{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,27]],"date-time":"2026-08-27T17:18:27Z","timestamp":1787851107004,"version":"build-2784847793"},"reference-count":227,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100020084","name":"Guangzhou Municipal Science and Technology Bureau","doi-asserted-by":"publisher","award":["202009020002"],"award-info":[{"award-number":["202009020002"]}],"id":[{"id":"10.13039\/501100020084","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neurocomputing"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.neucom.2026.133884","type":"journal-article","created":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T23:30:11Z","timestamp":1778196611000},"page":"133884","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":2,"special_numbering":"C","title":["A comprehensive review of adversarial attacks on autonomous driving: From single-modality to multi-sensor fusion"],"prefix":"10.1016","volume":"694","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-0321-9779","authenticated-orcid":false,"given":"Jingguo","family":"Liang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guangyuan","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2670-9045","authenticated-orcid":false,"given":"Jicheng","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yan","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2501-712X","authenticated-orcid":false,"given":"Hui","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"4","key":"10.1016\/j.neucom.2026.133884_bib0005","first-page":"2151","article-title":"Delving into the devils of bird\u2019s-eye-view perception: a review, evaluation and recipe","volume":"46","author":"Hongyang","year":"2023","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"1","key":"10.1016\/j.neucom.2026.133884_bib0010","doi-asserted-by":"crossref","DOI":"10.1007\/s10462-024-11014-8","article-title":"Deep learning adversarial attacks and defenses in autonomous vehicles: a systematic literature review from a safety perspective","volume":"58","author":"Ibrahum","year":"2024","journal-title":"Artif. Intell. Rev."},{"issue":"4","key":"10.1016\/j.neucom.2026.133884_bib0015","doi-asserted-by":"crossref","first-page":"2259","DOI":"10.1109\/TMECH.2023.3241398","article-title":"Continuous-time fixed-lag smoothing for LiDAR-inertial-camera slam","volume":"28","author":"Jiajun","year":"2023","journal-title":"IEEE\/ASME Trans. Mechatron."},{"issue":"108796","key":"10.1016\/j.neucom.2026.133884_bib0020","article-title":"3D object detection for autonomous driving: a survey","volume":"130","author":"Qian","year":"2022","journal-title":"Pattern Recognit."},{"issue":"2","key":"10.1016\/j.neucom.2026.133884_bib0025","doi-asserted-by":"crossref","first-page":"722","DOI":"10.1109\/TITS.2020.3023541","article-title":"Deep learning for image and point cloud fusion in autonomous driving: a review","volume":"23","author":"Cui","year":"2021","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"2","key":"10.1016\/j.neucom.2026.133884_bib0030","doi-asserted-by":"crossref","first-page":"1046","DOI":"10.1109\/TIV.2022.3223131","article-title":"Milestones in autonomous driving and intelligent vehicles: survey of surveys","volume":"8","author":"Chen","year":"2022","journal-title":"IEEE Trans. Intell. Veh."},{"issue":"6","key":"10.1016\/j.neucom.2026.133884_bib0035","doi-asserted-by":"crossref","first-page":"5136","DOI":"10.1109\/TMECH.2022.3174273","article-title":"Driving conflict resolution of autonomous vehicles at unsignalized intersections: a differential game approach","volume":"27","author":"Hang","year":"2022","journal-title":"IEEE\/ASME Trans. Mechatron."},{"key":"10.1016\/j.neucom.2026.133884_bib0040","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1016\/j.eng.2023.10.011","article-title":"A survey on an emerging safety challenge for autonomous vehicles: safety of the intended functionality","volume":"33","author":"Wang","year":"2024","journal-title":"Engineering"},{"issue":"10","key":"10.1016\/j.neucom.2026.133884_bib0045","doi-asserted-by":"crossref","first-page":"15616","DOI":"10.1109\/TITS.2025.3591012","article-title":"Crash-based safety testing of autonomous vehicles: insights from generating safety-critical scenarios based on in-depth crash data","volume":"26","author":"Zhou","year":"2025","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib0050","doi-asserted-by":"crossref","first-page":"10164","DOI":"10.1109\/TPAMI.2024.3435937","article-title":"End-to-end autonomous driving: challenges and frontiers","volume":"46","author":"Chen","year":"2024","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"7","key":"10.1016\/j.neucom.2026.133884_bib0055","doi-asserted-by":"crossref","first-page":"4316","DOI":"10.1109\/TITS.2020.3032227","article-title":"Deep learning for safe autonomous driving: current challenges and future directions","volume":"22","author":"Muhammad","year":"2020","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"3","key":"10.1016\/j.neucom.2026.133884_bib0060","doi-asserted-by":"crossref","first-page":"1350","DOI":"10.1109\/TMECH.2021.3064816","article-title":"Covert attacks through adversarial learning: study of lane keeping attacks on the safety of autonomous vehicles","volume":"26","author":"Farivar","year":"2021","journal-title":"IEEE\/ASME Trans. Mechatron."},{"key":"10.1016\/j.neucom.2026.133884_bib0065","doi-asserted-by":"crossref","first-page":"1291","DOI":"10.1109\/TIP.2020.3042083","article-title":"Interpreting and improving adversarial robustness of deep neural networks with neuron sensitivity","volume":"30","author":"Zhang","year":"2020","journal-title":"IEEE Trans. Image Process."},{"issue":"4","key":"10.1016\/j.neucom.2026.133884_bib0070","doi-asserted-by":"crossref","first-page":"485","DOI":"10.1016\/j.iatssr.2021.04.003","article-title":"Effects of the autonomous vehicle crashes on public perception of the technology","volume":"45","author":"Penmetsa","year":"2021","journal-title":"IATSS Research"},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib0075","doi-asserted-by":"crossref","first-page":"7865","DOI":"10.1109\/TIV.2024.3403667","article-title":"Securing autonomous vehicles visual perception: adversarial patch attack and defense schemes with experimental validations","volume":"9","author":"Liang","year":"2024","journal-title":"IEEE Trans. Intell. Veh."},{"issue":"9","key":"10.1016\/j.neucom.2026.133884_bib0080","doi-asserted-by":"crossref","first-page":"4433","DOI":"10.1109\/TIV.2024.3484152","article-title":"Adversarial attacks on autonomous driving systems in the physical world: a survey","volume":"10","author":"Chi","year":"2025","journal-title":"IEEE Trans. Intell. Veh."