{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T18:15:57Z","timestamp":1771697757262,"version":"3.50.1"},"reference-count":48,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2021,3,15]],"date-time":"2021-03-15T00:00:00Z","timestamp":1615766400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,3,15]],"date-time":"2021-03-15T00:00:00Z","timestamp":1615766400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,3,15]],"date-time":"2021-03-15T00:00:00Z","timestamp":1615766400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100011222","name":"Open Project Program of the National Laboratory of Pattern Recognition","doi-asserted-by":"publisher","award":["202000009"],"award-info":[{"award-number":["202000009"]}],"id":[{"id":"10.13039\/501100011222","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Major Scientific and Technological Projects of CNPC","award":["ZD2019-183-008"],"award-info":[{"award-number":["ZD2019-183-008"]}]},{"name":"Chinese NSF Project","award":["61771315"],"award-info":[{"award-number":["61771315"]}]},{"DOI":"10.13039\/501100000923","name":"Australian Research Council Projects","doi-asserted-by":"publisher","award":["FL-170100117"],"award-info":[{"award-number":["FL-170100117"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000923","name":"Australian Research Council Projects","doi-asserted-by":"publisher","award":["IC-190100031"],"award-info":[{"award-number":["IC-190100031"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Internet Things J."],"published-print":{"date-parts":[[2021,3,15]]},"DOI":"10.1109\/jiot.2020.3034899","type":"journal-article","created":{"date-parts":[[2020,10,30]],"date-time":"2020-10-30T20:52:47Z","timestamp":1604091167000},"page":"4980-4990","source":"Crossref","is-referenced-by-count":45,"title":["Targeted Attention Attack on Deep Learning Models in Road Sign Recognition"],"prefix":"10.1109","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6487-3183","authenticated-orcid":false,"given":"Xinghao","family":"Yang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5388-9080","authenticated-orcid":false,"given":"Weifeng","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7937-5870","authenticated-orcid":false,"given":"Shengli","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6565-5815","authenticated-orcid":false,"given":"Wei","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7225-5449","authenticated-orcid":false,"given":"Dacheng","family":"Tao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3003047"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/j.is.2020.101522"},{"key":"ref33","author":"xiao","year":"2018","journal-title":"Spatially transformed adversarial examples"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00130"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref30","author":"chen","year":"2019","journal-title":"Boundary attack++ Query-efficient decision-based adversarial attack"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/BF01589116"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375728"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2020.2967289"},{"key":"ref34","first-page":"1802","article-title":"Exploring the landscape of spatial robustness","author":"engstrom","year":"2019","journal-title":"Proc 36th Int Conf Mach Learn"},{"key":"ref10","author":"szegedy","year":"2013","journal-title":"Intriguing properties of neural networks"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref11","author":"goodfellow","year":"2014","journal-title":"Explaining and Harnessing Adversarial Examples"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46675-0_9"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00443"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972818.17"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.312"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref18","author":"narodytska","year":"2016","journal-title":"Simple Black-Box Adversarial Perturbations for Deep Networks"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref28","author":"brendel","year":"2017","journal-title":"Decision-Based Adversarial Attacks Reliable Attacks Against Black-Box Machine Learning Models"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3269206.3271757"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6173"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2013.2296516"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2966506"},{"key":"ref29","author":"schott","year":"2018","journal-title":"Towards the first adversarially robust neural network model on mnist"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2812300"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-31753-3_43"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2014.2306328"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01084"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2996615"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2005.852196"},{"key":"ref20","author":"kurakin","year":"2016","journal-title":"Adversarial examples in the physical world"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"ref48","author":"reinhard","year":"2010","journal-title":"High Dynamic Range Imaging Acquisition Display and Image-Based Lighting"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref47","author":"rauber","year":"2017","journal-title":"Foolbox A python toolbox to benchmark the robustness of machine learning models"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref42","first-page":"2204","article-title":"Recurrent models of visual attention","author":"mnih","year":"2014","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.683"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TCSII.2020.2973007"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2012.2209421"},{"key":"ref26","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","author":"ilyas","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn (ICML)"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref25","author":"hayes","year":"2017","journal-title":"Machine learning as an adversarial service Learning black-box adversarial examples"}],"container-title":["IEEE Internet of Things Journal"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6488907\/9371274\/09245511.pdf?arnumber=9245511","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:53:45Z","timestamp":1652194425000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9245511\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,3,15]]},"references-count":48,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/jiot.2020.3034899","relation":{},"ISSN":["2327-4662","2372-2541"],"issn-type":[{"value":"2327-4662","type":"electronic"},{"value":"2372-2541","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,3,15]]}}}