{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T14:54:26Z","timestamp":1780498466771,"version":"3.54.1"},"reference-count":87,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2024,4,10]],"date-time":"2024-04-10T00:00:00Z","timestamp":1712707200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,4,10]],"date-time":"2024-04-10T00:00:00Z","timestamp":1712707200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62376202"],"award-info":[{"award-number":["62376202"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Membr Comput"],"published-print":{"date-parts":[[2024,6]]},"DOI":"10.1007\/s41965-024-00142-3","type":"journal-article","created":{"date-parts":[[2024,4,10]],"date-time":"2024-04-10T18:01:31Z","timestamp":1712772091000},"page":"130-147","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":25,"title":["Adversarial attacks in computer vision: a survey"],"prefix":"10.1007","volume":"6","author":[{"given":"Chao","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Handing","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wen","family":"Yao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tingsong","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,4,10]]},"reference":[{"issue":"1","key":"142_CR1","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1186\/s12880-022-00793-7","volume":"22","author":"HE Kim","year":"2022","unstructured":"Kim, H. E., Cosa-Linan, A., Santhanam, N., Jannesari, M., Maros, M. E., & Ganslandt, T. (2022). Transfer learning for medical image classification: A literature review. BMC Medical Imaging, 22(1), 69.","journal-title":"BMC Medical Imaging"},{"key":"142_CR2","doi-asserted-by":"crossref","unstructured":"Zou, Z., Chen, K., Shi, Z., Guo, Y., & Ye, J. (2023). Object detection in 20 years: A survey. Proceedings of the IEEE.","DOI":"10.1109\/JPROC.2023.3238524"},{"key":"142_CR3","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2023.110370","volume":"142","author":"C Li","year":"2023","unstructured":"Li, C., Yao, W., Wang, H., Jiang, T., & Zhang, X. (2023). Bayesian evolutionary optimization for crafting high-quality adversarial examples with limited query budget. Applied Soft Computing, 142, 110370.","journal-title":"Applied Soft Computing"},{"key":"142_CR4","unstructured":"Wong, E., Schmidt, F., & Kolter, Z. (2019). Wasserstein adversarial examples via projected Sinkhorn iterations. In: International Conference on Machine Learning (pp. 6808\u20136817). PMLR."},{"key":"142_CR5","unstructured":"Ilyas, A., Engstrom, L., & Madry, A. (2018). Prior convictions: Black-box adversarial attacks with bandits and priors. arXiv:1807.07978."},{"key":"142_CR6","doi-asserted-by":"crossref","unstructured":"Komkov, S., & Petiushko, A. (2021). Advhat: Real-world adversarial attack on arcface face id system. In: 2020 25th International Conference on Pattern Recognition (ICPR) (pp. 819\u2013826). IEEE.","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"142_CR7","doi-asserted-by":"crossref","unstructured":"Li, J., Ji, S., Du, T., Li, B., & Wang, T. (2018). Textbugger: Generating adversarial text against real-world applications. arXiv:1812.05271.","DOI":"10.14722\/ndss.2019.23138"},{"key":"142_CR8","doi-asserted-by":"crossref","unstructured":"Wang, D., Yao, W., Jiang, T., Li, C., & Chen, X. (2023). Rfla: A stealthy reflected light adversarial attack in the physical world. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (pp. 4455\u20134465).","DOI":"10.1109\/ICCV51070.2023.00411"},{"key":"142_CR9","doi-asserted-by":"crossref","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., & Song, D. (2018). Robust physical-world attacks on deep learning visual classification. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (pp. 1625\u20131634).","DOI":"10.1109\/CVPR.2018.00175"},{"key":"142_CR10","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., & Fergus, R. (2013). Intriguing properties of neural networks. arXiv:1312.6199."