{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T08:42:44Z","timestamp":1780044164672,"version":"3.53.1"},"publisher-location":"New York, NY, USA","reference-count":50,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,5,24]],"date-time":"2021-05-24T00:00:00Z","timestamp":1621814400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"US National Science Foundation (NSF)","award":["EEC-1041877"],"award-info":[{"award-number":["EEC-1041877"]}]},{"name":"US National Science Foundation (NSF)","award":["CNS-2038922"],"award-info":[{"award-number":["CNS-2038922"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,5,24]]},"DOI":"10.1145\/3433210.3437513","type":"proceedings-article","created":{"date-parts":[[2021,6,4]],"date-time":"2021-06-04T15:26:39Z","timestamp":1622820399000},"page":"52-66","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":46,"title":["ConAML: Constrained Adversarial Machine Learning for Cyber-Physical Systems"],"prefix":"10.1145","author":[{"given":"Jiangnan","family":"Li","sequence":"first","affiliation":[{"name":"University of Tennessee, Knoxville, Knoxville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yingyuan","family":"Yang","sequence":"additional","affiliation":[{"name":"University of Illinois Springfield, Springfield, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinyuan Stella","family":"Sun","sequence":"additional","affiliation":[{"name":"University of Tennessee, Knoxville, Knoxville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kevin","family":"Tomsovic","sequence":"additional","affiliation":[{"name":"University of Tennessee, Knoxville, Knoxville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hairong","family":"Qi","sequence":"additional","affiliation":[{"name":"University of Tennessee, Knoxville, Knoxville, TN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274748"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAS.1979.319407"},{"key":"e_1_3_2_1_3_1","first-page":"1","volume-title":"2018 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT)","author":"Ayad Abdelrahman","year":"2018","unstructured":"Abdelrahman Ayad , Hany E.Z. Farag , Amr Youssef , and Ehab F . El-Saadany. Detection of false data injection attacks in smart grids using recurrent neural networks . In 2018 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT) , pages 1 -- 5 . IEEE, 2018 . Abdelrahman Ayad, Hany E.Z. Farag, Amr Youssef, and Ehab F. El-Saadany. Detection of false data injection attacks in smart grids using recurrent neural networks. In 2018 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT), pages 1--5. IEEE, 2018."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","first-page":"1162","DOI":"10.1109\/GLOCOMW.2011.6162362","volume-title":"2011 IEEE GLOBECOM Workshops (GC Wkshps)","author":"Bi Suzhi","year":"2011","unstructured":"Suzhi Bi and Ying Jun Zhang . Defending mechanisms against false-data injection attacks in the power system state estimation . In 2011 IEEE GLOBECOM Workshops (GC Wkshps) , pages 1162 -- 1167 . IEEE, 2011 . Suzhi Bi and Ying Jun Zhang. Defending mechanisms against false-data injection attacks in the power system state estimation. In 2011 IEEE GLOBECOM Workshops (GC Wkshps), pages 1162--1167. IEEE, 2011."},{"key":"e_1_3_2_1_5_1","first-page":"513","volume-title":"25th $$USENIX$$ Security Symposium ($$USENIX$$ Security 16)","author":"Carlini Nicholas","year":"2016","unstructured":"Nicholas Carlini , Pratyush Mishra , Tavish Vaidya , Yuankai Zhang , Micah Sherr , Clay Shields , David Wagner , and Wenchao Zhou . Hidden voice commands . In 25th $$USENIX$$ Security Symposium ($$USENIX$$ Security 16) , pages 513 -- 530 , 2016 . Nicholas Carlini, Pratyush Mishra, Tavish Vaidya, Yuankai Zhang, Micah Sherr, Clay Shields, David Wagner, and Wenchao Zhou. Hidden voice commands. In 25th $$USENIX$$ Security Symposium ($$USENIX$$ Security 16), pages 513--530, 2016."},{"key":"e_1_3_2_1_6_1","volume-title":"Adversarial attacks and defences: A survey. arXiv preprint arXiv:1810.00069","author":"Chakraborty Anirban","year":"2018","unstructured":"Anirban Chakraborty , Manaar Alam , Vishal Dey , Anupam Chattopadhyay , and Debdeep Mukhopadhyay . Adversarial attacks and defences: A survey. arXiv preprint arXiv:1810.00069 , 2018 . Anirban Chakraborty, Manaar Alam, Vishal Dey, Anupam Chattopadhyay, and Debdeep Mukhopadhyay. Adversarial attacks and defences: A survey. arXiv preprint arXiv:1810.00069, 2018."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00016"},{"key":"e_1_3_2_1_8_1","volume-title":"G\u00e9 rard Ben Arous, and Yann LeCun. The loss surface of multilayer networks. CoRR, abs\/1412.0233","author":"Choromanska Anna","year":"2014","unstructured":"Anna Choromanska , Mikael Henaff , Micha\u00eb l Mathieu , G\u00e9 rard Ben Arous, and Yann LeCun. The loss surface of multilayer networks. CoRR, abs\/1412.0233 , 2014 . Anna Choromanska, Mikael Henaff, Micha\u00eb l Mathieu, G\u00e9 rard Ben Arous, and Yann LeCun. The loss surface of multilayer networks. CoRR, abs\/1412.0233, 2014."