{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T00:07:08Z","timestamp":1784851628577,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":62,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,10,17]],"date-time":"2021-10-17T00:00:00Z","timestamp":1634428800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100004663","name":"Ministry of Science and Technology, Taiwan","doi-asserted-by":"publisher","award":["110-2221-E-007 -095 -MY3"],"award-info":[{"award-number":["110-2221-E-007 -095 -MY3"]}],"id":[{"id":"10.13039\/501100004663","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,10,17]]},"DOI":"10.1145\/3474085.3475338","type":"proceedings-article","created":{"date-parts":[[2021,10,18]],"date-time":"2021-10-18T06:09:05Z","timestamp":1634537345000},"page":"1856-1865","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":32,"title":["Adversarial Pixel Masking"],"prefix":"10.1145","author":[{"given":"Ping-Han","family":"Chiang","sequence":"first","affiliation":[{"name":"National Tsing Hua University, Hsinchu, Taiwan Roc"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chi-Shen","family":"Chan","sequence":"additional","affiliation":[{"name":"National Tsing Hua University, Hsinchu, Taiwan Roc"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shan-Hung","family":"Wu","sequence":"additional","affiliation":[{"name":"National Tsing Hua University, Hsinchu, Taiwan Roc"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,10,17]]},"reference":[{"key":"e_1_3_2_2_1_1","first-page":"274","volume-title":"International Conference on Machine Learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Nicholas Carlini , and David Wagner . Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples . In International Conference on Machine Learning , pages 274 -- 283 . PMLR, 2018 . Anish Athalye, Nicholas Carlini, and David Wagner. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International Conference on Machine Learning, pages 274--283. PMLR, 2018."},{"key":"e_1_3_2_2_2_1","first-page":"284","volume-title":"International conference on machine learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Logan Engstrom , Andrew Ilyas , and Kevin Kwok . Synthesizing robust adversarial examples . In International conference on machine learning , pages 284 -- 293 . PMLR, 2018 . Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. Synthesizing robust adversarial examples. In International conference on machine learning, pages 284--293. PMLR, 2018."},{"key":"e_1_3_2_2_3_1","volume-title":"Yolov4: Op-timal speed and accuracy of object detection. arXiv preprint arXiv:2004.10934","author":"Bochkovskiy Alexey","year":"2020","unstructured":"Alexey Bochkovskiy , Chien-Yao Wang , and Hong-Yuan Mark Liao . Yolov4: Op-timal speed and accuracy of object detection. arXiv preprint arXiv:2004.10934 , 2020 . Alexey Bochkovskiy, Chien-Yao Wang, and Hong-Yuan Mark Liao. Yolov4: Op-timal speed and accuracy of object detection. arXiv preprint arXiv:2004.10934, 2020."},{"key":"e_1_3_2_2_4_1","volume-title":"Approximating cnns with bag-of-local-features models works surprisingly well on imagenet. arXiv preprint arXiv:1904.00760","author":"Brendel Wieland","year":"2019","unstructured":"Wieland Brendel and Matthias Bethge . Approximating cnns with bag-of-local-features models works surprisingly well on imagenet. arXiv preprint arXiv:1904.00760 , 2019 . Wieland Brendel and Matthias Bethge. Approximating cnns with bag-of-local-features models works surprisingly well on imagenet. arXiv preprint arXiv:1904.00760, 2019."},{"key":"e_1_3_2_2_5_1","volume-title":"Adversarial patch. arXiv preprint arXiv:1712.09665","author":"Brown Tom B","year":"2017","unstructured":"Tom B Brown , Dandelion Man\u00e9 , Aurko Roy , Mart\u00edn Abadi , and Justin Gilmer . Adversarial patch. arXiv preprint arXiv:1712.09665 , 2017 . Tom B Brown, Dandelion Man\u00e9, Aurko Roy, Mart\u00edn Abadi, and Justin Gilmer. Adversarial patch. arXiv preprint arXiv:1712.09665, 2017."