},{"key":"142_CR11","doi-asserted-by":"publisher","first-page":"155161","DOI":"10.1109\/ACCESS.2021.3127960","volume":"9","author":"N Akhtar","year":"2021","unstructured":"Akhtar, N., Mian, A., Kardan, N., & Shah, M. (2021). Advances in adversarial attacks and defenses in computer vision: A survey. IEEE Access, 9, 155161\u2013155196.","journal-title":"IEEE Access"},{"issue":"4","key":"142_CR12","doi-asserted-by":"publisher","first-page":"3367","DOI":"10.1109\/TKDE.2021.3130903","volume":"35","author":"H Sun","year":"2023","unstructured":"Sun, H., Zhu, T., Zhang, Z., Jin, D., Xiong, P., & Zhou, W. (2023). Adversarial attacks against deep generative models on data: A survey. IEEE Transactions on Knowledge and Data Engineering, 35(4), 3367\u20133388. https:\/\/doi.org\/10.1109\/TKDE.2021.3130903","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"142_CR13","unstructured":"Goodfellow, I.J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv:1412.6572."},{"key":"142_CR14","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1016\/j.ins.2022.07.157","volume":"610","author":"Y Wang","year":"2022","unstructured":"Wang, Y., Liu, J., Chang, X., Rodr\u00edguez, R. J., & Wang, J. (2022). Di-aa: An interpretable white-box attack for fooling deep neural networks. Information Sciences, 610, 14\u201332.","journal-title":"Information Sciences"},{"key":"142_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109037","volume":"133","author":"Y Bai","year":"2023","unstructured":"Bai, Y., Wang, Y., Zeng, Y., Jiang, Y., & Xia, S.-T. (2023). Query efficient black-box adversarial attack on deep neural networks. Pattern Recognition, 133, 109037.","journal-title":"Pattern Recognition"},{"key":"142_CR16","doi-asserted-by":"crossref","unstructured":"Feng, W., Xu, N., Zhang, T., & Zhang, Y. (2023). Dynamic generative targeted attacks with pattern injection. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (pp. 16404\u201316414)","DOI":"10.1109\/CVPR52729.2023.01574"},{"key":"142_CR17","doi-asserted-by":"crossref","unstructured":"Reza, M.F., Rahmati, A., Wu, T., & Dai, H. (2023). Cgba: Curvature-aware geometric black-box attack. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (pp. 124\u2013133)","DOI":"10.1109\/ICCV51070.2023.00018"},{"issue":"6","key":"142_CR18","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L. (2012). The mnist database of handwritten digit images for machine learning research [best of the web]. IEEE Signal Processing Magazine, 29(6), 141\u2013142.","journal-title":"IEEE Signal Processing Magazine"},{"key":"142_CR19","unstructured":"Krizhevsky, A., & Hinton, G. et al. (2009). Learning multiple layers of features from tiny images."},{"key":"142_CR20","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.-J., Li, K., & Fei-Fei, L. (2009). Imagenet: A large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition (pp. 248\u2013255). Ieee","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"142_CR21","doi-asserted-by":"crossref","unstructured":"Lin, T.-Y., Maire, M., Belongie, S., Hays, J., Perona, P., Ramanan, D., Doll\u00e1r, P., & Zitnick, C.L.: (2014). Microsoft coco: Common objects in context. In: Computer Vision\u2013ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6\u201312, 2014, Proceedings, Part V 13 (pp. 740\u2013755). Springer","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"142_CR22","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1007\/s11263-009-0275-4","volume":"88","author":"M Everingham","year":"2010","unstructured":"Everingham, M., Van Gool, L., Williams, C. K., Winn, J., & Zisserman, A. (2010). The pascal visual object classes (voc) challenge. International Journal of Computer Vision, 88, 303\u2013338.","journal-title":"International Journal of Computer Vision"},{"key":"142_CR23","unstructured":"Kurakin, A., Goodfellow, I., & Bengio, S, et al. (2016). Adversarial examples in the physical world."},{"key":"142_CR24","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083."