{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/backdoor-attack/papers/2","list_of":"/task/backdoor-attack","task":"Backdoor Attack","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"repositories listed in the archive (most first), then date (newest first), then slug","page":2,"pages_in_order":6,"rows_per_page":100,"rows":[101,200],"of":523,"counts":{"archive_papers_tagged":523,"with_a_code_link":217,"where_syntology_ran_a_sample":88,"not_listed_spam_title":0,"listed":523,"listed_where_code_ran":88,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":67,"every_run_a_failure_of_syntologys_instrument":21,"listed_with_a_run_with_no_instrument_failure":67,"listed_every_run_a_failure_of_syntologys_instrument":21,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/backdoor-attack","prev":"/task/backdoor-attack","next":"/task/backdoor-attack/papers/3","papers":[{"url":"/paper/backdoor-attack-on-unpaired-medical-image","slug":"backdoor-attack-on-unpaired-medical-image","title":"Backdoor Attack on Unpaired Medical Image-Text Foundation Models: A Pilot Study on MedCLIP","date":"2024-01-01","arxiv_id":"2401.01911","repositories_listed":1,"syntology":null},{"url":"/paper/not-all-prompts-are-secure-a-switchable-1","slug":"not-all-prompts-are-secure-a-switchable-1","title":"Not All Prompts Are Secure: A Switchable Backdoor Attack Against Pre-trained Vision Transfomers","date":"2024-01-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/badrl-sparse-targeted-backdoor-attack-against","slug":"badrl-sparse-targeted-backdoor-attack-against","title":"BadRL: Sparse Targeted Backdoor Attack Against Reinforcement Learning","date":"2023-12-19","arxiv_id":"2312.12585","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_constructed":0,"n_ran_checked":0,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/badrl-sparse-targeted-backdoor-attack-against#ran","syntology_url":"https://syntology.ai/paper/2312.12585","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2312.12585"}},"official":{"repos":["7777777cc/code"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/flowmur-a-stealthy-and-practical-audio","slug":"flowmur-a-stealthy-and-practical-audio","title":"FlowMur: A Stealthy and Practical Audio Backdoor Attack with Limited Knowledge","date":"2023-12-15","arxiv_id":"2312.09665","repositories_listed":1,"syntology":null},{"url":"/paper/attacks-of-fairness-in-federated-learning","slug":"attacks-of-fairness-in-federated-learning","title":"Attacks on fairness in Federated Learning","date":"2023-11-21","arxiv_id":"2311.12715","repositories_listed":1,"syntology":null},{"url":"/paper/badclip-dual-embedding-guided-backdoor-attack","slug":"badclip-dual-embedding-guided-backdoor-attack","title":"BadCLIP: Dual-Embedding Guided Backdoor Attack on Multimodal Contrastive Learning","date":"2023-11-20","arxiv_id":"2311.12075","repositories_listed":1,"syntology":{"n":4,"n_ran":4,"n_constructed":0,"n_ran_checked":2,"n_instrument":2,"n_unverified":0,"n_honours":1,"n_violates":1,"n_no_contract":0,"n_pointer_only":0,"phrase":"4 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 1 honoured, 1 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/badclip-dual-embedding-guided-backdoor-attack#ran","syntology_url":"https://syntology.ai/paper/2311.12075","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2311.12075"}},"official":null}},{"url":"/paper/from-trojan-horses-to-castle-walls-unveiling","slug":"from-trojan-horses-to-castle-walls-unveiling","title":"From Trojan Horses to Castle Walls: Unveiling Bilateral Data Poisoning Effects in Diffusion Models","date":"2023-11-04","arxiv_id":"2311.02373","repositories_listed":1,"syntology":{"n":4,"n_ran":4,"n_constructed":0,"n_ran_checked":2,"n_instrument":2,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":4,"phrase":"4 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 2 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/from-trojan-horses-to-castle-walls-unveiling#ran","syntology_url":"https://syntology.ai/paper/2311.02373","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2311.02373"}},"official":{"repos":["optml-group/bibaddiff"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/label-poisoning-is-all-you-need","slug":"label-poisoning-is-all-you-need","title":"Label Poisoning is All You Need","date":"2023-10-29","arxiv_id":"2310.18933","repositories_listed":1,"syntology":{"n":10,"n_ran":6,"n_constructed":0,"n_ran_checked":5,"n_instrument":1,"n_unverified":4,"n_honours":0,"n_violates":0,"n_no_contract":5,"n_pointer_only":1,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 5 with no instrument failure: 0 honoured, 0 violated, 5 with no contract checked; 1 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/label-poisoning-is-all-you-need#ran","syntology_url":"https://syntology.ai/paper/2310.18933","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2310.18933"}},"official":{"repos":["SewoongLab/FLIP"],"state":"official (archive's flag): 6 ran","n_ran":6,"n_constructed":0,"n_ran_no_instrument_failure":5,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/cbd-a-certified-backdoor-detector-based-on-1","slug":"cbd-a-certified-backdoor-detector-based-on-1","title":"CBD: A Certified Backdoor Detector Based on Local Dominant Probability","date":"2023-10-26","arxiv_id":"2310.17498","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":3,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/cbd-a-certified-backdoor-detector-based-on-1#ran","syntology_url":"https://syntology.ai/paper/2310.17498","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2310.17498"}},"official":{"repos":["zhenxianglance/cbd"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/poisonprompt-backdoor-attack-on-prompt-based","slug":"poisonprompt-backdoor-attack-on-prompt-based","title":"PoisonPrompt: Backdoor Attack on Prompt-based Large Language Models","date":"2023-10-19","arxiv_id":"2310.12439","repositories_listed":1,"syntology":null},{"url":"/paper/composite-backdoor-attacks-against-large","slug":"composite-backdoor-attacks-against-large","title":"Composite Backdoor Attacks Against Large Language