{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,25]],"date-time":"2026-01-25T05:02:37Z","timestamp":1769317357434,"version":"3.49.0"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"7","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62202178"],"award-info":[{"award-number":["62202178"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Technologies Research and Development General Program of Shenzhen","award":["JSGG20201102170601003"],"award-info":[{"award-number":["JSGG20201102170601003"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Intell. Transport. Syst."],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1109\/tits.2023.3347860","type":"journal-article","created":{"date-parts":[[2024,1,11]],"date-time":"2024-01-11T18:25:53Z","timestamp":1704997553000},"page":"7081-7092","source":"Crossref","is-referenced-by-count":7,"title":["Fooling Decision-Based Black-Box Automotive Vision Perception Systems in Physical World"],"prefix":"10.1109","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-1684-8694","authenticated-orcid":false,"given":"Wei","family":"Jia","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5467-6597","authenticated-orcid":false,"given":"Zhaojun","family":"Lu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9806-3559","authenticated-orcid":false,"given":"Runze","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Optical and Electronic Information, Huazhong University of Science and Technology, Wuhan, China"}]},{"given":"Liaoyuan","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Huazhong University of Science and Technology, Wuhan, China"}]},{"given":"Haichun","family":"Zhang","sequence":"additional","affiliation":[{"name":"Shenzhen Kaiyuan Internet Security Company Ltd., Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1546-3417","authenticated-orcid":false,"given":"Zhenglin","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Optical and Electronic Information, Huazhong University of Science and Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6759-8949","authenticated-orcid":false,"given":"Gang","family":"Qu","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Institute for Systems Research, University of Maryland, College Park, MD, USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2004.10934"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.6"},{"key":"ref3","article-title":"Pseudo-LiDAR++: Accurate depth for 3D object detection in autonomous driving","author":"You","year":"2019","journal-title":"arXiv:1906.06310"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref6","first-page":"19288","article-title":"Finding optimal tangent points for reducing distortions of hard-label attacks","volume-title":"Proc. NeurIPS","author":"Ma"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01586"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_10"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467386"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-10925-7_4"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354259"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102694"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00047"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref18","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017","journal-title":"arXiv:1712.04248"},{"key":"ref19","first-page":"10932","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Cheng"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01166"},{"key":"ref21","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. ICML","author":"Athalye"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00288"},{"key":"ref23","first-page":"1865","article-title":"SLAP: Improving physical adversarial examples with short-lived adversarial perturbations","volume-title":"Proc. USENIX Secur. Symp.","author":"Lovisotto"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301962"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01426"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3485730.3485935"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24130"},{"key":"ref28","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016","journal-title":"arXiv:1605.07277"},{"key":"ref29","article-title":"Sign-OPT: A query-efficient hard-label adversarial attack","volume-title":"Proc. 8th Int. Conf. Learn. Represent.","author":"Cheng"},{"key":"ref30","volume-title":"Baidu Apollo","year":"2022"},{"key":"ref31","volume-title":"Autoware.Ai","year":"2022"},{"key":"ref32","volume-title":"YOLOv5","year":"2020"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.232"},{"key":"ref36","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014","journal-title":"arXiv:1412.6980"},{"key":"ref37","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1126\/science.290.5500.2319"},{"key":"ref40","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"Ioffe","year":"2015","journal-title":"arXiv:1502.03167"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00371"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/iccv.2017.322"},{"key":"ref45","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2939352"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00700"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2023.3300537"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00076"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2022.3145467"},{"key":"ref52","first-page":"317","article-title":"GhostImage: Remote perception attacks against camera-based image classification systems","volume-title":"Proc. RAID","author":"Man"}],"container-title":["IEEE Transactions on Intelligent Transportation Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6979\/10582787\/10397075.pdf?arnumber=10397075","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,3]],"date-time":"2024-07-03T17:47:29Z","timestamp":1720028849000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10397075\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":52,"journal-issue":{"issue":"7"},"URL":"https:\/\/doi.org\/10.1109\/tits.2023.3347860","relation":{},"ISSN":["1524-9050","1558-0016"],"issn-type":[{"value":"1524-9050","type":"print"},{"value":"1558-0016","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7]]}}}