{"id":"https://openalex.org/W4312233898","doi":"https://doi.org/10.1109/tpami.2022.3220849","title":"Rethinking Label Flipping Attack: From Sample Masking to Sample Thresholding","display_name":"Rethinking Label Flipping Attack: From Sample Masking to Sample Thresholding","publication_year":2022,"publication_date":"2022-11-09","ids":{"openalex":"https://openalex.org/W4312233898","doi":"https://doi.org/10.1109/tpami.2022.3220849","pmid":"https://pubmed.ncbi.nlm.nih.gov/37819793"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2022.3220849","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2022.3220849","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5089092566","display_name":"Qianqian Xu","orcid":"https://orcid.org/0000-0002-3512-7277"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Qianqian Xu","raw_affiliation_strings":["Key Laboratory of Intelligent Information Processing, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Key Laboratory of Intelligent Information Processing, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210090176","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009753955","display_name":"Zhiyong Yang","orcid":"https://orcid.org/0000-0002-4409-4999"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhiyong Yang","raw_affiliation_strings":["School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5059594320","display_name":"Yunrui Zhao","orcid":"https://orcid.org/0000-0002-3239-4628"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunrui Zhao","raw_affiliation_strings":["School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068837264","display_name":"Xiaochun Cao","orcid":"https://orcid.org/0000-0001-7141-708X"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaochun Cao","raw_affiliation_strings":["School of Cyber Science and Technology, Shenzhen Campus of Sun Yat-sen University, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, Shenzhen Campus of Sun Yat-sen University, Shenzhen, China","institution_ids":["https://openalex.org/I157773358"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5028597017","display_name":"Qingming Huang","orcid":"https://orcid.org/0000-0001-7542-296X"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]},{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qingming Huang","raw_affiliation_strings":["School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China","Key Laboratory of Big Data Mining and Knowledge Management (BDKM), University of Chinese Academy of Sciences, Beijing, China","Peng Cheng Laboratory, Shenzhen, China","Key Laboratory of Intelligent Information Processing, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]},{"raw_affiliation_string":"Key Laboratory of Big Data Mining and Knowledge Management (BDKM), University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]},{"raw_affiliation_string":"Peng Cheng Laboratory, Shenzhen, China","institution_ids":["https://openalex.org/I4210136793"]},{"raw_affiliation_string":"Key Laboratory of Intelligent Information Processing, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210090176","https://openalex.org/I19820366"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5089092566"],"corresponding_institution_ids":["https://openalex.org/I19820366","https://openalex.org/I4210090176"],"apc_list":null,"apc_paid":null,"fwci":1.8046,"has_fulltext":false,"cited_by_count":16,"citation_normalized_percentile":{"value":0.87563184,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"45","issue":"6","first_page":"7668","last_page":"7685"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9976000189781189,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10800","display_name":"Forensic Toxicology and Drug Analysis","score":0.9887999892234802,"subfield":{"id":"https://openalex.org/subfields/3005","display_name":"Toxicology"},"field":{"id":"https://openalex.org/fields/30","display_name":"Pharmacology, Toxicology and Pharmaceutics"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7538769245147705},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.7391431927680969},{"id":"https://openalex.org/keywords/thresholding","display_name":"Thresholding","score":0.6935789585113525},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6359328031539917},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.6124597191810608},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.6033043265342712},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.5450790524482727},{"id":"https://openalex.org/keywords/minimax","display_name":"Minimax","score":0.4694502055644989},{"id":"https://openalex.org/keywords/surrogate-model","display_name":"Surrogate