{"id":"https://openalex.org/W3011937245","doi":"https://doi.org/10.1109/spw50608.2020.00024","title":"Backdooring and Poisoning Neural Networks with Image-Scaling Attacks","display_name":"Backdooring and Poisoning Neural Networks with Image-Scaling Attacks","publication_year":2020,"publication_date":"2020-05-01","ids":{"openalex":"https://openalex.org/W3011937245","doi":"https://doi.org/10.1109/spw50608.2020.00024","mag":"3011937245"},"language":"en","primary_location":{"id":"doi:10.1109/spw50608.2020.00024","is_oa":true,"landing_page_url":"https://doi.org/10.1109/spw50608.2020.00024","pdf_url":"https://ieeexplore.ieee.org/ielx7/9283745/9283819/09283824.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE Security and Privacy Workshops (SPW)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/9283745/9283819/09283824.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5085852581","display_name":"Erwin Quiring","orcid":"https://orcid.org/0009-0004-7170-1274"},"institutions":[{"id":"https://openalex.org/I94509681","display_name":"Technische Universit\u00e4t Braunschweig","ror":"https://ror.org/010nsgg66","country_code":"DE","type":"education","lineage":["https://openalex.org/I94509681"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Erwin Quiring","raw_affiliation_strings":["Germany","Technische Universit\u00e4t; Braunschweig Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Germany","institution_ids":[]},{"raw_affiliation_string":"Technische Universit\u00e4t; Braunschweig Germany","institution_ids":["https://openalex.org/I94509681"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5066077721","display_name":"Konrad Rieck","orcid":"https://orcid.org/0000-0002-5054-8758"},"institutions":[{"id":"https://openalex.org/I94509681","display_name":"Technische Universit\u00e4t Braunschweig","ror":"https://ror.org/010nsgg66","country_code":"DE","type":"education","lineage":["https://openalex.org/I94509681"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Konrad Rieck","raw_affiliation_strings":["Germany","Technische Universit\u00e4t; Braunschweig Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Germany","institution_ids":[]},{"raw_affiliation_string":"Technische Universit\u00e4t; Braunschweig Germany","institution_ids":["https://openalex.org/I94509681"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.9479,"has_fulltext":true,"cited_by_count":9,"citation_normalized_percentile":{"value":0.80548623,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"41","last_page":"47"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9731000065803528,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9516000151634216,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9492532014846802},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7777290940284729},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5972610712051392},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5520918965339661},{"id":"https://openalex.org/keywords/scaling","display_name":"Scaling","score":0.5498507022857666},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5044876337051392},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.35782694816589355},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.05761858820915222}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9492532014846802},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7777290940284729},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5972610712051392},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5520918965339661},{"id":"https://openalex.org/C99844830","wikidata":"https://www.wikidata.org/wiki/Q102441924","display_name":"Scaling","level":2,"score":0.5498507022857666},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5044876337051392},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.35782694816589355},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.05761858820915222},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1109/spw50608.2020.00024","is_oa":true,"landing_page_url":"https://doi.org/10.1109/spw50608.2020.00024","pdf_url":"https://ieeexplore.ieee.org/ielx7/9283745/9283819/09283824.