{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T15:52:01Z","timestamp":1776181921576,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":40,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,5,19]],"date-time":"2021-05-19T00:00:00Z","timestamp":1621382400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-17-1-2012"],"award-info":[{"award-number":["N00014-17-1-2012"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["FA8750-18-C-0090"],"award-info":[{"award-number":["FA8750-18-C-0090"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000183","name":"Army Research Office","doi-asserted-by":"publisher","award":["W911NF-20-1-0080"],"award-info":[{"award-number":["W911NF-20-1-0080"]}],"id":[{"id":"10.13039\/100000183","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,5,19]]},"DOI":"10.1145\/3450267.3450535","type":"proceedings-article","created":{"date-parts":[[2021,4,1]],"date-time":"2021-04-01T22:09:05Z","timestamp":1617314945000},"page":"67-76","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":15,"title":["Real-time detectors for digital and physical adversarial inputs to perception systems"],"prefix":"10.1145","author":[{"given":"Yiannis","family":"Kantaros","sequence":"first","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Taylor","family":"Carpenter","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaustubh","family":"Sridhar","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yahan","family":"Yang","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Insup","family":"Lee","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James","family":"Weimer","sequence":"additional","affiliation":[{"name":"University of Pennsylvania"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,5,19]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Intriguing properties of neural networks,\" arXiv preprint arXiv:1312.6199","author":"Szegedy C.","year":"2013","unstructured":"C. Szegedy , W. Zaremba , I. Sutskever , J. Bruna , D. Erhan , I. Goodfellow , and R. Fergus , \" Intriguing properties of neural networks,\" arXiv preprint arXiv:1312.6199 , 2013 . C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, \"Intriguing properties of neural networks,\" arXiv preprint arXiv:1312.6199, 2013."},{"key":"e_1_3_2_1_2_1","volume-title":"Lavan: Localized and visible adversarial noise,\" arXiv preprint arXiv:1801.02608","author":"Karmon D.","year":"2018","unstructured":"D. Karmon , D. Zoran , and Y. Goldberg , \" Lavan: Localized and visible adversarial noise,\" arXiv preprint arXiv:1801.02608 , 2018 . D. Karmon, D. Zoran, and Y. Goldberg, \"Lavan: Localized and visible adversarial noise,\" arXiv preprint arXiv:1801.02608, 2018."},{"key":"e_1_3_2_1_3_1","first-page":"1625","article-title":"Robust physical-world attacks on deep learning visual classification","author":"Eykholt K.","year":"2018","unstructured":"K. Eykholt , I. Evtimov , E. Fernandes , B. Li , A. Rahmati , C. Xiao , A. Prakash , T. Kohno , and D. Song , \" Robust physical-world attacks on deep learning visual classification ,\" in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2018 , pp. 1625 -- 1634 . K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, \"Robust physical-world attacks on deep learning visual classification,\" in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2018, pp. 1625--1634.","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"e_1_3_2_1_4_1","volume-title":"Explaining and harnessing adversarial examples,\" arXiv preprint arXiv:1412.6572","author":"Goodfellow I. J.","year":"2014","unstructured":"I. J. Goodfellow , J. Shlens , and C. Szegedy , \" Explaining and harnessing adversarial examples,\" arXiv preprint arXiv:1412.6572 , 2014 . I. J. Goodfellow, J. Shlens, and C. Szegedy, \"Explaining and harnessing adversarial examples,\" arXiv preprint arXiv:1412.6572, 2014."},{"key":"e_1_3_2_1_5_1","first-page":"39","volume-title":"ACM","author":"Zantedeschi V.","year":"2017","unstructured":"V. Zantedeschi , M.