{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T10:18:55Z","timestamp":1781518735651,"version":"3.54.1"},"reference-count":41,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T00:00:00Z","timestamp":1730419200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T00:00:00Z","timestamp":1730419200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T00:00:00Z","timestamp":1730419200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,11,1]],"date-time":"2024-11-01T00:00:00Z","timestamp":1730419200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["CNS-2333980"],"award-info":[{"award-number":["CNS-2333980"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."],"published-print":{"date-parts":[[2024,11]]},"DOI":"10.1109\/tcad.2024.3447468","type":"journal-article","created":{"date-parts":[[2024,11,6]],"date-time":"2024-11-06T18:40:50Z","timestamp":1730918450000},"page":"4093-4104","source":"Crossref","is-referenced-by-count":4,"title":["Backdoor Attacks on Safe Reinforcement Learning-Enabled Cyber\u2013Physical Systems"],"prefix":"10.1109","volume":"43","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-9137-2359","authenticated-orcid":false,"given":"Shixiong","family":"Jiang","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, University of Notre Dame, Notre Dame, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3532-9506","authenticated-orcid":false,"given":"Mengyu","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of Notre Dame, Notre Dame, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2174-1620","authenticated-orcid":false,"given":"Fanxin","family":"Kong","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, University of Notre Dame, Notre Dame, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jmsy.2020.11.017"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.psep.2023.03.012"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS59052.2023.00017"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/RTAS52030.2021.00027"},{"key":"ref5","first-page":"9797","article-title":"Safe reinforcement learning in constrained Markov decision processes","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wachi"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3576841.3585919"},{"key":"ref7","article-title":"State-wise safe reinforcement learning with pixel observations","author":"Zhan","year":"2023","journal-title":"arXiv:2311.02227"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/840"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/IROS40897.2019.8968254"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3111139"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref13","first-page":"1","article-title":"TrojDRL: Trojan attacks on deep reinforcement learning agents","volume-title":"Proc. 57th ACM\/IEEE Design Autom. Conf. (DAC)","author":"Panagiota"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/509"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3207429"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i12.26764"},{"key":"ref17","first-page":"2228","article-title":"Learning from demonstrations using signal temporal logic","volume-title":"Proc. Conf. Robot Learn.","author":"Puranic"},{"key":"ref18","article-title":"Model-based reinforcement learning from signal temporal logic specifications","author":"Kapoor","year":"2020","journal-title":"arXiv:2011.04950"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30206-3_12"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15297-9_9"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CDC45484.2021.9683444"},{"key":"ref22","article-title":"Fulfilling formal specifications ASAP by model-free reinforcement learning","author":"Liu","year":"2023","journal-title":"arXiv:2304.12508"},{"key":"ref23","first-page":"308","article-title":"Tractable reinforcement learning of signal temporal logic objectives","volume-title":"Proc. Learn. Dyn. Control","author":"Venkataraman"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.23919\/ACC.2019.8814487"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.23919\/ACC45564.2020.9147692"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62416-7_19"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32430-8_14"},{"key":"ref28","first-page":"7974","article-title":"Policy teaching via environment poisoning: Training-time adversarial attacks against reinforcement learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rakhsha"},{"key":"ref29","first-page":"12400","article-title":"Provably efficient black-box action poisoning attacks against reinforcement learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Liu"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2017\/525"},{"key":"ref31","article-title":"BAFFLE: Backdoor attack in offline reinforcement learning","author":"Gong","year":"2022","journal-title":"arXiv:2210.04688"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.automatica.2010.02.018"},{"key":"ref33","volume-title":"Benchmarking safe exploration in deep reinforcement learning","author":"Ray","year":"2019"},{"key":"ref34","first-page":"1","article-title":"Safety Gymnasium: A unified safe reinforcement learning benchmark","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Ji"},{"key":"ref35","article-title":"Proximal policy optimization algorithms","author":"Schulman","year":"2017","journal-title":"arXiv:1707.06347"},{"key":"ref36","article-title":"Who is the strongest enemy? Towards optimal and efficient evasion attacks in deep RL","author":"Sun","year":"2021","journal-title":"arXiv:2106.05087"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS59052.2023.00016"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3489517.3530555"},{"key":"ref39","article-title":"Dealing with sparse rewards in reinforcement learning","author":"Hare","year":"2019","journal-title":"arXiv:1910.09281"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS49844.2020.00028"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3477010"}],"container-title":["IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/43\/10745760\/10745839-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/43\/10745760\/10745839.pdf?arnumber=10745839","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,27]],"date-time":"2024-11-27T13:58:10Z","timestamp":1732715890000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10745839\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11]]},"references-count":41,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tcad.2024.3447468","relation":{},"ISSN":["0278-0070","1937-4151"],"issn-type":[{"value":"0278-0070","type":"print"},{"value":"1937-4151","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11]]}}}