{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T14:32:49Z","timestamp":1784644369079,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:00:00Z","timestamp":1665360000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Nanyang Technological University (NTU)-DESAY SV Research Program","award":["Grant 2018-0980"],"award-info":[{"award-number":["Grant 2018-0980"]}]},{"name":"Singapore National Research Foundation under its National Cybersecurity R&D Programme","award":["NCR Award NRF2018 NCR-NCR009-0001"],"award-info":[{"award-number":["NCR Award NRF2018 NCR-NCR009-0001"]}]},{"name":"Singapore Ministry of Education (MOE) Academic Research Fund (AcRF) Tier 1","award":["Grant RG108\/19 (S)"],"award-info":[{"award-number":["Grant RG108\/19 (S)"]}]},{"name":"Singapore MOE AcRF Tier 2","award":["Grant MOE-T2EP20120-0004"],"award-info":[{"award-number":["Grant MOE-T2EP20120-0004"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,10,10]]},"DOI":"10.1145\/3503161.3548171","type":"proceedings-article","created":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T15:43:12Z","timestamp":1665416592000},"page":"2957-2968","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":47,"title":["Physical Backdoor Attacks to Lane Detection Systems in Autonomous Driving"],"prefix":"10.1145","author":[{"given":"Xingshuo","family":"Han","sequence":"first","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guowen","family":"Xu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuan","family":"Zhou","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuehuan","family":"Yang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiwei","family":"Li","sequence":"additional","affiliation":[{"name":"Shannon.AI, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tianwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,10,10]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"2021. Tusimple Challenge. https:\/\/paperswithcode.com\/sota\/lane-detection-ontusimple.  2021. Tusimple Challenge. https:\/\/paperswithcode.com\/sota\/lane-detection-ontusimple."},{"key":"e_1_3_2_2_2_1","volume-title":"Apollo Auto: An open autonomous driving platform. https:\/\/github.com\/ApolloAuto\/apollo\/.","author":"Apollo Baidu","year":"2021","unstructured":"Baidu Apollo . 2021 . Apollo Auto: An open autonomous driving platform. https:\/\/github.com\/ApolloAuto\/apollo\/. Baidu Apollo. 2021. Apollo Auto: An open autonomous driving platform. https:\/\/github.com\/ApolloAuto\/apollo\/."},{"key":"e_1_3_2_2_3_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Bagdasaryan Eugene","year":"2021","unstructured":"Eugene Bagdasaryan and Vitaly Shmatikov . 2021 . Blind backdoors in deep learning models . In 30th USENIX Security Symposium (USENIX Security 21) . 1505--1521. Eugene Bagdasaryan and Vitaly Shmatikov. 2021. Blind backdoors in deep learning models. In 30th USENIX Security Symposium (USENIX Security 21). 1505--1521."},{"key":"e_1_3_2_2_4_1","volume-title":"The OpenCV Library. Dr. Dobb's Journal of Software Tools","author":"Bradski G.","year":"2000","unstructured":"G. Bradski . 2000. The OpenCV Library. Dr. Dobb's Journal of Software Tools ( 2000 ). G. Bradski. 2000. The OpenCV Library. Dr. Dobb's Journal of Software Tools (2000)."},{"key":"e_1_3_2_2_5_1","volume-title":"International Conference on Learning Representation (ICLR).","author":"Chen Kangjie","year":"2022","unstructured":"Kangjie Chen , Yuxian Meng , Xiaofei Sun , Shangwei Guo , Tianwei Zhang , Jiwei Li , and Chun Fan . 2022 . BadPre: Task-agnostic backdoor attacks to pre-trained nlp foundation models . In International Conference on Learning Representation (ICLR). Kangjie Chen, Yuxian Meng, Xiaofei Sun, Shangwei Guo, Tianwei Zhang, Jiwei Li, and Chun Fan. 2022. BadPre: Task-agnostic backdoor attacks to pre-trained nlp foundation models. In International Conference on Learning Representation (ICLR)."