{"id":"https://openalex.org/W2971661634","doi":"https://doi.org/10.1145/3427228.3427264","title":"Februus: Input Purification Defense Against Trojan Attacks on Deep Neural Network Systems","display_name":"Februus: Input Purification Defense Against Trojan Attacks on Deep Neural Network Systems","publication_year":2020,"publication_date":"2020-12-07","ids":{"openalex":"https://openalex.org/W2971661634","doi":"https://doi.org/10.1145/3427228.3427264","mag":"2971661634"},"language":"en","primary_location":{"id":"doi:10.1145/3427228.3427264","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427264","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/1908.03369","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5070336991","display_name":"Bao Gia Doan","orcid":"https://orcid.org/0000-0001-6941-2765"},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Bao Gia Doan","raw_affiliation_strings":["The University of Adelaide, Australia"],"affiliations":[{"raw_affiliation_string":"The University of Adelaide, Australia","institution_ids":["https://openalex.org/I5681781"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058061726","display_name":"Ehsan Abbasnejad","orcid":null},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Ehsan Abbasnejad","raw_affiliation_strings":["The University of Adelaide"],"affiliations":[{"raw_affiliation_string":"The University of Adelaide","institution_ids":["https://openalex.org/I5681781"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5048703299","display_name":"Damith C. Ranasinghe","orcid":"https://orcid.org/0000-0002-2008-9255"},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Damith C. Ranasinghe","raw_affiliation_strings":["The University of Adelaide, Australia"],"affiliations":[{"raw_affiliation_string":"The University of Adelaide, Australia","institution_ids":["https://openalex.org/I5681781"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5070336991"],"corresponding_institution_ids":["https://openalex.org/I5681781"],"apc_list":null,"apc_paid":null,"fwci":14.8565,"has_fulltext":false,"cited_by_count":238,"citation_normalized_percentile":{"value":0.99221857,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"897","last_page":"912"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9882000088691711,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9872000217437744,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.8710122108459473},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6502152681350708},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5716484189033508},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.562138020992279},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.27774113416671753}],"concepts":[{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.8710122108459473},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6502152681350708},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5716484189033508},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.562138020992279},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.27774113416671753}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3427228.3427264","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3427228.3427264","pdf_url":null,"source":{"id":"https://openalex.org/S4306417673","display_name":"Annual Computer Security Applications Conference","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Annual Computer Security Applications Conference","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:1908.03369","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1908.03369","pdf_url":"https://arxiv.org/pdf/1908.03369","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:1908.03369","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1908.03369","pdf_url":"https://arxiv.org/pdf/1908.03369","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":74,"referenced_works":["https://openalex.org/W569478347","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1945616565","https://openalex.org/W1977610018","https://openalex.org/W2067713319","https://openalex.org/W2099471712","https://openalex.org/W2110889728","https://openalex.org/W2119112357","https://openalex.org/W2140609507","https://openalex.org/W2145287260","https://openalex.org/W2187089797","https://openalex.org/W2194775991","https://openalex.org/W2240067561","https://openalex.org/W2325939864","https://openalex.org/W2350778671","https://openalex.org/W2610321374","https://openalex.org/W2738588019","https://openalex.org/W2748789698","https://openalex.org/W2752517284","https://openalex.org/W2753783305","https://openalex.org/W2772825438","https://openalex.org/W2774423163","https://openalex.org/W2777186991","https://openalex.org/W2