{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T16:59:47Z","timestamp":1783529987620,"version":"3.55.0"},"publisher-location":"Cham","reference-count":47,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031200649","type":"print"},{"value":"9783031200656","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-20065-6_3","type":"book-chapter","created":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T20:24:03Z","timestamp":1667420643000},"page":"36-52","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":67,"title":["AdvDO: Realistic Adversarial Attacks for\u00a0Trajectory Prediction"],"prefix":"10.1007","author":[{"given":"Yulong","family":"Cao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaowei","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anima","family":"Anandkumar","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Danfei","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marco","family":"Pavone","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,11,3]]},"reference":[{"key":"3_CR1","doi-asserted-by":"crossref","unstructured":"Alahi, A., Goel, K., Ramanathan, V., Robicquet, A., Fei-Fei, L., Savarese, S.: Social LSTM: human trajectory prediction in crowded spaces. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 961\u2013971 (2016)","DOI":"10.1109\/CVPR.2016.110"},{"key":"3_CR2","doi-asserted-by":"crossref","unstructured":"Ivanovic, B., Pavone, M.: The trajectron: probabilistic multi-agent trajectory modeling with dynamic spatiotemporal graphs. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 2375\u20132384 (2019)","DOI":"10.1109\/ICCV.2019.00246"},{"key":"3_CR3","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"683","DOI":"10.1007\/978-3-030-58523-5_40","volume-title":"Computer Vision \u2013 ECCV 2020","author":"T Salzmann","year":"2020","unstructured":"Salzmann, T., Ivanovic, B., Chakravarty, P., Pavone, M.: Trajectron++: dynamically-feasible trajectory forecasting with heterogeneous data. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12363, pp. 683\u2013700. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58523-5_40"},{"key":"3_CR4","doi-asserted-by":"crossref","unstructured":"Yuan, Y., Weng, X., Ou, Y., Kitani, K.: AgentFormer: agent-aware transformers for socio-temporal multi-agent forecasting. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV) (2021)","DOI":"10.1109\/ICCV48922.2021.00967"},{"key":"3_CR5","doi-asserted-by":"crossref","unstructured":"Rhinehart, N., Kitani, K.M., Vernaza, P.: R2P2: a reparameterized pushforward policy for diverse, precise generative path forecasting. In: Proceedings of the European Conference on Computer Vision (ECCV), pp. 772\u2013788 (2018)","DOI":"10.1007\/978-3-030-01261-8_47"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Rhinehart, N., McAllister, R., Kitani, K., Levine, S.: PRECOG: prediction conditioned on goals in visual multi-agent settings. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 2821\u20132830 (2019)","DOI":"10.1109\/ICCV.2019.00291"},{"key":"3_CR7","first-page":"1","volume":"32","author":"V Kosaraju","year":"2019","unstructured":"Kosaraju, V., Sadeghian, A., Mart\u00edn-Mart\u00edn, R., Reid, I., Rezatofighi, H., Savarese, S.: Social-BiGAT: multimodal trajectory forecasting using bicycle-GAN and graph attention networks. Adv. Neural Inf. Proc. Syst. 32, 1\u201310 (2019)","journal-title":"Adv. Neural Inf. Proc. Syst."},{"key":"3_CR8","doi-asserted-by":"crossref","unstructured":"Ivanovic, B., Pavone, M.: Injecting planning-awareness into prediction and detection evaluation. CoRR, abs\/2110.03270 (2021)","DOI":"10.1109\/IV51971.2022.9827101"},{"key":"3_CR9","doi-asserted-by":"crossref","unstructured":"Holger Caesar, et al.: nuScenes: a multimodal dataset for autonomous driving. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 11621\u201311631 (2020)","DOI":"10.1109\/CVPR42600.2020.01164"},{"key":"3_CR10","unstructured":"N., Deo, Wolff, E., Beijbom, O.: Multimodal trajectory prediction conditioned on lane-graph traversals. In: 5th Annual Conference on Robot Learning (2021)"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Suo, S., Regalado, S., Casas, S., Urtasun, R.: Trafficsim: learning to simulate realistic multi-agent behaviors. