{"id":"https://openalex.org/W4396843660","doi":"https://doi.org/10.1145/3589335.3651525","title":"Interpretation-Empowered Neural Cleanse for Backdoor Attacks","display_name":"Interpretation-Empowered Neural Cleanse for Backdoor Attacks","publication_year":2024,"publication_date":"2024-05-12","ids":{"openalex":"https://openalex.org/W4396843660","doi":"https://doi.org/10.1145/3589335.3651525"},"language":"en","primary_location":{"id":"doi:10.1145/3589335.3651525","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3589335.3651525","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3589335.3651525","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Companion Proceedings of the ACM Web Conference 2024","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3589335.3651525","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5031718186","display_name":"Liangbo Ning","orcid":"https://orcid.org/0000-0001-6903-8996"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":true,"raw_author_name":"Liang-bo Ning","raw_affiliation_strings":["The Hong Kong Polytechnic University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035686964","display_name":"Zeyu Dai","orcid":"https://orcid.org/0000-0002-1351-476X"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Zeyu Dai","raw_affiliation_strings":["The Hong Kong Polytechnic University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072056125","display_name":"Jingran Su","orcid":"https://orcid.org/0000-0002-9873-1770"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Jingran Su","raw_affiliation_strings":["The Hong Kong Polytechnic University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103111054","display_name":"Chao Pan","orcid":"https://orcid.org/0000-0001-7406-5200"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Chao Pan","raw_affiliation_strings":["The Hong Kong Polytechnic University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100647855","display_name":"Luning Wang","orcid":"https://orcid.org/0009-0001-1101-2686"},"institutions":[{"id":"https://openalex.org/I2250955327","display_name":"Huawei Technologies (China)","ror":"https://ror.org/00cmhce21","country_code":"CN","type":"company","lineage":["https://openalex.org/I2250955327"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Luning Wang","raw_affiliation_strings":["Huawei, Hong Kong, China"],"affiliations":[{"raw_affiliation_string":"Huawei, Hong Kong, China","institution_ids":["https://openalex.org/I2250955327"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043696243","display_name":"Wenqi Fan","orcid":"https://orcid.org/0000-0002-4049-1233"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Wenqi Fan","raw_affiliation_strings":["Department of Computing, and Department of Management and Marketing, The Hong Kong Polytechnic University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"Department of Computing, and Department of Management and Marketing, The Hong Kong Polytechnic University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100404176","display_name":"Qing Li","orcid":"https://orcid.org/0000-0003-3370-471X"},"institutions":[{"id":"https://openalex.org/I14243506","display_name":"Hong Kong Polytechnic University","ror":"https://ror.org/0030zas98","country_code":"HK","type":"education","lineage":["https://openalex.org/I14243506"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Qing Li","raw_affiliation_strings":["The Hong Kong Polytechnic University, Hong Kong, Hong Kong"],"affiliations":[{"raw_affiliation_string":"The Hong Kong Polytechnic University, Hong Kong, Hong Kong","institution_ids":["https://openalex.org/I14243506"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5031718186"],"corresponding_institution_ids":["https://openalex.org/I14243506"],"apc_list":null,"apc_paid":null,"fwci":1.366,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.83204407,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":97,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"951","last_page":"954"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9916999936103821,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9876000285148621,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9741173982620239},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.697321355342865},{"id":"https://openalex.org/keywords/interpretation","display_name":"Interpretation (philosophy)","score":0.6489360332489014},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5248313546180725},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4668026268482208},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.44989579916000366},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.20159581303596497}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9741173982620239},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.697321355342865},{"id":"https://openalex.org/C527412718","wikidata":"https://www.wikidata.org/wiki/Q855395","display_name":"Interpretation (philosophy)","level":2,"score":0.6489360332489014},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5248313546180725},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4668026268482208},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.44989579916000366},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.20159581303596497}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3589335.3651525","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3589335.3651525","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3589335.3651525","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Companion Proceedings of the ACM Web Conference 2024","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3589335.3651525","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3589335.3651525","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3589335.3651525","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Companion Proceedings of the ACM Web Conference 2024","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G7322147438","display_name":null,"funder_award_id":"project no. 62102335","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"}],"funders":[{"id":"https://openalex.org/F4320323817","display_name":"Universitas Brawijaya","ror":"https://ror.org/01wk3d929"}],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4396843660.pdf"},"referenced_works_count":7,"referenced_works":["https://openalex.org/W2606462007","https://openalex.org/W2807363941","https://openalex.org/W2934843808","https://openalex.org/W2985913519","https://openalex.org/W2990270730","https://openalex.org/W3042368254","https://openalex.org/W3101609372"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4386080799","https://openalex.org/W3140988292","https://openalex.org/W4317672133","https://openalex.org/W4386185023"],"abstract_inverted_index":{"Backdoor":[0],"attacks":[1,47,151],"have":[2],"posed":[3],"a":[4,65,117],"significant":[5],"threat":[6],"to":[7,29,55,84,90,107,124,131],"deep":[8],"neural":[9,70],"networks,":[10],"highlighting":[11],"the":[12,32,49,86,94,109,113,126,133,144,153,156],"need":[13],"for":[14,74],"robust":[15],"defense":[16,43,134],"strategies.":[17],"Previous":[18],"research":[19],"has":[20],"demonstrated":[21],"that":[22],"attribution":[23],"maps":[24],"change":[25],"substantially":[26],"when":[27],"exposed":[28],"attacks,":[30],"suggesting":[31],"potential":[33,145],"of":[34,52,146,155],"interpreters":[35,87],"in":[36,148],"detecting":[37],"adversarial":[38],"examples.":[39],"However,":[40],"most":[41],"existing":[42],"methods":[44],"against":[45],"backdoor":[46,76,96,150],"overlook":[48],"untapped":[50],"capabilities":[51],"interpreters,":[53],"failing":[54],"fully":[56],"leverage":[57],"their":[58],"potential.":[59],"In":[60],"this":[61],"paper,":[62],"we":[63],"propose":[64],"novel":[66],"approach":[67,121],"called":[68],"interpretation-empowered":[69,100],"cleanse":[71,108],"(IENC":[72],")":[73],"defending":[75,149],"attacks.":[77],"Specifically,":[78],"integrated":[79],"gradient":[80],"(IG)":[81],"is":[82,105,122],"adopted":[83],"bridge":[85],"and":[88,92,128,152],"classifiers":[89],"reverse":[91],"reconstruct":[93],"high-quality":[95],"trigger.":[97],"Then,":[98],"an":[99],"adaptative":[101],"pruning":[102],"strategy":[103],"(IEAPS)":[104],"proposed":[106,157],"backdoor-related":[110],"neurons":[111],"without":[112],"pre-defined":[114],"threshold.":[115],"Additionally,":[116],"hybrid":[118],"model":[119],"patching":[120],"employed":[123],"integrate":[125],"IEAPS":[127],"preprocessing":[129],"techniques":[130],"enhance":[132],"performance.":[135],"Comprehensive":[136],"experiments":[137],"are":[138],"constructed":[139],"on":[140],"various":[141],"datasets,":[142],"demonstrating":[143],"interpretations":[147],"superiority":[154],"method.":[158]},"counts_by_year":[{"year":2025,"cited_by_count":4}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
