{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,7]],"date-time":"2026-08-07T14:38:14Z","timestamp":1786113494445,"version":"3.56.0"},"reference-count":20,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"3","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Fundamentals"],"published-print":{"date-parts":[[2024,3,1]]},"DOI":"10.1587\/transfun.2023cip0025","type":"journal-article","created":{"date-parts":[[2023,9,25]],"date-time":"2023-09-25T22:57:55Z","timestamp":1695682675000},"page":"344-354","source":"Crossref","is-referenced-by-count":3,"title":["Adversarial Examples Created by Fault Injection Attack on Image Sensor Interface"],"prefix":"10.1587","volume":"E107.A","author":[{"given":"Tatsuya","family":"OYAMA","sequence":"first","affiliation":[{"name":"Graduate School of Science and Technology, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kota","family":"YOSHIDA","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shunsuke","family":"OKURA","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Takeshi","family":"FUJINO","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"532","reference":[{"key":"1","unstructured":"[1] T. Gu, B. Dolan-Gavitt, and S. Garg, \u201cBadnets: Identifying vulnerabilities in the machine learning model supply chain,\u201d arXiv preprint arXiv:1708.06733, 2017. 10.48550\/arXiv.1708.06733"},{"key":"2","unstructured":"[2] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, \u201cIntriguing properties of neural networks,\u201d 2013."},{"key":"3","doi-asserted-by":"crossref","unstructured":"[3] K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, \u201cRobust physical-world attacks on deep learning visual classification,\u201d Proc. IEEE Conference on Computer Vision and Pattern Recognition, pp.1625-1634, 2018. 10.1109\/cvpr.2018.00175","DOI":"10.1109\/CVPR.2018.00175"},{"key":"4","doi-asserted-by":"publisher","unstructured":"[4] X. Yang, W. Liu, S. Zhang, W. Liu, and D. Tao, \u201cTargeted attention attack on deep learning models in road sign recognition,\u201d IEEE Internet Things J., vol.8, no.6, pp.4980-4990, 2021. 10.1109\/jiot.2020.3034899","DOI":"10.1109\/JIOT.2020.3034899"},{"key":"5","doi-asserted-by":"publisher","unstructured":"[5] T. Oyama, S. Okura, K. Yosida, and T. Fujino, \u201cExperimental study of fault injection attack on image sensor interface for triggering backdoored DNN models,\u201d IEICE Trans. Fundamentals, vol.E105-A, no.3, pp.336-343, March 2022. 10.1587\/transfun.2021cip0019","DOI":"10.1587\/transfun.2021CIP0019"},{"key":"6","doi-asserted-by":"crossref","unstructured":"[6] T. Oyama, S. Okura, K. Yoshida, and T. Fujino, \u201cBackdoor attack on deep neural networks triggered by fault injection attack on image sensor interface,\u201d Proc. 5th Workshop on Attacks and Solutions in Hardware Security, pp.63-72, 2021. 10.1145\/3474376.3487287","DOI":"10.1145\/3474376.3487287"},{"key":"7","doi-asserted-by":"crossref","unstructured":"[7] T. Oyama, S. Okura, K. Yoshida, and T. Fujino, \u201cBackdoor attack on deep neural networks triggered by fault injection attack on image sensor interface,\u201d Sensors, vol.23, no.10, p.4742, 2023. 10.3390\/s23104742","DOI":"10.3390\/s23104742"},{"key":"8","doi-asserted-by":"crossref","unstructured":"[8] T. Oyama, K. Yoshida, S. Okura, and T. Fujino, \u201cFundamental study of adversarial examples created by fault injection attack on image sensor interface,\u201d 2022 Asian Hardware Oriented Security and Trust Symposium (AsianHOST), pp.1-6, IEEE, 2022. 10.1109\/asianhost56390.2022.10022189","DOI":"10.1109\/AsianHOST56390.2022.10022189"},{"key":"9","doi-asserted-by":"crossref","unstructured":"[9] R. Duan, X. Ma, Y. Wang, J. Bailey, A.K. Qin, and Y. Yang, \u201cAdversarial camouflage: Hiding physical-world attacks with natural styles,\u201d Proc. IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp.1000-1008, 2020. 