{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T17:03:37Z","timestamp":1784567017957,"version":"3.55.0"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61932012, 62372228, U24A20337"],"award-info":[{"award-number":["61932012, 62372228, U24A20337"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["14380029"],"award-info":[{"award-number":["14380029"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Open Project of State Key Laboratory for Novel Software Technology at Nanjing University","award":["KFKT2024B21"],"award-info":[{"award-number":["KFKT2024B21"]}]},{"DOI":"10.13039\/501100010877","name":"Science, Technology and Innovation Commission of Shenzhen Municipality","doi-asserted-by":"publisher","award":["CJGJZD20200617103001003, 2021Szvup057"],"award-info":[{"award-number":["CJGJZD20200617103001003, 2021Szvup057"]}],"id":[{"id":"10.13039\/501100010877","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Comput Vis"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1007\/s11263-026-02890-4","type":"journal-article","created":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T11:12:17Z","timestamp":1780744337000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["UBA: A Unified Black-Box Adversarial Testing for Object Detection via Visualization-Based Contextual Reconstruction"],"prefix":"10.1007","volume":"134","author":[{"given":"Jiawei","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weisi","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9930-7111","authenticated-orcid":false,"given":"Chunrong","family":"Fang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Quanjun","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Junyi","family":"Xie","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dezhi","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenyu","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,6]]},"reference":[{"key":"2890_CR1","unstructured":"Bao, J. (2020). Sparse adversarial attack to object detection. CoRR arXiv:2012.13692"},{"issue":"3","key":"2890_CR2","doi-asserted-by":"publisher","first-page":"24","DOI":"10.1145\/1531326.1531330","volume":"28","author":"C Barnes","year":"2009","unstructured":"Barnes, C., Shechtman, E., Finkelstein, A., & Goldman, D. B. (2009). Patchmatch: A randomized correspondence algorithm for structural image editing. ACM Trans Graph, 28(3), 24. https:\/\/doi.org\/10.1145\/1531326.1531330","journal-title":"ACM Trans Graph"},{"key":"2890_CR3","doi-asserted-by":"crossref","unstructured":"Carion, N., Massa, F., Synnaeve, G., Usunier, N., Kirillov, A., & Zagoruyko, S. (2020). End-to-end object detection with transformers. European conference on computer vision (pp. 213\u2013229). Springer.","DOI":"10.1007\/978-3-030-58452-8_13"},{"key":"2890_CR4","unstructured":"Contributors, G. (2023a). Google: Detect multiple objects. https:\/\/cloud.google.com\/vision\/docs\/object-localizer"},{"key":"2890_CR5","unstructured":"Contributors, T. (2023b). Tencent: Object detection for video. https:\/\/cloud.tencent.com\/document\/api\/436\/85075"},{"key":"2890_CR6","unstructured":"Contributors, T. (2023c). Tesla: Autopilot. https:\/\/www.tesla.com\/autopilot"},{"key":"2890_CR7","doi-asserted-by":"publisher","unstructured":"Dalal, N., & Triggs, B. (2005). Histograms of oriented gradients for human detection. In: 2005 IEEE computer society conference on computer vision and pattern recognition (CVPR\u201905), 1, 886\u2013893 https:\/\/doi.org\/10.1109\/CVPR.2005.177","DOI":"10.1109\/CVPR.2005.177"},{"key":"2890_CR8","unstructured":"Development team SI (2021). Python-scikit-image: Psnr. https:\/\/scikit-image.org\/docs\/stable\/api\/skimage.metrics.html"},{"key":"2890_CR9","unstructured":"Everingham, M., Van\u00a0Gool, L., Williams, C.K.I., Winn, J., & Zisserman, A. (2012). The