{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T13:12:51Z","timestamp":1775913171652,"version":"3.50.1"},"reference-count":256,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2246920"],"award-info":[{"award-number":["2246920"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/access.2024.3363657","type":"journal-article","created":{"date-parts":[[2024,2,7]],"date-time":"2024-02-07T18:52:21Z","timestamp":1707331941000},"page":"22072-22097","source":"Crossref","is-referenced-by-count":49,"title":["Security Considerations in AI-Robotics: A Survey of Current Methods, Challenges, and Opportunities"],"prefix":"10.1109","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9260-3914","authenticated-orcid":false,"given":"Subash","family":"Neupane","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]},{"given":"Shaswata","family":"Mitra","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]},{"given":"Ivan A.","family":"Fernandez","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8007-8902","authenticated-orcid":false,"given":"Swayamjit","family":"Saha","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9151-8347","authenticated-orcid":false,"given":"Sudip","family":"Mittal","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5133-9552","authenticated-orcid":false,"given":"Jingdao","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2275-6998","authenticated-orcid":false,"given":"Nisha","family":"Pillai","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]},{"given":"Shahram","family":"Rahimi","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Mississippi State University, Starkville, MS, USA"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Robot System Architectures"},{"key":"ref2","volume-title":"The Worlds Most Experienced Driver"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICETST49965.2020.9080724"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TBME.2014.2302385"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TCDS.2021.3098350"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.25165\/j.ijabe.20181104.4278"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2975142"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CIC50333.2020.00025"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.21236\/ADA534697"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-021-00545-8"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/COMPTELIX.2017.8004033"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-33112-6_5"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109626"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TRO.2023.3248510"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCA51439.2020.9264513"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3050038"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SMARTCOMP.2016.7501710"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3022763"},{"key":"ref19","volume-title":"Hackers Can Trick a Tesla Into Accelerating by 50 Miles Per Hour","year":"2020"},{"key":"ref20","volume-title":"Legendary Hackers Charlie Miller and Chris Valasek Talk Cybersecurity and Autonomous Vehicles At Tc Sessions: Mobility","year":"2022"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MDAT.2018.2863106"},{"key":"ref22","volume-title":"Artificial Intelligence and Cybersecurity Opportunities and Challenges","year":"2023"},{"key":"ref23","article-title":"AI security threats against pervasive robotic systems: A course for next generation cybersecurity workforce","author":"Mittal","year":"2023","journal-title":"arXiv:2302.07953"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3508398.3519314"},{"key":"ref25","first-page":"1","article-title":"A code of ethics for the human\u2013robot interaction profession","author":"Riek","year":"2014","journal-title":"Proc. Robot"},{"key":"ref26","first-page":"35","article-title":"Ethical reflections on health care robotics","author":"Datteri","year":"2009","journal-title":"Ethics Robot."