{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T14:33:42Z","timestamp":1774449222099,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":84,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Department of National Defense (DND) Canada"},{"name":"Natural Sciences and Engineering Research Council of Canada (NSERC)"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690210","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"1849-1863","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["SpecGuard: Specification Aware Recovery for Robotic Autonomous Vehicles from Physical Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9818-4922","authenticated-orcid":false,"given":"Pritam","family":"Dash","sequence":"first","affiliation":[{"name":"University of British Columbia, Vancouver, BC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3259-2683","authenticated-orcid":false,"given":"Ethan","family":"Chan","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, BC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2380-3415","authenticated-orcid":false,"given":"Karthik","family":"Pattabiraman","sequence":"additional","affiliation":[{"name":"University of British Columbia, Vancouver, BC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2024. Aion R1 ArduPilot Edition. https:\/\/docs.aionrobotics.com\/en\/latest\/r1-ugv.html"},{"key":"e_1_3_2_1_2_1","unstructured":"2024. Ardupilot Software in the Loop. http:\/\/ardupilot.org\/dev\/docs\/sitl-simulatorsoftware-in-the-loop.html"},{"key":"e_1_3_2_1_3_1","unstructured":"2024. A downed drone highlights a vulnerable technology. https: \/\/www.washingtonpost.com\/politics\/2023\/03\/16\/downed-us-drone-pointscyber-vulnerabilities\/."},{"key":"e_1_3_2_1_4_1","unstructured":"2024. PX4 Open Source Autopilot. https:\/\/docs.px4.io\/main\/en\/"},{"key":"e_1_3_2_1_5_1","unstructured":"2024. SpecGuard Videos. https:\/\/tinyurl.com\/specguard."},{"key":"e_1_3_2_1_6_1","unstructured":"2024. Tarrot 650 v2 Drone. https:\/\/uavsystemsinternational.com\/products\/tarot-650-ready-to-fly-drone"},{"key":"e_1_3_2_1_7_1","unstructured":"2024. u-blox M8 concurrent GNSS modules. https:\/\/www.u-blox.com\/en\/product\/ neo-m8-series"},{"key":"e_1_3_2_1_8_1","volume-title":"Xuanpeng Zhao, and Nael Abu-Ghazaleh.","author":"Abdo Ahmed","year":"2024","unstructured":"Ahmed Abdo, Sakib Md Bin Malek, Xuanpeng Zhao, and Nael Abu-Ghazaleh. 2024. AVMON: Securing Autonomous Vehicles by Learning Control Invariants and Residual Prediction. VehicleSec (2024)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11797"},{"key":"e_1_3_2_1_10_1","volume-title":"Concrete problems in AI safety. arXiv preprint arXiv:1606.06565","author":"Amodei Dario","year":"2016","unstructured":"Dario Amodei, Chris Olah, Jacob Steinhardt, Paul Christiano, John Schulman, and Dan Man\u00e9. 2016. Concrete problems in AI safety. arXiv preprint arXiv:1606.06565 (2016)."},{"key":"e_1_3_2_1_11_1","volume-title":"PID controller: Theory, Design, and Tuning","author":"\u00c5str\u00f6m Karl J","year":"2006","unstructured":"Karl J \u00c5str\u00f6m and Tore H\u00e4gglund. 2006. PID controller: Theory, Design, and Tuning. IEEE Control Systems Magazine 1066 (2006)."},{"key":"e_1_3_2_1_12_1","volume-title":"International journal of production economics 229","author":"Bai Chunguang","year":"2020","unstructured":"Chunguang Bai, Patrick Dallasega, Guido Orzes, and Joseph Sarkis. 2020. Industry 4.0 technologies assessment: A sustainability perspective. International journal of production economics 229 (2020), 107776."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-62416-7_19"},{"key":"e_1_3_2_1_14_1","volume-title":"2020 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS). IEEE, 1637--1644","author":"Bonatti Rogerio","year":"2020","unstructured":"Rogerio Bonatti, Ratnesh Madaan, Vibhav Vineet, Sebastian Scherer, and Ashish Kapoor. 