{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T02:19:30Z","timestamp":1783045170218,"version":"3.54.6"},"reference-count":60,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2026A1515011438"],"award-info":[{"award-number":["2026A1515011438"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["GZC20252314"],"award-info":[{"award-number":["GZC20252314"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62506393"],"award-info":[{"award-number":["62506393"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.eswa.2026.132647","type":"journal-article","created":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T15:33:38Z","timestamp":1778340818000},"page":"132647","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["RDPA: A concealed and perilous physical adversarial attack for nighttime traffic signs recognition"],"prefix":"10.1016","volume":"327","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8643-1685","authenticated-orcid":false,"given":"Hongfei","family":"Suo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2042-2054","authenticated-orcid":false,"given":"Quan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-2324-7396","authenticated-orcid":false,"given":"Shuhuai","family":"Gu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1071-4966","authenticated-orcid":false,"given":"Hongbo","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.132647_bib0001","series-title":"International conference on machine learning","first-page":"284","article-title":"Synthesizing robust adversarial examples","author":"Athalye","year":"2018"},{"key":"10.1016\/j.eswa.2026.132647_bib0002","doi-asserted-by":"crossref","first-page":"1053","DOI":"10.1109\/OJITS.2025.3589563","article-title":"Reliable traffic sign recognition: Are we finally there?","volume":"6","author":"Atif","year":"2025","journal-title":"IEEE Open Journal of Intelligent Transportation Systems"},{"key":"10.1016\/j.eswa.2026.132647_bib0003","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2022.109037","article-title":"Query efficient black-box adversarial attack on deep neural networks","volume":"133","author":"Bai","year":"2023","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132647_bib0004","article-title":"Adversarial patch","author":"Brown","year":"2017","journal-title":"NeurIPS Workshop on Machine Learning and Computer Security"},{"key":"10.1016\/j.eswa.2026.132647_bib0005","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.111508","article-title":"Unsupervised group re-identification from aerial perspective via strategic member harmonization","volume":"164","author":"Chen","year":"2025","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132647_bib0006","series-title":"Proceedings of the 10th ACM workshop on artificial intelligence and security","first-page":"15","article-title":"Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models","author":"Chen","year":"2017"},{"key":"10.1016\/j.eswa.2026.132647_bib0007","series-title":"Proceedings of the international conference on knowledge science, engineering and management","first-page":"220","article-title":"Lurking in the shadows: Imperceptible shadow black-box attacks against lane detection models","author":"Cui","year":"2024"},{"key":"10.1016\/j.eswa.2026.132647_bib0008","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.112244","article-title":"Targeted attack via adversarial patch outside bounding box","volume":"171","author":"Deng","year":"2026","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132647_bib0009","doi-asserted-by":"crossref","first-page":"2596","DOI":"10.1109\/TIFS.2023.3266702","article-title":"Restricted black-box adversarial attack against deepfake face swapping","volume":"18","author":"Dong","year":"2023","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.132647_bib0010","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"16062","article-title":"Adversarial laser beam: Effective physical-world attack to dnns in a blink","author":"Duan","year":"2021"},{"key":"10.1016\/j.eswa.2026.132647_bib0011","unstructured":"Etim, A., & Szefer, J. (2025). Adversarial universal stickers: Universal perturbation attacks on traffic sign using stickers. 10.48550\/arXiv.2502.18724."