{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,2]],"date-time":"2025-11-02T10:21:46Z","timestamp":1762078906483,"version":"build-2065373602"},"publisher-location":"Singapore","reference-count":20,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789811982842"},{"type":"electronic","value":"9789811982859"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,12,10]],"date-time":"2022-12-10T00:00:00Z","timestamp":1670630400000},"content-version":"vor","delay-in-days":343,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Accurate and stable traffic sign detection is a key technology to achieve L3 driving automation, and its performance has been significantly improved by the development of deep learning technology in recent years. However, the current traffic sign detection has inadequate difficulty resisting anti-attack ability and even does not have basic defense capability. To solve this critical issue, an adversarial patch attack defense model IYOLO-TS is proposed in this paper. The main innovation is to simulate the conditions of traffic signs being partially damaged, obscured or maliciously modified in real world by training the attack patches, and then add the attacked classes in the last layer of the YOLOv2 which are corresponding to the original detection categories, and finally the attack patch obtained from the training is used to complete the adversarial training of the detection model. The attack patch is obtained by first using RP<jats:sub>2<\/jats:sub>algorithm to attack the detection model and then training on the blank patch. In order to verify the defense effective of the proposed IYOLO-TS model, we constructed a patch dataset LISA-Mask containing 50 different mask generation patches of 33000 sheets, and then training dataset by combining LISA and LISA-Mask datasets. The experiment results show that the mAP of the proposed IYOLO-TS is up to 98.12%. Compared with YOLOv2, it improved the defense ability against patch attacks and has the real-time detection ability. It can be considered that the proposed method has strong practicality and achieves a tradeoff between design complexity and efficiency.<\/jats:p>","DOI":"10.1007\/978-981-19-8285-9_15","type":"book-chapter","created":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T20:02:48Z","timestamp":1670616168000},"page":"199-210","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Research on Adversarial Patch Attack Defense Method for Traffic Sign Detection"],"prefix":"10.1007","author":[{"given":"Yanjing","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianming","family":"Cui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ming","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,12,10]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Balasubramaniam, A., Pasricha, S.: Object Detection in Autonomous Vehicles: Status and Open Challenges. arXiv preprint arXiv:2201.07706 (2022)","DOI":"10.1007\/978-3-031-28016-0_17"},{"key":"15_CR2","unstructured":"Salah Zaki, P., Magdy William, M., Karam Soliman, B., Gamal Alexsan, K., Khalil, K., El-Moursy, M.: Traffic Signs Detection and Recognition System using Deep Learning. arXiv preprint arXiv:2003.03256 (2020)"},{"key":"15_CR3","unstructured":"Yi Huang,\u00a0Wai-Kin Kong A.: Transferable\u00a0Adversarial\u00a0Attack\u00a0based on Integrated Gradients. arXiv preprint arXiv:2205.13152 (2022)"},{"key":"15_CR4","unstructured":"Cilloni, T., Walter, C., Fleming, C.: Focused Adversarial Attacks. arXiv preprint arXiv:2205.09624 (2022)"},{"key":"15_CR5","unstructured":"Mo, Z., Patel, V.M.: On Trace of PGD-Like Adversarial Attacks. arXiv preprint arXiv:2205.09586 (2022)"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Subramanya, A., Pillai, V., Pirsiavash, H.: Fooling Network Interpretation in Image Classification. arXiv preprint arXiv:1812.02843 (2019)","DOI":"10.1109\/ICCV.2019.00211"},{"key":"15_CR7","doi-asserted-by":"crossref","unstructured":"Singh, I., Araki, T., Kakizaki, R.K.: Powerful Physical Adversarial Examples Against Practical Face Recognition Systems. arXiv preprint arXiv:2203.15498 (2022)","DOI":"10.1109\/WACVW54805.2022.00036"},{"key":"15_CR8","doi-asserted-by":"crossref","unstructured":"Eykholt, K., et al.: Robust physical-world attacks on deep learning visual classification. In: 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 1625\u20131634 (2018)","DOI":"10.1109\/CVPR.2018.00175"},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Thys, S., Ranst, W., Goedeme, T.: Fooling automated surveillance cameras: adversarial patches to attack person detection. In: 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pp. 49\u201355 (2019)","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"15_CR10","unstructured":"Lee, M., Zico Kolter, J.: On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897 (2019)"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"Hayes, J.: On visible adversarial perturbations & digital watermarking. In: 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Work-shops (CVPRW), pp. 1597\u20131604 (2018)","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Naseer, M., Khan, S., Porikli, F.: Local gradients smoothing: defense against localized adversarial attacks. In: 2019 IEEE Winter Conference on Applications of Computer Vision (WACV), pp. 1300\u20131307 (2019)","DOI":"10.1109\/WACV.2019.00143"},{"key":"15_CR13","doi-asserted-by":"crossref","unstructured":"McCoyd, M., et al.: Minority reports defense: defending against adversarial patches. arXiv preprint arXiv:2004.13799 (2020)","DOI":"10.1007\/978-3-030-61638-0_31"},{"key":"15_CR14","doi-asserted-by":"crossref","unstructured":"Wang, J., Chen, Y., Gao, M., Dong, Z.: Improved YOLOv5 network for real-time multi-scale\u00a0traffic\u00a0sign\u00a0detection. arXiv preprint arXiv:2112.08782 (2021)","DOI":"10.1007\/s00521-022-08077-5"},{"key":"15_CR15","doi-asserted-by":"crossref","unstructured":"Redmon, J., Farhadi, A.: YOLO9000: Better, Faster, Stronger. CoRR (2016)","DOI":"10.1109\/CVPR.2017.690"},{"key":"15_CR16","unstructured":"Redmon, J., Farhadi, A.: Yolov3: an incremental improvement. arXiv preprint arXiv:1804.02767 (2018)"},{"key":"15_CR17","unstructured":"Bochkovskiy, A., Wang, C.Y., Liao, H.: YOLOv4: Optimal Speed and Accuracy of Object Detection (2020)"},{"key":"15_CR18","unstructured":"Ge, Z., Liu, S., Wang, F., et al.: YOLOX: Exceeding YOLO Series in 2021 (2021)"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Levering, A., Tomko, M., Tuia, D., Khoshelham, K.: Detecting Unsigned Physical Road Incidents from Driver-View Images. arXiv preprint arXiv:2004.11824 (2020)","DOI":"10.1109\/TIV.2020.2991963"},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., Reiter, M.K.: Accessorize to a crime: real and stealthy attacks on state-of-the-art face recognition. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 1528\u20131540 (2016)","DOI":"10.1145\/2976749.2978392"}],"container-title":["Communications in Computer and Information Science","Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-19-8285-9_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,12,2]],"date-time":"2023-12-02T19:25:15Z","timestamp":1701545115000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-19-8285-9_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9789811982842","9789811982859"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-981-19-8285-9_15","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"10 December 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CNCERT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China Cyber Security Annual Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cncert2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/conf.cert.org.cn","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}