{"id":"https://openalex.org/W7137807077","doi":"https://doi.org/10.1609/aaai.v40i32.39935","title":"Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization","display_name":"Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7137807077","doi":"https://doi.org/10.1609/aaai.v40i32.39935"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i32.39935","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i32.39935","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://doi.org/10.1609/aaai.v40i32.39935","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5129747815","display_name":"Binyan Xu","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Binyan Xu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129675541","display_name":"Fan Yang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Fan Yang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129687474","display_name":"Di Tang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Di Tang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5124129923","display_name":"Xilin Dai","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xilin Dai","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5008237643","display_name":"Kehuan Zhang","orcid":"https://orcid.org/0000-0003-1519-0057"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kehuan Zhang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5129747815"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.03537285,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"40","issue":"32","first_page":"27197","last_page":"27205"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9799000024795532,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9799000024795532,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.003800000064074993,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.003000000026077032,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.996399998664856},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.5616999864578247},{"id":"https://openalex.org/keywords/resilience","display_name":"Resilience (materials science)","score":0.41339999437332153},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.4106000065803528},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.37389999628067017},{"id":"https://openalex.org/keywords/trojan","display_name":"Trojan","score":0.3619000017642975},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.33340001106262207},{"id":"https://openalex.org/keywords/obstacle","display_name":"Obstacle","score":0.3255000114440918}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.996399998664856},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7184000015258789},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.5616999864578247},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5471000075340271},{"id":"https://openalex.org/C2779585090","wikidata":"https://www.wikidata.org/wiki/Q3457762","display_name":"Resilience (materials science)","level":2,"score":0.41339999437332153},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.41130000352859497},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.4106000065803528},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.37389999628067017},{"id":"https://openalex.org/C174333608","wikidata":"https://www.wikidata.org/wiki/Q19635","display_name":"Trojan","level":2,"score":0.3619000017642975},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.33340001106262207},{"id":"https://openalex.org/C2776650193","wikidata":"https://www.wikidata.org/wiki/Q264661","display_name":"Obstacle","level":2,"score":0.3255000114440918},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.32249999046325684},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.3156000077724457},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.3109999895095825},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.31060001254081726},{"id":"https://openalex.org/C31170391","wikidata":"https://www.wikidata.org/wiki/Q188619","display_name":"Hierarchy","level":2,"score":0.3005000054836273},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.29350000619888306},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.28299999237060547},{"id":"https://openalex.org/C3309286","wikidata":"https://www.wikidata.org/wiki/Q4907693","display_name":"Bilevel optimization","level":3,"score":0.27639999985694885},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.272599995136261},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2678000032901764},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.25200000405311584}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i32.39935","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i32.39935","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i32.39935","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i32.39935","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Clean-image":[0],"backdoor":[1,118,172],"attacks,":[2],"which":[3],"use":[4],"only":[5],"label":[6],"manipulation":[7],"in":[8,26,46,128,159],"training":[9],"datasets":[10],"to":[11,20,85,115,144],"compromise":[12],"deep":[13],"neural":[14],"networks,":[15],"pose":[16],"a":[17,36,40,56,78,82,112,129],"significant":[18],"threat":[19],"security-critical":[21],"applications.":[22],"A":[23],"critical":[24],"flaw":[25],"existing":[27,171],"methods":[28],"is":[29],"that":[30,62,80,91],"the":[31,69,117,153,170],"poison":[32],"rate":[33],"required":[34],"for":[35,59],"successful":[37],"attack":[38],"induces":[39],"proportional,":[41],"and":[42,96,149,161],"thus":[43],"noticeable,":[44],"drop":[45,131],"Clean":[47],"Accuracy":[48],"(CA),":[49],"undermining":[50],"their":[51],"stealthiness.":[52],"This":[53],"paper":[54],"presents":[55],"new":[57],"paradigm":[58],"clean-image":[60,157],"attacks":[61],"minimizes":[63],"this":[64],"accuracy":[65],"degradation":[66],"by":[67],"optimizing":[68],"trigger":[70],"itself.":[71],"We":[72],"introduce":[73],"Generative":[74],"Clean-Image":[75],"Backdoors":[76],"(GCB),":[77],"framework":[79],"uses":[81],"conditional":[83],"InfoGAN":[84],"identify":[86],"naturally":[87],"occurring":[88],"image":[89],"features":[90],"can":[92],"serve":[93],"as":[94],"potent":[95],"stealthy":[97],"triggers.":[98],"By":[99],"ensuring":[100],"these":[101],"triggers":[102],"are":[103],"easily":[104],"separable":[105],"from":[106,119],"benign":[107],"task-related":[108],"features,":[109],"GCB":[110,163],"enables":[111],"victim":[113],"model":[114],"learn":[116],"an":[120],"extremely":[121],"small":[122],"set":[123],"of":[124,132,156,169],"poisoned":[125],"examples,":[126],"resulting":[127],"CA":[130],"less":[133],"than":[134],"1%.":[135],"Our":[136],"experiments":[137],"demonstrate":[138],"GCB's":[139],"remarkable":[140],"versatility,":[141],"successfully":[142],"adapting":[143],"six":[145],"datasets,":[146],"five":[147],"architectures,":[148],"four":[150],"tasks,":[151],"including":[152],"first":[154],"demonstration":[155],"backdoors":[158],"regression":[160],"segmentation.":[162],"also":[164],"exhibits":[165],"resilience":[166],"against":[167],"most":[168],"defenses.":[173]},"counts_by_year":[],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-03-18T00:00:00"}