},{"key":"10.1016\/j.eswa.2026.132647_bib0012","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"1625","article-title":"Robust physical-world attacks on deep learning visual classification","author":"Eykholt","year":"2018"},{"key":"10.1016\/j.eswa.2026.132647_bib0013","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2022.108985","article-title":"Adversarial scratches: Deployable attacks to CNN classifiers","volume":"133","author":"Giulivi","year":"2023","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132647_bib0014","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision workshops","first-page":"92","article-title":"Optical adversarial attack","author":"Gnanasambandam","year":"2021"},{"key":"10.1016\/j.eswa.2026.132647_bib0015","series-title":"Proceedings of the international conference on learning representations","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015"},{"issue":"4","key":"10.1016\/j.eswa.2026.132647_bib0016","doi-asserted-by":"crossref","first-page":"2568","DOI":"10.1109\/TDSC.2023.3313577","article-title":"VeriDIP: Verifying ownership of deep neural networks through privacy leakage fingerprints","volume":"21","author":"Hu","year":"2023","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.eswa.2026.132647_bib0017","series-title":"Proceedings of the 32nd ACM conference on hypertext and social media","first-page":"111","article-title":"Structack: Structure-based adversarial attacks on graph neural networks","author":"Hussain","year":"2021"},{"key":"10.1016\/j.eswa.2026.132647_bib0018","unstructured":"Ji, H., Hu, T., Li, H., Jin, L., Xin, C., Yao, Y., & Xiao, J. (2025). The outline of deception: Physical adversarial attacks on traffic signs using edge patches. 10.48550\/arXiv.2512.00765."},{"key":"10.1016\/j.eswa.2026.132647_bib0019","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.128589","article-title":"A real world attack model combining LED modulation and attention-superpixel guidance","volume":"293","author":"Jiang","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132647_bib0020","series-title":"Artificial intelligence safety and security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"issue":"3","key":"10.1016\/j.eswa.2026.132647_bib0021","doi-asserted-by":"crossref","first-page":"2243","DOI":"10.1109\/TDSC.2024.3482707","article-title":"On security weaknesses and vulnerabilities in deep learning systems","volume":"22","author":"Lai","year":"2025","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.eswa.2026.132647_bib0022","unstructured":"Lin, J., Song, C., He, K., Wang, L., & Hopcroft, J. E. (2019). Nesterov accelerated gradient and scale invariance for adversarial attacks. 10.48550\/arXiv.1908.06281."},{"key":"10.1016\/j.eswa.2026.132647_bib0023","unstructured":"Liu, J., Lu, B., Xiong, M., Zhang, T., & Xiong, H. (2023). Adversarial attack with raindrops. 10.48550\/arXiv.2302.14267."},{"key":"10.1016\/j.eswa.2026.132647_bib0024","series-title":"Proceedings of the computer vision and pattern recognition conference","first-page":"128","article-title":"OverloCK: An overview-first-look-closely-next convnet with context-mixing dynamic kernels","author":"Lou","year":"2025"},{"key":"10.1016\/j.eswa.2026.132647_bib0025","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"102","article-title":"Set-level guidance attack: Boosting adversarial transferability of vision-language pre-training models","author":"Lu","year":"2023"},{"key":"10.1016\/j.eswa.2026.132647_bib0026","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"15315","article-title":"Frequency-driven imperceptible adversarial attack on semantic similarity","author":"Luo","year":"2022"},{"issue":"1","key":"10.1016\/j.eswa.2026.132647_bib0027","article-title":"Efficient black-box attack with surrogate models and multiple universal adversarial perturbations","volume":"15","author":"Ma","year":"2025","journal-title":"Scientific Reports"},{"issue":"4","key":"10.1016\/j.eswa.2026.132647_bib0028","doi-asserted-by":"crossref","first-page":"1484","DOI":"10.1109\/TITS.2012.2209421","article-title":"Vision-based traffic sign detection and analysis for intelligent driver assistance systems: Perspectives and survey","volume":"13","author":"Mogelmose","year":"2012","journal-title":"IEEE Transactions on Intelligent Transportation Systems"},{"key":"10.1016\/j.eswa.2026.132647_bib0029","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.111893","article-title":"Generative attack in complex real-world scenarios","volume":"169","author":"Peng","year":"2026","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132647_bib0030","series-title":"Proceedings of network and distributed system security symposium","first-page":"1","article-title":"Invisible reflections: Leveraging infrared laser reflections to target traffic sign