-I. Nicolae , and A. Rawat , \" Efficient defenses against adversarial attacks,\" in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security . ACM , 2017 , pp. 39 -- 49 . V. Zantedeschi, M.-I. Nicolae, and A. Rawat, \"Efficient defenses against adversarial attacks,\" in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. ACM, 2017, pp. 39--49."},{"key":"e_1_3_2_1_6_1","first-page":"1321","volume-title":"On calibration of modern neural networks,\" in Proceedings of the 34th International Conference on Machine Learning-Volume 70. JMLR. org","author":"Guo C.","year":"2017","unstructured":"C. Guo , G. Pleiss , Y. Sun , and K. Q. Weinberger , \" On calibration of modern neural networks,\" in Proceedings of the 34th International Conference on Machine Learning-Volume 70. JMLR. org , 2017 , pp. 1321 -- 1330 . C. Guo, G. Pleiss, Y. Sun, and K. Q. Weinberger, \"On calibration of modern neural networks,\" in Proceedings of the 34th International Conference on Machine Learning-Volume 70. JMLR. org, 2017, pp. 1321--1330."},{"key":"e_1_3_2_1_7_1","first-page":"39","volume-title":"IEEE","author":"Carlini N.","year":"2017","unstructured":"N. Carlini and D. Wagner , \" Towards evaluating the robustness of neural networks,\" in 2017 IEEE Symposium on Security and Privacy (SP) . IEEE , 2017 , pp. 39 -- 57 . N. Carlini and D. Wagner, \"Towards evaluating the robustness of neural networks,\" in 2017 IEEE Symposium on Security and Privacy (SP). IEEE, 2017, pp. 39--57."},{"key":"e_1_3_2_1_8_1","volume-title":"Damagenet: A universal adversarial dataset,\" arXiv preprint arXiv:1912.07160","author":"Chen S.","year":"2019","unstructured":"S. Chen , X. Huang , Z. He , and C. Sun , \" Damagenet: A universal adversarial dataset,\" arXiv preprint arXiv:1912.07160 , 2019 . S. Chen, X. Huang, Z. He, and C. Sun, \"Damagenet: A universal adversarial dataset,\" arXiv preprint arXiv:1912.07160, 2019."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"e_1_3_2_1_10_1","unstructured":"C. Guo M. Rana M. Cisse and L. van der Maaten \"Countering adversarial images using input transformations \" arXiv preprint arXiv:1711.00117 2017. C. Guo M. Rana M. Cisse and L. van der Maaten \"Countering adversarial images using input transformations \" arXiv preprint arXiv:1711.00117 2017."},{"key":"e_1_3_2_1_11_1","first-page":"196","volume-title":"ACM","author":"Das N.","year":"2018","unstructured":"N. Das , M. Shanbhogue , S.-T. Chen , F. Hohman , S. Li , L. Chen , M. E. Kounavis , and D. H. Chau , \" Shield: Fast, practical defense and vaccination for deep learning using jpeg compression,\" in Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining . ACM , 2018 , pp. 196 -- 204 . N. Das, M. Shanbhogue, S.-T. Chen, F. Hohman, S. Li, L. Chen, M. E. Kounavis, and D. H. Chau, \"Shield: Fast, practical defense and vaccination for deep learning using jpeg compression,\" in Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining. ACM, 2018, pp. 196--204."},{"key":"e_1_3_2_1_12_1","volume-title":"Defense-gan: Protecting classifiers against adversarial attacks using generative models,\" arXiv preprint arXiv:1805.06605","author":"Samangouei P.","year":"2018","unstructured":"P. Samangouei , M. Kabkab , and R. Chellappa , \" Defense-gan: Protecting classifiers against adversarial attacks using generative models,\" arXiv preprint arXiv:1805.06605 , 2018 . P. Samangouei, M. Kabkab, and R. Chellappa, \"Defense-gan: Protecting classifiers against adversarial attacks using generative models,\" arXiv preprint arXiv:1805.06605, 2018."