{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:17:56Z","timestamp":1763191076943,"version":"3.45.0"},"reference-count":77,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1109\/ijcnn64981.2025.11228187","type":"proceedings-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T18:46:15Z","timestamp":1763145975000},"page":"1-9","source":"Crossref","is-referenced-by-count":0,"title":["A Physical Attack for Segmentation-Based Visual Foundation Models"],"prefix":"10.1109","author":[{"given":"Mengqi","family":"He","sequence":"first","affiliation":[{"name":"Australian National University,ANU College of Systems and Society,Canberra,Australia"}]},{"given":"Jinhong","family":"Ni","sequence":"additional","affiliation":[{"name":"Australian National University,ANU College of Systems and Society,Canberra,Australia"}]},{"given":"Zhaoyuan","family":"Yang","sequence":"additional","affiliation":[{"name":"GE Research General Electric,New York"}]},{"given":"Yiwei","family":"Fu","sequence":"additional","affiliation":[{"name":"GE Research General Electric,New York"}]},{"given":"John","family":"Karigiannis","sequence":"additional","affiliation":[{"name":"GE Vernova Advanced Research General Electric,New York"}]},{"given":"Jing","family":"Zhang","sequence":"additional","affiliation":[{"name":"Australian National University,ANU College of Systems and Society,Canberra,Australia"}]}],"member":"263","reference":[{"article-title":"Intriguing properties of neural networks","volume-title":"ICLR","author":"Szegedy","key":"ref1"},{"article-title":"Explaining and harnessing adversarial examples","volume-title":"ICLR","author":"Goodfellow","key":"ref2"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref11","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"ICML","author":"Athalye"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref14","article-title":"A survey on physical adversarial attack in computer vision","author":"Wang","year":"2022","journal-title":"CoRR"},{"key":"ref15","article-title":"Adversarial patch","author":"Brown","year":"2017","journal-title":"CoRR"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00288"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58601-0_24"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3231886"},{"key":"ref21","article-title":"Dynamic adversarial patch for evading object detection models","author":"Hoory","year":"2020","journal-title":"CoRR"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3127849"},{"key":"ref23","article-title":"Random position adversarial patch for vision transformers","author":"Shao","year":"2023","journal-title":"CoRR"},{"key":"ref24","first-page":"44","article-title":"Projecting trouble: Light based adversarial attacks on deep learning classifiers","volume-title":"AAAI","author":"Nichols"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01443"},{"key":"ref26","article-title":"Light lies: Optical adversarial attack","author":"Kim","year":"2021","journal-title":"CoRR"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/VR51125.2022.00073"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00411"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00482"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58542-6_3"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00371"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00110"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72970-6_3"},{"key":"ref35","article-title":"Segment everything everywhere all at once","author":"Zou","year":"2023","journal-title":"CoRR"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00695"},{"key":"ref37","article-title":"On the opportunities and risks of foundation models","author":"Bommasani","year":"2021","journal-title":"CoRR"},{"article-title":"Cospgd: an efficient white-box adversarial attack for pixel-wise prediction tasks","volume-title":"ICML","author":"Agnihotri","key":"ref38"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01966"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19818-2_18"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00386"},{"key":"ref42","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"ICML","author":"Athalye"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301962"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00769"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01579"},{"key":"ref46","first-page":"33093","article-title":"Robust feature-level adversaries are interpretability tools","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Casper"},{"key":"ref47","first-page":"36789","article-title":"View-fool: Evaluating the robustness of visual recognition to adversarial viewpoints","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Dong"},{"article-title":"Watch out! motion is blurring the vision of your deep neural networks","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Guo","key":"ref48"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/WACVW54805.2022.00036"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/icpr48806.2021.9412236"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00401"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00108"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01628"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01487"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00846"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20141"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01295"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01965"},{"key":"ref60","article-title":"On the real-world adversarial robustness of real-time semantic segmentation models for autonomous driving","author":"Rossolini","year":"2022","journal-title":"CoRR"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3176760"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref64","article-title":"Attack-sam: Towards attacking segment anything model with adversarial examples","author":"Zhang","year":"2023","journal-title":"CoRR"},{"key":"ref65","article-title":"Segment (almost) nothing: Prompt-agnostic adversarial attacks on segmentation models","author":"Croce","year":"2023","journal-title":"CoRR"},{"key":"ref66","article-title":"On the robustness of segment anything","author":"Huang","year":"2023","journal-title":"CoRR"},{"key":"ref67","article-title":"Black-box targeted adversarial attack on segment anything (SAM)","author":"Zheng","year":"2023","journal-title":"CoRR"},{"key":"ref68","article-title":"Segment anything meets universal adversarial perturbation","author":"Han","year":"2023","journal-title":"CoRR"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7299155"},{"article-title":"Patch-fool: Are vision transformers always robust against adversarial perturbations?","year":"2022","author":"Fu","key":"ref70"},{"article-title":"Grounded sam: Assembling open-world models for diverse visual tasks","year":"2024","author":"Ren","key":"ref71"},{"key":"ref72","article-title":"On evaluating the adversarial robustness of semantic segmentation models","author":"Halmosi","year":"2023","journal-title":"CoRR"},{"key":"ref73","first-page":"17864","article-title":"Per-pixel classification is not all you need for semantic segmentation","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Cheng"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2105.15203"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.350"},{"key":"ref76","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Ilyas"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1802.02611"}],"event":{"name":"2025 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2025,6,30]]},"location":"Rome, Italy","end":{"date-parts":[[2025,7,5]]}},"container-title":["2025 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11227166\/11227148\/11228187.pdf?arnumber=11228187","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:13:36Z","timestamp":1763190816000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11228187\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":77,"URL":"https:\/\/doi.org\/10.1109\/ijcnn64981.2025.11228187","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]}}}