{"id":"https://openalex.org/W4416251868","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228721","title":"ShrinkBox: Backdoor Attack on Object Detection to Disrupt Collision Avoidance in Machine Learning-based Advanced Driver Assistance Systems","display_name":"ShrinkBox: Backdoor Attack on Object Detection to Disrupt Collision Avoidance in Machine Learning-based Advanced Driver Assistance Systems","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4416251868","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228721"},"language":null,"primary_location":{"id":"doi:10.1109/ijcnn64981.2025.11228721","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228721","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102701994","display_name":"Muhammad Zaeem Shahzad","orcid":null},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Muhammad Zaeem Shahzad","raw_affiliation_strings":["New York University Abu Dhabi (NYUAD),eBRAIN Lab,UAE"],"affiliations":[{"raw_affiliation_string":"New York University Abu Dhabi (NYUAD),eBRAIN Lab,UAE","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100647460","display_name":"Muhammad Abdullah Hanif","orcid":"https://orcid.org/0000-0001-9841-6132"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Muhammad Abdullah Hanif","raw_affiliation_strings":["New York University Abu Dhabi (NYUAD),eBRAIN Lab,UAE"],"affiliations":[{"raw_affiliation_string":"New York University Abu Dhabi (NYUAD),eBRAIN Lab,UAE","institution_ids":["https://openalex.org/I57206974"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051699271","display_name":"Bassem Ouni","orcid":null},"institutions":[{"id":"https://openalex.org/I4210087059","display_name":"Technology Innovation Institute","ror":"https://ror.org/001kv2y39","country_code":"AE","type":"facility","lineage":["https://openalex.org/I4210087059"]}],"countries":["AE"],"is_corresponding":false,"raw_author_name":"Bassem Ouni","raw_affiliation_strings":["Technology Innovation Institute (TII),AI and Digital Science Research Center,Abu Dhabi,UAE"],"affiliations":[{"raw_affiliation_string":"Technology Innovation Institute (TII),AI and Digital Science Research Center,Abu Dhabi,UAE","institution_ids":["https://openalex.org/I4210087059"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5005190949","display_name":"Muhammad Shafique","orcid":"https://orcid.org/0000-0002-2607-8135"},"institutions":[{"id":"https://openalex.org/I57206974","display_name":"New York University","ror":"https://ror.org/0190ak572","country_code":"US","type":"education","lineage":["https://openalex.org/I57206974"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Muhammad Shafique","raw_affiliation_strings":["New York University Abu Dhabi (NYUAD),eBRAIN Lab,UAE"],"affiliations":[{"raw_affiliation_string":"New York University Abu Dhabi (NYUAD),eBRAIN Lab,UAE","institution_ids":["https://openalex.org/I57206974"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5102701994"],"corresponding_institution_ids":["https://openalex.org/I57206974"],"apc_list":null,"apc_paid":null,"fwci":2.8331,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.93089844,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8375999927520752,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.8375999927520752,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.09430000185966492,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11099","display_name":"Autonomous Vehicle Technology and Safety","score":0.021700000390410423,"subfield":{"id":"https://openalex.org/subfields/2203","display_name":"Automotive Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.8220000267028809},{"id":"https://openalex.org/keywords/collision-avoidance","display_name":"Collision avoidance","score":0.649399995803833},{"id":"https://openalex.org/keywords/object-detection","display_name":"Object detection","score":0.6126999855041504},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.574400007724762},{"id":"https://openalex.org/keywords/bounding-overwatch","display_name":"Bounding