{"id":"https://openalex.org/W2985913519","doi":"https://doi.org/10.1145/3319535.3354209","title":"Latent Backdoor Attacks on Deep Neural Networks","display_name":"Latent Backdoor Attacks on Deep Neural Networks","publication_year":2019,"publication_date":"2019-11-06","ids":{"openalex":"https://openalex.org/W2985913519","doi":"https://doi.org/10.1145/3319535.3354209","mag":"2985913519"},"language":"en","primary_location":{"id":"doi:10.1145/3319535.3354209","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3354209","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354209","source":null,"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354209","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5014146843","display_name":"Yuanshun Yao","orcid":null},"institutions":[{"id":"https://openalex.org/I39422238","display_name":"University of Illinois Chicago","ror":"https://ror.org/02mpq6x41","country_code":"US","type":"education","lineage":["https://openalex.org/I39422238"]},{"id":"https://openalex.org/I40347166","display_name":"University of Chicago","ror":"https://ror.org/024mw5h28","country_code":"US","type":"education","lineage":["https://openalex.org/I40347166"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yuanshun Yao","raw_affiliation_strings":["University of Chicago, Chicago, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Chicago, Chicago, IL, USA","institution_ids":["https://openalex.org/I40347166","https://openalex.org/I39422238"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100603788","display_name":"Huiying Li","orcid":"https://orcid.org/0000-0002-3637-2581"},"institutions":[{"id":"https://openalex.org/I39422238","display_name":"University of Illinois Chicago","ror":"https://ror.org/02mpq6x41","country_code":"US","type":"education","lineage":["https://openalex.org/I39422238"]},{"id":"https://openalex.org/I40347166","display_name":"University of Chicago","ror":"https://ror.org/024mw5h28","country_code":"US","type":"education","lineage":["https://openalex.org/I40347166"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Huiying Li","raw_affiliation_strings":["University of Chicago, Chicago, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Chicago, Chicago, IL, USA","institution_ids":["https://openalex.org/I40347166","https://openalex.org/I39422238"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022672030","display_name":"Hai-Tao Zheng","orcid":"https://orcid.org/0000-0001-5128-5649"},"institutions":[{"id":"https://openalex.org/I40347166","display_name":"University of Chicago","ror":"https://ror.org/024mw5h28","country_code":"US","type":"education","lineage":["https://openalex.org/I40347166"]},{"id":"https://openalex.org/I39422238","display_name":"University of Illinois Chicago","ror":"https://ror.org/02mpq6x41","country_code":"US","type":"education","lineage":["https://openalex.org/I39422238"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Haitao Zheng","raw_affiliation_strings":["University of Chicago, Chicago, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Chicago, Chicago, IL, USA","institution_ids":["https://openalex.org/I40347166","https://openalex.org/I39422238"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5108248360","display_name":"Ben Y. Zhao","orcid":"https://orcid.org/0009-0003-8909-0494"},"institutions":[{"id":"https://openalex.org/I39422238","display_name":"University of Illinois Chicago","ror":"https://ror.org/02mpq6x41","country_code":"US","type":"education","lineage":["https://openalex.org/I39422238"]},{"id":"https://openalex.org/I40347166","display_name":"University of Chicago","ror":"https://ror.org/024mw5h28","country_code":"US","type":"education","lineage":["https://openalex.org/I40347166"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ben Y. Zhao","raw_affiliation_strings":["University of Chicago, Chicago, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Chicago, Chicago, IL, USA","institution_ids":["https://openalex.org/I40347166","https://openalex.org/I39422238"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5014146843"],"corresponding_institution_ids":["https://openalex.org/I39422238","https://openalex.org/I40347166"],"apc_list":null,"apc_paid":null,"fwci":24.9996,"has_fulltext":true,"cited_by_count":344,"citation_normalized_percentile":{"value":0.99626806,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"2041","last_page":"2055"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9866999983787537,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9800999760627747,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9958105087280273},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8256050944328308},{"id":"https://openalex.org/keywords/transfer-of-learning","display_name":"Transfer of learning","score":0.5488420724868774},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.5393486022949219},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5055091381072998},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.49359214305877686},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4811469316482544},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.43875280022621155},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4324193596839905},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.31952351331710815}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9958105087280273},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8256050944328308},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.5488420724868774},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.5393486022949219},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5055091381072998},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.49359214305877686},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4811469316482544},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.43875280022621155},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4324193596839905},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.31952351331710815},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3319535.3354209","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3354209","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354209","source":null,"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3319535.3354209","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3319535.3354209","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3319535.3354209","source":null,"license":"public-domain","license_id":"https://openalex.org/licenses/public-domain","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"score":0.5899999737739563,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G2811553095","display_name":null,"funder_award_id":"CNS-1527939","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G3485579720","display_name":"SaTC: