{"id":"https://openalex.org/W4285233920","doi":"https://doi.org/10.1109/tifs.2022.3175616","title":"LinkBreaker: Breaking the Backdoor-Trigger Link in DNNs via Neurons Consistency Check","display_name":"LinkBreaker: Breaking the Backdoor-Trigger Link in DNNs via Neurons Consistency Check","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4285233920","doi":"https://doi.org/10.1109/tifs.2022.3175616"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2022.3175616","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3175616","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5000833104","display_name":"Zhenzhu Chen","orcid":"https://orcid.org/0000-0001-6094-5995"},"institutions":[{"id":"https://openalex.org/I36399199","display_name":"Nanjing University of Science and Technology","ror":"https://ror.org/00xp9wg62","country_code":"CN","type":"education","lineage":["https://openalex.org/I36399199"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Zhenzhu Chen","raw_affiliation_strings":["School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"],"raw_orcid":"https://orcid.org/0000-0001-6094-5995","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China","institution_ids":["https://openalex.org/I36399199"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100346376","display_name":"Shang Wang","orcid":"https://orcid.org/0000-0001-8176-9038"},"institutions":[{"id":"https://openalex.org/I36399199","display_name":"Nanjing University of Science and Technology","ror":"https://ror.org/00xp9wg62","country_code":"CN","type":"education","lineage":["https://openalex.org/I36399199"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shang Wang","raw_affiliation_strings":["School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China","institution_ids":["https://openalex.org/I36399199"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048592388","display_name":"Anmin Fu","orcid":"https://orcid.org/0000-0002-1632-5737"},"institutions":[{"id":"https://openalex.org/I200845125","display_name":"Nanjing University of Information Science and Technology","ror":"https://ror.org/02y0rxk19","country_code":"CN","type":"education","lineage":["https://openalex.org/I200845125"]},{"id":"https://openalex.org/I36399199","display_name":"Nanjing University of Science and Technology","ror":"https://ror.org/00xp9wg62","country_code":"CN","type":"education","lineage":["https://openalex.org/I36399199"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Anmin Fu","raw_affiliation_strings":["School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China","School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China and State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, 100093, China"],"raw_orcid":"https://orcid.org/0000-0002-1632-5737","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China","institution_ids":["https://openalex.org/I36399199"]},{"raw_affiliation_string":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China and State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, 100093, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I200845125"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101863680","display_name":"Yansong Gao","orcid":"https://orcid.org/0000-0001-5783-2172"},"institutions":[{"id":"https://openalex.org/I36399199","display_name":"Nanjing University of Science and Technology","ror":"https://ror.org/00xp9wg62","country_code":"CN","type":"education","lineage":["https://openalex.org/I36399199"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yansong Gao","raw_affiliation_strings":["School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China"],"raw_orcid":"https://orcid.org/0000-0001-5783-2172","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Nanjing University of Science and Technology, Nanjing, China","institution_ids":["https://openalex.org/I36399199"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005228053","display_name":"Shui Yu","orcid":"https://orcid.org/0000-0003-4485-6743"},"institutions":[{"id":"https://openalex.org/I114017466","display_name":"University of Technology Sydney","ror":"https://ror.org/03f0f6041","country_code":"AU","type":"education","lineage":["https://openalex.org/I114017466"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Shui Yu","raw_affiliation_strings":["School of Software, University of Technology Sydney, Sydney, NSW, Australia","School of Software, University of Technology Sydney, Sydney, NSW 2007, Australia"],"raw_orcid":"https://orcid.org/0000-0003-4485-6743","affiliations":[{"raw_affiliation_string":"School of Software, University of Technology Sydney, Sydney, NSW, Australia","institution_ids":["https://openalex.org/I114017466"]},{"raw_affiliation_string":"School of Software, University of Technology