model","score":0.46156778931617737},{"id":"https://openalex.org/keywords/mathematical-optimization","display_name":"Mathematical optimization","score":0.1735146939754486},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.13511845469474792},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.08585244417190552}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7538769245147705},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.7391431927680969},{"id":"https://openalex.org/C191178318","wikidata":"https://www.wikidata.org/wiki/Q2256906","display_name":"Thresholding","level":3,"score":0.6935789585113525},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6359328031539917},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.6124597191810608},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.6033043265342712},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.5450790524482727},{"id":"https://openalex.org/C149728462","wikidata":"https://www.wikidata.org/wiki/Q751319","display_name":"Minimax","level":2,"score":0.4694502055644989},{"id":"https://openalex.org/C131675550","wikidata":"https://www.wikidata.org/wiki/Q7646884","display_name":"Surrogate model","level":2,"score":0.46156778931617737},{"id":"https://openalex.org/C126255220","wikidata":"https://www.wikidata.org/wiki/Q141495","display_name":"Mathematical optimization","level":1,"score":0.1735146939754486},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.13511845469474792},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.08585244417190552},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.0},{"id":"https://openalex.org/C43617362","wikidata":"https://www.wikidata.org/wiki/Q170050","display_name":"Chromatography","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tpami.2022.3220849","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2022.3220849","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:37819793","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/37819793","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.6399999856948853,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G431784793","display_name":null,"funder_award_id":"61976202","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4414281452","display_name":null,"funder_award_id":"62025604","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6212863906","display_name":null,"funder_award_id":"U21B2038","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6785349463","display_name":null,"funder_award_id":"6212200758","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7183324353","display_name":null,"funder_award_id":"U1936208","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7727892362","display_name":null,"funder_award_id":"2022M713101","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G7801426869","display_name":null,"funder_award_id":"61931008","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320321543","display_name":"China Postdoctoral Science Foundation","ror":"https://ror.org/0426zh255"},{"id":"https://openalex.org/F4320322847","display_name":"Youth Innovation Promotion Association of the Chinese Academy of Sciences","ror":"https://ror.org/031141b54"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":63,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1762726187","https://openalex.org/W1878518397","https://openalex.org/W2050818842","https://openalex.org/W2073068515","https://openalex.org/W2108598243","https://openalex.org/W2122429065","https://openalex.org/W2125943921","https://openalex.org/W2139037672","https://openalex.org/W2150578721","https://openalex.org/W2151009539","https://openalex.org/W2151298633","https://openalex.org/W2157364932","https://openalex.org/W2158880898","https://openalex.org/W2164545125","https://openalex.org/W2180612164","https://openalex.org/W2194775991","https://openalex.org/W2274745179","https://openalex.org/W2276146857","https://openalex.org/W2293844262","https://openalex.org/W2408141691","https://openalex.org/W2612448920","https://openalex.org/W2739478203","https://openalex.org/W2796314858","https://openalex.org/W2893554781","https://openalex.org/W2904169782","https://openalex.org/W2949956541","https://openalex.org/W2954182683","https://openalex.org/W2962907114","https://openalex.org/W2963618920","https://openalex.org/W2963775347","https://openalex.org/W2964413206","https://openalex.org/W2997229424","https://openalex.org/W3008051686","https://openalex.org/W3034339445","https://openalex.org/W3035419960","https://openalex.org/W3046774647","https://openalex.org/W3080270960","https://openalex.org/W3101787898","https://openalex.org