{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,19]],"date-time":"2025-12-19T09:50:47Z","timestamp":1766137847726,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,10,20]],"date-time":"2021-10-20T00:00:00Z","timestamp":1634688000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,10,20]]},"DOI":"10.1145\/3475724.3483606","type":"proceedings-article","created":{"date-parts":[[2021,10,22]],"date-time":"2021-10-22T16:09:52Z","timestamp":1634918992000},"page":"35-41","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Detecting Adversarial Patch Attacks through Global-local Consistency"],"prefix":"10.1145","author":[{"given":"Bo","family":"Li","sequence":"first","affiliation":[{"name":"Tencent Youtu Lab, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianghe","family":"Xu","sequence":"additional","affiliation":[{"name":"Tencent Youtu Lab, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuang","family":"Wu","sequence":"additional","affiliation":[{"name":"Tencent Youtu Lab, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shouhong","family":"Ding","sequence":"additional","affiliation":[{"name":"Tencent Youtu Lab, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jilin","family":"Li","sequence":"additional","affiliation":[{"name":"Tencent Youtu Lab, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Feiyue","family":"Huang","sequence":"additional","affiliation":[{"name":"Tencent Youtu Lab, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,10,22]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Detecting Patch Adversarial Attacks with Image Residuals. CoRR","author":"Arvinte Marius","year":"2020","unstructured":"Marius Arvinte . 2020. Detecting Patch Adversarial Attacks with Image Residuals. CoRR ( 2020 ). Marius Arvinte. 2020. Detecting Patch Adversarial Attacks with Image Residuals. CoRR (2020)."},{"key":"e_1_3_2_1_2_1","unstructured":"Anish Athalye. 2018. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In ICML.  Anish Athalye. 2018. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In ICML."},{"key":"e_1_3_2_1_3_1","unstructured":"Anish Athalye. 2018. Synthesizing Robust Adversarial Examples. In ICML.  Anish Athalye. 2018. Synthesizing Robust Adversarial Examples. In ICML."},{"key":"e_1_3_2_1_4_1","unstructured":"Wieland Brendel. 2019. In ICLR.  Wieland Brendel. 2019. In ICLR."},{"key":"e_1_3_2_1_5_1","volume-title":"Brown and Justin Gilmer","author":"Tom","year":"2017","unstructured":"Tom B. Brown and Justin Gilmer . 2017 . Adversarial Patch. CoRR ( 2017). Tom B. Brown and Justin Gilmer. 2017. Adversarial Patch. CoRR (2017)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_2_1_7_1","unstructured":"Ping-Yeh Chiang and Renkun Ni. 2020. Certified Defenses for Adversarial Patches. In ICLR. OpenReview.net.  Ping-Yeh Chiang and Renkun Ni. 2020. Certified Defenses for Adversarial Patches. In ICLR. OpenReview.net."},{"volume-title":"SentiNet: Detecting Localized Universal Attack Against Deep Learning Systems. IEEE SPW 2020 ([n. d.]).","author":"Chou Edward","key":"e_1_3_2_1_8_1","unstructured":"Edward Chou , Florian Tramer , and Giancarlo Pellegrino . [n.d.]. SentiNet: Detecting Localized Universal Attack Against Deep Learning Systems. IEEE SPW 2020 ([n. d.]). Edward Chou, Florian Tramer, and Giancarlo Pellegrino. [n.d.]. SentiNet: Detecting Localized Universal Attack Against Deep Learning Systems. IEEE SPW 2020 ([n. d.])."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1022627411411"},{"key":"e_1_3_2_1_10_1","unstructured":"fast.ai. 2020. ImageNette: A smaller subset of 10 easily classified classes from imagenet. (2020).  fast.ai. 2020. ImageNette: A smaller subset of 10 easily classified classes from imagenet. (2020)."},{"key":"e_1_3_2_1_11_1","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In ICLR.  Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In ICLR."},{"key":"e_1_3_2_1_12_1","unstructured":"Kaiming He. 2016. Deep Residual Learning for Image Recognition. In CVPR.  Kaiming He. 2016. Deep Residual Learning for Image Recognition. In CVPR."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.5555\/3154768.3154783"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Gao Huang. 2017. Densely Connected Convolutional Networks. In CVPR.  Gao Huang. 2017. Densely Connected Convolutional Networks. In CVPR.","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_1_15_1","unstructured":"Danny Karmon. 