{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,26]],"date-time":"2026-07-26T14:01:53Z","timestamp":1785074513638,"version":"3.55.0"},"reference-count":53,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100012154","name":"Graduate Research and Innovation Projects of Jiangsu Province","doi-asserted-by":"publisher","award":["KYCX25_1147"],"award-info":[{"award-number":["KYCX25_1147"]}],"id":[{"id":"10.13039\/501100012154","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010014","name":"Six Talent Peaks Project in Jiangsu Province","doi-asserted-by":"publisher","award":["RJFW-111"],"award-info":[{"award-number":["RJFW-111"]}],"id":[{"id":"10.13039\/501100010014","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Knowledge-Based Systems"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.knosys.2026.116425","type":"journal-article","created":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T15:41:32Z","timestamp":1781278892000},"page":"116425","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["MPQD-ADM: High-efficiency adversarial patch defense method based on mixed pixel quality differences"],"prefix":"10.1016","volume":"349","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-1017-4365","authenticated-orcid":false,"given":"Wenlong","family":"Zheng","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuhao","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Heng","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5026-5347","authenticated-orcid":false,"given":"Peng","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2809-2237","authenticated-orcid":false,"given":"He","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.knosys.2026.116425_b1","doi-asserted-by":"crossref","unstructured":"A. Ghosh, D.R. Narapureddy, C. Mertz, S.G. Narasimhan, Learned two-plane perspective prior based image resampling for efficient object detection, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 13364\u201313373.","DOI":"10.1109\/CVPR52729.2023.01284"},{"key":"10.1016\/j.knosys.2026.116425_b2","doi-asserted-by":"crossref","unstructured":"J.U. Kim, S. Park, Y.M. Ro, Towards versatile pedestrian detector with multisensory-matching and multispectral recalling memory, in: Proceedings of the AAAI Conference on Artificial Intelligence, 2022, pp. 1157\u20131165.","DOI":"10.1609\/aaai.v36i1.20001"},{"key":"10.1016\/j.knosys.2026.116425_b3","doi-asserted-by":"crossref","unstructured":"W. Zheng, W. Tang, L. Jiang, C.W. Fu, SE-SSD: Self-ensembling single-stage object detector from point cloud, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2021, pp. 14489\u201314498.","DOI":"10.1109\/CVPR46437.2021.01426"},{"key":"10.1016\/j.knosys.2026.116425_b4","first-page":"10164","article-title":"End-to-end autonomous driving: Challenges and frontiers","volume":"vol. 46","author":"Chen","year":"2023"},{"key":"10.1016\/j.knosys.2026.116425_b5","doi-asserted-by":"crossref","unstructured":"Z. Hu, S. Huang, X. Zhu, F. Sun, B. Zhang, X. Hu, Adversarial texture for fooling person detectors in the physical world, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 7828\u20137837.","DOI":"10.1109\/CVPR52688.2022.01295"},{"key":"10.1016\/j.knosys.2026.116425_b6","unstructured":"Y.C. Hu, J.C. Chen, B.H. Kung, K.L. Hua, D.S. Tan, Naturalistic physical adversarial patch for object detectors, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 13297\u201313306."},{"key":"10.1016\/j.knosys.2026.116425_b7","doi-asserted-by":"crossref","unstructured":"J. Zheng, C. Lin, J. Sun, Z. Zhao, Q. Li, C. Shen, Physical 3D adversarial attacks against monocular depth estimation in autonomous driving, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24452\u201324461.","DOI":"10.1109\/CVPR52733.2024.02308"},{"key":"10.1016\/j.knosys.2026.116425_b8","series-title":"Adversarial attack with raindrops","author":"Liu","year":"2023"},{"key":"10.1016\/j.knosys.2026.116425_b9","doi-asserted-by":"crossref","unstructured":"P.N. Williams, K. Li, Black-box sparse adversarial attack via multi-objective optimisation CVPR proceedings, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 12291\u201312301.","DOI":"10.1109\/CVPR52729.2023.01183"},{"key":"10.1016\/j.knosys.2026.116425_b10","unstructured":"I. Goodfellow, J. Shlens, C. Szegedy, Explaining and harnessing adversarial examples, in: Proceedings of the International Conference on Learning Representations, 2015, pp. 1\u201311."