{"id":"https://openalex.org/W4408565892","doi":"https://doi.org/10.1109/tifs.2025.3550062","title":"Mutual Information Guided Backdoor Mitigation for Pre-Trained Encoders","display_name":"Mutual Information Guided Backdoor Mitigation for Pre-Trained Encoders","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4408565892","doi":"https://doi.org/10.1109/tifs.2025.3550062"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2025.3550062","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3550062","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5021206073","display_name":"Tingxu Han","orcid":"https://orcid.org/0000-0003-1821-611X"},"institutions":[{"id":"https://openalex.org/I881766915","display_name":"Nanjing University","ror":"https://ror.org/01rxvg760","country_code":"CN","type":"education","lineage":["https://openalex.org/I881766915"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Tingxu Han","raw_affiliation_strings":["State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"],"raw_orcid":"https://orcid.org/0000-0003-1821-611X","affiliations":[{"raw_affiliation_string":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China","institution_ids":["https://openalex.org/I881766915"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013856385","display_name":"Weisong Sun","orcid":"https://orcid.org/0000-0001-9236-8264"},"institutions":[{"id":"https://openalex.org/I172675005","display_name":"Nanyang Technological University","ror":"https://ror.org/02e7b5302","country_code":"SG","type":"education","lineage":["https://openalex.org/I172675005"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Weisong Sun","raw_affiliation_strings":["College of Computing and Data Science, Nanyang Technological University, Nanyang, Singapore, Singapore","Nanyang, Nanyang Technological University, School of Computer Science and Engineering, Singapore"],"raw_orcid":"https://orcid.org/0000-0001-9236-8264","affiliations":[{"raw_affiliation_string":"College of Computing and Data Science, Nanyang Technological University, Nanyang, Singapore, Singapore","institution_ids":["https://openalex.org/I172675005"]},{"raw_affiliation_string":"Nanyang, Nanyang Technological University, School of Computer Science and Engineering, Singapore","institution_ids":["https://openalex.org/I172675005"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Ziqi Ding","orcid":"https://orcid.org/0009-0008-8336-7516"},"institutions":[{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Ziqi Ding","raw_affiliation_strings":["School of Computer Science and Engineering, University of New South Wales, Kensington, NSW, Australia","School of Computer Science and Engineering, University of New South Wales, New South Wales, Australia"],"raw_orcid":"https://orcid.org/0009-0008-8336-7516","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, University of New South Wales, Kensington, NSW, Australia","institution_ids":["https://openalex.org/I31746571"]},{"raw_affiliation_string":"School of Computer Science and Engineering, University of New South Wales, New South Wales, Australia","institution_ids":["https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075174750","display_name":"Chunrong Fang","orcid":"https://orcid.org/0000-0002-9930-7111"},"institutions":[{"id":"https://openalex.org/I881766915","display_name":"Nanjing University","ror":"https://ror.org/01rxvg760","country_code":"CN","type":"education","lineage":["https://openalex.org/I881766915"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chunrong Fang","raw_affiliation_strings":["State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"],"raw_orcid":"https://orcid.org/0000-0002-9930-7111","affiliations":[{"raw_affiliation_string":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China","institution_ids":["https://openalex.org/I881766915"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039218735","display_name":"Hanwei Qian","orcid":"https://orcid.org/0009-0007-9524-1411"},"institutions":[{"id":"https://openalex.org/I881766915","display_name":"Nanjing University","ror":"https://ror.org/01rxvg760","country_code":"CN","type":"education","lineage":["https://openalex.org/I881766915"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hanwei Qian","raw_affiliation_strings":["State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"],"raw_orcid":"https://orcid.org/0009-0007-9524-1411","affiliations":[{"raw_affiliation_string":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China","institution_ids":["https://openalex.org/I881766915"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Jiaxun Li","orcid":"https://orcid.org/0009-0002-8267-8968"},"institutions":[{"id":"https://openalex.org/I3923682","display_name":"Soochow University","ror":"https://ror.org/05t8y2r12","country_code":"CN","type":"education","lineage":["https://openalex.org/I3923682"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiaxun Li","raw_affiliation_strings":["School of Mathematical Sciences, Soochow University, Suzhou, China"],"raw_orcid":"https://orcid.org/0009-0002-8267-8968","affiliations":[{"raw_affiliation_string":"School of Mathematical