2018. LaVAN: Localized and Visible Adversarial Noise. In ICML.  Danny Karmon. 2018. LaVAN: Localized and Visible Adversarial Noise. In ICML."},{"key":"e_1_3_2_1_16_1","unstructured":"Krizhevsky et al. 2009. Learning multiple layers of features from tiny images. (2009).  Krizhevsky et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/2999134.2999257"},{"volume-title":"Certified Robustness to Adversarial Examples with Differential Privacy","author":"L\u00e9cuyer Mathias","key":"e_1_3_2_1_18_1","unstructured":"Mathias L\u00e9cuyer and Vaggelis Atlidakis . 2019. Certified Robustness to Adversarial Examples with Differential Privacy . In IEEE SSP. Mathias L\u00e9cuyer and Vaggelis Atlidakis. 2019. Certified Robustness to Adversarial Examples with Differential Privacy. In IEEE SSP."},{"key":"e_1_3_2_1_19_1","volume-title":"On Physical Adversarial Patches for Object Detection. CoRR","author":"Lee Mark","year":"2019","unstructured":"Mark Lee . 2019. On Physical Adversarial Patches for Object Detection. CoRR ( 2019 ). Mark Lee. 2019. On Physical Adversarial Patches for Object Detection. CoRR (2019)."},{"key":"e_1_3_2_1_20_1","unstructured":"Alexander Levine and Soheil Feizi. 2020. (De)Randomized Smoothing for Certifiable Defense against Patch Attacks. CoRR (2020).  Alexander Levine and Soheil Feizi. 2020. (De)Randomized Smoothing for Certifiable Defense against Patch Attacks. CoRR (2020)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Xin Li and Fuxin Li. 2017. Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics. In ICCV.  Xin Li and Fuxin Li. 2017. Adversarial Examples Detection in Deep Networks with Convolutional Filter Statistics. In ICCV.","DOI":"10.1109\/ICCV.2017.615"},{"key":"e_1_3_2_1_22_1","unstructured":"Aishan Liu. 2019. Perceptual-Sensitive GAN for Generating Adversarial Patches. In AAAI.  Aishan Liu. 2019. Perceptual-Sensitive GAN for Generating Adversarial Patches. In AAAI."},{"key":"e_1_3_2_1_23_1","unstructured":"Aishan Liu Jiakai Wang Xianglong Liu Bowen Cao Chongzhi Zhang and Hang Yu. [n.d.]. Bias-based Universal Adversarial Patch Attack for Automatic Check-out. ([n. d.]).  Aishan Liu Jiakai Wang Xianglong Liu Bowen Cao Chongzhi Zhang and Hang Yu. [n.d.]. Bias-based Universal Adversarial Patch Attack for Automatic Check-out. ([n. d.])."},{"key":"e_1_3_2_1_24_1","volume-title":"DPATCH: An Adversarial Patch Attack on Object Detectors. In SafeAI@AAAI.","author":"Liu Xin","year":"2019","unstructured":"Xin Liu and Huanrui Yang . 2019 . DPATCH: An Adversarial Patch Attack on Object Detectors. In SafeAI@AAAI. Xin Liu and Huanrui Yang. 2019. DPATCH: An Adversarial Patch Attack on Object Detectors. In SafeAI@AAAI."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"e_1_3_2_1_26_1","unstructured":"Jan Hendrik Metzen Tim Genewein Volker Fischer and Bastian Bischoff. 2017. On Detecting Adversarial Perturbations. In ICLR.  Jan Hendrik Metzen Tim Genewein Volker Fischer and Bastian Bischoff. 2017. On Detecting Adversarial Perturbations. In ICLR."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"Aaditya Prakash and Nick Moran. 2018. Deflecting Adversarial Attacks With Pixel Deflection. In CVPR.  Aaditya Prakash and Nick Moran. 2018. Deflecting Adversarial Attacks With Pixel Deflection. In CVPR.","DOI":"10.1109\/CVPR.2018.00894"},{"volume-title":"Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization. IJCV","year":"2020","key":"e_1_3_2_1_28_1","unstructured":"Ramprasaath. 2020. Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization. IJCV ( 2020 ). Ramprasaath. 2020. Grad-CAM: Visual Explanations from Deep Networks via Gradient-Based Localization. IJCV (2020)."},{"key":"e_1_3_2_1_29_1","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In ICLR.  Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In ICLR."},{"key":"e_1_3_2_1_30_1","volume-title":"One Pixel Attack for Fooling Deep Neural Networks","author":"Jiawei Su.","year":"2019","unstructured":"Jiawei Su. 2019. One Pixel Attack for Fooling Deep Neural Networks . IEEE Trans. Evol. Comput . ( 2019 ). Jiawei Su. 2019. One Pixel Attack for Fooling Deep Neural Networks. IEEE Trans. Evol. Comput. (2019)."},{"key":"e_1_3_2_1_31_1","unstructured":"Christian Szegedy. 2014. Intriguing properties of neural networks. In ICLR.  Christian Szegedy. 2014. Intriguing properties of neural networks. In ICLR."