{"id":"W4413476775","doi":"10.1016/j.eswa.2025.129481","title":"Clean-label backdoor attack via sample-customized feature alignment","year":2025,"lang":"en","type":"article","venue":"Expert Systems with Applications","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":false,"ca_institutions":"Artificial Intelligence in Medicine (Canada)","funders":"National Natural Science Foundation of China-Shandong Joint Fund; Natural Science Foundation of Shandong Province; National Natural Science Foundation of China","keywords":"Backdoor; Computer science; Sample (material); Feature (linguistics); Pattern recognition (psychology); Artificial intelligence; Data mining; Computer security; Chromatography","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002011311,0.001663739,0.001714544,0.0007793973,0.0009241606,0.001417593,0.001380227,0.002494101,0.003363458],"category_scores_gemma":[0.01055012,0.0006315344,0.001315655,0.0008970244,0.001836329,0.002862612,0.005259423,0.004137778,0.001676865],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006914167,"about_ca_system_score_gemma":0.001584114,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.000789627,"about_ca_topic_score_gemma":0.001214776,"domain_scores_codex":[0.9963841,0.0008574123,0.0001292031,0.0007711955,0.001395772,0.0004622526],"domain_scores_gemma":[0.9955021,0.001887502,0.0002977946,0.001871287,0.0003135491,0.0001279259],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.002669407,0.0005631396,0.003632284,0.0005033541,0.000528034,0.001001678,0.0003676114,0.262752,0.08943509,0.1513957,0.02811699,0.4590347],"study_design_scores_gemma":[0.00007295411,0.0001423815,0.0007645208,0.00003109738,0.00004938224,0.0004383469,0.00004352211,0.8812562,0.02759848,0.08657973,0.002973977,0.00004934049],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.02527059,0.0003089643,0.9675656,0.0007902764,0.0002080714,0.00008246072,0.0002974181,0.002875872,0.002600756],"genre_scores_gemma":[0.7472788,0.0002751629,0.2435365,0.0008870697,0.0002061951,0.0001905346,0.0009124818,0.0005386986,0.00617447],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003363458,"threshold_uncertainty_score":0.01125187,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.01506443899332251,"score_gpt":0.2946220818503113,"score_spread":0.2795576428569888,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}