},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib0085","doi-asserted-by":"crossref","first-page":"9797","DOI":"10.1109\/TPAMI.2024.3430860","article-title":"Physical adversarial attack meets computer vision: a decade survey","volume":"46","author":"Wei","year":"2024","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"11","key":"10.1016\/j.neucom.2026.133884_bib0090","doi-asserted-by":"crossref","first-page":"19046","DOI":"10.1109\/TITS.2024.3435715","article-title":"Adapting image classification adversarial detection methods for traffic sign classification in autonomous vehicles: a comparative study","volume":"25","author":"Sarwatt","year":"2024","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0095","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1016\/j.neucom.2022.10.046","article-title":"Adversarial examples based on object detection tasks: a survey","volume":"519","author":"Jian-Xun","year":"2023","journal-title":"Neurocomputing"},{"key":"10.1016\/j.neucom.2026.133884_bib0100","author":"Sharma"},{"issue":"102847","key":"10.1016\/j.neucom.2026.133884_bib0105","article-title":"A survey on adversarial attacks in computer vision: taxonomy, visualization and future directions","volume":"121","author":"Long","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.neucom.2026.133884_bib0110","author":"Wang"},{"issue":"1","key":"10.1016\/j.neucom.2026.133884_bib0115","doi-asserted-by":"crossref","first-page":"22","DOI":"10.1109\/TITS.2024.3488432","article-title":"A state-of-the-art review on attacks and defense mechanisms for LiDAR on autonomous vehicles","volume":"26","author":"Salguero-Luna","year":"2025","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib0120","doi-asserted-by":"crossref","first-page":"19176","DOI":"10.1109\/TITS.2024.3456293","article-title":"Toward robust 3D perception for autonomous vehicles: a review of adversarial attacks and countermeasures","volume":"25","author":"Mahima","year":"2024","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib0125","doi-asserted-by":"crossref","first-page":"7897","DOI":"10.1109\/TII.2021.3071405","article-title":"Deep learning-based autonomous driving systems: a survey of attacks and defenses","volume":"17","author":"Deng","year":"2021","journal-title":"IEEE Trans. Ind. Inform."},{"key":"10.1016\/j.neucom.2026.133884_bib0130","author":"Shen"},{"issue":"7","key":"10.1016\/j.neucom.2026.133884_bib0135","first-page":"6240","article-title":"A survey on cyber-security of connected and autonomous vehicles (cavs)","volume":"23","author":"Xiaoqiang Sun","year":"2021","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0140","doi-asserted-by":"crossref","first-page":"417","DOI":"10.1109\/OJVT.2023.3265363","article-title":"Cybersecurity of autonomous vehicles: a systematic literature review of adversarial attacks and defense models","volume":"4","author":"Girdhar","year":"2023","journal-title":"IEEE Open J. Veh. Technol."},{"issue":"102150","key":"10.1016\/j.neucom.2026.133884_bib0145","article-title":"Cybersecurity for autonomous vehicles: review of attacks and defense","volume":"103","author":"Kim","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.neucom.2026.133884_bib0150","series-title":"Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering","first-page":"385","article-title":"A comprehensive study of autonomous vehicle bugs","author":"Garcia","year":"2020"},{"issue":"4","key":"10.1016\/j.neucom.2026.133884_bib0155","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/MSP.2020.2985363","article-title":"Toward robust sensing for autonomous vehicles: an adversarial perspective","volume":"37","author":"Modas","year":"2020","journal-title":"IEEE Signal Process. Mag."},{"key":"10.1016\/j.neucom.2026.133884_bib0160","article-title":"A taxonomy of system-level attacks on deep learning models in autonomous vehicles","author":"Tehrani","year":"2025","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"10.1016\/j.neucom.2026.133884_bib0165","series-title":"Taxonomy and Definitions for Terms Related to Driving Automation Systems for on-Road Motor Vehicles","year":"2021"},{"issue":"8","key":"10.1016\/j.neucom.2026.133884_bib0170","doi-asserted-by":"crossref","first-page":"9840","DOI":"10.1109\/TITS.2024.3412432","article-title":"Carla-gear: a dataset generator for a systematic evaluation of adversarial robustness of deep learning vision models","volume":"25","author":"Nesti","year":"2024","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0175","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"4640","article-title":"Reap: a large-scale realistic adversarial patch benchmark","author":"Hingun","year":"2023"},{"issue":"114395","key":"10.1016\/j.neucom.2026.133884_bib0180","article-title":"Padetbench: towards benchmarking texture- and patch-based physical attacks against object detection","volume":"329","author":"Lian","year":"2025","journal-title":"Knowl.-based Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0185","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"12324","article-title":"Towards benchmarking and assessing visual naturalness of physical world adversarial attacks","author":"Simin","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0190","series-title":"International Conference on Machine Learning","first-page":"284","article-title":"Synthesizing robust adversarial examples","author":"Athalye","year":"2018"},{"key":"10.1016\/j.neucom.2026.133884_bib0195","series-title":"30th USENIX Security Symposium (USENIX Security 21)","first-page":"1865","article-title":"SLAP: improving physical adversarial examples with short-lived adversarial perturbations","author":"Lovisotto","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0200","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"1625","article-title":"Robust physical-world attacks on deep learning visual classification","author":"Eykholt","year":"2018"},{"key":"10.1016\/j.neucom.2026.133884_bib0205","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"4412","article-title":"Does physical adversarial example really matter to autonomous driving? Towards system-level effect of adversarial object evasion attack","author":"Wang","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0210","series-title":"International Conference on Machine Learning","first-page":"3896","article-title":"Adversarial camera stickers: a physical camera-based attack on deep learning systems","author":"Juncheng","year":"2019"},{"key":"10.1016\/j.neucom.2026.133884_bib0215","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"15232","article-title":"The translucent patch: a physical and universal attack on object detectors","author":"Zolfi","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0220","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"16062","article-title":"Adversarial laser beam: effective physical-world attack to dnns in a blink","author":"Duan","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0225","series-title":"Asian Conference on Machine Learning","first-page":"483","article-title":"Adversarial laser spot: robust and covert physical-world attack to dnns","author":"Chengyin","year":"2023"},{"issue":"8","key":"10.1016\/j.neucom.2026.133884_bib0230","first-page":"6337","article-title":"Adaptive square attack: fooling autonomous cars with adversarial traffic signs","volume":"8","author":"Yujie","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.neucom.2026.133884_bib0235","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"1000","article-title":"Adversarial camouflage: hiding physical-world attacks with natural styles","author":"Duan","year":"2020"},{"issue":"3","key":"10.1016\/j.neucom.2026.133884_bib0240","first-page":"2711","article-title":"Adversarial sticker: a stealthy attack method in the physical world","volume":"45","author":"Wei","year":"2022","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.neucom.2026.133884_bib0245","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"1028","article-title":"Perceptual-sensitive GAN for generating adversarial patches","volume":"vol. 33","author":"Liu","year":"2019"},{"issue":"103345","key":"10.1016\/j.neucom.2026.133884_bib0250","article-title":"Light can be dangerous: stealthy and effective physical-world adversarial attack by spot light","volume":"132","author":"Yufeng","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.neucom.2026.133884_bib0255","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"15345","article-title":"Shadows can be dangerous: stealthy and effective physical-world adversarial attack by natural phenomenon","author":"Zhong","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0260","author":"Sato"},{"key":"10.1016\/j.neucom.2026.133884_bib0265","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"14254","article-title":"Physgan: generating physical-world-resilient adversarial examples for autonomous driving","author":"Kong","year":"2020"},{"key":"10.1016\/j.neucom.2026.133884_bib0270","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"7848","article-title":"Naturalistic physical adversarial patch for object detectors","author":"Yu-Chih-Tuan","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0275","author":"Jiajun"},{"key":"10.1016\/j.neucom.2026.133884_bib0280","series-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1989","article-title":"Seeing isn\u2019t believing: towards more robust adversarial attack against real world object detectors","author":"Zhao","year":"2019"},{"key":"10.1016\/j.neucom.2026.133884_bib0285","author":"Hoory"},{"key":"10.1016\/j.neucom.2026.133884_bib0290","series-title":"2020 Second IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA)","first-page":"263","article-title":"Adversarial objectness gradient attacks in real-time object detection systems","author":"Chow","year":"2020"},{"key":"10.1016\/j.neucom.2026.133884_bib0295","author":"Cao"},{"key":"10.1016\/j.neucom.2026.133884_bib0300","author":"Yahn"},{"key":"10.1016\/j.neucom.2026.133884_bib0305","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"15234","article-title":"Give me your attention: dot-product attention considered harmful for adversarial patch robustness","author":"Lovisotto","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0310","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"3616","article-title":"Fooling thermal infrared pedestrian detectors in real world using small bulbs","volume":"vol. 35","author":"Zhu","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0315","series-title":"2021 IEEE Symposium on Security and Privacy (SP)","first-page":"160","article-title":"Poltergeist: acoustic adversarial machine learning against cameras and computer vision","author":"Xiaoyu","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0320","series-title":"32nd USENIX Security Symposium (USENIX Security 23)","first-page":"661","article-title":"TPatch: a triggered physical adversarial patch","author":"Zhu","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0325","series-title":"Network and Distributed System Security Symposium (NDSS) 2022","article-title":"Fooling the eyes of autonomous vehicles: robust physical adversarial examples against traffic sign recognition systems","author":"Jia","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0330","doi-asserted-by":"crossref","first-page":"6795","DOI":"10.1109\/TIFS.2024.3422920","article-title":"Stealthy and effective physical adversarial attacks in autonomous driving","volume":"19","author":"Zhou","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"17","key":"10.1016\/j.neucom.2026.133884_bib0335","doi-asserted-by":"crossref","first-page":"28931","DOI":"10.1109\/JIOT.2024.3405006","article-title":"Opticloak: blinding vision-based autonomous driving systems through adversarial optical projection","volume":"11","author":"Wen","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.neucom.2026.133884_bib0340","doi-asserted-by":"crossref","first-page":"8047","DOI":"10.52202\/079017-0259","article-title":"Revisiting adversarial patches for designing camera-agnostic attacks against person detection","volume":"37","author":"Wei","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0345","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"12334","article-title":"Physically adversarial infrared patches with learnable shapes and locations","author":"Wei","year":"2023"},{"issue":"6","key":"10.1016\/j.neucom.2026.133884_bib0350","doi-asserted-by":"crossref","first-page":"1928","DOI":"10.1007\/s11263-023-01963-y","article-title":"Infrared adversarial patches with learnable shapes and locations in the physical world","volume":"132","author":"Wei","year":"2024","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.neucom.2026.133884_bib0355","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"4445","article-title":"Unified adversarial patch for cross-modal attacks in the physical world","author":"Wei","year":"2023"},{"issue":"4","key":"10.1016\/j.neucom.2026.133884_bib0360","doi-asserted-by":"crossref","first-page":"2348","DOI":"10.1109\/TPAMI.2023.3330769","article-title":"Unified adversarial patch for visible-infrared cross-modal attacks in the physical world","volume":"46","author":"Wei","year":"2023","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.neucom.2026.133884_bib0365","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"15233","article-title":"Hotcold block: fooling thermal infrared detectors with a novel wearable design","volume":"vol. 37","author":"Wei","year":"2023"},{"issue":"106310","key":"10.1016\/j.neucom.2026.133884_bib0370","article-title":"Adversarial infrared blocks: a multi-view black-box attack to thermal infrared detectors in physical world","volume":"175","author":"Chengyin","year":"2024","journal-title":"Neural Netw."},{"issue":"106459","key":"10.1016\/j.neucom.2026.133884_bib0375","article-title":"Adversarial infrared curves: an attack on infrared pedestrian detectors in the physical world","volume":"178","author":"Chengyin","year":"2024","journal-title":"Neural Netw."},{"key":"10.1016\/j.neucom.2026.133884_bib0380","series-title":"Proceedings of the IEEE International Conference on Computer Vision","first-page":"2755","article-title":"Universal adversarial perturbations against semantic image segmentation","author":"Metzen","year":"2017"},{"key":"10.1016\/j.neucom.2026.133884_bib0385","series-title":"Proceedings of the European Conference on Computer Vision (ECCV)","first-page":"217","article-title":"Characterizing adversarial examples based on spatial consistency information for semantic segmentation","author":"Xiao","year":"2018"},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib0390","doi-asserted-by":"crossref","first-page":"3040","DOI":"10.1109\/TPAMI.2019.2919707","article-title":"On the robustness of semantic segmentation models to adversarial attacks","volume":"42","author":"Arnab","year":"2020","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.neucom.2026.133884_bib0395","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"888","article-title":"On the robustness of semantic segmentation models to adversarial attacks","author":"Arnab","year":"2018"},{"issue":"2","key":"10.1016\/j.neucom.2026.133884_bib0400","doi-asserted-by":"crossref","first-page":"1421","DOI":"10.1109\/LRA.2020.2967289","article-title":"Deceiving image-to-image translation networks for autonomous driving with adversarial perturbations","volume":"5","author":"Wang","year":"2020","journal-title":"IEEE Robot. Autom. Lett."},{"issue":"6","key":"10.1016\/j.neucom.2026.133884_bib0405","first-page":"4117","article-title":"Adversarial attack against urban scene segmentation for autonomous vehicles","volume":"17","author":"Xing","year":"2020","journal-title":"IEEE Trans. Ind. Inform."