},{"key":"e_1_3_2_2_6_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen , Chang Liu , Bo Li , Kimberly Lu , and Dawn Song . 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 ( 2017 ). Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_2_7_1","unstructured":"Alex Clark. 2015. Pillow (PIL Fork) Documentation. https:\/\/buildmedia.readthedocs.org\/media\/pdf\/pillow\/latest\/pillow.pdf  Alex Clark. 2015. Pillow (PIL Fork) Documentation. https:\/\/buildmedia.readthedocs.org\/media\/pdf\/pillow\/latest\/pillow.pdf"},{"key":"e_1_3_2_2_8_1","unstructured":"comma.ai. 2021. OpenPilot: Open source driving agent. https:\/\/github.com\/commaai\/openpilot.  comma.ai. 2021. OpenPilot: Open source driving agent. https:\/\/github.com\/commaai\/openpilot."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3471621.3471867"},{"key":"e_1_3_2_2_10_1","volume-title":"Triggerless Backdoor Attack for NLP Tasks with Clean Labels. In Annual Conference of the North American Chapter of the Association for Computational Linguistics (NAACL).","author":"Gan Leilei","year":"2022","unstructured":"Leilei Gan , Jiwei Li , Tianwei Zhang , Xiaoya Li , Yuxian Meng , Fei Wu , Shangwei Guo , and Chun Fan . 2022 . Triggerless Backdoor Attack for NLP Tasks with Clean Labels. In Annual Conference of the North American Chapter of the Association for Computational Linguistics (NAACL). Leilei Gan, Jiwei Li, Tianwei Zhang, Xiaoya Li, Yuxian Meng, Fei Wu, Shangwei Guo, and Chun Fan. 2022. Triggerless Backdoor Attack for NLP Tasks with Clean Labels. In Annual Conference of the North American Chapter of the Association for Computational Linguistics (NAACL)."},{"key":"e_1_3_2_2_11_1","volume-title":"Annual Computer Security Applications Conference.","author":"Gao Yansong","year":"2019","unstructured":"Yansong Gao , Change Xu , Derui Wang , Shiping Chen , Damith C Ranasinghe , and Surya Nepal . 2019 . STRIP: A defence against trojan attacks on deep neural networks . In Annual Computer Security Applications Conference. Yansong Gao, Change Xu, Derui Wang, Shiping Chen, Damith C Ranasinghe, and Surya Nepal. 2019. STRIP: A defence against trojan attacks on deep neural networks. In Annual Computer Security Applications Conference."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475254"},{"key":"e_1_3_2_2_13_1","volume-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017. BadNets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 ( 2017 ). Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. BadNets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_2_15_1","volume-title":"Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA\/BDCloud\/SocialCom\/SustainCom)","author":"Han Xingshuo","unstructured":"Xingshuo Han , Kangjie Chen , Yuan Zhou , Meikang Qiu , Chun Fan , Yang Liu , and Tianwei Zhang . 2021. A Unified Anomaly Detection Methodology for Lane- Following of Autonomous Driving Systems. In 2021 IEEE Intl Conf on Parallel & Distributed Processing with Applications , Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA\/BDCloud\/SocialCom\/SustainCom) . IEEE , 836--844. Xingshuo Han, Kangjie Chen, Yuan Zhou, Meikang Qiu, Chun Fan, Yang Liu, and Tianwei Zhang. 2021. A Unified Anomaly Detection Methodology for Lane- Following of Autonomous Driving Systems. In 2021 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA\/BDCloud\/SocialCom\/SustainCom). IEEE, 836--844."},{"key":"e_1_3_2_2_16_1","volume-title":"ADS-Lead: Lifelong anomaly detection in autonomous driving systems","author":"Han Xingshuo","year":"2022","unstructured":"Xingshuo Han , Yuan Zhou , Kangjie Chen , Han Qiu , Meikang Qiu , Yang Liu , and Tianwei Zhang . 