{"id":"https://openalex.org/W4385014544","doi":"https://doi.org/10.48550/arxiv.2307.10184","title":"A Dual Stealthy Backdoor: From Both Spatial and Frequency Perspectives","display_name":"A Dual Stealthy Backdoor: From Both Spatial and Frequency Perspectives","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4385014544","doi":"https://doi.org/10.48550/arxiv.2307.10184"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2307.10184","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},"type":"preprint","type_crossref":"posted-content","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/abs/2307.10184","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101218044","display_name":"Yudong Gao","orcid":"https://orcid.org/0000-0003-0264-6545"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gao, Yudong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005165463","display_name":"Honglong Chen","orcid":"https://orcid.org/0000-0003-0739-6338"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen, Honglong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101901310","display_name":"Peng Sun","orcid":"https://orcid.org/0000-0002-0663-320X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sun, Peng","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100741720","display_name":"Junjian Li","orcid":"https://orcid.org/0000-0001-5319-517X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Junjian","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101616378","display_name":"Anqing Zhang","orcid":"https://orcid.org/0000-0003-3993-8920"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Anqing","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5100422345","display_name":"Zhibo Wang","orcid":"https://orcid.org/0000-0002-5804-3279"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Zhibo","raw_affiliation_strings":[],"affiliations":[]}],"institution_assertions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.0,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":0,"max":65},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9989,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9989,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9655,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9880059},{"id":"https://openalex.org/keywords/invisibility","display_name":"Invisibility","score":0.57289875},{"id":"https://openalex.org/keywords/camouflage","display_name":"Camouflage","score":0.44038254}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9880059},{"id":"https://openalex.org/C50962388","wikidata":"https://www.wikidata.org/wiki/Q762018","display_name":"Invisibility","level":2,"score":0.57289875},{"id":"https://openalex.org/C19118579","wikidata":"https://www.wikidata.org/wiki/Q786423","display_name":"Frequency domain","level":2,"score":0.5708802},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5594017},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.47976336},{"id":"https://openalex.org/C2776196576","wikidata":"https://www.wikidata.org/wiki/Q196113","display_name":"Camouflage","level":2,"score":0.44038254},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3638625},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.34294066},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.22550672}],"mesh":[],"locations_count":3,"locations":[{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2307.10184","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://arxiv.org/abs/2307.10184","pdf_url":"http://arxiv.org/pdf/2307.10184","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},{"is_oa":false,"landing_page_url":"https://api.datacite.org/dois/10.48550/arxiv.2307.10184","pdf_url":null,"source":{"id":"https://openalex.org/S4393179698","display_name":"DataCite API","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I4210145204","host_organization_name":"DataCite","host_organization_lineage":["https://openalex.org/I4210145204"],"host_organization_lineage_names":["DataCite"],"type":"metadata"},"license":null,"license_id":null,"version":null}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2307.10184","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":0,"referenced_works":[],"related_works":["https://openalex.org/W4391667254","https://openalex.org/W4386185023","https://openalex.org/W4320031223","https://openalex.org/W4317672133","https://openalex.org/W4309417370","https://openalex.org/W4281902577","https://openalex.org/W4200629851","https://openalex.org/W3140988292","https://openalex.org/W3009072493","https://openalex.org/W1513242204"],"abstract_inverted_index":{"Backdoor":[0],"attacks":[1,221],"pose":[2],"serious":[3],"security":[4],"threats":[5],"to":[6,39,111,127,140,145,157,192],"deep":[7],"neural":[8],"networks":[9],"(DNNs).":[10],"Backdoored":[11],"models":[12],"make":[13],"arbitrarily":[14],"(targeted)":[15],"incorrect":[16],"predictions":[17],"on":[18,27,208],"inputs":[19],"embedded":[20],"with":[21,184,189],"well-designed":[22],"triggers":[23,38,63,103,186,191],"while":[24,116],"behaving":[25],"normally":[26],"clean":[28,138,163],"inputs.":[29],"Many":[30],"works":[31],"have":[32],"explored":[33],"the":[34,49,52,59,65,69,100,106,129,133,137,159,166,170,180,195,218,225],"invisibility":[35,50,101],"of":[36,45,61,102,132,224],"backdoor":[37,220],"improve":[40],"attack":[41,93,114,142,176,196,226],"stealthiness.":[42,119,199],"However,":[43],"most":[44],"them":[46],"only":[47],"consider":[48],"in":[51,64,84,104,165,178,222],"spatial":[53,107],"domain":[54],"without":[55],"explicitly":[56],"accounting":[57],"for":[58],"generation":[60],"invisible":[62],"frequency":[66,109,167],"domain,":[67],"making":[68],"generated":[70],"poisoned":[71,160],"images":[72],"be":[73],"easily":[74],"detected":[75],"by":[76],"recent":[77],"defense":[78],"methods.":[79],"To":[80],"address":[81],"this":[82,85],"issue,":[83],"paper,":[86],"we":[87,121,149],"propose":[88],"a":[89,174],"DUal":[90],"stealthy":[91],"BAckdoor":[92],"method":[94],"named":[95],"DUBA,":[96],"which":[97,179],"simultaneously":[98],"considers":[99],"both":[105],"and":[108,153,162,187,198,229],"domains,":[110],"achieve":[112],"desirable":[113],"performance,":[115],"ensuring":[117],"strong":[118,147,190],"Specifically,":[120],"first":[122],"use":[123],"Discrete":[124,154],"Wavelet":[125],"Transform":[126,152,156],"embed":[128],"high-frequency":[130],"information":[131],"trigger":[134],"image":[135,139,161,164,206],"into":[136],"ensure":[141],"effectiveness.":[143],"Then,":[144],"attain":[146],"stealthiness,":[148],"incorporate":[150],"Fourier":[151],"Cosine":[155],"mix":[158],"domain.":[168],"Moreover,":[169],"proposed":[171],"DUBA":[172,203],"adopts":[173],"novel":[175],"strategy,":[177],"model":[181],"is":[182],"trained":[183],"weak":[185],"attacked":[188],"further":[193],"enhance":[194],"performance":[197],"We":[200],"extensively":[201],"evaluate":[202],"against":[204],"popular":[205],"classifiers":[207],"four":[209],"datasets.":[210],"The":[211],"results":[212],"demonstrate":[213],"that":[214],"it":[215],"significantly":[216],"outperforms":[217],"state-of-the-art":[219],"terms":[223],"success":[227],"rate":[228],"stealthiness":[230]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4385014544","counts_by_year":[],"updated_date":"2025-04-15T08:11:00.721925","created_date":"2023-07-22"}