{"id":"https://openalex.org/W4416132581","doi":"https://doi.org/10.1145/3736425.3772355","title":"SifterNet: Model-Agnostic Defense against Backdoor Attack in Vision Large Model","display_name":"SifterNet: Model-Agnostic Defense against Backdoor Attack in Vision Large Model","publication_year":2025,"publication_date":"2025-11-11","ids":{"openalex":"https://openalex.org/W4416132581","doi":"https://doi.org/10.1145/3736425.3772355"},"language":null,"primary_location":{"id":"doi:10.1145/3736425.3772355","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3736425.3772355","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3736425.3772355","source":null,"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3736425.3772355","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5110981665","display_name":"Shaoye Luo","orcid":"https://orcid.org/0009-0000-0058-2811"},"institutions":[{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Shaoye Luo","raw_affiliation_strings":["University of Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China, Beijing, China"],"affiliations":[{"raw_affiliation_string":"University of Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China, Beijing, China","institution_ids":["https://openalex.org/I4210090176"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046658556","display_name":"Xinxin Fan","orcid":"https://orcid.org/0000-0002-6659-7431"},"institutions":[{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinxin Fan","raw_affiliation_strings":["Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China, Beijing, China","institution_ids":["https://openalex.org/I4210090176"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5009094383","display_name":"Quanliang Jing","orcid":"https://orcid.org/0000-0002-7670-7729"},"institutions":[{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Quanliang Jing","raw_affiliation_strings":["Institute of Computing Technology, Beijing, China, Beijing, Chile"],"affiliations":[{"raw_affiliation_string":"Institute of Computing Technology, Beijing, China, Beijing, Chile","institution_ids":["https://openalex.org/I4210090176"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033531006","display_name":"Minglu Niu","orcid":"https://orcid.org/0009-0004-6317-497X"},"institutions":[{"id":"https://openalex.org/I4210090176","display_name":"Institute of Computing Technology","ror":"https://ror.org/0090r4d87","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210090176"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Men Niu","raw_affiliation_strings":["University of Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China, Beijing, China"],"affiliations":[{"raw_affiliation_string":"University of Chinese Academy of Sciences, Institute of Computing Technology, Chinese Academy of Sciences, Beijing, China, Beijing, China","institution_ids":["https://openalex.org/I4210090176"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014651715","display_name":"Chi Lin","orcid":"https://orcid.org/0000-0002-0302-5102"},"institutions":[{"id":"https://openalex.org/I27357992","display_name":"Dalian University of Technology","ror":"https://ror.org/023hj5876","country_code":"CN","type":"education","lineage":["https://openalex.org/I27357992"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chi Lin","raw_affiliation_strings":["Dalian University of Technology, Dalian, LiaoNing, China"],"affiliations":[{"raw_affiliation_string":"Dalian University of Technology, Dalian, LiaoNing, China","institution_ids":["https://openalex.org/I27357992"]}]},{"author_position":"last","author":{"id":null,"display_name":"Yunfeng Lu","orcid":"https://orcid.org/0009-0000-5201-180X"},"institutions":[{"id":"https://openalex.org/I82880672","display_name":"Beihang University","ror":"https://ror.org/00wk2mp56","country_code":"CN","type":"education","lineage":["https://openalex.org/I82880672"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunfeng Lu","raw_affiliation_strings":["Beihang University, Beijing, China, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Beihang University, Beijing, China, Beijing, China","institution_ids":["https://openalex.org/I82880672"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5110981665"],"corresponding_institution_ids":["https://openalex.org/I4210090176"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.1789136,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"389","last_page":"393"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9692000150680542,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9692000150680542,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.003700000001117587,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.0027000000700354576,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9629999995231628},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.5450999736785889},{"id":"https://openalex.org/keywords/novelty","display_name":"Novelty","score":0.48739999532699585},{"id":"https://openalex.org/keywords/convolution","display_name":"Convolution (computer science)","score":0.4830000102519989},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.39959999918937683},{"id":"https://openalex.org/keywords/countermeasure","display_name":"Countermeasure","score":0.38530001044273376}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9629999995231628},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7014999985694885},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.5450999736785889},{"id":"https://openalex.org/C2778738651","wikidata":"https://www.wikidata.org/wiki/Q16546687","display_name":"Novelty","level":2,"score":0.48739999532699585},{"id":"https://openalex.org/C45347329","wikidata":"https://www.wikidata.org/wiki/Q5166604","display_name":"Convolution (computer science)","level":3,"score":0.4830000102519989},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4650999903678894},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4221999943256378},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.39959999918937683},{"id":"https://openalex.org/C21593369","wikidata":"https://www.wikidata.org/wiki/Q1032176","display_name":"Countermeasure","level":2,"score":0.38530001044273376},{"id":"https://openalex.org/C48659774","wikidata":"https://www.wikidata.org/wiki/Q4907197","display_name":"Bijection, injection and surjection","level":3,"score":0.38260000944137573},{"id":"https://openalex.org/C2778924833","wikidata":"https://www.wikidata.org/wiki/Q7064603","display_name":"Novelty detection","level":3,"score":0.31380000710487366},{"id":"https://openalex.org/C2776639384","wikidata":"https://www.wikidata.org/wiki/Q840396","display_name":"Ideal (ethics)","level":2,"score":0.3102000057697296},{"id":"https://openalex.org/C2781067378","wikidata":"https://www.wikidata.org/wiki/Q17027399","display_name":"Interpretability","level":2,"score":0.3000999987125397},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.29919999837875366},{"id":"https://openalex.org/C2780615836","wikidata":"https://www.wikidata.org/wiki/Q2471869","display_name":"USable","level":2,"score":0.26109999418258667},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.259799987077713}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3736425.3772355","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3736425.3772355","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3736425.3772355","source":null,"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3736425.3772355","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3736425.3772355","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3736425.3772355","source":null,"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th ACM International Conference on Systems for Energy-Efficient Buildings, Cities, and Transportation","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4039563609","display_name":null,"funder_award_id":"XDB06","funder_id":"https://openalex.org/F4320321133","funder_display_name":"Chinese Academy of Sciences"}],"funders":[{"id":"https://openalex.org/F4320321133","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35"}],"has_content":{"grobid_xml":false,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4416132581.pdf"},"referenced_works_count":8,"referenced_works":["https://openalex.org/W2112246162","https://openalex.org/W2112738128","https://openalex.org/W2112796928","https://openalex.org/W2128084896","https://openalex.org/W2133059825","https://openalex.org/W3001916452","https://openalex.org/W4384915898","https://openalex.org/W4410291923"],"related_works":[],"abstract_inverted_index":{"Vision":[0],"models":[1,28,125],"have":[2],"been":[3],"applied":[4],"into":[5],"urban":[6],"computing,":[7],"vision-language":[8],"navigation,":[9],"intelligent":[10],"transportation,":[11],"etc.":[12],"Nevertheless,":[13],"various":[14],"convolution":[15],"neural":[16],"networks":[17],"(CNN)-based":[18],"vision":[19,25,45],"models,":[20,46],"or":[21,89],"even":[22,90],"the":[23,57,73,95,107,117,123,141,149,171,184,202],"recently-developed":[24],"Transformer-based":[26],"large":[27,84],"all":[29],"encounter":[30],"security":[31],"and":[32,51,132,195,199],"privacy":[33],"issues.":[34],"In":[35],"this":[36,128],"paper,":[37],"aiming":[38],"at":[39],"resisting":[40],"backdoor":[41,216],"attacks":[42],"in":[43,61,79,102,158,170,189],"these":[44],"we":[47],"proposes":[48],"a":[49,83,130,159,209],"generalized":[50],"model-agnostic":[52],"trigger-purification":[53],"approach":[54,135,168,188],"resorting":[55],"to":[56,71,82,106,115,201],"classic":[58],"Ising":[59,176],"model":[60,78],"physics.":[62],"To":[63,127],"date,":[64],"existing":[65],"trigger":[66,119,193],"detection/removal":[67],"studies":[68],"usually":[69],"require":[70],"know":[72],"detailed":[74],"knowledge":[75],"of":[76,86,104,144,151,165,173,175,180,186,191],"target":[77,108,124],"advance,":[80],"access":[81],"number":[85],"clean":[87],"samples":[88,153],"model-retraining":[91],"authorization,":[92],"which":[93,148],"brings":[94],"huge":[96],"inconvenience":[97],"for":[98],"practical":[99],"applications,":[100],"especially":[101],"case":[103],"inaccessibility":[105],"model.":[109,177],"Thereby,":[110],"an":[111],"ideal":[112],"countermeasure":[113],"ought":[114],"eliminate":[116],"implanted":[118],"without":[120],"regarding":[121],"whatever":[122],"are.":[126],"end,":[129],"lightweight":[131],"black-box":[133],"defense":[134],"SifterNet":[136],"is":[137],"proposed":[138,167,206],"through":[139],"leveraging":[140],"memorization-association":[142],"functionality":[143],"Hopfield":[145],"network,":[146],"by":[147],"triggers":[150],"input":[152],"can":[154],"be":[155],"effectively":[156],"purified":[157],"proper":[160,192],"manner.":[161],"The":[162],"main":[163],"novelty":[164],"our":[166,187,205],"lies":[169],"introduction":[172],"ideology":[174],"A":[178],"set":[179],"experiments":[181],"also":[182],"validate":[183],"effectiveness":[185],"terms":[190],"purification":[194],"high":[196],"accuracy":[197],"achievement,":[198],"compared":[200],"state-of-the-art":[203],"baselines,":[204],"SiferNet":[207],"has":[208],"significant":[210],"superior":[211],"performance":[212],"under":[213],"five":[214],"popular":[215],"attacks.":[217]},"counts_by_year":[],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-11-11T00:00:00"}
