{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T21:20:00Z","timestamp":1775856000927,"version":"3.50.1"},"reference-count":216,"publisher":"Association for Computing Machinery (ACM)","issue":"10","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62576020"],"award-info":[{"award-number":["62576020"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,7,31]]},"abstract":"<jats:p>Although Deep Neural Networks (DNNs) have been widely applied in various real-world scenarios, they remain vulnerable to adversarial examples. Adversarial attacks in computer vision can be categorized into digital attacks and physical attacks based on their different forms. Compared to digital attacks, which generate perturbations in digital pixels, physical attacks are more practical in real-world settings. Due to the serious security risks posed by physically adversarial examples, many studies have been conducted to evaluate the physically adversarial robustness of DNNs in recent years. In this article, we provide a comprehensive survey of current physically adversarial attacks and defenses in computer vision. We establish a taxonomy by organizing physical attacks according to attack tasks, attack forms, and attack methods. This approach offers readers a systematic understanding of the topic from multiple perspectives. For physical defenses, we categorize them into pre-processing, in-processing, and post-processing for DNN models to ensure comprehensive coverage of adversarial defenses. Based on this survey, we discuss the challenges facing this research field and provide an outlook on future directions.<\/jats:p>","DOI":"10.1145\/3793659","type":"journal-article","created":{"date-parts":[[2026,2,10]],"date-time":"2026-02-10T21:06:16Z","timestamp":1770757576000},"page":"1-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Visual Adversarial Attacks and Defenses in the Physical World: A Survey"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0778-8377","authenticated-orcid":false,"given":"Xingxing","family":"Wei","sequence":"first","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University","place":["Beijing, China"]},{"name":"KAUST","place":["Beijing, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1097-6819","authenticated-orcid":false,"given":"Bangzheng","family":"Pu","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University","place":["Beijing, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6033-6049","authenticated-orcid":false,"given":"Shiji","family":"Zhao","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University","place":["Beijing, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3366-6610","authenticated-orcid":false,"given":"Jiefan","family":"Lu","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University","place":["Beijing, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2183-5990","authenticated-orcid":false,"given":"Baoyuan","family":"Wu","sequence":"additional","affiliation":[{"name":"The Chinese University of Hong Kong","place":["Shenzhen, China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,4,1]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP42928.2021.9506016"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00759"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICC45041.2023.10278837"},{"issue":"6","key":"e_1_3_1_7_2","first-page":"8759","article-title":"Human detection techniques for real time surveillance: A comprehensive survey","volume":"80","author":"Ansari Mohd","year":"2021","unstructured":"Mohd Ansari, Dushyant Kumar Singh, et\u00a0al. 2021. Human detection techniques for real time surveillance: A comprehensive survey. MTA 80, 6 (2021), 8759\u20138808.","journal-title":"MTA"},{"key":"e_1_3_1_8_2","first-page":"284","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018. Synthesizing robust adversarial examples. In Proceedings of the International Conference on Machine Learning. PMLR, 284\u2013293."