},{"key":"e_1_3_2_2_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_8_1","first-page":"52","volume-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","author":"Chen Shang-Tse","year":"2018","unstructured":"Shang-Tse Chen , Cory Cornelius , Jason Martin , and Duen Horng Polo Chau . Shapeshifter : Robust physical adversarial attack on faster r-cnn object detector . In Joint European Conference on Machine Learning and Knowledge Discovery in Databases , pages 52 -- 68 . Springer , 2018 . Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng Polo Chau. Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector. In Joint European Conference on Machine Learning and Knowledge Discovery in Databases, pages 52--68. Springer, 2018."},{"key":"e_1_3_2_2_9_1","unstructured":"Ping-Han Chiang Chi-Shen Chan and Shan-Hung Wu. Adversarial pixel mask-ing: Supplementary materials. http:\/\/www.cs.nthu.edu.tw\/~shwu\/pubs\/shwu-mm-21-sup.pdf.  Ping-Han Chiang Chi-Shen Chan and Shan-Hung Wu. Adversarial pixel mask-ing: Supplementary materials. http:\/\/www.cs.nthu.edu.tw\/~shwu\/pubs\/shwu-mm-21-sup.pdf."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2005.177"},{"key":"e_1_3_2_2_12_1","first-page":"6569","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","author":"Duan Kaiwen","year":"2019","unstructured":"Kaiwen Duan , Song Bai , Lingxi Xie , Honggang Qi , Qingming Huang , and Qi Tian. Center net : Keypoint triplets for object detection . In Proceedings of the IEEE\/CVF International Conference on Computer Vision , pages 6569 -- 6578 , 2019 . Kaiwen Duan, Song Bai, Lingxi Xie, Honggang Qi, Qingming Huang, and Qi Tian. Centernet: Keypoint triplets for object detection. In Proceedings of the IEEE\/CVF International Conference on Computer Vision, pages 6569--6578, 2019."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_2_2_14_1","volume-title":"Explaining and har-nessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . Explaining and har-nessing adversarial examples. arXiv preprint arXiv:1412.6572 , 2014 . Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. Explaining and har-nessing adversarial examples. arXiv preprint arXiv:1412.6572, 2014."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.5555\/3294771.3294987"},{"key":"e_1_3_2_2_17_1","first-page":"2137","volume-title":"International Conference on Machine Learning","author":"Ilyas Andrew","year":"2018","unstructured":"Andrew Ilyas , Logan Engstrom , Anish Athalye , and Jessy Lin . Black-box adver-sarial attacks with limited queries and information . In International Conference on Machine Learning , pages 2137 -- 2146 . PMLR, 2018 . Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. Black-box adver-sarial attacks with limited queries and information. In International Conference on Machine Learning, pages 2137--2146. PMLR, 2018."},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_32"},{"key":"e_1_3_2_2_19_1","volume-title":"Adversarial logit pairing. arXiv preprint arXiv:1803.06373","author":"Kannan Harini","year":"2018","unstructured":"Harini Kannan , Alexey Kurakin , and Ian Goodfellow . Adversarial logit pairing. arXiv preprint arXiv:1803.06373 , 2018 . Harini Kannan, Alexey Kurakin, and Ian Goodfellow. Adversarial logit pairing. arXiv preprint arXiv:1803.06373, 2018."},{"key":"e_1_3_2_2_20_1","first-page":"2507","volume-title":"International Conference on Machine Learning","author":"Karmon Danny","year":"2018","unstructured":"Danny Karmon , Daniel Zoran , and Yoav Goldberg . Lavan : Localized and visible adversarial noise . In International Conference on Machine Learning , pages 2507 -- 2515 . PMLR, 2018 . Danny Karmon, Daniel Zoran, and Yoav Goldberg. Lavan: Localized and visible adversarial noise. In International Conference on Machine Learning, pages 2507--2515. PMLR, 2018."},{"key":"e_1_3_2_2_21_1","volume-title":"Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 , 2016 . Alexey Kurakin, Ian Goodfellow, and Samy Bengio. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236, 2016."