2022. ADS-Lead: Lifelong anomaly detection in autonomous driving systems . IEEE Transactions on Intelligent Transportation Systems ( 2022 ). Xingshuo Han, Yuan Zhou, Kangjie Chen, Han Qiu, Meikang Qiu, Yang Liu, and Tianwei Zhang. 2022. ADS-Lead: Lifelong anomaly detection in autonomous driving systems. IEEE Transactions on Intelligent Transportation Systems (2022)."},{"key":"e_1_3_2_2_17_1","volume-title":"Fast and accurate lane detection via graph structure and disentangled representation learning. Sensors 21, 14","author":"He Yulin","year":"2021","unstructured":"Yulin He , Wei Chen , Chen Li , Xin Luo , and Libo Huang . 2021. Fast and accurate lane detection via graph structure and disentangled representation learning. Sensors 21, 14 ( 2021 ). Yulin He, Wei Chen, Chen Li, Xin Luo, and Libo Huang. 2021. Fast and accurate lane detection via graph structure and disentangled representation learning. Sensors 21, 14 (2021)."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00110"},{"key":"e_1_3_2_2_19_1","unstructured":"IARPA. 2021. TrojAI: Trojns in artificial intelligence. https:\/\/www.iarpa.gov\/index.php\/research-programs\/trojai.  IARPA. 2021. TrojAI: Trojns in artificial intelligence. https:\/\/www.iarpa.gov\/index.php\/research-programs\/trojai."},{"key":"e_1_3_2_2_20_1","unstructured":"M14 Intelligence. 2020. Autonomous Vehicle Data Annotation Market Analysis. https:\/\/www.researchandmarkets.com\/reports\/4985697\/autonomous-vehicledata-annotation-market-analysis.  M14 Intelligence. 2020. Autonomous Vehicle Data Annotation Market Analysis. https:\/\/www.researchandmarkets.com\/reports\/4985697\/autonomous-vehicledata-annotation-market-analysis."},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3351088"},{"key":"e_1_3_2_2_22_1","volume-title":"Eigenlanes: Data-Driven Lane Descriptors for Structurally Diverse Lanes. arXiv preprint arXiv:2203.15302","author":"Jin Dongkwon","year":"2022","unstructured":"Dongkwon Jin , Wonhui Park , Seong-Gyun Jeong , Heeyeon Kwon , and Chang-Su Kim . 2022 . Eigenlanes: Data-Driven Lane Descriptors for Structurally Diverse Lanes. arXiv preprint arXiv:2203.15302 (2022). Dongkwon Jin, Wonhui Park, Seong-Gyun Jeong, Heeyeon Kwon, and Chang-Su Kim. 2022. Eigenlanes: Data-Driven Lane Descriptors for Structurally Diverse Lanes. arXiv preprint arXiv:2203.15302 (2022)."},{"key":"e_1_3_2_2_23_1","volume-title":"30th USENIX Security Symposium (USENIX Security","author":"Jing Pengfei","year":"2021","unstructured":"Pengfei Jing , Qiyi Tang , Yuefeng Du , Lei Xue , Xiapu Luo , Ting Wang , Sen Nie , and Shi Wu . 2021 . Too good to be safe: Tricking lane detection in autonomous driving with crafted perturbations . In 30th USENIX Security Symposium (USENIX Security 2021). 3237--3254. Pengfei Jing, Qiyi Tang, Yuefeng Du, Lei Xue, Xiapu Luo, Ting Wang, Sen Nie, and Shi Wu. 2021. Too good to be safe: Tricking lane detection in autonomous driving with crafted perturbations. In 30th USENIX Security Symposium (USENIX Security 2021). 3237--3254."},{"key":"e_1_3_2_2_24_1","volume-title":"Mohammad Azam Khan, and Jaegul Choo","author":"Jung Seokwoo","year":"2020","unstructured":"Seokwoo Jung , Sungha Choi , Mohammad Azam Khan, and Jaegul Choo . 2020 . Towards lightweight lane detection by optimizing spatial embedding. arXiv preprint arXiv:2008.08311 (2020). Seokwoo Jung, Sungha Choi, Mohammad Azam Khan, and Jaegul Choo. 2020. Towards lightweight lane detection by optimizing spatial embedding. arXiv preprint arXiv:2008.08311 (2020)."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218663"},{"key":"e_1_3_2_2_26_1","volume-title":"Lap- Pui Chau, and Alex C Kot","author":"Li Haoliang","year":"2020","unstructured":"Haoliang Li , Yufei Wang , Xiaofei Xie , Yang Liu , Shiqi Wang , Renjie Wan , Lap- Pui Chau, and Alex C Kot . 