{"id":"https://openalex.org/W4307964213","doi":"https://doi.org/10.1145/3560830.3563730","title":"Just Rotate it: Deploying Backdoor Attacks via Rotation Transformation","display_name":"Just Rotate it: Deploying Backdoor Attacks via Rotation Transformation","publication_year":2022,"publication_date":"2022-11-02","ids":{"openalex":"https://openalex.org/W4307964213","doi":"https://doi.org/10.1145/3560830.3563730"},"language":"en","primary_location":{"id":"doi:10.1145/3560830.3563730","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3560830.3563730","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3560830.3563730","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3560830.3563730","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101847139","display_name":"Tong Wu","orcid":"https://orcid.org/0000-0001-5557-0623"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Tong Wu","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100610986","display_name":"Tianhao Wang","orcid":"https://orcid.org/0000-0002-9017-7947"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tianhao Wang","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011437254","display_name":"Vikash Sehwag","orcid":"https://orcid.org/0000-0001-7160-8556"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Vikash Sehwag","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049153799","display_name":"Saeed Mahloujifar","orcid":"https://orcid.org/0000-0001-6586-8378"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Saeed Mahloujifar","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5015619835","display_name":"Prateek Mittal","orcid":"https://orcid.org/0000-0002-4057-0118"},"institutions":[{"id":"https://openalex.org/I20089843","display_name":"Princeton University","ror":"https://ror.org/00hx57361","country_code":"US","type":"education","lineage":["https://openalex.org/I20089843"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Prateek Mittal","raw_affiliation_strings":["Princeton University, Princeton, NJ, USA"],"affiliations":[{"raw_affiliation_string":"Princeton University, Princeton, NJ, USA","institution_ids":["https://openalex.org/I20089843"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5101847139"],"corresponding_institution_ids":["https://openalex.org/I20089843"],"apc_list":null,"apc_paid":null,"fwci":4.1636,"has_fulltext":true,"cited_by_count":30,"citation_normalized_percentile":{"value":0.9470327,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"91","last_page":"102"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9919000267982483,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.968999981880188,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9953132271766663},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7889404296875},{"id":"https://openalex.org/keywords/spurious-relationship","display_name":"Spurious relationship","score":0.7068980932235718},{"id":"https://openalex.org/keywords/rotation","display_name":"Rotation (mathematics)","score":0.6858695149421692},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6028441190719604},{"id":"https://openalex.org/keywords/transformation","display_name":"Transformation (genetics)","score":0.568051278591156},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5668907165527344},{"id":"https://openalex.org/keywords/object","display_name":"Object (grammar)","score":0.5322031378746033},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.5208480954170227},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.4859689474105835},{"id":"https://openalex.org/keywords/object-detection","display_name":"Object detection","score":0.46532103419303894},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.44833311438560486},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3508165776729584},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.315540075302124}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9953132271766663},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7889404296875},{"id":"https://openalex.org/C97256817","wikidata":"https://www.wikidata.org/wiki/Q1462316","display_name":"Spurious relationship","level":2,"score":0.7068980932235718},{"id":"https://openalex.org/C74050887","wikidata":"https://www.wikidata.org/wiki/Q848368","display_name":"Rotation (mathematics)","level":2,"score":0.6858695149421692},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6028441190719604},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.568051278591156},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5668907165527344},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.5322031378746033},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.5208480954170227},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.4859689474105835},{"id":"https://openalex.org/C2776151529","wikidata":"https://www.wikidata.org/wiki/Q3045304","display_name":"Object