{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T04:59:08Z","timestamp":1779339548241,"version":"3.51.4"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T00:00:00Z","timestamp":1745539200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T00:00:00Z","timestamp":1745539200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Fraunhofer-Institut f\u00fcr Optronik, Systemtechnik und Bildauswertung IOSB"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Machine Vision and Applications"],"published-print":{"date-parts":[[2025,5]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Despite ongoing research on the topic of adversarial examples in deep learning for computer vision, some fundamentals of the nature of these attacks remain unclear. As the manifold hypothesis posits, high-dimensional data tends to be part of a low-dimensional manifold. To verify the thesis with adversarial patches\u2013a special form of adversarial attack that can be used to fool object detectors in the physical world\u2013this paper provides an analysis of a set of adversarial patches and investigates the reconstruction abilities of five different dimensionality reduction methods. Quantitatively, the performance of reconstructed patches in an attack setting is measured and the impact of sampled patches from the latent space during adversarial training is investigated. The evaluation is performed on two publicly available datasets for person detection. The results indicate that more sophisticated dimensionality reduction methods offer no advantages over a simple principal component analysis.<\/jats:p>","DOI":"10.1007\/s00138-025-01689-6","type":"journal-article","created":{"date-parts":[[2025,4,25]],"date-time":"2025-04-25T18:15:19Z","timestamp":1745604919000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Traversing the subspace of adversarial patches"],"prefix":"10.1007","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2806-6920","authenticated-orcid":false,"given":"Jens","family":"Bayer","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7367-2519","authenticated-orcid":false,"given":"Stefan","family":"Becker","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8577-5256","authenticated-orcid":false,"given":"David","family":"M\u00fcnch","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7857-0332","authenticated-orcid":false,"given":"Michael","family":"Arens","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3556-7181","authenticated-orcid":false,"given":"J\u00fcrgen","family":"Beyerer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,4,25]]},"reference":[{"issue":"4","key":"1689_CR1","doi-asserted-by":"publisher","first-page":"983","DOI":"10.1090\/jams\/852","volume":"29","author":"C Fefferman","year":"2016","unstructured":"Fefferman, C., Mitter, S., Narayanan, H.: Testing the manifold hypothesis. J. Am. Math. Soc. 29(4), 983\u20131049 (2016). https:\/\/doi.org\/10.1090\/jams\/852. arXiv:1310.0425","journal-title":"J. Am. Math. Soc."},{"key":"1689_CR2","doi-asserted-by":"publisher","unstructured":"Bayer, J., Becker, S., M\u00fcnch, D., Arens, M.: Eigenpatches\u2014adversarial patches from principal components. In: Advances in Visual Computing, pp. 274\u2013284. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-47966-3_21","DOI":"10.1007\/978-3-031-47966-3_21"},{"key":"1689_CR3","doi-asserted-by":"publisher","unstructured":"Wang, C.-Y., Bochkovskiy, A., Liao, H.-Y.M.: Yolov7: Trainable bag-of-freebies sets new state-of-the-art for real-time object detectors. In: CVPR, pp. 7464\u20137475 (2023). https:\/\/doi.org\/10.1109\/CVPR52729.2023.00721","DOI":"10.1109\/CVPR52729.2023.00721"},{"key":"1689_CR4","doi-asserted-by":"publisher","unstructured":"Tarchoun, B., Khalifa, A.B., Mahjoub, M.A., Abu-ghazaleh, N.: Jedi: Entropy-based localization and removal of adversarial patches. In: CVPR, pp. 4087\u20134095 (2023). https:\/\/doi.org\/10.1109\/CVPR52729.2023.00398","DOI":"10.1109\/CVPR52729.2023.00398"},{"key":"1689_CR5","doi-asserted-by":"publisher","unstructured":"Tram\u00e8r, F., Papernot, N., Goodfellow, I., Boneh, D., McDaniel, P.: The space of transferable adversarial examples. In: arXiv Prepr., pp. 1\u201315 (2017). https:\/\/doi.org\/10.48550\/arXiv.1704.03453","DOI":"10.48550\/arXiv.1704.03453"},{"issue":"3","key":"1689_CR6","doi-asserted-by":"publisher","first-page":"2731","DOI":"10.1007\/s11063-019-10058-0","volume":"50","author":"ZM Wang","year":"2019","unstructured":"Wang, Z.M., Gu, M.T., Hou, J.H.: Sample based fast adversarial attack method. Neural Process. Lett. 50(3), 2731\u20132744 (2019). https:\/\/doi.org\/10.1007\/s11063-019-10058-0","journal-title":"Neural Process. Lett."