{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T15:28:38Z","timestamp":1784129318724,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":67,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,11,6]],"date-time":"2022-11-06T00:00:00Z","timestamp":1667692800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1737590, CNS-2120369, CNS-1652503, ECCS-2028872"],"award-info":[{"award-number":["CNS-1737590, CNS-2120369, CNS-1652503, ECCS-2028872"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,11,6]]},"DOI":"10.1145\/3560905.3568539","type":"proceedings-article","created":{"date-parts":[[2023,1,24]],"date-time":"2023-01-24T23:37:10Z","timestamp":1674603430000},"page":"533-547","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":34,"title":["Towards Backdoor Attacks against LiDAR Object Detection in Autonomous Driving"],"prefix":"10.1145","author":[{"given":"Yan","family":"Zhang","sequence":"first","affiliation":[{"name":"University of Georgia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yi","family":"Zhu","sequence":"additional","affiliation":[{"name":"State University of New York at Buffalo"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zihao","family":"Liu","sequence":"additional","affiliation":[{"name":"University of Georgia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chenglin","family":"Miao","sequence":"additional","affiliation":[{"name":"University of Georgia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Foad","family":"Hajiaghajani","sequence":"additional","affiliation":[{"name":"State University of New York at Buffalo"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lu","family":"Su","sequence":"additional","affiliation":[{"name":"Purdue University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chunming","family":"Qiao","sequence":"additional","affiliation":[{"name":"State University of New York at Buffalo"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,1,24]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Wee Hyong Tok, and Luis Cabrera-Cordon","author":"Barga Roger","year":"2015","unstructured":"Roger Barga, Valentine Fontama, Wee Hyong Tok, and Luis Cabrera-Cordon. 2015. Predictive analytics with Microsoft Azure machine learning. Springer."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3478684.3479254"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01164"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00076"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"e_1_3_2_1_6_1","volume-title":"Badpre: Task-agnostic backdoor attacks to pre-trained nlp foundation models. arXiv preprint arXiv:2110.02467","author":"Chen Kangjie","year":"2021","unstructured":"Kangjie Chen, Yuxian Meng, Xiaofei Sun, Shangwei Guo, Tianwei Zhang, Jiwei Li, and Chun Fan. 2021. Badpre: Task-agnostic backdoor attacks to pre-trained nlp foundation models. arXiv preprint arXiv:2110.02467 (2021)."},{"key":"e_1_3_2_1_7_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_8_1","volume-title":"ICML 2021 Workshop on Adversarial Machine Learning.","author":"Chen Xiaoyi","year":"2021","unstructured":"Xiaoyi Chen, Ahmed Salem, Michael Backes, Shiqing Ma, and Yang Zhang. 2021. Badnl: Backdoor attacks against nlp models. In ICML 2021 Workshop on Adversarial Machine Learning."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00987"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16207"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2017.7989161"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.02021"},{"key":"e_1_3_2_1_13_1","volume-title":"Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, and Hyoungshick Kim.","author":"Gao Yansong","year":"2020","unstructured":"Yansong Gao, Bao Gia Doan, Zhi Zhang, Siqi Ma, Jiliang Zhang, Anmin Fu, Surya Nepal, and Hyoungshick Kim. 2020. Backdoor attacks and countermeasures on deep learning: A comprehensive review. arXiv preprint arXiv:2007.10760 (2020)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6248074"},{"key":"e_1_3_2_1_15_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_1_16_1","volume-title":"Deep learning for 3d point clouds: A survey","author":"Guo Yulan","year":"2020","unstructured":"Yulan Guo, Hanyun Wang, Qingyong Hu, Hao Liu, Li Liu, and Mohammed Bennamoun. 2020. Deep learning for 3d point clouds: A survey. IEEE transactions on pattern analysis and machine intelligence 43, 12 (2020), 4338--4364."