},{"key":"142_CR25","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., & Frossard, P. (2016). Deepfool: A simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (pp. 2574\u20132582).","DOI":"10.1109\/CVPR.2016.282"},{"key":"142_CR26","doi-asserted-by":"crossref","unstructured":"Carlini, N., & Wagner, D. (2017). Towards evaluating the robustness of neural networks. In: 2017 Ieee Symposium on Security and Privacy (sp) (pp. 39\u201357). IEEE.","DOI":"10.1109\/SP.2017.49"},{"key":"142_CR27","doi-asserted-by":"crossref","unstructured":"Wang, X., He, X., Wang, J., & He, K. (2021). Admix: Enhancing the transferability of adversarial attacks. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (pp. 16158\u201316167).","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"142_CR28","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., & Li, J. (2018). Boosting adversarial attacks with momentum. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (pp. 9185\u20139193).","DOI":"10.1109\/CVPR.2018.00957"},{"key":"142_CR29","doi-asserted-by":"crossref","unstructured":"Wang, X., & He, K. (2021). Enhancing the transferability of adversarial attacks through variance tuning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (pp. 1924\u20131933).","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"142_CR30","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.108979","volume":"133","author":"C Li","year":"2023","unstructured":"Li, C., Yao, W., Wang, H., & Jiang, T. (2023). Adaptive momentum variance for attention-guided sparse adversarial attacks. Pattern Recognition, 133, 108979.","journal-title":"Pattern Recognition"},{"key":"142_CR31","doi-asserted-by":"crossref","unstructured":"Xie, C., Zhang, Z., Zhou, Y., Bai, S., Wang, J., Ren, Z., & Yuille, A.L. (2019). Improving transferability of adversarial examples with input diversity. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (pp. 2730\u20132739).","DOI":"10.1109\/CVPR.2019.00284"},{"key":"142_CR32","doi-asserted-by":"crossref","unstructured":"Dong, Y., Pang, T., Su, H., & Zhu, J. (2019). Evading defenses to transferable adversarial examples by translation-invariant attacks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (pp. 4312\u20134321).","DOI":"10.1109\/CVPR.2019.00444"},{"key":"142_CR33","unstructured":"Lin, J., Song, C., He, K., Wang, L., & Hopcroft, J.E. (2019) Nesterov accelerated gradient and scale invariance for adversarial attacks. arXiv:1908.06281."},{"key":"142_CR34","unstructured":"Liu, Y., Chen, X., Liu, C., & Song, D. (2016). Delving into transferable adversarial examples and black-box attacks. arXiv:1611.02770."},{"key":"142_CR35","doi-asserted-by":"crossref","unstructured":"Chen, S., He, Z., Sun, C., Yang, J., & Huang, X. (2020). Universal adversarial attack on attention and the resulting dataset damagenet. IEEE Transactions on Pattern Analysis and Machine Intelligence.","DOI":"10.1109\/TPAMI.2020.3033291"},{"key":"142_CR36","doi-asserted-by":"crossref","unstructured":"Chen, P.-Y., Zhang, H., Sharma, Y., Yi, J., & Hsieh, C.-J. (2017). Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security (pp. 15\u201326).","DOI":"10.1145\/3128572.3140448"},{"key":"142_CR37","unstructured":"Brendel, W., Rauber, J., & Bethge, M. (2017). Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv:1712.04248."},{"key":"142_CR38","doi-asserted-by":"crossref","unstructured":"Andriushchenko, M., Croce, F., Flammarion, N., & Hein, M. (2020). Square attack: a query-efficient black-box adversarial attack via random search. In: European Conference on Computer Vision (pp. 484\u2013501). Springer.","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"142_CR39","unstructured":"Shukla, S. N., Sahu, A.K., Willmott, D., & Kolter, J. Z. (2019). Black-box adversarial attacks with Bayesian optimization. arXiv:1909.13857."