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219841"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_1_11_1","volume-title":"Real-time evasion attacks with physical constraints on deep learning-based anomaly detectors in industrial control systems. arXiv preprint arXiv:1907.07487","author":"Erba Alessandro","year":"2019","unstructured":"Alessandro Erba , Riccardo Taormina , Stefano Galelli , Marcello Pogliani , Michele Carminati , Stefano Zanero , and Nils Ole Tippenhauer . Real-time evasion attacks with physical constraints on deep learning-based anomaly detectors in industrial control systems. arXiv preprint arXiv:1907.07487 , 2019 . Alessandro Erba, Riccardo Taormina, Stefano Galelli, Marcello Pogliani, Michele Carminati, Stefano Zanero, and Nils Ole Tippenhauer. Real-time evasion attacks with physical constraints on deep learning-based anomaly detectors in industrial control systems. arXiv preprint arXiv:1907.07487, 2019."},{"key":"e_1_3_2_1_12_1","volume-title":"A deep learning-based framework for conducting stealthy attacks in industrial control systems. arXiv preprint arXiv:1709.06397","author":"Feng Cheng","year":"2017","unstructured":"Cheng Feng , Tingting Li , Zhanxing Zhu , and Deeph Chana . A deep learning-based framework for conducting stealthy attacks in industrial control systems. arXiv preprint arXiv:1709.06397 , 2017 . Cheng Feng, Tingting Li, Zhanxing Zhu, and Deeph Chana. A deep learning-based framework for conducting stealthy attacks in industrial control systems. arXiv preprint arXiv:1709.06397, 2017."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23265"},{"key":"e_1_3_2_1_14_1","volume-title":"IEEE 39-Bus System. https:\/\/icseg.iti.illinois.edu\/ieee-39-bus-system\/. [Online","author":"Illinois Center for a Smarter Electric Grid.","year":"2020","unstructured":"Illinois Center for a Smarter Electric Grid. IEEE 39-Bus System. https:\/\/icseg.iti.illinois.edu\/ieee-39-bus-system\/. [Online ; accessed 16- Aug- 2020 ]. Illinois Center for a Smarter Electric Grid. IEEE 39-Bus System. https:\/\/icseg.iti.illinois.edu\/ieee-39-bus-system\/. [Online; accessed 16-Aug-2020]."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/524"},{"key":"e_1_3_2_1_16_1","first-page":"88","volume-title":"International Conference on Critical Information Infrastructures Security","author":"Goh Jonathan","year":"2016","unstructured":"Jonathan Goh , Sridhar Adepu , Khurum Nazir Junejo , and Aditya Mathur . A dataset to support research in the design of secure water treatment systems . In International Conference on Critical Information Infrastructures Security , pages 88 -- 99 . Springer , 2016 . Jonathan Goh, Sridhar Adepu, Khurum Nazir Junejo, and Aditya Mathur. A dataset to support research in the design of secure water treatment systems. In International Conference on Critical Information Infrastructures Security, pages 88--99. Springer, 2016."},{"key":"e_1_3_2_1_17_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 , 2014 . Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572, 2014."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6638947"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2017.2703842"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2017.149"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2018.2825243"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3264888.3264896"},{"key":"e_1_3_2_1_25_1","volume-title":"Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533 , 2016 . Alexey Kurakin, Ian Goodfellow, and Samy Bengio. Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533, 2016."},{"key":"e_1_3_2_1_26_1","volume-title":"Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 , 2016 . Alexey Kurakin, Ian Goodfellow, and Samy Bengio. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236, 2016."},{"key":"e_1_3_2_1_27_1","volume-title":"Secure Water Treatment (SWaT) Dataset. https:\/\/itrust.sutd.edu.sg\/itrust-labs_datasets","author":"Labs Trust","year":"2019","unstructured":"I Trust Labs . Secure Water Treatment (SWaT) Dataset. https:\/\/itrust.sutd.edu.sg\/itrust-labs_datasets , 2019 . [Online; accessed 15-08--2019]. ITrust Labs. Secure Water Treatment (SWaT) Dataset. https:\/\/itrust.sutd.edu.sg\/itrust-labs_datasets, 2019. [Online; accessed 15-08--2019]."},{"key":"e_1_3_2_1_28_1","volume-title":"Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271","author":"Li Jinfeng","year":"2018","unstructured":"Jinfeng Li , Shouling Ji , Tianyu Du , Bo Li , and Ting Wang . Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271 , 2018 . Jinfeng Li, Shouling Ji, Tianyu Du, Bo Li, and Ting Wang. Textbugger: Generating adversarial text against real-world applications. arXiv preprint arXiv:1812.05271, 2018."},{"key":"e_1_3_2_1_29_1","first-page":"1370","volume-title":"Proceedings of the 17th ACM SIGKDD, KDD '11","author":"Li Lei","year":"2011","unstructured":"Lei Li , Chieh-Jan Mike Liang , Jie Liu , Suman Nath , Andreas Terzis , and Christos Faloutsos . Thermocast : A cyber-physical forecasting model for datacenters . In Proceedings of the 17th ACM SIGKDD, KDD '11 , pages 1370 -- 1378 . ACM, 2011 . Lei Li, Chieh-Jan Mike Liang, Jie Liu, Suman Nath, Andreas Terzis, and Christos Faloutsos. Thermocast: A cyber-physical forecasting model for datacenters. In Proceedings of the 17th ACM SIGKDD, KDD '11, pages 1370--1378. ACM, 2011."