{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,11]],"date-time":"2026-02-11T14:04:24Z","timestamp":1770818664116,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":30,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:00:00Z","timestamp":1667779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Bavarian Ministry of Economic Affairs, Regional Development and Energy"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,11,11]]},"DOI":"10.1145\/3560830.3563733","type":"proceedings-article","created":{"date-parts":[[2022,11,2]],"date-time":"2022-11-02T22:32:41Z","timestamp":1667428361000},"page":"79-90","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Assessing the Impact of Transformations on Physical Adversarial Attacks"],"prefix":"10.1145","author":[{"given":"Paul Andrei","family":"Sava","sequence":"first","affiliation":[{"name":"Technical University of Munich &amp; Fraunhofer AISEC, Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jan-Philipp","family":"Schulze","sequence":"additional","affiliation":[{"name":"Technical University of Munich &amp; Fraunhofer AISEC, Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Philip","family":"Sperl","sequence":"additional","affiliation":[{"name":"Technical University of Munich &amp; Fraunhofer AISEC, Munich, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Konstantin","family":"B\u00f6ttinger","sequence":"additional","affiliation":[{"name":"Fraunhofer AISEC, Garching, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Wagner","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Nicholas Carlini , and David A . Wagner . 2018 a. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In ICML. 274--283. http:\/\/proceedings.mlr.press\/v80\/athalye18a.html Anish Athalye, Nicholas Carlini, and David A. Wagner. 2018a. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In ICML. 274--283. http:\/\/proceedings.mlr.press\/v80\/athalye18a.html"},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research","volume":"293","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Logan Engstrom , Andrew Ilyas , and Kevin Kwok . 2018 b. Synthesizing Robust Adversarial Examples . In Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research , Vol. 80), , Jennifer Dy and Andreas Krause (Eds.). PMLR, 284-- 293 . https:\/\/proceedings.mlr.press\/v80\/athalye18b.html Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018b. Synthesizing Robust Adversarial Examples. In Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 80), , Jennifer Dy and Andreas Krause (Eds.). PMLR, 284--293. https:\/\/proceedings.mlr.press\/v80\/athalye18b.html"},{"key":"#cr-split#-e_1_3_2_1_3_1.1","unstructured":"Tom B. Brown Dandelion Man\u00e9 Aurko Roy Mart\u00edn Abadi and Justin Gilmer. 2018. Adversarial Patch. https:\/\/doi.org\/10.48550\/arXiv.1712.09665 arXiv:1712.09665 [cs]. 10.48550\/arXiv.1712.09665"},{"key":"#cr-split#-e_1_3_2_1_3_1.2","unstructured":"Tom B. Brown Dandelion Man\u00e9 Aurko Roy Mart\u00edn Abadi and Justin Gilmer. 2018. Adversarial Patch. https:\/\/doi.org\/10.48550\/arXiv.1712.09665 arXiv:1712.09665 [cs]."},{"key":"e_1_3_2_1_4_1","volume-title":"Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society","author":"Carlini N.","year":"2017","unstructured":"N. Carlini and D. Wagner . 2017 . Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society , Los Alamitos, CA, USA, 39--57. https:\/\/doi.org\/10.1109\/SP. 2017 .49 ISSN: 2375--1207. 10.1109\/SP.2017.49 N. Carlini and D. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, Los Alamitos, CA, USA, 39--57. https:\/\/doi.org\/10.1109\/SP.2017.49 ISSN: 2375--1207."},{"key":"e_1_3_2_1_5_1","volume-title":"Machine Learning and Knowledge Discovery in Databases","author":"Chen Shang-Tse","unstructured":"Shang-Tse Chen , Cory Cornelius , Jason Martin , and Duen Horng (Polo) Chau . 2019. ShapeShifter: Robust Physical Adversarial Attack on Faster R-CNN Object Detector . In Machine Learning and Knowledge Discovery in Databases , Michele Berlingerio , Francesco Bonchi, Thomas G\u00e4rtner, Neil Hurley, and Georgiana Ifrim (Eds.). Springer International Publishing , Cham, 52--68. Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng (Polo) Chau. 2019. ShapeShifter: Robust Physical Adversarial Attack on Faster R-CNN Object Detector. In Machine Learning and Knowledge Discovery in Databases, Michele Berlingerio, Francesco Bonchi, Thomas G\u00e4rtner, Neil Hurley, and Georgiana Ifrim (Eds.). Springer International Publishing, Cham, 52--68."