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2020.113816"},{"key":"e_1_3_1_10_2","article-title":"Inconspicuous adversarial patches for fooling image recognition systems on mobile devices","author":"Bai Tao","year":"2021","unstructured":"Tao Bai, Jinqi Luo, and Jun Zhao. 2021. Inconspicuous adversarial patches for fooling image recognition systems on mobile devices. IEEE Internet of Things Journal (IOTJ) 8, 20 (2021), 15301\u201315313.","journal-title":"IEEE Internet of Things Journal (IOTJ)"},{"key":"e_1_3_1_11_2","volume-title":"Proceedings of the Asian Conference on Computer Vision","author":"Benz Philipp","year":"2020","unstructured":"Philipp Benz, Chaoning Zhang, Tooba Imtiaz, and In So Kweon. 2020. Double targeted universal adversarial perturbations. In Proceedings of the Asian Conference on Computer Vision."},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-48881-3_56"},{"key":"e_1_3_1_13_2","first-page":"102589","article-title":"Deep learning and medical image processing for coronavirus (COVID-19) pandemic: A survey","volume":"65","author":"Bhattacharya Sweta","year":"2021","unstructured":"Sweta Bhattacharya, Praveen Kumar Reddy Maddikunta, Quoc-Viet Pham, Thippa Reddy Gadekallu, Chiranji Lal Chowdhary, Mamoun Alazab, Md Jalil Piran, et\u00a0al. 2021. Deep learning and medical image processing for coronavirus (COVID-19) pandemic: A survey. SCS 65, 13 (2021), 102589.","journal-title":"SCS"},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2020.101766"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58589-1_3"},{"key":"e_1_3_1_16_2","volume-title":"ICLR","author":"Brendel Wieland","year":"2018","unstructured":"Wieland Brendel and Matthias Bethge. 2018. Approximating CNNs with bag-of-local-features models works surprisingly well on ImageNet. In ICLR."},{"key":"e_1_3_1_17_2","unstructured":"Tom B. Brown Dandelion Man\u00e9 Aurko Roy Mart\u00edn Abadi and Justin Gilmer. 2017. Adversarial patch. arXiv:1712.09665. Retrieved from https:\/\/arxiv.org\/abs\/1712.09665"},{"key":"e_1_3_1_18_2","first-page":"2993","volume-title":"Proceedings of the USENIX Security","author":"Cao Yulong","year":"2023","unstructured":"Yulong Cao, S. Hrushikesh Bhupathiraju, Pirouz Naghavi, Takeshi Sugawara, Z. Morley Mao, and Sara Rampazzi. 2023. You can\u2019t see me: Physical removal attacks on \\(\\lbrace\\) lidar-based \\(\\rbrace\\) autonomous vehicles driving frameworks. In Proceedings of the USENIX Security. 2993\u20133010."},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_1_21_2","first-page":"0","volume-title":"Proceedings of the European Conference on Computer Vision Workshops","author":"Carrara Fabio","year":"2018","unstructured":"Fabio Carrara, Rudy Becarelli, Roberto Caldelli, Fabrizio Falchi, and Giuseppe Amato. 2018. Adversarial examples detection in features distance spaces. In Proceedings of the European Conference on Computer Vision Workshops. 0\u20130."},{"key":"e_1_3_1_22_2","unstructured":"Anirban Chakraborty Manaar Alam Vishal Dey Anupam Chattopadhyay and Debdeep Mukhopadhyay. 2018. Adversarial attacks and defences: A survey. arXiv:1810.00069. Retrieved from https:\/\/arxiv.org\/abs\/1810.00069"},{"key":"e_1_3_1_23_2","first-page":"6345","volume-title":"Proceedings of the USENIX Security","author":"Chen Baodong","year":"2024","unstructured":"Baodong Chen, Wei Wang, Pascal Sikorski, and Ting Zhu. 2024. Adversary is on the road: Attacks on visual \\(\\lbrace\\) SLAM \\(\\rbrace\\) using unnoticeable adversarial patch. In Proceedings of the USENIX Security. 6345\u20136362."},{"key":"e_1_3_1_24_2","first-page":"52","volume-title":"Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases","author":"Chen Shang-Tse","year":"2018","unstructured":"Shang-Tse Chen, Cory Cornelius, Jason Martin, and Duen Horng Polo Chau. 2018. Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector. In Proceedings of the Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 52\u201368."},{"key":"e_1_3_1_25_2","article-title":"Zo-adamm: Zeroth-order adaptive momentum method for black-box optimization","volume":"32","author":"Chen Xiangyi","year":"2019","unstructured":"Xiangyi Chen, Sijia Liu, Kaidi Xu, Xingguo Li, Xue Lin, Mingyi Hong, and David Cox. 2019. Zo-adamm: Zeroth-order adaptive momentum method for black-box optimization. NeurIPS 32 (2019), 7202\u20137213.","journal-title":"NeurIPS"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01019"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01472"},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19839-7_30"},{"key":"e_1_3_1_29_2","volume-title":"ICLR","author":"Chiang Ping-yeh","year":"2020","unstructured":"Ping-yeh Chiang, Renkun Ni, Ahmed Abdelkader, Chen Zhu, Christoph Studer, and Tom Goldstein. 