10.1109\/cvpr42600.2020.00108","DOI":"10.1109\/CVPR42600.2020.00108"},{"key":"10","doi-asserted-by":"publisher","unstructured":"[10] B. Deng, D. Zhang, F. Dong, J. Zhang, M. Shafiq, and Z. Gu, \u201cRust-style patch: A physical and naturalistic camouflage attacks on object detector for remote sensing images,\u201d Remote Sensing, vol.15, no.4, p.885, 2023. 10.3390\/rs15040885","DOI":"10.3390\/rs15040885"},{"key":"11","doi-asserted-by":"crossref","unstructured":"[11] W. Liu, W. He, B. Hu, and C.H. Chang, \u201cA practical man-in-the-middle attack on deep learning edge device by sparse light strip injection into camera data lane,\u201d 2022 IEEE 35th International System-on-Chip Conference (SOCC), pp.1-6, IEEE, 2022. 10.1109\/socc56010.2022.9908112","DOI":"10.1109\/SOCC56010.2022.9908112"},{"key":"12","unstructured":"[12] Q. Jiang, X. Ji, C. Yan, Z. Xie, H. Lou, and W. Xu, \u201cGlitchhiker: Uncovering vulnerabilities of image signal transmission with IEMI,\u201d USENIX Security 23, 2023."},{"key":"13","unstructured":"[13] J. Li, F. Schmidt, and Z. Kolter, \u201cAdversarial camera stickers: A physical camera-based attack on deep learning systems,\u201d International Conference on Machine Learning, pp.3896-3904, PMLR, 2019."},{"key":"14","doi-asserted-by":"crossref","unstructured":"[14] A. Sayles, A. Hooda, M. Gupta, R. Chatterjee, and E. Fernandes, \u201cInvisible perturbations: Physical adversarial examples exploiting the rolling shutter effect,\u201d Proc. IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp.14666-14675, 2021. 10.1109\/cvpr46437.2021.01443","DOI":"10.1109\/CVPR46437.2021.01443"},{"key":"15","unstructured":"[15] I.J. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d arXiv preprint arXiv:1412.6572, 2014. 10.48550\/arXiv.1412.6572"},{"key":"16","doi-asserted-by":"crossref","unstructured":"[16] N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z.B. Celik, and A. Swami, \u201cThe limitations of deep learning in adversarial settings,\u201d 2016 IEEE European Symposium on Security and Privacy, pp.372-387, 2016. 10.1109\/eurosp.2016.36","DOI":"10.1109\/EuroSP.2016.36"},{"key":"17","unstructured":"[17] K. Simonyan and A. Zisserman, \u201cVery deep convolutional networks for large-scale image recognition,\u201d arXiv preprint arXiv:1409.1556, 2014. 10.48550\/arXiv.1409.1556"},{"key":"18","doi-asserted-by":"publisher","unstructured":"[18] J. Stallkamp, M. Schlipsing, J. Salmen, and C. Igel, \u201cMan vs. computer: Benchmarking machine learning algorithms for traffic sign recognition,\u201d Neural Networks, vol.32, pp.323-332, 2012. 10.1016\/j.neunet.2012.02.016","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"19","doi-asserted-by":"crossref","unstructured":"[19] J. Redmon, S. Divvala, R. Girshick, and A. Farhadi, \u201cYou only look once: Unified, real-time object detection,\u201d Proc. IEEE Conference on Computer Vision and Pattern Recognition, pp.779-788, 2016. 10.1109\/cvpr.2016.91","DOI":"10.1109\/CVPR.2016.91"},{"key":"20","doi-asserted-by":"crossref","unstructured":"[20] W. Liu, D. Anguelov, D. Erhan, C. Szegedy, S. Reed, C.Y. Fu, and A.C. Berg, \u201cSSD: Single shot multibox detector,\u201d Computer Vision-ECCV 2016: 14th European Conference, Amsterdam, The Netherlands, Oct. 2016, Proceedings, Part I 14, pp.21-37, Springer, 2016. 10.1007\/978-3-319-46448-0_2","DOI":"10.1007\/978-3-319-46448-0_2"}],"container-title":["IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E107.A\/3\/E107.A_2023CIP0025\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,2]],"date-time":"2024-03-02T03:29:07Z","timestamp":1709350147000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E107.A\/3\/E107.A_2023CIP0025\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,3,1]]},"references-count":20,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2024]]}},"URL":"https:\/\/doi.org\/10.1587\/transfun.2023cip0025","relation":{},"ISSN":["0916-8508","1745-1337"],"issn-type":[{"value":"0916-8508","type":"print"},{"value":"1745-1337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,3,1]]},"article-number":"2023CIP0025"}}