},{"key":"ref27","volume-title":"California Consumer Privacy Act","year":"2023"},{"key":"ref28","volume-title":"General Data Protection Regulation","year":"2023"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.iswa.2023.200237"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.3390\/electronics10222850"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/s11235-019-00561-z"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.autcon.2022.104298"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3337791"},{"key":"ref34","volume-title":"Flaticon","year":"2023"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1108\/ir.2001.28.3.266.1"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.robot.2015.07.015"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3419474"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ROBOT.1985.1087316"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1007\/s10514-012-9321-0"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.2020.3018325"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2015.7139363"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.81"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2012.231"},{"key":"ref44","first-page":"82","article-title":"Recurrent convolutional neural networks for scene labeling","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Pinheiro"},{"key":"ref45","article-title":"URA: Uncertainty-aware path planning using image-based aerial-to-ground traversability estimation for off-road environments","author":"Moore","year":"2023","journal-title":"arXiv:2309.08814"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46487-9_13"},{"key":"ref47","article-title":"An image is worth 16 \u00d7 16 words: Transformers for image recognition at scale","author":"Dosovitskiy","year":"2020","journal-title":"arXiv:2010.11929"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19842-7_7"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/IROS47612.2022.9981248"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TSSC.1968.300136"},{"key":"ref51","article-title":"Rapidly-exploring random trees: A new tool for path planning","author":"LaValle","year":"9811"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.2140\/pjm.1990.145.367"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/100.580977"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/IROS51168.2021.9636039"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2018.8460851"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/ICNSC48988.2020.9238090"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/SYSOSE.2017.7994976"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.15607\/RSS.2017.XIII.064"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.5121\/csit.2020.101117"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.05.006"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.15607\/RSS.2018.XIV.021"},{"key":"ref62","volume-title":"The PID Control Algorithm","author":"Shaw","year":"2003"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-014-0818-1"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1177\/0278364913495721"},{"key":"ref65","first-page":"651","article-title":"Scalable deep reinforcement learning for vision-based robotic manipulation","volume-title":"Proc. Int. Conf. Robot Learn.","author":"Kalashnikov"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2015.7138994"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.6028\/nist.sp.800-171r3.ipd"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1016\/j.promfg.2021.07.029"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.3390\/computers11120181"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2334493"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3071405"},{"issue":"8","key":"ref73","first-page":"109","article-title":"Can you trust autonomous vehicles: Contactless attacks against sensors of self-driving vehicle","volume":"24","author":"Yan","year":"2016","journal-title":"Defcon"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66787-4_22"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/WF-IoT.2018.8355132"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660336"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179458"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00076"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485377"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.20"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2867917"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/ISSREW.2019.00080"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/VTCFall.2018.8690734"},{"key":"ref85","first-page":"1527","article-title":"All your GPS are belong to us: Towards stealthy manipulation of road navigation systems","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Zeng"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00091"},{"issue":"11","key":"ref87","first-page":"120","article-title":"The OpenCV library","volume":"25","author":"Bradski","year":"2000","journal-title":"Dr. Dobbs J., Softw. Tools Prof. Programmer"},{"key":"ref88","article-title":"TensorFlow: Large-scale machine learning on heterogeneous distributed systems","author":"Abadi","year":"2016","journal-title":"arXiv:1603.04467"},{"key":"ref89","article-title":"Open3D: A modern library for 3D data processing","author":"Zhou","year":"2018","journal-title":"arXiv:1801.09847"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196506"},{"key":"ref91","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref92","volume-title":"CVE-2018-5268 Detail"},{"key":"ref93","volume-title":"CVE-2021-37650 Detail"},{"key":"ref94","first-page":"995","article-title":"Remote attacks on automated vehicles sensors: Experiments on camera and LiDAR","volume":"11","author":"Petit","year":"2015","journal-title":"Black Hat Eur."