{"id":"https://openalex.org/W4415821056","doi":"https://doi.org/10.1109/tits.2025.3616645","title":"Manipulating Trajectory Prediction Models With Backdoors","display_name":"Manipulating Trajectory Prediction Models With Backdoors","publication_year":2025,"publication_date":"2025-11-03","ids":{"openalex":"https://openalex.org/W4415821056","doi":"https://doi.org/10.1109/tits.2025.3616645"},"language":null,"primary_location":{"id":"doi:10.1109/tits.2025.3616645","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tits.2025.3616645","pdf_url":null,"source":{"id":"https://openalex.org/S144771191","display_name":"IEEE Transactions on Intelligent Transportation Systems","issn_l":"1524-9050","issn":["1524-9050","1558-0016"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Intelligent Transportation Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5063024690","display_name":"Kaouther Messaoud","orcid":"https://orcid.org/0000-0002-4602-8100"},"institutions":[{"id":"https://openalex.org/I5124864","display_name":"\u00c9cole Polytechnique F\u00e9d\u00e9rale de Lausanne","ror":"https://ror.org/02s376052","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I5124864"]}],"countries":["CH"],"is_corresponding":true,"raw_author_name":"Kaouther Messaoud","raw_affiliation_strings":["EPFL, Lausanne, Switzerland"],"affiliations":[{"raw_affiliation_string":"EPFL, Lausanne, Switzerland","institution_ids":["https://openalex.org/I5124864"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018930655","display_name":"Kathrin Grosse","orcid":"https://orcid.org/0000-0002-5401-4171"},"institutions":[{"id":"https://openalex.org/I4210126328","display_name":"IBM Research - Zurich","ror":"https://ror.org/02js37d36","country_code":"CH","type":"facility","lineage":["https://openalex.org/I1341412227","https://openalex.org/I4210114115","https://openalex.org/I4210126328"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Kathrin Grosse","raw_affiliation_strings":["IBM Research, Z&#x00FC;rich, Switzerland"],"affiliations":[{"raw_affiliation_string":"IBM Research, Z&#x00FC;rich, Switzerland","institution_ids":["https://openalex.org/I4210126328"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058389247","display_name":"Micka\u00ebl Chen","orcid":"https://orcid.org/0000-0002-3960-2389"},"institutions":[{"id":"https://openalex.org/I220619192","display_name":"Valeo (France)","ror":"https://ror.org/04ryqpf83","country_code":"FR","type":"company","lineage":["https://openalex.org/I220619192"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Micka\u00ebl Chen","raw_affiliation_strings":["Valeo.ai, Paris, France"],"affiliations":[{"raw_affiliation_string":"Valeo.ai, Paris, France","institution_ids":["https://openalex.org/I220619192"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108118084","display_name":"Matthieu Cord","orcid":"https://orcid.org/0000-0002-0627-5844"},"institutions":[{"id":"https://openalex.org/I220619192","display_name":"Valeo (France)","ror":"https://ror.org/04ryqpf83","country_code":"FR","type":"company","lineage":["https://openalex.org/I220619192"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Matthieu Cord","raw_affiliation_strings":["Valeo.ai, Paris, France"],"affiliations":[{"raw_affiliation_string":"Valeo.ai, Paris, France","institution_ids":["https://openalex.org/I220619192"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113908330","display_name":"Patrick P\u00e9rez","orcid":null},"institutions":[{"id":"https://openalex.org/I220619192","display_name":"Valeo (France)","ror":"https://ror.org/04ryqpf83","country_code":"FR","type":"company","lineage":["https://openalex.org/I220619192"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Patrick P\u00e9rez","raw_affiliation_strings":["Valeo.ai, Paris, France"],"affiliations":[{"raw_affiliation_string":"Valeo.ai, Paris, France","institution_ids":["https://openalex.org/I220619192"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5068504559","display_name":"Alexandre Alahi","orcid":"https://orcid.org/0000-0002-5004-1498"},"institutions":[{"id":"https://openalex.org/I5124864","display_name":"\u00c9cole Polytechnique F\u00e9d\u00e9rale de Lausanne","ror":"https://ror.org/02s376052","country_code":"CH","type":"education","lineage":["https://openalex.org/I2799323385","https://openalex.org/I5124864"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Alexandre Alahi","raw_affiliation_strings":["EPFL, Lausanne, Switzerland"],"affiliations":[{"raw_affiliation_string":"EPFL, Lausanne, Switzerland","institution_ids":["https://openalex.org/I5124864"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5063024690"],"corresponding_institution_ids":["https://openalex.org/I5124864"],"apc_list":null,"apc_paid":null,"fwci":0.7702,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.78483713,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":"26","issue":"12","first_page":"22962","last_page":"22973"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11099","display_name":"Autonomous Vehicle Technology and Safety","score":0.9121999740600586,"subfield":{"id":"https://openalex.org/subfields/2203","display_name":"Automotive Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11099","display_name":"Autonomous Vehicle Technology and Safety","score":0.9121999740600586,"subfield":{"id":"https://openalex.org/subfields/2203","display_name":"Automotive Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.04520000144839287,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10761","display_name":"Vehicular Ad Hoc Networks (VANETs)","score":0.00800000037997961,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9858999848365784},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.7484999895095825},{"id":"https://openalex.org/keywords/trajectory","display_name":"Trajectory","score":0.7107999920845032},{"id":"https://openalex.org/keywords/encoding","display_name":"Encoding (memory)","score":0.4246000051498413},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3788999915122986},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.31209999322891235}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9858999848365784},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.7484999895095825},{"id":"https://openalex.org/C13662910","wikidata":"https://www.wikidata.org/wiki/Q193139","display_name":"Trajectory","level":2,"score":0.7107999920845032},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.698199987411499},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.45489999651908875},{"id":"https://openalex.org/C125411270","wikidata":"https://www.wikidata.org/wiki/Q18653","display_name":"Encoding (memory)","level":2,"score":0.4246000051498413},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.40380001068115234},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3788999915122986},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3774000108242035},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.3192000091075897},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.31209999322891235},{"id":"https://openalex.org/C13687954","wikidata":"https://www.wikidata.org/wiki/Q4826847","display_name":"Autonomous agent","level":2,"score":0.2849999964237213},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.2782999873161316},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.25839999318122864}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tits.2025.3616645","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tits.2025.3616645","pdf_url":null,"source":{"id":"https://openalex.org/S144771191","display_name":"IEEE Transactions on Intelligent Transportation Systems","issn_l":"1524-9050","issn":["1524-9050","1558-0016"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Intelligent Transportation Systems","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":46,"referenced_works":["https://openalex.org/W2607296803","https://openalex.org/W2753783305","https://openalex.org/W2807363941","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2953920792","https://openalex.org/W2962687116","https://openalex.org/W2963001155","https://openalex.org/W2963906196","https://openalex.org/W2966682689","https://openalex.org/W2967177252","https://openalex.org/W2990270730","https://openalex.org/W3035574168","https://openalex.org/W3096024389","https://openalex.org/W3106646114","https://openalex.org/W3108486966","https://openalex.org/W3116515605","https://openalex.org/W3169575318","https://openalex.org/W3204875639","https://openalex.org/W3208246861","https://openalex.org/W3214950490","https://openalex.org/W4205346763","https://openalex.org/W4214483958","https://openalex.org/W4221156702","https://openalex.org/W4226239849","https://openalex.org/W4288057740","https://openalex.org/W4312366598","https://openalex.org/W4312730708","https://openalex.org/W4312731878","https://openalex.org/W4315630292","https://openalex.org/W4319300103","https://openalex.org/W4320736757","https://openalex.org/W4322736917","https://openalex.org/W4372260097","https://openalex.org/W4378976916","https://openalex.org/W4383172002","https://openalex.org/W4385221361","https://openalex.org/W4386066003","https://openalex.org/W4386076672","https://openalex.org/W4390871698","https://openalex.org/W4390872910","https://openalex.org/W4390873034","https://openalex.org/W4400645048","https://openalex.org/W4402727728","https://openalex.org/W4404769984","https://openalex.org/W4413156939"],"related_works":[],"abstract_inverted_index":{"Autonomous":[0],"vehicles":[1],"depend":[2],"on":[3,55],"accurate":[4],"trajectory":[5,147],"prediction":[6],"to":[7,18,98,145],"navigate":[8],"safely":[9],"in":[10,149],"complex":[11],"traffic.":[12],"Yet":[13],"current":[14],"models":[15],"are":[16],"vulnerable":[17],"stealthy":[19],"backdoor":[20,113,139],"attacks:":[21],"an":[22],"adversary":[23],"embeds":[24],"subtle,":[25],"physically":[26],"plausible":[27],"triggers":[28,114],"during":[29],"training":[30,76],"that":[31,69],"remain":[32],"latent":[33],"until":[34],"activated.":[35],"To":[36],"address":[37],"this":[38],"risk,":[39],"we":[40],"introduce":[41],"a":[42,86,142],"structured":[43],"framework":[44],"categorizing":[45],"four":[46],"trigger":[47],"types\u2014spatial,":[48],"kinetic":[49],"(braking),":[50],"coordinated,":[51],"and":[52,59,62,67,102,141],"composite\u2014and":[53],"demonstrate":[54],"two":[56,63],"benchmarks":[57],"(nuScenes":[58],"Argoverse":[60],"2)":[61],"state-of-the-art":[64],"architectures":[65],"(Autobot":[66],"Wayformer)":[68],"poisoning":[70],"as":[71,73],"little":[72],"5%":[74],"of":[75,138],"samples":[77],"can":[78],"reliably":[79],"hijack":[80],"future":[81],"predictions.":[82],"We":[83],"further":[84],"propose":[85],"real-time":[87],"defense":[88,123],"leveraging":[89],"social":[90],"attention:":[91],"by":[92],"encoding":[93],"agent":[94],"histories,":[95],"computing":[96],"cross-attention":[97],"the":[99,136],"target":[100],"vehicle,":[101],"filtering":[103],"out":[104],"agents":[105],"with":[106],"anomalously":[107],"high":[108],"weights,":[109],"our":[110,122],"method":[111],"neutralizes":[112],"without":[115],"degrading":[116],"clean-data":[117],"accuracy.":[118],"Comprehensive":[119],"experiments":[120],"show":[121],"reduces":[124],"attack":[125],"success":[126],"rates":[127],"across":[128],"diverse":[129],"urban":[130],"scenarios\u2014intersections,":[131],"roundabouts,":[132],"multi-lane":[133],"roads\u2014highlighting":[134],"both":[135],"severity":[137],"threats":[140],"promising":[143],"pathway":[144],"secure":[146],"predictors":[148],"autonomous":[150],"driving":[151],"systems.":[152]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-11-03T00:00:00"}
