{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T12:29:11Z","timestamp":1777984151416,"version":"3.51.4"},"reference-count":67,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]},{"name":"AVL"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Intell. Veh."],"published-print":{"date-parts":[[2025,5]]},"DOI":"10.1109\/tiv.2024.3449830","type":"journal-article","created":{"date-parts":[[2024,8,26]],"date-time":"2024-08-26T13:37:20Z","timestamp":1724679440000},"page":"3208-3221","source":"Crossref","is-referenced-by-count":1,"title":["AVATAR: Autonomous Vehicle Assessment Through Testing of Adversarial Patches in Real-Time"],"prefix":"10.1109","volume":"10","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4592-2928","authenticated-orcid":false,"given":"Abhijith","family":"Sharma","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Waterloo, Waterloo, ON, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7203-8698","authenticated-orcid":false,"given":"Apurva","family":"Narayan","sequence":"additional","affiliation":[{"name":"Department of System Design Engineering, University of Waterloo, Waterloo, ON, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1412-7961","authenticated-orcid":false,"given":"Nasser Lashgarian","family":"Azad","sequence":"additional","affiliation":[{"name":"Department of System Design Engineering, University of Waterloo, Waterloo, ON, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8327-0000","authenticated-orcid":false,"given":"Sebastian","family":"Fischmeister","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Waterloo, Waterloo, ON, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8556-1541","authenticated-orcid":false,"given":"Stefan","family":"Marksteiner","sequence":"additional","affiliation":[{"name":"AVL List GmbH, Graz, Austria"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2983149"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3043716"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/IVS.2011.5940562"},{"key":"ref4","first-page":"1","article-title":"Ten ways autonomous driving could redefine the automotive world","volume":"6","author":"Bertoncello","year":"2015","journal-title":"McKinsey Co."},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2023.3321309"},{"key":"ref6","first-page":"3","article-title":"Environmental, safety legal and societal implications of autonomous driving systems","volume-title":"Proc. Int. Tech. Conf. Enhanced Saf. Veh.","volume":"334","author":"Eugensson"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1002\/rob.21918"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2021.3054625"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-022-01657-x"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.2993926"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.108796"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.2972974"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.281"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3130054"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVE45908.2019.8965092"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102269"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TIV.2022.3213796"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/OJVT.2023.3265363"},{"key":"ref19","article-title":"Benchmarking robustness in object detection: Autonomous driving when winter is coming","author":"Michaelis","year":"2019"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/PerCom45495.2020.9127389"},{"key":"ref21","first-page":"29935","article-title":"Data augmentation can improve robustness","volume-title":"Proc. Int. Conf. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Rebuffi","year":"2021"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-019-0197-0"},{"key":"ref23","first-page":"3571","article-title":"On interaction between augmentations and corruptions in natural corruption robustness","volume-title":"Proc. Int. Conf. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Mintun","year":"2021"},{"key":"ref24","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref25","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref27","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Madry","year":"2018"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1049\/cit2.12028"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref30","article-title":"Adversarial patch attacks and defences in vision-based tasks: A survey","author":"Sharma","year":"2022"},{"key":"ref31","article-title":"Adversarial patch","author":"Brown","year":"2017"},{"key":"ref32","article-title":"DPATCH: An adversarial patch attack on object detectors","volume-title":"Proc. Workshop Artif. Intell. Saf. 33th AAAI Conf. Artif. Intell.","volume":"2301","author":"Liu","year":"2019"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00288"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00249"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-19-8285-9_15"},{"key":"ref38","article-title":"On physical adversarial patches for object detection","author":"Lee","year":"2019"},{"key":"ref39","first-page":"1","article-title":"CARLA: An open urban driving simulator","volume-title":"Proc. Conf. Robot Learn.","author":"Dosovitskiy","year":"2017"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ITSC45102.2020.9294422"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67361-5_40"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2024.3412432"},{"key":"ref43","article-title":"Dynamic adversarial patch for evading object detection models","author":"Hoory","year":"2020"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-014-0733-5"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1561\/0600000079"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6248074"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.350"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00252"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01164"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.3390\/app12010281"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-33-4443-3_46"},{"issue":"1","key":"ref53","first-page":"85","article-title":"Comparison of CNN and YOLO for object detection","volume":"19","author":"Lee","year":"2020","journal-title":"J. Semicond. Display Technol."},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/ICICV50876.2021.9388577"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.08.087"},{"key":"ref56","article-title":"Impact of data quality on ML models: Improving data quality with outlier detection","author":"Sharma","year":"2024"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-67658-2_37"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00144"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00076"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3636534.3649372"},{"key":"ref61","first-page":"1013","article-title":"Exploring adversarial robustness of multi-sensor perception systems in self driving","volume-title":"Proc. 5th Conf. Robot Learn.","volume":"164","author":"Tu","year":"2022"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-97-2303-4_25"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3579988.3585054"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02310"},{"key":"ref65","first-page":"2237","article-title":"PatchGuard: A provably robust defense against adversarial patches via small receptive fields and masking","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Xiang","year":"2021"},{"key":"ref66","first-page":"2065","article-title":"{PatchCleanser}: Certifiably robust defense against adversarial patches for any image classifier","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Xiang","year":"2022"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00379"}],"container-title":["IEEE Transactions on Intelligent Vehicles"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/7274857\/11151628\/10646575.pdf?arnumber=10646575","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T18:26:15Z","timestamp":1757096775000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10646575\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5]]},"references-count":67,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tiv.2024.3449830","relation":{"has-preprint":[{"id-type":"doi","id":"10.36227\/techrxiv.172165647.71183157\/v1","asserted-by":"object"},{"id-type":"doi","id":"10.36227\/techrxiv.172165647.71183157\/v2","asserted-by":"object"}]},"ISSN":["2379-8904","2379-8858"],"issn-type":[{"value":"2379-8904","type":"electronic"},{"value":"2379-8858","type":"print"}],"subject":[],"published":{"date-parts":[[2025,5]]}}}