2020. Learning visuomotor policies for aerial navigation using crossmodal representations. In 2020 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS). IEEE, 1637--1644."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1146\/annurev-control-042920-020211"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the International Symposium on Combinatorial Search","volume":"8","author":"Camacho Alberto","year":"2017","unstructured":"Alberto Camacho, Oscar Chen, Scott Sanner, and Sheila McIlraith. 2017. Nonmarkovian rewards expressed in LTL: guiding search via reward shaping. In Proceedings of the International Symposium on Combinatorial Search, Vol. 8. 159--160."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00076"},{"key":"e_1_3_2_1_18_1","volume-title":"Adversarial objects against lidar-based autonomous driving systems. arXiv preprint arXiv:1907.05418","author":"Cao Yulong","year":"2019","unstructured":"Yulong Cao, Chaowei Xiao, Dawei Yang, Jing Fang, Ruigang Yang, Mingyan Liu, and Bo Li. 2019. Adversarial objects against lidar-based autonomous driving systems. arXiv preprint arXiv:1907.05418 (2019)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013387"},{"key":"e_1_3_2_1_20_1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Choi Hongjun","year":"2020","unstructured":"Hongjun Choi, Sayali Kate, Yousra Aafer, Xiangyu Zhang, and Dongyan Xu. 2020. Software-based Realtime Recovery from Sensor Attacks on Robotic Vehicles. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). USENIX Association, San Sebastian, 349--364."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243752"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.37"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(93)90054-9"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Pritam Dash Ethan Chan and Karthik Pattabiraman. 2024. SpecGuard: Specification Aware Recovery for Robotic Autonomous Vehicles from Physical Attacks. arXiv:2408.15200 [cs.RO] https:\/\/arxiv.org\/abs\/2408.15200","DOI":"10.1145\/3658644.3690210"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359847"},{"key":"e_1_3_2_1_26_1","volume-title":"Article 7 (jan","author":"Dash Pritam","year":"2021","unstructured":"Pritam Dash, Mehdi Karimibiuki, and Karthik Pattabiraman. 2021. Stealthy Attacks against Robotic Vehicles Protected by Control-based Intrusion Detection Techniques. Digital Threats 2, 1, Article 7 (jan 2021), 25 pages."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48987.2021.00020"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3634737.3644997"},{"key":"e_1_3_2_1_29_1","volume-title":"Controlling UAVs with Sensor Input Spoofing Attacks. In 10th USENIX Workshop on Offensive Technologies (WOOT 16)","author":"Davidson Drew","year":"2016","unstructured":"Drew Davidson, HaoWu, Rob Jellinek, Vikas Singh, and Thomas Ristenpart. 2016. Controlling UAVs with Sensor Input Spoofing Attacks. In 10th USENIX Workshop on Offensive Technologies (WOOT 16). USENIX Association, Austin, TX."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10703-017-0286-7"},{"key":"e_1_3_2_1_31_1","unstructured":"ONNX developers. 2024. Open Neural Network Exchange (ONNX). https:\/\/github. com\/onnx\/onnx"},{"key":"e_1_3_2_1_32_1","unstructured":"ONNX Runtime developers. 2024. ONNX Runtime. https:\/\/onnxruntime.ai\/"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA40945.2020.9196611"},{"key":"e_1_3_2_1_34_1","volume-title":"In Proceedings of the Institute of Navigation GNSS (ION GNSS.","author":"Humphreys Todd E.","year":"2008","unstructured":"Todd E. Humphreys. 2008. Assessing the Spoofing Threat: Development of a Portable GPS Civilian Spoofer. In In Proceedings of the Institute of Navigation GNSS (ION GNSS."