detection","level":3,"score":0.46532103419303894},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.44833311438560486},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3508165776729584},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.315540075302124},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3560830.3563730","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3560830.3563730","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3560830.3563730","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3560830.3563730","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3560830.3563730","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3560830.3563730","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2800119129","display_name":null,"funder_award_id":"CNS-1553437","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5165965387","display_name":"CAREER: Trustworthy Social Systems Using Network Science","funder_award_id":"1553437","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5334156545","display_name":"SaTC: CORE: Medium: Collaborative: A Linguistically-Informed Approach for Measuring and Circumventing Internet Censorship","funder_award_id":"1704105","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G5528185634","display_name":null,"funder_award_id":"CNS-1553437, CNS-1704105","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320337345","display_name":"Office of Naval Research","ror":"https://ror.org/00rk2pe57"},{"id":"https://openalex.org/F4320338281","display_name":"Army Research Office","ror":"https://ror.org/05epdh915"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4307964213.pdf","grobid_xml":"https://content.openalex.org/works/W4307964213.grobid-xml"},"referenced_works_count":19,"referenced_works":["https://openalex.org/W639708223","https://openalex.org/W2019464758","https://openalex.org/W2031489346","https://openalex.org/W2096733369","https://openalex.org/W2117539524","https://openalex.org/W2194775991","https://openalex.org/W2325939864","https://openalex.org/W2535873859","https://openalex.org/W2798302089","https://openalex.org/W2934843808","https://openalex.org/W2963037989","https://openalex.org/W2963839617","https://openalex.org/W2963857521","https://openalex.org/W2990270730","https://openalex.org/W3106646114","https://openalex.org/W3118608800","https://openalex.org/W3138516171","https://openalex.org/W3143283098","https://openalex.org/W4225329125"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W3121164913"],"abstract_inverted_index":{"Recent":[0],"works":[1],"have":[2],"demonstrated":[3],"that":[4,32,123],"deep":[5],"learning":[6],"models":[7],"are":[8,37],"vulnerable":[9],"to":[10,20],"backdoor":[11,116,175],"poisoning":[12],"attacks,":[13],"where":[14],"these":[15],"attacks":[16],"instill":[17],"spurious":[18],"correlations":[19],"external":[21,34],"trigger":[22,35],"patterns":[23],"or":[24],"objects":[25,64],"(e.g.,":[26],"stickers,":[27],"sunglasses,":[28],"etc.).":[29],"We":[30],"find":[31,122],"such":[33],"signals":[36],"not":[38],"necessary,":[39],"as":[40,129,151],"highly":[41,171],"effective":[42,172],"backdoors":[43],"can":[44,127,136],"be":[45,137],"easily":[46,138],"inserted":[47],"using":[48],"rotation-based":[49],"image":[50,100,155],"transformation.":[51],"Our":[52,134,177],"method":[53],"constructs":[54],"the":[55,73,141,149],"poisoned":[56],"dataset":[57],"by":[58],"rotating":[59,148],"a":[60,85,130,165],"limited":[61],"amount":[62],"of":[63,125],"and":[65,102,113,121,157,170],"labeling":[66],"them":[67,126],"incorrectly;":[68],"once":[69],"trained":[70],"with":[71],"it,":[72],"victim's":[74],"model":[75],"will":[76],"make":[77],"undesirable":[78],"predictions":[79],"during":[80],"run-time":[81],"inference.":[82],"It":[83],"exhibits":[84],"significantly":[86],"high":[87],"attack":[88,120,135],"success":[89],"rate":[90],"while":[91],"maintaining":[92],"clean":[93],"performance":[94],"through":[95],"comprehensive":[96],"empirical":[97],"studies":[98],"on":[99],"classification":[101,156],"object":[103,158],"detection":[104,159],"tasks.":[105],"Furthermore,":[106],"we":[107],"evaluate":[108],"standard":[109],"data":[110],"augmentation":[111],"techniques":[112],"five":[114],"different":[115],"defenses":[117],"against":[118],"our":[119,162],"none":[124],"serve":[128],"consistent":[131],"mitigation":[132],"approach.":[133],"deployed":[139],"in":[140,153],"real":[142],"world":[143],"since":[144],"it":[145],"only":[146],"requires":[147],"object,":[150],"shown":[152],"both":[154],"applications.":[160],"Overall,":[161],"work":[163],"highlights":[164],"new,":[166],"simple,":[167],"physically":[168],"realizable,":[169],"vector":[173],"for":[174],"attacks.":[176],"video":[178],"demo":[179],"is":[180],"available":[181],"at":[182],"https://youtu.be/6JIF8wnX34M":[183]},"counts_by_year":[{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":12},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":1}],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2025-10-10T00:00:00"}
