{"id":"https://openalex.org/W4415794694","doi":"https://doi.org/10.1145/3774648","title":"Flareon: Stealthy All2all Backdoor Injection via Poisoned Augmentation","display_name":"Flareon: Stealthy All2all Backdoor Injection via Poisoned Augmentation","publication_year":2025,"publication_date":"2025-11-03","ids":{"openalex":"https://openalex.org/W4415794694","doi":"https://doi.org/10.1145/3774648"},"language":"en","primary_location":{"id":"doi:10.1145/3774648","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3774648","pdf_url":null,"source":{"id":"https://openalex.org/S41523882","display_name":"ACM Transactions on Knowledge Discovery from Data","issn_l":"1556-4681","issn":["1556-4681","1556-472X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Knowledge Discovery from Data","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5118625832","display_name":"Tianrui Qin","orcid":"https://orcid.org/0009-0002-8386-2003"},"institutions":[{"id":"https://openalex.org/I4210145761","display_name":"Shenzhen Institutes of Advanced Technology","ror":"https://ror.org/04gh4er46","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210145761"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Tianrui Qin","raw_affiliation_strings":["Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen, China and OPPO Research Institute, Shenzhen, China","Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, China and OPPO Research Institute, China"],"raw_orcid":"https://orcid.org/0009-0002-8386-2003","affiliations":[{"raw_affiliation_string":"Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen, China and OPPO Research Institute, Shenzhen, China","institution_ids":["https://openalex.org/I4210145761"]},{"raw_affiliation_string":"Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, China and OPPO Research Institute, China","institution_ids":["https://openalex.org/I4210145761"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002605073","display_name":"Xuan Wang","orcid":"https://orcid.org/0000-0001-9900-9117"},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xuan Wang","raw_affiliation_strings":["Anhui Key Lab of CSSAE, National University of Defense Technology, Hefei, China"],"raw_orcid":"https://orcid.org/0000-0001-9900-9117","affiliations":[{"raw_affiliation_string":"Anhui Key Lab of CSSAE, National University of Defense Technology, Hefei, China","institution_ids":["https://openalex.org/I170215575"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5006560053","display_name":"Xianghuan He","orcid":"https://orcid.org/0009-0007-3962-4549"},"institutions":[{"id":"https://openalex.org/I76835614","display_name":"University of Missouri","ror":"https://ror.org/02ymw8z06","country_code":"US","type":"education","lineage":["https://openalex.org/I76835614"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xianghuan He","raw_affiliation_strings":["University of Missouri, Columbia, Missouri, USA"],"raw_orcid":"https://orcid.org/0009-0007-3962-4549","affiliations":[{"raw_affiliation_string":"University of Missouri, Columbia, Missouri, USA","institution_ids":["https://openalex.org/I76835614"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101093262","display_name":"Yiren Zhao","orcid":"https://orcid.org/0000-0002-3727-7463"},"institutions":[{"id":"https://openalex.org/I47508984","display_name":"Imperial College London","ror":"https://ror.org/041kmwe10","country_code":"GB","type":"education","lineage":["https://openalex.org/I47508984"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Yiren Zhao","raw_affiliation_strings":["Imperial College London, London, United Kingdom of Great Britain and Northern Ireland"],"raw_orcid":"https://orcid.org/0000-0002-3727-7463","affiliations":[{"raw_affiliation_string":"Imperial College London, London, United Kingdom of Great Britain and Northern Ireland","institution_ids":["https://openalex.org/I47508984"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012757772","display_name":"Kejiang Ye","orcid":"https://orcid.org/0000-0001-6133-407X"},"institutions":[{"id":"https://openalex.org/I4210145761","display_name":"Shenzhen Institutes of Advanced Technology","ror":"https://ror.org/04gh4er46","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210145761"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kejiang Ye","raw_affiliation_strings":["Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen,\u00a0China"],"raw_orcid":"https://orcid.org/0000-0001-6133-407X","affiliations":[{"raw_affiliation_string":"Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen,\u00a0China","institution_ids":["https://openalex.org/I4210145761"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012773300","display_name":"Chengzhong