},{"key":"e_1_3_2_1_6_1","volume-title":"Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1412","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1412 .6572 Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2009.5459211"},{"key":"e_1_3_2_1_8_1","volume-title":"An Improved ShapeShifter Method of Generating Adversarial Examples for Physical Attacks on Stop Signs against Faster R-CNNs. Comput. Secur","author":"Huang Shize","year":"2021","unstructured":"Shize Huang , Xiaowen Liu , Xiaolu Yang , and Zhaoxin Zhang . 2021. An Improved ShapeShifter Method of Generating Adversarial Examples for Physical Attacks on Stop Signs against Faster R-CNNs. Comput. Secur . , Vol. 104 , C ( May 2021 ). https:\/\/doi.org\/10.1016\/j.cose.2020.102120 Place : GBR Publisher: Elsevier Advanced Technology Publications . 10.1016\/j.cose.2020.102120 Shize Huang, Xiaowen Liu, Xiaolu Yang, and Zhaoxin Zhang. 2021. An Improved ShapeShifter Method of Generating Adversarial Examples for Physical Attacks on Stop Signs against Faster R-CNNs. Comput. Secur. , Vol. 104, C (May 2021). https:\/\/doi.org\/10.1016\/j.cose.2020.102120 Place: GBR Publisher: Elsevier Advanced Technology Publications."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICICI-BME.2009.5417252"},{"key":"e_1_3_2_1_10_1","volume-title":"5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24--26, 2017, Workshop Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=HJGU3Rodl","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin , Ian J. Goodfellow , and Samy Bengio . 2017 . Adversarial examples in the physical world . In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24--26, 2017, Workshop Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=HJGU3Rodl Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio. 2017. Adversarial examples in the physical world. In 5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24--26, 2017, Workshop Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id=HJGU3Rodl"},{"key":"#cr-split#-e_1_3_2_1_11_1.1","unstructured":"Mark Lee and Zico Kolter. 2019. On Physical Adversarial Patches for Object Detection. arXiv. https:\/\/doi.org\/10.48550\/arXiv.1906.11897 arXiv:1906.11897 [cs stat]. 10.48550\/arXiv.1906.11897"},{"key":"#cr-split#-e_1_3_2_1_11_1.2","unstructured":"Mark Lee and Zico Kolter. 2019. On Physical Adversarial Patches for Object Detection. arXiv. https:\/\/doi.org\/10.48550\/arXiv.1906.11897 arXiv:1906.11897 [cs stat]."},{"key":"e_1_3_2_1_12_1","volume-title":"Berg","author":"Liu Wei","year":"2016","unstructured":"Wei Liu , Dragomir Anguelov , Dumitru Erhan , Christian Szegedy , Scott Reed , Cheng-Yang Fu , and Alexander C . Berg . 2016 . SSD : Single Shot MultiBox Detector. In Computer Vision -- ECCV 2016, , Bastian Leibe, Jiri Matas, Nicu Sebe, and Max Welling (Eds.). Springer International Publishing , Cham, 21--37. Wei Liu, Dragomir Anguelov, Dumitru Erhan, Christian Szegedy, Scott Reed, Cheng-Yang Fu, and Alexander C. Berg. 2016. SSD: Single Shot MultiBox Detector. In Computer Vision -- ECCV 2016, , Bastian Leibe, Jiri Matas, Nicu Sebe, and Max Welling (Eds.). Springer International Publishing, Cham, 21--37."},{"key":"e_1_3_2_1_13_1","volume-title":"CEUR Workshop Proceedings","volume":"2301","author":"Liu Xin","year":"2019","unstructured":"Xin Liu , Huanrui Yang , Ziwei Liu , Linghao Song , Hai Li , and Yiran Chen . 2019 . DPatch: An adversarial patch attack on object detectors . In CEUR Workshop Proceedings , Vol. 2301 . ISSN: 16130073. Xin Liu, Huanrui Yang, Ziwei Liu, Linghao Song, Hai Li, and Yiran Chen. 2019. DPatch: An adversarial patch attack on object detectors. In CEUR Workshop Proceedings, Vol. 2301. ISSN: 16130073."},{"key":"e_1_3_2_1_14_1","volume-title":"SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Lovisotto Giulio","year":"2021","unstructured":"Giulio Lovisotto , Henry Turner , Ivo Sluganovic , Martin Strohmeier , and Ivan Martinovic . 2021 . SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations. In 30th USENIX Security Symposium (USENIX Security 21) . USENIX Association , 1865--1882. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/lovisotto Giulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier, and Ivan Martinovic. 2021. SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 1865--1882. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/lovisotto"},{"key":"#cr-split#-e_1_3_2_1_15_1.1","unstructured":"Jiajun Lu Hussein Sibai Evan Fabry and David Forsyth. 2017. NO Need to Worry about Adversarial Examples in Object Detection in Autonomous Vehicles. https:\/\/doi.org\/10.48550\/arXiv.1707.03501 arXiv:1707.03501 [cs]. 10.48550\/arXiv.1707.03501"},{"key":"#cr-split#-e_1_3_2_1_15_1.2","unstructured":"Jiajun Lu Hussein Sibai Evan Fabry and David Forsyth. 