PASCAL visual object classes challenge 2012 (VOC2012) results. http:\/\/host.robots.ox.ac.uk\/pascal\/VOC\/voc2012\/"},{"key":"2890_CR10","unstructured":"Ezyang\u00a0et al. (2021). Pytorch. https:\/\/github.com\/pytorch\/pytorch"},{"key":"2890_CR11","unstructured":"Ge, Z., Liu, S., Wang, F., Li, Z., & Sun, J. (2021). Yolox: Exceeding yolo series in 2021. arXiv preprint arXiv:2107.08430"},{"issue":"11","key":"2890_CR12","doi-asserted-by":"publisher","first-page":"1231","DOI":"10.1177\/0278364913491297","volume":"32","author":"A Geiger","year":"2013","unstructured":"Geiger, A., Lenz, P., Stiller, C., & Urtasun, R. (2013). Vision meets robotics: The kitti dataset. The international journal of robotics research, 32(11), 1231\u20131237.","journal-title":"The international journal of robotics research"},{"key":"2890_CR13","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2018). Explaining and harnessing adversarial examples. ICLR"},{"key":"2890_CR14","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2018). Explaining and harnessing adversarial examples. ICLR"},{"key":"2890_CR15","doi-asserted-by":"crossref","unstructured":"Hu, Y.C.T., Kung, B.H., Tan, D.S., Chen, J.C., Hua, K.L., & Cheng, W.H. (2021a). Naturalistic physical adversarial patch for object detectors. In: Proceedings of the IEEE\/CVF international conference on computer vision (pp. 7848\u20137857)","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"2890_CR16","doi-asserted-by":"crossref","unstructured":"Huang, H., Chen, Z., Chen, H., Wang, Y., & Zhang, K. (2023). T-sea: Transfer-based self-ensemble attack on object detection. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp 20514\u201320523)","DOI":"10.1109\/CVPR52729.2023.01965"},{"issue":"2","key":"2890_CR17","doi-asserted-by":"publisher","first-page":"462","DOI":"10.1007\/s11263-020-01383-2","volume":"129","author":"C Kamann","year":"2021","unstructured":"Kamann, C., & Rother, C. (2021). Benchmarking the robustness of semantic segmentation models with respect to common corruptions. The International Journal of Computer Vision, 129(2), 462\u2013483. https:\/\/doi.org\/10.1007\/s11263-020-01383-2","journal-title":"The International Journal of Computer Vision"},{"key":"2890_CR18","unstructured":"Kurakin, A., Goodfellow, I. J., & Bengio, S. (2016). Adversarial examples in the physical world. CoRR"},{"key":"2890_CR19","unstructured":"Lab, T.K.S. (2019). Experimental security research of tesla autopilot. https:\/\/keenlab.tencent.com\/en\/whitepapers\/Experimental_Security_Research_of_Tesla_Autopilot.pdf"},{"key":"2890_CR20","doi-asserted-by":"publisher","unstructured":"Levinson, J., Askeland, J., Becker, J., Dolson, J., Held, D., Kammel, S., Kolter, J.Z., Langer, D., Pink, O., Pratt, V., Sokolsky, M., Stanek, G., Stavens, D., Teichman, A., Werling, M., & Thrun, S. (2011). Towards fully autonomous driving: Systems and algorithms. In: 2011 IEEE intelligent vehicles symposium (IV) (pp. 163\u2013168). https:\/\/doi.org\/10.1109\/IVS.2011.5940562","DOI":"10.1109\/IVS.2011.5940562"},{"key":"2890_CR21","doi-asserted-by":"crossref","unstructured":"Liang, S., Wu, B., Fan, Y., Wei, X., & Cao, X. (2022). Parallel rectangle flip attack: A query-based black-box attack against object detection. CoRR arXiv:2201.08970","DOI":"10.1109\/ICCV48922.2021.00760"},{"key":"2890_CR22","doi-asserted-by":"crossref","unstructured":"Lin, T., Maire, M., Belongie, S.J., Bourdev, L.D., Girshick, R.B., Hays, J., Perona, P., Ramanan, D., Doll\u00e1r, P., & Zitnick, C.L. (2014). Microsoft COCO: Common objects in context. CoRR arXiv:1405.0312","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"2890_CR23","unstructured":"Liu, X., Yang, H., Song, L., Li, H., & Chen, Y. (2018). Dpatch: Attacking object detectors with adversarial patches. CoRR arXiv:abs\/1806.02299"},{"key":"2890_CR24","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1007\/s11263-019-01247-4","volume":"128","author":"L Liu","year":"2020","unstructured":"Liu, L., Ouyang, W., Wang, X., Fieguth, P., Chen, J., Liu, X., & Pietik\u00e4inen, M. (2020). Deep learning for generic object detection: A survey. International journal of computer vision, 128, 261\u2013318.","journal-title":"International journal of computer vision"},{"issue":"10","key":"2890_CR25","doi-asserted-by":"publisher","first-page":"4398","DOI":"10.1007\/s11263-024-02096-6","volume":"132","author":"J Liu","year":"2024","unstructured":"Liu, J., Wang, Z., Ma, L., Fang, C., Bai, T., Zhang, X., Liu, J., & Chen, Z. (2024). Benchmarking object detection robustness against real-world corruptions. International Journal of Computer Vision, 132(10), 4398\u20134416.","journal-title":"International Journal of Computer Vision"},{"key":"2890_CR26","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2018). Towards deep learning models resistant to adversarial attacks. ICLR"},{"key":"2890_CR27","unstructured":"McFarland, M. (2023). Tesla-induced pileup involved driver-assist tech, government data reveals. https:\/\/edition.cnn.com\/2023\/01\/17\/business\/tesla-8-car-crash-autopilot\/index.html"},{"key":"2890_CR28","unstructured":"Michaelis, C., Mitzkus, B., Geirhos, R., Rusak, E., Bringmann, O., Ecker, A.S., Bethge, M., Brendel, W. (2019). Benchmarking robustness in object detection: Autonomous driving when winter is coming. CoRR arXiv:1907.07484"},{"key":"2890_CR29","first-page":"02921","volume":"1703","author":"E Park","year":"2017","unstructured":"Park, E., Yang, J., Yumer, E., Ceylan, D., & Berg, A. C. (2017). Transformation-grounded image generation network for novel 3d view synthesis. CoRR arXiv, 1703, 02921.","journal-title":"CoRR arXiv"},{"key":"2890_CR30","doi-asserted-by":"publisher","first-page":"1706","DOI":"10.1016\/j.procs.2018.05.144","volume":"132","author":"AR Pathak","year":"2018","unstructured":"Pathak, A. R., Pandey, M., & Rautaray, S. (2018). Application of deep learning for object detection. Procedia computer science, 132, 1706\u20131717. https:\/\/doi.org\/10.1016\/j.procs.2018.05.144","journal-title":"Procedia computer science"},{"key":"2890_CR31","unstructured":"Petsiuk, V., Das, A., & Saenko, K. (2018). RISE: randomized input sampling for explanation of black-box models. CoRR arXiv:1806.07421"},{"key":"2890_CR32","unstructured":"Qi, Z., Khorram, S., & Li, F. (2019). Visualizing deep networks by optimizing with integrated gradients. CoRR arXiv:1905.00954"},{"key":"2890_CR33","doi-asserted-by":"crossref","unstructured":"Selvaraju, R.R., Das, A., Vedantam, R., Cogswell, M., Parikh, D., & Batra, D. (2016). Grad-cam: Why did you say that? visual explanations from deep networks via gradient-based localization. CoRR arXiv:1610.02391","DOI":"10.1109\/ICCV.2017.74"},{"key":"2890_CR34","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., & Reiter, M. K. (2016). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. CCS","DOI":"10.1145\/2976749.2978392"},{"key":"2890_CR35","doi-asserted-by":"publisher","first-page":"1185","DOI":"10.1007\/s11263-020-01423-x","volume":"129","author":"AK Shekar","year":"2021","unstructured":"Shekar, A. K., Gou, L., Ren, L., & Wendt, A. (2021). Label-free robustness estimation of object detection cnns for autonomous driving applications. International Journal of Computer Vision, 129, 1185\u20131201.","journal-title":"International Journal of Computer Vision"},{"key":"2890_CR36","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., & Fergus, R. (2013). Intriguing properties of neural networks