2020. Certified defenses for adversarial patches. In ICLR. International Conference on Learning Representations."},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01446"},{"key":"e_1_3_1_32_2","first-page":"1310","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. In Proceedings of the International Conference on Machine Learning. PMLR, 1310\u20131320."},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274895.3274904"},{"key":"e_1_3_1_34_2","first-page":"53","volume-title":"Proceedings of the Conference on Robot Learning","author":"Das Abhishek","year":"2018","unstructured":"Abhishek Das, Georgia Gkioxari, Stefan Lee, Devi Parikh, and Dhruv Batra. 2018. Neural modular control for embodied question answering. In Proceedings of the Conference on Robot Learning. PMLR, 53\u201362."},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1117\/12.2575907"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00103"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i2.16211"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01107"},{"key":"e_1_3_1_39_2","first-page":"1022","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Dong Yinpeng","year":"2023","unstructured":"Yinpeng Dong, Caixin Kang, Jinlai Zhang, Zijian Zhu, Yikai Wang, Xiao Yang, Hang Su, Xingxing Wei, and Jun Zhu. 2023. Benchmarking robustness of 3d object detection to common corruptions. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 1022\u20131032."},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_1_41_2","volume-title":"ICLR","author":"Dosovitskiy Alexey","year":"2020","unstructured":"Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, et\u00a0al. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. In ICLR."},{"key":"e_1_3_1_42_2","first-page":"1","volume-title":"Proceedings of the Conference on Robot Learning","author":"Dosovitskiy Alexey","year":"2017","unstructured":"Alexey Dosovitskiy, German Ros, Felipe Codevilla, Antonio Lopez, and Vladlen Koltun. 2017. CARLA: An open urban driving simulator. In Proceedings of the Conference on Robot Learning. 1\u201316."},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00385"},{"issue":"22","key":"e_1_3_1_44_2","first-page":"e4655","article-title":"Mobile payment recognition technology based on face detection algorithm","volume":"30","author":"Du Meiyan","year":"2018","unstructured":"Meiyan Du. 2018. Mobile payment recognition technology based on face detection algorithm. CCPE 30, 22 (2018), e4655.","journal-title":"CCPE"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00108"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"e_1_3_1_47_2","unstructured":"Gintare Karolina Dziugaite Zoubin Ghahramani and Daniel M. Roy. 2016. A study of the effect of jpg compression on adversarial images. arXiv:1608.00853. Retrieved from https:\/\/arxiv.org\/abs\/1608.00853"},{"key":"e_1_3_1_48_2","article-title":"Adversarial examples that fool both computer vision and time-limited humans","volume":"31","author":"Elsayed Gamaleldin","year":"2018","unstructured":"Gamaleldin Elsayed, Shreya Shankar, Brian Cheung, Nicolas Papernot, Alexey Kurakin, Ian Goodfellow, and Jascha Sohl-Dickstein. 2018. Adversarial examples that fool both computer vision and time-limited humans. NeurIPS 31 (2018), 3914\u20133924.","journal-title":"NeurIPS"},{"issue":"3","key":"e_1_3_1_49_2","first-page":"4","article-title":"Robust physical-world attacks on machine learning models","volume":"2","author":"Evtimov Ivan","year":"2017","unstructured":"Ivan Evtimov, Kevin Eykholt, Earlence Fernandes, Tadayoshi Kohno, Bo Li, Atul Prakash, Amir Rahmati, and Dawn Song. 2017. Robust physical-world attacks on machine learning models. arXiv preprint :1707.08945 2, 3 (2017), 4.","journal-title":"arXiv preprint :1707.08945"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_1_51_2","unstructured":"Reuben Feinman Ryan R. Curtin Saurabh Shintre and Andrew B. Gardner. 