{"id":"https://openalex.org/W4385569687","doi":"https://doi.org/10.1109/tcsi.2023.3298802","title":"An Imperceptible Data Augmentation Based Blackbox Clean-Label Backdoor Attack on Deep Neural Networks","display_name":"An Imperceptible Data Augmentation Based Blackbox Clean-Label Backdoor Attack on Deep Neural Networks","publication_year":2023,"publication_date":"2023-08-04","ids":{"openalex":"https://openalex.org/W4385569687","doi":"https://doi.org/10.1109/tcsi.2023.3298802"},"language":"en","primary_location":{"id":"doi:10.1109/tcsi.2023.3298802","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tcsi.2023.3298802","pdf_url":null,"source":{"id":"https://openalex.org/S116977442","display_name":"IEEE Transactions on Circuits and Systems I Regular Papers","issn_l":"1549-8328","issn":["1549-8328","1558-0806"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Circuits and Systems I: Regular Papers","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://dr.ntu.edu.sg/bitstream/10356/173118/2/TCAS-I_camera_ready.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5044945662","display_name":"Chaohui Xu","orcid":"https://orcid.org/0009-0002-1814-5016"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Chaohui Xu","raw_affiliation_strings":["School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"],"raw_orcid":"https://orcid.org/0009-0002-1814-5016","affiliations":[{"raw_affiliation_string":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000387478","display_name":"Wenye Liu","orcid":"https://orcid.org/0000-0003-4590-5367"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Wenye Liu","raw_affiliation_strings":["School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"],"raw_orcid":"https://orcid.org/0000-0003-4590-5367","affiliations":[{"raw_affiliation_string":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061840305","display_name":"Yue Zheng","orcid":"https://orcid.org/0000-0002-4992-6475"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Yue Zheng","raw_affiliation_strings":["School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"],"raw_orcid":"https://orcid.org/0000-0002-4992-6475","affiliations":[{"raw_affiliation_string":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100651867","display_name":"Si Wang","orcid":"https://orcid.org/0000-0003-2431-0612"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Si Wang","raw_affiliation_strings":["School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5029335324","display_name":"Chip-Hong Chang","orcid":"https://orcid.org/0000-0002-8897-6176"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Chip-Hong Chang","raw_affiliation_strings":["School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"],"raw_orcid":"https://orcid.org/0000-0002-8897-6176","affiliations":[{"raw_affiliation_string":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore","institution_ids":["https://openalex.org/I172675005"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.7948,"has_fulltext":true,"cited_by_count":11,"citation_normalized_percentile":{"value":0.87936958,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":"70","issue":"12","first_page":"5011","last_page":"5024"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.947700023651123,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9397000074386597,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9762768149375916},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7475027441978455},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.6745474934577942},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5493516325950623},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4967415928840637},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4688504636287689},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4624616801738739},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.34396642446517944},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3065897226333618}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9762768149375916},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7475027441978455},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.6745474934577942},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5493516325950623},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4967415928840637},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4688504636287689},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4624616801738739},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.34396642446517944},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3065897226333618},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tcsi.2023.3298802","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tcsi.2023.3298802","pdf_url":null,"source":{"id":"https://openalex.org/S116977442","display_name":"IEEE