{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:32:40Z","timestamp":1766442760382,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T00:00:00Z","timestamp":1763769600000},"content-version":"vor","delay-in-days":3,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2112562"],"award-info":[{"award-number":["CNS-2112562"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-23-1-2206"],"award-info":[{"award-number":["N00014-23-1-2206"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-19-1-0169"],"award-info":[{"award-number":["FA9550-19-1-0169"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765193","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:42:02Z","timestamp":1763854922000},"page":"2009-2023","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Security-Aware Sensor Fusion with MATE: the Multi-Agent Trust Estimator"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5418-7283","authenticated-orcid":false,"given":"R. Spencer","family":"Hallyburton","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, Duke University, Durham, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5357-0117","authenticated-orcid":false,"given":"Miroslav","family":"Pajic","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Duke University, Durham, NC, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"doi-asserted-by":"publisher","key":"e_1_3_2_1_1_1","DOI":"10.1109\/VNC48660.2019.9062796"},{"key":"e_1_3_2_1_2_1","first-page":"1165","article-title":"Design of a misbehavior detection system for objects based shared perception V2X applications. In 2019 IEEE ITSC","author":"Ambrosin Moreno","year":"2019","unstructured":"Moreno Ambrosin..., and Ignacio J Alvarez. 2019. Design of a misbehavior detection system for objects based shared perception V2X applications. In 2019 IEEE ITSC. IEEE, 1165-1172.","journal-title":"IEEE"},{"key":"e_1_3_2_1_3_1","first-page":"1","article-title":"V2x misbehavior and collective perception service.. In 2021 IEEE CSCN","author":"Ansari Mohammad","year":"2021","unstructured":"Mohammad Ansari..., and Cong Chen. 2021. V2x misbehavior and collective perception service.. In 2021 IEEE CSCN. IEEE, 1-6.","journal-title":"IEEE"},{"key":"e_1_3_2_1_4_1","volume-title":"International conference on machine learning. PMLR, 274-283","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning. PMLR, 274-283."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_5_1","DOI":"10.1002\/0471221279"},{"key":"e_1_3_2_1_6_1","first-page":"78","article-title":"Assessment of node trustworthiness in vanets using data plausibility checks. In 2012 IEEE VNC","author":"Bi\u00dfmeyer Norbert","year":"2012","unstructured":"Norbert Bi\u00dfmeyer..., and Frank Kargl. 2012. Assessment of node trustworthiness in vanets using data plausibility checks. In 2012 IEEE VNC. IEEE, 78-85.","journal-title":"IEEE"},{"key":"e_1_3_2_1_7_1","volume-title":"Multiple-target tracking with radar applications. Dedham","author":"Blackman Samuel S","year":"1986","unstructured":"Samuel S Blackman. 1986. Multiple-target tracking with radar applications. Dedham (1986)."},{"volume-title":"Introduction to Bayesian statistics","author":"Bolstad William M","unstructured":"William M Bolstad and James M Curran. 2016. Introduction to Bayesian statistics. John Wiley & Sons.","key":"e_1_3_2_1_8_1"},{"key":"e_1_3_2_1_9_1","first-page":"11621","article-title":"nuscenes: A multimodal dataset for autonomous driving","author":"Caesar Holger","year":"2020","unstructured":"Holger Caesar..., and Oscar Beijbom. 2020. nuscenes: A multimodal dataset for autonomous driving. In IEEE\/CVF CVPR. 11621-11631.","journal-title":"IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_10_1","first-page":"2267","volume-title":"CCS","author":"Cao Yulong","year":"2019","unstructured":"Yulong Cao..., and Z Morley Mao. 2019. Adversarial sensor attack on lidar-based perception in autonomous driving. In CCS 2019. ACM, London, UK, 2267-2281."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_11_1","DOI":"10.1080\/00031305.1992.10475878"},{"unstructured":"Kai Chen et al. 2019. MMDetection: Open mmlab detection toolbox and benchmark. arXiv preprint arXiv:1906.07155 (2019).","key":"e_1_3_2_1_12_1"},{"key":"e_1_3_2_1_13_1","first-page":"1","article-title":"CARLA: An open urban driving simulator","author":"Dosovitskiy Alexey","year":"2017","unstructured":"Alexey Dosovitskiy, German Ros, Felipe Codevilla, Antonio Lopez, and Vladlen Koltun. 