2020 . Light can hack your face! black-box backdoor attack on face recognition systems. arXiv preprint arXiv:2009.06996 (2020). Haoliang Li, Yufei Wang, Xiaofei Xie, Yang Liu, Shiqi Wang, Renjie Wan, Lap- Pui Chau, and Alex C Kot. 2020. Light can hack your face! black-box backdoor attack on face recognition systems. arXiv preprint arXiv:2009.06996 (2020)."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"e_1_3_2_2_28_1","volume-title":"Backdoor learning: A survey. arXiv preprint arXiv:2007.08745","author":"Li Yiming","year":"2020","unstructured":"Yiming Li , Baoyuan Wu , Yong Jiang , Zhifeng Li , and Shu-Tao Xia . 2020. Backdoor learning: A survey. arXiv preprint arXiv:2007.08745 ( 2020 ). Yiming Li, Baoyuan Wu, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2020. Backdoor learning: A survey. arXiv preprint arXiv:2007.08745 (2020)."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00375"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475290"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.12301"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58586-0_17"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453108"},{"key":"e_1_3_2_2_38_1","volume-title":"USENIX Security Symposium.","author":"Quiring Erwin","year":"2020","unstructured":"Erwin Quiring , David Klein , Daniel Arp , Martin Johns , and Konrad Rieck . 2020 . Adversarial preprocessing: Understanding and preventing image-scaling attacks in machine learning . In USENIX Security Symposium. Erwin Quiring, David Klein, Daniel Arp, Martin Johns, and Konrad Rieck. 2020. Adversarial preprocessing: Understanding and preventing image-scaling attacks in machine learning. In USENIX Security Symposium."},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00024"},{"key":"e_1_3_2_2_40_1","volume-title":"Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks. In IEEE International Conference on Image Processing (ICIP).","author":"Raj Ankita","year":"2021","unstructured":"Ankita Raj , Ambar Pal , and Chetan Arora . 2021 . Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks. In IEEE International Conference on Image Processing (ICIP). Ankita Raj, Ambar Pal, and Chetan Arora. 2021. Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks. In IEEE International Conference on Image Processing (ICIP)."},{"key":"e_1_3_2_2_41_1","unstructured":"Weston Robot. 2021. Accelerate Robot Adoption. https:\/\/www.westonrobot.com\/ground-UGV.  Weston Robot. 2021. Accelerate Robot Adoption. https:\/\/www.westonrobot.com\/ground-UGV."},{"key":"e_1_3_2_2_42_1","volume-title":"30th USENIX Security Symposium (USENIX Security","author":"Sato Takami","year":"2021","unstructured":"Takami Sato , Junjie Shen , Ningfei Wang , Yunhan Jia , Xue Lin , and Qi Alfred Chen . 2021 . Dirty road can attack: Security of deep learning based automated lane centering under physical-world attack . In 30th USENIX Security Symposium (USENIX Security 2021). 3309--3326. Takami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia, Xue Lin, and Qi Alfred Chen. 2021. Dirty road can attack: Security of deep learning based automated lane centering under physical-world attack. In 30th USENIX Security Symposium (USENIX Security 2021). 3309--3326."},{"key":"e_1_3_2_2_43_1","volume-title":"Poison frogs! targeted clean-label poisoning attacks on neural networks. arXiv preprint arXiv:1804.00792","author":"Shafahi Ali","year":"2018","unstructured":"Ali Shafahi , W Ronny Huang , Mahyar Najibi , Octavian Suciu , Christoph Studer , Tudor Dumitras , and Tom Goldstein . 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. arXiv preprint arXiv:1804.00792 ( 2018 ). Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein. 2018. Poison frogs! targeted clean-label poisoning attacks on neural networks. arXiv preprint arXiv:1804.00792 (2018)."},{"key":"e_1_3_2_2_44_1","volume-title":"Backdoor Pre-trained Models Can Transfer to All. arXiv preprint arXiv:2111.00197","author":"Shen Lujia","year":"2021","unstructured":"Lujia Shen , Shouling Ji , Xuhong Zhang , Jinfeng Li , Jing Chen , Jie Shi , Chengfang Fang , Jianwei Yin , and Ting Wang . 2021. Backdoor Pre-trained Models Can Transfer to All. arXiv preprint arXiv:2111.00197 ( 2021 ). Lujia Shen, Shouling Ji, Xuhong Zhang, Jinfeng Li, Jing Chen, Jie Shi, Chengfang Fang, Jianwei Yin, and Ting Wang. 2021. Backdoor Pre-trained Models Can Transfer to All. arXiv preprint arXiv:2111.00197 (2021)."},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2022.3157309"},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00036"},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412265"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/IV48863.2021.9575536"},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA48506.2021.9560890"},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678735"},{"key":"e_1_3_2_2_51_1","unstructured":"TuSimple. 2017. TuSimple Lane Detection Challenge. https:\/\/github.com\/TuSimple\/tusimple-benchmark\/tree\/master\/doc\/lane_detection.  TuSimple. 2017. TuSimple Lane Detection Challenge. https:\/\/github.com\/TuSimple\/tusimple-benchmark\/tree\/master\/doc\/lane_detection."},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_2_53_1","volume-title":"Backdoorl: Backdoor attack against competitive reinforcement learning. arXiv preprint arXiv:2105.00579","author":"Wang Lun","year":"2021","unstructured":"Lun Wang , Zaynah Javed , Xian Wu , Wenbo Guo , Xinyu Xing , and Dawn Song . 2021 . Backdoorl: Backdoor attack against competitive reinforcement learning. arXiv preprint arXiv:2105.00579 (2021). Lun Wang, Zaynah Javed, Xian Wu, Wenbo Guo, Xinyu Xing, and Dawn Song. 2021. Backdoorl: Backdoor attack against competitive reinforcement learning. arXiv preprint arXiv:2105.00579 (2021)."},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413544"},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"e_1_3_2_2_56_1","volume-title":"USENIX Security Symposium.","author":"Xiao Qixue","year":"2019","unstructured":"Qixue Xiao , Yufei Chen , Chao Shen , Yu Chen , and Kang Li . 2019 . Seeing is not believing: Camouflage attacks on image scaling algorithms . In USENIX Security Symposium. Qixue Xiao, Yufei Chen, Chao Shen, Yu Chen, and Kang Li. 2019. Seeing is not believing: Camouflage attacks on image scaling algorithms. In USENIX Security Symposium."},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2019.2929409"},{"key":"e_1_3_2_2_58_1","first-page":"1364","article-title":"Privacy-preserving federated deep learning with irregular users","volume":"19","author":"Xu Guowen","year":"2022","unstructured":"Guowen Xu , Hongwei Li , Yun Zhang , Shengmin Xu , Jianting Ning , and Robert Deng . 2022 . Privacy-preserving federated deep learning with irregular users . IEEE Transactions on Dependable and Secure Computing 19 , 2 (2022), 1364 -- 1381 . Guowen Xu, Hongwei Li, Yun Zhang, Shengmin Xu, Jianting Ning, and Robert Deng. 2022. Privacy-preserving federated deep learning with irregular users. IEEE Transactions on Dependable and Secure Computing 19, 2 (2022), 1364--1381.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_2_59_1","volume-title":"Model-Agnostic Defense for Lane Detection against Adversarial Attack. arXiv preprint arXiv:2103.00663","author":"Xu Henry","year":"2021","unstructured":"Henry Xu , An Ju , and David Wagner . 2021. Model-Agnostic Defense for Lane Detection against Adversarial Attack. arXiv preprint arXiv:2103.00663 ( 2021 ). Henry Xu, An Ju, and David Wagner. 