{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T10:14:38Z","timestamp":1778148878895,"version":"3.51.4"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030624590","type":"print"},{"value":"9783030624606","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-62460-6_51","type":"book-chapter","created":{"date-parts":[[2020,11,10]],"date-time":"2020-11-10T10:03:00Z","timestamp":1605002580000},"page":"572-582","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Adversarial Example Attacks in the Physical World"],"prefix":"10.1007","author":[{"given":"Huali","family":"Ren","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Teng","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,11,11]]},"reference":[{"key":"51_CR1","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I, et al.: Intriguing properties of neural networks. arXiv: Computer Vision and Pattern Recognition (2013)"},{"key":"51_CR2","unstructured":"Goodfellow, I., Shlens, J., Szegedy C., et al.: Explaining and harnessing adversarial examples. arXiv: Machine Learning (2014)"},{"key":"51_CR3","unstructured":"Kurakin, A., Goodfellow, I., Bengio, S., et al.: Adversarial examples in the physical world. arXiv: Computer Vision and Pattern Recognition (2016)"},{"key":"51_CR4","doi-asserted-by":"crossref","unstructured":"Moosavidezfooli, S., Fawzi, A., Fawzi, O., et al.: Universal Adversarial Perturbations. In: Computer Vision and Pattern Recognition, pp. 86\u201394 (2017)","DOI":"10.1109\/CVPR.2017.17"},{"key":"51_CR5","doi-asserted-by":"crossref","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., et al.: Robust Physical-world attacks on deep learning visual classification. In: Computer Vision and Pattern Recognition, pp. 1625\u20131634 (2018)","DOI":"10.1109\/CVPR.2018.00175"},{"key":"51_CR6","unstructured":"Zhou, H., Li, W., Zhu, Y., et al.: DeepBillboard: systematic physical-world testing of autonomous driving systems. arXiv: Computer Vision and Pattern Recognition (2018)"},{"key":"51_CR7","doi-asserted-by":"crossref","unstructured":"Thys, S., Van Ranst, W., Goedeme, T., et al.: Fooling automated surveillance cameras: adversarial patches to attack person detection. arXiv: Computer Vision and Pattern Recognition (2019)","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"51_CR8","doi-asserted-by":"crossref","unstructured":"Liu, A., Fan, J., Ma, Y., et al.: Perceptual-sensitive GAN for generating adversarial patches. In: National Conference on Artificial Intelligence, vol. 33(01), pp. 1028\u20131035 (2019)","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"51_CR9","doi-asserted-by":"crossref","unstructured":"Wu, Z., Lim, S., Davis, L.S, et al.: Making an invisibility cloak: real world adversarial attacks on object detectors. arXiv: Computer Vision and Pattern Recognition (2019)","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"51_CR10","unstructured":"Li, J., Schmidt, F.R., Kolter, Z., et al.: Adversarial camera stickers: a physical camera-based attack on deep learning systems. arXiv: Computer Vision and Pattern Recognition (2019)"},{"key":"51_CR11","unstructured":"Cao, Y., Xiao, C., Yang, D., et al.: Adversarial objects against LiDAR-based autonomous driving systems. arXiv: Cryptography and Security (2019)"},{"key":"51_CR12","doi-asserted-by":"crossref","unstructured":"Cao, Y., Xiao, C., Cyr, B., et al.: Adversarial sensor attack on LiDAR-based perception in autonomous driving. In: Computer And Communications Security, pp. 2267\u20132281 (2019)","DOI":"10.1145\/3319535.3339815"},{"key":"51_CR13","doi-asserted-by":"crossref","unstructured":"Tu, J., et al.: Physically realizable adversarial examples for lidarobject detection. CoRR, abs\/2004.0054 (2020)","DOI":"10.1109\/CVPR42600.2020.01373"},{"key":"51_CR14","doi-asserted-by":"crossref","unstructured":"Moosavidezfooli, S., Fawzi, A., Frossard, P., et al.: DeepFool: a simple and accurate method to fool deep neural networks. In: Computer Vision and Pattern Recognition, pp. 2574\u20132582 (2016)","DOI":"10.1109\/CVPR.2016.282"},{"key":"51_CR15","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: IEEE Symposium on Security And Privacy, pp. 39\u201357 (2017)","DOI":"10.1109\/SP.2017.49"},{"issue":"5","key":"51_CR16","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su, J., Vargas, D.V., Sakurai, K., et al.: One pixel attack for fooling deep neural networks. IEEE Trans. Evol. Comput. 23(5), 828\u2013841 (2019)","journal-title":"IEEE Trans. Evol. Comput."},{"key":"51_CR17","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., et al.: Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition. In: Computer and Communications Security, pp. 1528\u20131540 (2016)","DOI":"10.1145\/2976749.2978392"},{"key":"51_CR18","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"51_CR19","unstructured":"Sutskever, I., Vinyals, O. Le, Q.V.: Sequence to sequence learning with neural networks. In: NIPS (2014)"},{"issue":"6","key":"51_CR20","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1109\/MSP.2012.2205597","volume":"29","author":"G Hinton","year":"2012","unstructured":"Hinton, G., Deng, L., Yu, D., et al.: Deep neural networks for acoustic modeling in speech recognition: the shared views of four research groups. IEEE Signal Process. Mag. 29(6), 82\u201397 (2012)","journal-title":"IEEE Signal Process. Mag."