of Engineering, New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5061466757","display_name":"Saif Eddin Jabari","orcid":"https://orcid.org/0000-0002-2314-5312"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Saif Eddin Jabari","raw_affiliation_strings":["Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE","Department of Civil and Urban Engineering, Tandon School of Engineering, New York University, Brooklyn, NY, USA"],"affiliations":[{"raw_affiliation_string":"Division of Engineering, New York University Abu Dhabi, Abu Dhabi, UAE","institution_ids":[]},{"raw_affiliation_string":"Department of Civil and Urban Engineering, Tandon School of Engineering, New York University, Brooklyn, NY, USA","institution_ids":["https://openalex.org/I57206974"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5056854495"],"corresponding_institution_ids":["https://openalex.org/I57206974"],"apc_list":null,"apc_paid":null,"fwci":1.4602,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.83404961,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":"5","issue":"7","first_page":"3497","last_page":"3509"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9000683426856995},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.6327593922615051},{"id":"https://openalex.org/keywords/subspace-topology","display_name":"Subspace topology","score":0.5837429165840149},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5562119483947754},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.5141223073005676},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4983859062194824},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.4947633147239685},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.4360281527042389},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.1514934003353119}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9000683426856995},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.6327593922615051},{"id":"https://openalex.org/C32834561","wikidata":"https://www.wikidata.org/wiki/Q660730","display_name":"Subspace topology","level":2,"score":0.5837429165840149},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5562119483947754},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.5141223073005676},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4983859062194824},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4947633147239685},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.4360281527042389},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.1514934003353119}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tai.2024.3373720","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tai.2024.3373720","pdf_url":null,"source":{"id":"https://openalex.org/S4210169448","display_name":"IEEE Transactions on Artificial Intelligence","issn_l":"2691-4581","issn":["2691-4581"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.8199999928474426,"display_name":"Climate action","id":"https://metadata.un.org/sdg/13"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":54,"referenced_works":["https://openalex.org/W1985690171","https://openalex.org/W1993962865","https://openalex.org/W2040975718","https://openalex.org/W2163922914","https://openalex.org/W2165916500","https://openalex.org/W2194775991","https://openalex.org/W2342792901","https://openalex.org/W2751584934","https://openalex.org/W2768149277","https://openalex.org/W2774423163","https://openalex.org/W2898759955","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2963178695","https://openalex.org/W2963446712","https://openalex.org/W2964080999","https://openalex.org/W2965527544","https://openalex.org/W2966187620","https://openalex.org/W2979584253","https://openalex.org/W2985913519","https://openalex.org/W2986013765","https://openalex.org/W2988471847","https://openalex.org/W2996800219","https://openalex.org/W3000280594","https://openalex.org/W3004639598","https://openalex.org/W3012113073","https://openalex.org/W3019166713","https://openalex.org/W3034258347","https://openalex.org/W3034579202","https://openalex.org/W3042633958","https://openalex.org/W3044063956","https://openalex.org/W3074128044","https://openalex.org/W3081178496","https://openalex.org/W3083185154","https://openalex.org/W3107337211","https://openalex.org/W3108535146","https://openalex.org/W3113332968","https://openalex.org/W3121099749","https://openalex.org/W3159143330","https://openalex.org/W3171398265","https://openalex.org/W3195462295","https://openalex.org/W3202773188","https://openalex.org/W4283792797","https://openalex.org/W4288093767","https://openalex.org/W4289300166","https://openalex.org/W4360753265","https://openalex.org/W4390874086","https://openalex.org/W6746897123","https://openalex.org/W6756074407","https://openalex.org/W6756333562","https://openalex.org/W6766253520","https://openalex.org/W6767183785","https://openalex.org/W6770286897","https://openalex.org/W6776469819"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W4386185023"],"abstract_inverted_index":{"Backdoor":[0],"attacks":[1,35,156],"in":[2,68,127,152,171],"Deep":[3],"Neural":[4],"Networks":[5],"(DNNs)":[6],"involve":[7],"an":[8],"attacker":[9,41],"inserting":[10],"a":[11,28,59,75,94,104,109,115,128],"backdoor":[12,155],"into":[13],"the":[14,18,40,43,52,55,79,120,133,147,174,185,192],"network":[15],"by":[16,113],"manipulating":[17],"training":[19],"dataset,":[20],"which":[21,71,102],"causes":[22],"misclassification":[23],"of":[24,62,81,135,149,161,184,191],"inputs":[25],"that":[26,51,157],"contain":[27],"specific":[29],"trigger.":[30],"Detecting":[31],"and":[32,45,64,119,142,168,188],"mitigating":[33],"such":[34],"is":[36],"challenging":[37],"as":[38,106,108],"only":[39],"knows":[42],"trigger":[44],"target":[46],"class.":[47],"Our":[48,177],"study":[49],"demonstrates":[50],"representations,":[53],"i.e.,":[54],"neuron":[56],"activations":[57],"for":[58],"given":[60],"DNN,":[61],"poisoned":[63,162,193],"genuine":[65],"data":[66,85],"lie":[67],"different":[69,84,159],"subspaces,":[70],"implies":[72],"there":[73],"exists":[74],"certain":[76],"subspace":[77,98,105],"where":[78],"difference":[80],"projections":[82],"from":[83],"can":[86,124,179],"be":[87,125],"manifested.":[88],"To":[89],"this":[90],"end,":[91],"we":[92,145],"propose":[93],"method":[95,151],"based":[96],"on":[97,138,164],"projective":[99],"clustering":[100,129],"(SPC),":[101],"learns":[103],"well":[107],"projection-based":[110],"weight":[111,122],"vector":[112,123],"solving":[114],"projection":[116],"maximization":[117],"program,":[118],"optimized":[121],"utilized":[126],"framework":[130],"to":[131],"infer":[132],"group":[134],"data.":[136],"Based":[137],"our":[139,150],"theoretical":[140],"analysis":[141],"experimental":[143],"results,":[144],"demonstrate":[146],"effectiveness":[148],"defending":[153],"against":[154],"use":[158],"settings":[160],"samples":[163],"GTSRB,":[165],"Imagenet,":[166],"VGGFace2":[167],"PubFig":[169],"datasets":[170],"comparison":[172],"with":[173],"state-of-the-art":[175],"methods.":[176],"algorithm":[178],"detect":[180],"more":[181],"than":[182],"90%":[183],"infected":[186],"classes":[187],"identify":[189],"95%":[190],"samples.":[194]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2024-03-09T00:00:00"}