Models","date":"2023-10-11","arxiv_id":"2310.07676","repositories_listed":1,"syntology":{"n":4,"n_ran":3,"n_constructed":0,"n_ran_checked":2,"n_instrument":1,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":4,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/composite-backdoor-attacks-against-large#ran","syntology_url":"https://syntology.ai/paper/2310.07676","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2310.07676"}},"official":{"repos":["miraclehh/cba"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/horizontal-class-backdoor-to-deep-learning","slug":"horizontal-class-backdoor-to-deep-learning","title":"Watch Out! Simple Horizontal Class Backdoor Can Trivially Evade Defense","date":"2023-10-01","arxiv_id":"2310.00542","repositories_listed":1,"syntology":{"n":22,"n_ran":16,"n_constructed":0,"n_ran_checked":10,"n_instrument":6,"n_unverified":6,"n_honours":0,"n_violates":0,"n_no_contract":10,"n_pointer_only":7,"phrase":"16 ran (of which 0 constructed an object rather than computing a result; 10 with no instrument failure: 0 honoured, 0 violated, 10 with no contract checked; 6 where Syntology's instrument failed) · 6 unverified","sample_list":"/paper/horizontal-class-backdoor-to-deep-learning#ran","syntology_url":"https://syntology.ai/paper/2310.00542","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2310.00542"}},"official":{"repos":["shihe98/hcb"],"state":"official (archive's flag): 4 ran","n_ran":4,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":0,"ran_from_kinds":["found_in_text","official"]}}},{"url":"/paper/vdc-versatile-data-cleanser-for-detecting","slug":"vdc-versatile-data-cleanser-for-detecting","title":"VDC: Versatile Data Cleanser based on Visual-Linguistic Inconsistency by Multimodal Large Language Models","date":"2023-09-28","arxiv_id":"2309.16211","repositories_listed":1,"syntology":{"n":17,"n_ran":8,"n_constructed":4,"n_ran_checked":5,"n_instrument":3,"n_unverified":9,"n_honours":0,"n_violates":0,"n_no_contract":5,"n_pointer_only":0,"phrase":"8 ran (of which 4 constructed an object rather than computing a result; 5 with no instrument failure: 0 honoured, 0 violated, 5 with no contract checked; 3 where Syntology's instrument failed) · 9 unverified","sample_list":"/paper/vdc-versatile-data-cleanser-for-detecting#ran","syntology_url":"https://syntology.ai/paper/2309.16211","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2309.16211"}},"official":{"repos":["zihao-ai/vdc"],"state":"official (archive's flag): 8 ran","n_ran":8,"n_constructed":4,"n_ran_no_instrument_failure":5,"n_unverified":9,"ran_from_kinds":["official"]}}},{"url":"/paper/genetic-algorithm-based-dynamic-backdoor","slug":"genetic-algorithm-based-dynamic-backdoor","title":"Genetic Algorithm-Based Dynamic Backdoor Attack on Federated Learning-Based Network Traffic Classification","date":"2023-09-27","arxiv_id":"2310.06855","repositories_listed":1,"syntology":null},{"url":"/paper/mdtd-a-multi-domain-trojan-detector-for-deep","slug":"mdtd-a-multi-domain-trojan-detector-for-deep","title":"MDTD: A Multi Domain Trojan Detector for Deep Neural Networks","date":"2023-08-30","arxiv_id":"2308.15673","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":2,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":3,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/mdtd-a-multi-domain-trojan-detector-for-deep#ran","syntology_url":"https://syntology.ai/paper/2308.15673","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2308.15673"}},"official":{"repos":["rajabia/mdtd"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/patchbackdoor-backdoor-attack-against-deep","slug":"patchbackdoor-backdoor-attack-against-deep","title":"PatchBackdoor: Backdoor Attack against Deep Neural Networks without Model Modification","date":"2023-08-22","arxiv_id":"2308.11822","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/patchbackdoor-backdoor-attack-against-deep#ran","syntology_url":"https://syntology.ai/paper/2308.11822","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2308.11822"}},"official":{"repos":["xaiveryuan/patchbackdoor"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/poison-dart-frog-a-clean-label-attack-with","slug":"poison-dart-frog-a-clean-label-attack-with","title":"DFB: A Data-Free, Low-Budget, and High-Efficacy Clean-Label Backdoor Attack","date":"2023-08-18","arxiv_id":"2308.09487","repositories_listed":1,"syntology":null},{"url":"/paper/bagm-a-backdoor-attack-for-manipulating-text","slug":"bagm-a-backdoor-attack-for-manipulating-text","title":"BAGM: A Backdoor Attack for Manipulating Text-to-Image Generative Models","date":"2023-07-31","arxiv_id":"2307.16489","repositories_listed":1,"syntology":null},{"url":"/paper/virtual-prompt-injection-for-instruction","slug":"virtual-prompt-injection-for-instruction","title":"Backdooring Instruction-Tuned Large Language Models with Virtual Prompt Injection","date":"2023-07-31","arxiv_id":"2307.16888","repositories_listed":1,"syntology":null},{"url":"/paper/you-can-backdoor-personalized-federated","slug":"you-can-backdoor-personalized-federated","title":"You Can Backdoor Personalized Federated Learning","date":"2023-07-29","arxiv_id":"2307.15971","repositories_listed":1,"syntology":{"n":6,"n_ran":6,"n_constructed":0,"n_ran_checked":6,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":6,"n_pointer_only":6,"phrase":"6 ran (of which 0 constructed an object rather than computing a result; 6 with no instrument failure: 0 honoured, 0 violated, 6 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/you-can-backdoor-personalized-federated#ran","syntology_url":"https://syntology.ai/paper/2307.15971","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2307.15971"}},"official":{"repos":["bapfl/code"],"state":"official (archive's flag): 6 ran","n_ran":6,"n_constructed":0,"n_ran_no_instrument_failure":6,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/risk-optimized-outlier-removal-for-robust","slug":"risk-optimized-outlier-removal-for-robust","title":"Risk-optimized Outlier Removal for Robust 3D Point Cloud Classification","date":"2023-07-20","arxiv_id":"2307.10875","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-attack-against-object-detection-with","slug":"backdoor-attack-against-object-detection-with","title":"Attacking by Aligning: Clean-Label Backdoor Attacks on Object Detection","date":"2023-07-19","arxiv_id":"2307.10487","repositories_listed":1,"syntology":null},{"url":"/paper/towards-stealthy-backdoor-attacks-against","slug":"towards-stealthy-backdoor-attacks-against","title":"Towards