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3032970.3032987"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00823"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3307334.3326107"},{"key":"e_1_3_2_1_20_1","volume-title":"The apolloscape open dataset for autonomous driving and its application","author":"Huang Xinyu","year":"2019","unstructured":"Xinyu Huang, Peng Wang, Xinjing Cheng, Dingfu Zhou, Qichuan Geng, and Ruigang Yang. 2019. The apolloscape open dataset for autonomous driving and its application. IEEE transactions on pattern analysis and machine intelligence 42, 10 (2019), 2702--2719."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.26"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2018.2868659"},{"key":"e_1_3_2_1_23_1","volume-title":"International Conference on Learning Representations (ICLR'20)","author":"Jia Yunhan Jia","year":"2020","unstructured":"Yunhan Jia Jia, Yantao Lu, Junjie Shen, Qi Alfred Chen, Hao Chen, Zhenyu Zhong, and Tao Wei Wei. 2020. Fooling detection alone is not enough: Adversarial attack against multiple object tracking. In International Conference on Learning Representations (ICLR'20)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3103852"},{"key":"e_1_3_2_1_25_1","volume-title":"Can you hear it? backdoor attacks via ultrasonic triggers. arXiv preprint arXiv:2107.14569","author":"Koffas Stefanos","year":"2021","unstructured":"Stefanos Koffas, Jing Xu, Mauro Conti, and Stjepan Picek. 2021. Can you hear it? backdoor attacks via ultrasonic triggers. arXiv preprint arXiv:2107.14569 (2021)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.3390\/s20030704"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00028"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01298"},{"key":"e_1_3_2_1_29_1","unstructured":"Gene Lewis. 2014. Object detection for autonomous vehicles."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475314"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01618"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00746"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01270-0_39"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01296"},{"key":"e_1_3_2_1_35_1","volume-title":"Microsoft azure machine learning","author":"Mund Sumit","unstructured":"Sumit Mund. 2015. Microsoft azure machine learning. Packt Publishing Ltd."},{"key":"e_1_3_2_1_36_1","volume-title":"Invisible and Efficient Backdoor Attacks for Compressed Deep Neural Networks. In ICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 96--100","author":"Phan Huy","year":"2022","unstructured":"Huy Phan, Yi Xie, Jian Liu, Yingying Chen, and Bo Yuan. 2022. Invisible and Efficient Backdoor Attacks for Compressed Deep Neural Networks. In ICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 96--100."},{"key":"e_1_3_2_1_37_1","volume-title":"Google Cloud AI Services Quick Start Guide: Build Intelligent Applications with Google Cloud AI Services","author":"Ravulavaru Arvind","unstructured":"Arvind Ravulavaru. 2018. Google Cloud AI Services Quick Start Guide: Build Intelligent Applications with Google Cloud AI Services. Packt Publishing Ltd."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2019.2948775"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/PST47121.2019.8949034"},{"key":"e_1_3_2_1_41_1","volume-title":"James Crowley, Jasmin Grosinger, F\u00e9lix Ingrand, Uwe K\u00f6ckemann, Alessandro Saffiotti, and Martin Welss.","author":"Sch\u00fcller Peter","year":"2022","unstructured":"Peter Sch\u00fcller, Jo\u00e3o Paolo Costeira, James Crowley, Jasmin Grosinger, F\u00e9lix Ingrand, Uwe K\u00f6ckemann, Alessandro Saffiotti, and Martin Welss. 2022. Composing Complex and Hybrid AI Solutions. arXiv preprint arXiv:2202.12566 (2022)."},{"key":"e_1_3_2_1_42_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Severi Giorgio","year":"2021","unstructured":"Giorgio Severi, Jim Meyer, Scott Coull, and Alina Oprea. 2021. {Explanation-Guided} Backdoor Poisoning Attacks Against Malware Classifiers. In 30th USENIX Security Symposium (USENIX Security 21). 1487--1504."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01054"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00086"},{"key":"e_1_3_2_1_45_1","volume-title":"3d part-aware and aggregation neural network for object detection from point cloud. arXiv preprint arXiv:1907.03670 2, 3","author":"Shi Shaoshuai","year":"2019","unstructured":"Shaoshuai Shi, Zhe Wang, Xiaogang Wang, and Hongsheng Li. 2019. Part-a^ 2 net: 3d part-aware and aggregation neural network for object detection from point cloud. arXiv preprint arXiv:1907.03670 2, 3 (2019)."