{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T02:09:42Z","timestamp":1760148582331,"version":"build-2065373602"},"reference-count":24,"publisher":"MDPI AG","issue":"10","license":[{"start":{"date-parts":[[2023,5,14]],"date-time":"2023-05-14T00:00:00Z","timestamp":1684022400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"JSPS KAKENHI","award":["22H03593","JPMJFS2146"],"award-info":[{"award-number":["22H03593","JPMJFS2146"]}]},{"name":"JST","award":["22H03593","JPMJFS2146"],"award-info":[{"award-number":["22H03593","JPMJFS2146"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>A backdoor attack is a type of attack method that induces deep neural network (DNN) misclassification. The adversary who aims to trigger the backdoor attack inputs the image with a specific pattern (the adversarial mark) into the DNN model (backdoor model). In general, the adversary mark is created on the physical object input to an image by capturing a photo. With this conventional method, the success of the backdoor attack is not stable because the size and position change depending on the shooting environment. So far, we have proposed a method of creating an adversarial mark for triggering backdoor attacks by means of a fault injection attack on the mobile industry processor interface (MIPI), which is the image sensor interface. We propose the image tampering model, with which the adversarial mark can be generated in the actual fault injection to create the adversarial mark pattern. Then, the backdoor model was trained with poison data images, which the proposed simulation model created. We conducted a backdoor attack experiment using a backdoor model trained on a dataset containing 5% poison data. The clean data accuracy in normal operation was 91%; nevertheless, the attack success rate with fault injection was 83%.<\/jats:p>","DOI":"10.3390\/s23104742","type":"journal-article","created":{"date-parts":[[2023,5,15]],"date-time":"2023-05-15T08:33:01Z","timestamp":1684139581000},"page":"4742","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Backdoor Attack on Deep Neural Networks Triggered by Fault Injection Attack on Image Sensor Interface"],"prefix":"10.3390","volume":"23","author":[{"given":"Tatsuya","family":"Oyama","sequence":"first","affiliation":[{"name":"Graduate School of Science and Engineering, Ritsumeikan University, 1-1-1 Noji-higashi, Kusatsu 525-8577, Shiga, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6422-3703","authenticated-orcid":false,"given":"Shunsuke","family":"Okura","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University, 1-1-1 Noji-higashi, Kusatsu 525-8577, Shiga, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1293-6415","authenticated-orcid":false,"given":"Kota","family":"Yoshida","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University, 1-1-1 Noji-higashi, Kusatsu 525-8577, Shiga, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takeshi","family":"Fujino","sequence":"additional","affiliation":[{"name":"Department of Science and Engineering, Ritsumeikan University, 1-1-1 Noji-higashi, Kusatsu 525-8577, Shiga, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2023,5,14]]},"reference":[{"key":"ref_1","unstructured":"Oh, S.J., Schiele, B., and Fritz, M. (2019). Explainable AI: Interpreting, Explaining and Visualizing Deep Learning, Springer."},{"key":"ref_2","unstructured":"Fredrikson, M., Jha, S., and Ristenpart, T. (2015). CCS\u201915: 22nd ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery."},{"key":"ref_3","unstructured":"Huang, L., Joseph, A.D., Nelson, B., Rubinstein, B.I., and Tygar, J.D. (2011). AISec\u201911: 4th ACM Workshop on Security and Artificial Intelligence, Association for Computing Machinery."},{"key":"ref_4","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015). Explaining and Harnessing Adversarial Examples. arXiv."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","article-title":"BadNets: Evaluating Backdooring Attacks on Deep Neural Networks","volume":"7","author":"Gu","year":"2019","journal-title":"IEEE Access"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D. (2018). Robust Physical-World Attacks on Deep Learning Models. arXiv.","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Yang, X., Liu, W., Zhang, S., Liu, W., and Tao, D. (2020). Targeted Attention Attack on Deep Learning Models in Road Sign Recognition. arXiv.","DOI":"10.1109\/JIOT.2020.3034899"},{"key":"ref_8","unstructured":"Boneh, D., DeMillo, R.A., and Lipton, R.J. (2001). Advances in Cryptology\u2014EUROCRYPT\u201997: International Conference on the Theory and Application of Cryptographic Techniques Konstanz, Germany, 11\u201315 May 1997, Springer."