{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T02:25:49Z","timestamp":1777343149360,"version":"3.51.4"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2021YFB3100300"],"award-info":[{"award-number":["2021YFB3100300"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61872180"],"award-info":[{"award-number":["61872180"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Science Foundation (NSF) SaTC Program","award":["1804603"],"award-info":[{"award-number":["1804603"]}]},{"name":"Jiangsu \u201cShuang-Chuang\u201d Program"},{"name":"Jiangsu \u201cSix-Talent-Peaks\u201d Program"},{"DOI":"10.13039\/501100008048","name":"Program B for Outstanding Ph.D. Candidate of Nanjing University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100008048","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/tifs.2022.3160359","type":"journal-article","created":{"date-parts":[[2022,3,16]],"date-time":"2022-03-16T19:36:42Z","timestamp":1647459402000},"page":"1372-1387","source":"Crossref","is-referenced-by-count":24,"title":["Stealthy Backdoors as Compression Artifacts"],"prefix":"10.1109","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0163-4542","authenticated-orcid":false,"given":"Yulong","family":"Tian","sequence":"first","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"given":"Fnu","family":"Suya","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Virginia, Charlottesville, VA, USA"}]},{"given":"Fengyuan","family":"Xu","sequence":"additional","affiliation":[{"name":"State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7988-8943","authenticated-orcid":false,"given":"David","family":"Evans","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of Virginia, Charlottesville, VA, USA"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. ICLR","author":"Simonyan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref4","article-title":"Language models are few-shot learners","author":"Brown","year":"2020","journal-title":"arXiv:2005.14165"},{"key":"ref5","volume-title":"8-Bit Inference With Tensorrt","author":"Migacz","year":"2017"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00286"},{"key":"ref7","first-page":"1","article-title":"Learning to prune deep neural networks via layer-wise optimal brain surgeon","volume-title":"Proc. NeurIPS","author":"Dong"},{"key":"ref8","first-page":"1","article-title":"Dynamic network surgery for efficient DNNs","volume-title":"Proc. NeurIPS","author":"Guo"},{"key":"ref9","first-page":"1","article-title":"Synaptic strength for convolutional neural network","volume-title":"Proc. NeurIPS","author":"Lin"},{"key":"ref10","first-page":"1","article-title":"PerforatedCNNs: Acceleration through elimination of redundant convolutions","volume-title":"Proc. NeurIPS","author":"Figurnov"},{"key":"ref11","article-title":"Pruning filters for efficient ConvNets","author":"Li","year":"2016","journal-title":"arXiv:1608.08710"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.643"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5924"},{"key":"ref14","article-title":"Quantizing deep convolutional networks for efficient inference: A whitepaper","author":"Krishnamoorthi","year":"2018","journal-title":"arXiv:1806.08342"},{"key":"ref15","first-page":"1","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proc. NeurIPS","author":"Paszke"},{"key":"ref16","first-page":"265","article-title":"Tensorflow: A system for large-scale machine learning","volume-title":"Proc. OSDI","author":"Abadi"},{"key":"ref17","first-page":"1","article-title":"Efficient inference with TensorRT","volume-title":"Proc. GTC-EU","author":"Vanholder"},{"key":"ref18","volume-title":"Core ML","year":"2021"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref20","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref21","volume-title":"ModelZoo","author":"Koh","year":"2020"},{"key":"ref22","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018","journal-title":"arXiv:1810.04805"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_29"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01070"},{"key":"ref26","article-title":"Fixing the train-test resolution discrepancy: FixEfficientNet","author":"Touvron","year":"2020","journal-title":"arXiv:2003.08237"},{"key":"ref27","volume-title":"Securing the Future of Artificial Intelligence and Machine Learning at Microsoft","author":"Marshall","year":"2020"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"ref32","first-page":"1","article-title":"Tabor: A highly accurate approach to inspecting and restoring trojan backdoors in AI systems","volume-title":"Proc. ICDM","author":"Guo"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"ref34","volume-title":"Post Training Quantization of TRTorch","year":"2021"},{"key":"ref35","volume-title":"Post-training Quantization of TensorFlow","year":"2021"},{"key":"ref36","article-title":"Estimating or propagating gradients through stochastic neurons for conditional computation","author":"Bengio","year":"2013","journal-title":"arXiv:1308.3432"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01234-2_48"},{"key":"ref38","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref39","first-page":"1","article-title":"NeuronInspect: Detecting backdoors in neural networks via output explanations","volume-title":"Proc. AAAI","author":"Huang"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403064"},{"key":"ref42","article-title":"Dynamic backdoor attacks against machine learning models","author":"Salem","year":"2020","journal-title":"arXiv:2003.03675"},{"key":"ref43","first-page":"443","article-title":"Seeing is not believing: Camouflage attacks on image scaling algorithms","volume-title":"Proc. USENIX Secur.","author":"Xiao"},{"key":"ref44","first-page":"1","article-title":"Model compression with adversarial robustness: A unified optimization framework","volume-title":"Proc. NeurIPS","author":"Gui"},{"key":"ref45","article-title":"Quantization backdoors to deep learning commercial frameworks","author":"Ma","year":"2021","journal-title":"arXiv:2108.09187"},{"key":"ref46","first-page":"1","article-title":"Qu-antization: Exploiting quantization artifacts for achieving adversarial outcomes","volume-title":"Proc. NeurIPS","author":"Hong"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"ref48","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"Proc. USENIX Secur.","author":"Bagdasaryan"},{"key":"ref49","volume-title":"PyTorch Quantization","year":"2021"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3386901.3388946"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3419111.3421282"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref53","volume-title":"The CIFAR Dataset","author":"Krizhevsky","year":"2010"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2013.6706807"},{"key":"ref55","article-title":"MobileNets: Efficient convolutional neural networks for mobile vision applications","author":"Howard","year":"2017","journal-title":"arXiv:1704.04861"},{"key":"ref56","volume-title":"Learning Multiple Layers of Features From Tiny Images","author":"Krizhevsky","year":"2009"},{"key":"ref57","volume-title":"Chinese Traffic Sign Database","author":"Huang","year":"2021"},{"key":"ref58","first-page":"1","article-title":"Reading digits in natural images with unsupervised feature learning","volume-title":"Proc. NeurIPS","author":"Netzer"},{"key":"ref59","volume-title":"Filter-Level Structured Pruning Based on the $\\ell_2$-Norm","year":"2021"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00447"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2008.4587747"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/10206\/9652463\/9737144-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9652463\/09737144.pdf?arnumber=9737144","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,18]],"date-time":"2024-01-18T00:48:31Z","timestamp":1705538911000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9737144\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/tifs.2022.3160359","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}