{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T06:44:26Z","timestamp":1768545866337,"version":"3.49.0"},"reference-count":83,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"10","license":[{"start":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T00:00:00Z","timestamp":1759276800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T00:00:00Z","timestamp":1759276800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T00:00:00Z","timestamp":1759276800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"NSFC Projects","award":["92370124"],"award-info":[{"award-number":["92370124"]}]},{"name":"NSFC Projects","award":["92248303"],"award-info":[{"award-number":["92248303"]}]},{"name":"NSFC Projects","award":["62276149"],"award-info":[{"award-number":["62276149"]}]},{"name":"NSFC Projects","award":["62350080"],"award-info":[{"award-number":["62350080"]}]},{"name":"NSFC Projects","award":["62061136001"],"award-info":[{"award-number":["62061136001"]}]},{"name":"NSFC Projects","award":["62076147"],"award-info":[{"award-number":["62076147"]}]},{"name":"NSFC Projects","award":["BNR2022RC01006"],"award-info":[{"award-number":["BNR2022RC01006"]}]},{"name":"Tsinghua Institute for Guo Qiang"},{"name":"High Performance Computing Center, Tsinghua University"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2025,10]]},"DOI":"10.1109\/tpami.2025.3585726","type":"journal-article","created":{"date-parts":[[2025,7,3]],"date-time":"2025-07-03T13:28:46Z","timestamp":1751549326000},"page":"9078-9094","source":"Crossref","is-referenced-by-count":1,"title":["Reinforced Embodied Active Defense: Exploiting Adaptive Interaction for Robust Visual Perception in Adversarial 3D Environments"],"prefix":"10.1109","volume":"47","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9502-9962","authenticated-orcid":false,"given":"Xiao","family":"Yang","sequence":"first","affiliation":[{"name":"Department of Computer Science &#x0026; Technology, Institute for AI, BNRist Center, THBI Lab, Tsinghua-Bosch Joint Center for ML, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3201-2244","authenticated-orcid":false,"given":"Lingxuan","family":"Wu","sequence":"additional","affiliation":[{"name":"Department of Computer Science &#x0026; Technology, Institute for AI, BNRist Center, THBI Lab, Tsinghua-Bosch Joint Center for ML, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0895-0732","authenticated-orcid":false,"given":"Lizhong","family":"Wang","sequence":"additional","affiliation":[{"name":"Department of Computer Science &#x0026; Technology, Institute for AI, BNRist Center, THBI Lab, Tsinghua-Bosch Joint Center for ML, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3334-2915","authenticated-orcid":false,"given":"Chengyang","family":"Ying","sequence":"additional","affiliation":[{"name":"Department of Computer Science &#x0026; Technology, Institute for AI, BNRist Center, THBI Lab, Tsinghua-Bosch Joint Center for ML, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8294-6315","authenticated-orcid":false,"given":"Hang","family":"Su","sequence":"additional","affiliation":[{"name":"Department of Computer Science &#x0026; Technology, Institute for AI, BNRist Center, THBI Lab, Tsinghua-Bosch Joint Center for ML, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6254-2388","authenticated-orcid":false,"given":"Jun","family":"Zhu","sequence":"additional","affiliation":[{"name":"Department of Computer Science &#x0026; Technology, Institute for AI, BNRist Center, THBI Lab, Tsinghua-Bosch Joint Center for ML, Tsinghua University, Beijing, China"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Adversarial patch","author":"Brown","year":"2017"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52729.2023.02069"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01167"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-024-02177-6"},{"key":"ref6","first-page":"1","article-title":"Physical adversarial examples for object detectors","volume-title":"Proc. USENIX Conf. Offensive Technol.","author":"Song"},{"key":"ref7","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref8","article-title":"Defending against physically realizable attacks on image classification","author":"Wu","year":"2019"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"ref10","first-page":"4218","article-title":"Improving robustness using generated data","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Gowal"},{"key":"ref11","first-page":"2237","article-title":"Patchguard: A provably robust defense against adversarial patches via small receptive fields and masking","volume-title":"Proc. USENIX Secur. Symp.","author":"Xiang"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00461"},{"key":"ref14","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref15","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Tramer"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1207\/s15516709cog2302_3"},{"key":"ref17","first-page":"3914","article-title":"Adversarial examples that fool both computer vision and time-limited humans","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Elsayed"},{"key":"ref18","article-title":"Embodied active defense: Leveraging recurrent feedback to counter adversarial patches","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wu"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00401"},{"key":"ref21","article-title":"A study of the effect of JPG compression on adversarial images","author":"Dziugaite","year":"2016"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00051"},{"key":"ref24","first-page":"23","article-title":"Probabilistic