USENIX Security '23 - Aliasing Backdoor Attacks on Pre-trained Models