Sciences, Soochow University, Suzhou, China","institution_ids":["https://openalex.org/I3923682"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100422935","display_name":"Zhenyu Chen","orcid":"https://orcid.org/0000-0002-9592-7022"},"institutions":[{"id":"https://openalex.org/I881766915","display_name":"Nanjing University","ror":"https://ror.org/01rxvg760","country_code":"CN","type":"education","lineage":["https://openalex.org/I881766915"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhenyu Chen","raw_affiliation_strings":["State Key Laboratory for Novel Software Technology and Shenzhen Research Institute, Nanjing University, Nanjing, China","State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"],"raw_orcid":"https://orcid.org/0000-0002-9592-7022","affiliations":[{"raw_affiliation_string":"State Key Laboratory for Novel Software Technology and Shenzhen Research Institute, Nanjing University, Nanjing, China","institution_ids":["https://openalex.org/I881766915"]},{"raw_affiliation_string":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China","institution_ids":["https://openalex.org/I881766915"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5107249133","display_name":"Xiangyu Zhang","orcid":"https://orcid.org/0000-0002-9544-2500"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiangyu Zhang","raw_affiliation_strings":["School of Computer Sciences, Purdue University, West Lafayette, IN, USA","School of Computer Sciences, Purdue University, West Lafayette, USA"],"raw_orcid":"https://orcid.org/0000-0002-9544-2500","affiliations":[{"raw_affiliation_string":"School of Computer Sciences, Purdue University, West Lafayette, IN, USA","institution_ids":["https://openalex.org/I219193219"]},{"raw_affiliation_string":"School of Computer Sciences, Purdue University, West Lafayette, USA","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":4,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5021206073"],"corresponding_institution_ids":["https://openalex.org/I881766915"],"apc_list":null,"apc_paid":null,"fwci":13.0395,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.98316902,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":"20","issue":null,"first_page":"3414","last_page":"3428"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9557999968528748,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9557999968528748,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12810","display_name":"Real-time simulation and control systems","score":0.9549999833106995,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10876","display_name":"Fault Detection and Control Systems","score":0.9333999752998352,"subfield":{"id":"https://openalex.org/subfields/2207","display_name":"Control and Systems Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.875177800655365},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7860456705093384},{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.4984288215637207},{"id":"https://openalex.org/keywords/mutual-information","display_name":"Mutual information","score":0.4946708381175995},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.39382457733154297},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3691500723361969}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.875177800655365},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7860456705093384},{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.4984288215637207},{"id":"https://openalex.org/C152139883","wikidata":"https://www.wikidata.org/wiki/Q252973","display_name":"Mutual information","level":2,"score":0.4946708381175995},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39382457733154297},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3691500723361969},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2025.3550062","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3550062","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/13","score":0.6700000166893005,"display_name":"Climate action"}],"awards":[{"id":"https://openalex.org/G3894403112","display_name":null,"funder_award_id":"14380029","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"},{"id":"https://openalex.org/G8287377286","display_name":null,"funder_award_id":"U24A20337","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8662163125","display_name":null,"funder_award_id":"62372228","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G948224718","display_name":null,"funder_award_id":"AISG2-GC-2023-008","funder_id":"https://openalex.org/F4320320671","funder_display_name":"National Research Foundation"}],"funders":[{"id":"https://openalex.org/F4320320671","display_name":"National Research