Research map / Adversarial robustness and security
Backdoor and poisoning: research map
320 accepted papers on Backdoor and poisoning in Adversarial robustness and security, from ICML, NeurIPS, ICLR, CVPR and AAAI (2016–2026), grouped into 2 clusters and 5 approaches. The busiest year so far is 2026.
Within Adversarial robustness and security, its share grew from 13.8% in 2023–24 to 15.2% in 2025–26 (107 → 149 papers at ICML, NeurIPS, CVPR and AAAI, the venues with data for all four years).
Explore Backdoor and poisoning in the interactive map
Working on something in this topic? Describe your idea in scime atlas to see which approach it falls under, the closest papers by meaning and how crowded the spot has become.
Approaches and key papers
backdoor attack · poisoning · triggers · 226 papers
Approaches in this cluster:
- Trigger-based backdoor attacks (106 papers)
Design poisoning-based backdoor attacks with hidden or clean-label triggers on vision models. - Backdoors in large multimodal models (104 papers)
Attack and analyze backdoors in LLMs, vision-language and action models. - Backdoors in federated learning (16 papers)
Attack and defend federated training with distributed backdoors and robust aggregation.
Most cited and most cited since 2024:
- Spectral Signatures in Backdoor Attacks (NeurIPS 2018 · 367 citations)
- DBA: Distributed Backdoor Attacks against Federated Learning (ICLR 2020 · 260 citations)
- Beyond Traditional Threats: A Persistent Backdoor Attack on Federated Learning (AAAI 2024 · 41 citations)
- BadCLIP: Dual-Embedding Guided Backdoor Attack on Multimodal Contrastive Learning (CVPR 2024 · 32 citations)
backdoor defense · backdoored · clean · 94 papers
Approaches in this cluster:
- Detecting poisoned samples (54 papers)
Identify backdoor data or inputs and unlearn triggers, including in pretrained language models. - Training-time backdoor defense (40 papers)
Train clean models on poisoned data by splitting data and decoupling features.
Most cited and most cited since 2024:
- Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks (ICLR 2021 · 142 citations)
- Backdoor Defense via Adaptively Splitting Poisoned Dataset (CVPR 2023 · 60 citations)
- Nearest is Not Dearest: Towards Practical Defense against Quantization-conditioned Backdoor Attacks (CVPR 2024 · 17 citations)
- Progressive Poisoned Data Isolation for Training-Time Backdoor Defense (AAAI 2024 · 14 citations)
