{"id":"https://openalex.org/W4410608997","doi":"https://doi.org/10.1109/satml64287.2025.00020","title":"The Ultimate Cookbook for Invisible Poison: Crafting Subtle Clean-Label Text Backdoors with Style Attributes","display_name":"The Ultimate Cookbook for Invisible Poison: Crafting Subtle Clean-Label Text Backdoors with Style Attributes","publication_year":2025,"publication_date":"2025-04-09","ids":{"openalex":"https://openalex.org/W4410608997","doi":"https://doi.org/10.1109/satml64287.2025.00020"},"language":"en","primary_location":{"id":"doi:10.1109/satml64287.2025.00020","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00020","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5062325280","display_name":"Wencong You","orcid":null},"institutions":[{"id":"https://openalex.org/I181233156","display_name":"University of Oregon","ror":"https://ror.org/0293rh119","country_code":"US","type":"education","lineage":["https://openalex.org/I181233156"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Wencong You","raw_affiliation_strings":["University of Oregon,Department of Computer Science,Eugene,OR,USA"],"affiliations":[{"raw_affiliation_string":"University of Oregon,Department of Computer Science,Eugene,OR,USA","institution_ids":["https://openalex.org/I181233156"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5053373401","display_name":"Daniel Lowd","orcid":"https://orcid.org/0000-0002-9501-0361"},"institutions":[{"id":"https://openalex.org/I181233156","display_name":"University of Oregon","ror":"https://ror.org/0293rh119","country_code":"US","type":"education","lineage":["https://openalex.org/I181233156"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Daniel Lowd","raw_affiliation_strings":["University of Oregon,Department of Computer Science,Eugene,OR,USA"],"affiliations":[{"raw_affiliation_string":"University of Oregon,Department of Computer Science,Eugene,OR,USA","institution_ids":["https://openalex.org/I181233156"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5062325280"],"corresponding_institution_ids":["https://openalex.org/I181233156"],"apc_list":null,"apc_paid":null,"fwci":2.5857,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.88121402,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"222","last_page":"246"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T14056","display_name":"Safety Warnings and Signage","score":0.06759999692440033,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T14056","display_name":"Safety Warnings and Signage","score":0.06759999692440033,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.617020308971405},{"id":"https://openalex.org/keywords/style","display_name":"Style (visual arts)","score":0.6041346192359924},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5362424850463867},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.4245024025440216},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.40017327666282654},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.34253308176994324},{"id":"https://openalex.org/keywords/visual-arts","display_name":"Visual arts","score":0.08529895544052124},{"id":"https://openalex.org/keywords/art","display_name":"Art","score":0.07272139191627502}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.617020308971405},{"id":"https://openalex.org/C2776445246","wikidata":"https://www.wikidata.org/wiki/Q1792644","display_name":"Style (visual arts)","level":2,"score":0.6041346192359924},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5362424850463867},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.4245024025440216},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.40017327666282654},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.34253308176994324},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.08529895544052124},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.07272139191627502}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/satml64287.2025.00020","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00020","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/2","display_name":"Zero hunger","score":0.5}],"awards":[{"id":"https://openalex.org/G7345645070","display_name":null,"funder_award_id":"HR00112090135","funder_id":"https://openalex.org/F4320332180","funder_display_name":"Defense Advanced Research Projects