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2017.2720851"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3111139"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"crossref","unstructured":"Joon-Ha Jang Mangi Cho Jaehoon Kim Dongkwan Kim and Yongdae Kim. 2023. Paralyzing Drones via EMI Signal Injection on Sensory Communication Channels.. In NDSS.","DOI":"10.14722\/ndss.2023.24616"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"Jinseob Jeong Dongkwan Kim Joon-Ha Jang Juhwan Noh Changhun Song and Yongdae Kim. 2023. Un-Rocking Drones: Foundations of Acoustic Injection Attacks and Recovery Thereof.. In NDSS.","DOI":"10.14722\/ndss.2023.24112"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00091"},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of the 2020 Conference on Robot Learning (Proceedings of Machine Learning Research","volume":"2136","author":"Julian Ryan","year":"2021","unstructured":"Ryan Julian, Benjamin Swanson, Gaurav Sukhatme, Sergey Levine, Chelsea Finn, and Karol Hausman. 2021. Never Stop Learning: The Effectiveness of Fine-Tuning in Robotic Reinforcement Learning. In Proceedings of the 2020 Conference on Robot Learning (Proceedings of Machine Learning Research, Vol. 155), Jens Kober, Fabio Ramos, and Claire Tomlin (Eds.). PMLR, 2120--2136."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00143"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCPS.2018.00011"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Israel Koren and C Mani Krishna. 2020. Fault-tolerant systems. Morgan Kaufmann.","DOI":"10.1016\/B978-0-12-818105-8.00014-0"},{"key":"e_1_3_2_1_44_1","volume-title":"The fiber-optic gyroscope","author":"Lefevre Herve C","unstructured":"Herve C Lefevre. 2022. The fiber-optic gyroscope. Artech house."},{"key":"e_1_3_2_1_45_1","volume-title":"Signal analysis and prediction","author":"Ljung Lennart","unstructured":"Lennart Ljung. 1998. System identification. In Signal analysis and prediction. Springer, 163--173."},{"key":"e_1_3_2_1_46_1","unstructured":"Ratnesh Madaan Nicholas Gyde Sai Vemprala Matthew Brown Keiko Nagami Tim Taubner Eric Cristofalo Davide Scaramuzza Mac Schwager and Ashish Kapoor. 2020. Airsim drone racing lab. In Neurips 2019 competition and demonstration track. PMLR 177--191."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30206-3_12"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30206-3_12"},{"key":"e_1_3_2_1_49_1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Man Yanmao","year":"2020","unstructured":"Yanmao Man, Ming Li, and Ryan Gerdes. 2020. GhostImages: Remote perception attacks against camera-based image classification systems. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020). 317--332."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICRA.2011.5980229"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"crossref","unstructured":"Volodymyr Mnih Koray Kavukcuoglu David Silver Andrei A Rusu Joel Veness Marc G Bellemare Alex Graves Martin Riedmiller Andreas K Fidjeland Georg Ostrovski et al. 2015. Human-level control through deep reinforcement learning. nature 518 7540 (2015) 529--533.","DOI":"10.1038\/nature14236"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/3309735"},{"key":"e_1_3_2_1_53_1","volume-title":"The Effects of Reward Misspecification: Mapping and Mitigating Misaligned Models. In International Conference on Learning Representations.","author":"Pan Alexander","year":"2022","unstructured":"Alexander Pan, Kush Bhatia, and Jacob Steinhardt. 2022. The Effects of Reward Misspecification: Mapping and Mitigating Misaligned Models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607221"},{"key":"e_1_3_2_1_55_1","volume-title":"Robust deep reinforcement learning with adversarial attacks. arXiv preprint arXiv:1712.03632","author":"Pattanaik Anay","year":"2017","unstructured":"Anay Pattanaik, Zhenyi Tang, Shuijing Liu, Gautham Bommannan, and Girish Chowdhary. 2017. Robust deep reinforcement learning with adversarial attacks. arXiv preprint arXiv:1712.03632 (2017)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/icra.2018.8460528"},{"key":"e_1_3_2_1_57_1","volume-title":"International Conference on Machine Learning. PMLR, 2817--2826","author":"Pinto Lerrel","year":"2017","unstructured":"Lerrel Pinto, James Davidson, Rahul Sukthankar, and Abhinav Gupta. 