margins for instance reweighting in adversarial training","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Liu"},{"key":"ref25","first-page":"25","article-title":"Understanding robust overfitting of adversarial training and beyond","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yu"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3635310"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/BF00133571"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/5.5968"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01444"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/iccv51070.2023.00434"},{"key":"ref31","article-title":"Proactive multi-camera collaboration for 3D human pose estimation","author":"Ci","year":"2023"},{"key":"ref32","article-title":"SQA3D: Situated question answering in 3D scenes","author":"Ma","year":"2022"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.322"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref36","first-page":"1023","article-title":"Acting optimally in partially observable stochastic domains","volume-title":"Proc. Conf. Assoc. Advance. Artif. Intell.","author":"Cassandra"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1038\/s41593-019-0392-5"},{"key":"ref38","article-title":"Representation learning with contrastive predictive coding","author":"Oord","year":"2018"},{"key":"ref39","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Radford"},{"key":"ref40","article-title":"Understanding measures of uncertainty for adversarial example detection","author":"Smith","year":"2018"},{"key":"ref41","article-title":"Robust reinforcement learning on state observations with learned optimal adversary","author":"Zhang","year":"2021"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/510"},{"key":"ref43","first-page":"36","article-title":"ViewFool: Evaluating the robustness of visual recognition to adversarial viewpoints","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Dong"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/122344.122377"},{"key":"ref45","article-title":"The elements of differentiable programming","author":"Blondel","year":"2024"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/72.279181"},{"key":"ref47","first-page":"276","article-title":"Rethinking optimization with differentiable simulation from a global perspective","volume-title":"Proc. Conf. Robot Learn.","author":"Antonova"},{"key":"ref48","first-page":"1","article-title":"CARLA: An open urban driving simulator","volume-title":"Proc. Conf. Robot Learn.","author":"Dosovitskiy"},{"key":"ref49","volume-title":"Reinforcement Learning: An Introduction","author":"Sutton","year":"2018"},{"key":"ref50","first-page":"278","article-title":"Policy invariance under reward transformations: Theory and application to reward shaping","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ng"},{"key":"ref51","article-title":"Proximal policy optimization algorithms","author":"Schulman","year":"2017"},{"key":"ref52","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong","year":"2020"},{"key":"ref53","article-title":"Perceptual adversarial robustness: Defense against unseen threat models","author":"Laidlaw","year":"2020"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01565"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46454-1_36"},{"key":"ref56","article-title":"Labeled faces in the wild: A database for studying face recognition in unconstrained environments","author":"Huang","year":"2007"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-43567-6_13"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref59","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412193"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00552"},{"key":"ref62","first-page":"3866","article-title":"NATTACK: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1137\/120880811"},{"key":"ref64","first-page":"15","article-title":"Decision transformer: Reinforcement learning via sequence modeling","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02310"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72943-0_8"},{"key":"ref67","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/97879.97901"},{"key":"ref70","article-title":"Differentiable rendering: A survey","author":"Kato","year":"2020"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00780"},{"key":"ref72","article-title":"Accelerating 3D deep learning with PyTorch3D","author":"Ravi","year":"2020"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10584-0_11"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.94"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00084"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref77","article-title":"OpenAI Gym","author":"Brockman","year":"2016"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00706"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354259"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01628"},{"key":"ref83","article-title":"Ultralytics\/YOLOv5: V5. 0-YOLOv5-P6 1280 models, AWS, supervisely and YouTube integrations","author":"Jocher","year":"2021","journal-title":"Zenodo"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/11163533\/11068116.pdf?arnumber=11068116","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T13:10:54Z","timestamp":1758028254000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11068116\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10]]},"references-count":83,"journal-issue":{"issue":"10"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2025.3585726","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10]]}}}