Sydney, Sydney, NSW 2007, Australia","institution_ids":["https://openalex.org/I114017466"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5001712801","display_name":"Robert H. Deng","orcid":"https://orcid.org/0000-0003-3491-8146"},"institutions":[{"id":"https://openalex.org/I79891267","display_name":"Singapore Management University","ror":"https://ror.org/050qmg959","country_code":"SG","type":"education","lineage":["https://openalex.org/I79891267"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Robert H. Deng","raw_affiliation_strings":["School of Information Systems, Singapore Management University, Singapore"],"raw_orcid":"https://orcid.org/0000-0003-3491-8146","affiliations":[{"raw_affiliation_string":"School of Information Systems, Singapore Management University, Singapore","institution_ids":["https://openalex.org/I79891267"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5000833104"],"corresponding_institution_ids":["https://openalex.org/I36399199"],"apc_list":null,"apc_paid":null,"fwci":3.607,"has_fulltext":false,"cited_by_count":26,"citation_normalized_percentile":{"value":0.93695854,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"17","issue":null,"first_page":"2000","last_page":"2014"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9954000115394592,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12808","display_name":"Ferroelectric and Negative Capacitance Devices","score":0.9726999998092651,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9598663449287415},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7882646918296814},{"id":"https://openalex.org/keywords/consistency","display_name":"Consistency (knowledge bases)","score":0.5948415994644165},{"id":"https://openalex.org/keywords/link","display_name":"Link (geometry)","score":0.5777522325515747},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.4126166105270386},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3089783191680908},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.22548189759254456}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9598663449287415},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7882646918296814},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.5948415994644165},{"id":"https://openalex.org/C2778753846","wikidata":"https://www.wikidata.org/wiki/Q6554239","display_name":"Link (geometry)","level":2,"score":0.5777522325515747},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.4126166105270386},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3089783191680908},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.22548189759254456}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tifs.2022.3175616","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3175616","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},{"id":"pmh:oai:ink.library.smu.edu.sg:sis_research-8253","is_oa":false,"landing_page_url":"https://ink.library.smu.edu.sg/sis_research/7250","pdf_url":null,"source":{"id":"https://openalex.org/S4377196871","display_name":"Institutional Knowledge (InK) - Institutional Knowledge at Singapore Management University (Singapore Management University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I79891267","host_organization_name":"Singapore Management University","host_organization_lineage":["https://openalex.org/I79891267"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"https://doi.org/10.1109/TIFS.2022.3175616","raw_type":"Journal Article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7400000095367432}],"awards":[{"id":"https://openalex.org/G264155573","display_name":null,"funder_award_id":"30920021129","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"},{"id":"https://openalex.org/G3561187080","display_name":null,"funder_award_id":"BK20211192","funder_id":"https://openalex.org/F4320322769","funder_display_name":"Natural Science Foundation of Jiangsu Province"},{"id":"https://openalex.org/G419831423","display_name":null,"funder_award_id":"BK20200461","funder_id":"https://openalex.org/F4320322769","funder_display_name":"Natural Science Foundation of Jiangsu Province"},{"id":"https://openalex.org/G4677554732","display_name":null,"funder_award_id":"30921013111","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"},{"id":"https://openalex.org/G5663473917","display_name":null,"funder_award_id":"62072239","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7884758391","display_name":null,"funder_award_id":"62002167","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320322769","display_name":"Natural Science Foundation of Jiangsu