},{"key":"e_1_3_2_2_22_1","volume-title":"On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897","author":"Lee Mark","year":"2019","unstructured":"Mark Lee and Zico Kolter . On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897 , 2019 . Mark Lee and Zico Kolter. On physical adversarial patches for object detection. arXiv preprint arXiv:1906.11897, 2019."},{"key":"e_1_3_2_2_23_1","first-page":"3896","volume-title":"International Conference on Machine Learning","author":"Li Juncheng","year":"2019","unstructured":"Juncheng Li , Frank Schmidt , and Zico Kolter . Adversarial camera stickers: A phys-ical camera-based attack on deep learning systems . In International Conference on Machine Learning , pages 3896 -- 3904 . PMLR, 2019 . Juncheng Li, Frank Schmidt, and Zico Kolter. Adversarial camera stickers: A phys-ical camera-based attack on deep learning systems. In International Conference on Machine Learning, pages 3896--3904. PMLR, 2019."},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.324"},{"key":"e_1_3_2_2_25_1","first-page":"740","volume-title":"European conference on computer vision","author":"Lin Tsung-Yi","year":"2014","unstructured":"Tsung-Yi Lin , Michael Maire , Serge Belongie , James Hays , Pietro Perona , Deva Ramanan , Piotr Doll\u00e1r , and C Lawrence Zitnick . Microsoft coco : Common objects in context . In European conference on computer vision , pages 740 -- 755 . Springer , 2014 . Tsung-Yi Lin, Michael Maire, Serge Belongie, James Hays, Pietro Perona, Deva Ramanan, Piotr Doll\u00e1r, and C Lawrence Zitnick. Microsoft coco: Common objects in context. In European conference on computer vision, pages 740--755. Springer, 2014."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46448-0_2"},{"key":"e_1_3_2_2_27_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 , 2017 . Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083, 2017."},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-61638-0_31"},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"e_1_3_2_2_30_1","volume-title":"Bag of tricks for adversarial training. arXiv preprint arXiv:2010.00467","author":"Pang Tianyu","year":"2020","unstructured":"Tianyu Pang , Xiao Yang , Yinpeng Dong , Hang Su , and Jun Zhu . Bag of tricks for adversarial training. arXiv preprint arXiv:2010.00467 , 2020 . Tianyu Pang, Xiao Yang, Yinpeng Dong, Hang Su, and Jun Zhu. Bag of tricks for adversarial training. arXiv preprint arXiv:2010.00467, 2020."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_2_32_1","volume-title":"Adversarial training against location-optimized adversarial patches. arXiv preprint arXiv:2005.02313","author":"Rao Sukrut","year":"2020","unstructured":"Sukrut Rao , David Stutz , and Bernt Schiele . Adversarial training against location-optimized adversarial patches. arXiv preprint arXiv:2005.02313 , 2020 . Sukrut Rao, David Stutz, and Bernt Schiele. Adversarial training against location-optimized adversarial patches. arXiv preprint arXiv:2005.02313, 2020."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"e_1_3_2_2_34_1","volume-title":"Yolov3: An incremental improvement. arXiv preprint arXiv:1804.02767","author":"Redmon Joseph","year":"2018","unstructured":"Joseph Redmon and Ali Farhadi . Yolov3: An incremental improvement. arXiv preprint arXiv:1804.02767 , 2018 . Joseph Redmon and Ali Farhadi. Yolov3: An incremental improvement. arXiv preprint arXiv:1804.02767, 2018."},{"key":"e_1_3_2_2_35_1","volume-title":"Faster r-cnn: To-wards real-time object detection with region proposal networks. arXiv preprint arXiv:1506.01497","author":"Ren Shaoqing","year":"2015","unstructured":"Shaoqing Ren , Kaiming He , Ross Girshick , and Jian Sun . Faster r-cnn: To-wards real-time object detection with region proposal networks. arXiv preprint arXiv:1506.01497 , 2015 . Shaoqing Ren, Kaiming He, Ross Girshick, and Jian Sun. Faster r-cnn: To-wards real-time object detection with region proposal networks. arXiv preprint arXiv:1506.01497, 2015."