{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T11:28:01Z","timestamp":1764588481043,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,26]],"date-time":"2023-10-26T00:00:00Z","timestamp":1698278400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"CAAI-Huawei MindSpore Open Fund"},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62171325"],"award-info":[{"award-number":["62171325"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key R&D Project","award":["2021YFC3320301"],"award-info":[{"award-number":["2021YFC3320301"]}]},{"name":"Hubei Key R&D Project","award":["2022BAA033"],"award-info":[{"award-number":["2022BAA033"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,26]]},"DOI":"10.1145\/3581783.3611910","type":"proceedings-article","created":{"date-parts":[[2023,10,27]],"date-time":"2023-10-27T07:27:40Z","timestamp":1698391660000},"page":"8828-8838","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Moir\u00e9 Backdoor Attack (MBA): A Novel Trigger for Pedestrian Detectors in the Physical World"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2144-2065","authenticated-orcid":false,"given":"Hui","family":"Wei","sequence":"first","affiliation":[{"name":"National Engineering Research Center for Multimedia Software, School of Computer Science, Wuhan University, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2144-1975","authenticated-orcid":false,"given":"Hanxun","family":"Yu","sequence":"additional","affiliation":[{"name":"National Engineering Research Center for Multimedia Software, School of Computer Science, Wuhan University, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-6038-5279","authenticated-orcid":false,"given":"Kewei","family":"Zhang","sequence":"additional","affiliation":[{"name":"National Engineering Research Center for Multimedia Software, School of Computer Science, Wuhan University, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5016-587X","authenticated-orcid":false,"given":"Zhixiang","family":"Wang","sequence":"additional","affiliation":[{"name":"The University of Tokyo, Tokyo, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1831-0106","authenticated-orcid":false,"given":"Jianke","family":"Zhu","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3846-9157","authenticated-orcid":false,"given":"Zheng","family":"Wang","sequence":"additional","affiliation":[{"name":"National Engineering Research Center for Multimedia Software, School of Computer Science, Wuhan University, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,10,27]]},"reference":[{"key":"e_1_3_2_2_1_1","series-title":"Journal of Physics: Conference Series","volume-title":"Moir\u00e9 methods for the protection of documents and products: A short survey","author":"Amidror Itzhak","year":"2001","unstructured":"Itzhak Amidror, Sylvain Chosson, and RD Hersch. 2007. Moir\u00e9 methods for the protection of documents and products: A short survey. In Journal of Physics: Conference Series, Vol. 77. IOP Publishing, 012001."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1038\/lsa.2013.42"},{"key":"e_1_3_2_2_3_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_2_4_1","first-page":"18944","article-title":"Backdoor attack with imperceptible input and latent modification","volume":"34","author":"Doan Khoa","year":"2021","unstructured":"Khoa Doan, Yingjie Lao, and Ping Li. 2021a. Backdoor attack with imperceptible input and latent modification. Advances in Neural Information Processing Systems, Vol. 34 (2021), 18944--18957.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"e_1_3_2_2_6_1","volume-title":"Marksman Backdoor: Backdoor Attacks with Arbitrary Target Class. arXiv preprint arXiv:2210.09194","author":"Doan Khoa D","year":"2022","unstructured":"Khoa D Doan, Yingjie Lao, and Ping Li. 2022. Marksman Backdoor: Backdoor Attacks with Arbitrary Target Class. arXiv preprint arXiv:2210.09194 (2022)."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.02021"},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_2_9_1","volume-title":"Mask R-CNN. 2017 IEEE International Conference on Computer Vision (ICCV) (Oct","author":"He Kaiming","year":"2017","unstructured":"Kaiming He, Georgia Gkioxari, Piotr Dollar, and Ross Girshick. 2017. Mask R-CNN. 2017 IEEE International Conference on Computer Vision (ICCV) (Oct 2017)."},{"key":"e_1_3_2_2_10_1","unstructured":"Glenn Jocher. 2020. YOLOv5 Detector. https:\/\/github.com\/ultralytics\/yolov5. Accessed: 2023-03--13."},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.optcom.2018.01.013"},{"key":"e_1_3_2_2_12_1","first-page":"2088","article-title":"Invisible backdoor attacks on deep neural networks via steganography and regularization","volume":"18","author":"Li Shaofeng","year":"2020","unstructured":"Shaofeng Li, Minhui Xue, Benjamin Zi Hao Zhao, Haojin Zhu, and Xinpeng Zhang. 2020. Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Transactions on Dependable and Secure Computing, Vol. 18, 5 (2020), 2088--2105.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_2_13_1","volume-title":"Backdoor learning: A survey","author":"Li Yiming","year":"2022","unstructured":"Yiming Li, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2022. Backdoor learning: A survey. IEEE Transactions on Neural Networks and Learning Systems (2022)."},{"key":"e_1_3_2_2_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"e_1_3_2_2_15_1","volume-title":"Backdoor attack in the physical world. arXiv preprint arXiv:2104.02361","author":"Li Yiming","year":"2021","unstructured":"Yiming Li, Tongqing Zhai, Yong Jiang, Zhifeng Li, and Shu-Tao Xia. 2021b. Backdoor attack in the physical world. arXiv preprint arXiv:2104.02361 (2021)."},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"e_1_3_2_2_20_1","volume-title":"Untargeted Backdoor Attack against Object Detection. arXiv preprint arXiv:2211.05638","author":"Luo Chengxiao","year":"2022","unstructured":"Chengxiao Luo, Yiming Li, Yong Jiang, and Shu-Tao Xia. 2022. Untargeted Backdoor Attack against Object Detection. arXiv preprint arXiv:2211.05638 (2022)."