{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:38:17Z","timestamp":1786113497245,"version":"3.56.0"},"reference-count":15,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Fundamentals"],"published-print":{"date-parts":[[2022,3,1]]},"DOI":"10.1587\/transfun.2021cip0019","type":"journal-article","created":{"date-parts":[[2021,10,25]],"date-time":"2021-10-25T22:09:51Z","timestamp":1635199791000},"page":"336-343","source":"Crossref","is-referenced-by-count":4,"title":["Experimental Study of Fault Injection Attack on Image Sensor Interface for Triggering Backdoored DNN Models"],"prefix":"10.1587","volume":"E105.A","author":[{"given":"Tatsuya","family":"OYAMA","sequence":"first","affiliation":[{"name":"Graduate School of Science and Technology, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shunsuke","family":"OKURA","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kota","family":"YOSHIDA","sequence":"additional","affiliation":[{"name":"Graduate School of Science and Technology, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Takeshi","family":"FUJINO","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"crossref","unstructured":"[1] S.J. Oh, M. Augustin, B. Schiele, and M. Fritz, \u201cTowards reverse-engineering black-box neural networks,\u201d Explainable AI: Interpreting, Explaining and Visualizing Deep Learning, pp.121-144, 2018. 10.1007\/978-3-030-28954-6_7","DOI":"10.1007\/978-3-030-28954-6_7"},{"key":"2","doi-asserted-by":"crossref","unstructured":"[2] M. Fredrikson, S. Jha, and T. Ristenpart, \u201cModel inversion attacks that exploit confidence information and basic countermeasures,\u201d Proc. 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS&apos;15, New York, NY, USA, pp.1322-1333, Association for Computing Machinery, 2015. 10.1145\/2810103.2813677","DOI":"10.1145\/2810103.2813677"},{"key":"3","doi-asserted-by":"crossref","unstructured":"[3] L. Huang, A.D. Joseph, B. Nelson, B.I. Rubinstein, and J.D. Tygar, \u201cAdversarial machine learning,\u201d Proc. 4th ACM Workshop on Security and Artificial Intelligence, AISec&apos;11, New York, NY, USA, pp.43-58, Association for Computing Machinery, 2011. 10.1145\/2046684.2046692","DOI":"10.1145\/2046684.2046692"},{"key":"4","unstructured":"[4] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, \u201cIntriguing properties of neural networks,\u201d International Conference on Learning Representations, arXiv:1312.6199, 2014."},{"key":"5","unstructured":"[5] I. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d International Conference on Learning Representations, arXiv:1412.6572, 2015."},{"key":"6","unstructured":"[6] T. Gu, B. Dolan-Gavitt, and S. Garg, \u201cBadNets: Identifying vulnerabilities in the machine learning model supply chain,\u201d CoRR, vol.abs\/1708.06733, 2017."},{"key":"7","unstructured":"[7] Y. Li, T. Zhai, B. Wu, Y. Jiang, Z. Li, and S. Xia, \u201cRethinking the trigger of backdoor attack,\u201d arXiv:2004.04692, 2021."},{"key":"8","doi-asserted-by":"publisher","unstructured":"[8] T. Gu, K. Liu, B. Dolan-Gavitt, and S. Garg, \u201cBadNets: Evaluating backdooring attacks on deep neural networks,\u201d IEEE Access, vol.7, pp.47230-47244, 2019. 10.1109\/access.2019.2909068","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"9","doi-asserted-by":"crossref","unstructured":"[9] E. Wenger, J. Passananti, A. Bhagoji, Y. Yao, H. Zheng, and B.Y. Zhao, \u201cBackdoor attacks against deep learning systems in the physical world,\u201d arXiv:2006.14580, 2020.","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"10","doi-asserted-by":"publisher","unstructured":"[10] M. Farsi, K. Ratcliff, and M. Barbosa, \u201cAn overview of controller area network,\u201d Comput. Control Eng. J., vol.10, no.3, pp.113-120, June 1999. 10.1049\/cce:19990304","DOI":"10.1049\/cce:19990304"},{"key":"11","unstructured":"[11] H. Ogura, R. Isshiki, K. Iokibe, Y. Kodera, T. Kusaka, and Y. Nogami, \u201cElectrical falsification of can data by magnetic coupling,\u201d 2020 35th International Technical Conference on Circuits\/Systems, Computers and Communications (ITC-CSCC), pp.348-353, 2020."},{"key":"12","unstructured":"[12] Y. LeCun and C. Cortes, \u201cMNIST handwritten digit database,\u201d http:\/\/yann.lecun.com\/exdb\/mnist\/, 2010."},{"key":"13","doi-asserted-by":"crossref","unstructured":"[13] Y. Yao, H. Li, H. Zheng, and B.Y. Zhao, \u201cLatent backdoor attacks on deep neural networks,\u201d Proc. 2019 ACM SIGSAC Conference on Computer and Communications Security, CCS&apos;19, New York, NY, USA, pp.2041-2055, Association for Computing Machinery, 2019. 10.1145\/3319535.3354209","DOI":"10.1145\/3319535.3354209"},{"key":"14","unstructured":"[14] X. Chen, C. Liu, B. Li, K. Lu, and D. Song, \u201cTargeted backdoor attacks on deep learning systems using data poisoning,\u201d arXiv:1712.05526, 2017."},{"key":"15","unstructured":"[15] H. Li, Y. Wang, X. Xie, Y. Liu, S. Wang, R. Wan, L.P. Chau, and A.C. Kot, \u201cLight can hack your face! black-box backdoor attack on face recognition systems,\u201d arXiv:2009.06996, 2020."}],"container-title":["IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E105.A\/3\/E105.A_2021CIP0019\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,5]],"date-time":"2022-03-05T03:19:30Z","timestamp":1646450370000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E105.A\/3\/E105.A_2021CIP0019\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,1]]},"references-count":15,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022]]}},"URL":"https:\/\/doi.org\/10.1587\/transfun.2021cip0019","relation":{},"ISSN":["0916-8508","1745-1337"],"issn-type":[{"value":"0916-8508","type":"print"},{"value":"1745-1337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,1]]},"article-number":"2021CIP0019"}}