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2016.2542061"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653666"},{"key":"e_1_3_2_1_32_1","volume-title":"No need to worry about adversarial examples in object detection in autonomous vehicles. arXiv preprint arXiv:1707.03501","author":"Lu Jiajun","year":"2017","unstructured":"Jiajun Lu , Hussein Sibai , Evan Fabry , and David Forsyth . No need to worry about adversarial examples in object detection in autonomous vehicles. arXiv preprint arXiv:1707.03501 , 2017 . Jiajun Lu, Hussein Sibai, Evan Fabry, and David Forsyth. No need to worry about adversarial examples in object detection in autonomous vehicles. arXiv preprint arXiv:1707.03501, 2017."},{"key":"e_1_3_2_1_33_1","volume-title":"State estimation in electric power systems: a generalized approach","author":"Monticelli Alcir","year":"2012","unstructured":"Alcir Monticelli . State estimation in electric power systems: a generalized approach . Springer Science & Business Media , 2012 . Alcir Monticelli. State estimation in electric power systems: a generalized approach. Springer Science & Business Media, 2012."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISGT.2019.8791598"},{"key":"e_1_3_2_1_37_1","volume-title":"Sanjeev R Kulkarni, and H Vincent Poor. Machine learning methods for attack detection in the smart grid","author":"Ozay Mete","year":"2015","unstructured":"Mete Ozay , Inaki Esnaola , Fatos Tunay Yarman Vural , Sanjeev R Kulkarni, and H Vincent Poor. Machine learning methods for attack detection in the smart grid . IEEE transactions on neural networks and learning systems, 27(8):1773--1786, 2015 . Mete Ozay, Inaki Esnaola, Fatos Tunay Yarman Vural, Sanjeev R Kulkarni, and H Vincent Poor. Machine learning methods for attack detection in the smart grid. IEEE transactions on neural networks and learning systems, 27(8):1773--1786, 2015."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.20"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2016.58"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_2_1_42_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 , 2013 . Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199, 2013."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"e_1_3_2_1_44_1","volume-title":"Detection of false data injection attacks using the autoencoder approach. arXiv preprint arXiv:2003.02229","author":"Wang Chenguang","year":"2020","unstructured":"Chenguang Wang , Simon Tindemans , Kaikai Pan , and Peter Palensky . Detection of false data injection attacks using the autoencoder approach. arXiv preprint arXiv:2003.02229 , 2020 . Chenguang Wang, Simon Tindemans, Kaikai Pan, and Peter Palensky. Detection of false data injection attacks using the autoencoder approach. arXiv preprint arXiv:2003.02229, 2020."},{"key":"e_1_3_2_1_45_1","volume-title":"Power generation, operation, and control","author":"Wood Allen J","year":"2013","unstructured":"Allen J Wood , Bruce F Wollenberg , and Gerald B Shebl\u00e9 . Power generation, operation, and control . John Wiley & Sons , 2013 . Allen J Wood, Bruce F Wollenberg, and Gerald B Shebl\u00e9. Power generation, operation, and control. John Wiley & Sons, 2013."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2016.7727361"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2686367"},{"key":"e_1_3_2_1_48_1","volume-title":"Adversarial examples: Attacks and defenses for deep learning","author":"Yuan Xiaoyong","year":"2019","unstructured":"Xiaoyong Yuan , Pan He , Qile Zhu , and Xiaolin Li . Adversarial examples: Attacks and defenses for deep learning . IEEE transactions on neural networks and learning systems, 2019 . Xiaoyong Yuan, Pan He, Qile Zhu, and Xiaolin Li. Adversarial examples: Attacks and defenses for deep learning. IEEE transactions on neural networks and learning systems, 2019."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2740070.2631434"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRS.2010.2051168"}],"event":{"name":"ASIA CCS '21: ACM Asia Conference on Computer and Communications Security","location":"Virtual Event Hong Kong","acronym":"ASIA CCS '21","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3433210.3437513","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3433210.3437513","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:11Z","timestamp":1750193291000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3433210.3437513"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,24]]},"references-count":50,"alternative-id":["10.1145\/3433210.3437513","10.1145\/3433210"],"URL":"https:\/\/doi.org\/10.1145\/3433210.3437513","relation":{},"subject":[],"published":{"date-parts":[[2021,5,24]]},"assertion":[{"value":"2021-06-04","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}