},{"key":"142_CR40","doi-asserted-by":"crossref","unstructured":"Li, Z., Cheng, H., Cai, X., Zhao, J., & Zhang, Q. (2022). Sa-es: Subspace activation evolution strategy for black-box adversarial attacks. IEEE Transactions on Emerging Topics in Computational Intelligence.","DOI":"10.1109\/TETCI.2022.3214627"},{"issue":"2","key":"142_CR41","doi-asserted-by":"publisher","first-page":"182","DOI":"10.1109\/4235.996017","volume":"6","author":"K Deb","year":"2002","unstructured":"Deb, K., Pratap, A., Agarwal, S., & Meyarivan, T. (2002). A fast and elitist multiobjective genetic algorithm: Nsga-ii. IEEE Transactions on Evolutionary Computation, 6(2), 182\u2013197.","journal-title":"IEEE Transactions on Evolutionary Computation"},{"key":"142_CR42","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1016\/j.neunet.2020.04.015","volume":"127","author":"P Vidnerov\u00e1","year":"2020","unstructured":"Vidnerov\u00e1, P., & Neruda, R. (2020). Vulnerability of classifiers to evolutionary generated adversarial examples. Neural Networks, 127, 168\u2013181.","journal-title":"Neural Networks"},{"key":"142_CR43","doi-asserted-by":"crossref","unstructured":"Alzantot, M., Sharma, Y., Chakraborty, S., Zhang, H., Hsieh, C.-J., & Srivastava, M. B. (2019). Genattack: Practical black-box attacks with gradient-free optimization. In: Proceedings of the Genetic and Evolutionary Computation Conference (pp. 1111\u20131119).","DOI":"10.1145\/3321707.3321749"},{"key":"142_CR44","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2020.110767","volume":"170","author":"J Lin","year":"2020","unstructured":"Lin, J., Xu, L., Liu, Y., & Zhang, X. (2020). Black-box adversarial sample generation based on differential evolution. Journal of Systems and Software, 170, 110767.","journal-title":"Journal of Systems and Software"},{"key":"142_CR45","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102947","volume":"123","author":"J Wang","year":"2022","unstructured":"Wang, J., Yin, Z., Jiang, J., Tang, J., & Luo, B. (2022). Pisa: Pixel skipping-based attentional black-box adversarial attack. Computers & Security, 123, 102947.","journal-title":"Computers & Security"},{"issue":"2","key":"142_CR46","doi-asserted-by":"publisher","first-page":"268","DOI":"10.1109\/TAI.2022.3168038","volume":"4","author":"Y Tian","year":"2022","unstructured":"Tian, Y., Pan, J., Yang, S., Zhang, X., He, S., & Jin, Y. (2022). Imperceptible and sparse adversarial attacks via a dual-population-based constrained evolutionary algorithm. IEEE Transactions on Artificial Intelligence, 4(2), 268\u2013281.","journal-title":"IEEE Transactions on Artificial Intelligence"},{"key":"142_CR47","doi-asserted-by":"publisher","first-page":"158051","DOI":"10.1109\/ACCESS.2019.2948146","volume":"7","author":"Q Zhang","year":"2019","unstructured":"Zhang, Q., Wang, K., Zhang, W., & Hu, J. (2019). Attacking black-box image classifiers with particle swarm optimization. IEEE Access, 7, 158051\u2013158063.","journal-title":"IEEE Access"},{"key":"142_CR48","unstructured":"Ilyas, A., Engstrom, L., Athalye, A., & Lin, J. (2018). Black-box adversarial attacks with limited queries and information. In: International Conference on Machine Learning (pp. 2137\u20132146). PMLR."},{"key":"142_CR49","doi-asserted-by":"crossref","unstructured":"Qiu, H., Custode, L.L., & Iacca, G. (2021). Black-box adversarial attacks using evolution strategies. In: Proceedings of the Genetic and Evolutionary Computation Conference Companion (pp. 1827\u20131833).","DOI":"10.1145\/3449726.3463137"},{"key":"142_CR50","doi-asserted-by":"crossref","unstructured":"Li, C., Wang, H., Zhang, J., Yao, W., & Jiang, T. (2022). An approximated gradient sign method using differential evolution for black-box adversarial attack. IEEE Transactions on Evolutionary Computation.","DOI":"10.1109\/TEVC.2022.3151373"},{"key":"142_CR51","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z. B., & Swami, A. (2016). The limitations of deep learning in adversarial settings. In: 2016 IEEE European Symposium on Security and Privacy (EuroS &P) (pp. 372\u2013387). IEEE.