{"id":"https://openalex.org/W7138902653","doi":"https://doi.org/10.1609/aaai.v40i42.40842","title":"MOBA: A Material-Oriented Backdoor Attack Against LiDAR-Based 3D Object Detection Systems","display_name":"MOBA: A Material-Oriented Backdoor Attack Against LiDAR-Based 3D Object Detection Systems","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7138902653","doi":"https://doi.org/10.1609/aaai.v40i42.40842"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i42.40842","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i42.40842","pdf_url":"https://ojs.aaai.org/index.php/AAAI/article/download/40842/44803","source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://ojs.aaai.org/index.php/AAAI/article/download/40842/44803","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5129955822","display_name":"Saket Sanjeev Chaturvedi","orcid":null},"institutions":[{"id":"https://openalex.org/I8078737","display_name":"Clemson University","ror":"https://ror.org/037s24f05","country_code":"US","type":"education","lineage":["https://openalex.org/I8078737"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Saket Sanjeev Chaturvedi","raw_affiliation_strings":["Clemson University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Clemson University","institution_ids":["https://openalex.org/I8078737"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073718577","display_name":"Gaurav Bagwe","orcid":"https://orcid.org/0000-0001-5706-5065"},"institutions":[{"id":"https://openalex.org/I8078737","display_name":"Clemson University","ror":"https://ror.org/037s24f05","country_code":"US","type":"education","lineage":["https://openalex.org/I8078737"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gaurav Bagwe","raw_affiliation_strings":["Clemson University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Clemson University","institution_ids":["https://openalex.org/I8078737"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130066014","display_name":"Lan Emily Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I8078737","display_name":"Clemson University","ror":"https://ror.org/037s24f05","country_code":"US","type":"education","lineage":["https://openalex.org/I8078737"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lan Emily Zhang","raw_affiliation_strings":["Clemson University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Clemson University","institution_ids":["https://openalex.org/I8078737"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129969272","display_name":"Pan He","orcid":null},"institutions":[{"id":"https://openalex.org/I82497590","display_name":"Auburn University","ror":"https://ror.org/02v80fc35","country_code":"US","type":"education","lineage":["https://openalex.org/I82497590"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Pan He","raw_affiliation_strings":["Auburn University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Auburn University","institution_ids":["https://openalex.org/I82497590"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5010643450","display_name":"Xiaoyong Yuan","orcid":"https://orcid.org/0000-0003-0782-4187"},"institutions":[{"id":"https://openalex.org/I8078737","display_name":"Clemson University","ror":"https://ror.org/037s24f05","country_code":"US","type":"education","lineage":["https://openalex.org/I8078737"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiaoyong Yuan","raw_affiliation_strings":["Clemson University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Clemson University","institution_ids":["https://openalex.org/I8078737"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.68471035,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"40","issue":"42","first_page":"35340","last_page":"35347"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6434000134468079,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6434000134468079,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.04690000042319298,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.045099999755620956,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9821000099182129},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6251000165939331},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.5677000284194946},{"id":"https://openalex.org/keywords/camouflage","display_name":"Camouflage","score":0.413100004196167},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.3709999918937683},{"id":"https://openalex.org/keywords/reflection","display_name":"Reflection (computer programming)","score":0.361299991607666},{"id":"https://openalex.org/keywords/consistency","display_name":"Consistency (knowledge bases)","score":0.35850000381469727},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.32429999113082886}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9821000099182129},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7092000246047974},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6251000165939331},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.5677000284194946},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4271000027656555},{"id":"https://openalex.org/C2776196576","wikidata":"https://www.wikidata.org/wiki/Q196113","display_name":"Camouflage","level":2,"score":0.413100004196167},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3903000056743622},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.3709999918937683},{"id":"https://openalex.org/C65682993","wikidata":"https://www.wikidata.org/wiki/Q1056451","display_name":"Reflection (computer