{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T16:40:19Z","timestamp":1783183219327,"version":"3.54.6"},"reference-count":44,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3620528","type":"journal-article","created":{"date-parts":[[2025,10,13]],"date-time":"2025-10-13T17:43:30Z","timestamp":1760377410000},"page":"1736-1750","source":"Crossref","is-referenced-by-count":1,"title":["Action-Perturbation Backdoor Attacks on Partially Observable Multiagent Systems"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0257-1240","authenticated-orcid":false,"given":"Shuo","family":"Chen","sequence":"first","affiliation":[{"name":"State Key Laboratory of General Artificial Intelligence, BIGAI, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2286-397X","authenticated-orcid":false,"given":"Yue","family":"Qiu","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8996-7581","authenticated-orcid":false,"given":"Jie","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218663"},{"key":"ref2","article-title":"Design of intentional backdoors in sequential models","author":"Yang","year":"2019"},{"key":"ref3","first-page":"1","article-title":"Poisoning deep reinforcement learning agents with in-distribution triggers","volume-title":"Proc. ICLR 2021 Workshop Secur. Saf. Mach. Learn. Syst.","author":"Ashcraft"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM48099.2022.10000751"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3207429"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/509"},{"key":"ref7","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref8","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref10","first-page":"554","article-title":"BadNL: Backdoor attacks against NLP models","volume-title":"Proc. ICML 2021 Workshop Adversarial Mach. Learn.","author":"Chen"},{"key":"ref11","article-title":"BAAAN: Backdoor attacks against autoencoder and GAN-based machine learning models","author":"Salem","year":"2020"},{"key":"ref12","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref13","first-page":"1","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref14","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang"},{"key":"ref15","article-title":"Cooperative backdoor attack in decentralized reinforcement learning with theoretical guarantee","author":"Gao","year":"2024"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/s11063-024-11625-w"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i10.29052"},{"key":"ref18","first-page":"111994","article-title":"SleeperNets: Universal backdoor poisoning attacks against reinforcement learning agents","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Rathbun"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103005"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3114024"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM52923.2024.10901370"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28929-8"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TNN.1998.712192"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1613\/jair.2447"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/s10458-019-09421-1"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.65109\/JSRC7365"},{"key":"ref27","first-page":"4295","article-title":"QMIX: Monotonic value function factorisation for deep multi-agent reinforcement learning","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Rashid"},{"key":"ref28","first-page":"5887","article-title":"QTRAN: Learning to factorize with transformation for cooperative multi-agent reinforcement learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Son"},{"key":"ref29","first-page":"10199","article-title":"Weighted QMIX: Expanding monotonic value function factorisation for deep multi-agent reinforcement learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Rashid"},{"key":"ref30","first-page":"980","article-title":"Deep coordination graphs","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"B\u00f6hmer"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1038\/nature14236"},{"key":"ref32","first-page":"1","article-title":"Exploration by random network distillation","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Burda"},{"key":"ref33","first-page":"3839","article-title":"Lipschitz regularity of deep neural networks: Analysis and efficient estimation","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Virmaux"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.65109\/LVZZ5205"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11492"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5878"},{"key":"ref37","article-title":"Starcraft II: A new challenge for reinforcement learning","author":"Vinyals","year":"2017"},{"key":"ref38","first-page":"50094","article-title":"Neural MMO 2.0: A massively multi-task addition to massively multi-agent learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Suarez"},{"key":"ref39","volume-title":"PyTorch: An Imperative Style, High-Performance Deep Learning Library","author":"Paszke","year":"2019"},{"key":"ref40","first-page":"14704","article-title":"Provable defense against backdoor policies in reinforcement learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Bharti"},{"key":"ref41","first-page":"1","article-title":"Belief-enriched pessimistic Q-learning against adversarial state perturbations","volume-title":"Proc. 12th Int. Conf. Learn. Representations","author":"Sun"},{"key":"ref42","first-page":"40786","article-title":"BIRD: Generalizable backdoor detection and removal for deep reinforcement learning","volume-title":"Proc. 37th Conf. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00433"},{"key":"ref44","article-title":"Proximal policy optimization algorithms","author":"Schulman","year":"2017"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11202248.pdf?arnumber=11202248","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T05:27:02Z","timestamp":1768541222000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11202248\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":44,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3620528","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}