{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T03:46:56Z","timestamp":1772941616520,"version":"3.50.1"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202387"],"award-info":[{"award-number":["62202387"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE J. Select. Areas Commun."],"published-print":{"date-parts":[[2024,4]]},"DOI":"10.1109\/jsac.2023.3345379","type":"journal-article","created":{"date-parts":[[2023,12,21]],"date-time":"2023-12-21T19:48:55Z","timestamp":1703188135000},"page":"948-962","source":"Crossref","is-referenced-by-count":12,"title":["A Spatiotemporal Backdoor Attack Against Behavior-Oriented Decision Makers in Metaverse: From Perspective of Autonomous Driving"],"prefix":"10.1109","volume":"42","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0257-5081","authenticated-orcid":false,"given":"Yinbo","family":"Yu","sequence":"first","affiliation":[{"name":"National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, School of Cybersecurity, Northwestern Polytechnical University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4273-8866","authenticated-orcid":false,"given":"Jiajia","family":"Liu","sequence":"additional","affiliation":[{"name":"National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, School of Cybersecurity, Northwestern Polytechnical University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2503-2784","authenticated-orcid":false,"given":"Hongzhi","family":"Guo","sequence":"additional","affiliation":[{"name":"National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, School of Cybersecurity, Northwestern Polytechnical University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7780-5972","authenticated-orcid":false,"given":"Bomin","family":"Mao","sequence":"additional","affiliation":[{"name":"National Engineering Laboratory for Integrated Aero-Space-Ground-Ocean Big Data Application Technology, School of Cybersecurity, Northwestern Polytechnical University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8769-302X","authenticated-orcid":false,"given":"Nei","family":"Kato","sequence":"additional","affiliation":[{"name":"Graduate School of Information Sciences, Tohoku University, Sendai, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3221119"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3202047"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/MTS.2018.2826060"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3450614.3463293"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3411764.3445401"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3169347"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TFUZZ.2022.3190613"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.2022.3225250"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.23919\/JCIN.2022.9815195"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2022.3186294"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2022.3181308"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.23919\/JCC.2023.02.005"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3196842"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2019.2921444"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2021.3102580"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/VR.2018.8446529"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3050804"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2021.3054625"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.3024655"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3087237"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548171"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3114024"},{"key":"ref25","first-page":"1","article-title":"Spectral signatures in backdoor attacks","volume-title":"Proc. NeurIPS","volume":"31","author":"Tran"},{"key":"ref26","first-page":"1","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","volume-title":"Proc. Artif. Intell. Saf. Workshop (AAAI)","author":"Chen"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2022.105581"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM48099.2022.10000751"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICNP55882.2022.9940259"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2022.3213333"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2022.3148642"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218663"},{"key":"ref33","article-title":"Design of intentional backdoors in sequential models","author":"Yang","year":"2019","journal-title":"arXiv:1902.09972"},{"key":"ref34","first-page":"1","article-title":"Poisoning deep reinforcement learning agents with in-distribution triggers","volume-title":"Proc. ICLR Workshop","author":"Ashcraft"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/509"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330884"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2021.3061627"},{"key":"ref38","first-page":"29","article-title":"Deep recurrent Q-learning for partially observable MDPs","volume-title":"Proc. AAAI","author":"Hausknecht"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/IROS40897.2019.8968565"},{"key":"ref40","first-page":"1","article-title":"Social attention for autonomous decision-making in dense traffic","volume-title":"Proc. Mach. Learn. Auto. Driving Workshop (NeurIPS)","author":"Leurent"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796841"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/647"},{"key":"ref45","article-title":"PolicyCleanse: Backdoor detection and mitigation in reinforcement learning","author":"Guo","year":"2022","journal-title":"arXiv:2202.03609"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/IVS.2015.7225830"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ITSC.2001.948767"},{"key":"ref48","article-title":"Deep attention recurrent Q-network","author":"Sorokin","year":"2015","journal-title":"arXiv:1512.01693"},{"key":"ref49","first-page":"1","article-title":"Deep transformer Q-networks for partially observable reinforcement learning","volume-title":"Proc. Found. Models Decis. Making Workshop (NeurIPS)","author":"Esslinger"},{"key":"ref50","first-page":"16691","article-title":"Recurrent model-free RL can be a strong baseline for many POMDPs","volume-title":"Proc. ICML","author":"Ni"},{"key":"ref51","volume-title":"An Environment for Autonomous Driving Decision-Making","author":"Leurent","year":"2018"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.3042981"},{"key":"ref53","volume-title":"Adversarial Robustness Toolbox (ART) Python Library for Machine Learning Security Evasion, Poisoning, Extraction, Inference","year":"2018"},{"key":"ref54","first-page":"621","article-title":"Towards playing full MOBA games with deep reinforcement learning","volume-title":"Proc. NeurIPS","volume":"33","author":"Ye"}],"container-title":["IEEE Journal on Selected Areas in Communications"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/49\/10474539\/10368076.pdf?arnumber=10368076","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,26]],"date-time":"2024-03-26T13:03:05Z","timestamp":1711458185000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10368076\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4]]},"references-count":54,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/jsac.2023.3345379","relation":{},"ISSN":["0733-8716","1558-0008"],"issn-type":[{"value":"0733-8716","type":"print"},{"value":"1558-0008","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4]]}}}