Stealthy Backdoor Attacks against Speech Recognition via Elements of Sound","date":"2023-07-17","arxiv_id":"2307.08208","repositories_listed":1,"syntology":{"n":2,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/towards-stealthy-backdoor-attacks-against#ran","syntology_url":"https://syntology.ai/paper/2307.08208","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2307.08208"}},"official":{"repos":["hanbocai/badspeech_soe"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/feddefender-backdoor-attack-defense-in","slug":"feddefender-backdoor-attack-defense-in","title":"FedDefender: Backdoor Attack Defense in Federated Learning","date":"2023-07-02","arxiv_id":"2307.08672","repositories_listed":1,"syntology":null},{"url":"/paper/bkd-fedgnn-a-benchmark-for-classification","slug":"bkd-fedgnn-a-benchmark-for-classification","title":"Bkd-FedGNN: A Benchmark for Classification Backdoor Attacks on Federated Graph Neural Network","date":"2023-06-17","arxiv_id":"2306.10351","repositories_listed":1,"syntology":null},{"url":"/paper/efficient-backdoor-attacks-for-deep-neural","slug":"efficient-backdoor-attacks-for-deep-neural","title":"Efficient Backdoor Attacks for Deep Neural Networks in Real-world Scenarios","date":"2023-06-14","arxiv_id":"2306.08386","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"0 ran · 1 unverified","sample_list":"/paper/efficient-backdoor-attacks-for-deep-neural#ran","syntology_url":"https://syntology.ai/paper/2306.08386","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2306.08386"}},"official":{"repos":["sunh1113/efficient-backdoor-attacks-for-deep-neural-networks-in-real-world-scenarios"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/villandiffusion-a-unified-backdoor-attack-1","slug":"villandiffusion-a-unified-backdoor-attack-1","title":"VillanDiffusion: A Unified Backdoor Attack Framework for Diffusion Models","date":"2023-06-12","arxiv_id":"2306.06874","repositories_listed":1,"syntology":{"n":14,"n_ran":9,"n_constructed":0,"n_ran_checked":7,"n_instrument":2,"n_unverified":5,"n_honours":1,"n_violates":2,"n_no_contract":4,"n_pointer_only":3,"phrase":"9 ran (of which 0 constructed an object rather than computing a result; 7 with no instrument failure: 1 honoured, 2 violated, 4 with no contract checked; 2 where Syntology's instrument failed) · 5 unverified","sample_list":"/paper/villandiffusion-a-unified-backdoor-attack-1#ran","syntology_url":"https://syntology.ai/paper/2306.06874","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2306.06874"}},"official":{"repos":["ibm/villandiffusion"],"state":"official (archive's flag): 9 ran","n_ran":9,"n_constructed":0,"n_ran_no_instrument_failure":7,"n_unverified":5,"ran_from_kinds":["official"]}}},{"url":"/paper/backdoor-attack-with-sparse-and-invisible","slug":"backdoor-attack-with-sparse-and-invisible","title":"Backdoor Attack with Sparse and Invisible Trigger","date":"2023-05-11","arxiv_id":"2306.06209","repositories_listed":1,"syntology":null},{"url":"/paper/text-to-image-diffusion-models-can-be-easily","slug":"text-to-image-diffusion-models-can-be-easily","title":"Text-to-Image Diffusion Models can be Easily Backdoored through Multimodal Data Poisoning","date":"2023-05-07","arxiv_id":"2305.04175","repositories_listed":1,"syntology":{"n":4,"n_ran":2,"n_constructed":0,"n_ran_checked":2,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":2,"n_pointer_only":0,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 0 honoured, 0 violated, 2 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/text-to-image-diffusion-models-can-be-easily#ran","syntology_url":"https://syntology.ai/paper/2305.04175","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2305.04175"}},"official":{"repos":["sf-zhai/badt2i"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/defending-against-insertion-based-textual","slug":"defending-against-insertion-based-textual","title":"Defending against Insertion-based Textual Backdoor Attacks via Attribution","date":"2023-05-03","arxiv_id":"2305.02394","repositories_listed":1,"syntology":null},{"url":"/paper/fedgrad-mitigating-backdoor-attacks-in","slug":"fedgrad-mitigating-backdoor-attacks-in","title":"FedGrad: Mitigating Backdoor Attacks in Federated Learning Through Local Ultimate Gradients Inspection","date":"2023-04-29","arxiv_id":"2305.00328","repositories_listed":1,"syntology":null},{"url":"/paper/unicorn-a-unified-backdoor-trigger-inversion","slug":"unicorn-a-unified-backdoor-trigger-inversion","title":"UNICORN: A Unified Backdoor Trigger Inversion Framework","date":"2023-04-05","arxiv_id":"2304.02786","repositories_listed":1,"syntology":{"n":12,"n_ran":7,"n_constructed":0,"n_ran_checked":4,"n_instrument":3,"n_unverified":5,"n_honours":0,"n_violates":0,"n_no_contract":4,"n_pointer_only":3,"phrase":"7 ran (of which 0 constructed an object rather than computing a result; 4 with no instrument failure: 0 honoured, 0 violated, 4 with no contract checked; 3 where Syntology's instrument failed) · 5 unverified","sample_list":"/paper/unicorn-a-unified-backdoor-trigger-inversion#ran","syntology_url":"https://syntology.ai/paper/2304.02786","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2304.02786"}},"official":{"repos":["ru-system-software-and-security/unicorn"],"state":"official (archive's flag): 7 ran","n_ran":7,"n_constructed":0,"n_ran_no_instrument_failure":4,"n_unverified":5,"ran_from_kinds":["official"]}}},{"url":"/paper/recover-triggered-states-protect-model","slug":"recover-triggered-states-protect-model","title":"Recover Triggered States: Protect Model Against Backdoor Attack in Reinforcement Learning","date":"2023-04-01","arxiv_id":"2304.00252","repositories_listed":1,"syntology":null},{"url":"/paper/influencer-backdoor-attack-on-semantic","slug":"influencer-backdoor-attack-on-semantic","title":"Influencer Backdoor Attack on Semantic Segmentation","date":"2023-03-21","arxiv_id":"2303.12054","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-defense-via-deconfounded","slug":"backdoor-defense-via-deconfounded","title":"Backdoor Defense via Deconfounded Representation Learning","date":"2023-03-13","arxiv_id":"2303.06818","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"0 ran · 1 