2017. Detecting adversarial samples from artifacts. arXiv:1703.00410. Retrieved from https:\/\/arxiv.org\/abs\/1703.00410"},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00769"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.265"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW54120.2021.00016"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1145\/3593078.3593935"},{"key":"e_1_3_1_57_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_1_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00494"},{"key":"e_1_3_1_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02322"},{"key":"e_1_3_1_60_2","unstructured":"Amira Guesmi Muhammad Abdullah Hanif Ihsen Alouani and Muhammad Shafique. 2023. APARATE: Adaptive adversarial patch for CNN-based monocular depth estimation for autonomous navigation. arXiv:2303.01351. Retrieved from https:\/\/arxiv.org\/abs\/2303.01351"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3353042"},{"key":"e_1_3_1_62_2","volume-title":"ICLR","author":"Guo Chuan","year":"2018","unstructured":"Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten. 2018. Countering adversarial images using input transformations. In ICLR."},{"key":"e_1_3_1_63_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01252-6_30"},{"key":"e_1_3_1_64_2","first-page":"3976","volume-title":"Proceedings of the International Conference on Machine Learning","author":"G\u00fcrel Nezihe Merve","year":"2021","unstructured":"Nezihe Merve G\u00fcrel, Xiangyu Qi, Luka Rimanic, Ce Zhang, and Bo Li. 2021. Knowledge enhanced machine learning pipeline against diverse adversarial attacks. In Proceedings of the International Conference on Machine Learning. 3976\u20133987."},{"key":"e_1_3_1_65_2","first-page":"28169","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Han Husheng","year":"2021","unstructured":"Husheng Han, Kaidi Xu, Xing Hu, Xiaobing Chen, Ling LIANG, Zidong Du, Qi Guo, Yanzhi Wang, and Yunji Chen. 2021. ScaleCert: Scalable certified defense against adversarial patches with sparse superficial layers. In Proceedings of the Advances in Neural Information Processing Systems. 28169\u201328181."},{"key":"e_1_3_1_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00428"},{"key":"e_1_3_1_68_2","unstructured":"Vlad Hondru and Radu Tudor Ionescu. 2023. Towards few-call model stealing via active self-paced knowledge distillation and diffusion-based image generation. arXiv:2310.00096. Retrieved from https:\/\/arxiv.org\/abs\/2310.00096"},{"key":"e_1_3_1_69_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"e_1_3_1_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01628"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01295"},{"key":"e_1_3_1_72_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01965"},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"e_1_3_1_74_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100270"},{"key":"e_1_3_1_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02314"},{"issue":"6","key":"e_1_3_1_76_2","first-page":"1","article-title":"Patchcensor: Patch robustness certification for transformers via exhaustive testing","volume":"32","author":"Huang Yuheng","year":"2023","unstructured":"Yuheng Huang, Lei Ma, and Yuanchun Li. 2023. Patchcensor: Patch robustness certification for transformers via exhaustive testing. ACM T-SE 32, 6 (2023), 1\u201334.","journal-title":"ACM T-SE"},{"key":"e_1_3_1_77_2","article-title":"Adversarial examples are not bugs, they are features","volume":"32","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial examples are not bugs, they are features. NeurIPS 32 (2019), 125\u2013136.","journal-title":"NeurIPS"},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301962"},{"key":"e_1_3_1_79_2","unstructured":"Nan Ji YanFei Feng Haidong Xie Xueshuang Xiang and Naijin Liu. 2021. Adversarial yolo: Defense human detection patch attacks via detecting adversarial patches. arXiv:2103.08860. Retrieved from https:\/\/arxiv.org\/abs\/2103.08860"},{"key":"e_1_3_1_80_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00624"},{"key":"e_1_3_1_81_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179458"},{"key":"e_1_3_1_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02310"},{"key":"e_1_3_1_83_2","first-page":"130","volume-title":"Proceedings of the European Conference on Computer Vision","author":"Kang Caixin","year":"2024","unstructured":"Caixin Kang, Yinpeng Dong, Zhengyi Wang, Shouwei Ruan, Yubo Chen, Hang Su, and Xingxing Wei. 2024. Diffender: Diffusion-based adversarial defense against patch attacks. In Proceedings of the European Conference on Computer Vision. Springer, 130\u2013147."