In ICLR"},{"key":"2890_CR37","doi-asserted-by":"crossref","unstructured":"Thys, S., Van Ranst, W., & Goedem\u00e9, T. (2019). Fooling automated surveillance cameras: Adversarial patches to attack person detection. CVPRW: Workshop on the bright and dark sides of computer vision: Challenges and opportunities for privacy and security","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"2890_CR38","doi-asserted-by":"publisher","unstructured":"Tian, Y., Luo, P., Wang, X., & Tang, X. (2015). Deep learning strong parts for pedestrian detection. In: 2015 IEEE international conference on computer vision (ICCV) (pp. 1904\u20131912). https:\/\/doi.org\/10.1109\/ICCV.2015.221","DOI":"10.1109\/ICCV.2015.221"},{"key":"2890_CR39","doi-asserted-by":"crossref","unstructured":"Tian, Z., Shen, C., Chen, H., & He, T. (2021). FCOS: A simple and strong anchor-free object detector","DOI":"10.1109\/TPAMI.2020.3032166"},{"key":"2890_CR40","doi-asserted-by":"publisher","unstructured":"Wei, X., Liang, S., Chen, N., & Cao, X. (2019). Transferable adversarial attacks for image and video object detection. Proceedings of the twenty-eighth international joint conference on artificial intelligence, IJCAI-19, international joint conferences on artificial intelligence organization (pp. 954\u2013960). https:\/\/doi.org\/10.24963\/ijcai.2019\/134","DOI":"10.24963\/ijcai.2019\/134"},{"key":"2890_CR41","doi-asserted-by":"crossref","unstructured":"Xu, K., Zhang, G., Liu, S., Fan, Q., Sun, M., Chen, H., Chen, P.Y., Wang, Y., & Lin, X. (2019). Adversarial t-shirt! evading person detectors in a physical world. arXiv preprint arXiv:1910.11099","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"2890_CR42","unstructured":"Zeng, Y., Lin, Z., Lu, H., & Patel, V.M. (2020). Image inpainting with contextual reconstruction loss. CoRR abs\/2011.12836, arXiv:2011.12836,"},{"key":"2890_CR43","doi-asserted-by":"crossref","unstructured":"Zhang, R., Isola, P., Efros, A. A., Shechtman, E., & Wang, O. (2018). The unreasonable effectiveness of deep features as a perceptual metric. CVPR.","DOI":"10.1109\/CVPR.2018.00068"},{"key":"2890_CR44","unstructured":"Zhang, Y., Foroosh, H., David, P., & Gong, B. (2019). Camou: Learning physical vehicle camouflages to adversarially attack detectors in the wild. ICLR"},{"key":"2890_CR45","unstructured":"Zheng, Z., Wang, P., Liu, W., Li, J., Ye, R., & Ren, D. (2019). Distance-iou loss: Faster and better learning for bounding box regression. CoRR arXiv:abs\/1911.08287"},{"key":"2890_CR46","unstructured":"Zhu, X., Su, W., Lu, L., Li, B., Wang, X., & Dai, J. (2020). Deformable detr: Deformable transformers for end-to-end object detection arXiv:2010.04159 arXiv preprint"},{"key":"2890_CR47","unstructured":"Ziegler, C. (2016). A google self-driving car caused a crash for the first time. https:\/\/www.theverge.com\/2016\/2\/29\/11134344\/google-self-driving-car-crash-report"}],"container-title":["International Journal of Computer Vision"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-026-02890-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11263-026-02890-4","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-026-02890-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T16:14:07Z","timestamp":1784564047000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11263-026-02890-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":47,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,6]]}},"alternative-id":["2890"],"URL":"https:\/\/doi.org\/10.1007\/s11263-026-02890-4","relation":{},"ISSN":["0920-5691","1573-1405"],"issn-type":[{"value":"0920-5691","type":"print"},{"value":"1573-1405","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"10 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"309"}}