},{"key":"10.1016\/j.neucom.2026.133884_bib0410","series-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision","first-page":"4080","article-title":"Semantically stealthy adversarial attacks against segmentation models","author":"Chen","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0415","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"20524","article-title":"Proximal splitting adversarial attack for semantic segmentation","author":"Rony","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0420","series-title":"European Conference on Computer Vision","first-page":"180","article-title":"Towards reliable evaluation and fast training of robust semantic segmentation models","author":"Croce","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0425","series-title":"European Conference on Computer Vision","first-page":"308","article-title":"Segpgd: an effective and efficient adversarial attack for evaluating and boosting segmentation robustness","author":"Jindong","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0430","series-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision","first-page":"2280","article-title":"Evaluating the robustness of semantic segmentation for autonomous driving against real-world adversarial patch attacks","author":"Nesti","year":"2022"},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib0435","doi-asserted-by":"crossref","first-page":"18328","DOI":"10.1109\/TNNLS.2023.3314512","article-title":"On the real-world adversarial robustness of real-time semantic segmentation models for autonomous driving","volume":"35","author":"Rossolini","year":"2024","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"issue":"102682","key":"10.1016\/j.neucom.2026.133884_bib0440","article-title":"Adversarial attacks on YOLACT instance segmentation","volume":"116","author":"Zhang","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.neucom.2026.133884_bib0445","series-title":"2022 IEEE Intelligent Vehicles Symposium (IV)","first-page":"867","article-title":"On adversarial robustness of semantic segmentation models for automated driving","author":"Yin","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0450","series-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision","first-page":"3906","article-title":"Uncertainty-weighted loss functions for improved adversarial attacks on semantic segmentation","author":"Maag","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0455","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"194","article-title":"Practical region-level attack against segment anything models","author":"Shen","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0460","doi-asserted-by":"crossref","first-page":"1901","DOI":"10.1109\/TMM.2024.3521769","article-title":"Black-box targeted adversarial attack on segment anything (SAM)","volume":"27","author":"Zheng","year":"2025","journal-title":"IEEE Trans. Multimedia"},{"key":"10.1016\/j.neucom.2026.133884_bib0465","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"5775","article-title":"Robust SAM: on the adversarial robustness of vision foundation models","volume":"vol. 39","author":"Long","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0470","series-title":"Proceedings of the 32nd ACM International Conference on Multimedia","first-page":"2136","article-title":"Cascaded adversarial attack: simultaneously fooling rain removal and semantic segmentation networks","author":"Wang","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0475","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1016\/j.patrec.2024.01.010","article-title":"Time-aware and task-transferable adversarial attack for perception of autonomous vehicles","volume":"178","author":"Yantao","year":"2024","journal-title":"Pattern Recognit. Lett."},{"issue":"6","key":"10.1016\/j.neucom.2026.133884_bib0480","first-page":"5049","article-title":"Adversarial attacks on video object segmentation with hard region discovery","volume":"34","author":"Ping","year":"2023","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"10.1016\/j.neucom.2026.133884_bib0485","series-title":"IEEE Robotics and Automation Letters","article-title":"Semantic hierarchy-guided adversarial attack for autonomous driving","author":"Kim","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0490","series-title":"2025 IEEE Security and Privacy Workshops (SPW)","first-page":"322","article-title":"Do adversarial patches generalize? Attack transferability study across real-time segmentation models in autonomous vehicles","author":"Shekhar","year":"2025"},{"issue":"1","key":"10.1016\/j.neucom.2026.133884_bib0495","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1109\/MSP.2020.2983666","article-title":"The vulnerability of semantic segmentation networks to adversarial attacks in autonomous driving: enhancing extensive environment sensing","volume":"38","author":"Bar","year":"2020","journal-title":"IEEE Signal Process. Mag."},{"key":"10.1016\/j.neucom.2026.133884_bib0500","series-title":"30th USENIX Security Symposium (USENIX Security 21)","first-page":"3237","article-title":"Too good to be safe: tricking lane detection in autonomous driving with crafted perturbations","author":"Jing","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0505","series-title":"30th USENIX Security Symposium (USENIX Security 21)","first-page":"3309","article-title":"Dirty road can attack: security of deep learning based automated lane centering under physical-world attack","author":"Sato","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0510","series-title":"Proceedings of the 30th ACM International Conference on Multimedia","first-page":"2957","article-title":"Physical backdoor attacks to lane detection systems in autonomous driving","author":"Han","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0515","author":"MohajerAnsari"},{"key":"10.1016\/j.neucom.2026.133884_bib0520","series-title":"2023 IEEE Intelligent Vehicles Symposium (IV)","first-page":"1","article-title":"Adversarial driving: attacking end-to-end autonomous driving","author":"Han","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0525","series-title":"International Conference on Learning Representations (ICLR\u201920)","article-title":"Fooling detection alone is not enough: adversarial attack against multiple object tracking","author":"Jia","year":"2020"},{"issue":"101766","key":"10.1016\/j.neucom.2026.133884_bib0530","article-title":"Attacking vision-based perception in end-to-end autonomous driving models","volume":"110","author":"Boloor","year":"2020","journal-title":"J. Syst. Archit."},{"key":"10.1016\/j.neucom.2026.133884_bib0535","author":"Duan"},{"key":"10.1016\/j.neucom.2026.133884_bib0540","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24512","article-title":"Towards transferable targeted 3D adversarial attack in the physical world","author":"Huang","year":"2024"},{"issue":"11","key":"10.1016\/j.neucom.2026.133884_bib0545","doi-asserted-by":"crossref","first-page":"5084","DOI":"10.1007\/s11263-024-02098-4","article-title":"Generate transferable adversarial physical camouflages via triplet attention suppression","volume":"132","author":"Wang","year":"2024","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.neucom.2026.133884_bib0550","article-title":"On the adversarial robustness of camera-based 3D object detection","author":"Xie","year":"2024","journal-title":"Transactions on Machine Learning Research (TMLR)"},{"key":"10.1016\/j.neucom.2026.133884_bib0555","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"21600","article-title":"Understanding the robustness of 3D object detection with bird\u2019s-eye-view representations in autonomous driving","author":"Zhu","year":"2023"},{"issue":"109435","key":"10.1016\/j.neucom.2026.133884_bib0560","article-title":"Boosting transferability of physical attack against detectors by redistributing separable attention","volume":"138","author":"Zhang","year":"2023","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.neucom.2026.133884_bib0565","series-title":"2024 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS)","first-page":"10813","article-title":"Adv3d: generating 3D adversarial examples for 3D object detection in driving scenarios with nerf","author":"Leheng","year":"2024"},{"issue":"5","key":"10.1016\/j.neucom.2026.133884_bib0570","doi-asserted-by":"crossref","first-page":"4949","DOI":"10.1109\/TCSVT.2025.3525725","article-title":"A unified framework for adversarial patch attacks against visual 3D object detection in autonomous driving","volume":"35","author":"Wang","year":"2025","journal-title":"IEEE Trans. Circuits Syst. Video Technol."