},{"key":"10.1016\/j.knosys.2026.116425_b11","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards deep learning models resistant to adversarial attacks, in: Proceedings of the International Conference on Learning Representations, 2018, pp. 1\u201323."},{"key":"10.1016\/j.knosys.2026.116425_b12","doi-asserted-by":"crossref","unstructured":"G. Jin, X. Yi, D. Wu, R. Mu, X. Huang, Randomized adversarial training via taylor expansion, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 16447\u201316457.","DOI":"10.1109\/CVPR52729.2023.01578"},{"key":"10.1016\/j.knosys.2026.116425_b13","unstructured":"L. Rice, E. Wong, Z. Kolter, Overfitting in adversarially robust deep learning, in: Proceedings of the International Conference on Machine Learning, 2020, pp. 8093\u20138104."},{"key":"10.1016\/j.knosys.2026.116425_b14","doi-asserted-by":"crossref","unstructured":"T. Li, Y. Wu, S. Chen, K. Fang, X. Huang, Subspace adversarial training, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 13399\u201313408.","DOI":"10.1109\/CVPR52688.2022.01305"},{"key":"10.1016\/j.knosys.2026.116425_b15","doi-asserted-by":"crossref","unstructured":"C. Dong, L. Liu, J. Shang, Label noise in adversarial training: A novel perspective to study robust overfitting, in: Proceedings of the Advances in Neural Information Processing Systems, 2022, pp. 17556\u201317567.","DOI":"10.52202\/068431-1276"},{"key":"10.1016\/j.knosys.2026.116425_b16","unstructured":"J. Cohen, E. Rosenfeld, Z. Kolter, Certified adversarial robustness via randomized smoothing, in: Proceedings of the International Conference on Machine Learning, 2019, pp. 1310\u20131320."},{"key":"10.1016\/j.knosys.2026.116425_b17","unstructured":"A. Raghunathan, J. Steinhardt, P. Liang, Certified defenses against adversarial examples, in: Proceedings of the International Conference on Learning Representations, 2018, pp. 1\u201315."},{"key":"10.1016\/j.knosys.2026.116425_b18","unstructured":"E. Wong, Z. Kolter, Provable defenses against adversarial examples via the convex outer adversarial polytope, in: Proceedings of the International Conference on Machine Learning, 2018, pp. 5286\u20135295."},{"key":"10.1016\/j.knosys.2026.116425_b19","doi-asserted-by":"crossref","unstructured":"J. Liu, A. Levine, C.P. Lau, R. Chellappa, S. Feizi, Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 14953\u201314962.","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"10.1016\/j.knosys.2026.116425_b20","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"4087","article-title":"Jedi: Entropy-based localization and removal of adversarial patches","author":"Tarchoun","year":"2023"},{"key":"10.1016\/j.knosys.2026.116425_b21","doi-asserted-by":"crossref","unstructured":"J. Feng, et al., Fight fire with fire: Combating adversarial patch attacks using pattern-randomized defensive patches, in: Proceedings of the IEEE Symposium on Security and Privacy, 2025, pp. 2133\u20132151.","DOI":"10.1109\/SP61157.2025.00006"},{"key":"10.1016\/j.knosys.2026.116425_b22","doi-asserted-by":"crossref","unstructured":"C. Xiang, P. Mittal, DetectorGuard: Provably securing object detectors against localized patch hiding attacks, in: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2021, pp. 3177\u20133196.","DOI":"10.1145\/3460120.3484757"},{"key":"10.1016\/j.knosys.2026.116425_b23","doi-asserted-by":"crossref","unstructured":"W. Xu, D. Evans, Y. Qi, Feature squeezing: Detecting adversarial examples in deep neural networks, in: Proceedings of the Network and Distributed Systems Security Symposium, 2018, pp. 1\u201315.","DOI":"10.14722\/ndss.2018.23198"},{"key":"10.1016\/j.knosys.2026.116425_b24","doi-asserted-by":"crossref","unstructured":"C. Xiang, A. Valtchanov, S. Mahloujifar, P. Mittal, ObjectSeeker: Certifiably robust object detection against patch hiding attacks via patch-agnostic masking, in: Proceedings of the IEEE Symposium on Security and Privacy, 2022, pp. 1329\u20131347.","DOI":"10.1109\/SP46215.2023.10179319"},{"key":"10.1016\/j.knosys.2026.116425_b25","doi-asserted-by":"crossref","unstructured":"C.X. Kang, et