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"e_1_3_2_1_33_1","volume-title":"On Adaptive Attacks to Adversarial Example Defenses. CoRR","author":"Tram\u00e8r Florian","year":"2020","unstructured":"Florian Tram\u00e8r , Nicholas Carlini , Wieland Brendel , and Aleksander Madry . 2020. On Adaptive Attacks to Adversarial Example Defenses. CoRR ( 2020 ). Florian Tram\u00e8r, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On Adaptive Attacks to Adversarial Example Defenses. CoRR (2020)."},{"key":"e_1_3_2_1_34_1","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020","author":"Tram\u00e8r Florian","year":"2020","unstructured":"Florian Tram\u00e8r , Nicholas Carlini , Wieland Brendel , and Aleksander Madry . 2020 . On Adaptive Attacks to Adversarial Example Defenses . In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020 , NeurIPS 2020, December 6--12, 2020, virtual, Hugo Larochelle, Marc'Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.). https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/ 11f38f8ecd71867b42433548d1078e38-Abstract.html Florian Tram\u00e8r, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On Adaptive Attacks to Adversarial Example Defenses. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6--12, 2020, virtual, Hugo Larochelle, Marc'Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.). https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/ 11f38f8ecd71867b42433548d1078e38-Abstract.html"},{"key":"e_1_3_2_1_35_1","volume-title":"Threat of Adversarial Attacks on Face Recognition: A Comprehensive Survey. CoRR","author":"Vakhshiteh Fatemeh","year":"2020","unstructured":"Fatemeh Vakhshiteh . 2020. Threat of Adversarial Attacks on Face Recognition: A Comprehensive Survey. CoRR ( 2020 ). Fatemeh Vakhshiteh. 2020. Threat of Adversarial Attacks on Face Recognition: A Comprehensive Survey. CoRR (2020)."},{"key":"e_1_3_2_1_36_1","unstructured":"TongWu and Liang Tong. 2020. Defending Against Physically Realizable Attacks on Image Classification. In ICLR. OpenReview.net.  TongWu and Liang Tong. 2020. Defending Against Physically Realizable Attacks on Image Classification. In ICLR. OpenReview.net."},{"key":"e_1_3_2_1_37_1","unstructured":"Zuxuan Wu and Ser-Nam Lim. 2020. Making an Invisibility Cloak: Real World Adversarial Attacks on Object Detectors. In ECCV (4).  Zuxuan Wu and Ser-Nam Lim. 2020. Making an Invisibility Cloak: Real World Adversarial Attacks on Object Detectors. In ECCV (4)."},{"key":"e_1_3_2_1_38_1","volume-title":"PatchGuard: Provable Defense against Adversarial Patches Using Masks on Small Receptive Fields. CoRR","author":"Xiang Chong","year":"2020","unstructured":"Chong Xiang . 2020. PatchGuard: Provable Defense against Adversarial Patches Using Masks on Small Receptive Fields. CoRR ( 2020 ). Chong Xiang. 2020. PatchGuard: Provable Defense against Adversarial Patches Using Masks on Small Receptive Fields. CoRR (2020)."},{"key":"e_1_3_2_1_39_1","unstructured":"Kaidi Xu and Gaoyuan Zhang. 2020. Adversarial T-Shirt! Evading Person Detectors in a Physical World. In ECCV (5).  Kaidi Xu and Gaoyuan Zhang. 2020. Adversarial T-Shirt! Evading Person Detectors in a Physical World. In ECCV (5)."},{"key":"e_1_3_2_1_40_1","unstructured":"Zirui Xu Fuxun Yu and Xiang Chen. 2020. LanCe: A Comprehensive and Lightweight CNN Defense Methodology against Physical Adversarial Attacks on Embedded Multimedia Applications. In ASP-DAC.  Zirui Xu Fuxun Yu and Xiang Chen. 2020. LanCe: A Comprehensive and Lightweight CNN Defense Methodology against Physical Adversarial Attacks on Embedded Multimedia Applications. In ASP-DAC."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.5555\/2381019"}],"event":{"name":"MM '21: ACM Multimedia Conference","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Virtual Event China","acronym":"MM '21"},"container-title":["Proceedings of the 1st International Workshop on Adversarial Learning for Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3475724.3483606","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3475724.3483606","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:18Z","timestamp":1750193298000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3475724.3483606"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,10,20]]},"references-count":41,"alternative-id":["10.1145\/3475724.3483606","10.1145\/3475724"],"URL":"https:\/\/doi.org\/10.1145\/3475724.3483606","relation":{},"subject":[],"published":{"date-parts":[[2021,10,20]]},"assertion":[{"value":"2021-10-22","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}