},{"key":"e_1_3_2_2_21_1","volume-title":"Dangerous cloaking: Natural trigger based backdoor attacks on object detectors in the physical world. arXiv preprint arXiv:2201.08619","author":"Ma Hua","year":"2022","unstructured":"Hua Ma, Yinshan Li, Yansong Gao, Alsharif Abuadbba, Zhi Zhang, Anmin Fu, Hyoungshick Kim, Said F Al-Sarawi, Nepal Surya, and Derek Abbott. 2022a. Dangerous cloaking: Natural trigger based backdoor attacks on object detectors in the physical world. arXiv preprint arXiv:2201.08619 (2022)."},{"key":"e_1_3_2_2_22_1","volume-title":"MACAB: Model-Agnostic Clean-Annotation Backdoor to Object Detection with Natural Trigger in Real-World. arXiv preprint arXiv:2209.02339","author":"Ma Hua","year":"2022","unstructured":"Hua Ma, Yinshan Li, Yansong Gao, Zhi Zhang, Alsharif Abuadbba, Anmin Fu, Said F Al-Sarawi, Nepal Surya, and Derek Abbott. 2022b. MACAB: Model-Agnostic Clean-Annotation Backdoor to Object Detection with Natural Trigger in Real-World. arXiv preprint arXiv:2209.02339 (2022)."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3495243.3560537"},{"key":"e_1_3_2_2_24_1","first-page":"26117","article-title":"Mori\u00e9 attack (ma): A new potential risk of screen photos","volume":"34","author":"Niu Dantong","year":"2021","unstructured":"Dantong Niu, Ruohao Guo, and Yisen Wang. 2021. Mori\u00e9 attack (ma): A new potential risk of screen photos. Advances in Neural Information Processing Systems, Vol. 34 (2021), 26117--26129.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1364\/AO.438037"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1186\/s13635-020-00104-z"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01299"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1364\/OE.393843"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01298"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01301"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"crossref","unstructured":"Glenn Tournier Mario Valenti Jonathan How and Eric Feron. 2006. Estimation and control of a quadrotor vehicle using monocular vision and moire patterns. In AIAA Guidance Navigation and Control Conference and Exhibit. 6711.","DOI":"10.2514\/6.2006-6711"},{"key":"e_1_3_2_2_33_1","volume-title":"Label-consistent backdoor attacks. arXiv preprint arXiv:1912.02771","author":"Turner Alexander","year":"2019","unstructured":"Alexander Turner, Dimitris Tsipras, and Aleksander Madry. 2019. Label-consistent backdoor attacks. arXiv preprint arXiv:1912.02771 (2019)."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.apm.2015.01.056"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1242\/jcs.255745"},{"key":"e_1_3_2_2_36_1","volume-title":"Physical Adversarial Attack meets Computer Vision: A Decade Survey. arXiv preprint arXiv:2209.15179","author":"Wei Hui","year":"2022","unstructured":"Hui Wei, Hao Tang, Xuemei Jia, Hanxun Yu, Zhubo Li, Zhixiang Wang, Shin'ichi Satoh, and Zheng Wang. 2022b. Physical Adversarial Attack meets Computer Vision: A Decade Survey. arXiv preprint arXiv:2209.15179 (2022)."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i12.26777"},{"key":"e_1_3_2_2_38_1","volume-title":"Physically Adversarial Attacks and Defenses in Computer Vision: A Survey. arXiv preprint arXiv:2211.01671","author":"Wei Xingxing","year":"2022","unstructured":"Xingxing Wei, Bangzheng Pu, Jiefan Lu, and Baoyuan Wu. 2022a. Physically Adversarial Attacks and Defenses in Computer Vision: A Survey. arXiv preprint arXiv:2211.01671 (2022)."},{"key":"e_1_3_2_2_39_1","first-page":"22103","article-title":"Finding Naturally Occurring Physical Backdoors in Image Datasets","volume":"35","author":"Wenger Emily","year":"2022","unstructured":"Emily Wenger, Roma Bhattacharjee, Arjun Nitin Bhagoji, Josephine Passananti, Emilio Andere, Heather Zheng, and Ben Zhao. 2022. Finding Naturally Occurring Physical Backdoors in Image Datasets. Advances in Neural Information Processing Systems, Vol. 35 (2022), 22103--22116.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102726"},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3232232"},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19797-0_37"},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.05.099"},{"key":"e_1_3_2_2_45_1","volume-title":"International Conference on Learning Representations.","author":"Zhang Hao","year":"2022","unstructured":"Hao Zhang, Feng Li, Shilong Liu, Lei Zhang, Hang Su, Jun Zhu, Lionel Ni, and Harry Shum. 2022. Dino: Detr with improved denoising anchor boxes for end-to-end object detection. In International Conference on Learning Representations."},{"key":"e_1_3_2_2_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464809"},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00098"},{"key":"e_1_3_2_2_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01478"},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"}],"event":{"name":"MM '23: The 31st ACM International Conference on Multimedia","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Ottawa ON Canada","acronym":"MM '23"},"container-title":["Proceedings of the 31st ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3581783.3611910","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3581783.3611910","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T00:11:28Z","timestamp":1755821488000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3581783.3611910"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,26]]},"references-count":49,"alternative-id":["10.1145\/3581783.3611910","10.1145\/3581783"],"URL":"https:\/\/doi.org\/10.1145\/3581783.3611910","relation":{},"subject":[],"published":{"date-parts":[[2023,10,26]]},"assertion":[{"value":"2023-10-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}