{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T21:53:08Z","timestamp":1774043588211,"version":"3.50.1"},"reference-count":66,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Japan Society for the Promotion of Science (JSPS) Grants-in-Aid for Scientific Research","award":["JP23K03756"],"award-info":[{"award-number":["JP23K03756"]}]},{"DOI":"10.13039\/100018237","name":"Asian Office of Aerospace Research and Development","doi-asserted-by":"publisher","award":["FA2386-22-1-4042"],"award-info":[{"award-number":["FA2386-22-1-4042"]}],"id":[{"id":"10.13039\/100018237","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Automat. Sci. Eng."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tase.2025.3589764","type":"journal-article","created":{"date-parts":[[2025,7,16]],"date-time":"2025-07-16T17:41:04Z","timestamp":1752687664000},"page":"18629-18645","source":"Crossref","is-referenced-by-count":1,"title":["Shortcut-Enhanced Multimodal Backdoor Attack in Vision-Guided Robot Grasping"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-0404-3825","authenticated-orcid":false,"given":"Chenghao","family":"Li","sequence":"first","affiliation":[{"name":"School of Information Science, Japan Advanced Institute of Science and Technology, Ishikawa, Japan"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9948-7960","authenticated-orcid":false,"given":"Ziyan","family":"Gao","sequence":"additional","affiliation":[{"name":"School of Information Science, Japan Advanced Institute of Science and Technology, Ishikawa, Japan"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5736-0769","authenticated-orcid":false,"given":"Nak","family":"Young Chong","sequence":"additional","affiliation":[{"name":"School of Information Science, Japan Advanced Institute of Science and Technology, Ishikawa, Japan"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1561\/1100000005"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TASE.2022.3214196"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1177\/0278364919859066"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TASE.2021.3139610"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TASE.2023.3272664"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2018.8593950"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TIM.2024.3413164"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2022.3145064"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/JSEN.2023.3321742"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref11","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS60354.2023.00018"},{"key":"ref13","article-title":"Robust backdoor attacks on object detection in real world","author":"Qian","year":"2023","journal-title":"arXiv:2309.08953"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10095980"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/s12369-015-0305-z"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2020.3026970"},{"key":"ref17","article-title":"Poisoning attacks against support vector machines","author":"Biggio","year":"2012","journal-title":"arXiv:1206.6389"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref20","first-page":"18944","article-title":"Backdoor attack with imperceptible input and latent modification","volume-title":"Proc. Conf. Neural Informat. Process. Syst.","volume":"34","author":"Doan"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP42928.2021.9506313"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01478"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16201"},{"key":"ref26","article-title":"WaNet\u2013imperceptible warping-based backdoor attack","author":"Nguyen","year":"2021","journal-title":"arXiv:2102.10369"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670361"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2024\/185"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2016.7759657"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICICML57342.2022.10009877"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00203"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1177\/1687814016668077"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2017.8202237"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2018.2852777"},{"key":"ref36","first-page":"91","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","volume-title":"Proc. Int. Conf. Adv. Neural Inf. Process. Syst.","volume":"28","author":"Ren"},{"key":"ref37","first-page":"10","article-title":"EnsembleNet: Improving grasp detection using an ensemble of convolutional neural networks","volume-title":"Proc. Brit. Mach. Vis. Conf.","author":"Asif"},{"key":"ref38","article-title":"Data-efficient learning for sim-to-real robotic grasping using deep point cloud prediction networks","author":"Yan","year":"2019","journal-title":"arXiv:1906.08989"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/IROS45743.2020.9340777"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-020-00257-z"},{"key":"ref41","first-page":"2933","article-title":"On lazy training in differentiable programming","volume-title":"Proc. Conf. Neural Informat. Process. Syst.","author":"Chizat"},{"key":"ref42","article-title":"A finite sample analysis of the benign overfitting phenomenon for ridge function estimation","author":"Caron","year":"2020","journal-title":"arXiv:2007.12882"},{"key":"ref43","first-page":"4148","article-title":"The marginal value of adaptive gradient methods in machine learning","volume-title":"Proc. Conf. Neural Informat. Process. Syst.","author":"Wilson"},{"key":"ref44","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Ilyas"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01501"},{"key":"ref46","first-page":"9448","article-title":"ObjectNet: A large-scale bias-controlled dataset for pushing the limits of object recognition models","volume-title":"Proc. Conf. Neural Informat. Process. Syst.","volume":"32","author":"Barbu"},{"key":"ref47","article-title":"One-pixel shortcut: On the learning preference of deep neural networks","author":"Wu","year":"2022","journal-title":"arXiv:2205.12141"},{"key":"ref48","first-page":"1","article-title":"Unlearnable examples: Making personal data unexploitable","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Huang"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2013.471"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1038\/323533a0"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-35289-8_3"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1117\/1.JEI.31.1.013023"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1177\/0278364914549607"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA48506.2021.9561398"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1177\/0278364907087172"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/ROBOT.2010.5509508"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2011.5980145"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2019.8793917"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3292075"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3181039"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/UR61395.2024.10597484"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/TRO.2024.3353484"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2025.3544083"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359820"}],"container-title":["IEEE Transactions on Automation Science and Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8856\/10839176\/11082295.pdf?arnumber=11082295","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T20:02:07Z","timestamp":1774036927000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11082295\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":66,"URL":"https:\/\/doi.org\/10.1109\/tase.2025.3589764","relation":{},"ISSN":["1545-5955","1558-3783"],"issn-type":[{"value":"1545-5955","type":"print"},{"value":"1558-3783","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}