Foundation","ror":"https://ror.org/05s0g1g46"},{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":54,"referenced_works":["https://openalex.org/W343636949","https://openalex.org/W1821462560","https://openalex.org/W2001610032","https://openalex.org/W2067713319","https://openalex.org/W2138621090","https://openalex.org/W2194775991","https://openalex.org/W2560647685","https://openalex.org/W2807363941","https://openalex.org/W2934843808","https://openalex.org/W2950306824","https://openalex.org/W2962858109","https://openalex.org/W2964082701","https://openalex.org/W3035524453","https://openalex.org/W3042368254","https://openalex.org/W3114632476","https://openalex.org/W3170224286","https://openalex.org/W3189812816","https://openalex.org/W4288057740","https://openalex.org/W4288057770","https://openalex.org/W4291023040","https://openalex.org/W4312768002","https://openalex.org/W4322760473","https://openalex.org/W4385990902","https://openalex.org/W4386066154","https://openalex.org/W4386072179","https://openalex.org/W6674924502","https://openalex.org/W6677919164","https://openalex.org/W6730179637","https://openalex.org/W6738597727","https://openalex.org/W6743581629","https://openalex.org/W6743986261","https://openalex.org/W6752051073","https://openalex.org/W6754278344","https://openalex.org/W6766253520","https://openalex.org/W6780006332","https://openalex.org/W6784339589","https://openalex.org/W6787972765","https://openalex.org/W6788876066","https://openalex.org/W6789730115","https://openalex.org/W6791353385","https://openalex.org/W6795961950","https://openalex.org/W6800751262","https://openalex.org/W6801793958","https://openalex.org/W6803329306","https://openalex.org/W6804292721","https://openalex.org/W6809890637","https://openalex.org/W6840331315","https://openalex.org/W6844194202","https://openalex.org/W6846810734","https://openalex.org/W6851321561","https://openalex.org/W6852894864","https://openalex.org/W6853525784","https://openalex.org/W6862484556","https://openalex.org/W6869369774"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W4401407399"],"abstract_inverted_index":{"Self-supervised":[0],"learning":[1],"(SSL)":[2],"is":[3,56,176,246,262],"increasingly":[4],"attractive":[5],"for":[6,49,106],"pre-training":[7,243],"encoders":[8,21,29],"without":[9],"requiring":[10],"labeled":[11],"data.":[12],"Downstream":[13],"tasks":[14],"built":[15],"on":[16,215],"top":[17],"of":[18,69,241,260],"those":[19],"pre-trained":[20,28,63,79,107],"can":[22,224],"achieve":[23],"nearly":[24],"state-of-the-art":[25,253],"performance.":[26],"The":[27,257],"by":[30,40,231],"SSL,":[31],"however,":[32],"are":[33,47],"vulnerable":[34],"to":[35,62,66,125,163,178,184,201,248],"backdoor":[36,44,76,91,102,217,254],"attacks":[37,77,218],"as":[38,117],"demonstrated":[39],"existing":[41,135],"studies.":[42],"Numerous":[43],"mitigation":[45,92,255],"techniques":[46],"designed":[48],"downstream":[50],"task":[51],"models.":[52],"However,":[53],"their":[54],"effectiveness":[55],"impaired":[57],"and":[58,121,160,197,204],"limited":[59],"when":[60,72],"adapted":[61],"encoders,":[64,80],"due":[65],"the":[67,113,118,141,170,188,209,227,249],"lack":[68],"label":[70],"information":[71,89,156],"pre-training.":[73],"To":[74],"address":[75],"against":[78],"in":[81,169,219],"this":[82],"paper,":[83],"we":[84],"innovatively":[85],"propose":[86],"a":[87,127],"mutual":[88,155],"guided":[90,101],"technique,":[93],"named":[94],"MIMIC(<underline":[95],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[96,99,104,109,235,266],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">M</u>utual":[97],"<underline":[98,103],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">I</u>nformation":[100],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">MI</u>tigation":[105],"en<underline":[108],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">C</u>oders).":[110],"MIMIC":[111,139,153,223,261],"uses":[112],"potentially":[114],"backdoored":[115],"encoder":[116,130,206],"teacher":[119,150,171,183],"network":[120],"applies":[122],"knowledge":[123,136,167],"distillation":[124,137,175,189],"create":[126],"clean":[128,180,242],"student":[129,142],"from":[131,134,149,182],"it.":[132],"Different":[133],"approaches,":[138],"initializes":[140],"with":[143,173,191],"random":[144],"weights,":[145],"inheriting":[146],"no":[147],"backdoors":[148,203],"nets.":[151],"Then":[152],"leverages":[154],"between":[157],"each":[158],"layer":[159],"extracted":[161],"features":[162,181],"locate":[164],"where":[165],"benign":[166],"lies":[168],"net,":[172],"which":[174],"deployed":[177],"clone":[179,195],"student.":[185],"We":[186],"craft":[187],"loss":[190,196],"two":[192,216],"aspects,":[193],"including":[194],"attention":[198],"loss,":[199],"aiming":[200],"mitigate":[202],"maintain":[205],"performance":[207],"at":[208,264],"same":[210],"time.":[211],"Our":[212],"evaluation":[213],"conducted":[214],"SSL":[220],"demonstrates":[221],"that":[222,245],"significantly":[225],"reduce":[226],"attack":[228],"success":[229],"rate":[230],"only":[232],"utilizing":[233],"<inline-formula":[234],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">":[236],"<tex-math":[237],"notation=\"LaTeX\">$\\leq":[238],"5$":[239],"</tex-math></inline-formula>%":[240],"data":[244],"accessible":[247],"defender,":[250],"surpassing":[251],"seven":[252],"techniques.":[256],"source":[258],"code":[259],"available":[263],"<uri":[265],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">https://github.com/wssun/MIMIC</uri>.":[267]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