Xu","orcid":"https://orcid.org/0000-0001-9480-0356"},"institutions":[{"id":"https://openalex.org/I204512498","display_name":"University of Macau","ror":"https://ror.org/01r4q9n85","country_code":"MO","type":"education","lineage":["https://openalex.org/I204512498"]},{"id":"https://openalex.org/I6469544","display_name":"City University of Macau","ror":"https://ror.org/04gpd4q15","country_code":"MO","type":"education","lineage":["https://openalex.org/I6469544"]}],"countries":["MO"],"is_corresponding":false,"raw_author_name":"Cheng-Zhong Xu","raw_affiliation_strings":["State Key Laboratory for Internet of Things for Smart City, University of Macau, Taipa, Macau S.A.R., China","University of Macau, Macau S.A.R., China"],"raw_orcid":"https://orcid.org/0000-0001-9480-0356","affiliations":[{"raw_affiliation_string":"State Key Laboratory for Internet of Things for Smart City, University of Macau, Taipa, Macau S.A.R., China","institution_ids":["https://openalex.org/I6469544","https://openalex.org/I204512498"]},{"raw_affiliation_string":"University of Macau, Macau S.A.R., China","institution_ids":["https://openalex.org/I204512498"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5026189787","display_name":"Xitong Gao","orcid":"https://orcid.org/0000-0002-2063-2051"},"institutions":[{"id":"https://openalex.org/I180726961","display_name":"Shenzhen University","ror":"https://ror.org/01vy4gh70","country_code":"CN","type":"education","lineage":["https://openalex.org/I180726961"]},{"id":"https://openalex.org/I4210145761","display_name":"Shenzhen Institutes of Advanced Technology","ror":"https://ror.org/04gh4er46","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210145761"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xitong Gao","raw_affiliation_strings":["Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen, China and Shenzhen University of Advanced Technology, Shenzhen, China"],"raw_orcid":"https://orcid.org/0000-0002-2063-2051","affiliations":[{"raw_affiliation_string":"Shenzhen Institutes of Advanced Technology, Chinese Academy of Sciences, Shenzhen, China and Shenzhen University of Advanced Technology, Shenzhen, China","institution_ids":["https://openalex.org/I4210145761","https://openalex.org/I180726961"]}]}],"institutions":[],"countries_distinct_count":4,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5118625832"],"corresponding_institution_ids":["https://openalex.org/I4210145761"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.15563242,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"20","issue":"1","first_page":"1","last_page":"23"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7753000259399414,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7753000259399414,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.08169999718666077,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.059300001710653305,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9775999784469604},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5483999848365784},{"id":"https://openalex.org/keywords/source-code","display_name":"Source code","score":0.4756999909877777},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.4697999954223633},{"id":"https://openalex.org/keywords/resilience","display_name":"Resilience (materials science)","score":0.4487999975681305},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.4462999999523163},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.41179999709129333},{"id":"https://openalex.org/keywords/open-source","display_name":"Open source","score":0.4083000123500824}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9775999784469604},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.713699996471405},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5483999848365784},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.507099986076355},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4823000133037567},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.4756999909877777},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.4697999954223633},{"id":"https://openalex.org/C2779585090","wikidata":"https://www.wikidata.org/wiki/Q3457762","display_name":"Resilience (materials science)","level":2,"score":0.4487999975681305},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.4462999999523163},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.41179999709129333},{"id":"https://openalex.org/C3018397939","wikidata":"https://www.wikidata.org/wiki/Q3644502","display_name":"Open source","level":3,"score":0.4083000123500824},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.39070001244544983},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.3828999996185303},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.3785000145435333},{"id":"https://openalex.org/C204323151","wikidata":"https://www.wikidata.org/wiki/Q905424","display_name":"Range (aeronautics)","level":2,"score":0.36719998717308044},{"id":"https://openalex.org/C2777904410","wikidata":"https://www.wikidata.org/wiki/Q7397","display_name":"Software","level":2,"score":0.3425000011920929},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3305000066757202},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.32190001010894775},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.32120001316070557},{"id":"https://openalex.org/C2776654903","wikidata":"https://www.wikidata.org/wiki/Q2601463","display_name":"SAFER","level":2,"score":0.2784000039100647},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.25519999861717224}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3774648","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3774648","pdf_url":null,"source":{"id":"https://openalex.org/S41523882","display_name":"ACM Transactions on Knowledge Discovery from Data","issn_l":"1556-4681","issn":["1556-4681","1556-472X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Knowledge Discovery from Data","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1501130358","display_name":null,"funder_award_id":"62376263","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4386207735","display_name":null,"funder_award_id":"JCYJ20230807140507015","funder_id":"https://openalex.org/F4320326705","funder_display_name":"Science, Technology and Innovation Commission of Shenzhen Municipality"},{"id":"https://openalex.org/G7362547439","display_name":null,"funder_award_id":"2024A1515030209","funder_id":"https://openalex.org/F4320321921","funder_display_name":"Natural Science Foundation of Guangdong Province"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320321921","display_name":"Natural Science Foundation of Guangdong Province","ror":null},{"id":"https://openalex.org/F4320326705","display_name":"Science, Technology and Innovation Commission of Shenzhen Municipality","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":6,"referenced_works":["https://openalex.org/W2194775991","https://openalex.org/W2807363941","https://openalex.org/W2934843808","https://openalex.org/W2963163009","https://openalex.org/W3010216907","https://openalex.org/W3035367371"],"related_works":[],"abstract_inverted_index":{"Open":[0],"source":[1,16,177],"software":[2],"supply-chain":[3],"attacks,":[4],"once":[5],"successful,":[6],"can":[7,130],"exact":[8],"heavy":[9],"costs":[10],"in":[11,36,122],"mission-critical":[12],"applications.":[13],"As":[14],"open":[15,176],"ecosystems":[17],"for":[18,136],"deep":[19,37,183],"learning":[20,184],"flourish":[21],"and":[22,87,140,178],"become":[23],"increasingly":[24],"universal,":[25],"they":[26],"present":[27],"attackers":[28],"previously":[29],"unexplored":[30],"avenues":[31],"to":[32,181],"code-inject":[33],"malicious":[34],"backdoors":[35],"neural":[38],"network":[39],"models.":[40],"This":[41],"article":[42],"proposes":[43],"Flareon":[44,63,101,117,166,173],",":[45],"a":[46,93,113,168],"small,":[47],"stealthy,":[48],"seemingly":[49],"harmless":[50],"code":[51],"modification":[52],"that":[53,118,147],"specifically":[54],"targets":[55],"the":[56,70,81,163,182],"data":[57],"augmentation":[58],"pipeline":[59],"with":[60],"motion-based":[61],"triggers.":[62],"neither":[64],"alters":[65],"ground-truth":[66],"labels,":[67],"nor":[68,74],"modifies":[69],"training":[71,85,88],"loss":[72],"objective,":[73],"does":[75],"it":[76,91],"assume":[77,155],"prior":[78],"knowledge":[79],"of":[80,116,124,165,171],"victim":[82],"model":[83],"architecture,":[84],"data,":[86],"hyperparameters.":[89],"Yet,":[90],"has":[92],"surprisingly":[94],"large":[95],"ramification":[96],"on":[97],"training\u2014models":[98],"trained":[99],"under":[100],"learn":[102],"powerful":[103],"target-conditioned":[104],"(or":[105],"\u201c":[106],"all2all":[107],"\u201d)":[108],"backdoors.":[109],"We":[110,160],"also":[111,154,161],"proposed":[112],"learnable":[114],"variant":[115],"is":[119,174],"even":[120],"stealthier":[121],"terms":[123],"added":[125],"perturbations.":[126],"The":[127],"resulting":[128],"models":[129],"exhibit":[131],"high":[132],"attack":[133,158],"success":[134],"rates":[135],"any":[137],"target":[138],"choices":[139],"better":[141],"clean":[142],"accuracies":[143],"than":[144],"backdoor":[145],"attacks":[146],"not":[148],"only":[149],"seize":[150],"greater":[151],"control":[152],"but":[153],"more":[156],"restrictive":[157],"capabilities.":[159],"demonstrate":[162],"resilience":[164],"against":[167],"wide":[169],"range":[170],"defenses.":[172],"fully":[175],"available":[179],"online":[180],"community.":[185]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2025-11-03T00:00:00"}