},{"key":"10.1016\/j.neucom.2026.133884_bib0575","doi-asserted-by":"crossref","first-page":"538","DOI":"10.1109\/TIP.2025.3526056","article-title":"Physically realizable adversarial creating attack against vision-based BEV space 3D object detection","volume":"34","author":"Wang","year":"2025","journal-title":"IEEE Trans. Image Process."},{"key":"10.1016\/j.neucom.2026.133884_bib0580","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV)","article-title":"3D Gaussian splatting driven multi-view robust physical adversarial camouflage generation","author":"Lou","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0585","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24284","article-title":"Infrared adversarial car stickers","author":"Zhu","year":"2024"},{"issue":"5","key":"10.1016\/j.neucom.2026.133884_bib0590","doi-asserted-by":"crossref","first-page":"3443","DOI":"10.1109\/JIOT.2021.3099164","article-title":"Evaluating adversarial attacks on driving safety in vision-based autonomous vehicles","volume":"9","author":"Zhang","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.neucom.2026.133884_bib0595","series-title":"ICLR","article-title":"Camou: learning a vehicle camouflage for physical adversarial attack on object detections in the wild","author":"Yang Zhang","year":"2019"},{"key":"10.1016\/j.neucom.2026.133884_bib0600","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"720","article-title":"Universal physical camouflage attacks on object detectors","author":"Huang","year":"2020"},{"key":"10.1016\/j.neucom.2026.133884_bib0605","author":"Tong"},{"key":"10.1016\/j.neucom.2026.133884_bib0610","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"8565","article-title":"Dual attention suppression attack: generate adversarial camouflage in physical world","author":"Wang","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0615","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"15305","article-title":"DTA: physical camouflage attacks using differentiable transformation network","author":"Suryanto","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0620","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"2414","article-title":"Fca: learning a 3D full-coverage vehicle camouflage for multi-view physical adversarial attack","volume":"vol. 36","author":"Wang","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0625","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"4305","article-title":"Active: towards highly transferable 3D physical camouflage for universal and robust vehicle evasion","author":"Suryanto","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0630","series-title":"Forty-First International Conference on Machine Learning","article-title":"RAUCA: a novel physical adversarial attack on vehicle detectors via robust and accurate camouflage generation","author":"Zhou","year":"2024"},{"issue":"6","key":"10.1016\/j.neucom.2026.133884_bib0635","doi-asserted-by":"crossref","first-page":"7272","DOI":"10.1109\/TDSC.2025.3596311","article-title":"Toward robust and accurate adversarial camouflage generation against vehicle detectors","volume":"22","author":"Zhou","year":"2025","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10.1016\/j.neucom.2026.133884_bib0640","series-title":"Advances in Neural Information Processing Systems","first-page":"133092","article-title":"Cnca: toward customizable and natural generation of adversarial camouflage for vehicle detectors","volume":"vol. 37","author":"Lyu","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0645","author":"Zhang"},{"key":"10.1016\/j.neucom.2026.133884_bib0650","series-title":"Proceedings of the Forty-First International Conference on Machine Learning (ICML)","article-title":"Badpart: unified black-box adversarial patch attacks against pixel-wise regression tasks","author":"Cheng","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0655","first-page":"8486","article-title":"Targeted adversarial perturbations for monocular depth prediction","volume":"33","author":"Wong","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0660","series-title":"European Conference on Computer Vision","first-page":"514","article-title":"Physical attack on monocular depth estimation with optimal adversarial patches","author":"Cheng","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0665","doi-asserted-by":"crossref","first-page":"67689","DOI":"10.52202\/079017-2162","article-title":"Beware of road markings: a new adversarial patch attack to monocular depth estimation","volume":"37","author":"Liu","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"22","key":"10.1016\/j.neucom.2026.133884_bib0670","doi-asserted-by":"crossref","first-page":"38440","DOI":"10.1109\/JSEN.2024.3472032","article-title":"Physical adversarial attack on monocular depth estimation via shape-varying patches","volume":"24","author":"Zhao","year":"2024","journal-title":"IEEE Sens. J."},{"key":"10.1016\/j.neucom.2026.133884_bib0675","series-title":"2024 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS)","first-page":"2786","article-title":"Ssap: a shape-sensitive adversarial patch for comprehensive disruption of monocular depth estimation in autonomous navigation applications","author":"Guesmi","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0680","series-title":"Proceedings of the 32nd ACM International Conference on Multimedia","first-page":"2739","article-title":"Depthcloak: projecting optical camouflage patches for erroneous monocular depth estimation of vehicles","author":"Wen","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0685","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24452","article-title":"Physical 3D adversarial attacks against monocular depth estimation in autonomous driving","author":"Zheng","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0690","series-title":"33rd USENIX Security Symposium (USENIX Security 24)","first-page":"7321","article-title":"\u03c0-Jack:Physical-World adversarial attack on monocular depth estimation with perspective hijacking","author":"Zheng","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0695","series-title":"2022 IEEE\/RSJ International Conference on Intelligent Robotics and Systems (IROS)","article-title":"Adversarial attacks on monocular pose estimation","author":"Chawla","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0700","series-title":"International Conference on Learning Representations","article-title":"Adversarial training of self-supervised monocular depth estimation against physical-world attacks","author":"Cheng","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0705","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1016\/j.neucom.2021.09.027","article-title":"Adversarial point cloud perturbations against 3D object detection in autonomous driving systems","volume":"466","author":"Wang","year":"2021","journal-title":"Neurocomputing"},{"key":"10.1016\/j.neucom.2026.133884_bib0710","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"13716","article-title":"Physically realizable adversarial examples for LiDAR object detection","author":"James","year":"2020"},{"key":"10.1016\/j.neucom.2026.133884_bib0715","series-title":"2023 IEEE Symposium on Security and Privacy (SP)","first-page":"1822","article-title":"PLA-LiDAR: physical laser attacks against LiDAR-based 3D object detection in autonomous vehicle","author":"Jin","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0720","series-title":"Proceedings