{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T05:55:52Z","timestamp":1780466152029,"version":"3.54.1"},"reference-count":40,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,3,23]],"date-time":"2023-03-23T00:00:00Z","timestamp":1679529600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2023,4]]},"abstract":"<jats:p>Enabling object detectors to better distinguish between real and fake objects in semi-autonomous and fully autonomous vehicles.<\/jats:p>","DOI":"10.1145\/3552308","type":"journal-article","created":{"date-parts":[[2023,3,23]],"date-time":"2023-03-23T14:41:50Z","timestamp":1679582510000},"page":"56-69","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Protecting Autonomous Cars from Phantom Attacks"],"prefix":"10.1145","volume":"66","author":[{"given":"Ben","family":"Nassi","sequence":"first","affiliation":[{"name":"Ben-Gurion University of the Negev, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yisroel","family":"Mirsky","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jacob","family":"Shams","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raz","family":"Ben-Netanel","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dudi","family":"Nassi","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[{"name":"Ben-Gurion University of the Negev, Beersheba, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,3,23]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Anker. 2019. Nebula Capsule; https:\/\/amzn.to\/3XWDrgY."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2018.08.009"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/83.650851"},{"key":"e_1_2_1_4_1","unstructured":"Brown T.B. et al. Adversarial patch (2017); arXiv preprint arXiv:1712.09665."},{"key":"e_1_2_1_5_1","volume-title":"2017 IEEE Symp. on Security and Privacy, 39--57","author":"Carlini N.","unstructured":"Carlini, N. and Wagner, D. Towards evaluating the robustness of neural networks. In 2017 IEEE Symp. on Security and Privacy, 39--57."},{"key":"e_1_2_1_6_1","doi-asserted-by":"crossref","unstructured":"Chen P-Y. et al. EAD: Elastic-net attacks to deep neural networks via adversarial examples (2017); arXiv preprint arXiv:1709.04114.","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"e_1_2_1_7_1","volume-title":"Joint European Conf. on Machine Learning and Knowledge Discovery in Databases","author":"Chen S-T.","year":"2018","unstructured":"Chen, S-T., Cornelius, C., Martin, J., and Chau, D.H.P. Shapeshifter: Robust physical adversarial attack on Faster R-CNN object detector. In Joint European Conf. on Machine Learning and Knowledge Discovery in Databases, Springer (2018), 52--68."},{"key":"e_1_2_1_8_1","volume-title":"Advances in Neural Information Processing Systems","author":"Dai J.","year":"2016","unstructured":"Dai, J., He, K., Li, Y., and Sun, J. R-FCN: Object detection via region-based fully convolutional networks. In Advances in Neural Information Processing Systems (2016), 379--387."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/41.649946"},{"key":"e_1_2_1_10_1","volume-title":"2018 IEEE\/CVF Conf. on Computer Vision and Pattern Recognition, 1625--1634; http:\/\/bit.ly\/3WC075l.","author":"Eykholt K.","unstructured":"Eykholt, K. et al. Robust physical-world attacks on deep learning visual classification. In 2018 IEEE\/CVF Conf. on Computer Vision and Pattern Recognition, 1625--1634; http:\/\/bit.ly\/3WC075l."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45103-X_50"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.3390\/s20154220"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2019.07.007"},{"key":"e_1_2_1_14_1","unstructured":"Goodfellow I.J. Shlens J. and Szegedy C. Explaining and harnessing adversarial examples. (2014); arXiv preprint arXiv:1412.6572."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"},{"key":"e_1_2_1_16_1","unstructured":"Howard A.G. et al. Mobilenets: Efficient convolutional neural networks for mobile vision applications (2017); arXiv preprint arXiv:1704.04861."},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the IEEE Conf. on Computer Vision and Pattern Recognition","author":"Huang J.","year":"2017","unstructured":"Huang, J. et al. Speed\/accuracy trade-offs for modern convolutional object detectors. In Proceedings of the IEEE Conf. on Computer Vision and Pattern Recognition (2017), 7310--7311."},{"key":"e_1_2_1_18_1","volume-title":"Handbook of Neural Network Signal Processing","author":"Hwang J-N","year":"2001","unstructured":"Hwang, J-N. and Hu, Y-H. Handbook of Neural Network Signal Processing, CRC Press (2001)."},{"key":"e_1_2_1_19_1","unstructured":"Ioffe S. and Szegedy C. Batch normalization: Accelerating deep network training by reducing internal covariate shift (2015); arXiv preprint arXiv:1502.03167."