Transactions on Circuits and Systems I Regular Papers","issn_l":"1549-8328","issn":["1549-8328","1558-0806"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Circuits and Systems I: Regular Papers","raw_type":"journal-article"},{"id":"pmh:oai:dr.ntu.edu.sg:10356/173118","is_oa":true,"landing_page_url":"https://hdl.handle.net/10356/173118","pdf_url":"https://dr.ntu.edu.sg/bitstream/10356/173118/2/TCAS-I_camera_ready.pdf","source":{"id":"https://openalex.org/S4306402609","display_name":"DR-NTU (Nanyang Technological University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I172675005","host_organization_name":"Nanyang Technological University","host_organization_lineage":["https://openalex.org/I172675005"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Journal Article"}],"best_oa_location":{"id":"pmh:oai:dr.ntu.edu.sg:10356/173118","is_oa":true,"landing_page_url":"https://hdl.handle.net/10356/173118","pdf_url":"https://dr.ntu.edu.sg/bitstream/10356/173118/2/TCAS-I_camera_ready.pdf","source":{"id":"https://openalex.org/S4306402609","display_name":"DR-NTU (Nanyang Technological University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I172675005","host_organization_name":"Nanyang Technological University","host_organization_lineage":["https://openalex.org/I172675005"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Journal Article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5928885788","display_name":null,"funder_award_id":"NRF2018NCR-NCR009-0001","funder_id":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore"},{"id":"https://openalex.org/G6854926366","display_name":null,"funder_award_id":"Tier 2","funder_id":"https://openalex.org/F4320320751","funder_display_name":"Ministry of Education - Singapore"},{"id":"https://openalex.org/G982644696","display_name":null,"funder_award_id":"CHFA-GC1-AW01","funder_id":"https://openalex.org/F4320320709","funder_display_name":"National Research Foundation Singapore"}],"funders":[{"id":"https://openalex.org/F4320320671","display_name":"National Research Foundation","ror":"https://ror.org/05s0g1g46"},{"id":"https://openalex.org/F4320320709","display_name":"National Research Foundation Singapore","ror":"https://ror.org/03cpyc314"},{"id":"https://openalex.org/F4320320751","display_name":"Ministry of Education - Singapore","ror":"https://ror.org/01kcva023"},{"id":"https://openalex.org/F4320322724","display_name":"Ministry of Education, India","ror":"https://ror.org/048xjjh50"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4385569687.pdf","grobid_xml":"https://content.openalex.org/works/W4385569687.grobid-xml"},"referenced_works_count":78,"referenced_works":["https://openalex.org/W1686810756","https://openalex.org/W1834627138","https://openalex.org/W1836465849","https://openalex.org/W1955857676","https://openalex.org/W1964859077","https://openalex.org/W2031489346","https://openalex.org/W2064076387","https://openalex.org/W2095705004","https://openalex.org/W2107397716","https://openalex.org/W2108598243","https://openalex.org/W2112507308","https://openalex.org/W2133665775","https://openalex.org/W2194775991","https://openalex.org/W2399587145","https://openalex.org/W2618530766","https://openalex.org/W2741594031","https://openalex.org/W2753783305","https://openalex.org/W2774423163","https://openalex.org/W2792643794","https://openalex.org/W2807363941","https://openalex.org/W2905810447","https://openalex.org/W2907271713","https://openalex.org/W2914712270","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2943491685","https://openalex.org/W2946227741","https://openalex.org/W2954996726","https://openalex.org/W2955425717","https://openalex.org/W2962785568","https://openalex.org/W2962858109","https://openalex.org/W2963446712","https://openalex.org/W2966689772","https://openalex.org/W2970335439","https://openalex.org/W2971661634","https://openalex.org/W2986013765","https://openalex.org/W2990270730","https://openalex.org/W2996800219","https://openalex.org/W3010216907","https://openalex.org/W3012113073","https://