programming)","level":2,"score":0.361299991607666},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.35850000381469727},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3449000120162964},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.33880001306533813},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.32429999113082886},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.3057999908924103},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.30559998750686646},{"id":"https://openalex.org/C2776151529","wikidata":"https://www.wikidata.org/wiki/Q3045304","display_name":"Object detection","level":3,"score":0.30230000615119934},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.2930000126361847},{"id":"https://openalex.org/C116672817","wikidata":"https://www.wikidata.org/wiki/Q1454986","display_name":"Physical system","level":2,"score":0.27619999647140503},{"id":"https://openalex.org/C179768478","wikidata":"https://www.wikidata.org/wiki/Q1120057","display_name":"Cyber-physical system","level":2,"score":0.27480000257492065},{"id":"https://openalex.org/C77714075","wikidata":"https://www.wikidata.org/wiki/Q5452017","display_name":"Firewall (physics)","level":5,"score":0.26460000872612},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.2624000012874603},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.26030001044273376},{"id":"https://openalex.org/C2780264999","wikidata":"https://www.wikidata.org/wiki/Q7445032","display_name":"Security domain","level":2,"score":0.2590000033378601},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.2549000084400177}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i42.40842","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i42.40842","pdf_url":"https://ojs.aaai.org/index.php/AAAI/article/download/40842/44803","source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i42.40842","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i42.40842","pdf_url":"https://ojs.aaai.org/index.php/AAAI/article/download/40842/44803","source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W7138902653.pdf","grobid_xml":"https://content.openalex.org/works/W7138902653.grobid-xml"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"LiDAR-based":[0,209],"3D":[1],"object":[2],"detection":[3],"is":[4,32],"widely":[5],"used":[6],"in":[7,49,105,251],"safety-critical":[8],"systems.":[9],"However,":[10],"these":[11],"systems":[12],"remain":[13],"vulnerable":[14],"to":[15,40,70,136,154,185,196],"backdoor":[16,30,107],"attacks":[17,31],"that":[18,86,174,215,246],"embed":[19],"hidden":[20],"malicious":[21],"behaviors":[22],"during":[23],"training.":[24],"A":[25],"key":[26,103],"limitation":[27],"of":[28,35,97,111,164,180,235],"existing":[29],"their":[33],"lack":[34],"physical":[36,106,123,162],"realizability,":[37],"primarily":[38],"due":[39],"the":[41,60,88,94,112,122,156,161,165,181,241],"digital-to-physical":[42],"domain":[43],"gap.":[44],"Digital":[45],"triggers":[46,65],"often":[47,67],"fail":[48],"real-world":[50,98,252],"settings":[51],"because":[52],"they":[53],"overlook":[54],"material-dependent":[55],"LiDAR":[56,188],"reflection":[57],"properties.":[58],"On":[59],"other":[61],"hand,":[62],"physically":[63,236],"constructed":[64],"are":[66],"unoptimized,":[68],"leading":[69],"low":[71],"effectiveness":[72],"or":[73],"easy":[74],"detectability.":[75],"This":[76],"paper":[77],"introduces":[78],"Material-Oriented":[79],"Backdoor":[80],"Attack":[81],"(MOBA),":[82],"a":[83,133,170,192,218,232],"novel":[84,171],"framework":[85],"bridges":[87],"digital\u2013physical":[89],"gap":[90],"by":[91,226],"explicitly":[92],"modeling":[93],"material":[95,114],"properties":[96,250],"triggers.":[99],"MOBA":[100,216],"tackles":[101],"two":[102],"challenges":[104],"design:":[108],"1)":[109],"robustness":[110],"trigger":[113,139,158],"under":[115],"diverse":[116],"environmental":[117,151],"conditions,":[118],"2)":[119],"alignment":[120],"between":[121],"trigger's":[124],"behavior":[125,163],"and":[126,150,190,210,239],"its":[127,146],"digital":[128,157],"simulation.":[129],"First,":[130],"we":[131,168],"propose":[132],"systematic":[134],"approach":[135],"selecting":[137],"robust":[138],"materials,":[140],"identifying":[141],"titanium":[142],"dioxide":[143],"(TiO\u2082)":[144],"for":[145,244,248],"high":[147],"diffuse":[148],"reflectivity":[149],"resilience.":[152],"Second,":[153],"ensure":[155],"accurately":[159],"mimics":[160],"material-based":[166],"trigger,":[167],"develop":[169],"simulation":[172],"pipeline":[173],"features:":[175],"(1)":[176],"an":[177],"angle-independent":[178],"approximation":[179],"Oren\u2013Nayar":[182],"BRDF":[183],"model":[184],"generate":[186],"realistic":[187],"intensities,":[189],"(2)":[191],"distance-aware":[193],"scaling":[194],"mechanism":[195],"maintain":[197],"spatial":[198],"consistency":[199],"across":[200],"varying":[201],"depths.":[202],"We":[203],"conduct":[204],"extensive":[205],"experiments":[206],"on":[207],"state-of-the-art":[208],"Camera-LiDAR":[211],"fusion":[212],"models,":[213],"showing":[214],"achieves":[217],"93.50%":[219],"attack":[220],"success":[221],"rate,":[222],"outperforming":[223],"prior":[224],"methods":[225],"over":[227],"41%.":[228],"Our":[229],"work":[230],"reveals":[231],"new":[233],"class":[234],"realizable":[237],"threats":[238],"underscores":[240],"urgent":[242],"need":[243],"defenses":[245],"account":[247],"material-level":[249],"environments.":[253]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-20T00:00:00"}