2017. CARLA: An open urban driving simulator. In CoRL. PMLR, 1-16.","journal-title":"CoRL. PMLR"},{"key":"e_1_3_2_1_14_1","first-page":"1625","article-title":"Robust physical-world attacks on deep learning visual classification","author":"Eykholt Kevin","year":"2018","unstructured":"Kevin Eykholt and Dawn Song. 2018. Robust physical-world attacks on deep learning visual classification. In Proceedings of the IEEE CVPR. 1625-1634.","journal-title":"Proceedings of the IEEE CVPR."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_15_1","DOI":"10.1145\/1023875.1023881"},{"key":"e_1_3_2_1_16_1","volume-title":"Probabilistic Segmentation for Robust Field of View Estimation. arXiv preprint arXiv:2503.07375","author":"Hallyburton R Spencer","year":"2025","unstructured":"R Spencer Hallyburton, David Hunt, Yiwei He, Judy He, and Miroslav Pajic. 2025. Probabilistic Segmentation for Robust Field of View Estimation. arXiv preprint arXiv:2503.07375 (2025)."},{"volume-title":"31st USENIX SECURITY)","author":"Hallyburton R Spencer","unstructured":"R Spencer Hallyburton, Yupei Liu, Yulong Cao, Z Morley Mao, and Miroslav Pajic. 2022. Security analysis of camera-lidar fusion against black-box attacks on autonomous vehicles. In 31st USENIX SECURITY). USENIX, Berkeley, CA, 1-18.","key":"e_1_3_2_1_17_1"},{"key":"e_1_3_2_1_18_1","volume-title":"models, and algorithms for multi-sensor, multi-agent autonomy using avstack. arXiv preprint arXiv:2312.04970","author":"Spencer Hallyburton R","year":"2023","unstructured":"R Spencer Hallyburton and Miroslav Pajic. 2023. Datasets, models, and algorithms for multi-sensor, multi-agent autonomy using avstack. arXiv preprint arXiv:2312.04970 (2023)."},{"key":"e_1_3_2_1_19_1","volume-title":"Bayesian Methods for Trust in Collaborative Multi-Agent Autonomy. In 2024 IEEE 63rd Conference on Decision and Control (CDC). 470-476","author":"Spencer Hallyburton R.","year":"2024","unstructured":"R. Spencer Hallyburton and Miroslav Pajic. 2024a. Bayesian Methods for Trust in Collaborative Multi-Agent Autonomy. In 2024 IEEE 63rd Conference on Decision and Control (CDC). 470-476."},{"unstructured":"R. Spencer Hallyburton and Miroslav Pajic. 2024b. Security-Aware Sensor Fusion. https:\/\/sites.google.com\/view\/trusted-sensor-fusion\/.","key":"e_1_3_2_1_20_1"},{"key":"e_1_3_2_1_21_1","volume-title":"Trust-Based Assured Sensor Fusion in Distributed Aerial Autonomy. In ACM\/IEEE Int. Conf. on Cyber-Physcial Systems (ICCPS). Article 25","author":"Spencer Hallyburton R.","year":"2025","unstructured":"R. Spencer Hallyburton and Miroslav Pajic. 2025. Trust-Based Assured Sensor Fusion in Distributed Aerial Autonomy. In ACM\/IEEE Int. Conf. on Cyber-Physcial Systems (ICCPS). Article 25, 12 pages."},{"key":"e_1_3_2_1_22_1","volume-title":"Longitudinal Cyber Attacks on LiDAR in Autonomous Vehicles. arXiv preprint arXiv:2303.03470","author":"Hallyburton R Spencer","year":"2023","unstructured":"R Spencer Hallyburton, Qingzhao Zhang, Z Morley Mao, and Miroslav Pajic. 2023b. Partial-Information, Longitudinal Cyber Attacks on LiDAR in Autonomous Vehicles. arXiv preprint arXiv:2303.03470 (2023)."},{"key":"e_1_3_2_1_23_1","first-page":"209","article-title":"Avstack: An open-source, reconfigurable platform for autonomous vehicle development","author":"Hallyburton R. Spencer","year":"2023","unstructured":"R. Spencer Hallyburton, Shucheng Zhang, and Miroslav Pajic. 2023a. Avstack: An open-source, reconfigurable platform for autonomous vehicle development. In ACM\/IEEE ICCPS. 209-220.","journal-title":"ACM\/IEEE ICCPS."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_24_1","DOI":"10.1109\/MIC.2002.1003138"},{"unstructured":"Yunhan Jia Jia and Tao Wei Wei. 2020. Fooling detection alone is not enough: Adversarial attack against multiple object tracking. In ICLR.","key":"e_1_3_2_1_25_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_26_1","DOI":"10.25300\/MISQ\/2014\/38.2.06"},{"key":"e_1_3_2_1_27_1","first-page":"12697","article-title":"Pointpillars: Fast encoders for object detection from point clouds","author":"Lang Alex H","year":"2019","unstructured":"Alex H Lang, Sourabh Vora, Holger Caesar, Lubing Zhou, Jiong Yang, and Oscar Beijbom. 2019. Pointpillars: Fast encoders for object detection from point clouds. In Proceedings of the IEEE\/CVF CVPR. 12697-12705.","journal-title":"Proceedings of the IEEE\/CVF CVPR."},{"key":"e_1_3_2_1_28_1","first-page":"2209","volume-title":"IEEE TDSC","volume":"18","author":"Liu Jinshan","year":"2021","unstructured":"Jinshan Liu and Jung-Min Park. 2021. ''Seeing is not always believing'': detecting perception error attacks against AVs. IEEE TDSC, Vol. 18, 5 (2021), 2209-2223."