Province","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":52,"referenced_works":["https://openalex.org/W1945616565","https://openalex.org/W2002427601","https://openalex.org/W2112796928","https://openalex.org/W2243397390","https://openalex.org/W2606462007","https://openalex.org/W2748789698","https://openalex.org/W2753783305","https://openalex.org/W2807363941","https://openalex.org/W2897865027","https://openalex.org/W2924551358","https://openalex.org/W2934843808","https://openalex.org/W2947133760","https://openalex.org/W2963184668","https://openalex.org/W2963542245","https://openalex.org/W2963564844","https://openalex.org/W2965527544","https://openalex.org/W2970335439","https://openalex.org/W2985913519","https://openalex.org/W2986013765","https://openalex.org/W2990270730","https://openalex.org/W2996800219","https://openalex.org/W3016560828","https://openalex.org/W3034258347","https://openalex.org/W3042368254","https://openalex.org/W3047335002","https://openalex.org/W3088377098","https://openalex.org/W3093239278","https://openalex.org/W3093791164","https://openalex.org/W3095859802","https://openalex.org/W3096024389","https://openalex.org/W3101609372","https://openalex.org/W3106646114","https://openalex.org/W3107337211","https://openalex.org/W3110845456","https://openalex.org/W3118608800","https://openalex.org/W3156793535","https://openalex.org/W3163966458","https://openalex.org/W3167334189","https://openalex.org/W3171726921","https://openalex.org/W4289300166","https://openalex.org/W6640425456","https://openalex.org/W6743581629","https://openalex.org/W6750462152","https://openalex.org/W6756074407","https://openalex.org/W6756333562","https://openalex.org/W6770046844","https://openalex.org/W6779739866","https://openalex.org/W6784558051","https://openalex.org/W6787959460","https://openalex.org/W6787972765","https://openalex.org/W6803329705","https://openalex.org/W6948312134"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W4401407399"],"abstract_inverted_index":{"Backdoor":[0],"attacks":[1,200],"cause":[2],"model":[3,126],"misbehaving":[4],"by":[5,177],"first":[6],"implanting":[7],"backdoors":[8,165],"in":[9,61],"deep":[10],"neural":[11],"networks":[12],"(DNNs)":[13],"during":[14,25],"training":[15],"and":[16,58,63,84,136,144,214],"then":[17],"activating":[18],"the":[19,52,56,59,65,68,82,85,119,122,125,139,142,145,171],"backdoor":[20,57,69,101,143,156,207],"via":[21,72],"samples":[22],"with":[23,226],"triggers":[24],"inference.":[26],"The":[27],"compromised":[28,114],"models":[29],"could":[30],"pose":[31],"serious":[32],"security":[33],"risks":[34],"to":[35,118,127,148,189],"artificial":[36],"intelligence":[37],"systems,":[38],"such":[39,212],"as":[40],"misidentifying":[41],"\u2018stop\u2019":[42],"traffic":[43],"sign":[44],"into":[45],"\u201880km/h\u2019.":[46],"In":[47,103],"this":[48,89],"paper,":[49],"we":[50,91],"investigate":[51],"connection":[53],"characteristic":[54],"between":[55,76,141],"trigger":[60,231],"DNNs":[62],"observe":[64],"fact":[66],"that":[67,158,223],"is":[70,159,183,225],"implanted":[71],"establishing":[73],"a":[74,77,94,107,153,190,194],"link":[75,140],"cluster":[78],"of":[79,179,229],"neurons,":[80],"representing":[81],"backdoor,":[83],"triggers.":[86],"Based":[87],"on":[88,131,201,219,239],"observation,":[90],"design":[92],"LinkBreaker,":[93],"new":[95],"generic":[96],"scheme":[97],"for":[98,112],"defending":[99],"against":[100,163,185,197],"attacks.":[102],"particular,":[104],"LinkBreaker":[105,123,151,182,224],"deploys":[106],"neuron":[108,115,133],"consistency":[109],"check":[110],"mechanism":[111],"identifying":[113],"set":[116,134],"related":[117],"trigger.":[120,146],"Then,":[121],"regulates":[124],"make":[128],"predictions":[129],"based":[130],"benign":[132,240],"only":[135,161],"thus":[137],"breaks":[138],"Compared":[147],"previous":[149],"defenses,":[150],"offers":[152],"more":[154],"general":[155],"countermeasure":[157],"not":[160,174,210],"effective":[162],"input-agnostic":[164],"but":[166],"also":[167],"source-specific":[168],"backdoors,":[169],"which":[170],"later":[172],"can":[173],"be":[175],"defeated":[176],"majority":[178],"state-of-the-arts.":[180],"Besides,":[181],"robust":[184],"adversarial":[186,198],"examples,":[187],"which,":[188],"large":[191],"extent,":[192],"provides":[193],"holistic":[195],"defense":[196],"example":[199],"DNNs,":[202],"while":[203,233],"almost":[204],"all":[205],"current":[206],"defenses":[208],"do":[209],"have":[211],"consideration":[213],"capability.":[215],"Extensive":[216],"experimental":[217],"evaluations":[218],"real":[220],"datasets":[221],"demonstrate":[222],"high":[227],"efficacy":[228],"suppressing":[230],"inputs":[232],"incurring":[234],"no":[235],"noticeable":[236],"accuracy":[237],"deterioration":[238],"inputs.":[241]},"counts_by_year":[{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":12},{"year":2023,"cited_by_count":7}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
