{"id":"https://openalex.org/W7160265053","doi":"https://doi.org/10.1109/wacv61042.2026.00064","title":"Mitigating Backdoor Attacks via Trigger Reconstruction and Model Hardening","display_name":"Mitigating Backdoor Attacks via Trigger Reconstruction and Model Hardening","publication_year":2026,"publication_date":"2026-03-06","ids":{"openalex":"https://openalex.org/W7160265053","doi":"https://doi.org/10.1109/wacv61042.2026.00064"},"language":null,"primary_location":{"id":"doi:10.1109/wacv61042.2026.00064","is_oa":false,"landing_page_url":"https://doi.org/10.1109/wacv61042.2026.00064","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5014842586","display_name":"Guanhong Tao","orcid":"https://orcid.org/0000-0002-4701-1327"},"institutions":[{"id":"https://openalex.org/I223532165","display_name":"University of Utah","ror":"https://ror.org/03r0ha626","country_code":"US","type":"education","lineage":["https://openalex.org/I223532165"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Guanhong Tao","raw_affiliation_strings":["University of Utah"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Utah","institution_ids":["https://openalex.org/I223532165"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135306828","display_name":"Siyuan Cheng","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Siyuan Cheng","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135342001","display_name":"Guangyu Shen","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Guangyu Shen","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135381538","display_name":"Yingqi Liu","orcid":null},"institutions":[{"id":"https://openalex.org/I4210164937","display_name":"Microsoft Research (United Kingdom)","ror":"https://ror.org/05k87vq12","country_code":"GB","type":"company","lineage":["https://openalex.org/I1290206253","https://openalex.org/I4210164937"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Yingqi Liu","raw_affiliation_strings":["Microsoft"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Microsoft","institution_ids":["https://openalex.org/I4210164937"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030118506","display_name":"Shengwei An","orcid":null},"institutions":[{"id":"https://openalex.org/I859038795","display_name":"Virginia Tech","ror":"https://ror.org/02smfhw86","country_code":"US","type":"education","lineage":["https://openalex.org/I859038795"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Shengwei An","raw_affiliation_strings":["Virginia Tech"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Virginia Tech","institution_ids":["https://openalex.org/I859038795"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103110440","display_name":"Zhuo Zhang","orcid":"https://orcid.org/0000-0001-6696-8282"},"institutions":[{"id":"https://openalex.org/I78577930","display_name":"Columbia University","ror":"https://ror.org/00hj8s172","country_code":"US","type":"education","lineage":["https://openalex.org/I78577930"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zhuo Zhang","raw_affiliation_strings":["Columbia University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Columbia University","institution_ids":["https://openalex.org/I78577930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5135406250","display_name":"Zhenting Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I1310439424","display_name":"Accenture (Switzerland)","ror":"https://ror.org/041r3e346","country_code":"CH","type":"company","lineage":["https://openalex.org/I1310439424","https://openalex.org/I4210093804"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Zhenting Wang","raw_affiliation_strings":["Accenture"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Accenture","institution_ids":["https://openalex.org/I1310439424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009370494","display_name":"Hanxi Guo","orcid":"https://orcid.org/0000-0002-7566-1589"},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hanxi Guo","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5135298398","display_name":"Xiangyu Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I219193219","display_name":"Purdue University West Lafayette","ror":"https://ror.org/02dqehb95","country_code":"US","type":"education","lineage":["https://openalex.org/I219193219"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiangyu Zhang","raw_affiliation_strings":["Purdue University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Purdue University","institution_ids":["https://openalex.org/I219193219"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5014842586"],"corresponding_institution_ids":["https://openalex.org/I223532165"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.92942991,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"580","last_page":"590"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6503999829292297,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6503999829292297,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10951","display_name":"Cryptographic Implementations and Security","score":0.08510000258684158,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.08009999990463257,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.8661999702453613},{"id":"https://openalex.org/keywords/hardening","display_name":"Hardening (computing)","score":0.3709999918937683},{"id":"https://openalex.org/keywords/safer","display_name":"SAFER","score":0.2802000045776367},{"id":"https://openalex.org/keywords/emulation","display_name":"Emulation","score":0.2540000081062317},{"id":"https://openalex.org/keywords/minification","display_name":"Minification","score":0.24869999289512634}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.8661999702453613},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4787999987602234},{"id":"https://openalex.org/C44255700","wikidata":"https://www.wikidata.org/wiki/Q978423","display_name":"Hardening (computing)","level":3,"score":0.3709999918937683},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.29820001125335693},{"id":"https://openalex.org/C2776654903","wikidata":"https://www.wikidata.org/wiki/Q2601463","display_name":"SAFER","level":2,"score":0.2802000045776367},{"id":"https://openalex.org/C200601418","wikidata":"https://www.wikidata.org/wiki/Q2193887","display_name":"Reliability engineering","level":1,"score":0.27950000762939453},{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.2540000081062317},{"id":"https://openalex.org/C147764199","wikidata":"https://www.wikidata.org/wiki/Q6865248","display_name":"Minification","level":2,"score":0.24869999289512634},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.24799999594688416},{"id":"https://openalex.org/C47446073","wikidata":"https://www.wikidata.org/wiki/Q5165890","display_name":"Control theory (sociology)","level":3,"score":0.24500000476837158}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/wacv61042.2026.00064","is_oa":false,"landing_page_url":"https://doi.org/10.1109/wacv61042.2026.00064","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Sustainable cities and communities","id":"https://metadata.un.org/sdg/11","score":0.6105571389198303}],"awards":[],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":46,"referenced_works":["https://openalex.org/W66427752","https://openalex.org/W1834627138","https://openalex.org/W1979596264","https://openalex.org/W2001610032","https://openalex.org/W2067713319","https://openalex.org/W2115579991","https://openalex.org/W2133665775","https://openalex.org/W2183341477","https://openalex.org/W2193145675","https://openalex.org/W2325939864","https://openalex.org/W2340897893","https://openalex.org/W2753783305","https://openalex.org/W2807363941","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2963446712","https://openalex.org/W2970335439","https://openalex.org/W2986013765","https://openalex.org/W2990270730","https://openalex.org/W3010216907","https://openalex.org/W3034258347","https://openalex.org/W3106646114","https://openalex.org/W3107337211","https://openalex.org/W3114838227","https://openalex.org/W3156877806","https://openalex.org/W3189812816","https://openalex.org/W4214564822","https://openalex.org/W4214680449","https://openalex.org/W4288057770","https://openalex.org/W4293846201","https://openalex.org/W4312329503","https://openalex.org/W4320736757","https://openalex.org/W4324007922","https://openalex.org/W4386066154","https://openalex.org/W4388867373","https://openalex.org/W4389546075","https://openalex.org/W4390871934","https://openalex.org/W4393156382","https://openalex.org/W4393158822","https://openalex.org/W4402263866","https://openalex.org/W4402727117","https://openalex.org/W4403905746","https://openalex.org/W4408565421","https://openalex.org/W4411337784","https://openalex.org/W7133188219","https://openalex.org/W7133214567"],"related_works":[],"abstract_inverted_index":{"Backdoor":[0],"attacks":[1,33,117],"are":[2],"among":[3],"the":[4,40,81,101,107,125,146],"most":[5],"prominent":[6],"security":[7],"threats":[8],"to":[9,105,132,148],"deep":[10],"learning":[11],"models.":[12],"Traditional":[13],"backdoors":[14,154],"rely":[15],"on":[16,112,134],"fixed":[17],"trigger":[18,73],"patterns":[19],"(e.g.,":[20],"a":[21,54,71,86],"red":[22],"square)":[23],"that":[24,37,59,79],"existing":[25],"defenses":[26,49],"can":[27,123,151],"often":[28],"effectively":[29],"remove.":[30],"However,":[31],"recent":[32],"embed":[34],"semantic":[35,64],"triggers":[36],"vary":[38],"with":[39,44,95],"input":[41],"and":[42,63,160],"blend":[43],"meaningful":[45],"features,":[46],"rendering":[47],"prior":[48],"ineffective.":[50],"We":[51],"propose":[52],"MARTINI,":[53],"novel":[55],"backdoor":[56,68,116,139],"mitigation":[57],"framework":[58],"addresses":[60],"both":[61],"traditional":[62],"backdoors.":[65],"MARTINI":[66],"reconstructs":[67],"samples":[69,93],"via":[70],"dedicated":[72],"reconstruction":[74],"procedure,":[75],"producing":[76],"malicious":[77],"inputs":[78],"replicate":[80],"injected":[82],"attack":[83,126],"effect":[84],"across":[85],"spectrum":[87],"of":[88,115],"attacks.":[89],"Using":[90],"these":[91],"reconstructed":[92],"paired":[94],"their":[96],"correct":[97],"labels,MARTINI":[98],"then":[99],"hardens":[100],"model":[102],"through":[103],"retraining":[104],"neutralize":[106],"targeted":[108],"misclassification.":[109],"Our":[110],"evaluation":[111],"14":[113],"types":[114],"in":[118,155],"image":[119],"classification":[120],"shows":[121],"thatMARTINI":[122],"reduce":[124,145],"success":[127],"rate":[128],"(ASR)":[129],"from":[130],"96.56%":[131],"5.17%":[133],"average,":[135],"outperforming":[136],"12":[137],"state-of-the-art":[138],"removal":[140],"approaches,":[141],"which":[142],"at":[143],"best":[144],"ASR":[147],"26.56%.":[149],"It":[150],"also":[152],"mitigate":[153],"self-supervised":[156],"learning,":[157],"object":[158],"detection":[159],"NLP":[161],"sentiment":[162],"analysis.":[163]},"counts_by_year":[],"updated_date":"2026-05-07T06:04:25.777469","created_date":"2026-05-06T00:00:00"}