},{"key":"e_1_3_2_1_29_1","first-page":"369","article-title":"MISO-V: Misbehavior detection for collective perception services in vehicular communications. In 2021 IEEE IV","author":"Liu Xiruo","year":"2021","unstructured":"Xiruo Liu, Lily Yang..., and Leonardo Gomes Baltar. 2021. MISO-V: Misbehavior detection for collective perception services in vehicular communications. In 2021 IEEE IV. IEEE, 369-376.","journal-title":"IEEE"},{"key":"e_1_3_2_1_30_1","first-page":"1","article-title":"Illusion attack on vanet applications-a message plausibility problem. In 2007 IEEE globecom workshops","author":"Lo Nai-Wei","year":"2007","unstructured":"Nai-Wei Lo and Hsiao-Chien Tsai. 2007. Illusion attack on vanet applications-a message plausibility problem. In 2007 IEEE globecom workshops. IEEE, 1-8.","journal-title":"IEEE"},{"key":"e_1_3_2_1_31_1","first-page":"214","article-title":"Understanding insider threat: A framework for characterising attacks. In 2014 IEEE S&P workshops","author":"Nurse Jason RC","year":"2014","unstructured":"Jason RC Nurse..., and Monica Whitty. 2014. Understanding insider threat: A framework for characterising attacks. In 2014 IEEE S&P workshops. IEEE, 214-228.","journal-title":"IEEE"},{"key":"e_1_3_2_1_32_1","first-page":"163","article-title":"Robustness of attack-resilient state estimators","author":"Pajic Miroslav","year":"2014","unstructured":"Miroslav Pajic..., and George J Pappas. 2014. Robustness of attack-resilient state estimators. In ACM\/IEEE ICCPS. 163-174.","journal-title":"ACM\/IEEE ICCPS."},{"key":"e_1_3_2_1_33_1","first-page":"587","volume-title":"JISE","volume":"28","author":"Park Jin-Seo","year":"2012","unstructured":"Jin-Seo Park and Se-Jong Oh. 2012. A new concave hull algorithm and concaveness measure for n-dimensional datasets. JISE, Vol. 28, 3 (2012), 587-600."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_34_1","DOI":"10.1109\/TITS.2014.2342271"},{"key":"e_1_3_2_1_35_1","volume-title":"ICRA workshop","volume":"3","author":"Quigley Morgan","year":"2009","unstructured":"Morgan Quigley, Ken Conley, Brian Gerkey, Josh Faust, Tully Foote, Jeremy Leibs, Rob Wheeler, Andrew Y Ng, et al., 2009. ROS: an open-source Robot Operating System. In ICRA workshop, Vol. 3. Kobe, Japan, 5."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_36_1","DOI":"10.1109\/TSP.2008.920469"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_37_1","DOI":"10.1109\/TIT.2011.2158885"},{"key":"e_1_3_2_1_38_1","first-page":"877","article-title":"Towards robust {LiDAR-based} perception in autonomous driving: General black-box adversarial sensor attack and countermeasures","volume":"2020","author":"Sun Jiachen","year":"2020","unstructured":"Jiachen Sun, Yulong Cao, Qi Alfred Chen, and Z Morley Mao. 2020. Towards robust {LiDAR-based} perception in autonomous driving: General black-box adversarial sensor attack and countermeasures. In USENIX Security 2020. 877-894.","journal-title":"USENIX Security"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_39_1","DOI":"10.1145\/1023646.1023648"},{"key":"e_1_3_2_1_40_1","volume-title":"On adaptive attacks to adversarial example defenses. Advances in neural information processing systems","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. Advances in neural information processing systems, Vol. 33 (2020), 1633-1645."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_41_1","DOI":"10.1109\/COMST.2018.2873088"},{"key":"e_1_3_2_1_42_1","first-page":"357","article-title":"An Autonomous Trust Construction System Based on Bayesian Method. In 2006 IEEE\/WIC\/ACM ICIAT","author":"Wang Wei","year":"2006","unstructured":"Wei Wang, Guosun Zeng, and Tao Liu. 2006. An Autonomous Trust Construction System Based on Bayesian Method. In 2006 IEEE\/WIC\/ACM ICIAT. IEEE, 357-362.","journal-title":"IEEE"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_43_1","DOI":"10.2753\/MIS0742-1222240110"},{"unstructured":"Q. Zhang... Q. A. Chen and Z. M. Mao. 2024. On data fabrication in collaborative vehicular perception.. In 33rd USENIX Security. 6309-6326.","key":"e_1_3_2_1_44_1"}],"event":{"sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"acronym":"CCS '25","name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765193","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765193","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:31:09Z","timestamp":1766442669000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765193"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":44,"alternative-id":["10.1145\/3719027.3765193","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765193","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}