{"id":"W4413786017","doi":"10.1109/tdsc.2025.3603639","title":"I2I Backdoor: Backdoor Attacks Against Image-to-Image Tasks","year":2025,"lang":"en","type":"article","venue":"IEEE Transactions on Dependable and Secure Computing","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":5,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of New Brunswick","funders":"National Natural Science Foundation of China","keywords":"Backdoor; Computer science; Image (mathematics); Computer security; Artificial intelligence; Computer vision","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002159929,0.00170045,0.001138986,0.0006076,0.0007672536,0.001052142,0.001785578,0.002115408,0.001933124],"category_scores_gemma":[0.01004717,0.0005392344,0.001249317,0.0004142454,0.002378014,0.003184255,0.004157432,0.003443327,0.0006365706],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0009858091,"about_ca_system_score_gemma":0.0007791629,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0009631009,"about_ca_topic_score_gemma":0.0008380325,"domain_scores_codex":[0.9976394,0.0005653089,0.0001071132,0.0004720663,0.0007712898,0.0004447697],"domain_scores_gemma":[0.9951715,0.002280781,0.0006070806,0.001329113,0.0004042493,0.0002072944],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"simulation_or_modeling","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.001697544,0.0003228472,0.003908253,0.0005029524,0.0004150562,0.001592261,0.0005108336,0.6125049,0.09788316,0.0692597,0.01166985,0.1997326],"study_design_scores_gemma":[0.00002370463,0.0001617486,0.0003828135,0.00002672187,0.00002817431,0.0004179703,0.0000426709,0.9516878,0.02975158,0.01608233,0.001360953,0.00003356802],"study_design_candidate":"simulation_or_modeling","study_design_consensus":"simulation_or_modeling","genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.08430095,0.0010947,0.9049997,0.0008993006,0.0002362014,0.0002417063,0.0002101718,0.00303394,0.004983331],"genre_scores_gemma":[0.9258351,0.0003656748,0.0701943,0.0005605737,0.000061959,0.0001575801,0.000186833,0.0001899793,0.002448086],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.002159929,"threshold_uncertainty_score":0.01142293,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.008572549446998498,"score_gpt":0.2709500114351712,"score_spread":0.2623774619881727,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}