overwatch","score":0.5449000000953674},{"id":"https://openalex.org/keywords/collision","display_name":"Collision","score":0.5306000113487244},{"id":"https://openalex.org/keywords/collision-avoidance-system","display_name":"Collision avoidance system","score":0.4916999936103821},{"id":"https://openalex.org/keywords/radar","display_name":"Radar","score":0.4478999972343445},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3995000123977661}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.8220000267028809},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6582000255584717},{"id":"https://openalex.org/C2780864053","wikidata":"https://www.wikidata.org/wiki/Q5147495","display_name":"Collision avoidance","level":3,"score":0.649399995803833},{"id":"https://openalex.org/C2776151529","wikidata":"https://www.wikidata.org/wiki/Q3045304","display_name":"Object detection","level":3,"score":0.6126999855041504},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.574400007724762},{"id":"https://openalex.org/C63584917","wikidata":"https://www.wikidata.org/wiki/Q333286","display_name":"Bounding overwatch","level":2,"score":0.5449000000953674},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.534600019454956},{"id":"https://openalex.org/C121704057","wikidata":"https://www.wikidata.org/wiki/Q352070","display_name":"Collision","level":2,"score":0.5306000113487244},{"id":"https://openalex.org/C2777016798","wikidata":"https://www.wikidata.org/wiki/Q2001988","display_name":"Collision avoidance system","level":4,"score":0.4916999936103821},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.47929999232292175},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.45739999413490295},{"id":"https://openalex.org/C554190296","wikidata":"https://www.wikidata.org/wiki/Q47528","display_name":"Radar","level":2,"score":0.4478999972343445},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3995000123977661},{"id":"https://openalex.org/C94915269","wikidata":"https://www.wikidata.org/wiki/Q1834857","display_name":"Detector","level":2,"score":0.36739999055862427},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.3634999990463257},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.36320000886917114},{"id":"https://openalex.org/C146849305","wikidata":"https://www.wikidata.org/wiki/Q370766","display_name":"Ground truth","level":2,"score":0.35280001163482666},{"id":"https://openalex.org/C51399673","wikidata":"https://www.wikidata.org/wiki/Q504027","display_name":"Lidar","level":2,"score":0.34599998593330383},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.34220001101493835},{"id":"https://openalex.org/C199668693","wikidata":"https://www.wikidata.org/wiki/Q1550329","display_name":"Collision detection","level":3,"score":0.3418000042438507},{"id":"https://openalex.org/C183469790","wikidata":"https://www.wikidata.org/wiki/Q333501","display_name":"Crash","level":2,"score":0.3228999972343445},{"id":"https://openalex.org/C147037132","wikidata":"https://www.wikidata.org/wiki/Q6865426","display_name":"Minimum bounding box","level":3,"score":0.30379998683929443},{"id":"https://openalex.org/C145804949","wikidata":"https://www.wikidata.org/wiki/Q478123","display_name":"Situation awareness","level":2,"score":0.3037000000476837},{"id":"https://openalex.org/C87833898","wikidata":"https://www.wikidata.org/wiki/Q1060280","display_name":"Advanced driver assistance systems","level":2,"score":0.30309998989105225},{"id":"https://openalex.org/C52102323","wikidata":"https://www.wikidata.org/wiki/Q1671968","display_name":"Pose","level":2,"score":0.302700012922287},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.2775000035762787},{"id":"https://openalex.org/C2780704645","wikidata":"https://www.wikidata.org/wiki/Q9251458","display_name":"Observer (physics)","level":2,"score":0.2587999999523163},{"id":"https://openalex.org/C79337645","wikidata":"https://www.wikidata.org/wiki/Q779824","display_name":"Outlier","level":2,"score":0.25589999556541443},{"id":"https://openalex.org/C25344961","wikidata":"https://www.wikidata.org/wiki/Q192726","display_name":"Virtual