{"url":"/task/backdoor-defense","name":"backdoor defense","slug":"backdoor-defense","description_markdown":null,"categories":[{"name":"Adversarial","url":"/area/adversarial"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":131,"papers_with_code":59,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":2,"subtasks":1,"parent_tasks":0},"benchmarks":[],"datasets":[{"url":"/dataset/ulp-dataset","name":"ULP Dataset","full_name":"","num_papers_in_archive":2},{"url":"/dataset/trojans-against-trojans-tat","name":"Trojans Against Trojans (TAT)","full_name":"Trojans Against Trojans","num_papers_in_archive":1}],"subtasks":[{"url":"/task/backdoor-defense-for-data-free-distillation","name":"Backdoor Defense for Data-Free Distillation with Poisoned Teachers"}],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":59,"tagged_in_all":131,"items":[{"url":"/paper/backdoor-defense-via-decoupling-the-training-1","title":"Backdoor Defense via Decoupling the Training Process","date":"2022-02-05","arxiv_id":"2202.03423","repositories_listed":3,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/fiba-frequency-injection-based-backdoor","title":"FIBA: Frequency-Injection based Backdoor Attack in Medical Image Analysis","date":"2021-12-02","arxiv_id":"2112.01148","repositories_listed":3,"syntology":{"n":2,"n_ran":2,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/refine-inversion-free-backdoor-defense-via","title":"REFINE: Inversion-Free Backdoor Defense via Model Reprogramming","date":"2025-02-22","arxiv_id":"2502.18508","repositories_listed":2,"syntology":{"n":10,"n_ran":5,"n_unverified":5,"n_pointer_only":10}},{"url":"/paper/uncovering-explaining-and-mitigating-the","title":"Uncovering, Explaining, and Mitigating the Superficial Safety of Backdoor Defense","date":"2024-10-13","arxiv_id":"2410.09838","repositories_listed":2,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":1}},{"url":"/paper/mitigating-backdoor-attack-by-injecting","title":"Mitigating Backdoor Attack by Injecting Proactive Defensive Backdoor","date":"2024-05-25","arxiv_id":"2405.16112","repositories_listed":2,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":5}},{"url":"/paper/backdoor-defense-with-non-adversarial","title":"Beating Backdoor Attack at Its Own Game","date":"2023-07-28","arxiv_id":"2307.15539","repositories_listed":2,"syntology":{"n":9,"n_ran":5,"n_unverified":4,"n_pointer_only":9}},{"url":"/paper/shared-adversarial-unlearning-backdoor","title":"Shared Adversarial Unlearning: Backdoor Mitigation by Unlearning Shared Adversarial Examples","date":"2023-07-20","arxiv_id":"2307.10562","repositories_listed":2,"syntology":{"n":4,"n_ran":3,"n_unverified":1,"n_pointer_only":4}},{"url":"/paper/lira-learnable-imperceptible-and-robust","title":"LIRA: Learnable, Imperceptible and Robust Backdoor Attacks","date":"2021-01-01","arxiv_id":null,"repositories_listed":2,"syntology":null},{"url":"/paper/onion-a-simple-and-effective-defense-against","title":"ONION: A Simple and Effective Defense Against Textual Backdoor Attacks","date":"2020-11-20","arxiv_id":"2011.10369","repositories_listed":2,"syntology":{"n":4,"n_ran":3,"n_unverified":1,"n_pointer_only":0}},{"url":"/paper/clip-guided-backdoor-defense-through-entropy","title":"CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation","date":"2025-07-07","arxiv_id":"2507.05113","repositories_listed":1,"syntology":null},{"url":"/paper/fl-plas-federated-learning-with-partial-layer","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","date":"2025-05-17","arxiv_id":"2505.12019","repositories_listed":1,"syntology":null},{"url":"/paper/cert-ssb-toward-certified-sample-specific","title":"Cert-SSB: Toward Certified Sample-Specific Backdoor Defense","date":"2025-04-30","arxiv_id":"2504.21730","repositories_listed":1,"syntology":null},{"url":"/paper/trojandam-detection-free-backdoor-defense-in","title":"TrojanDam: Detection-Free Backdoor Defense in Federated Learning through Proactive Model Robustification utilizing OOD Data","date":"2025-04-22","arxiv_id":"2504.15674","repositories_listed":1,"syntology":null},{"url":"/paper/gungnir-exploiting-stylistic-features-in","title":"Gungnir: Exploiting Stylistic Features in Images for Backdoor Attacks on Diffusion Models","date":"2025-02-28","arxiv_id":"2502.20650","repositories_listed":1,"syntology":null},{"url":"/paper/towards-backdoor-stealthiness-in-model","title":"Towards Backdoor Stealthiness in Model Parameter Space","date":"2025-01-10","arxiv_id":"2501.05928","repositories_listed":1,"syntology":null},{"url":"/paper/backdoor-token-unlearning-exposing-and","title":"Backdoor Token Unlearning: Exposing and Defending Backdoors in Pretrained Language Models","date":"2025-01-05","arxiv_id":"2501.03272","repositories_listed":1,"syntology":null},{"url":"/paper/gracefully-filtering-backdoor-samples-for","title":"Gracefully Filtering Backdoor Samples for Generative Large Language Models without Retraining","date":"2024-12-03","arxiv_id":"2412.02454","repositories_listed":1,"syntology":null},{"url":"/paper/crow-eliminating-backdoors-from-large","title":"CROW: Eliminating Backdoors from Large Language Models via Internal Consistency Regularization","date":"2024-11-18","arxiv_id":"2411.12768","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/backdoormbti-a-backdoor-learning-multimodal","title":"BackdoorMBTI: A Backdoor Learning Multimodal Benchmark Tool Kit for Backdoor Defense Evaluation","date":"2024-11-17","arxiv_id":"2411.11006","repositories_listed":1,"syntology":null},{"url":"/paper/expose-before-you-defend-unifying-and","title":"Expose Before You Defend: Unifying and Enhancing Backdoor Defenses via Exposed Models","date":"2024-10-25","arxiv_id":"2410.19427","repositories_listed":1,"syntology":null},{"url":"/paper/no-matter-what-you-do-mitigating-backdoor","title":"\"No Matter What You Do\": Purifying GNN Models via Backdoor Unlearning","date":"2024-10-02","arxiv_id":"2410.01272","repositories_listed":1,"syntology":null},{"url":"/paper/terd-a-unified-framework-for-safeguarding","title":"TERD: A Unified Framework for Safeguarding Diffusion Models Against Backdoors","date":"2024-09-09","arxiv_id":"2409.05294","repositories_listed":1,"syntology":null},{"url":"/paper/fisher-information-guided-purification","title":"Fisher Information guided Purification against Backdoor Attacks","date":"2024-09-01","arxiv_id":"2409.00863","repositories_listed":1,"syntology":null},{"url":"/paper/vflip-a-backdoor-defense-for-vertical","title":"VFLIP: A Backdoor Defense for Vertical Federated Learning via Identification and Purification","date":"2024-08-28","arxiv_id":"2408.15591","repositories_listed":1,"syntology":null},{"url":"/paper/2407-21316","title":"Diff-Cleanse: Identifying and Mitigating Backdoor Attacks in Diffusion Models","date":"2024-07-31","arxiv_id":"2407.21316","repositories_listed":1,"syntology":null},{"url":"/paper/towards-unified-robustness-against-both","title":"Towards Unified Robustness Against Both Backdoor and Adversarial Attacks","date":"2024-05-28","arxiv_id":"2405.17929","repositories_listed":1,"syntology":null},{"url":"/paper/badacts-a-universal-backdoor-defense-in-the","title":"BadActs: A Universal Backdoor Defense in the Activation Space","date":"2024-05-18","arxiv_id":"2405.11227","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/backdoor-secrets-unveiled-identifying","title":"Backdoor Secrets Unveiled: Identifying Backdoor Data with Optimized Scaled Prediction Consistency","date":"2024-03-15","arxiv_id":"2403.10717","repositories_listed":1,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":5}},{"url":"/paper/watch-out-for-your-agents-investigating","title":"Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents","date":"2024-02-17","arxiv_id":"2402.11208","repositories_listed":1,"syntology":{"n":2,"n_ran":2,"n_unverified":0,"n_pointer_only":2}},{"url":"/paper/spy-watermark-robust-invisible-watermarking","title":"Spy-Watermark: Robust Invisible Watermarking for Backdoor Attack","date":"2024-01-04","arxiv_id":"2401.02031","repositories_listed":1,"syntology":{"n":9,"n_ran":5,"n_unverified":4,"n_pointer_only":9}}],"syntology_records":13,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}