{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T13:57:24Z","timestamp":1772632644968,"version":"3.50.1"},"reference-count":37,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T00:00:00Z","timestamp":1762905600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T00:00:00Z","timestamp":1762905600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,11,12]]},"DOI":"10.1109\/tps-isa67132.2025.00017","type":"proceedings-article","created":{"date-parts":[[2026,3,3]],"date-time":"2026-03-03T20:50:15Z","timestamp":1772571015000},"page":"66-75","source":"Crossref","is-referenced-by-count":0,"title":["Robust Physically Realizable Backdoor Attack"],"prefix":"10.1109","author":[{"given":"Md Jahirul","family":"Islam","sequence":"first","affiliation":[{"name":"Kennesaw State University,Department of Computer Science,Marietta,GA,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kazi Aminul","family":"Islam","sequence":"additional","affiliation":[{"name":"Kennesaw State University,Department of Computer Science,Marietta,GA,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2987435"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3045078"},{"key":"ref3","doi-asserted-by":"crossref","first-page":"103297","DOI":"10.1016\/j.cose.2023.103297","article-title":"A comprehensive review on deep learning algorithms: Security and privacy issues","volume":"131","author":"Tayyab","year":"2023","journal-title":"Computers Security"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2019.2962338"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.iatssr.2019.11.008"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/6184756"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3309814"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.3390\/rs16020327"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.isprsjprs.2019.02.017"},{"key":"ref10","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009","journal-title":"Tech. Rep."},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1869790.1869829"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/tgrs.2017.2685945"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"ref14","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv preprint"},{"key":"ref15","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv preprint"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.07.157"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref19","article-title":"Backdoor attack with imperceptible input and latent modification","volume-title":"Proceedings of the 38th International Conference on Machine Learning (ICML)","author":"Doan","year":"2021"},{"key":"ref20","article-title":"Triggerless backdoor attacks on deep neural networks","volume-title":"Proceedings of the 39th International Conference on Machine Learning (ICML)","author":"Xiang","year":"2022"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464809"},{"key":"ref22","article-title":"Adversarial patch","author":"Brown","year":"2017","journal-title":"arXiv preprint"},{"key":"ref23","article-title":"On physical adversarial patches for object detection","author":"Lee","year":"2019","journal-title":"arXiv preprint"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2022.01.135"},{"key":"ref25","first-page":"661","article-title":"{TPatch}: A triggered physical adversarial patch","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Zhu","year":"2023"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-023-00145-0"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TGRS.2022.3225306"},{"key":"ref28","article-title":"Physical backdoor attack on object detectors","volume-title":"International Conference on Learning Representations (ICLR)","author":"Zeng","year":"2023"},{"key":"ref29","first-page":"11357","article-title":"Adversarial textures for real-world recognition systems","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Li","year":"2019"},{"key":"ref30","first-page":"15016","article-title":"Physical adversarial patch attack on monocular depth estimation","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Cheng","year":"2021"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref32","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv preprint"},{"key":"ref33","article-title":"Practical black-box attacks against deep learning systems using adversarial examples. arxiv 2016","author":"Papernot","journal-title":"arXiv preprint"},{"key":"ref34","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"International conference on machine learning","author":"Athalye","year":"2018"},{"key":"ref35","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","volume-title":"International conference on machine learning","author":"Ioffe","year":"2015"},{"key":"ref36","first-page":"807","article-title":"Rectified linear units improve restricted boltzmann machines","volume-title":"Proceedings of the 27th international conference on machine learning (ICML-10)","author":"Nair","year":"2010"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"}],"event":{"name":"2025 IEEE 7th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)","location":"Pittsburgh, PA, USA","start":{"date-parts":[[2025,11,12]]},"end":{"date-parts":[[2025,11,14]]}},"container-title":["2025 IEEE 7th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11410113\/11410157\/11410297.pdf?arnumber=11410297","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T07:05:29Z","timestamp":1772607929000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11410297\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,12]]},"references-count":37,"URL":"https:\/\/doi.org\/10.1109\/tps-isa67132.2025.00017","relation":{},"subject":[],"published":{"date-parts":[[2025,11,12]]}}}