{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T11:51:45Z","timestamp":1782906705021,"version":"3.54.5"},"reference-count":47,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372218"],"award-info":[{"award-number":["62372218"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24A6009"],"award-info":[{"award-number":["U24A6009"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shenzhen Science and Technology Program","award":["SGDX20201103095408029"],"award-info":[{"award-number":["SGDX20201103095408029"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3616288","type":"journal-article","created":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T17:42:02Z","timestamp":1759340522000},"page":"1373-1389","source":"Crossref","is-referenced-by-count":1,"title":["Toward a Secure Framework for Regulating Artificial Intelligence Systems"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9097-2484","authenticated-orcid":false,"given":"Haroon","family":"Elahi","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Chalmers University of Technology, G&#x00F6;teborg, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-4481-9395","authenticated-orcid":false,"given":"Nian","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Southern University of Science and Technology, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-8402-8583","authenticated-orcid":false,"given":"Jiatong","family":"Chen","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Southern University of Science and Technology, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3365-2526","authenticated-orcid":false,"given":"Fengwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Southern University of Science and Technology, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-FoSE59343.2023.00010"},{"key":"ref2","article-title":"Testing system intelligence","author":"Sifakis","year":"2023"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-022-15245-z"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3117075"},{"key":"ref6","article-title":"Subject vehicle crashes with in-road or roadside first responders","author":"Steven Posada","year":"2022"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/s13347-022-00543-1"},{"key":"ref9","article-title":"Frontier AI regulation: Managing emerging risks to public safety","author":"Anderljung","year":"2023"},{"issue":"815","key":"ref12","article-title":"UK Government \/ The Secretary of State for Science, Innovation and Technology, A Pro-innovative Approach to AI Regulation, Department for Science, Innovation & Technology, Ed HH Associates Ltd.","year":"2023"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467177"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-Companion52605.2021.00041"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539145"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3555776.3577771"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP.2019.00042"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-016-9505-7"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2962027"},{"key":"ref21","article-title":"Cyber security risks to artificial intelligence","year":"2024"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3533378"},{"key":"ref24","article-title":"FTC sues amazon for illegally maintaining monopoly power","author":"Graham","year":"2023"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/s11023-021-09577-4"},{"key":"ref28","first-page":"497","article-title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Hong"},{"key":"ref29","article-title":"Shifting the balance of cybersecurity risk: Principles and approaches for secure by design software","year":"2023"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1093\/mind\/LIX.236.433"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238187"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-FoSE59343.2023.00009"},{"key":"ref34","first-page":"1","article-title":"Towards more practical threat models in artificial intelligence security","volume-title":"Proc. 33rd USENIX Secur. Symp.","author":"Grosse"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24188"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2015.7357468"},{"key":"ref40","first-page":"6025","article-title":"Detecting multi-step IAM attacks in AWS environments via model checking","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Shevrin"},{"key":"ref41","article-title":"European Union Agency for Cybersecurity, ENISA Threat Landscape 2024: July 2023 to Jun. 2024, I. Lella, M. Theocharidou, E. Magonara, A. Malatras, R. S. Naydenov, C. Ciobanu, and G. Chatzichristos, Eds. Athens, Greece: European Union Agency for Cybersecurity (ENISA)","year":"2024"},{"key":"ref44","article-title":"A technical analysis of confidential computing","year":"2022"},{"key":"ref45","article-title":"Regulation (EU) 2024\/1183 of the EUROPEAN PARLIAMENT and of THE COUNCIL","year":"2024"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/18.61115"},{"key":"ref47","first-page":"256","article-title":"Real-time AI systems: A definition and an architecture","volume-title":"Proc. 11th Int. Joint Conf. Artif. Intell.","author":"Dodhiawala"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-67281-2_2"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464816"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2014.2372785"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/SEED51797.2021.00025"},{"key":"ref55","article-title":"Protecting VM register state with SEV-ES","author":"Kaplan","year":"2017"},{"key":"ref57","article-title":"Cloc: V1.92","author":"Danial","year":"2021"},{"key":"ref60","article-title":"Labeled faces in the wild: A database for studying face recognition in unconstrained environments","author":"Huang","year":"2007"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3301268"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2015.2505301"},{"key":"ref64","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3015432"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.8319"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1016\/j.amepre.2013.03.010"},{"key":"ref68","first-page":"7393","article-title":"Differential testing of cross deep learning framework APIs: Revealing inconsistencies and vulnerabilities","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Deng"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11185308.pdf?arnumber=11185308","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T23:23:32Z","timestamp":1768951412000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11185308\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":47,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3616288","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}