unverified","sample_list":"/paper/backdoor-defense-via-deconfounded#ran","syntology_url":"https://syntology.ai/paper/2303.06818","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2303.06818"}},"official":{"repos":["zaixizhang/cbd"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/robust-contrastive-language-image-pretraining","slug":"robust-contrastive-language-image-pretraining","title":"Robust Contrastive Language-Image Pre-training against Data Poisoning and Backdoor Attacks","date":"2023-03-13","arxiv_id":"2303.06854","repositories_listed":1,"syntology":{"n":2,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/robust-contrastive-language-image-pretraining#ran","syntology_url":"https://syntology.ai/paper/2303.06854","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2303.06854"}},"official":{"repos":["bigml-cs-ucla/roclip"],"state":"official: no sample here; runs from other or unrecorded repositories","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["unlocated"]}}},{"url":"/paper/cleanclip-mitigating-data-poisoning-attacks","slug":"cleanclip-mitigating-data-poisoning-attacks","title":"CleanCLIP: Mitigating Data Poisoning Attacks in Multimodal Contrastive Learning","date":"2023-03-06","arxiv_id":"2303.03323","repositories_listed":1,"syntology":{"n":3,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":2,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/cleanclip-mitigating-data-poisoning-attacks#ran","syntology_url":"https://syntology.ai/paper/2303.03323","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2303.03323"}},"official":{"repos":["nishadsinghi/cleanclip"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/learning-to-backdoor-federated-learning","slug":"learning-to-backdoor-federated-learning","title":"Learning to Backdoor Federated Learning","date":"2023-03-06","arxiv_id":"2303.03320","repositories_listed":1,"syntology":{"n":13,"n_ran":8,"n_constructed":0,"n_ran_checked":8,"n_instrument":0,"n_unverified":5,"n_honours":0,"n_violates":0,"n_no_contract":8,"n_pointer_only":0,"phrase":"8 ran (of which 0 constructed an object rather than computing a result; 8 with no instrument failure: 0 honoured, 0 violated, 8 with no contract checked; 0 where Syntology's instrument failed) · 5 unverified","sample_list":"/paper/learning-to-backdoor-federated-learning#ran","syntology_url":"https://syntology.ai/paper/2303.03320","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2303.03320"}},"official":{"repos":["HengerLi/RLBackdoorFL"],"state":"official (archive's flag): 8 ran","n_ran":8,"n_constructed":0,"n_ran_no_instrument_failure":8,"n_unverified":5,"ran_from_kinds":["official"]}}},{"url":"/paper/backdoor-for-debias-mitigating-model-bias","slug":"backdoor-for-debias-mitigating-model-bias","title":"Backdoor for Debias: Mitigating Model Bias with Backdoor Attack-based Artificial Bias","date":"2023-03-01","arxiv_id":"2303.01504","repositories_listed":1,"syntology":null},{"url":"/paper/freeeagle-detecting-complex-neural-trojans-in","slug":"freeeagle-detecting-complex-neural-trojans-in","title":"FreeEagle: Detecting Complex Neural Trojans in Data-Free Cases","date":"2023-02-28","arxiv_id":"2302.14500","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"0 ran · 1 unverified","sample_list":"/paper/freeeagle-detecting-complex-neural-trojans-in#ran","syntology_url":"https://syntology.ai/paper/2302.14500","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2302.14500"}},"official":{"repos":["FuChong-cyber/Data-Free-Neural-Backdoor-Detector-FreeEagle"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/defending-against-backdoor-attacks-by-layer","slug":"defending-against-backdoor-attacks-by-layer","title":"Defending Against Backdoor Attacks by Layer-wise Feature Analysis","date":"2023-02-24","arxiv_id":"2302.12758","repositories_listed":1,"syntology":{"n":9,"n_ran":5,"n_constructed":0,"n_ran_checked":4,"n_instrument":1,"n_unverified":4,"n_honours":0,"n_violates":0,"n_no_contract":4,"n_pointer_only":0,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 4 with no instrument failure: 0 honoured, 0 violated, 4 with no contract checked; 1 where Syntology's instrument failed) · 4 unverified","sample_list":"/paper/defending-against-backdoor-attacks-by-layer#ran","syntology_url":"https://syntology.ai/paper/2302.12758","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2302.12758"}},"official":{"repos":["najeebjebreel/dbalfa"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":4,"n_unverified":4,"ran_from_kinds":["official"]}}},{"url":"/paper/adversarial-machine-learning-a-systematic","slug":"adversarial-machine-learning-a-systematic","title":"Attacks in Adversarial Machine Learning: A Systematic Survey from the Life-cycle Perspective","date":"2023-02-19","arxiv_id":"2302.09457","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_constructed":0,"n_ran_checked":1,"n_instrument":1,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/adversarial-machine-learning-a-systematic#ran","syntology_url":"https://syntology.ai/paper/2302.09457","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2302.09457"}},"official":{"repos":["sclbd/backdoorbench"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/unnoticeable-backdoor-attacks-on-graph-neural","slug":"unnoticeable-backdoor-attacks-on-graph-neural","title":"Unnoticeable Backdoor Attacks on Graph Neural Networks","date":"2023-02-11","arxiv_id":"2303.01263","repositories_listed":1,"syntology":null},{"url":"/paper/training-free-lexical-backdoor-attacks-on","slug":"training-free-lexical-backdoor-attacks-on","title":"Training-free Lexical Backdoor Attacks on Language Models","date":"2023-02-08","arxiv_id":"2302.04116","repositories_listed":1,"syntology":null},{"url":"/paper/revisiting-personalized-federated-learning","slug":"revisiting-personalized-federated-learning","title":"Revisiting Personalized Federated Learning: Robustness Against Backdoor Attacks","date":"2023-02-03","arxiv_id":"2302.01677","repositories_listed":1,"syntology":null},{"url":"/paper/on-the-vulnerability-of-backdoor-defenses-for","slug":"on-the-vulnerability-of-backdoor-defenses-for","title":"On the Vulnerability of Backdoor Defenses for Federated Learning","date":"2023-01-19","arxiv_id":"2301.08170","repositories_listed":1,"syntology":null},{"url":"/paper/beagle-forensics-of-deep-learning-backdoor","slug":"beagle-forensics-of-deep-learning-backdoor","title":"BEAGLE: Forensics of Deep Learning Backdoor Attack for Better Defense","date":"2023-01-16","arxiv_id":"2301.06241","repositories_listed":1,"syntology":{"n":6,"n_ran":3,"n_constructed":0,"n_ran_checked":2,"n_instrument":1,"n_unverified":3,"n_honours":2,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 2 with no instrument failure: 2 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 3 unverified","sample_list":"/paper/beagle-forensics-of-deep-learning-backdoor#ran","syntology_url":"https://syntology.ai/paper/2301.06241","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2301.06241"}},"official":{"repos":["megum1/beagle"],"state":"official (archive's flag): 3 ran","n_ran":3,"n_constructed":0,"n_ran_no_instrument_failure":2,"n_unverified":3,"ran_from_kinds":["official"]}}},{"url":"/paper/universal-detection-of-backdoor-attacks-via","slug":"universal-detection-of-backdoor-attacks-via","title":"Universal Detection of Backdoor Attacks via Density-based Clustering and Centroids Analysis","date":"2023-01-11","arxiv_id":"2301.04554","repositories_listed":1,"syntology":null},{"url":"/paper/silent-killer-optimizing-backdoor-trigger","slug":"silent-killer-optimizing-backdoor-trigger","title":"Silent Killer: A Stealthy, Clean-Label, Black-Box Backdoor Attack","date":"2023-01-05","arxiv_id":"2301.02615","repositories_listed":1,"syntology":null},{"url":"/paper/color-backdoor-a-robust-poisoning-attack-in","slug":"color-backdoor-a-robust-poisoning-attack-in","title":"Color Backdoor: A Robust Poisoning Attack in Color Space","date":"2023-01-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/ssda-secure-source-free-domain-adaptation","slug":"ssda-secure-source-free-domain-adaptation","title":"SSDA: Secure Source-Free Domain Adaptation","date":"2023-01-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/mind-your-heart-stealthy-backdoor-attack-on","slug":"mind-your-heart-stealthy-backdoor-attack-on","title":"Mind Your Heart: Stealthy Backdoor Attack on Dynamic Deep Neural Network in Edge Computing","date":"2022-12-22","arxiv_id":"2212.11751","repositories_listed":1,"syntology":null},{"url":"/paper/how-to-backdoor-diffusion-models","slug":"how-to-backdoor-diffusion-models","title":"How to Backdoor Diffusion Models?","date":"2022-12-11","arxiv_id":"2212.05400","repositories_listed":1,"syntology":null},{"url":"/paper/badprompt-backdoor-attacks-on-continuous","slug":"badprompt-backdoor-attacks-on-continuous","title":"BadPrompt: Backdoor Attacks on Continuous Prompts","date":"2022-11-27","arxiv_id":"2211.14719","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/badprompt-backdoor-attacks-on-continuous#ran","syntology_url":"https://syntology.ai/paper/2211.14719","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2211.14719"}},"official":{"repos":["paperspapers/badprompt"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/invisible-backdoor-attack-with-dynamic","slug":"invisible-backdoor-attack-with-dynamic","title":"Invisible Backdoor Attack with Dynamic Triggers against Person Re-identification","date":"2022-11-20","arxiv_id":"2211.10933","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-attacks-for-remote-sensing-data-with","slug":"backdoor-attacks-for-remote-sensing-data-with","title":"Backdoor Attacks for Remote Sensing Data with Wavelet Transform","date":"2022-11-15","arxiv_id":"2211.08044","repositories_listed":1,"syntology":{"n":10,"n_ran":8,"n_constructed":0,"n_ran_checked":6,"n_instrument":2,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":6,"n_pointer_only":1,"phrase":"8 ran (of which 0 constructed an object rather than computing a result; 6 with no instrument failure: 0 honoured, 0 violated, 6 with no contract checked; 2 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/backdoor-attacks-for-remote-sensing-data-with#ran","syntology_url":"https://syntology.ai/paper/2211.08044","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2211.08044"}},"official":{"repos":["ndraeger/waba"],"state":"official (archive's flag): 8 ran","n_ran":8,"n_constructed":0,"n_ran_no_instrument_failure":6,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/msdt-masked-language-model-scoring-defense-in","slug":"msdt-masked-language-model-scoring-defense-in","title":"MSDT: Masked Language Model Scoring Defense in Text Domain","date":"2022-11-10","arxiv_id":"2211.05371","repositories_listed":1,"syntology":null},{"url":"/paper/going-in-style-audio-backdoors-through","slug":"going-in-style-audio-backdoors-through","title":"Going In Style: Audio Backdoors Through Stylistic Transformations","date":"2022-11-06","arxiv_id":"2211.03117","repositories_listed":1,"syntology":null},{"url":"/paper/untargeted-backdoor-attack-against-object","slug":"untargeted-backdoor-attack-against-object","title":"Untargeted Backdoor Attack against Object Detection","date":"2022-11-02","arxiv_id":"2211.05638","repositories_listed":1,"syntology":null},{"url":"/paper/motif-backdoor-rethinking-the-backdoor-attack","slug":"motif-backdoor-rethinking-the-backdoor-attack","title":"Motif-Backdoor: Rethinking the Backdoor Attack on Graph Neural Networks via Motifs","date":"2022-10-25","arxiv_id":"2210.13710","repositories_listed":1,"syntology":{"n":2,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":2,"phrase":"0 ran · 2 unverified","sample_list":"/paper/motif-backdoor-rethinking-the-backdoor-attack#ran","syntology_url":"https://syntology.ai/paper/2210.13710","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2210.13710"}},"official":{"repos":["seaocn/motif-backdoor"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":2,"ran_from_kinds":[]}}},{"url":"/paper/flip-a-provable-defense-framework-for","slug":"flip-a-provable-defense-framework-for","title":"FLIP: A Provable Defense Framework for Backdoor Mitigation in Federated Learning","date":"2022-10-23","arxiv_id":"2210.12873","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/flip-a-provable-defense-framework-for#ran","syntology_url":"https://syntology.ai/paper/2210.12873","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2210.12873"}},"official":{"repos":["KaiyuanZh/FLIP"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/few-shot-backdoor-attacks-via-neural-tangent","slug":"few-shot-backdoor-attacks-via-neural-tangent","title":"Few-shot