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 10400\u201310409 (2021)","DOI":"10.1109\/CVPR46437.2021.01026"},{"key":"3_CR12","doi-asserted-by":"crossref","unstructured":"Ding, W., Chen, B., Xu, M., Zhao, D.: Learning to collide: an adaptive safety-critical scenarios generating method. In: 2020 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS), pp. 2243\u20132250. IEEE (2020)","DOI":"10.1109\/IROS45743.2020.9340696"},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"Koren, M., Kochenderfer, M.J.: Efficient autonomy validation in simulation with adaptive stress testing. In: 2019 IEEE Intelligent Transportation Systems Conference (ITSC), pp. 4178\u20134183. IEEE (2019)","DOI":"10.1109\/ITSC.2019.8917403"},{"issue":"2","key":"3_CR14","doi-asserted-by":"publisher","first-page":"1551","DOI":"10.1109\/LRA.2021.3058873","volume":"6","author":"W Ding","year":"2021","unstructured":"Ding, W., Chen, B., Li, B., Eun, K.J., Zhao, D.: Multimodal safety-critical scenarios generation for decision-making algorithms evaluation. IEEE Robot. Autom. Lett. 6(2), 1551\u20131558 (2021)","journal-title":"IEEE Robot. Autom. Lett."},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"Abeysirigoonawardena, Y., Shkurti, F., Dudek, G.: Generating adversarial driving scenarios in high-fidelity simulators. In: 2019 International Conference on Robotics and Automation (ICRA), pp. 8271\u20138277. IEEE (2019)","DOI":"10.1109\/ICRA.2019.8793740"},{"key":"3_CR16","doi-asserted-by":"crossref","unstructured":"Rempe, D., Philion, J., Guibas, L.J., Fidler, S., Litany, O.: Generating useful accident-prone driving scenarios via a learned traffic prior. arXiv:2112.05077 (2021)","DOI":"10.1109\/CVPR52688.2022.01679"},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Wang, J., et al.: AdvSim: generating safety-critical scenarios for self-driving vehicles. In: Proceedings of the Conference on Computer Vision and Pattern Recognition (CVPR) (2021)","DOI":"10.1109\/CVPR46437.2021.00978"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Zhang, Q., Hu, S., Sun, J., Chen, Q.A., Mao, Z.M.: On adversarial robustness of trajectory prediction for autonomous vehicles. CoRR, abs\/2201.05057 (2022)","DOI":"10.1109\/CVPR52688.2022.01473"},{"key":"3_CR19","unstructured":"Carlini, N., et al.: On evaluating adversarial robustness. arXiv preprint arXiv:1902.06705 (2019)"},{"key":"3_CR20","unstructured":"Demontis, A., et al. Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 321\u2013338, Santa Clara, CA, August 2019. USENIX Association"},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"3_CR22","doi-asserted-by":"crossref","unstructured":"Xiao, C., Li, B., Zhu, J.-Y., He, W., Liu, M., Song, D.: Generating adversarial examples with adversarial networks. arXiv preprint arXiv:1801.02610 (2018)","DOI":"10.24963\/ijcai.2018\/543"},{"key":"3_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"681","DOI":"10.1007\/978-3-030-58574-7_41","volume-title":"Computer Vision \u2013 ECCV 2020","author":"C Yang","year":"2020","unstructured":"Yang, C., Kortylewski, A., Xie, C., Cao, Y., Yuille, A.: PatchAttack: a black-box texture-based attack with reinforcement learning. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12371, pp. 681\u2013698. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58574-7_41"},{"key":"3_CR24","doi-asserted-by":"crossref","unstructured":"Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., Yuille, A.: Adversarial examples for semantic segmentation and object detection. In: International Conference on Computer Vision. IEEE (2017)","DOI":"10.1109\/ICCV.2017.153"},{"key":"3_CR25","doi-asserted-by":"crossref","unstructured":"Huang, L., et al.: Universal physical camouflage attacks on object detectors (2019)","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"3_CR26","doi-asserted-by":"crossref","unstructured":"Huang, L., et al.: Universal physical camouflage attacks on object detectors. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 720\u2013729 (2020)","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"3_CR27","doi-asserted-by":"crossref","unstructured":"Xiang, C., Qi, C.R., Li, B.: Generating 3D adversarial point clouds. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 9136\u20139144 (2019)","DOI":"10.1109\/CVPR.2019.00935"},{"key":"3_CR28","unstructured":"Wen, Y., Lin, J., Chen, K., Jia, K.: Geometry-aware generation of adversarial and cooperative point clouds (2019)"},{"key":"3_CR29","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"241","DOI":"10.1007\/978-3-030-58610-2_15","volume-title":"Computer Vision \u2013 ECCV 2020","author":"A Hamdi","year":"2020","unstructured":"Hamdi, A., Rojas, S., Thabet, A., Ghanem, B.: AdvPC: transferable adversarial perturbations on 3D point clouds. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12357, pp. 241\u2013257. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58610-2_15"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Xiao, C., Yang, D., Li, B., Deng, J., Liu, M.: MeshAdv: adversarial meshes for visual recognition. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 6898\u20136907 (2019)","DOI":"10.1109\/CVPR.2019.00706"},{"issue":"1","key":"3_CR31","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s42979-020-00390-x","volume":"2","author":"A Noack","year":"2021","unstructured":"Noack, A., Ahern, I., Dou, D., Li, B.: An empirical study on the relation between network interpretability and adversarial robustness. SN Comput. Sci. 2(1), 1\u201313 (2021). https:\/\/doi.org\/10.1007\/s42979-020-00390-x","journal-title":"SN Comput. Sci."},{"key":"3_CR32","first-page":"12836","volume":"34","author":"A Sarkar","year":"2021","unstructured":"Sarkar, A., Sarkar, A., Gali, S., Balasubramanian, V.N.: Adversarial robustness without adversarial training: a teacher-guided curriculum learning approach. Adv. Neural Inf. Proc. Syst. 34, 12836\u201312848 (2021)","journal-title":"Adv. Neural Inf. Proc. Syst."},{"key":"3_CR33","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: International Conference on Learning Representations (2018)"},{"key":"3_CR34","unstructured":"Yang, Y., Zhang, G., Katabi, D., Xu, Z.: Me-Net: towards effective adversarial robustness with matrix estimation. arXiv preprint arXiv:1905.11971 (2019)"},{"key":"3_CR35","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., Qi, Y.: Feature squeezing: detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155 (2017)","DOI":"10.14722\/ndss.2018.23198"},{"key":"3_CR36","unstructured":"Bafna, M., Murtagh, J., Vyas, N.: Thwarting adversarial examples: an $$ l_0 $$-robustsparse fourier transform. arXiv preprint arXiv:1812.05013 (2018)"},{"key":"3_CR37","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., Swami, A.: Distillation as a defense to adversarial perturbations against deep neural networks. In: 2016 IEEE Symposium on Security and Privacy (SP), pp. 582\u2013597. IEEE (2016)","DOI":"10.1109\/SP.2016.41"},{"key":"3_CR38","doi-asserted-by":"crossref","unstructured":"Meng, D., Chen, H.: Magnet: a two-pronged defense against adversarial examples. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 135\u2013147 (2017)","DOI":"10.1145\/3133956.3134057"},{"key":"3_CR39","unstructured":"Zhang, H., et al.: Towards stable and efficient training of verifiably robust neural networks. arXiv preprint arXiv:1906.06316 (2019)"},{"key":"3_CR40","unstructured":"Zhang, H., Chen, H., Xiao, C., Li, B., Boning, D.S., Hsieh, C.J.: Robust deep reinforcement learning against adversarial perturbations on observations (2020)"},{"key":"3_CR41","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"3_CR42","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"3_CR43","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: revisiting adversarial training. arXiv preprint arXiv:2001.03994 (2020)"},{"key":"3_CR44","unstructured":"Shafahi, A., et al.: Adversarial training for free! arXiv preprint arXiv:1904.12843 (2019)"},{"key":"3_CR45","doi-asserted-by":"crossref","unstructured":"Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., Yuille, A.: Adversarial examples for semantic segmentation and object detection. In: IEEE International Conference on Computer Vision (ICCV) (2017)","DOI":"10.1109\/ICCV.2017.153"},{"issue":"4","key":"3_CR46","doi-asserted-by":"publisher","first-page":"656","DOI":"10.1002\/j.1538-7305.1949.tb00928.x","volume":"28","author":"CE Shannon","year":"1949","unstructured":"Shannon, C.E.: Communication theory of secrecy systems. Bell Labs Tech. J. 28(4), 656\u2013715 (1949)","journal-title":"Bell Labs Tech. J."},{"key":"3_CR47","volume-title":"Model Predictive Control","author":"EF Camacho","year":"2013","unstructured":"Camacho, E.F., Alba, C.B.: Model Predictive Control. Springer, Heidelberg (2013)"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-20065-6_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:04:14Z","timestamp":1667779454000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-20065-6_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031200649","9783031200656"],"references-count":47,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-20065-6_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"3 November 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Tel Aviv","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Israel","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 October 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 October 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2022.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"CMT","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5804","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1645","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.21","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.91","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}