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1002\/int.22258"},{"key":"e_1_3_2_1_14_1","first-page":"4480","volume-title":"Improving the robustness of deep neural networks via stability training,\" in Proceedings of the ieee conference on computer vision and pattern recognition","author":"Zheng S.","year":"2016","unstructured":"S. Zheng , Y. Song , T. Leung , and I. Goodfellow , \" Improving the robustness of deep neural networks via stability training,\" in Proceedings of the ieee conference on computer vision and pattern recognition , 2016 , pp. 4480 -- 4488 . S. Zheng, Y. Song, T. Leung, and I. Goodfellow, \"Improving the robustness of deep neural networks via stability training,\" in Proceedings of the ieee conference on computer vision and pattern recognition, 2016, pp. 4480--4488."},{"key":"e_1_3_2_1_15_1","volume-title":"Enhancing transformation-based defenses against adversarial attacks with a distribution classifier,\" in International Conference on Learning Representations","author":"Kou C.","year":"2019","unstructured":"C. Kou , H. K. Lee , E.-C. Chang , and T. K. Ng , \" Enhancing transformation-based defenses against adversarial attacks with a distribution classifier,\" in International Conference on Learning Representations , 2019 . C. Kou, H. K. Lee, E.-C. Chang, and T. K. Ng, \"Enhancing transformation-based defenses against adversarial attacks with a distribution classifier,\" in International Conference on Learning Representations, 2019."},{"key":"e_1_3_2_1_16_1","volume-title":"Detecting adversarial examples through image transformation,\" in Thirty-Second AAAI Conference on Artificial Intelligence","author":"Tian S.","year":"2018","unstructured":"S. Tian , G. Yang , and Y. Cai , \" Detecting adversarial examples through image transformation,\" in Thirty-Second AAAI Conference on Artificial Intelligence , 2018 . S. Tian, G. Yang, and Y. Cai, \"Detecting adversarial examples through image transformation,\" in Thirty-Second AAAI Conference on Artificial Intelligence, 2018."},{"key":"e_1_3_2_1_17_1","first-page":"135","volume-title":"ACM","author":"Meng D.","year":"2017","unstructured":"D. Meng and H. Chen , \" Magnet: a two-pronged defense against adversarial examples,\" in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security . ACM , 2017 , pp. 135 -- 147 . D. Meng and H. Chen, \"Magnet: a two-pronged defense against adversarial examples,\" in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. ACM, 2017, pp. 135--147."},{"key":"e_1_3_2_1_18_1","volume-title":"Detecting adversarial samples from artifacts,\" arXiv preprint arXiv:1703.00410","author":"Feinman R.","year":"2017","unstructured":"R. Feinman , R. R. Curtin , S. Shintre , and A. B. Gardner , \" Detecting adversarial samples from artifacts,\" arXiv preprint arXiv:1703.00410 , 2017 . R. Feinman, R. R. Curtin, S. Shintre, and A. B. Gardner, \"Detecting adversarial samples from artifacts,\" arXiv preprint arXiv:1703.00410, 2017."},{"key":"e_1_3_2_1_19_1","first-page":"547","article-title":"Detecting adversarial examples using data manifolds,\" in IEEE Military Communications Conference (MILCOM), Norfolk","author":"Jha S.","year":"2018","unstructured":"S. Jha , U. Jang , S. Jha , and B. Jalaian , \" Detecting adversarial examples using data manifolds,\" in IEEE Military Communications Conference (MILCOM), Norfolk , VA , 2018 , pp. 547 -- 552 . S. Jha, U. Jang, S. Jha, and B. Jalaian, \"Detecting adversarial examples using data manifolds,\" in IEEE Military Communications Conference (MILCOM), Norfolk, VA, 2018, pp. 547--552.","journal-title":"VA"},{"key":"e_1_3_2_1_20_1","first-page":"1","volume-title":"IEEE","author":"Fidel G.","year":"2020","unstructured":"G. Fidel , R. Bitton , and A. Shabtai , \" When explainability meets adversarial learning: Detecting adversarial examples using shap signatures,\" in 2020 International Joint Conference on Neural Networks (IJCNN) . IEEE , 2020 , pp. 1 -- 8 . G. Fidel, R. Bitton, and A. Shabtai, \"When explainability meets adversarial learning: Detecting adversarial examples using shap signatures,\" in 2020 International Joint Conference on Neural Networks (IJCNN). IEEE, 2020, pp. 1--8."