al., DIFFender: Diffusion-based adversarial defense against patch attacks, in: Proceedings of the International Conference on Learning Representations, 2024, pp. 1\u201318.","DOI":"10.1007\/978-3-031-72943-0_8"},{"key":"10.1016\/j.knosys.2026.116425_b26","doi-asserted-by":"crossref","unstructured":"L. Jing, R. Wang, W. Ren, X. Dong, C. Zou, PAD: Patch-agnostic defense against adversarial patch attacks, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24472\u201324481.","DOI":"10.1109\/CVPR52733.2024.02310"},{"key":"10.1016\/j.knosys.2026.116425_b27","first-page":"1137","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","volume":"vol. 39","author":"Ren","year":"2017"},{"key":"10.1016\/j.knosys.2026.116425_b28","doi-asserted-by":"crossref","unstructured":"J. Redmon, S.K. Divvala, R.B. Girshick, A. Farhadi, You only look once: Unified, real-time object detection, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2016, pp. 779\u2013788.","DOI":"10.1109\/CVPR.2016.91"},{"key":"10.1016\/j.knosys.2026.116425_b29","series-title":"Adversarial patch","author":"Brown","year":"2017"},{"key":"10.1016\/j.knosys.2026.116425_b30","unstructured":"D. Karmon, D. Zoran, Y. Goldberg, LaVAN: Localized and visible adversarial noise, in: Proceedings of the International Conference on Machine Learning, 2018, pp. 2507\u20132515."},{"key":"10.1016\/j.knosys.2026.116425_b31","doi-asserted-by":"crossref","unstructured":"M. Zajac, N. Rostamzadeh K. Zo\u0142 na, P. Pinheiro, Adversarial framing for image and video classification, in: Proceedings of the AAAI Conference on Artificial Intelligence, 2019, pp. 10077\u201310078.","DOI":"10.1609\/aaai.v33i01.330110077"},{"key":"10.1016\/j.knosys.2026.116425_b32","doi-asserted-by":"crossref","unstructured":"S. Thys, W.V. Ranst, T. Goedem\u00e9, Fooling automated surveillance cameras: Adversarial patches to attack person detection, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, 2019, pp. 49\u201355.","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"10.1016\/j.knosys.2026.116425_b33","doi-asserted-by":"crossref","unstructured":"X. Wei, Y. Huang, Y. Sun, J. Yu, Unified adversarial patch for cross-modal attacks in the physical world, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2023, pp. 4422\u20134431.","DOI":"10.1109\/ICCV51070.2023.00410"},{"key":"10.1016\/j.knosys.2026.116425_b34","doi-asserted-by":"crossref","unstructured":"A. Guesmi, R. Ding, M.A. Hanif, I. Alouani, M. Shafique, DAP: A dynamic adversarial patch for evading person detectors, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24595\u201324604.","DOI":"10.1109\/CVPR52733.2024.02322"},{"key":"10.1016\/j.knosys.2026.116425_b35","unstructured":"A. Athalye, N. Carlini, D. Wagner, Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples, in: Proceedings of the International Conference on Machine Learning, 2018, pp. 274\u2013283."},{"key":"10.1016\/j.knosys.2026.116425_b36","doi-asserted-by":"crossref","unstructured":"T. Chen, S. Liu, S. Chang, Y. Cheng, L. Amini, Z. Wang, Adversarial robustness: From self-supervised pre-training to fine-tuning, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2020, pp. 696\u2013705.","DOI":"10.1109\/CVPR42600.2020.00078"},{"key":"10.1016\/j.knosys.2026.116425_b37","doi-asserted-by":"crossref","unstructured":"K.L. Navaneet, S.A. Koohpayegani, E. Sleiman, H. Pirsiavash, SlowFormer: Adversarial attack on compute and energy consumption of efficient vision transformers, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24786\u201324797.","DOI":"10.1109\/CVPR52733.2024.02341"},{"key":"10.1016\/j.knosys.2026.116425_b38","doi-asserted-by":"crossref","unstructured":"J. Hayes, On visible adversarial perturbations & digital watermarking, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, 2018, pp. 1678\u201316787.","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"10.1016\/j.knosys.2026.116425_b39","doi-asserted-by":"crossref","unstructured":"M. Naseer, S.H. Khan, F.M. Porikli, Local gradients smoothing: Defense against localized adversarial attacks, in: Proceedings of the IEEE Winter Conference on Applications of Computer Vision, 2018, pp. 