of the 19th ACM Conference on Embedded Networked Sensor Systems","first-page":"329","article-title":"Adversarial attacks against LiDAR semantic segmentation in autonomous driving","author":"Zhu","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0725","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"9136","article-title":"Generating 3D adversarial point clouds","author":"Xiang","year":"2019"},{"key":"10.1016\/j.neucom.2026.133884_bib0730","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"11767","article-title":"Robustness of 3D deep learning in an adversarial setting","author":"Wicker","year":"2019"},{"key":"10.1016\/j.neucom.2026.133884_bib0735","series-title":"European Conference on Computer Vision","first-page":"88","article-title":"Adversarial shape perturbations on 3D point clouds","author":"Liu","year":"2020"},{"key":"10.1016\/j.neucom.2026.133884_bib0740","series-title":"European Conference on Computer Vision","first-page":"241","article-title":"Advpc: transferable adversarial perturbations on 3D point clouds","author":"Hamdi","year":"2020"},{"key":"10.1016\/j.neucom.2026.133884_bib0745","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TGRS.2023.3292372","article-title":"Evaa\u2014exchange vanishing adversarial attack on LiDAR point clouds in autonomous vehicles","volume":"61","author":"Vishnu","year":"2023","journal-title":"IEEE Trans. Geosci. Remote Sens."},{"key":"10.1016\/j.neucom.2026.133884_bib0750","series-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision","first-page":"4581","article-title":"Explainability-aware one point attack for point cloud neural networks","author":"Tan","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0755","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24326","article-title":"Hide in thicket: generating imperceptible and rational adversarial perturbations on 3D point clouds","author":"Lou","year":"2024"},{"issue":"10","key":"10.1016\/j.neucom.2026.133884_bib0760","doi-asserted-by":"crossref","first-page":"14019","DOI":"10.1109\/TITS.2024.3406153","article-title":"SR-adv: salient region adversarial attacks on 3D point clouds for autonomous driving","volume":"25","author":"Zheng","year":"2024","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0765","series-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","first-page":"2267","article-title":"Adversarial sensor attack on LiDAR-based perception in autonomous driving","author":"Cao","year":"2019"},{"key":"10.1016\/j.neucom.2026.133884_bib0770","series-title":"29th USENIX Security Symposium (USENIX Security 20)","first-page":"877","article-title":"Towards robust LiDAR-based perception in autonomous driving: general black-box adversarial sensor attack and countermeasures","author":"Sun","year":"2020"},{"key":"10.1016\/j.neucom.2026.133884_bib0775","author":"Cao"},{"key":"10.1016\/j.neucom.2026.133884_bib0780","series-title":"Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security","first-page":"349","article-title":"Robust roadside physical adversarial attack against deep learning in LiDAR perception modules","author":"Yang","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0785","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"7898","article-title":"Fooling LiDAR perception via adversarial trajectory perturbation","author":"Yiming","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0790","series-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1945","article-title":"Can we use arbitrary objects to attack LiDAR perception in autonomous driving?","author":"Zhu","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0795","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"5146","article-title":"Slowlidar: increasing the latency of LiDAR-based detection using adversarial examples","author":"Liu","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0800","series-title":"32nd USENIX Security Symposium (USENIX Security 23)","first-page":"2993","article-title":"You can\u2019t see me: physical removal attacks on LiDAR-based autonomous vehicles driving frameworks","author":"Yulong Cao","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0805","author":"Sato"},{"key":"10.1016\/j.neucom.2026.133884_bib0810","series-title":"Proc. Workshop Automot. Auto. Vehicle Secur.(AutoSec)","first-page":"1","article-title":"Automated tracking system for LiDAR spoofing attacks on moving targets","author":"Cao","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0815","series-title":"Proc. 4th Int. Workshop Automot. Auto. Vehicle Secur","first-page":"1","article-title":"Generating 3D adversarial point clouds under the principle of lidars","author":"Yang","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0820","series-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS)","article-title":"On the realism of LiDAR spoofing attacks against autonomous driving vehicle at high speed and long distance","author":"Sato","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0825","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"9425","article-title":"Open-set semantic segmentation for point clouds via adversarial prototype framework","author":"Jianan","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0830","series-title":"2023 53rd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN)","first-page":"531","article-title":"On adversarial robustness of point cloud semantic segmentation","author":"Jiacen","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0835","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"2791","article-title":"Explaining 3D point cloud semantic segmentation models through adversarial attacks","author":"Cipri\u00e1n-S\u00e1nchez","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0840","author":"Haosheng"},{"key":"10.1016\/j.neucom.2026.133884_bib0845","series-title":"Proceedings of the 5th Workshop on Attacks and Solutions in Hardware Security","first-page":"91","article-title":"Spoofing attacks against vehicular fmcw radar","author":"Komissarov","year":"2021"},{"issue":"3","key":"10.1016\/j.neucom.2026.133884_bib0850","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1007\/s13389-020-00252-5","article-title":"Low-cost distance-spoofing attack on fmcw radar and its feasibility study on countermeasure","volume":"11","author":"Nashimoto","year":"2021","journal-title":"J. Cryptogr. Eng."},{"key":"10.1016\/j.neucom.2026.133884_bib0855","doi-asserted-by":"crossref","first-page":"3199","DOI":"10.1109\/TIFS.2021.3076287","article-title":"Who is in control? Practical physical layer attack and defense for mmWave-based sensing in autonomous vehicles","volume":"16","author":"Sun","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.neucom.2026.133884_bib0860","author":"Hunt"},{"key":"10.1016\/j.neucom.2026.133884_bib0865","series-title":"Proceedings of the 23rd Annual International Conference on Mobile Systems, Applications and Services","first-page":"417","article-title":"Toward spoofing-resilient and communication-integrated mmWave radar sensing","author":"Qian","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0870","author":"Guesmi"},{"key":"10.1016\/j.neucom.2026.133884_bib0875","series-title":"2025 IEEE Intelligent Vehicles Symposium (IV)","first-page":"1","article-title":"Deep sensor fusion for detection and localization of automotive radar spoofing attacks","author":"Alkanat","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0880","series-title":"2023 IEEE Symposium on Security and Privacy (SP)","first-page":"1807","article-title":"Aanjhan ranganathan, and dinesh Bharadia. Mmspoof: resilient spoofing of automotive millimeter-wave radars using reflect array","author":"Vennam","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0885","series-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1317","article-title":"Tilemask: a passive-reflection-based attack against mmWave radar object detection in autonomous driving","author":"Zhu","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib0890","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1016\/j.ins.2020.03.066","article-title":"Adversarial attacks on deep-learning-based radar range profile target recognition","volume":"531","author":"Huang","year":"2020","journal-title":"Inf. Sci."