perception","author":"Sato","year":"2024"},{"key":"10.1016\/j.eswa.2026.132647_bib0031","series-title":"Proceedings of the 2018 workshop on attacks and solutions in hardware security","first-page":"1","article-title":"Acoustic denial of service attacks on hard disk drives","author":"Shahrad","year":"2018"},{"key":"10.1016\/j.eswa.2026.132647_bib0032","series-title":"Proceedings of network and distributed system security symposium","first-page":"1","article-title":"Flytrap: Physical distance-pulling attack towards camera-based autonomous target tracking systems","author":"Shao","year":"2026"},{"issue":"1","key":"10.1016\/j.eswa.2026.132647_bib0033","doi-asserted-by":"crossref","first-page":"178","DOI":"10.1109\/TAFFC.2021.3064601","article-title":"Self-supervised learning of person-specific facial dynamics for automatic personality recognition","volume":"14","author":"Song","year":"2021","journal-title":"IEEE Transactions on Affective Computing"},{"key":"10.1016\/j.eswa.2026.132647_bib0034","doi-asserted-by":"crossref","first-page":"323","DOI":"10.1016\/j.neunet.2012.02.016","article-title":"Man vs. computer: Benchmarking machine learning algorithms for traffic sign recognition","volume":"32","author":"Stallkamp","year":"2012","journal-title":"Neural Networks"},{"issue":"5","key":"10.1016\/j.eswa.2026.132647_bib0035","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","article-title":"One pixel attack for fooling deep neural networks","volume":"23","author":"Su","year":"2019","journal-title":"IEEE Transactions on Evolutionary Computation"},{"key":"10.1016\/j.eswa.2026.132647_bib0036","series-title":"Proceedings of the international conference on learning representations","first-page":"1","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"key":"10.1016\/j.eswa.2026.132647_bib0037","series-title":"Proceedings of the 2024 conference on empirical methods in natural language processing","first-page":"1610","article-title":"Glue pizza and eat rocks-exploiting vulnerabilities in retrieval-augmented generative models","author":"Tan","year":"2024"},{"key":"10.1016\/j.eswa.2026.132647_bib0038","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"742","article-title":"Autozoom: Autoencoder-based zeroth order optimization method for attacking black-box neural networks","volume":"33","author":"Tu","year":"2019"},{"key":"10.1016\/j.eswa.2026.132647_bib0039","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"4455","article-title":"Rfla: A stealthy reflected light adversarial attack in the physical world","author":"Wang","year":"2023"},{"key":"10.1016\/j.eswa.2026.132647_bib0040","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.110449","article-title":"Multi-target label backdoor attacks on graph neural networks","volume":"152","author":"Wang","year":"2024","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132647_bib0041","doi-asserted-by":"crossref","first-page":"5476","DOI":"10.1109\/TIFS.2024.3402155","article-title":"Progen: Projection-based adversarial attack generation against network intrusion detection","volume":"19","author":"Wang","year":"2024","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"3","key":"10.1016\/j.eswa.2026.132647_bib0042","first-page":"2711","article-title":"Adversarial sticker: A stealthy attack method in the physical world","volume":"45","author":"Wei","year":"2022","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.eswa.2026.132647_bib0043","series-title":"Proceedings of the 28th ACM international conference on multimedia","first-page":"2802","article-title":"Learning optimization-based adversarial perturbations for attacking sequential recognition models","author":"Xu","year":"2020"},{"key":"10.1016\/j.eswa.2026.132647_bib0044","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"12733","article-title":"Physical backdoor: Towards temperature-based backdoor attacks in the physical world","author":"Yin","year":"2024"},{"key":"10.1016\/j.eswa.2026.132647_bib0045","series-title":"Proceedings of the European conference on computer vision","first-page":"1","article-title":"Adaptive image transformations for transfer-based adversarial attack","author":"Yuan","year":"2022"},{"key":"10.1016\/j.eswa.2026.132647_bib0046","article-title":"Secure video quality assessment resisting adversarial attacks","author":"Zhang","year":"2025","journal-title":"IEEE Transactions on Broadcasting"},{"key":"10.1016\/j.eswa.2026.132647_bib0047","doi-asserted-by":"crossref","first-page":"352","DOI":"10.1109\/TIP.2021.3128330","article-title":"Seeing