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"142_CR52","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.108985","volume":"133","author":"L Giulivi","year":"2023","unstructured":"Giulivi, L., Jere, M., Rossi, L., Koushanfar, F., Ciocarlie, G., Hitaj, B., & Boracchi, G. (2023). Adversarial scratches: Deployable attacks to cnn classifiers. Pattern Recognition, 133, 108985.","journal-title":"Pattern Recognition"},{"issue":"5","key":"142_CR53","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su, J., Vargas, D. V., & Sakurai, K. (2019). One pixel attack for fooling deep neural networks. IEEE Transactions on Evolutionary Computation, 23(5), 828\u2013841.","journal-title":"IEEE Transactions on Evolutionary Computation"},{"issue":"10","key":"142_CR54","doi-asserted-by":"publisher","first-page":"2452","DOI":"10.1109\/TPAMI.2018.2861800","volume":"41","author":"KR Mopuri","year":"2018","unstructured":"Mopuri, K. R., Ganeshan, A., & Babu, R. V. (2018). Generalizable data-free objective for crafting universal adversarial perturbations. IEEE Transactions on Pattern Analysis and Machine Intelligence, 41(10), 2452\u20132465.","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"142_CR55","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.-M., Fawzi, A., Fawzi, O., & Frossard, P. (2017). Universal adversarial perturbations. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (pp. 1765\u20131773).","DOI":"10.1109\/CVPR.2017.17"},{"key":"142_CR56","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108279","volume":"122","author":"A Ghosh","year":"2022","unstructured":"Ghosh, A., Mullick, S. S., Datta, S., Das, S., Das, A. K., & Mallipeddi, R. (2022). A black-box adversarial attack strategy with adjustable sparsity and generalizability for deep image classifiers. Pattern Recognition, 122, 108279.","journal-title":"Pattern Recognition"},{"key":"142_CR57","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1016\/j.ins.2020.10.028","volume":"550","author":"X Wei","year":"2021","unstructured":"Wei, X., Guo, Y., & Li, B. (2021). Black-box adversarial attacks by manipulating image attributes. Information Sciences, 550, 285\u2013296.","journal-title":"Information Sciences"},{"key":"142_CR58","doi-asserted-by":"crossref","unstructured":"Duan, R., Ma, X., Wang, Y., Bailey, J., Qin, A.K., & Yang, Y. (2020). Adversarial camouflage: Hiding physical-world attacks with natural styles. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (pp. 1000\u20131008).","DOI":"10.1109\/CVPR42600.2020.00108"},{"key":"142_CR59","doi-asserted-by":"crossref","unstructured":"Thys, S., Van\u00a0Ranst, W., & Goedem\u00e9, T. (2019). Fooling automated surveillance cameras: adversarial patches to attack person detection. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops.","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"142_CR60","doi-asserted-by":"publisher","first-page":"128","DOI":"10.1016\/j.neucom.2023.03.050","volume":"537","author":"G Tang","year":"2023","unstructured":"Tang, G., Jiang, T., Zhou, W., Li, C., Yao, W., & Zhao, Y. (2023). Adversarial patch attacks against aerial imagery object detectors. Neurocomputing, 537, 128\u2013140.","journal-title":"Neurocomputing"},{"key":"142_CR61","doi-asserted-by":"crossref","unstructured":"Hu, Y.-C.-T., Kung, B.-H., Tan, D.S., Chen, J.-C., Hua, K.-L., & Cheng, W.-H. (2021). Naturalistic physical adversarial patch for object detectors. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (pp. 7848\u20137857).","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"142_CR62","doi-asserted-by":"crossref","unstructured":"Tang, G., Yao, W., Jiang, T., Zhou, W., Yang, Y., & Wang, D. (2023). Natural weather-style black-box adversarial attacks against optical aerial detectors. IEEE Transactions on Geoscience and Remote Sensing.","DOI":"10.1109\/TGRS.2023.3315053"},{"key":"142_CR63","unstructured":"Liu, X., Yang, H., Liu, Z., Song, L., Li, H., & Chen, Y. (2018). Dpatch: An adversarial patch attack on object detectors. arXiv:1806.02299."