2017. Robust adversarial reinforcement learning. In International Conference on Machine Learning. PMLR, 2817--2826."},{"key":"e_1_3_2_1_58_1","volume-title":"Markov decision processes: discrete stochastic dynamic programming","author":"Puterman Martin L","unstructured":"Martin L Puterman. 2014. Markov decision processes: discrete stochastic dynamic programming. John Wiley & Sons."},{"key":"e_1_3_2_1_59_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Quinonez Raul","year":"2020","unstructured":"Raul Quinonez, Jairo Giraldo, Luis Salazar, Erick Bauman, Alvaro Cardenas, and Zhiqiang Lin. 2020. Savior: Securing autonomous vehicles with robust physical invariants. In 29th USENIX Security Symposium (USENIX Security 20). 895--912."},{"key":"e_1_3_2_1_60_1","first-page":"1","article-title":"Stable Baselines3: Reliable Reinforcement Learning Implementations","volume":"22","author":"Raffin Antonin","year":"2021","unstructured":"Antonin Raffin, Ashley Hill, Adam Gleave, Anssi Kanervisto, Maximilian Ernestus, and Noah Dormann. 2021. Stable Baselines3: Reliable Reinforcement Learning Implementations. Journal of Machine Learning Research 22, 268 (2021), 1--8.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2014.7039363"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179371"},{"key":"e_1_3_2_1_63_1","volume-title":"d.]. An Analysis of Global Positioning System (GPS) Standard Positioning Service (SPS) Performance for","author":"Renfro Brent A.","year":"2018","unstructured":"Brent A. Renfro, Miquela Stein, Nicholas Boeker, Emery Reed, and Eduardo Villalba. [n. d.]. An Analysis of Global Positioning System (GPS) Standard Positioning Service (SPS) Performance for 2018."},{"key":"e_1_3_2_1_64_1","volume-title":"Extended Kalman filtering for fuzzy modelling and multi-sensor fusion. Mathematical and computer modelling of dynamical systems 13, 3","author":"Rigatos Gerasimos","year":"2007","unstructured":"Gerasimos Rigatos and Spyros Tzafestas. 2007. Extended Kalman filtering for fuzzy modelling and multi-sensor fusion. Mathematical and computer modelling of dynamical systems 13, 3 (2007), 251--266."},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings 2000 ICRA. Millennium Conference. IEEE International Conference on Robotics and Automation.","volume":"4","author":"Roberts J.M.","unstructured":"J.M. Roberts, E.S. Duff, P.I. Corke, P. Sikka, G.J. Winstanley, and J. Cunningham. 2000. Autonomous control of underground mining vehicles using reactive navigation. In Proceedings 2000 ICRA. Millennium Conference. IEEE International Conference on Robotics and Automation., Vol. 4. 3790--3795 vol.4."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23071"},{"key":"e_1_3_2_1_67_1","volume-title":"Proximal policy optimization algorithms. arXiv preprint arXiv:1707.06347","author":"Schulman John","year":"2017","unstructured":"John Schulman, Filip Wolski, Prafulla Dhariwal, Alec Radford, and Oleg Klimov. 2017. Proximal policy optimization algorithms. arXiv preprint arXiv:1707.06347 (2017)."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67361-5_40"},{"key":"e_1_3_2_1_69_1","volume-title":"Rocking Drones with Intentional Sound Noise on Gyroscopic Sensors. In 24th USENIX Security Symposium (USENIX Security 15)","author":"Son Yunmok","year":"2015","unstructured":"Yunmok Son, Hocheol Shin, Dongkwan Kim, Youngseok Park, Juhwan Noh, Kibum Choi, Jungwoo Choi, and Yongdae Kim. 2015. Rocking Drones with Intentional Sound Noise on Gyroscopic Sensors. In 24th USENIX Security Symposium (USENIX Security 15). USENIX Association, Washington, D.C., 881--896."},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/IROS51168.2021.9636053"},{"key":"e_1_3_2_1_71_1","volume-title":"Reinforcement learning: An introduction","author":"Sutton Richard S","unstructured":"Richard S Sutton and Andrew G Barto. 2018. Reinforcement learning: An introduction. MIT press."