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134635"},{"key":"e_1_2_1_21_1","unstructured":"Kurakin A. Goodfellow I. and Bengio S. Adversarial examples in the physical world. (2016); arXiv preprint arXiv:1607.02533."},{"key":"e_1_2_1_22_1","volume-title":"Men hack electronic billboard, play porn on it. Ars Technica (October 1","author":"Lee T.B.","year":"2019","unstructured":"Lee, T.B. Men hack electronic billboard, play porn on it. Ars Technica (October 1, 2019); http:\/\/bit.ly\/3wvLoy4."},{"key":"e_1_2_1_23_1","volume-title":"Evaluating the energy efficiency of deep convolutional neural networks on CPUs and GPUs. In 2016 IEEE Intern. Confs. on Big Data and Cloud Computing","author":"Li D.","unstructured":"Li, D., et al. Evaluating the energy efficiency of deep convolutional neural networks on CPUs and GPUs. In 2016 IEEE Intern. Confs. on Big Data and Cloud Computing; Social Computing and Networking; Sustainable Computing; and Communications. 477--484."},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the IEEE\/CVF Conf. on Computer Vision and Pattern Recognition","author":"Liu W.","year":"2019","unstructured":"Liu, W. et al. High-level semantic feature detection: A new perspective for pedestrian detection. In Proceedings of the IEEE\/CVF Conf. on Computer Vision and Pattern Recognition (2019), 5187--5196."},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_2_1_27_1","volume-title":"Fooling a real car with adversarial traffic signs (2019)","author":"Morgulis N.","year":"1907","unstructured":"Morgulis, N., Kreines, A., Mendelowitz, S., and Weisglass, Y. Fooling a real car with adversarial traffic signs (2019); arXiv preprint arXiv:1907.00374."},{"key":"e_1_2_1_28_1","doi-asserted-by":"crossref","unstructured":"Nassi B. Shams J. Netanel R.B. and Elovici Y. bAdvertisement: Attacking advanced driver-assistance systems using print advertisements (2022); http:\/\/bit.ly\/3YaCdPe.","DOI":"10.1109\/EuroSPW55150.2022.00045"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298640"},{"key":"e_1_2_1_30_1","volume-title":"2016 IEEE European Symp. on Security and Privacy, 372--387","author":"Papernot P.","unstructured":"Papernot, P. et al. The limitations of deep learning in adversarial settings. In 2016 IEEE European Symp. on Security and Privacy, 372--387."},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"e_1_2_1_32_1","volume-title":"et al. Darts: Deceiving autonomous cars with toxic signs (2018)","author":"Sitawarin C.","year":"1802","unstructured":"Sitawarin, C. et al. Darts: Deceiving autonomous cars with toxic signs (2018); arXiv preprint arXiv:1802.06430."},{"key":"e_1_2_1_33_1","volume-title":"USENIX Workshop on Offensive Technologies","author":"Song D.","year":"2018","unstructured":"Song, D. et al. Physical adversarial examples for object detectors. USENIX Workshop on Offensive Technologies (2018)."},{"key":"e_1_2_1_34_1","volume-title":"Energy and policy considerations for deep learning in NLP (2019)","author":"Strubell E.","year":"1906","unstructured":"Strubell, E., Ganesh, A., and McCallum, A. Energy and policy considerations for deep learning in NLP (2019); arXiv preprint arXiv:1906.02243."},{"key":"e_1_2_1_35_1","unstructured":"Security tutorials: Hacking digital billboards; http:\/\/bit.ly\/3HpuIx9."},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the 9th Intern. Joint Conf. on Artificial Intelligence 2, (August","author":"Wallace R.S.","year":"1985","unstructured":"Wallace, R.S. et al. First results in robot road-following. In Proceedings of the 9th Intern. Joint Conf. on Artificial Intelligence 2, (August 1985), 1089--1095."},{"key":"e_1_2_1_37_1","volume-title":"Radio Today (September 30","author":"Wilson Z.","year":"2020","unstructured":"Wilson, Z. Why Ben Fordham's face is confusing cars in Sydney traffic. Radio Today (September 30, 2020); http:\/\/bit.ly\/3JA0YAE."},{"key":"e_1_2_1_38_1","unstructured":"Xu K. et al. Adversarial T-shirt! Evading person detectors in a physical world (2019); http:\/\/bit.ly\/3YekxSX."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/6979.892151"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354259"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3552308","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3552308","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T18:43:36Z","timestamp":1750272216000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3552308"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,3,23]]},"references-count":40,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,4]]}},"alternative-id":["10.1145\/3552308"],"URL":"https:\/\/doi.org\/10.1145\/3552308","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,3,23]]},"assertion":[{"value":"2023-03-23","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}