},{"key":"142_CR64","doi-asserted-by":"crossref","unstructured":"Wang, D., Jiang, T., Sun, J., Zhou, W., Gong, Z., Zhang, X., Yao, W., & Chen, X. (2022). Fca: Learning a 3d full-coverage vehicle camouflage for multi-view physical adversarial attack. In: Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 36, pp. 2414\u20132422).","DOI":"10.1609\/aaai.v36i2.20141"},{"key":"142_CR65","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1016\/j.neunet.2023.03.041","volume":"163","author":"J Sun","year":"2023","unstructured":"Sun, J., Yao, W., Jiang, T., Wang, D., & Chen, X. (2023). Differential evolution based dual adversarial camouflage: Fooling human eyes and object detectors. Neural Networks, 163, 256\u2013271.","journal-title":"Neural Networks"},{"key":"142_CR66","doi-asserted-by":"crossref","unstructured":"Zhu, X., Li, X., Li, J., Wang, Z., & Hu, X. (2021). Fooling thermal infrared pedestrian detectors in real world using small bulbs. In: Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 35, pp. 3616\u20133624).","DOI":"10.1609\/aaai.v35i4.16477"},{"key":"142_CR67","doi-asserted-by":"crossref","unstructured":"Zhu, X., Hu, Z., Huang, S., Li, J., & Hu, X.(2022). Infrared invisible clothing: Hiding from infrared detectors at multiple angles in real world. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (pp. 13317\u201313326).","DOI":"10.1109\/CVPR52688.2022.01296"},{"key":"142_CR68","doi-asserted-by":"crossref","unstructured":"Hu, C., Shi, W., Jiang, T., Yao, W., Tian, L., Chen, X., Zhou, J., & Li, W. (2023). Adversarial infrared blocks: A multi-view black-box attack to thermal infrared detectors in physical world. Available at SSRN 4532269.","DOI":"10.2139\/ssrn.4532269"},{"key":"142_CR69","doi-asserted-by":"crossref","unstructured":"Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., & Yuille, A. (2017). Adversarial examples for semantic segmentation and object detection. In: Proceedings of the IEEE International Conference on Computer Vision (pp. 1369\u20131378).","DOI":"10.1109\/ICCV.2017.153"},{"key":"142_CR70","doi-asserted-by":"crossref","unstructured":"Strudel, R., Garcia, R., Laptev, I., & Schmid, C. (2021). Segmenter: Transformer for semantic segmentation. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV) (pp. 7262\u20137272).","DOI":"10.1109\/ICCV48922.2021.00717"},{"issue":"4","key":"142_CR71","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1145\/1177352.1177355","volume":"38","author":"A Yilmaz","year":"2006","unstructured":"Yilmaz, A., Javed, O., & Shah, M. (2006). Object tracking: A survey. ACM Computing Survey, 38(4), 13. https:\/\/doi.org\/10.1145\/1177352.1177355","journal-title":"ACM Computing Survey"},{"issue":"12","key":"142_CR72","doi-asserted-by":"publisher","first-page":"4338","DOI":"10.1109\/TPAMI.2020.3005434","volume":"43","author":"Y Guo","year":"2021","unstructured":"Guo, Y., Wang, H., Hu, Q., Liu, H., Liu, L., & Bennamoun, M. (2021). Deep learning for 3d point clouds: A survey. IEEE Transactions on Pattern Analysis and Machine Intelligence, 43(12), 4338\u20134364. https:\/\/doi.org\/10.1109\/TPAMI.2020.3005434","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"142_CR73","doi-asserted-by":"crossref","unstructured":"Arnab, A., Miksik, O., & Torr, P. H. S. (2018). On the robustness of semantic segmentation models to adversarial attacks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR).","DOI":"10.1109\/CVPR.2018.00099"},{"key":"142_CR74","doi-asserted-by":"crossref","unstructured":"Nesti, F., Rossolini, G., Nair, S., Biondi, A., & Buttazzo, G.(2022). Evaluating the robustness of semantic segmentation for autonomous driving against real-world adversarial patch attacks. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision (WACV) (pp. 2280\u20132289).","DOI":"10.1109\/WACV51458.2022.00288"},{"key":"142_CR75","doi-asserted-by":"crossref","unstructured":"Wiyatno, R. R., Xu, A.(2019). Physical adversarial textures that fool visual object tracking. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV).","DOI":"10.1109\/ICCV.2019.00492"},{"key":"142_CR76","doi-asserted-by":"crossref","unstructured":"Yan, B., Wang, D., Lu, H., & Yang, X. (2020). Cooling-shrinking attack: Blinding the tracker with imperceptible noises. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR).","DOI":"10.1109\/CVPR42600.2020.00107"},{"key":"142_CR77","doi-asserted-by":"crossref","unstructured":"Chen, X., Yan, X., Zheng, F., Jiang, Y., Xia, S.