},{"issue":"11","key":"51_CR21","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y Lecun","year":"1998","unstructured":"Lecun, Y., Bottou, L.: Gradient-based learning applied to document recognition. IEEE 86(11), 2278\u20132324 (1998)","journal-title":"IEEE"},{"key":"51_CR22","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition (2014). arXiv:1409.1556"},{"key":"51_CR23","doi-asserted-by":"crossref","unstructured":"Krizhevsky, A., Sutskever, I., Hinton, G.: Imagenet classification with deep convolutional neural networks. Commun. ACM, 60(6), 84\u201390 (2017)","DOI":"10.1145\/3065386"},{"key":"51_CR24","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., et al.: The limitations of deep learning in adversarial settings. In: 2016 IEEE European symposium on security and privacy (EuroS&P), pp. 372\u2013387(2016)","DOI":"10.1109\/EuroSP.2016.36"},{"key":"51_CR25","doi-asserted-by":"crossref","unstructured":"Xie, C., Zhang, Z., Zhou, Y., et al.: Improving transferability of adversarial examples with input diversity. In: Computer Vision and Pattern Recognition, pp. 2730\u20132739 (2019)","DOI":"10.1109\/CVPR.2019.00284"},{"key":"51_CR26","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., et al.: Deep residual learning for image recognition. In: IEEE conference on computer vision and pattern recognition. IEEE Computer Society, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"51_CR27","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., et al.: Synthesizing robust adversarial examples. In: International conference on machine learning. pp. 284\u2013293 (2018)"},{"issue":"7553","key":"51_CR28","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y LeCun","year":"2015","unstructured":"LeCun, Y., Bengio, Y., Hinton, G.: Deep learning. Nature 521(7553), 436\u2013444 (2015)","journal-title":"Nature"},{"key":"51_CR29","doi-asserted-by":"crossref","unstructured":"Girshick, R.: Fast R-CNN. In: IEEE international conference on computer vision. pp.1440\u20131448 (2015)","DOI":"10.1109\/ICCV.2015.169"},{"issue":"6","key":"51_CR30","doi-asserted-by":"publisher","first-page":"1137","DOI":"10.1109\/TPAMI.2016.2577031","volume":"39","author":"S Ren","year":"2017","unstructured":"Ren, S., He, K., Girshick, R., et al.: Faster R-CNN: towards real-time object detection with region proposal networks. IEEE Trans. Pattern Anal. Mach. Intell. 39(6), 1137\u20131149 (2017)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"51_CR31","doi-asserted-by":"crossref","unstructured":"He, K., Gkioxari, G., Doll\u00e1r, P., et al.: Mask R-CNN. In: 2017 IEEE International Conference on Computer Vision (ICCV). IEEE (2017)","DOI":"10.1109\/ICCV.2017.322"},{"key":"51_CR32","doi-asserted-by":"crossref","unstructured":"Redmon, J., Farhadi, A.: YOLO9000: better, faster, stronger, pp. 6517\u20136525 (2017)","DOI":"10.1109\/CVPR.2017.690"},{"key":"51_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1007\/978-3-319-46448-0_2","volume-title":"Computer Vision \u2013 ECCV 2016","author":"W Liu","year":"2016","unstructured":"Liu, W., et al.: SSD: single shot multibox detector. In: Leibe, B., Matas, J., Sebe, N., Welling, M. (eds.) ECCV 2016. LNCS, vol. 9905, pp. 21\u201337. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-46448-0_2"}],"container-title":["Lecture Notes in Computer Science","Machine Learning for Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-62460-6_51","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,10]],"date-time":"2020-11-10T10:39:06Z","timestamp":1605004746000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-62460-6_51"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030624590","9783030624606"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-62460-6_51","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"11 November 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ML4CS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Machine Learning for Cyber Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Guangzhou","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"8 October 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 October 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ml4cs2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/nsclab.org\/ml4cs2020\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"360","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"118","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"40","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"33% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.2","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"8","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}