2017. NO Need to Worry about Adversarial Examples in Object Detection in Autonomous Vehicles. https:\/\/doi.org\/10.48550\/arXiv.1707.03501 arXiv:1707.03501 [cs]."},{"key":"e_1_3_2_1_16_1","volume-title":"International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJzIBfZAb","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2018 . Towards Deep Learning Models Resistant to Adversarial Attacks . In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJzIBfZAb Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"#cr-split#-e_1_3_2_1_18_1.1","unstructured":"Joseph Redmon and Ali Farhadi. 2018. YOLOv3: An Incremental Improvement. https:\/\/doi.org\/10.48550\/arXiv.1804.02767 arXiv:1804.02767 [cs]. 10.48550\/arXiv.1804.02767"},{"key":"#cr-split#-e_1_3_2_1_18_1.2","unstructured":"Joseph Redmon and Ali Farhadi. 2018. YOLOv3: An Incremental Improvement. https:\/\/doi.org\/10.48550\/arXiv.1804.02767 arXiv:1804.02767 [cs]."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS '16)","author":"Sharif Mahmood","unstructured":"Mahmood Sharif , Sruti Bhagavatula , Lujo Bauer , and Michael K. Reiter . 2016. Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition . In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS '16) . Association for Computing Machinery, New York, NY, USA, 1528--1540. https:\/\/doi.org\/10.1145\/2976749.2978392 event-place: Vienna, Austria. 10.1145\/2976749.2978392 Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and Michael K. Reiter. 2016. Accessorize to a Crime: Real and Stealthy Attacks on State-of-the-Art Face Recognition. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS '16). Association for Computing Machinery, New York, NY, USA, 1528--1540. https:\/\/doi.org\/10.1145\/2976749.2978392 event-place: Vienna, Austria."},{"key":"e_1_3_2_1_21_1","volume-title":"Arsalan Mosenia, Mung Chiang, and Prateek Mittal.","author":"Sitawarin Chawin","year":"2018","unstructured":"Chawin Sitawarin , Arjun Nitin Bhagoji , Arsalan Mosenia, Mung Chiang, and Prateek Mittal. 2018 . DARTS : Deceiving Autonomous Cars with Toxic Signs . https:\/\/doi.org\/10.48550\/arXiv.1802.06430 arXiv:1802.06430 [cs]. 10.48550\/arXiv.1802.06430 Chawin Sitawarin, Arjun Nitin Bhagoji, Arsalan Mosenia, Mung Chiang, and Prateek Mittal. 2018. DARTS: Deceiving Autonomous Cars with Toxic Signs. https:\/\/doi.org\/10.48550\/arXiv.1802.06430 arXiv:1802.06430 [cs]."},{"key":"e_1_3_2_1_22_1","volume-title":"International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1312","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2014 . Intriguing properties of neural networks . In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1312 .6199 Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475653"},{"key":"e_1_3_2_1_24_1","volume-title":"Computer Vision -- ECCV","author":"Xu Kaidi","year":"2020","unstructured":"Kaidi Xu , Gaoyuan Zhang , Sijia Liu , Quanfu Fan , Mengshu Sun , Hongge Chen , Pin-Yu Chen , Yanzhi Wang , and Xue Lin . 2020. Adversarial T-Shirt! Evading Person Detectors in a Physical World . In Computer Vision -- ECCV 2020 , , Andrea Vedaldi, Horst Bischof , Thomas Brox, and Jan-Michael Frahm (Eds.). Vol. 12350 . Springer International Publishing , Cham, 665--681. https:\/\/doi.org\/10.1007\/978--3-030--58558--7_39 Series Title : Lecture Notes in Computer Science. 10.1007\/978--3-030--58558--7_39 Kaidi Xu, Gaoyuan Zhang, Sijia Liu, Quanfu Fan, Mengshu Sun, Hongge Chen, Pin-Yu Chen, Yanzhi Wang, and Xue Lin. 2020. Adversarial T-Shirt! Evading Person Detectors in a Physical World. In Computer Vision -- ECCV 2020, , Andrea Vedaldi, Horst Bischof, Thomas Brox, and Jan-Michael Frahm (Eds.). Vol. 12350. Springer International Publishing, Cham, 665--681. https:\/\/doi.org\/10.1007\/978--3-030--58558--7_39 Series Title: Lecture Notes in Computer Science."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354259"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00138-021-01194-6"}],"event":{"name":"CCS '22: 2022 ACM SIGSAC Conference on Computer and Communications Security","location":"Los Angeles CA USA","acronym":"CCS '22","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560830.3563733","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3560830.3563733","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T19:00:34Z","timestamp":1750186834000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3560830.3563733"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,7]]},"references-count":30,"alternative-id":["10.1145\/3560830.3563733","10.1145\/3560830"],"URL":"https:\/\/doi.org\/10.1145\/3560830.3563733","relation":{},"subject":[],"published":{"date-parts":[[2022,11,7]]},"assertion":[{"value":"2022-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}