},{"key":"e_1_3_2_1_21_1","first-page":"4584","article-title":"Towards robust detection of adversarial examples","author":"Pang T.","year":"2018","unstructured":"T. Pang , C. Du , Y. Dong , and J. Zhu , \" Towards robust detection of adversarial examples ,\" in Advances in Neural Information Processing Systems , 2018 , pp. 4584 -- 4594 . T. Pang, C. Du, Y. Dong, and J. Zhu, \"Towards robust detection of adversarial examples,\" in Advances in Neural Information Processing Systems, 2018, pp. 4584--4594.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_22_1","first-page":"14453","article-title":"Detecting adversarial samples using influence functions and nearest neighbors","author":"Cohen G.","year":"2020","unstructured":"G. Cohen , G. Sapiro , and R. Giryes , \" Detecting adversarial samples using influence functions and nearest neighbors ,\" in Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition , 2020 , pp. 14453 -- 14462 . G. Cohen, G. Sapiro, and R. Giryes, \"Detecting adversarial samples using influence functions and nearest neighbors,\" in Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2020, pp. 14453--14462.","journal-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition"},{"key":"e_1_3_2_1_23_1","first-page":"4825","article-title":"Detection based defense against adversarial examples from the steganalysis point of view","author":"Liu J.","year":"2019","unstructured":"J. Liu , W. Zhang , Y. Zhang , D. Hou , Y. Liu , H. Zha , and N. Yu , \" Detection based defense against adversarial examples from the steganalysis point of view ,\" in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2019 , pp. 4825 -- 4834 . J. Liu, W. Zhang, Y. Zhang, D. Hou, Y. Liu, H. Zha, and N. Yu, \"Detection based defense against adversarial examples from the steganalysis point of view,\" in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2019, pp. 4825--4834.","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"e_1_3_2_1_24_1","first-page":"3","volume-title":"ACM","author":"Carlini N.","year":"2017","unstructured":"N. Carlini and D. Wagner , \" Adversarial examples are not easily detected: Bypassing ten detection methods,\" in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security . ACM , 2017 pp. 3 -- 14 . N. Carlini and D. Wagner, \"Adversarial examples are not easily detected: Bypassing ten detection methods,\" in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. ACM, 2017 pp. 3--14."},{"key":"e_1_3_2_1_25_1","first-page":"174","volume-title":"IEEE","author":"Cai F.","year":"2020","unstructured":"F. Cai and X. Koutsoukos , \" Real-time out-of-distribution detection in learning-enabled cyber-physical systems,\" in 2020 ACM\/IEEE 11th International Conference on Cyber-Physical Systems (ICCPS) . IEEE , 2020 , pp. 174 -- 183 . F. Cai and X. Koutsoukos, \"Real-time out-of-distribution detection in learning-enabled cyber-physical systems,\" in 2020 ACM\/IEEE 11th International Conference on Cyber-Physical Systems (ICCPS). IEEE, 2020, pp. 174--183."},{"key":"e_1_3_2_1_26_1","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"Moosavi-Dezfooli S.-M.","year":"2016","unstructured":"S.-M. Moosavi-Dezfooli , A. Fawzi , and P. Frossard , \" Deepfool: a simple and accurate method to fool deep neural networks ,\" in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition , 2016 , pp. 2574 -- 2582 . S.-M. Moosavi-Dezfooli, A. Fawzi, and P. Frossard, \"Deepfool: a simple and accurate method to fool deep neural networks,\" in Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2016, pp. 2574--2582.","journal-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition"},{"key":"e_1_3_2_1_27_1","volume-title":"Adversarial machine learning at scale,\" arXiv preprint arXiv:1611.01236","author":"Kurakin A.","year":"2016","unstructured":"A. Kurakin , I. Goodfellow , and S. Bengio , \" Adversarial machine learning at scale,\" arXiv preprint arXiv:1611.01236 , 2016 . A. Kurakin, I. Goodfellow, and S. Bengio, \"Adversarial machine learning at scale,\" arXiv preprint arXiv:1611.01236, 2016."