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE Security and Privacy Workshops (SPW)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2003.08633","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2003.08633","pdf_url":"https://arxiv.org/pdf/2003.08633","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},{"id":"mag:3011937245","is_oa":true,"landing_page_url":"http://export.arxiv.org/pdf/2003.08633","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},{"id":"doi:10.48550/arxiv.2003.08633","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2003.08633","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/spw50608.2020.00024","is_oa":true,"landing_page_url":"https://doi.org/10.1109/spw50608.2020.00024","pdf_url":"https://ieeexplore.ieee.org/ielx7/9283745/9283819/09283824.pdf","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE Security and Privacy Workshops (SPW)","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G18682879","display_name":null,"funder_award_id":"390781972","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"},{"id":"https://openalex.org/G8214026871","display_name":null,"funder_award_id":"EXC 2092 CASA - 390781972,RI 2469/3-1","funder_id":"https://openalex.org/F4320320879","funder_display_name":"Deutsche Forschungsgemeinschaft"}],"funders":[{"id":"https://openalex.org/F4320320879","display_name":"Deutsche Forschungsgemeinschaft","ror":"https://ror.org/018mejw64"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3011937245.pdf","grobid_xml":"https://content.openalex.org/works/W3011937245.grobid-xml"},"referenced_works_count":33,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1513231349","https://openalex.org/W1686810756","https://openalex.org/W2117539524","https://openalex.org/W2183341477","https://openalex.org/W2187013920","https://openalex.org/W2461943168","https://openalex.org/W2535690855","https://openalex.org/W2748789698","https://openalex.org/W2753783305","https://openalex.org/W2774423163","https://openalex.org/W2934843808","https://openalex.org/W2947864246","https://openalex.org/W2963343288","https://openalex.org/W2963857521","https://openalex.org/W2964318098","https://openalex.org/W2965628707","https://openalex.org/W2966840685","https://openalex.org/W2985913519","https://openalex.org/W3020403113","https://openalex.org/W3103836116","https://openalex.org/W3118608800","https://openalex.org/W6630632610","https://openalex.org/W6637373629","https://openalex.org/W6686674283","https://openalex.org/W6743581629","https://openalex.org/W6746897123","https://openalex.org/W6750462152","https://openalex.org/W6763098168","https://openalex.org/W6763178796","https://openalex.org/W6766313860","https://openalex.org/W6776865198","https://openalex.org/W6787972765"],"related_works":["https://openalex.org/W3115279145","https://openalex.org/W3214399478","https://openalex.org/W3205870294","https://openalex.org/W3205612941","https://openalex.org/W3013323233","https://openalex.org/W2898998737","https://openalex.org/W3120223105","https://openalex.org/W2984157150","https://openalex.org/W2996800219","https://openalex.org/W2964041528","https://openalex.org/W3009072493","https://openalex.org/W2753783305","https://openalex.org/W2748789698","https://openalex.org/W3127283121","https://openalex.org/W2958193440","https://openalex.org/W2972120770","https://openalex.org/W3096338975","https://openalex.org/W2417524550","https://openalex.org/W3199529221","https://openalex.org/W2130580367"],"abstract_inverted_index":{"Backdoors":[0],"and":[1,13,31,49,84,111,132],"poisoning":[2,50,83,133,174],"attacks":[3,19,60,65,110,151],"are":[4,152],"a":[5,43,56,78,162],"major":[6],"threat":[7],"to":[8,77,154,172],"the":[9,24,33,36,90,98,106,122],"security":[10],"of":[11,35,59,92,100,108,124,168],"machine-learning":[12],"vision":[14],"systems.":[15],"Often,":[16],"however,":[17],"these":[18],"leave":[20],"visible":[21],"artifacts":[22],"in":[23],"images":[25,68],"that":[26,70,130,145],"can":[27,88],"be":[28],"visually":[29],"detected":[30],"weaken":[32],"efficacy":[34],"attacks.":[37,51,141],"In":[38,116],"this":[39],"paper,":[40],"we":[41,87,104,120,128,143],"propose":[42],"novel":[44,163],"strategy":[45],"for":[46,165],"hiding":[47,166],"backdoor":[48],"Our":[52],"approach":[53],"builds":[54],"on":[55],"recent":[57],"class":[58],"against":[61,149],"image":[62],"scaling.":[63],"These":[64],"enable":[66],"manipulating":[67],"such":[69],"they":[71],"change":[72],"their":[73],"content":[74],"when":[75,137],"scaled":[76],"specific":[79],"resolution.":[80],"By":[81],"combining":[82],"image-scaling":[85,109,140,150],"attacks,":[86],"conceal":[89],"trigger":[91],"backdoors":[93,131],"as":[94,96],"well":[95,136],"hide":[97],"overlays":[99],"clean-label":[101],"poisoning.":[102],"Furthermore,":[103],"consider":[105],"detection":[107,147],"derive":[112],"an":[113,117],"adaptive":[114],"attack.":[115],"empirical":[118],"evaluation,":[119],"demonstrate":[121,144],"effectiveness":[123],"our":[125,156,159],"strategy.":[126],"First,":[127],"show":[129],"work":[134,160],"equally":[135],"combined":[138],"with":[139],"Second,":[142],"current":[146],"defenses":[148],"insufficient":[153],"uncover":[155],"manipulations.":[157],"Overall,":[158],"provides":[161],"means":[164],"traces":[167],"manipulations,":[169],"being":[170],"applicable":[171],"different":[173],"approaches.":[175]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":2},{"year":2022,"cited_by_count":1},{"year":2021,"cited_by_count":1},{"year":2020,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