CORE: Medium: Collaborative: Defending against Compromise and Manipulation of Mobile Communities","funder_award_id":"1705042","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G3818558036","display_name":null,"funder_award_id":"CNS-1705042","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G51858836","display_name":"TWC: Small: User Behavior Modeling and Prediction in Anonymous Social Networks","funder_award_id":"1527939","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2985913519.pdf","grobid_xml":"https://content.openalex.org/works/W2985913519.grobid-xml"},"referenced_works_count":46,"referenced_works":["https://openalex.org/W1968411139","https://openalex.org/W1978660892","https://openalex.org/W1998582365","https://openalex.org/W2007562169","https://openalex.org/W2062118960","https://openalex.org/W2103154003","https://openalex.org/W2117876524","https://openalex.org/W2126628495","https://openalex.org/W2126725946","https://openalex.org/W2158213899","https://openalex.org/W2180612164","https://openalex.org/W2275811363","https://openalex.org/W2325939864","https://openalex.org/W2550821151","https://openalex.org/W2552767274","https://openalex.org/W2607219512","https://openalex.org/W2618043096","https://openalex.org/W2626801932","https://openalex.org/W2748789698","https://openalex.org/W2753783305","https://openalex.org/W2759471388","https://openalex.org/W2787708942","https://openalex.org/W2796004214","https://openalex.org/W2805779034","https://openalex.org/W2807363941","https://openalex.org/W2888940765","https://openalex.org/W2900018096","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2949667497","https://openalex.org/W2950864148","https://openalex.org/W2953106684","https://openalex.org/W2962763344","https://openalex.org/W2962939738","https://openalex.org/W2963037989","https://openalex.org/W2963253279","https://openalex.org/W2963303951","https://openalex.org/W2963431851","https://openalex.org/W2963522845","https://openalex.org/W2963857521","https://openalex.org/W2964041528","https://openalex.org/W2964082701","https://openalex.org/W2964253222","https://openalex.org/W3037225663","https://openalex.org/W3102720581","https://openalex.org/W4252979261"],"related_works":["https://openalex.org/W4206357785","https://openalex.org/W4281381188","https://openalex.org/W3192840557","https://openalex.org/W2951211570","https://openalex.org/W4375928479","https://openalex.org/W3167935049","https://openalex.org/W3023427754","https://openalex.org/W3131673289","https://openalex.org/W4393011546","https://openalex.org/W4380075502"],"abstract_inverted_index":{"Recent":[0],"work":[1],"proposed":[2],"the":[3,81,134,138,145],"concept":[4],"of":[5,84,101,163,179,184],"backdoor":[6,102,146],"attacks":[7,103,172],"on":[8],"deep":[9],"neural":[10],"networks":[11],"(DNNs),":[12],"where":[13,36],"misclassification":[14],"rules":[15],"are":[16,111],"hidden":[17,77],"inside":[18],"normal":[19],"models,":[20],"only":[21,197],"to":[22,73],"be":[23,157],"triggered":[24],"by":[25,57,122,137],"very":[26],"specific":[27],"inputs.":[28],"However,":[29],"these":[30],"\"traditional\"":[31],"backdoors":[32,85,110,113,155],"assume":[33],"a":[34,62,95,116,161,208],"context":[35],"users":[37,50],"train":[38],"their":[39],"own":[40],"models":[41,54,74,125,132],"from":[42],"scratch,":[43],"which":[44],"rarely":[45],"occurs":[46],"in":[47,86,160,201,210],"practice.":[48,87],"Instead,":[49],"typically":[51],"customize":[52],"\"Teacher\"":[53,117],"already":[55],"pretrained":[56],"providers":[58],"like":[59],"Google,":[60],"through":[61,126,170],"process":[63,69,143],"called":[64],"transfer":[65,107,127],"learning.":[66,108,128],"This":[67],"customization":[68,142],"introduces":[70],"significant":[71],"changes":[72],"and":[75,98,119,147,166,181,194],"disrupts":[76],"backdoors,":[78,94,204],"greatly":[79],"reducing":[80],"actual":[82],"impact":[83],"In":[88],"this":[89],"paper,":[90],"we":[91,189],"describe":[92],"latent":[93,154,203],"more":[96],"powerful":[97],"stealthy":[99],"variant":[100],"that":[104,153,196],"functions":[105],"under":[106],"Latent":[109],"incomplete":[112],"embedded":[114],"into":[115],"model,":[118],"automatically":[120],"inherited":[121],"multiple":[123],"\"Student\"":[124],"If":[129],"any":[130],"Student":[131],"include":[133],"label":[135],"targeted":[136],"backdoor,":[139],"then":[140],"its":[141,168],"completes":[144],"makes":[148],"it":[149],"active.":[150],"We":[151],"show":[152],"can":[156],"quite":[158],"effective":[159,200],"variety":[162],"application":[164],"contexts,":[165],"validate":[167],"practicality":[169],"real-world":[171],"against":[173],"traffic":[174],"sign":[175],"recognition,":[176],"iris":[177],"identification":[178],"volunteers,":[180],"facial":[182],"recognition":[183],"public":[185],"figures":[186],"(politicians).":[187],"Finally,":[188],"evaluate":[190],"4":[191],"potential":[192],"defenses,":[193],"find":[195],"one":[198],"is":[199],"disrupting":[202],"but":[205],"might":[206],"incur":[207],"cost":[209],"classification":[211],"accuracy":[212],"as":[213],"tradeoff.":[214]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":42},{"year":2024,"cited_by_count":71},{"year":2023,"cited_by_count":55},{"year":2022,"cited_by_count":63},{"year":2021,"cited_by_count":67},{"year":2020,"cited_by_count":42},{"year":2019,"cited_by_count":1}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