},{"key":"ref95","article-title":"SoK: Rethinking sensor spoofing attacks against robotic vehicles from a systematic view","author":"Xu","year":"2022","journal-title":"arXiv:2205.04662"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1155\/2015\/140217"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.1016\/S1353-4858(19)30122-9"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/LCSYS.2019.2921753"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053342"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1109\/VLSID.2018.97"},{"key":"ref101","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2019.1800156"},{"key":"ref102","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.2018.1800065"},{"key":"ref103","first-page":"3503","article-title":"An experimental study of GPS spoofing and takeover attacks on UAVs","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Sathaye"},{"key":"ref104","first-page":"931","article-title":"Drift with devil: Security of multi-sensor fusion based localization in high-level autonomous driving under GPS spoofing","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Shen"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00780"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.14722\/autosec.2021.23029"},{"key":"ref107","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179458"},{"key":"ref108","first-page":"877","article-title":"Towards robust LiDAR-based perception in autonomous driving: General black-box adversarial sensor attack and countermeasures","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Sun"},{"key":"ref109","first-page":"881","article-title":"Rocking drones with intentional sound noise on gyroscopic sensors","volume-title":"Proc. 24th USENIX Secur. Symp.","author":"Son"},{"key":"ref110","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.42"},{"key":"ref111","first-page":"1545","article-title":"Injected and delivered: Fabricating implicit control over actuation systems by spoofing inertial sensors","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Tu"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA48506.2021.9561817"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01679"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM55135.2022.10017870"},{"key":"ref115","doi-asserted-by":"publisher","DOI":"10.1109\/tiv.2023.3296227"},{"key":"ref116","doi-asserted-by":"publisher","DOI":"10.5772\/45604"},{"key":"ref117","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484766"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2018.2881296"},{"key":"ref119","doi-asserted-by":"publisher","DOI":"10.23919\/ACC.2017.7962962"},{"key":"ref120","doi-asserted-by":"publisher","DOI":"10.1109\/IROS40897.2019.8968611"},{"key":"ref121","doi-asserted-by":"publisher","DOI":"10.1007\/s10514-019-09870-3"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1007\/s43154-021-00046-5"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1007\/s10514-018-9715-8"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2017.7989099"},{"key":"ref125","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-44051-0_9"},{"key":"ref126","first-page":"671","article-title":"Learning decentralized controllers for robot swarms with graph neural networks","volume-title":"Proc. Conf. Robot Learn.","author":"Tolstaya"},{"key":"ref127","doi-asserted-by":"publisher","DOI":"10.1109\/IROS45743.2020.9341668"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485350"},{"key":"ref129","doi-asserted-by":"publisher","DOI":"10.1109\/ICC45855.2022.9838325"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3266699"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-19-1983-1"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1109\/DFT.2012.6378199"},{"key":"ref133","article-title":"Maldrone the first backdoor for drones","author":"Sasi","year":"2015","journal-title":"Rahul Sasis Blog"},{"key":"ref134","article-title":"Introducing the robot security framework (RSF), a standardized methodology to perform security assessments in robotics","author":"Vilches","year":"2018","journal-title":"arXiv:1806.04042"},{"key":"ref135","article-title":"Robot hazards: From safety to security","author":"Kirschgens","year":"2018","journal-title":"arXiv:1806.06681"},{"key":"ref136","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-019-00329-8"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45748-8_24"},{"issue":"3","key":"ref138","first-page":"1","article-title":"Cybsersecurity issues in robotics","volume":"12","author":"Lacava","year":"2021","journal-title":"J. Wireless Mobile Netw., Ubiquitous Comput. Dependable Appl."