machine","level":2,"score":0.2515999972820282}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn64981.2025.11228721","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228721","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":11,"referenced_works":["https://openalex.org/W2150066425","https://openalex.org/W2942091739","https://openalex.org/W2963488291","https://openalex.org/W2985775862","https://openalex.org/W3042368254","https://openalex.org/W4210733301","https://openalex.org/W4320002812","https://openalex.org/W4320736757","https://openalex.org/W4386076325","https://openalex.org/W4403770406","https://openalex.org/W4405786343"],"related_works":[],"abstract_inverted_index":{"Advanced":[0],"Driver":[1],"Assistance":[2],"Systems":[3],"(ADAS)":[4],"significantly":[5],"enhance":[6],"road":[7],"safety":[8],"by":[9,118,234],"detecting":[10],"potential":[11],"collisions":[12],"and":[13,26,33,69,87,108,165],"alerting":[14],"drivers.":[15],"However,":[16,110],"their":[17,71],"reliance":[18],"on":[19,97,238],"expensive":[20],"sensor":[21],"technologies":[22],"such":[23],"as":[24],"LiDAR":[25],"radar":[27],"limits":[28],"accessibility,":[29],"particularly":[30],"in":[31,121,137,162,181,200,215,230,243],"low-":[32],"middle-income":[34],"countries.":[35],"Machine":[36],"learning-based":[37],"ADAS":[38],"(ML-ADAS),":[39],"leveraging":[40],"deep":[41],"neural":[42],"networks":[43],"(DNNs)":[44],"with":[45,77,194],"only":[46,195],"standard":[47,166],"camera":[48],"input,":[49],"offers":[50],"a":[51,89,130,196],"cost-effective":[52],"alternative.":[53],"Critical":[54],"to":[55,66],"ML-ADAS":[56],"is":[57,75,116],"the":[58,64,102,111,182,201,205,210,225],"collision":[59,138,248],"avoidance":[60,139],"feature,":[61],"which":[62,82],"requires":[63],"ability":[65],"detect":[67],"objects":[68],"estimate":[70],"distances":[72],"accurately.":[73],"This":[74,158],"achieved":[76],"specialized":[78],"DNNs":[79],"like":[80,104],"YOLO,":[81],"provides":[83],"real-time":[84],"object":[85,122,135,146,184],"detection,":[86],"DECADE,":[88],"lightweight,":[90],"detection-wise":[91],"distance":[92,172,232],"estimation":[93,233],"approach":[94],"that":[95,144,176,222],"relies":[96],"key":[98],"features":[99],"extracted":[100],"from":[101],"detections":[103],"bounding":[105,156],"box":[106],"dimensions":[107],"size.":[109],"robustness":[112],"of":[113,192,204,247],"these":[114],"systems":[115],"undermined":[117],"security":[119],"vulnerabilities":[120],"detectors.":[123],"In":[124],"this":[125],"paper,":[126],"we":[127,220],"introduce":[128],"ShrinkBox,":[129],"novel":[131],"backdoor":[132],"attack":[133,159],"targeting":[134],"detection":[136],"ML-ADAS.":[140],"Unlike":[141],"existing":[142],"attacks":[143],"manipulate":[145],"class":[147],"labels":[148],"or":[149,245],"presence,":[150],"ShrinkBox":[151,177,223],"subtly":[152],"shrinks":[153],"ground":[154],"truth":[155],"boxes.":[157],"remains":[160],"undetected":[161],"dataset":[163],"inspections":[164],"benchmarks":[167],"while":[168],"severely":[169],"disrupting":[170],"downstream":[171],"estimation.":[173],"We":[174],"demonstrate":[175],"can":[178],"be":[179],"realized":[180],"YOLOv9m":[183],"detector":[185],"at":[186],"an":[187],"Attack":[188],"Success":[189],"Rate":[190],"(ASR)":[191],"96%,":[193],"4%":[197],"poisoning":[198,218],"ratio":[199],"training":[202],"instances":[203],"KITTI":[206],"dataset.":[207],"Furthermore,":[208],"given":[209],"low":[211],"error":[212],"targets":[213],"introduced":[214],"our":[216],"relaxed":[217],"strategy,":[219],"find":[221],"increases":[224],"Mean":[226],"Absolute":[227],"Error":[228],"(MAE)":[229],"DECADE\u2019s":[231],"more":[235],"than":[236],"3x":[237],"poisoned":[239],"samples,":[240],"potentially":[241],"resulting":[242],"delays":[244],"prevention":[246],"warnings":[249],"altogether.":[250]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-11-14T00:00:00"}