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046719"},{"key":"e_1_3_2_1_73_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Tu Yazhou","year":"2018","unstructured":"Yazhou Tu, Zhiqiang Lin, Insup Lee, and Xiali Hei. 2018. Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial Sensors. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, MD, 1545--1562."},{"key":"e_1_3_2_1_74_1","volume-title":"2013 ACM\/IEEE International Conference on Cyber-Physical Systems (ICCPS). 41--50","author":"Hovakimyan Naira","year":"2013","unstructured":"XiaofengWang, Naira Hovakimyan, and Lui Sha. 2013. L1Simplex: Fault-tolerant control of cyber-physical systems. In 2013 ACM\/IEEE International Conference on Cyber-Physical Systems (ICCPS). 41--50."},{"key":"e_1_3_2_1_75_1","first-page":"339","article-title":"Active faulttolerant control for a class of nonlinear systems with sensor faults","volume":"6","author":"Wang Youqing","year":"2008","unstructured":"Youqing Wang, Donghua Zhou, S Joe Qin, and Hong Wang. 2008. Active faulttolerant control for a class of nonlinear systems with sensor faults. International Journal of Control, Automation, and Systems 6, 3 (2008), 339--350.","journal-title":"International Journal of Control, Automation, and Systems"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/JRA.1987.1087115"},{"key":"e_1_3_2_1_77_1","volume-title":"DeepSIM: GPS Spoofing Detection on UAVs Using Satellite Imagery Matching. In Annual Computer Security Applications Conference","author":"Xue Nian","year":"2020","unstructured":"Nian Xue, Liang Niu, Xianbin Hong, Zhen Li, Larissa Hoffaeller, and Christina P\u00f6pper. 2020. DeepSIM: GPS Spoofing Detection on UAVs Using Satellite Imagery Matching. In Annual Computer Security Applications Conference (Austin, USA) (ACSAC '20). Association for Computing Machinery, New York, NY, USA, 304--319."},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00026"},{"key":"e_1_3_2_1_79_1","first-page":"21024","article-title":"Robust deep reinforcement learning against adversarial perturbations on state observations","volume":"33","author":"Zhang Huan","year":"2020","unstructured":"Huan Zhang, Hongge Chen, Chaowei Xiao, Bo Li, Mingyan Liu, Duane Boning, and Cho-Jui Hsieh. 2020. Robust deep reinforcement learning against adversarial perturbations on state observations. Advances in Neural Information Processing Systems 33 (2020), 21024--21037.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/RTSS49844.2020.00028"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477010"},{"key":"e_1_3_2_1_82_1","volume-title":"Real-Time Data-Predictive Attack-Recovery for Complex Cyber-Physical Systems. In 2023 IEEE 29th Real-Time and Embedded Technology and Applications Symposium (RTAS). 209--222","author":"Zhang Lin","year":"2023","unstructured":"Lin Zhang, Kaustubh Sridhar, Mengyu Liu, Pengyuan Lu, Xin Chen, Fanxin Kong, Oleg Sokolsky, and Insup Lee. 2023. Real-Time Data-Predictive Attack-Recovery for Complex Cyber-Physical Systems. In 2023 IEEE 29th Real-Time and Embedded Technology and Applications Symposium (RTAS). 209--222."},{"key":"e_1_3_2_1_83_1","volume-title":"International Conference on Machine Learning. PMLR, 11225--11234","author":"Zhang Xuezhou","year":"2020","unstructured":"Xuezhou Zhang, Yuzhe Ma, Adish Singla, and Xiaojin Zhu. 2020. Adaptive rewardpoisoning attacks against reinforcement learning. In International Conference on Machine Learning. PMLR, 11225--11234."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/7.670324"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690210","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690210","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:14:45Z","timestamp":1755843285000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690210"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":84,"alternative-id":["10.1145\/3658644.3690210","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690210","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}