2021. Model-Agnostic Defense for Lane Detection against Adversarial Attack. arXiv preprint arXiv:2103.00663 (2021)."},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413543"},{"key":"e_1_3_2_2_61_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2021.06.063"},{"key":"e_1_3_2_2_62_1","volume-title":"SoK: Rethinking Sensor Spoofing Attacks against Robotic Vehicles from a Systematic View. arXiv preprint arXiv:2205.04662","author":"Xu Yuan","year":"2022","unstructured":"Yuan Xu , Xingshuo Han , Gelei Deng , Guanlin Li , Yang Liu , Jiwei Li , and Tianwei Zhang . 2022. SoK: Rethinking Sensor Spoofing Attacks against Robotic Vehicles from a Systematic View. arXiv preprint arXiv:2205.04662 ( 2022 ). Yuan Xu, Xingshuo Han, Gelei Deng, Guanlin Li, Yang Liu, Jiwei Li, and Tianwei Zhang. 2022. SoK: Rethinking Sensor Spoofing Attacks against Robotic Vehicles from a Systematic View. arXiv preprint arXiv:2205.04662 (2022)."},{"key":"e_1_3_2_2_63_1","volume-title":"Analysis and Mitigation of Function Interaction Risks in Robot Apps. In 24th International Symposium on Research in Attacks, Intrusions and Defenses. 1--16","author":"Xu Yuan","year":"2021","unstructured":"Yuan Xu , Tianwei Zhang , and Yungang Bao . 2021 . Analysis and Mitigation of Function Interaction Risks in Robot Apps. In 24th International Symposium on Research in Attacks, Intrusions and Defenses. 1--16 . Yuan Xu, Tianwei Zhang, and Yungang Bao. 2021. Analysis and Mitigation of Function Interaction Risks in Robot Apps. In 24th International Symposium on Research in Attacks, Intrusions and Defenses. 1--16."},{"key":"e_1_3_2_2_64_1","volume-title":"Robust backdoor attacks against deep neural networks in real physical world. arXiv preprint arXiv:2104.07395","author":"Xue Mingfu","year":"2021","unstructured":"Mingfu Xue , Can He , Shichang Sun , Jian Wang , and Weiqiang Liu . 2021. Robust backdoor attacks against deep neural networks in real physical world. arXiv preprint arXiv:2104.07395 ( 2021 ). Mingfu Xue, Can He, Shichang Sun, Jian Wang, and Weiqiang Liu. 2021. Robust backdoor attacks against deep neural networks in real physical world. arXiv preprint arXiv:2104.07395 (2021)."},{"key":"e_1_3_2_2_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475395"},{"key":"e_1_3_2_2_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"e_1_3_2_2_67_1","volume-title":"Resa: Recurrent feature-shift aggregator for lane detection. arXiv preprint arXiv:2008.13719 5, 7","author":"Zheng Tu","year":"2020","unstructured":"Tu Zheng , Hao Fang , Yi Zhang , Wenjian Tang , Zheng Yang , Haifeng Liu , and Deng Cai . 2020 . Resa: Recurrent feature-shift aggregator for lane detection. arXiv preprint arXiv:2008.13719 5, 7 (2020). Tu Zheng, Hao Fang, Yi Zhang, Wenjian Tang, Zheng Yang, Haifeng Liu, and Deng Cai. 2020. Resa: Recurrent feature-shift aggregator for lane detection. arXiv preprint arXiv:2008.13719 5, 7 (2020)."}],"event":{"name":"MM '22: The 30th ACM International Conference on Multimedia","location":"Lisboa Portugal","acronym":"MM '22","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 30th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548171","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3503161.3548171","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:20Z","timestamp":1750186820000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3503161.3548171"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,10]]},"references-count":67,"alternative-id":["10.1145\/3503161.3548171","10.1145\/3503161"],"URL":"https:\/\/doi.org\/10.1145\/3503161.3548171","relation":{},"subject":[],"published":{"date-parts":[[2022,10,10]]},"assertion":[{"value":"2022-10-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}