},{"key":"e_1_3_1_84_2","unstructured":"Caixin Kang Yinpeng Dong Zhengyi Wang Shouwei Ruan Hang Su and Xingxing Wei. 2023. DIFFender: Diffusion-based adversarial defense against patch attacks in the physical world. arXiv:2306.09124. Retrieved from https:\/\/arxiv.org\/abs\/2306.09124"},{"key":"e_1_3_1_85_2","first-page":"2507","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Karmon Danny","year":"2018","unstructured":"Danny Karmon, Daniel Zoran, and Yoav Goldberg. 2018. Lavan: Localized and visible adversarial noise. In Proceedings of the International Conference on Machine Learning. PMLR, 2507\u20132515."},{"key":"e_1_3_1_86_2","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548362"},{"key":"e_1_3_1_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01426"},{"key":"e_1_3_1_89_2","doi-asserted-by":"crossref","unstructured":"Alexey Kurakin Ian Goodfellow Samy Bengio et\u00a0al. 2016. Adversarial examples in the physical world. In Artificial intelligence Safety and security. Chapman and Hall\/CRC. 99\u2013112.","DOI":"10.1201\/9781351251389-8"},{"key":"e_1_3_1_90_2","unstructured":"Tencent Keen Security Lab. 2019. Experimental security research of Tesla autopilot. Tencent Keen Security Lab."},{"key":"e_1_3_1_91_2","unstructured":"Jin Han Lee Myung-Kyu Han Dong Wook Ko and Il Hong Suh. 2019. From big to small: Multi-scale local planar guidance for monocular depth estimation. arXiv:1907.10326. Retrieved from https:\/\/arxiv.org\/abs\/1907.10326"},{"key":"e_1_3_1_92_2","article-title":"A simple unified framework for detecting out-of-distribution samples and adversarial attacks","volume":"31","author":"Lee Kimin","year":"2018","unstructured":"Kimin Lee, Kibok Lee, Honglak Lee, and Jinwoo Shin. 2018. A simple unified framework for detecting out-of-distribution samples and adversarial attacks. NeurIPS 31 (2018), 7167\u20137177.","journal-title":"NeurIPS"},{"key":"e_1_3_1_93_2","first-page":"6465","article-title":"(De) Randomized smoothing for certifiable defense against patch attacks","volume":"33","author":"Levine Alexander","year":"2020","unstructured":"Alexander Levine and Soheil Feizi. 2020. (De) Randomized smoothing for certifiable defense against patch attacks. NeurIPS 33 (2020), 6465\u20136475.","journal-title":"NeurIPS"},{"key":"e_1_3_1_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00441"},{"key":"e_1_3_1_95_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00935"},{"key":"e_1_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488754"},{"key":"e_1_3_1_97_2","first-page":"3896","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Li Juncheng","year":"2019","unstructured":"Juncheng Li, Frank Schmidt, and Zico Kolter. 2019. Adversarial camera stickers: A physical camera-based attack on deep learning systems. In Proceedings of the International Conference on Machine Learning. 3896\u20133904."},{"key":"e_1_3_1_98_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01186"},{"key":"e_1_3_1_99_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00780"},{"key":"e_1_3_1_100_2","doi-asserted-by":"crossref","unstructured":"Jiawei Lian Jianhong Pan Lefan Wang Yi Wang Lap-Pui Chau and Shaohui Mei. 2024. PADetBench: Towards benchmarking physical attacks against object detection. arXiv:2408.09181. Retrieved from https:\/\/arxiv.org\/abs\/2408.09181","DOI":"10.1016\/j.knosys.2025.114395"},{"key":"e_1_3_1_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00760"},{"key":"e_1_3_1_102_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58520-4_8"},{"key":"e_1_3_1_103_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"e_1_3_1_104_2","volume-title":"CEUR Workshop","author":"Liu Xin","year":"2018","unstructured":"Xin Liu, Huanrui Yang, Ziwei Liu, Linghao Song, Hai Li, and Yiran Chen. 2018. DPATCH: An adversarial patch attack on object detectors. In CEUR Workshop."