Backdoor Attacks via Neural Tangent Kernels","date":"2022-10-12","arxiv_id":"2210.05929","repositories_listed":1,"syntology":null},{"url":"/paper/mind-your-data-hiding-backdoors-in-offline","slug":"mind-your-data-hiding-backdoors-in-offline","title":"BAFFLE: Hiding Backdoors in Offline Reinforcement Learning Datasets","date":"2022-10-07","arxiv_id":"2210.04688","repositories_listed":1,"syntology":null},{"url":"/paper/where-to-attack-a-dynamic-locator-model-for","slug":"where-to-attack-a-dynamic-locator-model-for","title":"Where to Attack: A Dynamic Locator Model for Backdoor Attack in Text Classifications","date":"2022-10-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/trojvit-trojan-insertion-in-vision","slug":"trojvit-trojan-insertion-in-vision","title":"TrojViT: Trojan Insertion in Vision Transformers","date":"2022-08-27","arxiv_id":"2208.13049","repositories_listed":1,"syntology":{"n":13,"n_ran":12,"n_constructed":0,"n_ran_checked":8,"n_instrument":4,"n_unverified":1,"n_honours":1,"n_violates":0,"n_no_contract":7,"n_pointer_only":4,"phrase":"12 ran (of which 0 constructed an object rather than computing a result; 8 with no instrument failure: 1 honoured, 0 violated, 7 with no contract checked; 4 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/trojvit-trojan-insertion-in-vision#ran","syntology_url":"https://syntology.ai/paper/2208.13049","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2208.13049"}},"official":{"repos":["mxzheng/trojvit"],"state":"official (archive's flag): 12 ran","n_ran":12,"n_constructed":0,"n_ran_no_instrument_failure":8,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/ribac-towards-robust-and-imperceptible","slug":"ribac-towards-robust-and-imperceptible","title":"RIBAC: Towards Robust and Imperceptible Backdoor Attack against Compact DNN","date":"2022-08-22","arxiv_id":"2208.10608","repositories_listed":1,"syntology":{"n":4,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":3,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 3 unverified","sample_list":"/paper/ribac-towards-robust-and-imperceptible#ran","syntology_url":"https://syntology.ai/paper/2208.10608","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2208.10608"}},"official":{"repos":["huyvnphan/eccv2022-ribac"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":3,"ran_from_kinds":["official"]}}},{"url":"/paper/imperceptible-and-robust-backdoor-attack-in","slug":"imperceptible-and-robust-backdoor-attack-in","title":"Imperceptible and Robust Backdoor Attack in 3D Point Cloud","date":"2022-08-17","arxiv_id":"2208.08052","repositories_listed":1,"syntology":null},{"url":"/paper/link-backdoor-backdoor-attack-on-link","slug":"link-backdoor-backdoor-attack-on-link","title":"Link-Backdoor: Backdoor Attack on Link Prediction via Node Injection","date":"2022-08-14","arxiv_id":"2208.06776","repositories_listed":1,"syntology":null},{"url":"/paper/versatile-weight-attack-via-flipping-limited","slug":"versatile-weight-attack-via-flipping-limited","title":"Versatile Weight Attack via Flipping Limited Bits","date":"2022-07-25","arxiv_id":"2207.12405","repositories_listed":1,"syntology":{"n":4,"n_ran":2,"n_constructed":0,"n_ran_checked":1,"n_instrument":1,"n_unverified":2,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":4,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/versatile-weight-attack-via-flipping-limited#ran","syntology_url":"https://syntology.ai/paper/2207.12405","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2207.12405"}},"official":{"repos":["jiawangbai/versatile-weight-attack"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":2,"ran_from_kinds":["official","unlocated"]}}},{"url":"/paper/backdoor-attacks-on-crowd-counting","slug":"backdoor-attacks-on-crowd-counting","title":"Backdoor Attacks on Crowd Counting","date":"2022-07-12","arxiv_id":"2207.05641","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-attack-is-a-devil-in-federated-gan","slug":"backdoor-attack-is-a-devil-in-federated-gan","title":"Backdoor Attack is a Devil in Federated GAN-based Medical Image Synthesis","date":"2022-07-02","arxiv_id":"2207.00762","repositories_listed":1,"syntology":null},{"url":"/paper/badhash-invisible-backdoor-attacks-against","slug":"badhash-invisible-backdoor-attacks-against","title":"BadHash: Invisible Backdoor Attacks against Deep Hashing with Clean Label","date":"2022-07-01","arxiv_id":"2207.00278","repositories_listed":1,"syntology":{"n":12,"n_ran":10,"n_constructed":0,"n_ran_checked":9,"n_instrument":1,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":9,"n_pointer_only":1,"phrase":"10 ran (of which 0 constructed an object rather than computing a result; 9 with no instrument failure: 0 honoured, 0 violated, 9 with no contract checked; 1 where Syntology's instrument failed) · 2 unverified","sample_list":"/paper/badhash-invisible-backdoor-attacks-against#ran","syntology_url":"https://syntology.ai/paper/2207.00278","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2207.00278"}},"official":{"repos":["cgcl-codes/badhash"],"state":"official (archive's flag): 10 ran","n_ran":10,"n_constructed":0,"n_ran_no_instrument_failure":9,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/backdoorbench-a-comprehensive-benchmark-of","slug":"backdoorbench-a-comprehensive-benchmark-of","title":"BackdoorBench: A Comprehensive Benchmark of Backdoor Learning","date":"2022-06-25","arxiv_id":"2206.12654","repositories_listed":1,"syntology":{"n":3,"n_ran":2,"n_constructed":0,"n_ran_checked":1,"n_instrument":1,"n_unverified":1,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":3,"phrase":"2 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/backdoorbench-a-comprehensive-benchmark-of#ran","syntology_url":"https://syntology.ai/paper/2206.12654","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2206.12654"}},"official":{"repos":["sclbd/backdoorbench"],"state":"official (archive's flag): 2 ran","n_ran":2,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/baddet-backdoor-attacks-on-object-detection","slug":"baddet-backdoor-attacks-on-object-detection","title":"BadDet: Backdoor Attacks on Object