},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.20"},{"key":"ref140","article-title":"To make a robot secure: An experimental analysis of cyber security threats against teleoperated surgical robots","author":"Bonaci","year":"2015","journal-title":"arXiv:1504.04339"},{"key":"ref141","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2016.43"},{"key":"ref142","article-title":"Exploiting physical dynamics to detect actuator and sensor attacks in mobile robots","author":"Guo","year":"2017","journal-title":"arXiv:1708.01834"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1016\/j.automatica.2019.108687"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00029"},{"key":"ref145","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2018.2815758"},{"key":"ref146","doi-asserted-by":"publisher","DOI":"10.1016\/j.amc.2020.125668"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.23919\/ECC55457.2022.9838201"},{"key":"ref148","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2016.7487160"},{"key":"ref149","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2018.00065"},{"key":"ref150","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2023.123132"},{"key":"ref151","doi-asserted-by":"publisher","DOI":"10.1177\/1729881419874962"},{"key":"ref152","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2012.6225218"},{"key":"ref153","doi-asserted-by":"publisher","DOI":"10.1080\/01969722.2011.583593"},{"key":"ref154","doi-asserted-by":"publisher","DOI":"10.1109\/AFGR.2008.4813386"},{"key":"ref155","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1038\/538020a"},{"key":"ref157","volume-title":"In 2016, Microsofts Racist Chatbot Revealed the Dangers of Online Conversation","year":"2016"},{"key":"ref158","volume-title":"How Data Poisoning Attacks Can Corrupt Machine Learning Models","year":"2021"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref160","article-title":"Dataset security for machine learning: Data poisoning, backdoor attacks, and defenses","author":"Goldblum","year":"2020","journal-title":"arXiv:2012.10544"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1145\/3055399.3055491"},{"key":"ref162","first-page":"1487","article-title":"Explanation-guided backdoor poisoning attacks against malware classifiers","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Severi"},{"key":"ref163","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD.2017.16"},{"key":"ref164","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413546"},{"key":"ref166","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref167","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref168","first-page":"5345","article-title":"When does data augmentation help with membership inference attacks?","volume-title":"Proc. ICML","author":"Kaya"},{"key":"ref169","doi-asserted-by":"publisher","DOI":"10.1145\/3485133"},{"key":"ref170","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485837"},{"key":"ref171","article-title":"ReLUSyn: Synthesizing stealthy attacks for deep neural network based cyber-physical systems","author":"Kashyap","year":"2021","journal-title":"arXiv:2105.10393"},{"key":"ref172","article-title":"Targeted attack against deep neural networks via flipping limited weight bits","author":"Bai","year":"2021","journal-title":"arXiv:2102.10496"},{"key":"ref173","article-title":"Subnet replacement: Deployment-stage backdoor attack against deep neural networks in gray-box setting","author":"Qi","year":"2021","journal-title":"arXiv:2107.07240"},{"key":"ref174","doi-asserted-by":"publisher","DOI":"10.1109\/TENCON50793.2020.9293933"},{"key":"ref175","article-title":"IdentityDP: Differential private identification protection for face images","author":"Wen","year":"2021","journal-title":"arXiv:2103.01745"},{"key":"ref176","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00549"},{"key":"ref177","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417880"},{"key":"ref178","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/137"},{"key":"ref179","first-page":"1599","article-title":"Formal security analysis of neural networks using symbolic intervals","volume-title":"Proc. USENIX