1300\u20131307.","DOI":"10.1109\/WACV.2019.00143"},{"key":"10.1016\/j.knosys.2026.116425_b40","doi-asserted-by":"crossref","unstructured":"A. Kirillov, et al., Segment anything, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 3992\u20134003.","DOI":"10.1109\/ICCV51070.2023.00371"},{"key":"10.1016\/j.knosys.2026.116425_b41","first-page":"154","article-title":"Exposing digital forgeries from JPEG ghosts","volume":"vol. 4","author":"Farid","year":"2009"},{"key":"10.1016\/j.knosys.2026.116425_b42","first-page":"1003","article-title":"Image forgery localization via block-grained analysis of JPEG artifacts","volume":"7","author":"Bianchi","year":"2012"},{"key":"10.1016\/j.knosys.2026.116425_b43","first-page":"674","article-title":"A theory for multiresolution signal decomposition: the wavelet representation","volume":"vol. 11","author":"Mallat","year":"1989"},{"key":"10.1016\/j.knosys.2026.116425_b44","doi-asserted-by":"crossref","unstructured":"A. Kirillov, et al., Microsoft COCO: Common objects in context, in: Proceedings of the European Conference on Computer Vision, 2014, pp. 740\u2013755.","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"10.1016\/j.knosys.2026.116425_b45","doi-asserted-by":"crossref","unstructured":"N. Dalal, B. Triggs, Histograms of oriented gradients for human detection, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2005, pp. 886\u2013893.","DOI":"10.1109\/CVPR.2005.177"},{"key":"10.1016\/j.knosys.2026.116425_b46","doi-asserted-by":"crossref","unstructured":"J. Redmon, A. Farhadi, YOLO9000: Better, faster, stronger, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2017, pp. 6517\u20136525.","DOI":"10.1109\/CVPR.2017.690"},{"key":"10.1016\/j.knosys.2026.116425_b47","series-title":"YOLOv3: An incremental improvement","author":"Redmon","year":"2018"},{"key":"10.1016\/j.knosys.2026.116425_b48","series-title":"YOLOv5 release v6.0","author":"Jocher","year":"2020"},{"key":"10.1016\/j.knosys.2026.116425_b49","first-page":"691","article-title":"You only learn one representation: Unified network for multiple tasks","volume":"vol. 39","author":"Wang","year":"2021"},{"key":"10.1016\/j.knosys.2026.116425_b50","series-title":"Adversarial YOLO: Defense human detection patch attacks via detecting adversarial patches","author":"Ji","year":"2021"},{"key":"10.1016\/j.knosys.2026.116425_b51","doi-asserted-by":"crossref","unstructured":"H. Huang, Z. Chen, H. Chen, Y. Wang, K. Zhang, T-SEA: Transfer-based self-ensemble attack on object detection, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 20514\u201320523.","DOI":"10.1109\/CVPR52729.2023.01965"},{"issue":"12","key":"10.1016\/j.knosys.2026.116425_b52","doi-asserted-by":"crossref","first-page":"11124","DOI":"10.1109\/TPAMI.2025.3596462","article-title":"Real-world adversarial defense against patch attacks based on diffusion model","volume":"47","author":"Wei","year":"2025","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"1","key":"10.1016\/j.knosys.2026.116425_b53","doi-asserted-by":"crossref","first-page":"1410","DOI":"10.1109\/TNNLS.2023.3326871","article-title":"Improving adversarial robustness against universal patch attacks through feature norm suppressing","volume":"36","author":"Yu","year":"2025","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."}],"container-title":["Knowledge-Based Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126011512?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126011512?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,26]],"date-time":"2026-07-26T13:28:14Z","timestamp":1785072494000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0950705126011512"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":53,"alternative-id":["S0950705126011512"],"URL":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116425","relation":{},"ISSN":["0950-7051"],"issn-type":[{"value":"0950-7051","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"MPQD-ADM: High-efficiency adversarial patch defense method based on mixed pixel quality differences","name":"articletitle","label":"Article Title"},{"value":"Knowledge-Based Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116425","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"116425"}}