{"id":"https://openalex.org/W4416238252","doi":"https://doi.org/10.48550/arxiv.2511.09999","title":"MOBA: A Material-Oriented Backdoor Attack against LiDAR-based 3D Object Detection Systems","display_name":"MOBA: A Material-Oriented Backdoor Attack against LiDAR-based 3D Object Detection Systems","publication_year":2025,"publication_date":"2025-11-13","ids":{"openalex":"https://openalex.org/W4416238252","doi":"https://doi.org/10.48550/arxiv.2511.09999"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2511.09999","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.09999","pdf_url":"https://arxiv.org/pdf/2511.09999","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2511.09999","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5057682656","display_name":"Saket S. Chaturvedi","orcid":"https://orcid.org/0000-0003-0700-404X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chaturvedi, Saket S.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073718577","display_name":"Gaurav Bagwe","orcid":"https://orcid.org/0000-0001-5706-5065"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bagwe, Gaurav","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101469408","display_name":"Lan Zhang","orcid":"https://orcid.org/0000-0002-1319-2596"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Lan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100839835","display_name":"He Pan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"He, Pan","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5010643450","display_name":"Xiaoyong Yuan","orcid":"https://orcid.org/0000-0003-0782-4187"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yuan, Xiaoyong","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6902999877929688,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6902999877929688,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.05040000006556511,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.03849999979138374,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9821000099182129},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6251000165939331},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.567799985408783},{"id":"https://openalex.org/keywords/camouflage","display_name":"Camouflage","score":0.413100004196167},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.3711000084877014},{"id":"https://openalex.org/keywords/reflection","display_name":"Reflection (computer programming)","score":0.3614000082015991},{"id":"https://openalex.org/keywords/consistency","display_name":"Consistency (knowledge bases)","score":0.35839998722076416},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.32429999113082886}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9821000099182129},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7089999914169312},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6251000165939331},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.567799985408783},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.42719998955726624},{"id":"https://openalex.org/C2776196576","wikidata":"https://www.wikidata.org/wiki/Q196113","display_name":"Camouflage","level":2,"score":0.413100004196167},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.39010000228881836},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.3711000084877014},{"id":"https://openalex.org/C65682993","wikidata":"https://www.wikidata.org/wiki/Q1056451","display_name":"Reflection (computer programming)","level":2,"score":0.3614000082015991},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.35839998722076416},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3449000120162964},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.33880001306533813},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.32429999113082886},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.3057999908924103},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.30550000071525574},{"id":"https://openalex.org/C2776151529","wikidata":"https://www.wikidata.org/wiki/Q3045304","display_name":"Object detection","level":3,"score":0.30239999294281006},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.2930000126361847},{"id":"https://openalex.org/C116672817","wikidata":"https://www.wikidata.org/wiki/Q1454986","display_name":"Physical system","level":2,"score":0.2761000096797943},{"id":"https://openalex.org/C179768478","wikidata":"https://www.wikidata.org/wiki/Q1120057","display_name":"Cyber-physical system","level":2,"score":0.27489998936653137},{"id":"https://openalex.org/C77714075","wikidata":"https://www.wikidata.org/wiki/Q5452017","display_name":"Firewall (physics)","level":5,"score":0.26460000872612},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.2624000012874603},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.2603999972343445},{"id":"https://openalex.org/C2780264999","wikidata":"https://www.wikidata.org/wiki/Q7445032","display_name":"Security domain","level":2,"score":0.2590999901294708},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.2547999918460846}],"mesh":[],"locations_count":3,"locations":[{"id":"pmh:oai:arXiv.org:2511.09999","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.09999","pdf_url":"https://arxiv.org/pdf/2511.09999","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"pmh:oai:ojs.aaai.org:article/40842","is_oa":false,"landing_page_url":"https://ojs.aaai.org/index.php/AAAI/article/view/40842","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"2159-5399","raw_type":"info:eu-repo/semantics/publishedVersion"},{"id":"doi:10.48550/arxiv.2511.09999","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2511.09999","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2511.09999","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2511.09999","pdf_url":"https://arxiv.org/pdf/2511.09999","source":{"id":"https://openalex.org/S4393918464","display_name":"ArXiv.org","issn_l":"2331-8422","issn":["2331-8422"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G7323074465","display_name":"CNS Core: Small: Privacy-Preserving On-Device Intelligence in the IoT Era","funder_award_id":"2444389","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4416238252.pdf"},"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"LiDAR-based":[0,208],"3D":[1],"object":[2],"detection":[3],"is":[4,32],"widely":[5],"used":[6],"in":[7,49,104,250],"safety-critical":[8],"systems.":[9],"However,":[10],"these":[11],"systems":[12],"remain":[13],"vulnerable":[14],"to":[15,40,70,135,153,184,195],"backdoor":[16,30,106],"attacks":[17,31],"that":[18,85,173,214,245],"embed":[19],"hidden":[20],"malicious":[21],"behaviors":[22],"during":[23],"training.":[24],"A":[25],"key":[26,102],"limitation":[27],"of":[28,35,96,110,163,179,234],"existing":[29],"their":[33],"lack":[34],"physical":[36,105,122,161],"realizability,":[37],"primarily":[38],"due":[39],"the":[41,60,87,93,111,121,155,160,164,180,240],"digital-to-physical":[42],"domain":[43],"gap.":[44],"Digital":[45],"triggers":[46,65],"often":[47,67],"fail":[48],"real-world":[50,97,251],"settings":[51],"because":[52],"they":[53],"overlook":[54],"material-dependent":[55],"LiDAR":[56,187],"reflection":[57],"properties.":[58],"On":[59],"other":[61],"hand,":[62],"physically":[63,235],"constructed":[64],"are":[66],"unoptimized,":[68],"leading":[69],"low":[71],"effectiveness":[72],"or":[73],"easy":[74],"detectability.This":[75],"paper":[76],"introduces":[77],"Material-Oriented":[78],"Backdoor":[79],"Attack":[80],"(MOBA),":[81],"a":[82,132,169,191,217,231],"novel":[83,170],"framework":[84],"bridges":[86],"digital-physical":[88],"gap":[89],"by":[90,225],"explicitly":[91],"modeling":[92],"material":[94,113],"properties":[95,249],"triggers.":[98],"MOBA":[99,215],"tackles":[100],"two":[101],"challenges":[103],"design:":[107],"1)":[108],"robustness":[109],"trigger":[112,138,157],"under":[114],"diverse":[115],"environmental":[116,150],"conditions,":[117],"2)":[118],"alignment":[119],"between":[120],"trigger's":[123],"behavior":[124,162],"and":[125,149,189,209,238],"its":[126,145],"digital":[127,156],"simulation.":[128],"First,":[129],"we":[130,167],"propose":[131],"systematic":[133],"approach":[134],"selecting":[136],"robust":[137],"materials,":[139],"identifying":[140],"titanium":[141],"dioxide":[142],"(TiO_2)":[143],"for":[144,243,247],"high":[146],"diffuse":[147],"reflectivity":[148],"resilience.":[151],"Second,":[152],"ensure":[154],"accurately":[158],"mimics":[159],"material-based":[165],"trigger,":[166],"develop":[168],"simulation":[171],"pipeline":[172],"features:":[174],"(1)":[175],"an":[176],"angle-independent":[177],"approximation":[178],"Oren-Nayar":[181],"BRDF":[182],"model":[183],"generate":[185],"realistic":[186],"intensities,":[188],"(2)":[190],"distance-aware":[192],"scaling":[193],"mechanism":[194],"maintain":[196],"spatial":[197],"consistency":[198],"across":[199],"varying":[200],"depths.":[201],"We":[202],"conduct":[203],"extensive":[204],"experiments":[205],"on":[206],"state-of-the-art":[207],"Camera-LiDAR":[210],"fusion":[211],"models,":[212],"showing":[213],"achieves":[216],"93.50%":[218],"attack":[219],"success":[220],"rate,":[221],"outperforming":[222],"prior":[223],"methods":[224],"over":[226],"41%.":[227],"Our":[228],"work":[229],"reveals":[230],"new":[232],"class":[233],"realizable":[236],"threats":[237],"underscores":[239],"urgent":[241],"need":[242],"defenses":[244],"account":[246],"material-level":[248],"environments.":[252]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-11-15T00:00:00"}
