{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,2]],"date-time":"2026-04-02T15:57:44Z","timestamp":1775145464767,"version":"3.50.1"},"reference-count":85,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001348","name":"Agency for Science, Technology and Research (A*STAR) under Singapore Aerospace Programme","doi-asserted-by":"publisher","award":["M2215a0067"],"award-info":[{"award-number":["M2215a0067"]}],"id":[{"id":"10.13039\/501100001348","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001381","name":"National Research Foundation Singapore and DSO National Laboratories under the AI Singapore Programme","doi-asserted-by":"publisher","award":["AISG2-GC-2023-007"],"award-info":[{"award-number":["AISG2-GC-2023-007"]}],"id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tnnls.2025.3561225","type":"journal-article","created":{"date-parts":[[2025,5,6]],"date-time":"2025-05-06T13:03:56Z","timestamp":1746536636000},"page":"15706-15722","source":"Crossref","is-referenced-by-count":11,"title":["A Survey and Evaluation of Adversarial Attacks in Object Detection"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-0227-4887","authenticated-orcid":false,"given":"Khoi Nguyen Tiet","family":"Nguyen","sequence":"first","affiliation":[{"name":"Institute for Infocomm Research, Agency for Science, Technology and Research (A*STAR), Fusionopolis, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3849-4320","authenticated-orcid":false,"given":"Wenyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute for Infocomm Research, A*STAR, Fusionopolis, Singapore"}]},{"given":"Kangkang","family":"Lu","sequence":"additional","affiliation":[{"name":"Institute for Infocomm Research, A*STAR, Fusionopolis, Singapore"}]},{"given":"Yu-Huan","family":"Wu","sequence":"additional","affiliation":[{"name":"Institute of High Performance Computing, A*STAR, Fusionopolis, Singapore"}]},{"given":"Xingjian","family":"Zheng","sequence":"additional","affiliation":[{"name":"Institute of High Performance Computing, A*STAR, Fusionopolis, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3012-9222","authenticated-orcid":false,"given":"Hui","family":"Li Tan","sequence":"additional","affiliation":[{"name":"Institute for Infocomm Research, A*STAR, Fusionopolis, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0481-3298","authenticated-orcid":false,"given":"Liangli","family":"Zhen","sequence":"additional","affiliation":[{"name":"Institute of High Performance Computing, A*STAR, Fusionopolis, Singapore"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00127"},{"key":"ref2","article-title":"ONE-PEACE: Exploring one general representation model toward unlimited modalities","author":"Wang","year":"2023","journal-title":"arXiv:2305.11172"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00071"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-60248-2_27"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100270"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1049\/cit2.12028"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICUS55513.2022.9986597"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICDIS55630.2022.00021"},{"key":"ref10","first-page":"1","article-title":"RobustBench: A standardized adversarial robustness benchmark","volume-title":"Proc. Neural Inf. Process. Syst. Track Datasets Benchmarks","volume":"1","author":"Croce"},{"key":"ref11","article-title":"RobustART: Benchmarking robustness on architecture design and training techniques","author":"Tang","year":"2021","journal-title":"arXiv:2109.05211"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/QRS-C55045.2021.00012"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/s00371-022-02660-6"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2022.10.046"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.23919\/CCC50068.2020.9188998"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00428"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TPS-ISA50397.2020.00042"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108491"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00394"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01460"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-25056-9_21"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00760"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2020.3041481"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1002\/int.22851"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/UEMCON.2018.8796670"},{"key":"ref27","article-title":"A comprehensive study of real-time object detection networks across multiple domains: A survey","author":"Arani","year":"2022","journal-title":"Trans. Mach. Learn. Res."},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59013-0_23"},{"key":"ref29","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","volume":"80","author":"Athalye"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00289"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i1.19889"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00455"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.l007\/978-3-319-46448-0_2"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2004.10934"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00091"},{"key":"ref41","article-title":"DPAttack: Diffused patch attacks against universal object detection","author":"Wu","year":"2020","journal-title":"arXiv:2010.11679"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.3002345"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3032166"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58452-8_13"},{"key":"ref45","article-title":"Deformable DETR: Deformable transformers for end-to-end object detection","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Zhu"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.81"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58580-8_24"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01422"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/134"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428443"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107584"},{"key":"ref52","article-title":"Exploring the vulnerability of single shot module in object detectors via imperceptible background patches","volume-title":"Proc. Brit. Mach. Vis. Conf. (BMVC)","author":"Li"},{"key":"ref53","first-page":"1204","article-title":"G-UAP: Generic universal adversarial perturbation that fools RPN-based detectors","volume-title":"Proc. Asian Conf. Mach. Learn. (ACML)","author":"Wu"},{"key":"ref54","article-title":"DPatch: An adversarial patch attack on object detectors","volume-title":"Proc. AAAI Workshop Artif. Intell. Saf.","author":"Liu"},{"key":"ref55","article-title":"Robust adversarial perturbation on deep proposal-based models","volume-title":"Proc. Brit. Mach. Vis. Conf. (BMVC)","author":"Li"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/ICME46284.2020.9102805"},{"key":"ref57","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Madry"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2020.102634"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-021-11480-0"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"ref61","first-page":"18583","article-title":"Measuring robustness to natural distribution shifts in image classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Taori"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-009-0275-4"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.690"},{"key":"ref64","article-title":"YOLOv3: An incremental improvement","author":"Redmon","year":"2018","journal-title":"arXiv:1804.02767"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3395118"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3208131"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20077-9_18"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00400"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01028"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00051"},{"key":"ref71","first-page":"1275","article-title":"Detection as regression: Certified object detection by median smoothing","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Chiang"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3631908.3631920"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548362"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP51287.2024.10647435"},{"key":"ref76","article-title":"Adversarial YOLO: Defense human detection patch attacks via detecting adversarial patches","author":"Ji","year":"2021","journal-title":"arXiv:2103.08860"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484757"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72970-6_3"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01069"},{"key":"ref80","first-page":"26831","article-title":"Are transformers more robust than CNNs?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Bai"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01007"},{"key":"ref82","article-title":"Understanding the robustness in vision transformers","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhou"},{"key":"ref83","article-title":"Exploring the landscape of spatial robustness","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Engstrom"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00123"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00108"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/5962385\/11151745\/10988892.pdf?arnumber=10988892","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,5]],"date-time":"2025-09-05T18:24:04Z","timestamp":1757096644000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10988892\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":85,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2025.3561225","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}