Dawei Xu, Tao Lei, Guogang Zhao, Jian Zhao, Dawen Sun · Journal on Information Security 2026 · 2026
DOI: 10.1186/s13635-026-00246-6
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Deep neural networks have achieved remarkable success in image classification, but their training processes remain vulnerable to backdoor attacks. Existing frequency-domain backdoor attacks typically rely on manually designed and data-independent triggers, limiting their adaptability across different models and datasets. Moreover, fixed spectral perturbations may introduce detectable frequency anomalies. To address these limitations, we propose CLTBA, a backdoor attack based on learnable frequency-domain triggers. CLTBA jointly optimizes the trigger distribution and model parameters through an adaptive spectral mask and a dynamic training strategy, enabling flexible trigger generation while preserving visual quality. A spectral preservation mechanism further constrains trigger perturbations within a controllable frequency region, thereby reducing spectral anomalies and improving stealthiness. Experiments on GTSRB, CelebA, and MNIST with ResNet-18 and EfficientNet-B0 demonstrate that CLTBA achieves high attack success rates while maintaining benign accuracy and shows improved resistance to representative backdoor defenses and analysis methods, including STRIP, Neural Cleanse, Fine-Pruning, and Grad-CAM.
No comments yet — start the discussion below.