},{"key":"e_1_3_1_105_2","volume-title":"ICLR","author":"Liu Yanpei","year":"2017","unstructured":"Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2017. Delving into transferable adversarial examples and black-box attacks. In ICLR."},{"key":"e_1_3_1_106_2","doi-asserted-by":"publisher","DOI":"10.3390\/e25020282"},{"key":"e_1_3_1_107_2","first-page":"962","article-title":"Defending against multiple and unforeseen adversarial videos","volume":"31","author":"Lo Shao-Yuan","year":"2021","unstructured":"Shao-Yuan Lo and Vishal M. Patel. 2021. Defending against multiple and unforeseen adversarial videos. IEEE TIP 31 (2021), 962\u2013973.","journal-title":"IEEE TIP"},{"key":"e_1_3_1_108_2","first-page":"1865","volume-title":"Proceedings of the USENIX Security 21","author":"Lovisotto Giulio","year":"2021","unstructured":"Giulio Lovisotto, Henry Turner, Ivo Sluganovic, Martin Strohmeier, and Ivan Martinovic. 2021. \\(\\lbrace\\) SLAP \\(\\rbrace\\) : Improving physical adversarial examples with \\(\\lbrace\\) Short-Lived \\(\\rbrace\\) adversarial perturbations. In Proceedings of the USENIX Security 21. 1865\u20131882."},{"key":"e_1_3_1_109_2","unstructured":"Jiajun Lu Hussein Sibai and Evan Fabry. 2017. Adversarial examples that fool detectors. arXiv:1712.02494. Retrieved from https:\/\/arxiv.org\/abs\/1712.02494"},{"key":"e_1_3_1_110_2","unstructured":"Xingjun Ma Bo Li Yisen Wang Sarah M. Erfani Sudanthi Wijewickrema Grant Schoenebeck Dawn Song Michael E. Houle and James Bailey. 2018. Characterizing adversarial subspaces using local intrinsic dimensionality. arXiv:1801.02613. Retrieved from https:\/\/arxiv.org\/abs\/1801.02613"},{"key":"e_1_3_1_111_2","doi-asserted-by":"publisher","DOI":"10.1145\/3485133"},{"key":"e_1_3_1_112_2","volume-title":"ICLR","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In ICLR."},{"key":"e_1_3_1_113_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-61638-0_31"},{"key":"e_1_3_1_114_2","volume-title":"Proceedings of the ICML 2021 Workshop on Adversarial Machine Learning","author":"Metzen Jan Hendrik","year":"2021","unstructured":"Jan Hendrik Metzen, Nicole Finnie, and Robin Hutmacher. 2021. Meta adversarial training against universal patches. In Proceedings of the ICML 2021 Workshop on Adversarial Machine Learning."},{"key":"e_1_3_1_115_2","volume-title":"ICLR","author":"Metzen Jan Hendrik","year":"2021","unstructured":"Jan Hendrik Metzen and Maksym Yatsura. 2021. Efficient certified defenses against patch attacks on image classifiers. In ICLR. International Conference on Learning Representations."},{"key":"e_1_3_1_116_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_1_117_2","volume-title":"Proceedings of the 2021 Workshop on Uncertainty and Robustness in Deep Learning Workshop","author":"Mu Norman","year":"2021","unstructured":"Norman Mu and David Wagner. 2021. Defending against adversarial patches with robust self-attention. In Proceedings of the 2021 Workshop on Uncertainty and Robustness in Deep Learning Workshop."},{"key":"e_1_3_1_118_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"e_1_3_1_119_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00415"},{"key":"e_1_3_1_120_2","first-page":"16805","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Nie Weili","year":"2022","unstructured":"Weili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao, Arash Vahdat, and Animashree Anandkumar. 2022. Diffusion models for adversarial purification. In Proceedings of the International Conference on Machine Learning. PMLR, 16805\u201316827."},{"key":"e_1_3_1_121_2","doi-asserted-by":"publisher","DOI":"10.47852\/bonviewJCCE2202322"},{"key":"e_1_3_1_122_2","article-title":"Towards robust detection of adversarial examples","volume":"31","author":"Pang Tianyu","year":"2018","unstructured":"Tianyu Pang, Chao Du, Yinpeng Dong, and Jun Zhu. 2018. Towards robust detection of adversarial examples. NeurIPS 31 (2018).","journal-title":"NeurIPS"},{"key":"e_1_3_1_123_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_1_124_2","unstructured":"Naman Patel Prashanth Krishnamurthy Siddharth Garg and Farshad Khorrami. 