},{"key":"e_1_3_2_1_28_1","volume-title":"Distilling the knowledge in a neural network,\" arXiv preprint arXiv:1503.02531","author":"Hinton G.","year":"2015","unstructured":"G. Hinton , O. Vinyals , and J. Dean , \" Distilling the knowledge in a neural network,\" arXiv preprint arXiv:1503.02531 , 2015 . G. Hinton, O. Vinyals, and J. Dean, \"Distilling the knowledge in a neural network,\" arXiv preprint arXiv:1503.02531, 2015."},{"key":"e_1_3_2_1_29_1","first-page":"582","volume-title":"IEEE","author":"Papernot N.","year":"2016","unstructured":"N. Papernot , P. McDaniel , X. Wu , S. Jha , and A. Swami , \" Distillation as a defense to adversarial perturbations against deep neural networks,\" in 2016 IEEE Symposium on Security and Privacy (SP) . IEEE , 2016 , pp. 582 -- 597 . N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, \"Distillation as a defense to adversarial perturbations against deep neural networks,\" in 2016 IEEE Symposium on Security and Privacy (SP). IEEE, 2016, pp. 582--597."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"crossref","first-page":"311","DOI":"10.7551\/mitpress\/10761.003.0012","article-title":"11 adversarial perturbations of deep neural networks","author":"Warde-Farley D.","year":"2016","unstructured":"D. Warde-Farley and I. Goodfellow , \" 11 adversarial perturbations of deep neural networks ,\" Perturbations, Optimization, and Statistics , p. 311 , 2016 . D. Warde-Farley and I. Goodfellow, \"11 adversarial perturbations of deep neural networks,\" Perturbations, Optimization, and Statistics, p. 311, 2016.","journal-title":"Perturbations, Optimization, and Statistics"},{"key":"e_1_3_2_1_31_1","volume-title":"Adversarial examples: Attacks and defenses for deep learning,\" IEEE transactions on neural networks and learning systems","author":"Yuan X.","year":"2019","unstructured":"X. Yuan , P. He , Q. Zhu , and X. Li , \" Adversarial examples: Attacks and defenses for deep learning,\" IEEE transactions on neural networks and learning systems , 2019 . X. Yuan, P. He, Q. Zhu, and X. Li, \"Adversarial examples: Attacks and defenses for deep learning,\" IEEE transactions on neural networks and learning systems, 2019."},{"key":"e_1_3_2_1_32_1","volume-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples,\" arXiv preprint arXiv:1605.07277","author":"Papernot N.","year":"2016","unstructured":"N. Papernot , P. McDaniel , and I. Goodfellow , \" Transferability in machine learning: from phenomena to black-box attacks using adversarial samples,\" arXiv preprint arXiv:1605.07277 , 2016 . N. Papernot, P. McDaniel, and I. Goodfellow, \"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples,\" arXiv preprint arXiv:1605.07277, 2016."},{"key":"e_1_3_2_1_33_1","volume-title":"Adversarial spheres,\" arXiv preprint arXiv:1801.02774","author":"Gilmer J.","year":"2018","unstructured":"J. Gilmer , L. Metz , F. Faghri , S. S. Schoenholz , M. Raghu , M. Watenberg , and I. Goodfellow , \" Adversarial spheres,\" arXiv preprint arXiv:1801.02774 , 2018 . J. Gilmer, L. Metz, F. Faghri, S. S. Schoenholz, M. Raghu, M. Watenberg, and I. Goodfellow, \"Adversarial spheres,\" arXiv preprint arXiv:1801.02774, 2018."},{"key":"e_1_3_2_1_34_1","volume-title":"Magnet and\" efficient defenses against adversarial attacks\" are not robust to adversarial examples,\" arXiv preprint arXiv:1711.08478","author":"Carlini N.","year":"2017","unstructured":"N. Carlini and D. Wagner , \" Magnet and\" efficient defenses against adversarial attacks\" are not robust to adversarial examples,\" arXiv preprint arXiv:1711.08478 , 2017 . N. Carlini and D. Wagner, \"Magnet and\" efficient defenses against adversarial attacks\" are not robust to adversarial examples,\" arXiv preprint arXiv:1711.08478, 2017."