{"id":"https://openalex.org/W3188772578","doi":"https://doi.org/10.1109/tip.2022.3201472","title":"Poison Ink: Robust and Invisible Backdoor Attack","display_name":"Poison Ink: Robust and Invisible Backdoor Attack","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W3188772578","doi":"https://doi.org/10.1109/tip.2022.3201472","mag":"3188772578","pmid":"https://pubmed.ncbi.nlm.nih.gov/36040942"},"language":"en","primary_location":{"id":"doi:10.1109/tip.2022.3201472","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tip.2022.3201472","pdf_url":null,"source":{"id":"https://openalex.org/S4210173141","display_name":"IEEE Transactions on Image Processing","issn_l":"1057-7149","issn":["1057-7149","1941-0042"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Image Processing","raw_type":"journal-article"},"type":"article","indexed_in":["arxiv","crossref","pubmed"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2108.02488","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100436740","display_name":"Jie Zhang","orcid":"https://orcid.org/0000-0002-4230-1077"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Jie Zhang","raw_affiliation_strings":["School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]},{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100364587","display_name":"Dongdong Chen","orcid":"https://orcid.org/0000-0002-4642-4373"},"institutions":[{"id":"https://openalex.org/I1290206253","display_name":"Microsoft (United States)","ror":"https://ror.org/00d0nc645","country_code":"US","type":"company","lineage":["https://openalex.org/I1290206253"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chen Dongdong","raw_affiliation_strings":["Microsoft Research, Redmond, WA, USA","Microsoft Research, Redmond, Washington, USA"],"affiliations":[{"raw_affiliation_string":"Microsoft Research, Redmond, WA, USA","institution_ids":["https://openalex.org/I1290206253"]},{"raw_affiliation_string":"Microsoft Research, Redmond, Washington, USA","institution_ids":["https://openalex.org/I1290206253"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058616951","display_name":"Qidong Huang","orcid":"https://orcid.org/0000-0003-2702-8516"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qidong Huang","raw_affiliation_strings":["School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]},{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013972536","display_name":"Jing Liao","orcid":"https://orcid.org/0000-0001-7014-5377"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Jing Liao","raw_affiliation_strings":["Department of Computer Science, City University of Hong, Kowloon Tong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, City University of Hong, Kowloon Tong, Hong Kong","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067689180","display_name":"Weiming Zhang","orcid":"https://orcid.org/0000-0001-5576-6108"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Weiming Zhang","raw_affiliation_strings":["School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]},{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China","institution_ids":["https://openalex.org/I126520041"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109860620","display_name":"Huamin Feng","orcid":null},"institutions":[{"id":"https://openalex.org/I202334528","display_name":"Beijing Electronic Science and Technology Institute","ror":"https://ror.org/01xdzh226","country_code":"CN","type":"education","lineage":["https://openalex.org/I202334528"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Huamin Feng","raw_affiliation_strings":["Beijing Electronic Science and Technology Institute, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Beijing Electronic Science and Technology Institute, Beijing, China","institution_ids":["https://openalex.org/I202334528"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081114810","display_name":"Gang Hua","orcid":"https://orcid.org/0000-0001-9522-6157"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gang Hua","raw_affiliation_strings":["Wormpex AI Research LLC, Bellevue, WA, USA"],"affiliations":[{"raw_affiliation_string":"Wormpex AI Research LLC, Bellevue, WA, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5064573190","display_name":"Nenghai Yu","orcid":"https://orcid.org/0000-0003-4417-9316"},"institutions":[{"id":"https://openalex.org/I126520041","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09","country_code":"CN","type":"education","lineage":["https://openalex.org/I126520041","https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Nenghai Yu","raw_affiliation_strings":["School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, China","institution_ids":["https://openalex.org/I126520041"]},{"raw_affiliation_string":"School of Cyber Science and Security, University of Science and Technology of