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00400"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.5555\/3454287.3454589"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.5555\/3307423.3307424"},{"key":"e_1_3_2_2_41_1","volume-title":"Striving for simplicity: The all convolutional net. arXiv preprint arXiv:1412.6806","author":"Springenberg Jost Tobias","year":"2014","unstructured":"Jost Tobias Springenberg , Alexey Dosovitskiy , Thomas Brox , and Martin Ried-miller. Striving for simplicity: The all convolutional net. arXiv preprint arXiv:1412.6806 , 2014 . Jost Tobias Springenberg, Alexey Dosovitskiy, Thomas Brox, and Martin Ried-miller. Striving for simplicity: The all convolutional net. arXiv preprint arXiv:1412.6806, 2014."},{"key":"e_1_3_2_2_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"e_1_3_2_2_43_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 , 2013 . Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199, 2013."},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01079"},{"key":"e_1_3_2_2_45_1","first-page":"0","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops","author":"Thys Simen","year":"2019","unstructured":"Simen Thys , Wiebe Van Ranst , and Toon Goedem\u00e9 . Fooling automated surveil-lance cameras: adversarial patches to attack person detection . In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops , pages 0 -- 0 , 2019 . Simen Thys, Wiebe Van Ranst, and Toon Goedem\u00e9. Fooling automated surveil-lance cameras: adversarial patches to attack person detection. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, pages 0--0, 2019."},{"key":"e_1_3_2_2_46_1","volume-title":"Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204","author":"Tram\u00e8r Florian","year":"2017","unstructured":"Florian Tram\u00e8r , Alexey Kurakin , Nicolas Papernot , Ian Goodfellow , Dan Boneh , and Patrick McDaniel . Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 , 2017 . Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204, 2017."},{"key":"e_1_3_2_2_47_1","volume-title":"Defending against physically realizable attacks on image classification. arXiv preprint arXiv:1909.09552","author":"Wu Tong","year":"2019","unstructured":"Tong Wu , Liang Tong , and Yevgeniy Vorobeychik . Defending against physically realizable attacks on image classification. arXiv preprint arXiv:1909.09552 , 2019 . Tong Wu, Liang Tong, and Yevgeniy Vorobeychik. Defending against physically realizable attacks on image classification. arXiv preprint arXiv:1909.09552, 2019."},{"key":"e_1_3_2_2_48_1","first-page":"1","volume-title":"European Conference on Computer Vision","author":"Wu Zuxuan","year":"2020","unstructured":"Zuxuan Wu , Ser-Nam Lim , Larry S Davis , and Tom Goldstein . Making an in-visibility cloak: Real world adversarial attacks on object detectors . In European Conference on Computer Vision , pages 1 -- 17 . Springer , 2020 . Zuxuan Wu, Ser-Nam Lim, Larry S Davis, and Tom Goldstein. Making an in-visibility cloak: Real world adversarial attacks on object detectors. In European Conference on Computer Vision, pages 1--17. Springer, 2020."},{"key":"e_1_3_2_2_49_1","volume-title":"Vikash Sehwag, and Prateek Mittal. Patch-guard: Provable defense against adversarial patches using masks on small recep-tive fields. arXiv preprint arXiv:2005.10884","author":"Xiang Chong","year":"2020","unstructured":"Chong Xiang , Arjun Nitin Bhagoji , Vikash Sehwag, and Prateek Mittal. Patch-guard: Provable defense against adversarial patches using masks on small recep-tive fields. arXiv preprint arXiv:2005.10884 , 2020 . Chong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, and Prateek Mittal. Patch-guard: Provable defense against adversarial patches using masks on small recep-tive fields. arXiv preprint arXiv:2005.10884, 2020."},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00090"},{"key":"e_1_3_2_2_51_1","first-page":"501","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Xie Cihang","year":"2019","unstructured":"Cihang Xie , Yuxin Wu , Laurens van der Maaten, Alan L Yuille, and Kaiming He. Feature denoising for improving adversarial robustness . In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition , pages 501 -- 509 , 2019 . Cihang Xie, Yuxin Wu, Laurens van der Maaten, Alan L Yuille, and Kaiming He. Feature denoising for improving adversarial robustness. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pages 501--509, 2019."},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"e_1_3_2_2_53_1","volume-title":"Evading real-time person detectors by adversarial t-shirt. arXiv preprint arXiv:1910.11099, 3","author":"Xu Kaidi","year":"2019","unstructured":"Kaidi Xu , Gaoyuan Zhang , Sijia Liu , Quanfu Fan , Mengshu Sun , Hongge Chen , Pin-Yu Chen , Yanzhi Wang , and Xue Lin . Evading real-time person detectors by adversarial t-shirt. arXiv preprint arXiv:1910.11099, 3 , 2019 . Kaidi Xu, Gaoyuan Zhang, Sijia Liu, Quanfu Fan, Mengshu Sun, Hongge Chen, Pin-Yu Chen, Yanzhi Wang, and Xue Lin. Evading real-time person detectors by adversarial t-shirt. arXiv preprint arXiv:1910.11099, 3, 2019."},{"key":"e_1_3_2_2_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASP-DAC47756.2020.9045584"},{"key":"e_1_3_2_2_55_1","first-page":"368","volume-title":"Electronics & Mobile Communication Conference (UEMCON)","author":"Yang Darren Yu","year":"2018","unstructured":"Darren Yu Yang , Jay Xiong , Xincheng Li , Xu Yan , John Raiti , Yuntao Wang , HuaQiang Wu , and Zhenyu Zhong . Building towards\" invisible cloak\" : Robust physical adversarial attack on yolo object detector. In 2018 9th IEEE Annual Ubiq-uitous Computing , Electronics & Mobile Communication Conference (UEMCON) , pages 368 -- 374 . IEEE, 2018 . Darren Yu Yang, Jay Xiong, Xincheng Li, Xu Yan, John Raiti, Yuntao Wang, HuaQiang Wu, and Zhenyu Zhong. Building towards\" invisible cloak\": Robust physical adversarial attack on yolo object detector. In 2018 9th IEEE Annual Ubiq-uitous Computing, Electronics & Mobile Communication Conference (UEMCON), pages 368--374. IEEE, 2018."},{"key":"e_1_3_2_2_56_1","volume-title":"Adversarial examples: Attacks and defenses for deep learning","author":"Yuan Xiaoyong","year":"2019","unstructured":"Xiaoyong Yuan , Pan He , Qile Zhu , and Xiaolin Li . Adversarial examples: Attacks and defenses for deep learning . IEEE transactions on neural networks and learning systems, 30(9):2805--2824, 2019 . Xiaoyong Yuan, Pan He, Qile Zhu, and Xiaolin Li. Adversarial examples: Attacks and defenses for deep learning. IEEE transactions on neural networks and learning systems, 30(9):2805--2824, 2019."},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00051"},{"key":"e_1_3_2_2_58_1","volume-title":"International Conference on Learning Representations","author":"Zhang Yang","year":"2018","unstructured":"Yang Zhang , Hassan Foroosh , Philip David , and Boqing Gong . Camou : Learning physical vehicle camouflages to adversarially attack detectors in the wild . In International Conference on Learning Representations , 2018 . Yang Zhang, Hassan Foroosh, Philip David, and Boqing Gong. Camou: Learning physical vehicle camouflages to adversarially attack detectors in the wild. In International Conference on Learning Representations, 2018."},{"key":"e_1_3_2_2_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00026"},{"key":"e_1_3_2_2_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354259"},{"key":"e_1_3_2_2_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"e_1_3_2_2_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMEW46912.2020.9105983"}],"event":{"name":"MM '21: ACM Multimedia Conference","location":"Virtual Event China","acronym":"MM '21","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 29th ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3474085.3475338","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3474085.3475338","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:49:18Z","timestamp":1750193358000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3474085.3475338"}},"subtitle":["A Defense against Physical Attacks for Pre-trained Object Detectors"],"short-title":[],"issued":{"date-parts":[[2021,10,17]]},"references-count":62,"alternative-id":["10.1145\/3474085.3475338","10.1145\/3474085"],"URL":"https:\/\/doi.org\/10.1145\/3474085.3475338","relation":{},"subject":[],"published":{"date-parts":[[2021,10,17]]},"assertion":[{"value":"2021-10-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}