},{"key":"e_1_3_2_1_35_1","first-page":"372","volume-title":"IEEE","author":"Papernot N.","year":"2016","unstructured":"N. Papernot , P. McDaniel , S. Jha , M. Fredrikson , Z. B. Celik , and A. Swami , \" The limitations of deep learning in adversarial settings,\" in 2016 IEEE European Symposium on Security and Privacy (EuroS&P) . IEEE , 2016 , pp. 372 -- 387 . N. Papernot, P. McDaniel, S. Jha, M. Fredrikson, Z. B. Celik, and A. Swami, \"The limitations of deep learning in adversarial settings,\" in 2016 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE, 2016, pp. 372--387."},{"key":"e_1_3_2_1_36_1","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He K.","year":"2016","unstructured":"K. He , X. Zhang , S. Ren , and J. Sun , \" Deep residual learning for image recognition ,\" in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016 , pp. 770 -- 778 . K. He, X. Zhang, S. Ren, and J. Sun, \"Deep residual learning for image recognition,\" in Proceedings of the IEEE conference on computer vision and pattern recognition, 2016, pp. 770--778.","journal-title":"Proceedings of the IEEE conference on computer vision and pattern recognition"},{"key":"e_1_3_2_1_37_1","volume-title":"Adversarial examples in the physical world,\" arXiv preprint arXiv:1607.02533","author":"Kurakin A.","year":"2016","unstructured":"A. Kurakin , I. Goodfellow , and S. Bengio , \" Adversarial examples in the physical world,\" arXiv preprint arXiv:1607.02533 , 2016 . A. Kurakin, I. Goodfellow, and S. Bengio, \"Adversarial examples in the physical world,\" arXiv preprint arXiv:1607.02533, 2016."},{"key":"e_1_3_2_1_38_1","first-page":"65","article-title":"A complexity analysis of the jpeg image compression algorithm,\" in 2017 9th Computer Science and Electronic Engineering (CEEC)","author":"Chiou P. T.","year":"2017","unstructured":"P. T. Chiou , Y. Sun , and G. Young , \" A complexity analysis of the jpeg image compression algorithm,\" in 2017 9th Computer Science and Electronic Engineering (CEEC) . IEEE , 2017 , pp. 65 -- 70 . P. T. Chiou, Y. Sun, and G. Young, \"A complexity analysis of the jpeg image compression algorithm,\" in 2017 9th Computer Science and Electronic Engineering (CEEC). IEEE, 2017, pp. 65--70.","journal-title":"IEEE"},{"key":"e_1_3_2_1_39_1","first-page":"779","article-title":"You only look once: Unified, real-time object detection","author":"Redmon J.","year":"2016","unstructured":"J. Redmon , S. Divvala , R. Girshick , and A. Farhadi , \" You only look once: Unified, real-time object detection ,\" in Proceedings of the IEEE conference on computer vision and pattern recognition , 2016 , pp. 779 -- 788 . J. Redmon, S. Divvala, R. Girshick, and A. Farhadi, \"You only look once: Unified, real-time object detection,\" in Proceedings of the IEEE conference on computer vision and pattern recognition, 2016, pp. 779--788.","journal-title":"Proceedings of the IEEE conference on computer vision and pattern recognition"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2983149"}],"event":{"name":"ICCPS '21: ACM\/IEEE 12th International Conference on Cyber-Physical Systems","location":"Nashville Tennessee","acronym":"ICCPS '21","sponsor":["SIGBED ACM Special Interest Group on Embedded Systems","IEEE-CS\\TCRT TC on Real-Time Systems"]},"container-title":["Proceedings of the ACM\/IEEE 12th International Conference on Cyber-Physical Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3450267.3450535","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3450267.3450535","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3450267.3450535","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:46:58Z","timestamp":1750193218000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3450267.3450535"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,19]]},"references-count":40,"alternative-id":["10.1145\/3450267.3450535","10.1145\/3450267"],"URL":"https:\/\/doi.org\/10.1145\/3450267.3450535","relation":{},"subject":[],"published":{"date-parts":[[2021,5,19]]},"assertion":[{"value":"2021-05-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}