788097838","https://openalex.org/W2791175987","https://openalex.org/W2800416765","https://openalex.org/W2807363941","https://openalex.org/W2807765471","https://openalex.org/W2810065831","https://openalex.org/W2902351501","https://openalex.org/W2914712270","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2949152835","https://openalex.org/W2949311987","https://openalex.org/W2962835968","https://openalex.org/W2962858109","https://openalex.org/W2962879692","https://openalex.org/W2963207607","https://openalex.org/W2963389226","https://openalex.org/W2963629198","https://openalex.org/W2963839617","https://openalex.org/W2963857521","https://openalex.org/W2964082701","https://openalex.org/W2964153729","https://openalex.org/W2964253222","https://openalex.org/W2966187620","https://openalex.org/W2966689772","https://openalex.org/W2986013765","https://openalex.org/W2990052251","https://openalex.org/W2990270730","https://openalex.org/W2996800219","https://openalex.org/W3008901592","https://openalex.org/W3011700838","https://openalex.org/W3022042319","https://openalex.org/W3022179901","https://openalex.org/W3036721937","https://openalex.org/W3037024761","https://openalex.org/W3083185154","https://openalex.org/W3101294892","https://openalex.org/W3103940881","https://openalex.org/W3107337211","https://openalex.org/W3118608800","https://openalex.org/W3195462295","https://openalex.org/W4206627894","https://openalex.org/W4252979261","https://openalex.org/W4288101435","https://openalex.org/W4289300166","https://openalex.org/W4293846201","https://openalex.org/W4295521014","https://openalex.org/W4320013936","https://openalex.org/W4365800072","https://openalex.org/W4385679845"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W4253721122","https://openalex.org/W1671033612","https://openalex.org/W4389527383","https://openalex.org/W4206524843","https://openalex.org/W2139923244","https://openalex.org/W2237899707","https://openalex.org/W576137284"],"abstract_inverted_index":{"We":[0,130],"propose":[1],"Februus;":[2],"a":[3,28,32,38,41,53],"new":[4],"idea":[5],"to":[6,44,47,52,62,138,155],"neutralize":[7],"highly":[8],"potent":[9],"and":[10,59,77,121,149],"insidious":[11],"Trojan":[12,23,88,171],"attacks":[13],"on":[14,107,112,146],"Deep":[15],"Neural":[16],"Network":[17],"(DNN)":[18],"systems":[19],"at":[20,188],"run-time.":[21],"In":[22],"attacks,":[24],"an":[25],"adversary":[26],"activates":[27],"backdoor":[29,183],"crafted":[30],"in":[31],"deep":[33],"neural":[34],"network":[35],"model":[36,200],"using":[37],"secret":[39],"trigger,":[40],"Trojan,":[42],"applied":[43],"any":[45],"input":[46,69,80],"alter":[48],"the":[49,63,67,73,79,82,125,151,164,168,174,181],"model\u2019s":[50],"decision":[51],"target":[54,56],"prediction\u2014a":[55],"determined":[57],"by":[58,70,90],"only":[60],"known":[61],"attacker.":[64],"Februus":[65,85,154,179],"sanitizes":[66],"incoming":[68],"surgically":[71],"removing":[72],"potential":[74],"trigger":[75,122],"artifacts":[76],"restoring":[78],"for":[81,98,141,186],"classification":[83],"task.":[84],"enables":[86],"effective":[87],"mitigation":[89],"sanitizing":[91,192],"inputs":[92,194],"with":[93],"no":[94],"loss":[95],"of":[96,128,153,176,191],"performance":[97],"sanitized":[99],"inputs,":[100],"Trojaned":[101,193],"or":[102,202],"benign.":[103],"Our":[104],"extensive":[105],"evaluations":[106],"multiple":[108,147],"infected":[109],"models":[110],"based":[111],"four":[113],"popular":[114],"datasets":[115],"across":[116],"three":[117],"contrasting":[118],"vision":[119],"applications":[120],"types":[123],"demonstrate":[124],"high":[126],"efficacy":[127],"Februus.":[129],"dramatically":[131],"reduced":[132],"attack":[133],"success":[134],"rates":[135],"from":[136],"100%":[137],"near":[139],"0%":[140,145],"all":[142],"cases":[143],"(achieving":[144],"cases)":[148],"evaluated":[150],"generalizability":[152],"defend":[156],"against":[157,167],"complex":[158],"adaptive":[159],"attacks;":[160],"notably,":[161],"we":[162],"realized":[163],"first":[165,182],"defense":[166,184],"advanced":[169],"partial":[170],"attack.":[172],"To":[173],"best":[175],"our":[177],"knowledge,":[178],"is":[180],"method":[185],"operation":[187],"run-time":[189],"capable":[190],"without":[195],"requiring":[196],"anomaly":[197],"detection":[198],"methods,":[199],"retraining":[201],"costly":[203],"labeled":[204],"data.":[205]},"counts_by_year":[{"year":2026,"cited_by_count":5},{"year":2025,"cited_by_count":38},{"year":2024,"cited_by_count":61},{"year":2023,"cited_by_count":53},{"year":2022,"cited_by_count":29},{"year":2021,"cited_by_count":34},{"year":2020,"cited_by_count":17},{"year":2019,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2019-09-12T00:00:00"}
