Skip to main navigation Skip to search Skip to main content

Clean-Label Backdoor Attacks: A Survey

Research output: Contribution to journalArticlepeer-review

Abstract

Backdoor attacks against neural networks allow adversaries to implant hidden behaviors that are activated at inference time while preserving high performance on clean inputs. Clean-label backdoor attacks are particularly stealthy because they poison training data without altering the ground-truth labels, making malicious samples difficult to detect through conventional data validation. This threat is especially relevant when training data is collected from untrusted, outsourced, or distributed sources. This paper presents a systematic survey of clean-label, data-poisoning-based backdoor attacks in image classification. We introduce a unified two-level taxonomy that first distinguishes between trigger-containing and trigger-free attacks and then organizes each category according to its underlying attack mechanisms. Based on this taxonomy, we analyze 18 representative methods and compare them in terms of attack effectiveness, stealth, and operational assumptions, using commonly reported metrics such as attack success rate and clean accuracy. We further examine attacker knowledge settings and practical deployment scenarios to assess the real-world feasibility of these attacks. In addition, we identify emerging trends, including adaptive and sample-specific triggers, discuss the limitations of existing defense strategies, and outline open challenges in evaluation and mitigation. Finally, we propose a standardized reporting framework to improve reproducibility, comparability, and consistency across studies. This survey provides a structured understanding of clean-label backdoor attacks and offers guidance for developing more robust and secure machine learning systems.

Original languageEnglish
Pages (from-to)72508-72539
Number of pages32
JournalIEEE Access
Volume14
DOIs
StatePublished - 1 Jan 2026

Keywords

  • Backdoor
  • clean-label backdoor attack
  • data poisoning
  • image classification
  • neural networks

ASJC Scopus subject areas

  • General Computer Science
  • General Materials Science
  • General Engineering

Fingerprint

Dive into the research topics of 'Clean-Label Backdoor Attacks: A Survey'. Together they form a unique fingerprint.

Cite this