},{"key":"10.1016\/j.neucom.2026.133884_bib0895","series-title":"2025 IEEE Radar Conference (RadarConf25)","first-page":"1513","article-title":"Adversarial attack on automotive radar point cloud classifiers","author":"Hadad","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0900","series-title":"27th USENIX Security Symposium (USENIX Security 18)","first-page":"1527","article-title":"All your GPS are belong to us: towards stealthy manipulation of road navigation systems","author":"Zeng","year":"2018"},{"key":"10.1016\/j.neucom.2026.133884_bib0905","series-title":"2019 IEEE Symposium on Security and Privacy (SP)","first-page":"587","article-title":"Security of GPS\/INS based on-road location tracking systems","author":"Narain","year":"2019"},{"key":"10.1016\/j.neucom.2026.133884_bib0910","series-title":"2023 IEEE 97th Vehicular Technology Conference (VTC2023-Spring)","first-page":"1","article-title":"A machine learning approach for detecting GPS location spoofing attacks in autonomous vehicles","author":"Stylianos Filippou","year":"2023"},{"issue":"1","key":"10.1016\/j.neucom.2026.133884_bib0915","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1109\/TVT.2024.3454416","article-title":"Anomaly detection and secure position estimation against GPS spoofing attack: a security-critical study of localization in autonomous driving","volume":"74","author":"Chen","year":"2025","journal-title":"IEEE Trans. Veh. Technol."},{"key":"10.1016\/j.neucom.2026.133884_bib0920","series-title":"2025 IEEE 4th International Conference on AI in Cybersecurity (ICAIC)","first-page":"1","article-title":"Detection of multiple small biased GPS spoofing attacks on autonomous vehicles","author":"Mohammadi","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0925","doi-asserted-by":"crossref","first-page":"105513","DOI":"10.1109\/ACCESS.2023.3319514","article-title":"Securing autonomous vehicles against GPS spoofing attacks: a deep learning approach","volume":"11","author":"Shabbir","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.neucom.2026.133884_bib0930","series-title":"2021 IEEE 94th Vehicular Technology Conference (VTC2021-Fall)","first-page":"1","article-title":"GPS location spoofing attack detection for enhancing the security of autonomous vehicles","author":"Kamal","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0935","series-title":"2024 9th International Conference on Computer Science and Engineering (UBMK)","first-page":"500","article-title":"GPS spoofing detection on autonomous vehicles with XGBoost","author":"\u0130\u015fleyen","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0940","series-title":"29th USENIX Security Symposium (USENIX Security 20)","first-page":"931","article-title":"Drift with devil: security of multi-sensor fusion based localization in high-level autonomous driving under GPS spoofing","author":"Shen","year":"2020"},{"issue":"9","key":"10.1016\/j.neucom.2026.133884_bib0945","doi-asserted-by":"crossref","first-page":"9462","DOI":"10.1109\/TITS.2023.3269029","article-title":"Anomaly detection against GPS spoofing attacks on connected and autonomous vehicles using learning from demonstration","volume":"24","author":"Yang","year":"2023","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"3","key":"10.1016\/j.neucom.2026.133884_bib0950","doi-asserted-by":"crossref","first-page":"2822","DOI":"10.1109\/TVT.2021.3061065","article-title":"Multi-source adversarial sample attack on autonomous vehicles","volume":"70","author":"Xiong","year":"2021","journal-title":"IEEE Trans. Veh. Technol."},{"key":"10.1016\/j.neucom.2026.133884_bib0955","series-title":"2021 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS)","first-page":"2189","article-title":"Adversarial attacks on camera-lidar models for 3D car detection","author":"Abdelfattah","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib0960","author":"James"},{"key":"10.1016\/j.neucom.2026.133884_bib0965","series-title":"2021 IEEE Symposium on Security and Privacy (SP)","first-page":"176","article-title":"Invisible for both camera and LiDAR: security of multi-sensor fusion based perception in autonomous driving under physical-world attacks","author":"Cao","year":"2021"},{"issue":"3","key":"10.1016\/j.neucom.2026.133884_bib0970","doi-asserted-by":"crossref","first-page":"1441","DOI":"10.1002\/int.22349","article-title":"Camdar-adv: generating adversarial patches on 3D object","volume":"36","author":"Chen","year":"2021","journal-title":"Int. J. Intell. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib0975","series-title":"31st USENIX Security Symposium (USENIX Security 22)","first-page":"1903","article-title":"Security analysis of Camera-LiDAR fusion against black-box attacks on autonomous vehicles","author":"Hallyburton","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib0980","series-title":"Proceedings of the 30th Annual International Conference on Mobile Computing and Networking","first-page":"436","article-title":"Malicious attacks against multi-sensor fusion in autonomous driving","author":"Zhu","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0985","series-title":"The Twelfth International Conference on Learning Representations","article-title":"Fusion is not enough: single modal attack on fusion models for 3D object detection","author":"Cheng","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib0990","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"3561","article-title":"Probing vulnerabilities of vision-lidar based autonomous driving systems","author":"Yang","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib0995","series-title":"International Conference on Learning Representations (ICLR)","article-title":"Part-based models improve adversarial robustness","author":"Sitawarin","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib1000","series-title":"Proceedings of the 31st ACM International Conference on Multimedia","first-page":"3706","article-title":"Paif: perception-aware infrared-visible image fusion for attack-tolerant semantic segmentation","author":"Liu","year":"2023"},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib1005","doi-asserted-by":"crossref","first-page":"9084","DOI":"10.1109\/TPAMI.2024.3412632","article-title":"Self-supervised adversarial training of monocular depth estimation against physical-world attacks","volume":"46","author":"Cheng","year":"2024","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib1010","doi-asserted-by":"crossref","first-page":"5193","DOI":"10.1109\/TCAD.2022.3166112","article-title":"Counteracting adversarial attacks in autonomous driving","volume":"41","author":"Sun","year":"2022","journal-title":"IEEE Trans. Comput.