{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T22:37:26Z","timestamp":1778625446692,"version":"3.51.4"},"reference-count":41,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"10","license":[{"start":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T00:00:00Z","timestamp":1727740800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T00:00:00Z","timestamp":1727740800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T00:00:00Z","timestamp":1727740800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Artif. Intell."],"published-print":{"date-parts":[[2024,10]]},"DOI":"10.1109\/tai.2024.3428520","type":"journal-article","created":{"date-parts":[[2024,7,15]],"date-time":"2024-07-15T15:27:55Z","timestamp":1721057275000},"page":"4884-4892","source":"Crossref","is-referenced-by-count":3,"title":["A Human-in-the-Middle Attack Against Object Detection Systems"],"prefix":"10.1109","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1778-1814","authenticated-orcid":false,"given":"Han","family":"Wu","sequence":"first","affiliation":[{"name":"University of Exeter, Exeter, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6783-3064","authenticated-orcid":false,"given":"Sareh","family":"Rowlands","sequence":"additional","affiliation":[{"name":"University of Exeter, Exeter, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2058-0834","authenticated-orcid":false,"given":"Johan","family":"Wahlstr\u00f6m","sequence":"additional","affiliation":[{"name":"University of Exeter, Exeter, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref2","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/IV55152.2023.10186608"},{"key":"ref4","article-title":"No need to worry about adversarial examples in object detection in autonomous vehicles","volume-title":"Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Lu","year":"2017"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/IV55152.2023.10186386"},{"key":"ref6","article-title":"On physical adversarial patches for object detection","author":"Lee","year":"2019"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2876865"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.4324\/9780203978948-13"},{"key":"ref11","article-title":"Yolov4: Optimal speed and accuracy of object detection","author":"Bochkovskiy","year":"2020"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.l007\/978-3-319-46448-0_2"},{"issue":"6","key":"ref13","first-page":"1137","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"39","author":"Ren","year":"2016"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.322"},{"key":"ref15","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Goodfellow","year":"2015"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107584"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/IV55152.2023.10186386"},{"key":"ref19","article-title":"Traits & transferability of adversarial examples against instance segmentation & object detection","author":"Gurbaxani","year":"2018"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TPS-ISA50397.2020.00042"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/IV55152.2023.10186608"},{"key":"ref23","article-title":"Transferable universal adversarial perturbations using generative models","author":"Hashemi","year":"2020"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/134"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428301"},{"key":"ref27","article-title":"A survey on physical adversarial attack in computer vision","author":"Wang","year":"2022"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00846"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20141"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW54120.2021.00016"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01491"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021008"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SOCC56010.2022.9908112"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.593"},{"key":"ref37","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-009-0275-4"},{"key":"ref39","article-title":"KITTI-CARLA: A KITTI-like dataset generated by CARLA simulator","author":"Deschaud","year":"2021"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/IROS.2018.8594067"},{"key":"ref41","first-page":"1369","article-title":"Adversarial examples for semantic image segmentation","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Fischer","year":"2017"}],"container-title":["IEEE Transactions on Artificial Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/9078688\/10720652\/10599093.pdf?arnumber=10599093","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T01:09:33Z","timestamp":1755911373000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10599093\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10]]},"references-count":41,"journal-issue":{"issue":"10"},"URL":"https:\/\/doi.org\/10.1109\/tai.2024.3428520","relation":{},"ISSN":["2691-4581"],"issn-type":[{"value":"2691-4581","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10]]}}}