2020. Bait and switch: Online training data poisoning of autonomous driving systems. arXiv:2011.04065. Retrieved from https:\/\/arxiv.org\/abs\/2011.04065"},{"key":"e_1_3_1_125_2","doi-asserted-by":"publisher","DOI":"10.1109\/SIBIRCON48586.2019.8958134"},{"issue":"2015","key":"e_1_3_1_126_2","first-page":"995","article-title":"Remote attacks on automated vehicles sensors: Experiments on camera and lidar","volume":"11","author":"Petit Jonathan","year":"2015","unstructured":"Jonathan Petit, Bas Stottelaar, Michael Feiri, and Frank Kargl. 2015. Remote attacks on automated vehicles sensors: Experiments on camera and lidar. Black Hat Europe 11, 2015 (2015), 995.","journal-title":"Black Hat Europe"},{"key":"e_1_3_1_127_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01579"},{"issue":"2","key":"e_1_3_1_128_2","first-page":"153","article-title":"Survey of model-based reinforcement learning: Applications on robotics","volume":"86","author":"Polydoros Athanasios S.","year":"2017","unstructured":"Athanasios S. Polydoros and Lazaros Nalpantidis. 2017. Survey of model-based reinforcement learning: Applications on robotics. JINT 86, 2 (2017), 153\u2013173.","journal-title":"JINT"},{"key":"e_1_3_1_129_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00058"},{"key":"e_1_3_1_130_2","doi-asserted-by":"publisher","DOI":"10.3390\/app9050909"},{"key":"e_1_3_1_131_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W50199.2020.00016"},{"key":"e_1_3_1_132_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"e_1_3_1_133_2","article-title":"Faster r-cnn: Towards real-time object detection with region proposal networks","author":"Ren Shaoqing","year":"2015","unstructured":"Shaoqing Ren, Kaiming He, Ross Girshick, and Jian Sun. 2015. Faster r-cnn: Towards real-time object detection with region proposal networks. NeurIPS 28, 6 (2015), 1137\u20131149.","journal-title":"NeurIPS"},{"key":"e_1_3_1_134_2","doi-asserted-by":"publisher","DOI":"10.1109\/ITSC45102.2020.9294422"},{"key":"e_1_3_1_135_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01471"},{"key":"e_1_3_1_136_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.241053"},{"key":"e_1_3_1_137_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3563537"},{"key":"e_1_3_1_138_2","first-page":"3309","volume-title":"Proceedings of the USENIX Security","author":"Sato Takami","year":"2021","unstructured":"Takami Sato, Junjie Shen, Ningfei Wang, Yunhan Jia, Xue Lin, and Qi Alfred Chen. 2021. Dirty road can attack: Security of deep learning based automated lane centering under \\(\\lbrace\\) Physical-World \\(\\rbrace\\) attack. In Proceedings of the USENIX Security. 3309\u20133326."},{"key":"e_1_3_1_139_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.230628"},{"key":"e_1_3_1_140_2","doi-asserted-by":"publisher","DOI":"10.1145\/3560830.3563733"},{"key":"e_1_3_1_141_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01443"},{"key":"e_1_3_1_142_2","doi-asserted-by":"publisher","DOI":"10.1145\/3398394"},{"key":"e_1_3_1_143_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-67361-5_40"},{"key":"e_1_3_1_144_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_1_145_2","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"e_1_3_1_146_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66787-4_22"},{"key":"e_1_3_1_147_2","doi-asserted-by":"publisher","DOI":"10.1109\/BIOSIG52210.2021.9548291"},{"key":"e_1_3_1_148_2","unstructured":"Chawin Sitawarin Arjun Nitin Bhagoji Arsalan Mosenia Prateek Mittal and Mung Chiang. 2018. Rogue signs: Deceiving traffic sign recognition with malicious ads and logos. arXiv:1801.02780. Retrieved from https:\/\/arxiv.org\/abs\/1801.02780"},{"key":"e_1_3_1_149_2","volume-title":"Proceedings of the 12th USENIX Workshop on Offensive Technologies","author":"Song Dawn","year":"2018","unstructured":"Dawn Song, Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Florian Tramer, Atul Prakash, and Tadayoshi Kohno. 2018. Physical adversarial examples for object detectors. In Proceedings of the 12th USENIX Workshop on Offensive Technologies."},{"key":"e_1_3_1_150_2","doi-asserted-by":"crossref","unstructured":"Rolf Sprengel Karl Rohr and H. Stiehl. 