Agency"}],"funders":[{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":49,"referenced_works":["https://openalex.org/W1982897610","https://openalex.org/W2058373514","https://openalex.org/W2251939518","https://openalex.org/W2942091739","https://openalex.org/W2973217491","https://openalex.org/W2979826702","https://openalex.org/W3035367371","https://openalex.org/W3098757341","https://openalex.org/W3104208618","https://openalex.org/W3109409894","https://openalex.org/W3128663834","https://openalex.org/W3158487140","https://openalex.org/W3204619801","https://openalex.org/W3205696278","https://openalex.org/W4281902577","https://openalex.org/W4297629560","https://openalex.org/W4385570794","https://openalex.org/W4389518719","https://openalex.org/W4393325714","https://openalex.org/W4402683911","https://openalex.org/W6676670208","https://openalex.org/W6682631176","https://openalex.org/W6685053522","https://openalex.org/W6754654208","https://openalex.org/W6755207826","https://openalex.org/W6761205521","https://openalex.org/W6763701032","https://openalex.org/W6766673545","https://openalex.org/W6767552790","https://openalex.org/W6772461460","https://openalex.org/W6774111340","https://openalex.org/W6778883912","https://openalex.org/W6794210157","https://openalex.org/W6795104400","https://openalex.org/W6795607857","https://openalex.org/W6796246527","https://openalex.org/W6797172672","https://openalex.org/W6797228356","https://openalex.org/W6801759574","https://openalex.org/W6802269988","https://openalex.org/W6802628810","https://openalex.org/W6803540272","https://openalex.org/W6804303261","https://openalex.org/W6809810311","https://openalex.org/W6839252630","https://openalex.org/W6839383656","https://openalex.org/W6856773073","https://openalex.org/W6857895977","https://openalex.org/W6898505805"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W2356229341","https://openalex.org/W2349768204","https://openalex.org/W4313326281","https://openalex.org/W574867512","https://openalex.org/W2387271333","https://openalex.org/W581389233","https://openalex.org/W2361120309","https://openalex.org/W632157940","https://openalex.org/W2387981414"],"abstract_inverted_index":{"Backdoor":[0],"attacks":[1,20,179],"on":[2,23],"text":[3,81],"classifiers":[4],"can":[5,51,180],"cause":[6],"them":[7],"to":[8,32,86,89,115],"predict":[9],"a":[10,14,36,42,72,76],"predefined":[11],"label":[12],"when":[13],"particular":[15],"\u201ctrigger\u201d":[16],"is":[17,79,154],"present.":[18],"Prior":[19],"often":[21,155],"rely":[22],"triggers":[24,85],"that":[25,71,148,177],"are":[26],"ungrammatical":[27],"or":[28],"otherwise":[29],"unusual,":[30],"leading":[31],"conspicuous":[33],"attacks.":[34,68,143],"As":[35],"result,":[37],"human":[38,104,113,145,198,220],"annotators,":[39],"who":[40],"play":[41],"critical":[43],"role":[44],"in":[45,49,209],"curating":[46],"training":[47],"data":[48],"practice,":[50],"easily":[52],"detect":[53],"and":[54,83,101,162,186,212],"filter":[55],"out":[56],"these":[57,151,217],"unnatural":[58],"texts":[59],"during":[60],"manual":[61],"inspection,":[62,192],"reducing":[63],"the":[64,108,171,214],"risk":[65],"of":[66,124,216],"such":[67,134],"We":[69,106,119],"argue":[70],"key":[73],"criterion":[74],"for":[75,80,127],"successful":[77],"attack":[78,99,117,159],"with":[82,103,150,219],"without":[84],"be":[87],"indistinguishable":[88],"humans.":[90],"However,":[91],"prior":[92,210],"work":[93],"neither":[94],"directly":[95],"nor":[96],"comprehensively":[97],"evaluated":[98],"subtlety":[100],"invisibility":[102],"involvement.":[105],"bridge":[107],"gap":[109],"by":[110,168,183,205],"conducting":[111],"thorough":[112],"evaluations":[114,146],"assess":[116],"subtlety.":[118],"also":[120,200],"propose":[121],"AttrBkd":[122,149],"consisting":[123],"three":[125],"recipes":[126],"crafting":[128],"subtle":[129,164],"yet":[130],"effective":[131,157],"trigger":[132],"attributes,":[133],"as":[135],"extracting":[136],"fine-grained":[137],"attributes":[138,153],"from":[139],"existing":[140],"baseline":[141,173],"backdoor":[142,178],"Our":[144,197],"find":[147],"baseline-derived":[152],"more":[156,163],"(higher":[158],"success":[160],"rate)":[161],"(fewer":[165],"instances":[166],"detected":[167],"humans)":[169],"than":[170],"original":[172],"back-door":[174],"attacks,":[175],"demonstrating":[176],"bypass":[181],"detection":[182],"being":[184],"inconspicuous":[185],"appearing":[187],"natural":[188],"even":[189],"upon":[190],"close":[191],"while":[193],"still":[194],"remaining":[195],"effective.":[196],"annotation":[199],"provides":[201],"information":[202],"not":[203],"captured":[204],"automated":[206],"metrics":[207,218],"used":[208],"work,":[211],"demonstrates":[213],"misalignment":[215],"judgment.":[221]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