Secur. Symp.","author":"Wang"},{"key":"ref180","article-title":"Prediction poisoning: Towards defenses against DNN model stealing attacks","author":"Orekondy","year":"2019","journal-title":"arXiv:1906.10908"},{"key":"ref181","article-title":"Cylance, I kill you","author":"Ashkenazy","year":"2019"},{"key":"ref182","first-page":"337","article-title":"Smart malware that uses leaked control data of robotic applications: The case of Raven-II surgical robots","volume-title":"Proc. 22nd Int. Symp. Res. Attacks, Intrusions Defenses","author":"Chung"},{"key":"ref183","doi-asserted-by":"publisher","DOI":"10.1109\/IRC.2020.00080"},{"key":"ref184","doi-asserted-by":"publisher","DOI":"10.1109\/SSRR.2017.8088163"},{"key":"ref185","first-page":"1","article-title":"The birth of Roboethics","volume-title":"Proc. IEEE Int. Conf. Robot. Autom. (ICRA)","author":"Veruggio"},{"key":"ref186","volume-title":"Robot Ethics.","year":"2023"},{"key":"ref187","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-21714-7"},{"key":"ref188","first-page":"191","article-title":"Health insurance portability and accountability act of 1996","volume":"104","author":"Act","year":"1996","journal-title":"Public Law"},{"key":"ref189","doi-asserted-by":"publisher","DOI":"10.5040\/9781782258674.0010"},{"key":"ref190","doi-asserted-by":"publisher","DOI":"10.1109\/MITS.2019.2953556"},{"key":"ref191","doi-asserted-by":"publisher","DOI":"10.1109\/MSPEC.2016.7473149"},{"key":"ref192","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v38i3.2741"},{"key":"ref193","article-title":"The ethics of saving lives with autonomous cars are far murkier than you think","volume":"30","author":"Lin","year":"2013","journal-title":"Wired Opinion"},{"key":"ref194","article-title":"Robot wars: Legal and ethical dilemmas of using unmanned robotic systems in 21st century warfare and beyond","author":"McDaniel","year":"2008"},{"key":"ref195","article-title":"Three laws of robotics","volume":"2","author":"Asimov","year":"1941","journal-title":"Asimov, I. Runaround"},{"key":"ref196","first-page":"190","article-title":"The liability problem for autonomous artificial agents","volume-title":"Proc. AAAI Spring Symp. Ser.","author":"Asaro"},{"key":"ref197","doi-asserted-by":"publisher","DOI":"10.1002\/rcs.1968"},{"key":"ref198","volume-title":"Preparing for the Future of Artificial Intelligence","year":"2023"},{"key":"ref199","doi-asserted-by":"publisher","DOI":"10.1007\/s00146-017-0758-8"},{"key":"ref200","doi-asserted-by":"publisher","DOI":"10.1145\/3579515"},{"key":"ref201","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i13.17371"},{"key":"ref202","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2017.08.007"},{"key":"ref203","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00932"},{"key":"ref204","doi-asserted-by":"publisher","DOI":"10.1145\/2157689.2157807"},{"key":"ref205","doi-asserted-by":"publisher","DOI":"10.1016\/j.pmcj.2021.101397"},{"key":"ref206","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2016.12.008"},{"key":"ref207","doi-asserted-by":"publisher","DOI":"10.1177\/1064804611415045"},{"key":"ref208","doi-asserted-by":"publisher","DOI":"10.1007\/s12369-010-0073-8"},{"key":"ref209","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376372"},{"key":"ref210","doi-asserted-by":"publisher","DOI":"10.3389\/frobt.2017.00021"},{"key":"ref211","doi-asserted-by":"publisher","DOI":"10.1145\/3025453.3025735"},{"key":"ref212","doi-asserted-by":"publisher","DOI":"10.1016\/j.robot.2017.12.008"},{"key":"ref213","first-page":"65","article-title":"End user security and privacy concerns with smart homes","volume-title":"Proc. 13th Symp. Usable Privacy Security (SOUPS)","author":"Zeng"},{"key":"ref214","doi-asserted-by":"publisher","DOI":"10.1145\/1132736.1132751"},{"key":"ref215","doi-asserted-by":"publisher","DOI":"10.1518\/hfes.46.1.50_30392"},{"key":"ref216","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-62056-1_44"},{"key":"ref217","first-page":"141","article-title":"Would you trust a (Faulty) robot? Effects of error, task type and personality on human\u2013robot cooperation and trust","volume-title":"Proc. 10th ACM\/IEEE Int. Conf. Human Robot Interact. (HRI)","author":"Salem"},{"key":"ref218","doi-asserted-by":"publisher","DOI":"10.1145\/2701973.2702059"},{"key":"ref219","doi-asserted-by":"publisher","DOI":"10.1109\/SISY.2017.8080540"},{"key":"ref220","doi-asserted-by":"publisher","DOI":"10.1145\/2157689.2157702"},{"key":"ref221","first-page":"78","article-title":"Building and maintaining trust between humans and guidance robots in an emergency","volume-title":"Proc. AAAI Spring