-T., Zhao, Y., & Ji, R. (2020). One-shot adversarial attacks on visual tracking with dual attention. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR).","DOI":"10.1109\/CVPR42600.2020.01019"},{"key":"142_CR78","unstructured":"Cao, Y., Xiao, C., Yang, D., Fang, J., Yang, R., Liu, M., & Li, B. (2019). Adversarial Objects Against LiDAR-Based Autonomous Driving Systems."},{"key":"142_CR79","doi-asserted-by":"crossref","unstructured":"Zheng, S., Song, Y., Leung, T., & Goodfellow, I.(2016). Improving the robustness of deep neural networks via stability training. In: Proceedings of the Ieee Conference on Computer Vision and Pattern Recognition (pp. 4480\u20134488).","DOI":"10.1109\/CVPR.2016.485"},{"key":"142_CR80","doi-asserted-by":"crossref","unstructured":"Ross, A., & Doshi-Velez, F.(2018). Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In: Proceedings of the AAAI Conference on Artificial Intelligence (Vol. 32).","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"142_CR81","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.110038","volume":"146","author":"J Sun","year":"2024","unstructured":"Sun, J., Yao, W., Jiang, T., & Chen, X. (2024). Efficient search of comprehensively robust neural architectures via multi-fidelity evaluation. Pattern Recognition, 146, 110038.","journal-title":"Pattern Recognition"},{"key":"142_CR82","doi-asserted-by":"publisher","unstructured":"Zhou, X., Qin, A. K., Sun, Y., & Tan, K. C. (2021). A survey of advances in evolutionary neural architecture search. In: 2021 IEEE Congress on Evolutionary Computation (CEC) (pp. 950\u2013957). https:\/\/doi.org\/10.1109\/CEC45853.2021.9504890.","DOI":"10.1109\/CEC45853.2021.9504890"},{"issue":"5","key":"142_CR83","doi-asserted-by":"publisher","first-page":"894","DOI":"10.1109\/TEVC.2021.3079985","volume":"25","author":"X Zhou","year":"2021","unstructured":"Zhou, X., Qin, A. K., Gong, M., & Tan, K. C. (2021). A survey on evolutionary construction of deep neural networks. IEEE Transactions on Evolutionary Computation, 25(5), 894\u2013912. https:\/\/doi.org\/10.1109\/TEVC.2021.3079985","journal-title":"IEEE Transactions on Evolutionary Computation"},{"key":"142_CR84","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/j.neucom.2021.04.111","volume":"453","author":"J Liu","year":"2021","unstructured":"Liu, J., & Jin, Y. (2021). Multi-objective search of robust neural architectures against multiple types of adversarial attacks. Neurocomputing, 453, 73\u201384.","journal-title":"Neurocomputing"},{"key":"142_CR85","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., & Yuille, A. (2017) Mitigating adversarial effects through randomization. arXiv:1711.01991."},{"key":"142_CR86","unstructured":"Dziugaite, G. K., Ghahramani, Z., & Roy, D. M. (2016). A study of the effect of jpg compression on adversarial images. arXiv:1608.00853."},{"key":"142_CR87","doi-asserted-by":"crossref","unstructured":"Xu, W., Evans, D., & Qi, Y. (2017). Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv:1704.01155.","DOI":"10.14722\/ndss.2018.23198"}],"container-title":["Journal of Membrane Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s41965-024-00142-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s41965-024-00142-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s41965-024-00142-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,6,3]],"date-time":"2024-06-03T08:08:52Z","timestamp":1717402132000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s41965-024-00142-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,10]]},"references-count":87,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,6]]}},"alternative-id":["142"],"URL":"https:\/\/doi.org\/10.1007\/s41965-024-00142-3","relation":{},"ISSN":["2523-8906","2523-8914"],"issn-type":[{"value":"2523-8906","type":"print"},{"value":"2523-8914","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4,10]]},"assertion":[{"value":"12 December 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 April 2024","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}]}}