Detection","date":"2022-05-28","arxiv_id":"2205.14497","repositories_listed":1,"syntology":null},{"url":"/paper/bagflip-a-certified-defense-against-data","slug":"bagflip-a-certified-defense-against-data","title":"BagFlip: A Certified Defense against Data Poisoning","date":"2022-05-26","arxiv_id":"2205.13634","repositories_listed":1,"syntology":{"n":8,"n_ran":5,"n_constructed":0,"n_ran_checked":3,"n_instrument":2,"n_unverified":3,"n_honours":3,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"5 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 3 honoured, 0 violated, 0 with no contract checked; 2 where Syntology's instrument failed) · 3 unverified","sample_list":"/paper/bagflip-a-certified-defense-against-data#ran","syntology_url":"https://syntology.ai/paper/2205.13634","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2205.13634"}},"official":{"repos":["foreverzyh/defend_framework"],"state":"official (archive's flag): 5 ran","n_ran":5,"n_constructed":0,"n_ran_no_instrument_failure":3,"n_unverified":3,"ran_from_kinds":["official"]}}},{"url":"/paper/textual-backdoor-attacks-with-iterative","slug":"textual-backdoor-attacks-with-iterative","title":"BITE: Textual Backdoor Attacks with Iterative Trigger Injection","date":"2022-05-25","arxiv_id":"2205.12700","repositories_listed":1,"syntology":null},{"url":"/paper/universal-post-training-backdoor-detection","slug":"universal-post-training-backdoor-detection","title":"MM-BD: Post-Training Detection of Backdoor Attacks with Arbitrary Backdoor Pattern Types Using a Maximum Margin Statistic","date":"2022-05-13","arxiv_id":"2205.06900","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_constructed":0,"n_ran_checked":1,"n_instrument":0,"n_unverified":0,"n_honours":1,"n_violates":0,"n_no_contract":0,"n_pointer_only":1,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 1 with no instrument failure: 1 honoured, 0 violated, 0 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/universal-post-training-backdoor-detection#ran","syntology_url":"https://syntology.ai/paper/2205.06900","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2205.06900"}},"official":{"repos":["wanghangpsu/mm-bd"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":0,"n_ran_no_instrument_failure":1,"n_unverified":0,"ran_from_kinds":["official"]}}},{"url":"/paper/model-contrastive-learning-for-backdoor","slug":"model-contrastive-learning-for-backdoor","title":"Model-Contrastive Learning for Backdoor Defense","date":"2022-05-09","arxiv_id":"2205.04411","repositories_listed":1,"syntology":null},{"url":"/paper/imperceptible-backdoor-attack-from-input","slug":"imperceptible-backdoor-attack-from-input","title":"Imperceptible Backdoor Attack: From Input Space to Feature Representation","date":"2022-05-06","arxiv_id":"2205.03190","repositories_listed":1,"syntology":{"n":2,"n_ran":1,"n_constructed":1,"n_ran_checked":1,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":1,"n_pointer_only":2,"phrase":"1 ran (of which 1 constructed an object rather than computing a result; 1 with no instrument failure: 0 honoured, 0 violated, 1 with no contract checked; 0 where Syntology's instrument failed) · 1 unverified; the one sample that ran constructed an object rather than computing a result","sample_list":"/paper/imperceptible-backdoor-attack-from-input#ran","syntology_url":"https://syntology.ai/paper/2205.03190","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2205.03190"}},"official":{"repos":["ekko-zn/ijcai2022-backdoor"],"state":"official (archive's flag): 1 ran","n_ran":1,"n_constructed":1,"n_ran_no_instrument_failure":1,"n_unverified":1,"ran_from_kinds":["official"]}}},{"url":"/paper/pass-off-fish-eyes-for-pearls-attacking-model","slug":"pass-off-fish-eyes-for-pearls-attacking-model","title":"Pass off Fish Eyes for Pearls: Attacking Model Selection of Pre-trained Models","date":"2022-05-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/semi-targeted-model-poisoning-attack-on","slug":"semi-targeted-model-poisoning-attack-on","title":"Semi-Targeted Model Poisoning Attack on Federated Learning via Backward Error Analysis","date":"2022-03-22","arxiv_id":"2203.11633","repositories_listed":1,"syntology":null},{"url":"/paper/resurrecting-trust-in-facial-recognition","slug":"resurrecting-trust-in-facial-recognition","title":"Resurrecting Trust in Facial Recognition: Mitigating Backdoor Attacks in Face Recognition to Prevent Potential Privacy Breaches","date":"2022-02-18","arxiv_id":"2202.10320","repositories_listed":1,"syntology":null},{"url":"/paper/towards-understanding-and-defending-input","slug":"towards-understanding-and-defending-input","title":"Training with More Confidence: Mitigating Injected and Natural Backdoors During Training","date":"2022-02-13","arxiv_id":"2202.06382","repositories_listed":1,"syntology":null},{"url":"/paper/few-shot-backdoor-attacks-on-visual-object-1","slug":"few-shot-backdoor-attacks-on-visual-object-1","title":"Few-Shot Backdoor Attacks on Visual Object Tracking","date":"2022-01-31","arxiv_id":"2201.13178","repositories_listed":1,"syntology":null},{"url":"/paper/anomaly-localization-in-model-gradients-under","slug":"anomaly-localization-in-model-gradients-under","title":"Anomaly Localization in Model Gradients Under Backdoor Attacks Against Federated Learning","date":"2021-11-29","arxiv_id":"2111.14683","repositories_listed":1,"syntology":null},{"url":"/paper/towards-practical-deployment-stage-backdoor","slug":"towards-practical-deployment-stage-backdoor","title":"Towards Practical Deployment-Stage Backdoor Attack on Deep Neural Networks","date":"2021-11-25","arxiv_id":"2111.12965","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-attack-through-frequency-domain","slug":"backdoor-attack-through-frequency-domain","title":"Backdoor Attack through Frequency Domain","date":"2021-11-22","arxiv_id":"2111.10991","repositories_listed":1,"syntology":null},{"url":"/paper/dbia-data-free-backdoor-injection-attack","slug":"dbia-data-free-backdoor-injection-attack","title":"DBIA: Data-free Backdoor Injection Attack against Transformer Networks","date":"2021-11-22","arxiv_id":"2111.11870","repositories_listed":1,"syntology":null},{"url":"/paper/a-statistical-difference-reduction-method-for","slug":"a-statistical-difference-reduction-method-for","title":"Enhancing Backdoor Attacks with Multi-Level MMD