Symp.","author":"Robinette"},{"key":"ref222","doi-asserted-by":"publisher","DOI":"10.1016\/j.chb.2014.05.014"},{"key":"ref223","doi-asserted-by":"publisher","DOI":"10.1109\/HRI.2016.7451740"},{"key":"ref224","doi-asserted-by":"publisher","DOI":"10.1109\/ROMAN.2016.7745155"},{"key":"ref225","first-page":"408","article-title":"Evaluating effects of user experience and system transparency on trust in automation","volume-title":"Proc. 12th ACM\/IEEE Int. Conf. Human Robot Interact. (HRI","author":"Yang"},{"key":"ref226","doi-asserted-by":"publisher","DOI":"10.1109\/ROMAN.2011.6005274"},{"key":"ref227","first-page":"60","article-title":"Building appropriate trust in human\u2013robot teams","volume-title":"Proc. AAAI Spring Symp. Ser.","author":"Ososky"},{"key":"ref228","doi-asserted-by":"crossref","DOI":"10.1007\/3-540-45150-1","volume-title":"IT-Security and Privacy: Design and Use of Privacy-Enhancing Security Mechanisms","author":"Fischer-Hubner","year":"2001"},{"key":"ref229","volume-title":"Anonymity, Unlinkability, Unobservability, Pseudonymity, and Identity Management\u2014A Consolidated Proposal for Terminology","author":"Pfitzmann","year":"2005"},{"key":"ref230","volume-title":"Privacy Enhancing Technologies","year":"2023"},{"key":"ref231","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2020.102807"},{"key":"ref232","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA40945.2020.9196983"},{"key":"ref233","doi-asserted-by":"publisher","DOI":"10.1109\/RO-MAN47096.2020.9223556"},{"key":"ref234","first-page":"27","article-title":"The privacy-utility tradeoff for remotely teleoperated robots","volume-title":"Proc. 10th ACM\/IEEE Int. Conf. Human Robot Interact. (HRI)","author":"Butler"},{"key":"ref235","doi-asserted-by":"publisher","DOI":"10.1126\/scirobotics.abe4385"},{"key":"ref236","doi-asserted-by":"publisher","DOI":"10.1109\/TRO.2023.3290449"},{"key":"ref237","article-title":"Towards representation identical privacy-preserving graph neural network via split learning","author":"Shan","year":"2021","journal-title":"arXiv:2107.05917"},{"key":"ref238","doi-asserted-by":"publisher","DOI":"10.1109\/BigData52589.2021.9671867"},{"key":"ref239","first-page":"1069","article-title":"Planning with resource conflicts in human\u2013robot cohabitation","volume-title":"Proc. 15th Int. Conf. Auton. Agents Multiagent Syst.","author":"Chakraborti"},{"key":"ref240","doi-asserted-by":"publisher","DOI":"10.1007\/s43154-020-00029-y"},{"key":"ref241","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2998358"},{"key":"ref242","doi-asserted-by":"publisher","DOI":"10.1016\/j.cirp.2019.04.011"},{"key":"ref243","doi-asserted-by":"publisher","DOI":"10.1186\/s10033-022-00680-w"},{"key":"ref244","article-title":"TwinExplainer: Explaining predictions of an automotive digital twin","author":"Neupane","year":"2023","journal-title":"arXiv:2302.00152"},{"key":"ref245","doi-asserted-by":"publisher","DOI":"10.1080\/10447318.2022.2066246"},{"key":"ref246","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3216617"},{"key":"ref247","first-page":"351","article-title":"Explainable AI for robot failures: Generating explanations that improve user assistance in fault recovery","volume-title":"Proc. 16th ACM\/IEEE Int. Conf. Human Robot Interact. (HRI)","author":"Das"},{"key":"ref248","doi-asserted-by":"publisher","DOI":"10.3389\/fnbot.2020.570308"},{"key":"ref249","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17462-0_28"},{"key":"ref250","doi-asserted-by":"publisher","DOI":"10.1146\/annurev-control-042920-020211"},{"key":"ref251","first-page":"1","article-title":"Safe model-based reinforcement learning with stability guarantees","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Berkenkamp"},{"key":"ref252","doi-asserted-by":"publisher","DOI":"10.1007\/s12525-020-00441-4"},{"key":"ref253","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00092"},{"key":"ref254","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2017.12.002"},{"key":"ref255","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2017.2782813"},{"key":"ref256","volume-title":"Association for Advancing Automation","year":"2023"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/6287639\/10380310\/10423748-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/10380310\/10423748.pdf?arnumber=10423748","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,3]],"date-time":"2024-03-03T12:15:41Z","timestamp":1709468141000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10423748\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":256,"URL":"https:\/\/doi.org\/10.1109\/access.2024.3363657","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}