like a human: Asynchronous learning with dynamic progressive refinement for person re-identification","volume":"31","author":"Zhang","year":"2021","journal-title":"IEEE Transactions on Image Processing"},{"issue":"8","key":"10.1016\/j.eswa.2026.132647_bib0048","doi-asserted-by":"crossref","first-page":"3046","DOI":"10.1007\/s11263-024-02013-x","article-title":"Uncertainty modeling for group re-identification","volume":"132","author":"Zhang","year":"2024","journal-title":"International Journal of Computer Vision"},{"key":"10.1016\/j.eswa.2026.132647_bib0049","doi-asserted-by":"crossref","first-page":"8019","DOI":"10.1109\/TIP.2021.3112035","article-title":"Learning modal-invariant angular metric by cyclic projection network for VIS-NIR person re-identification","volume":"30","author":"Zhang","year":"2021","journal-title":"IEEE Transactions on Image Processing"},{"issue":"8","key":"10.1016\/j.eswa.2026.132647_bib0050","doi-asserted-by":"crossref","first-page":"5791","DOI":"10.1109\/TPAMI.2024.3369483","article-title":"Separable spatial-temporal residual graph for cloth-changing group re-identification","volume":"46","author":"Zhang","year":"2024","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.eswa.2026.132647_bib0051","series-title":"Ieee conference on computer vision and pattern recognition","first-page":"22000","article-title":"View-decoupled transformer for person re-identification under aerial-ground camera network","author":"Zhang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132647_bib0052","series-title":"2024\u202fIEEE 26th international workshop on multimedia signal processing (MMSP)","first-page":"1","article-title":"Multi-network ensembling for GAN training and adversarial attacks","author":"Zheng","year":"2024"},{"key":"10.1016\/j.eswa.2026.132647_bib0053","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2022.109009","article-title":"Robust physical-world attacks on face recognition","volume":"133","author":"Zheng","year":"2023","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.132647_bib0054","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"15345","article-title":"Shadows can be dangerous: Stealthy and effective physical-world adversarial attack by natural phenomenon","author":"Zhong","year":"2022"},{"key":"10.1016\/j.eswa.2026.132647_bib0055","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2025.113686","article-title":"Query-efficient hard-label black-box attack against vision transformers","volume":"183","author":"Zhou","year":"2025","journal-title":"Applied Soft Computing"},{"key":"10.1016\/j.eswa.2026.132647_bib0056","doi-asserted-by":"crossref","DOI":"10.1016\/j.jisa.2024.103710","article-title":"Object-attentional untargeted adversarial attack","volume":"81","author":"Zhou","year":"2024","journal-title":"Journal of Information Security and Applications"},{"key":"10.1016\/j.eswa.2026.132647_bib0057","series-title":"International conference on security and privacy in cyber-physical systems and smart vehicles","first-page":"259","article-title":"Transient adversarial 3d projection attacks on object detection in autonomous driving","author":"Zhou","year":"2024"},{"key":"10.1016\/j.eswa.2026.132647_bib0058","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"20730","article-title":"Uniface: Unified cross-entropy loss for deep face recognition","author":"Zhou","year":"2023"},{"key":"10.1016\/j.eswa.2026.132647_bib0059","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"234","article-title":"Dast: Data-free substitute training for adversarial attacks","author":"Zhou","year":"2020"},{"key":"10.1016\/j.eswa.2026.132647_bib0060","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"24284","article-title":"Infrared adversarial car stickers","author":"Zhu","year":"2024"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426015605?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426015605?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T01:58:13Z","timestamp":1783043893000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426015605"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":60,"alternative-id":["S0957417426015605"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132647","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"RDPA: A concealed and perilous physical adversarial attack for nighttime traffic signs recognition","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132647","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"132647"}}