Regularization","date":"2021-11-09","arxiv_id":"2111.05077","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-pre-trained-models-can-transfer-to","slug":"backdoor-pre-trained-models-can-transfer-to","title":"Backdoor Pre-trained Models Can Transfer to All","date":"2021-10-30","arxiv_id":"2111.00197","repositories_listed":1,"syntology":null},{"url":"/paper/qu-anti-zation-exploiting-quantization","slug":"qu-anti-zation-exploiting-quantization","title":"Qu-ANTI-zation: Exploiting Quantization Artifacts for Achieving Adversarial Outcomes","date":"2021-10-26","arxiv_id":"2110.13541","repositories_listed":1,"syntology":{"n":12,"n_ran":10,"n_constructed":10,"n_ran_checked":10,"n_instrument":0,"n_unverified":2,"n_honours":0,"n_violates":0,"n_no_contract":10,"n_pointer_only":0,"phrase":"10 ran (of which 10 constructed an object rather than computing a result; 10 with no instrument failure: 0 honoured, 0 violated, 10 with no contract checked; 0 where Syntology's instrument failed) · 2 unverified; every one of the 10 samples that ran constructed an object rather than computing a result","sample_list":"/paper/qu-anti-zation-exploiting-quantization#ran","syntology_url":"https://syntology.ai/paper/2110.13541","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.13541"}},"official":{"repos":["secure-ai-systems-group/qu-anti-zation"],"state":"official (archive's flag): 10 ran","n_ran":10,"n_constructed":10,"n_ran_no_instrument_failure":10,"n_unverified":2,"ran_from_kinds":["official"]}}},{"url":"/paper/anti-distillation-backdoor-attacks-backdoors","slug":"anti-distillation-backdoor-attacks-backdoors","title":"Anti-Distillation Backdoor Attacks: Backdoors Can Really Survive in Knowledge Distillation","date":"2021-10-24","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/anti-backdoor-learning-training-clean-models","slug":"anti-backdoor-learning-training-clean-models","title":"Anti-Backdoor Learning: Training Clean Models on Poisoned Data","date":"2021-10-22","arxiv_id":"2110.11571","repositories_listed":1,"syntology":{"n":6,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":6,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":6,"phrase":"0 ran · 6 unverified","sample_list":"/paper/anti-backdoor-learning-training-clean-models#ran","syntology_url":"https://syntology.ai/paper/2110.11571","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.11571"}},"official":{"repos":["bboylyg/abl"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":6,"ran_from_kinds":[]}}},{"url":"/paper/mind-the-style-of-text-adversarial-and","slug":"mind-the-style-of-text-adversarial-and","title":"Mind the Style of Text! Adversarial and Backdoor Attacks Based on Text Style Transfer","date":"2021-10-14","arxiv_id":"2110.07139","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_constructed":0,"n_ran_checked":0,"n_instrument":0,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"0 ran · 1 unverified","sample_list":"/paper/mind-the-style-of-text-adversarial-and#ran","syntology_url":"https://syntology.ai/paper/2110.07139","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2110.07139"}},"official":{"repos":["thunlp/styleattack"],"state":"official: harvested, nothing ran","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":1,"ran_from_kinds":[]}}},{"url":"/paper/foobar-fault-fooling-backdoor-attack-on","slug":"foobar-fault-fooling-backdoor-attack-on","title":"FooBaR: Fault Fooling Backdoor Attack on Neural Network Training","date":"2021-09-23","arxiv_id":"2109.11249","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-attacks-on-federated-learning-with","slug":"backdoor-attacks-on-federated-learning-with","title":"Backdoor Attacks on Federated Learning with Lottery Ticket Hypothesis","date":"2021-09-22","arxiv_id":"2109.10512","repositories_listed":1,"syntology":null},{"url":"/paper/clean-label-backdoor-attack-against-deep","slug":"clean-label-backdoor-attack-against-deep","title":"Backdoor Attack on Hash-based Image Retrieval via Clean-label Data Poisoning","date":"2021-09-18","arxiv_id":"2109.08868","repositories_listed":1,"syntology":null},{"url":"/paper/excess-capacity-and-backdoor-poisoning","slug":"excess-capacity-and-backdoor-poisoning","title":"Excess Capacity and Backdoor Poisoning","date":"2021-09-02","arxiv_id":"2109.00685","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_constructed":0,"n_ran_checked":3,"n_instrument":0,"n_unverified":0,"n_honours":0,"n_violates":0,"n_no_contract":3,"n_pointer_only":0,"phrase":"3 ran (of which 0 constructed an object rather than computing a result; 3 with no instrument failure: 0 honoured, 0 violated, 3 with no contract checked; 0 where Syntology's instrument failed) · 0 unverified","sample_list":"/paper/excess-capacity-and-backdoor-poisoning#ran","syntology_url":"https://syntology.ai/paper/2109.00685","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2109.00685"}},"official":{"repos":["narenmanoj/mnist-adv-training"],"state":"official: no sample here; runs from other or unrecorded repositories","n_ran":0,"n_constructed":0,"n_ran_no_instrument_failure":0,"n_unverified":0,"ran_from_kinds":["found_in_text"]}}},{"url":"/paper/poison-ink-robust-and-invisible-backdoor","slug":"poison-ink-robust-and-invisible-backdoor","title":"Poison Ink: Robust and Invisible Backdoor Attack","date":"2021-08-05","arxiv_id":"2108.02488","repositories_listed":1,"syntology":{"n":2,"n_ran":1,"n_constructed":0,"n_ran_checked":0,"n_instrument":1,"n_unverified":1,"n_honours":0,"n_violates":0,"n_no_contract":0,"n_pointer_only":0,"phrase":"1 ran (of which 0 constructed an object rather than computing a result; 0 with no instrument failure: 0 honoured, 0 violated, 0 with no contract checked; 1 where Syntology's instrument failed) · 1 unverified","sample_list":"/paper/poison-ink-robust-and-invisible-backdoor#ran","syntology_url":"https://syntology.ai/paper/2108.02488","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2108.02488"}},"official":null}},{"url":"/paper/rethinking-stealthiness-of-backdoor-attack","slug":"rethinking-stealthiness-of-backdoor-attack","title":"Rethinking Stealthiness of Backdoor Attack against NLP Models","date":"2021-08-01","arxiv_id":null,"repositories_listed":1,"syntology":null}],"record_sha256":"4e6948d7575dd2bfca4cf6458273d472b3e2733a14b5823e03194c730b7be01b","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}