{"id":"https://openalex.org/W7105839785","doi":"https://doi.org/10.1109/tetc.2025.3631134","title":"IsBad: Imperceptible Sample-Specific Backdoor to DNN With Denoising Autoencoder","display_name":"IsBad: Imperceptible Sample-Specific Backdoor to DNN With Denoising Autoencoder","publication_year":2025,"publication_date":"2025-11-17","ids":{"openalex":"https://openalex.org/W7105839785","doi":"https://doi.org/10.1109/tetc.2025.3631134"},"language":null,"primary_location":{"id":"doi:10.1109/tetc.2025.3631134","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tetc.2025.3631134","pdf_url":null,"source":{"id":"https://openalex.org/S2496326734","display_name":"IEEE Transactions on Emerging Topics in Computing","issn_l":"2168-6750","issn":["2168-6750","2376-4562"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Emerging Topics in Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Xiangqi Wang","orcid":"https://orcid.org/0000-0002-2291-9443"},"institutions":[{"id":"https://openalex.org/I41198531","display_name":"Nanjing University of Posts and Telecommunications","ror":"https://ror.org/043bpky34","country_code":"CN","type":"education","lineage":["https://openalex.org/I41198531"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xiangqi Wang","raw_affiliation_strings":["College of Science, Nanjing University of Posts and Telecommunications, Nanjing, China"],"raw_orcid":"https://orcid.org/0000-0002-2291-9443","affiliations":[{"raw_affiliation_string":"College of Science, Nanjing University of Posts and Telecommunications, Nanjing, China","institution_ids":["https://openalex.org/I41198531"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Mingfu Xue","orcid":"https://orcid.org/0000-0003-2408-503X"},"institutions":[{"id":"https://openalex.org/I66867065","display_name":"East China Normal University","ror":"https://ror.org/02n96ep67","country_code":"CN","type":"education","lineage":["https://openalex.org/I66867065"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mingfu Xue","raw_affiliation_strings":["School of Communication and Electronic Engineering, East China Normal University, Shanghai, China"],"raw_orcid":"https://orcid.org/0000-0003-2408-503X","affiliations":[{"raw_affiliation_string":"School of Communication and Electronic Engineering, East China Normal University, Shanghai, China","institution_ids":["https://openalex.org/I66867065"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Kewei Chen","orcid":"https://orcid.org/0009-0008-2502-5796"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kewei Chen","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, China"],"raw_orcid":"https://orcid.org/0009-0008-2502-5796","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, China","institution_ids":["https://openalex.org/I9842412"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Jing Xu","orcid":"https://orcid.org/0000-0002-0408-9984"},"institutions":[{"id":"https://openalex.org/I16609230","display_name":"Hunan University","ror":"https://ror.org/05htk5m33","country_code":"CN","type":"education","lineage":["https://openalex.org/I16609230"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jing Xu","raw_affiliation_strings":["College of Computer Science and Electronic Engineering, Hunan University, Changsha, China"],"raw_orcid":"https://orcid.org/0000-0002-0408-9984","affiliations":[{"raw_affiliation_string":"College of Computer Science and Electronic Engineering, Hunan University, Changsha, China","institution_ids":["https://openalex.org/I16609230"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Wenmao Liu","orcid":"https://orcid.org/0009-0000-2046-5305"},"institutions":[{"id":"https://openalex.org/I75390827","display_name":"Beijing University of Chemical Technology","ror":"https://ror.org/00df5yc52","country_code":"CN","type":"education","lineage":["https://openalex.org/I75390827"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenmao Liu","raw_affiliation_strings":["Innovation Center, NSFOCUS Information Technology Company, Ltd., Beijing, China"],"raw_orcid":"https://orcid.org/0009-0000-2046-5305","affiliations":[{"raw_affiliation_string":"Innovation Center, NSFOCUS Information Technology Company, Ltd., Beijing, China","institution_ids":["https://openalex.org/I75390827"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Leo Yu Zhang","orcid":"https://orcid.org/0000-0001-9330-2662"},"institutions":[{"id":"https://openalex.org/I11701301","display_name":"Griffith University","ror":"https://ror.org/02sc3r913","country_code":"AU","type":"education","lineage":["https://openalex.org/I11701301"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Leo Yu Zhang","raw_affiliation_strings":["School of Information and Communication Technology, Griffith University, Southport, QLD, Australia"],"raw_orcid":"https://orcid.org/0000-0001-9330-2662","affiliations":[{"raw_affiliation_string":"School of Information and Communication Technology, Griffith University, Southport, QLD, Australia","institution_ids":["https://openalex.org/I11701301"]}]},{"author_position":"last","author":{"id":null,"display_name":"Yushu Zhang","orcid":"https://orcid.org/0000-0001-8183-8435"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yushu Zhang","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, China"],"raw_orcid":"https://orcid.org/0000-0001-8183-8435","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, China","institution_ids":["https://openalex.org/I9842412"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I41198531"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.76223127,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"14","issue":"1","first_page":"30","last_page":"41"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9901000261306763,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9901000261306763,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.00139999995008111,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.0008999999845400453,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9961000084877014},{"id":"https://openalex.org/keywords/autoencoder","display_name":"Autoencoder","score":0.753600001335144},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.555899977684021},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4593000113964081},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.41830000281333923},{"id":"https://openalex.org/keywords/generator","display_name":"Generator (circuit theory)","score":0.3889999985694885},{"id":"https://openalex.org/keywords/noise-reduction","display_name":"Noise reduction","score":0.37689998745918274}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9961000084877014},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7791000008583069},{"id":"https://openalex.org/C101738243","wikidata":"https://www.wikidata.org/wiki/Q786435","display_name":"Autoencoder","level":3,"score":0.753600001335144},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6101999878883362},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.555899977684021},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4593000113964081},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.41830000281333923},{"id":"https://openalex.org/C2780992000","wikidata":"https://www.wikidata.org/wiki/Q17016113","display_name":"Generator (circuit theory)","level":3,"score":0.3889999985694885},{"id":"https://openalex.org/C163294075","wikidata":"https://www.wikidata.org/wiki/Q581861","display_name":"Noise reduction","level":2,"score":0.37689998745918274},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3707999885082245},{"id":"https://openalex.org/C138236772","wikidata":"https://www.wikidata.org/wiki/Q25098575","display_name":"Edge device","level":3,"score":0.3479999899864197},{"id":"https://openalex.org/C162307627","wikidata":"https://www.wikidata.org/wiki/Q204833","display_name":"Enhanced Data Rates for GSM Evolution","level":2,"score":0.3425000011920929},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.32429999113082886},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.32120001316070557},{"id":"https://openalex.org/C111335779","wikidata":"https://www.wikidata.org/wiki/Q3454686","display_name":"Reduction (mathematics)","level":2,"score":0.30140000581741333},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.29499998688697815},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.2827000021934509},{"id":"https://openalex.org/C2781137444","wikidata":"https://www.wikidata.org/wiki/Q237105","display_name":"Sharpening","level":2,"score":0.2815000116825104}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tetc.2025.3631134","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tetc.2025.3631134","pdf_url":null,"source":{"id":"https://openalex.org/S2496326734","display_name":"IEEE Transactions on Emerging Topics in Computing","issn_l":"2168-6750","issn":["2168-6750","2376-4562"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Emerging Topics in Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1036532235","display_name":null,"funder_award_id":"2022Z071052008","funder_id":"https://openalex.org/F4320322857","funder_display_name":"Aeronautical Science Foundation of China"},{"id":"https://openalex.org/G5080558733","display_name":null,"funder_award_id":"62372231","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320322857","display_name":"Aeronautical Science Foundation of China","ror":"https://ror.org/02wq41p38"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":31,"referenced_works":["https://openalex.org/W1966068039","https://openalex.org/W2054804336","https://openalex.org/W2108598243","https://openalex.org/W2111308925","https://openalex.org/W2130103520","https://openalex.org/W2133665775","https://openalex.org/W2194775991","https://openalex.org/W2515770085","https://openalex.org/W2807363941","https://openalex.org/W2891828758","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2962858109","https://openalex.org/W2970335439","https://openalex.org/W2986013765","https://openalex.org/W2990270730","https://openalex.org/W2996800219","https://openalex.org/W3114686421","https://openalex.org/W3215966579","https://openalex.org/W4214680449","https://openalex.org/W4386072159","https://openalex.org/W4386076050","https://openalex.org/W4386147982","https://openalex.org/W4386634675","https://openalex.org/W4387841611","https://openalex.org/W4390818097","https://openalex.org/W4390969331","https://openalex.org/W4391661654","https://openalex.org/W4393154709","https://openalex.org/W4393160907","https://openalex.org/W4393184763"],"related_works":[],"abstract_inverted_index":{"The":[0,13,118],"backdoor":[1,15,48,87,165],"attack":[2,88,103],"poses":[3],"a":[4,66,96,142],"new":[5],"security":[6],"threat":[7],"to":[8,22,35,55,132,151],"deep":[9],"neural":[10],"networks":[11],"(DNNs).":[12],"existing":[14],"often":[16],"relies":[17],"on":[18,89,109],"visible":[19],"universal":[20],"triggers":[21],"make":[23],"the":[24,50,110,115,136],"backdoored":[25,157],"model":[26,158],"malfunction,":[27],"which":[28,94],"is":[29,58,63,70,123,148],"not":[30,149],"only":[31],"usually":[32],"visually":[33],"suspicious":[34],"humans":[36],"but":[37,74],"also":[38],"catchable":[39],"by":[40],"mainstream":[41,164],"countermeasures.":[42],"We":[43,82],"propose":[44],"an":[45],"imperceptible":[46],"sample-specific":[47],"that":[49,69],"trigger":[51,61,121,137,143],"varies":[52],"from":[53,130],"sample":[54,56,147],"and":[57,91,98,175],"invisible.":[59],"Our":[60],"generation":[62],"automated":[64],"through":[65],"denoising":[67,119],"autoencoder":[68],"fed":[71],"with":[72,85,106],"delicate":[73],"pervasive":[75],"features":[76],"(e.g.,":[77,129],"edge":[78],"patterns":[79],"per":[80],"image).":[81],"extensively":[83],"experiment":[84],"our":[86,155],"ImageNet":[90,131],"MS-Celeb-1":[92,133],"M,":[93],"demonstrates":[95],"stable":[97],"nearly":[99],"100%":[100],"(i.e.,":[101,141],"99.8%)":[102],"success":[104],"rate":[105],"negligible":[107],"impact":[108],"clean":[111],"data":[112],"accuracy":[113],"of":[114],"infected":[116],"model.":[117],"autoencoder-based":[120],"generator":[122],"reusable":[124],"or":[125],"transferable":[126],"across":[127],"tasks":[128],"M),":[134],"whilst":[135],"has":[138,159],"high":[139,161],"exclusiveness":[140],"generated":[144],"for":[145],"one":[146],"applicable":[150],"another":[152],"sample).":[153],"Besides,":[154],"proposal":[156],"achieved":[160],"evasiveness":[162],"against":[163],"defenses":[166],"such":[167],"as":[168],"Neural":[169],"Cleanse,":[170],"STRIP,":[171],"SentiNet,":[172],"Fine-Pruning,":[173],"BDMAE,":[174],"BTI-DBF.":[176]},"counts_by_year":[],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-11-17T00:00:00"}