/W3103836116","https://openalex.org/W3121763331","https://openalex.org/W3217417806","https://openalex.org/W4302313152","https://openalex.org/W6630632610","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6676931166","https://openalex.org/W6676935882","https://openalex.org/W6681673350","https://openalex.org/W6686674283","https://openalex.org/W6712837096","https://openalex.org/W6714069269","https://openalex.org/W6714198993","https://openalex.org/W6729756640","https://openalex.org/W6739088070","https://openalex.org/W6748556508","https://openalex.org/W6755038706","https://openalex.org/W6759424558","https://openalex.org/W6762814303","https://openalex.org/W6767222012","https://openalex.org/W6767513282","https://openalex.org/W6773640337","https://openalex.org/W6783596713"],"related_works":["https://openalex.org/W2953058328","https://openalex.org/W1542224353","https://openalex.org/W1661087619","https://openalex.org/W2016058626","https://openalex.org/W2750730210","https://openalex.org/W2474724840","https://openalex.org/W2116854923","https://openalex.org/W2236974868","https://openalex.org/W4312766348","https://openalex.org/W2730764323"],"abstract_inverted_index":{"Nowadays,":[0],"machine":[1],"learning":[2,6,125,200],"(ML)":[3],"and":[4,181,259],"deep":[5,124,199],"(DL)":[7],"methods":[8,25],"have":[9,50,216],"become":[10],"fundamental":[11],"building":[12],"blocks":[13],"for":[14],"a":[15,100,132,161,168,211,236,241],"wide":[16],"range":[17],"of":[18,23,45,103,141,239,270,304],"AI":[19],"applications.":[20],"The":[21],"popularity":[22],"these":[24],"also":[26],"makes":[27],"them":[28],"widely":[29],"exposed":[30],"to":[31,53,57,92,120,167,197,217,221,277,290,301],"malicious":[32],"attacks,":[33],"which":[34,136],"may":[35],"cause":[36],"severe":[37],"security":[38,43],"concerns.":[39],"To":[40,127],"understand":[41],"the":[42,46,65,72,82,89,104,107,142,149,153,176,182,189,204,223,228,232,248,252,257,260,278,286,302],"properties":[44],"ML/DL":[47,95],"methods,":[48],"researchers":[49],"recently":[51],"started":[52],"turn":[54],"their":[55],"focus":[56],"adversarial":[58,291],"attack":[59,198,213],"algorithms":[60],"that":[61,247],"could":[62,157],"successfully":[63],"corrupt":[64,93],"model":[66,183,225,254,262],"or":[67],"clean":[68],"data":[69],"owned":[70],"by":[71,98,227,256],"victim":[73,229,258],"with":[74,160],"imperceptible":[75],"perturbations.":[76],"In":[77,148],"this":[78,113,128,271],"paper,":[79],"we":[80,130,192,215,234,245,273],"study":[81],"Label":[83],"Flipping":[84],"Attack":[85],"(LFA)":[86],"problem,":[87,152,233],"where":[88,282],"attacker":[90],"expects":[91],"an":[94,138],"model's":[96],"performance":[97,249],"flipping":[99],"small":[101,264],"fraction":[102],"labels":[105,283],"in":[106,146,210],"training":[108,170],"data.":[109],"Prior":[110],"art":[111],"along":[112],"direction":[114],"adopts":[115],"combinatorial":[116],"optimization":[117,151],"problems,":[118],"leading":[119],"limited":[121],"scalability":[122],"toward":[123],"models.":[126,201],"end,":[129],"propose":[131],"novel":[133,169],"minimax":[134],"problem":[135],"provides":[137],"efficient":[139],"reformulation":[140],"sample":[143,154,190],"selection":[144,155],"process":[145],"LFA.":[147],"new":[150],"operation":[156],"be":[158],"implemented":[159],"single":[162],"thresholding":[163],"parameter.":[164],"This":[165],"leads":[166],"algorithm":[171],"called":[172],"Sample":[173,195,275],"Thresholding.":[174],"Since":[175],"objective":[177],"function":[178],"is":[179,207,263],"differentiable":[180],"complexity":[184],"does":[185],"not":[186,208],"depend":[187],"on":[188,296],"size,":[191],"can":[193],"apply":[194],"Thresholding":[196,276],"Moreover,":[202],"since":[203],"victim's":[205],"behavior":[206],"predictable":[209],"poisonous":[212],"setting,":[214],"employ":[218],"surrogate":[219,242,261],"models":[220],"simulate":[222],"true":[224,253],"employed":[226,255],"model.":[230],"Seeing":[231],"provide":[235],"theoretical":[237],"analysis":[238],"such":[240],"paradigm.":[243],"Specifically,":[244],"show":[246],"gap":[250],"between":[251],"under":[265],"mild":[266],"conditions.":[267],"On":[268],"top":[269],"paradigm,":[272],"extend":[274],"crowdsourced":[279],"ranking":[280],"task,":[281],"collected":[284],"from":[285],"annotators":[287],"are":[288],"vulnerable":[289],"attacks.":[292],"Finally,":[293],"experimental":[294],"analyses":[295],"three":[297],"real-world":[298],"datasets":[299],"speak":[300],"efficacy":[303],"our":[305],"method.":[306]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":8}],"updated_date":"2026-04-14T08:04:32.555800","created_date":"2025-10-10T00:00:00"}