},{"key":"1689_CR7","doi-asserted-by":"publisher","unstructured":"Shi, R., Yang, B., Jiang, Y., Zhao, C., Ni, B.: Energy attack: on transferring adversarial examples. In: arXiv Prepr. (2021). https:\/\/doi.org\/10.48550\/arXiv.2109.04300","DOI":"10.48550\/arXiv.2109.04300"},{"key":"1689_CR8","doi-asserted-by":"publisher","unstructured":"Dohmatob, E., Guo, C., Goibert, M.: Origins of low-dimensional adversarial perturbations. In: Ruiz, F., Dy, J., Meent, J.-W. (eds.) AISTATS, pp. 9221\u20139237 (2023). https:\/\/doi.org\/10.48550\/arXiv.2203.13779","DOI":"10.48550\/arXiv.2203.13779"},{"key":"1689_CR9","doi-asserted-by":"publisher","unstructured":"Shafahi, A., Huang, R., Studer, C., Feizi, S., Goldstein, T.: Are adversarial examples inevitable? In: ICLR (2019) https:\/\/doi.org\/10.48550\/arXiv.1809.02104arXiv:1809.02104","DOI":"10.48550\/arXiv.1809.02104"},{"key":"1689_CR10","doi-asserted-by":"publisher","unstructured":"Weng, J., Luo, Z., Lin, D., Li, S., Zhong, Z.: Boosting adversarial transferability via fusing logits of top-1 decomposed feature (2023) https:\/\/doi.org\/10.48550\/arXiv.2305.01361arXiv:2305.01361","DOI":"10.48550\/arXiv.2305.01361"},{"key":"1689_CR11","doi-asserted-by":"publisher","unstructured":"Garcia, W., Chen, P.-Y., Clouse, H.S., Jha, S., Butler, K.R.B.: Less is more: Dimension reduction finds on-manifold adversarial examples in hard-label attacks. In: SaTML, pp. 254\u2013270 (2023). https:\/\/doi.org\/10.1109\/SaTML54575.2023.00025","DOI":"10.1109\/SaTML54575.2023.00025"},{"key":"1689_CR12","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., Mian, A.: Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access 6, 14410\u201314430 (2018). https:\/\/doi.org\/10.1109\/ACCESS.2018.2807385","journal-title":"IEEE Access"},{"issue":"1","key":"1689_CR13","doi-asserted-by":"publisher","first-page":"25","DOI":"10.1049\/cit2.12028","volume":"6","author":"A Chakraborty","year":"2021","unstructured":"Chakraborty, A., Alam, M., Dey, V., Chattopadhyay, A., Mukhopadhyay, D.: A survey on adversarial attacks and defences. CAAI Trans. Intell. Technol. 6(1), 25\u201345 (2021). https:\/\/doi.org\/10.1049\/cit2.12028","journal-title":"CAAI Trans. Intell. Technol."},{"key":"1689_CR14","doi-asserted-by":"publisher","unstructured":"Pauling, C., Gimson, M., Qaid, M., Kida, A., Halak, B.: A tutorial on adversarial learning attacks and countermeasures (2022). https:\/\/doi.org\/10.48550\/arXiv.2202.10377","DOI":"10.48550\/arXiv.2202.10377"},{"key":"1689_CR15","doi-asserted-by":"publisher","unstructured":"Wang, S., Veldhuis, R., Strisciuglio, N.: A survey on the robustness of computer vision models against common corruptions. arXiv Prepr. 1\u201323 (2023) https:\/\/doi.org\/10.48550\/arXiv.2305.06024arXiv:2305.06024","DOI":"10.48550\/arXiv.2305.06024"},{"key":"1689_CR16","doi-asserted-by":"publisher","unstructured":"Godfrey, C., Kvinge, H., Bishoff, E., Mckay, M., Brown, D., Doster, T., Byler, E.: How many dimensions are required to find an adversarial example? In: CVPRW, pp. 2353\u20132360 (2023). https:\/\/doi.org\/10.1109\/CVPRW59228.2023.00232","DOI":"10.1109\/CVPRW59228.2023.00232"},{"issue":"3","key":"1689_CR17","doi-asserted-by":"publisher","first-page":"519","DOI":"10.1364\/josaa.4.000519","volume":"4","author":"L Sirovich","year":"1987","unstructured":"Sirovich, L., Kirby, M.: Low-dimensional procedure for the characterization of human faces. J. Opt. Soc. Am. A 4(3), 519 (1987). https:\/\/doi.org\/10.1364\/josaa.4.000519","journal-title":"J. Opt. Soc. Am. A"},{"issue":"5500","key":"1689_CR18","doi-asserted-by":"publisher","first-page":"2319","DOI":"10.1126\/science.290.5500.2319","volume":"290","author":"JB Tenenbaum","year":"2000","unstructured":"Tenenbaum, J.B., Silva, V.D., Langford, J.C.: A global geometric framework for nonlinear dimensionality reduction. Science 290(5500), 2319\u20132323 (2000). https:\/\/doi.org\/10.1126\/science.290.5500.2319","journal-title":"Science"},{"key":"1689_CR19","doi-asserted-by":"publisher","unstructured":"Cox, M.A.A., Cox, T.F.: Multidimensional Scaling, pp. 315\u2013347. Springer, Berlin (2008). https:\/\/doi.org\/10.1007\/978-3-540-33037-0_14","DOI":"10.1007\/978-3-540-33037-0_14"},{"key":"1689_CR20","doi-asserted-by":"publisher","unstructured":"Roweis, S.T., Saul, L.K.: Nonlinear dimensionality reduction by locally linear embedding. Science 290(5500), 2323\u20132326 (2000) https:\/\/doi.org\/10.1126\/science.290.5500.2323","DOI":"10.1126\/science.290.5500.2323"},{"key":"1689_CR21","doi-asserted-by":"publisher","unstructured":"Breiman, L.: Random forests. Mach. Learn. 45, 5\u201332 (2001) https:\/\/doi.org\/10.1023\/A:1010933404324","DOI":"10.1023\/A:1010933404324"},{"issue":"2","key":"1689_CR22","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1007\/s10462-023-10662-6","volume":"57","author":"K Berahmand","year":"2024","unstructured":"Berahmand, K., Daneshfar, F., Salehi, E.S., Li, Y., Xu, Y.: Autoencoders and their applications in machine learning: a survey. Artif. Intell. Rev. 57(2), 28 (2024). https:\/\/doi.org\/10.1007\/s10462-023-10662-6","journal-title":"Artif. Intell. Rev."},{"key":"1689_CR23","unstructured":"Sohn, K., Yan, X., Lee, H.: Learning structured output representation using deep conditional generative models, 3483\u20133491 (2015)"},{"key":"1689_CR24","doi-asserted-by":"publisher","unstructured":"Kingma, D.P., Welling, M.: Auto-encoding variational bayes. In: Bengio, Y., LeCun, Y. (eds.) 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, Conference Track Proceedings (2014). https:\/\/doi.org\/10.48550\/arXiv.1312.6114","DOI":"10.48550\/arXiv.1312.6114"},{"key":"1689_CR25","doi-asserted-by":"publisher","unstructured":"Dalal, N., Triggs, B.: Histograms of oriented gradients for human detection. In: CVPR, vol. 1, pp. 886\u2013893 (2005). https:\/\/doi.org\/10.1109\/CVPR.2005.177","DOI":"10.1109\/CVPR.2005.177"},{"key":"1689_CR26","doi-asserted-by":"publisher","unstructured":"Shao, S., Zhao, Z., Li, B., Xiao, T., Yu, G., Zhang, X., Sun, J.: CrowdHuman: A benchmark for detecting human in a crowd, 1\u20139 (2018) https:\/\/doi.org\/10.48550\/arXiv.1805.00123. arXiv:1805.00123","DOI":"10.48550\/arXiv.1805.00123"},{"key":"1689_CR27","doi-asserted-by":"publisher","unstructured":"Loshchilov, I., Hutter, F.: Decoupled weight decay regularization. In: ICLR (2019) https:\/\/doi.org\/10.48550\/arXiv.1711.05101. arXiv:1711.05101","DOI":"10.48550\/arXiv.1711.05101"}],"container-title":["Machine Vision and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-025-01689-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00138-025-01689-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00138-025-01689-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,9]],"date-time":"2025-05-09T14:31:12Z","timestamp":1746801072000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00138-025-01689-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,25]]},"references-count":27,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,5]]}},"alternative-id":["1689"],"URL":"https:\/\/doi.org\/10.1007\/s00138-025-01689-6","relation":{},"ISSN":["0932-8092","1432-1769"],"issn-type":[{"value":"0932-8092","type":"print"},{"value":"1432-1769","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,25]]},"assertion":[{"value":"12 April 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 December 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 April 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 April 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no relevant financial or non-financial interests to disclose.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"70"}}