openalex.org/W3083185154","https://openalex.org/W3090898103","https://openalex.org/W3102564565","https://openalex.org/W3107337211","https://openalex.org/W3114686421","https://openalex.org/W3118608800","https://openalex.org/W3130788031","https://openalex.org/W3152758407","https://openalex.org/W3162804012","https://openalex.org/W3212023986","https://openalex.org/W3214636874","https://openalex.org/W4214680449","https://openalex.org/W4252979261","https://openalex.org/W4287556596","https://openalex.org/W4287998266","https://openalex.org/W4288094728","https://openalex.org/W4289300166","https://openalex.org/W4293929015","https://openalex.org/W4298140072","https://openalex.org/W4304140713","https://openalex.org/W6637373629","https://openalex.org/W6638667902","https://openalex.org/W6674330103","https://openalex.org/W6676935882","https://openalex.org/W6681673350","https://openalex.org/W6684191040","https://openalex.org/W6712837096","https://openalex.org/W6746897123","https://openalex.org/W6747321236","https://openalex.org/W6749029207","https://openalex.org/W6750462152","https://openalex.org/W6756074407","https://openalex.org/W6762718338","https://openalex.org/W6770897281","https://openalex.org/W6787972765","https://openalex.org/W6789325072","https://openalex.org/W6803053407","https://openalex.org/W6803329306"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W3015678314","https://openalex.org/W4281902577","https://openalex.org/W4200629851","https://openalex.org/W4379116102","https://openalex.org/W3210882018","https://openalex.org/W4388858813","https://openalex.org/W2970990331","https://openalex.org/W3207178610","https://openalex.org/W3211782752"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"have":[4],"permeated":[5],"into":[6],"many":[7],"diverse":[8],"application":[9],"domains,":[10],"making":[11],"them":[12],"attractive":[13],"targets":[14],"of":[15,63,70,116,205],"malicious":[16],"attacks.":[17,25],"DNNs":[18],"are":[19,120,191],"particularly":[20],"susceptible":[21],"to":[22,35,75,81,133,136,143],"data":[23,106],"poisoning":[24,38],"Such":[26],"attacks":[27],"can":[28],"be":[29],"made":[30],"more":[31],"venomous":[32],"and":[33,57,68,128,139,157,177,211],"harder":[34],"detect":[36],"by":[37,103,123],"the":[39,50,71,77,110,117,125,195,206],"training":[40],"samples":[41],"without":[42],"changing":[43],"their":[44,134],"ground-truth":[45],"labels.":[46],"Despite":[47],"its":[48,129],"pragmatism,":[49],"clean-label":[51,162],"requirement":[52],"imposes":[53],"a":[54,82],"stiff":[55],"restriction":[56],"strong":[58],"conflict":[59],"in":[60],"simultaneous":[61],"optimization":[62],"attack":[64,149,174,188],"stealth,":[65],"success":[66,175,189],"rate,":[67,85,169,176],"utility":[69],"poisoned":[72,171,207],"model.":[73],"Attempts":[74],"circumvent":[76],"pitfalls":[78],"often":[79],"lead":[80],"high":[83,184],"injection":[84,168],"ineffective":[86],"embedded":[87],"backdoors,":[88],"unnatural":[89],"triggers,":[90],"low":[91],"transferability,":[92],"and/or":[93],"poor":[94],"robustness.":[95],"In":[96],"this":[97],"paper,":[98],"we":[99],"overcome":[100],"these":[101],"constraints":[102],"amalgamating":[104],"different":[105,154],"augmentation":[107,118],"techniques":[108],"for":[109],"backdoor":[111,163,179],"trigger.":[112],"The":[113],"spatial":[114],"intensities":[115],"methods":[119],"iteratively":[121],"adjusted":[122],"interpolating":[124],"clean":[126],"sample":[127],"augmented":[130,140],"version":[131],"according":[132],"tolerance":[135],"perceptual":[137],"loss":[138],"feature":[141],"saliency":[142],"target":[144],"class":[145],"activation.":[146],"Our":[147],"proposed":[148],"is":[150],"comprehensively":[151],"evaluated":[152],"on":[153,194],"network":[155],"models":[156],"datasets.":[158],"Compared":[159],"with":[160],"state-of-the-art":[161],"attacks,":[164],"it":[165],"has":[166],"lower":[167],"stealthier":[170],"samples,":[172],"higher":[173],"greater":[178],"mitigation":[180],"resistance":[181],"while":[182],"preserving":[183],"benign":[185],"accuracy.":[186],"Similar":[187],"rates":[190],"also":[192],"demonstrated":[193],"Intel":[196],"Neural":[197],"Compute":[198],"Stick":[199],"2":[200],"edge":[201],"AI":[202],"device":[203],"implementation":[204],"model":[208],"after":[209],"weight-pruning":[210],"quantization.":[212]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":4},{"year":2023,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