China, Hefei, Anhui, China","institution_ids":["https://openalex.org/I126520041"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5100436740"],"corresponding_institution_ids":["https://openalex.org/I126520041"],"apc_list":null,"apc_paid":null,"fwci":13.6058,"has_fulltext":false,"cited_by_count":107,"citation_normalized_percentile":{"value":0.9906459,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":100},"biblio":{"volume":"31","issue":null,"first_page":"5691","last_page":"5705"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.995199978351593,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9341999888420105,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9951971769332886},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6574368476867676},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.6175434589385986},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5784265398979187},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5670422315597534},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5334620475769043},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.46591830253601074}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9951971769332886},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6574368476867676},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.6175434589385986},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5784265398979187},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5670422315597534},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5334620475769043},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.46591830253601074},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[{"descriptor_ui":"D007281","descriptor_name":"Ink","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D007281","descriptor_name":"Ink","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D007281","descriptor_name":"Ink","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D011042","descriptor_name":"Poisons","qualifier_ui":null,"qualifier_name":null,"is_major_topic":true},{"descriptor_ui":"D011042","descriptor_name":"Poisons","qualifier_ui":null,"qualifier_name":null,"is_major_topic":true},{"descriptor_ui":"D011042","descriptor_name":"Poisons","qualifier_ui":null,"qualifier_name":null,"is_major_topic":true},{"descriptor_ui":"D012660","descriptor_name":"Semantics","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D012660","descriptor_name":"Semantics","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D012660","descriptor_name":"Semantics","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D016571","descriptor_name":"Neural Networks, Computer","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D016571","descriptor_name":"Neural Networks, Computer","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false},{"descriptor_ui":"D016571","descriptor_name":"Neural Networks, Computer","qualifier_ui":null,"qualifier_name":null,"is_major_topic":false}],"locations_count":3,"locations":[{"id":"doi:10.1109/tip.2022.3201472","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tip.2022.3201472","pdf_url":null,"source":{"id":"https://openalex.org/S4210173141","display_name":"IEEE Transactions on Image Processing","issn_l":"1057-7149","issn":["1057-7149","1941-0042"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Image Processing","raw_type":"journal-article"},{"id":"pmid:36040942","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/36040942","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on image processing : a publication of the IEEE Signal Processing Society","raw_type":null},{"id":"pmh:oai:arXiv.org:2108.02488","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2108.02488","pdf_url":"https://arxiv.org/pdf/2108.02488","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2108.02488","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2108.02488","pdf_url":"https://arxiv.org/pdf/2108.02488","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1586809628","display_name":null,"funder_award_id":"2018AAA0101400","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G278967557","display_name":null,"funder_award_id":"WK2100000011","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"},{"id":"https://openalex.org/G4073200200","display_name":null,"funder_award_id":"WK5290000001","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"},{"id":"https://openalex.org/G4260595822","display_name":null,"funder_award_id":"YD3480002001","funder_id":"https://openalex.org/F4320325599","funder_display_name":"University of Science and Technology of China"},{"id":"https://openalex.org/G6866081702","display_name":null,"funder_award_id":"61629301","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320325599","display_name":"University of Science and Technology of China","ror":"https://ror.org/04c4dkn09"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":106,"referenced_works":["https://openalex.org/W1616262590","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1849277567","https://openalex.org/W1901129140","https://openalex.org/W2108598243","https://openalex.org/W2117876524","https://openalex.org/W2143612262","https://openalex.org/W2145023731","https://openalex.org/W2163605009","https://openalex.org/W2194775991","https://openalex.org/W2325939864","https://openalex.org/W2520715860","https://openalex.org/W2549139847","https://openalex.org/W2753783305","https://openalex.org/W2771036112","https://openalex.org/W2774423163","https://openalex.org/W2774644650","https://openalex.org/W2800394774","https://openalex.org/W2807363941","https://openalex.org/W2883233582","https://openalex.org/W2898759955","https://openalex.org/W2913848079","https://openalex.org/W2914712270","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2952610664","https://openalex.org/W2962763344","https://openalex.org/W2962793481","https://openalex.org/W2962858109","https://openalex.org/W2963073614","https://openalex.org/W2963343288","https://openalex.org/W2963403868","https://openalex.org/W2963446712","https://openalex.org/W2964041528","https://openalex.org/W2964153729","https://openalex.org/W2966187620","https://openalex.org/W2970200861","https://openalex.org/W2970335439","https://openalex.org/W2971661634","https://openalex.org/W2974383094","https://openalex.org/W2986013765","https://openalex.org/W2990270730","https://openalex.org/W2997717738","https://openalex.org/W3012113073","https://openalex.org/W3015678314","https://openalex.org/W3031808717","https://openalex.org/W3034258347","https://openalex.org/W3034579202","https://openalex.org/W3042368254","https://openalex.org/W3042950035","https://openalex.org/W3044223678","https://openalex.org/W3044855816","https://openalex.org/W3046418752","https://openalex.org/W3083185154","https://openalex.org/W3101202235","https://openalex.org/W3102431071","https://openalex.org/W3103340107","https://openalex.org/W3107337211","https://openalex.org/W3109235236","https://openalex.org/W3111857723","https://openalex.org/W3112001526","https://openalex.org/W3118608800","https://openalex.org/W3123566204","https://openalex.org/W3128781534","https://openalex.org/W3130788031","https://openalex.org/W3133747496","https://openalex.org/W3162804012","https://openalex.org/W3178326529","https://openalex.org/W3189396597","https://openalex.org/W3196199654","https://openalex.org/W3198190218","https://openalex.org/W3217308368","https://openalex.org/W4214680449","https://openalex.org/W4250533120","https://openalex.org/W4287322937","https://openalex.org/W4287393645","https://openalex.org/W4288093767","https://openalex.org/W4289300166","https://openalex.org/W4293846201","https://openalex.org/W4298140072","https://openalex.org/W4308831279","https://openalex.org/W4385245566","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6684191040","https://openalex.org/W6739868092","https://openalex.org/W6739901393","https://openalex.org/W6746523225","https://openalex.org/W6746897123","https://openalex.org/W6750462152","https://openalex.org/W6756074407","https://openalex.org/W6756333562","https://openalex.org/W6756444276","https://openalex.org/W6758975236","https://openalex.org/W6766253520","https://openalex.org/W6767183785","https://openalex.org/W6774549192","https://openalex.org/W6775678023","https://openalex.org/W6780735040","https://openalex.org/W6781420246","https://openalex.org/W6787972765","https://openalex.org/W6789325072","https://openalex.org/W6799498295","https://openalex.org/W6800551481","https://openalex.org/W6804995136"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W4401407399"],"abstract_inverted_index":{"Recent":[0],"research":[1],"shows":[2],"deep":[3,40,139],"neural":[4],"networks":[5],"are":[6,27,61],"vulnerable":[7],"to":[8,65,107,132,142,152,156,182],"different":[9,183,192],"types":[10],"of":[11,38,48],"attacks,":[12,16,19],"such":[13,69,125,144],"as":[14,70,96],"adversarial":[15],"data":[17,72,123,133],"poisoning":[18,98],"and":[20,31,53,82,100,168,185],"backdoor":[21,25,58,84,159],"attacks.":[22],"Among":[23],"them,":[24],"attacks":[26,44],"the":[28,39,93,109,113,122,149],"most":[29,56],"cunning":[30],"can":[32,116],"occur":[33],"in":[34,166],"almost":[35],"every":[36],"stage":[37],"learning":[41],"pipeline.":[42],"Backdoor":[43],"have":[45],"attracted":[46],"lots":[47],"interest":[49],"from":[50],"both":[51,165],"academia":[52],"industry.":[54],"However,":[55],"existing":[57,157],"attack":[59,85,160,193],"methods":[60],"visible":[62],"or":[63],"fragile":[64],"some":[66],"effortless":[67],"pre-processing":[68],"common":[71],"transformations.":[73,134],"To":[74],"address":[75],"these":[76],"limitations,":[77],"we":[78,90,136,173],"propose":[79],"a":[80,126,138],"robust":[81,131],"invisible":[83],"called":[86],"\"Poison":[87],"Ink\".":[88],"Concretely,":[89],"first":[91],"leverage":[92,137],"image":[94,114,151],"structures":[95],"target":[97],"areas":[99],"fill":[101],"them":[102],"with":[103],"poison":[104],"ink":[105],"(information)":[106],"generate":[108],"trigger":[110,127,146],"pattern.":[111],"As":[112],"structure":[115],"keep":[117],"its":[118],"semantic":[119],"meaning":[120],"during":[121],"transformation,":[124],"pattern":[128,147],"is":[129,178],"inherently":[130],"Then":[135],"injection":[140],"network":[141,186],"embed":[143],"input-aware":[145],"into":[148],"cover":[150],"achieve":[153],"stealthiness.":[154],"Compared":[155],"popular":[158],"methods,":[161],"Poison":[162,176],"Ink":[163,177],"outperforms":[164],"stealthiness":[167],"robustness.":[169],"Through":[170],"extensive":[171],"experiments,":[172],"demonstrate":[174],"that":[175],"not":[179],"only":[180],"general":[181],"datasets":[184],"architectures":[187],"but":[188],"also":[189,197],"flexible":[190],"for":[191],"scenarios.":[194],"Besides,":[195],"it":[196],"has":[198],"very":[199],"strong":[200],"resistance":[201],"against":[202],"many":[203],"state-of-the-art":[204],"defense":[205],"techniques.":[206]},"counts_by_year":[{"year":2026,"cited_by_count":8},{"year":2025,"cited_by_count":33},{"year":2024,"cited_by_count":40},{"year":2023,"cited_by_count":23},{"year":2022,"cited_by_count":2},{"year":2021,"cited_by_count":1}],"updated_date":"2026-04-07T14:57:38.498316","created_date":"2025-10-10T00:00:00"}
