{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T11:00:11Z","timestamp":1780398011847,"version":"3.54.1"},"reference-count":70,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2020,6,1]],"date-time":"2020-06-01T00:00:00Z","timestamp":1590969600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,6,1]],"date-time":"2020-06-01T00:00:00Z","timestamp":1590969600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,6,1]],"date-time":"2020-06-01T00:00:00Z","timestamp":1590969600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"GRF grant from the Research Grants Council of Hong Kong","award":["CityU 11217817"],"award-info":[{"award-number":["CityU 11217817"]}]},{"name":"Science Technology and Innovation Committee of Shenzhen Municipality","award":["JCYJ20170818095109386"],"award-info":[{"award-number":["JCYJ20170818095109386"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2020,6]]},"DOI":"10.1109\/jiot.2020.2975654","type":"journal-article","created":{"date-parts":[[2020,2,21]],"date-time":"2020-02-21T21:21:31Z","timestamp":1582320091000},"page":"5103-5115","source":"Crossref","is-referenced-by-count":74,"title":["Adversarial Attacks and Defenses on Cyber\u2013Physical Systems: A Survey"],"prefix":"10.1109","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3918-4922","authenticated-orcid":false,"given":"Jiao","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2474-2004","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4565-5548","authenticated-orcid":false,"given":"Tao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1387-583X","authenticated-orcid":false,"given":"Zhen","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3296-3392","authenticated-orcid":false,"given":"Zhenjiang","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9318-1482","authenticated-orcid":false,"given":"Jianping","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3278492"},{"key":"ref39","author":"rajaratnam","year":"2018","journal-title":"Speech Coding and Audio Preprocessing for Mitigating and Detecting Audio Adversarial Examples on Automatic Speech Recognition"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/PESMG.2013.6672638"},{"key":"ref33","first-page":"1","article-title":"False data injection attacks in control systems","author":"mo","year":"2010","journal-title":"Proc SCSC"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/1952982.1952995"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3307334.3326109"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2018.8485958"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/GLOCOM.2012.6503599"},{"key":"ref36","author":"qin","year":"2019","journal-title":"Imperceptible robust and targeted adversarial examples for automatic speech recognition"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-99626-4_3"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-1353"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2013.92"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2019.2915124"},{"key":"ref61","first-page":"1","article-title":"Towards mitigating audio adversarial perturbations","author":"yang","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2014.2382714"},{"key":"ref28","author":"liang","year":"2017","journal-title":"Deep text classification can be fooled"},{"key":"ref64","first-page":"49","article-title":"CommanderSong: A systematic approach for practical adversarial voice recognition","author":"yuan","year":"2018","journal-title":"Proc Usenix Security"},{"key":"ref27","first-page":"11908","article-title":"Adversarial music: Real world audio adversary against wake-word detection system","author":"li","year":"2019","journal-title":"Proc NIPS"},{"key":"ref65","author":"yuan","year":"2018","journal-title":"Adaptive adversarial attack on scene text recognition"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2019.00019"},{"key":"ref29","author":"liu","year":"2019","journal-title":"Adversarial attack on speech-to-text recognition models"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/3327962.3331456"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.2019.1800477"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.23919\/ACC.2019.8814659"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref1","author":"abdoli","year":"2019","journal-title":"Universal adversarial audio perturbations"},{"key":"ref20","author":"karim","year":"2019","journal-title":"Adversarial attacks on time series"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8462693"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/SMARTGRID.2010.5622045"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363246"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2925452"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CEC.2019.8790213"},{"key":"ref25","article-title":"Discrete adversarial attacks and submodular optimization with applications to text classification","author":"lei","year":"2019","journal-title":"Proc SysML"},{"key":"ref50","author":"vijayaraghavan","year":"2019","journal-title":"Generating black-box adversarial examples for text classifiers using a deep reinforced model"},{"key":"ref51","author":"wang","year":"2019","journal-title":"AdvCodec Towards a unified framework for adversarial text generation"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2919635"},{"key":"ref58","author":"yakura","year":"2018","journal-title":"Robust audio adversarial example for a physical attack"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1002\/acs.3001"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2011.2161892"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SMARTGRID.2010.5622048"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/DySPAN.2019.8935789"},{"key":"ref53","author":"wang","year":"2019","journal-title":"Natural language adversarial attacks and defenses in word level"},{"key":"ref52","author":"wang","year":"2019","journal-title":"A survey on adversarial attacks and defenses in text"},{"key":"ref10","doi-asserted-by":"crossref","first-page":"106","DOI":"10.1109\/MSP.2012.2185911","article-title":"Coordinated data-injection attack and detection in the smart grid: A detailed look at enriching detection solutions","volume":"29","author":"cui","year":"2012","journal-title":"IEEE Signal Process Mag"},{"key":"ref11","first-page":"17","article-title":"Gray-box techniques for adversarial text generation","author":"dasgupta","year":"2018","journal-title":"Proc AAAI Fall Symp"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ISSPIT.2018.8642623"},{"key":"ref12","author":"feng","year":"2017","journal-title":"A deep learning-based framework for conducting stealthy attacks in industrial control systems"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00016"},{"key":"ref14","author":"gong","year":"2017","journal-title":"Crafting adversarial examples for speech paralinguistics applications"},{"key":"ref15","author":"goodfellow","year":"2014","journal-title":"Explaining and Harnessing Adversarial Examples"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363264"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2015.2475695"},{"key":"ref18","article-title":"Generating adversarial examples for speech recognition","author":"iter","year":"2017"},{"key":"ref19","author":"jin","year":"2019","journal-title":"Is BERT Really Robust? Natural Language Attack on Text Classification and Entailment"},{"key":"ref4","author":"alzantot","year":"2018","journal-title":"Did you hear that? adversarial examples against automatic speech recognition"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.5120\/ijca2019919384"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8682430"},{"key":"ref5","author":"alzantot","year":"2018","journal-title":"Generating natural adversarial examples"},{"key":"ref8","first-page":"355","article-title":"Attacks against process control systems: Risk assessment, detection, and response","author":"c\u00e1rdenas","year":"2011","journal-title":"Proc ACM Symp Inf Comput Commun Security"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/MPRV.2017.3971131"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30508-6_54"},{"key":"ref45","author":"sch\u00f6nherr","year":"2018","journal-title":"Adversarial attacks against automatic speech recognition systems via psychoacoustic hiding"},{"key":"ref48","author":"taori","year":"2018","journal-title":"Targeted Adversarial Examples for Black Box Audio Systems"},{"key":"ref47","author":"szurley","year":"2019","journal-title":"Perceptual based adversarial audio attacks"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2016.2633287"},{"key":"ref44","author":"samanta","year":"2017","journal-title":"Towards crafting text adversarial samples"},{"key":"ref43","author":"rosenberg","year":"2019","journal-title":"Defense methods against adversarial examples for recurrent neural networks"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488907\/9115800\/09006862.pdf?arnumber=9006862","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,27]],"date-time":"2022-04-27T17:25:47Z","timestamp":1651080347000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9006862\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6]]},"references-count":70,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2020.2975654","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,6]]}}}