-Aided Des. Integr. Circuits Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib1015","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"17295","article-title":"3D-VField: adversarial augmentation of point clouds for domain generalization in 3D object detection","author":"Lehner","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib1020","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"6186","article-title":"Pointguard: provably robust 3D point cloud classification","author":"Liu","year":"2021"},{"key":"10.1016\/j.neucom.2026.133884_bib1025","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"17528","article-title":"Commit: certifying robustness of multi-sensor fusion systems against semantic attacks","volume":"vol. 39","author":"Huang","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib1030","series-title":"2025 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS)","first-page":"3076","article-title":"Rocars: robust camera-radar BEV segmentation for sensor failure scenarios","author":"Park","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib1035","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"6720","article-title":"Resilient sensor fusion under adverse sensor failures via multi-modal expert fusion","author":"Park","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib1040","doi-asserted-by":"crossref","first-page":"6976","DOI":"10.1109\/TIP.2022.3217375","article-title":"Defending person detection against adversarial patch attack by using universal defensive frame","volume":"31","author":"Youngjoon","year":"2022","journal-title":"IEEE Trans. Image Process."},{"issue":"7","key":"10.1016\/j.neucom.2026.133884_bib1045","doi-asserted-by":"crossref","first-page":"9543","DOI":"10.1109\/TITS.2022.3146038","article-title":"Csg: classifier-aware defense strategy based on compressive sensing and generative networks for visual recognition in autonomous vehicle systems","volume":"23","author":"Wang","year":"2022","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"issue":"3","key":"10.1016\/j.neucom.2026.133884_bib1050","doi-asserted-by":"crossref","first-page":"645","DOI":"10.1109\/TC.2021.3076826","article-title":"An efficient preprocessing-based approach to mitigate advanced adversarial attacks","volume":"73","author":"Qiu","year":"2024","journal-title":"IEEE Trans. Comput."},{"key":"10.1016\/j.neucom.2026.133884_bib1055","series-title":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","first-page":"3825","article-title":"Towards real-time defense against object-based LiDAR attacks in autonomous driving","author":"Zhang","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib1060","series-title":"International Conference on Machine Learning (ICML)","article-title":"Diffusion models for adversarial purification","author":"Nie","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib1065","series-title":"Proceedings of the 31st ACM International Conference on Multimedia","first-page":"8849","article-title":"Ada3diff: defending against 3D adversarial point clouds via adaptive diffusion","author":"Zhang","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib1070","series-title":"2024 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","first-page":"24665","article-title":"Mimicdiffusion: purifying adversarial perturbation via mimicking clean diffusion model","author":"Song","year":"2024"},{"issue":"5","key":"10.1016\/j.neucom.2026.133884_bib1075","first-page":"2209","article-title":"\u201cseeing is not always believing\u201d: detecting perception error attacks against autonomous vehicles","volume":"18","author":"Liu","year":"2021","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"2","key":"10.1016\/j.neucom.2026.133884_bib1080","doi-asserted-by":"crossref","first-page":"1140","DOI":"10.1109\/JIOT.2020.3011690","article-title":"Detecting and identifying optical signal attacks on autonomous driving systems","volume":"8","author":"Zhang","year":"2021","journal-title":"IEEE Internet Things J."},{"issue":"12","key":"10.1016\/j.neucom.2026.133884_bib1085","doi-asserted-by":"crossref","first-page":"23559","DOI":"10.1109\/TITS.2022.3197817","article-title":"A sensor fusion-based GNSS spoofing attack detection framework for autonomous vehicles","volume":"23","author":"Dasgupta","year":"2022","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.neucom.2026.133884_bib1090","series-title":"2023 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS)","first-page":"9707","article-title":"Lateral-direction localization attack in high-level autonomous driving: domain-specific defense opportunity via lane detection","author":"Shen","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib1095","series-title":"Proceedings of the 61st ACM\/IEEE Design Automation Conference","first-page":"1","article-title":"Laser shield: a physical defense with polarizer against laser attacks on autonomous driving systems","author":"Zhang","year":"2024"},{"key":"10.1016\/j.neucom.2026.133884_bib1100","series-title":"2022 IEEE Security and Privacy Workshops (SPW)","first-page":"229","article-title":"Using 3D shadows to detect object hiding attacks on autonomous vehicle perception","author":"Hau","year":"2022"},{"key":"10.1016\/j.neucom.2026.133884_bib1105","doi-asserted-by":"crossref","first-page":"3199","DOI":"10.1109\/TIFS.2021.3076287","article-title":"Who is in control? Practical physical layer attack and defense for mmWave-based sensing in autonomous vehicles","volume":"16","author":"Sun","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.neucom.2026.133884_bib1110","doi-asserted-by":"crossref","first-page":"2810","DOI":"10.1109\/TIFS.2023.3268880","article-title":"Radar2: passive spy radar detection and localization using cots mmWave radar","volume":"18","author":"Qiu","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.neucom.2026.133884_bib1115","series-title":"NDSS Symposium on Vehicular Security and Privacy","article-title":"Cooperative perception for safe control of autonomous vehicles under LiDAR spoofing attacks","author":"Zhang","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib1120","series-title":"Proceedings of the 8th Conference on Robot Learning of Proceedings of Machine Learning Research","first-page":"4698","article-title":"Drivevlm: the convergence of autonomous driving and large vision-language models","volume":"vol. 270","author":"Tian","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib1125","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV)","first-page":"6585","article-title":"Are vlms ready for autonomous driving? An empirical study from the reliability, data and metric perspectives","author":"Xie","year":"2025"},{"key":"10.1016\/j.neucom.2026.133884_bib1130","series-title":"2023 IEEE\/CVF International Conference on Computer Vision (ICCV)","first-page":"8545","article-title":"Motionlm: multi-agent motion forecasting as language modeling","author":"Seff","year":"2023"},{"key":"10.1016\/j.neucom.2026.133884_bib1135","series-title":"2024 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","first-page":"15141","article-title":"Lampilot: an open benchmark dataset for autonomous driving with language model programs","author":"Yunsheng","year":"2024"}],"container-title":["Neurocomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0925231226012816?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0925231226012816?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,8,27]],"date-time":"2026-08-27T16:25:43Z","timestamp":1787847943000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0925231226012816"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":227,"alternative-id":["S0925231226012816"],"URL":"https:\/\/doi.org\/10.1016\/j.neucom.2026.133884","relation":{},"ISSN":["0925-2312"],"issn-type":[{"value":"0925-2312","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A comprehensive review of adversarial attacks on autonomous driving: From single-modality to multi-sensor fusion","name":"articletitle","label":"Article Title"},{"value":"Neurocomputing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neucom.2026.133884","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"133884"}}