},{"key":"e_1_3_2_1_46_1","volume-title":"29th {USENIX} Security Symposium ({USENIX} Security 20). 1327--1344.","author":"Suya Fnu","unstructured":"Fnu Suya, Jianfeng Chi, David Evans, and Yuan Tian. 2020. Hybrid batch attacks: Finding black-box adversarial examples with limited queries. In 29th {USENIX} Security Symposium ({USENIX} Security 20). 1327--1344."},{"key":"e_1_3_2_1_47_1","volume-title":"International Conference on Machine Learning. PMLR, 10000--10010","author":"Suya Fnu","year":"2021","unstructured":"Fnu Suya, Saeed Mahloujifar, Anshuman Suri, David Evans, and Yuan Tian. 2021. Model-targeted poisoning attacks with provable convergence. In International Conference on Machine Learning. PMLR, 10000--10010."},{"key":"e_1_3_2_1_48_1","volume-title":"Query-limited black-box attacks to classifiers. arXiv preprint arXiv:1712.08713","author":"Suya Fnu","year":"2017","unstructured":"Fnu Suya, Yuan Tian, David Evans, and Paolo Papotti. 2017. Query-limited black-box attacks to classifiers. arXiv preprint arXiv:1712.08713 (2017)."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01373"},{"key":"e_1_3_2_1_50_1","volume-title":"Robotics: Science and Systems","volume":"1","author":"Wang Dominic Zeng","year":"2015","unstructured":"Dominic Zeng Wang and Ingmar Posner. 2015. Voting for voting in online point cloud object detection.. In Robotics: Science and Systems, Vol. 1. Rome, Italy, 10--15."},{"key":"e_1_3_2_1_51_1","volume-title":"Multi-modal 3d object detection in autonomous driving: a survey. arXiv preprint arXiv:2106.12735","author":"Wang Yingjie","year":"2021","unstructured":"Yingjie Wang, Qiuyu Mao, Hanqi Zhu, Yu Zhang, Jianmin Ji, and Yanyong Zhang. 2021. Multi-modal 3d object detection in autonomous driving: a survey. arXiv preprint arXiv:2106.12735 (2021)."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477244.3477611"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2018.8462926"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00750"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00706"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00798"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5459"},{"key":"e_1_3_2_1_58_1","volume-title":"Jigsaw Puzzle: Selective Backdoor Attack to Subvert Malware Classifiers. arXiv preprint arXiv:2202.05470","author":"Yang Limin","year":"2022","unstructured":"Limin Yang, Zhi Chen, Jacopo Cortellazzi, Feargus Pendlebury, Kevin Tu, Fabio Pierazzi, Lorenzo Cavallaro, and Gang Wang. 2022. Jigsaw Puzzle: Selective Backdoor Attack to Subvert Malware Classifiers. arXiv preprint arXiv:2202.05470 (2022)."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.431"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00204"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.3390\/app12125786"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cag.2021.07.003"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413468"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00472"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485730.3485935"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485377"}],"event":{"name":"SenSys '22: The 20th ACM Conference on Embedded Networked Sensor Systems","location":"Boston Massachusetts","acronym":"SenSys '22","sponsor":["SIGMETRICS ACM Special Interest Group on Measurement and Evaluation","SIGCOMM ACM Special Interest Group on Data Communication","SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing","SIGOPS ACM Special Interest Group on Operating Systems","SIGBED ACM Special Interest Group on Embedded Systems","SIGARCH ACM Special Interest Group on Computer Architecture"]},"container-title":["Proceedings of the 20th ACM Conference on Embedded Networked Sensor Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560905.3568539","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3560905.3568539","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3560905.3568539","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:15Z","timestamp":1750182555000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560905.3568539"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,6]]},"references-count":67,"alternative-id":["10.1145\/3560905.3568539","10.1145\/3560905"],"URL":"https:\/\/doi.org\/10.1145\/3560905.3568539","relation":{},"subject":[],"published":{"date-parts":[[2022,11,6]]},"assertion":[{"value":"2023-01-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}