},{"key":"ref_9","unstructured":"Biham, E., and Shamir, A. (1997). Advances in Cryptology\u2014CRYPTO\u201997: 17th Annual International Cryptology Conference Santa Barbara, CA, USA, 17\u201321 August 1997, Springer."},{"key":"ref_10","unstructured":"Rakin, A.S., He, Z., and Fan, D. (November, January 27). Bit-flip attack: Crushing neural network with progressive bit search. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Seoul, Republic of Korea."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Zhao, P., Wang, S., Gongye, C., Wang, Y., Fei, Y., and Lin, X. (2019, January 2\u20136). Fault sneaking attack: A stealthy framework for misleading deep neural networks. Proceedings of the 56th Annual Design Automation Conference 2019, Las Vegas, NV, USA.","DOI":"10.1145\/3316781.3317825"},{"key":"ref_12","unstructured":"Breier, J., Hou, X., Jap, D., Ma, L., Bhasin, S., and Liu, Y. (2018). CCS\u201918: 2018 ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery."},{"key":"ref_13","first-page":"336","article-title":"Experimental Study of Fault Injection Attack on Image Sensor Interface for Triggering Backdoored DNN Models","volume":"105","author":"Oyama","year":"2021","journal-title":"IEICE Trans. Fundam. Electron. Commun. Comput. Sci."},{"key":"ref_14","unstructured":"Oyama, T., Okura, S., Yoshida, K., and Fujino, T. (2021). ASHES\u201921: 5th Workshop on Attacks and Solutions in Hardware Security, Association for Computing Machinery."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Oyama, T., Yoshida, K., Okura, S., and Fujino, T. (2022, January 14\u201316). Fundamental Study of Adversarial Examples Created by Fault Injection Attack on Image Sensor Interface. Proceedings of the 2022 Asian Hardware Oriented Security and Trust Symposium (AsianHOST), Singapore.","DOI":"10.1109\/AsianHOST56390.2022.10022189"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"323","DOI":"10.1016\/j.neunet.2012.02.016","article-title":"Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition","volume":"32","author":"Stallkamp","year":"2012","journal-title":"Neural Netw."},{"key":"ref_17","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., and Song, D. (2017). Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. arXiv."},{"key":"ref_18","unstructured":"Liu, Y., Ma, X., Bailey, J., and Lu, F. (2020). Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, 23\u201328 August 2020, Springer."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Li, Y., Hua, J., Wang, H., Chen, C., and Liu, Y. (2021, January 22\u201330). DeepPayload: Black-box Backdoor Attack on Deep Learning Models through Neural Payload Injection. Proceedings of the 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE), Madrid, Spain.","DOI":"10.1109\/ICSE43902.2021.00035"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Wenger, E., Passananti, J., Bhagoji, A., Yao, Y., Zheng, H., and Zhao, B.Y. (2020). Backdoor Attacks against Deep Learning Systems in the Physical World. arXiv.","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref_21","unstructured":"Li, H., Wang, Y., Xie, X., Liu, Y., Wang, S., Wan, R., Chau, L.P., and Kot, A.C. (2020). Light Can Hack Your Face! Black-box Backdoor Attack on Face Recognition Systems. arXiv."},{"key":"ref_22","unstructured":"Li, Y., Zhai, T., Wu, B., Jiang, Y., Li, Z., and Xia, S. (2021). Rethinking the Trigger of Backdoor Attack. arXiv."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"847","DOI":"10.1109\/LSP.2005.859503","article-title":"Frequency-domain methods for demosaicking of Bayer-sampled color images","volume":"12","author":"Dubois","year":"2005","journal-title":"IEEE Signal Process. Lett."},{"key":"ref_24","unstructured":"Simonyan, K., and Zisserman, A. (2015). Very Deep Convolutional Networks for Large-Scale Image Recognition. arXiv."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/10\/4742\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T19:34:44Z","timestamp":1760124884000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/10\/4742"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,14]]},"references-count":24,"journal-issue":{"issue":"10","published-online":{"date-parts":[[2023,5]]}},"alternative-id":["s23104742"],"URL":"https:\/\/doi.org\/10.3390\/s23104742","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2023,5,14]]}}}