{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T06:58:17Z","timestamp":1775199497246,"version":"3.50.1"},"reference-count":60,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100003725","name":"Field-Oriented Technology Development Project for Customs Administration through the National Research Foundation of Korea (NRF) through the Ministry of Science and ICT and Korea Customs Service","doi-asserted-by":"publisher","award":["NRF-2021M3I1A1097938"],"award-info":[{"award-number":["NRF-2021M3I1A1097938"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tip.2021.3106807","type":"journal-article","created":{"date-parts":[[2021,8,27]],"date-time":"2021-08-27T20:10:55Z","timestamp":1630095055000},"page":"7541-7553","source":"Crossref","is-referenced-by-count":13,"title":["PSAT-GAN: Efficient Adversarial Attacks Against Holistic Scene Understanding"],"prefix":"10.1109","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7485-4493","authenticated-orcid":false,"given":"Lin","family":"Wang","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1634-2756","authenticated-orcid":false,"given":"Kuk-Jin","family":"Yoon","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","article-title":"Conditional generative adversarial nets","author":"mirza","year":"2014","journal-title":"arXiv 1411 1784"},{"key":"ref38","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Conf Neural Inf Process Syst"},{"key":"ref33","article-title":"On the (statistical) detection of adversarial examples","author":"grosse","year":"2017","journal-title":"arXiv 1702 06280"},{"key":"ref32","article-title":"Detecting adversarial samples from artifacts","author":"feinman","year":"2017","journal-title":"arXiv 1703 00410"},{"key":"ref31","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref30","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref37","article-title":"Deep-Safe: A data-driven approach for checking adversarial robustness in neural networks","author":"gopinath","year":"2017","journal-title":"arXiv 1710 00486"},{"key":"ref36","article-title":"Defensive distillation is not robust to adversarial examples","author":"carlini","year":"2016","journal-title":"arXiv 1607 04311"},{"key":"ref35","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc 35th Int Conf Mach Learn"},{"key":"ref34","first-page":"1","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","author":"song","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref60","first-page":"608","article-title":"Evdistill: Asynchronous events to end-task learning via bidirectional reconstruction-guided cross-modal knowledge distillation","author":"wang","year":"2021","journal-title":"Proc IEEE Conf Comput Vis and Pattern Recog"},{"key":"ref28","first-page":"12885","article-title":"Cross-domain transferability of adversarial perturbations","author":"naseer","year":"2019","journal-title":"Proc Conf Neural Inf Process Syst"},{"key":"ref27","first-page":"8312","article-title":"Constructing unrestricted adversarial examples with generative models","author":"song","year":"2018","journal-title":"Proc Conf Neural Inf Process Syst"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/LRA.2020.2967289"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref1","first-page":"1","article-title":"Fast scene understanding for autonomous driving","author":"neven","year":"2017","journal-title":"Proc DLVP"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"ref21","article-title":"Spatially transformed adversarial examples","author":"xiao","year":"2018","journal-title":"ArXiv 1801 02612"},{"key":"ref24","article-title":"Adversarial transformation networks: Learning to generate adversarial examples","author":"baluja","year":"2017","journal-title":"arXiv 1703 09387"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2996758.2996767"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/134"},{"key":"ref50","author":"everingham","year":"2012","journal-title":"The PASCAL Visual Object Classes Challenge 2012 (VOC2012) Results"},{"key":"ref51","author":"everingham","year":"2012","journal-title":"The PASCAL Visual Object Classes Challenge 2011 (VOC2011) Results"},{"key":"ref59","article-title":"Knowledge distillation and student-teacher learning for visual intelligence: A review and new outlooks","author":"wang","year":"2021","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.244"},{"key":"ref55","first-page":"234","article-title":"U-Net: Convolutional networks for biomedical image segmentation","author":"ronneberger","year":"2015","journal-title":"Proc Int Conf Med Image Comput Comput -Assist Intervent"},{"key":"ref54","first-page":"91","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","author":"ren","year":"2015","journal-title":"Proc Conf Neural Inf Process Syst"},{"key":"ref53","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv 1409 1556"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"ref10","first-page":"1","article-title":"Physical adversarial examples for object detectors","author":"song","year":"2018","journal-title":"Proc 12th USENIX Workshop Offensive Technol (WOOT)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01032"},{"key":"ref12","first-page":"1","article-title":"Adversarial examples for semantic image segmentation","author":"fischer","year":"2017","journal-title":"Proc Int Conf Learn Represent Workshop"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref14","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref15","doi-asserted-by":"crossref","DOI":"10.7551\/mitpress\/10761.003.0012","article-title":"Adversarial perturbations of deep neural networks","volume":"311","author":"warde-farley","year":"2016","journal-title":"Perturbation Optimization and Statistics"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.300"},{"key":"ref17","article-title":"Fast feature fool: A data independent approach to universal adversarial perturbations","author":"mopuri","year":"2017","journal-title":"arXiv 1707 05572 [cs]"},{"key":"ref18","first-page":"1","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/ICESS.2019.8782514"},{"key":"ref3","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref6","first-page":"52","article-title":"ShapeShifter: Robust physical adversarial attack on faster R-CNN object detector","author":"chen","year":"2018","journal-title":"Proc Eur Conf Mach Learn Knowl Discovery Databases"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref8","article-title":"Adversarial perturbations against deep neural networks for malware classification","author":"grosse","year":"2016","journal-title":"arXiv 1606 04435"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.3048626"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01219-9_11"},{"key":"ref45","first-page":"469","article-title":"Coupled generative adversarial networks","author":"liu","year":"2016","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3052084"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00834"},{"key":"ref42","first-page":"2172","article-title":"InfoGAN: Interpretable representation learning by information maximizing generative adversarial nets","author":"chen","year":"2016","journal-title":"Proc Conf Neural Inf Process Syst"},{"key":"ref41","first-page":"5767","article-title":"Improved training of Wasserstein GANs","author":"gulrajani","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00916"},{"key":"ref43","article-title":"BEGAN: Boundary equilibrium generative adversarial networks","author":"berthelot","year":"2017","journal-title":"arXiv 1703 10717"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/9263394\/09524508.pdf?arnumber=9524508","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,7]],"date-time":"2023-11-07T23:11:28Z","timestamp":1699398688000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9524508\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":60,"URL":"https:\/\/doi.org\/10.1109\/tip.2021.3106807","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"value":"1057-7149","type":"print"},{"value":"1941-0042","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}