1996. Thin-plate spline approximation for image registration. In Proceedings of 18th annual international conference of the IEEE engineering in medicine and biology society. IEEE. 3 (1996) 1190\u20131191.","DOI":"10.1109\/IEMBS.1996.652767"},{"key":"e_1_3_1_151_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP51287.2024.10647435"},{"key":"e_1_3_1_152_2","doi-asserted-by":"publisher","DOI":"10.1088\/0266-5611\/19\/6\/059"},{"key":"e_1_3_1_153_2","first-page":"877","volume-title":"Proceedings of the USENIX Security","author":"Sun Jiachen","year":"2020","unstructured":"Jiachen Sun, Yulong Cao, Qi Alfred Chen, and Z. Morley Mao. 2020. Towards robust \\(\\lbrace\\) LiDAR-based \\(\\rbrace\\) perception in autonomous driving: General black-box adversarial sensor attack and countermeasures. In Proceedings of the USENIX Security. 877\u2013894."},{"key":"e_1_3_1_154_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01487"},{"key":"e_1_3_1_155_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00397"},{"key":"e_1_3_1_156_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00398"},{"key":"e_1_3_1_157_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"e_1_3_1_158_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5443"},{"key":"e_1_3_1_159_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01373"},{"key":"e_1_3_1_160_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46466-4_49"},{"key":"e_1_3_1_161_2","article-title":"EV AA-exchange vanishing adversarial attack on LiDAR point clouds in autonomous vehicles","author":"Vishnu Chalavadi","year":"2023","unstructured":"Chalavadi Vishnu, Jayesh Khandelwal, C. Krishna Mohan, and Cenkeramaddi Linga Reddy. 2023. EV AA-exchange vanishing adversarial attack on LiDAR point clouds in autonomous vehicles. IEEE T-GRS 61 (2023), 1\u201310.","journal-title":"IEEE T-GRS"},{"key":"e_1_3_1_162_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20141"},{"key":"e_1_3_1_163_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00411"},{"key":"e_1_3_1_164_2","article-title":"Adversarial obstacle generation against lidar-based 3d object detection","author":"Wang Jian","year":"2023","unstructured":"Jian Wang, Fan Li, Xuchong Zhang, and Hongbin Sun. 2023. Adversarial obstacle generation against lidar-based 3d object detection. IEEE T-MM 26 (2023), 2686\u20132699.","journal-title":"IEEE T-MM"},{"key":"e_1_3_1_165_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00846"},{"key":"e_1_3_1_166_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00142"},{"key":"e_1_3_1_167_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00843"},{"key":"e_1_3_1_168_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3430860"},{"key":"e_1_3_1_169_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3176760"},{"key":"e_1_3_1_170_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3231886"},{"key":"e_1_3_1_171_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00410"},{"key":"e_1_3_1_172_2","unstructured":"Xingxing Wei Caixin Kang Yinpeng Dong Zhengyi Wang Shouwei Ruan Yubo Chen and Hang Su. 2024. Real-world adversarial defense against patch attacks based on diffusion model. arXiv:2409.09406. Retrieved from https:\/\/arxiv.org\/abs\/2409.09406"},{"key":"e_1_3_1_173_2","unstructured":"Xingxing Wei Shouwei Ruan Yinpeng Dong and Hang Su. 2023. Distributional modeling for location-aware adversarial patches. arXiv:2306.16131. Retrieved from https:\/\/arxiv.org\/abs\/2306.16131"},{"key":"e_1_3_1_174_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01187"},{"key":"e_1_3_1_175_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3411035"},{"key":"e_1_3_1_176_2","article-title":"Geometry-aware generation of adversarial point clouds","author":"Wen Yuxin","year":"2020","unstructured":"Yuxin Wen, Jiehong Lin, Ke Chen, CL Philip Chen, and Kui Jia. 2020. Geometry-aware generation of adversarial point clouds. IEEE T-PAMI 44, 6 (2020), 2984\u20132999.","journal-title":"IEEE T-PAMI"},{"key":"e_1_3_1_177_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00492"},{"key":"e_1_3_1_178_2","first-page":"5286","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Wong Eric","year":"2018","unstructured":"Eric Wong and Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. In Proceedings of the International Conference on Machine Learning. 5286\u20135295."},{"key":"e_1_3_1_179_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02300"},{"key":"e_1_3_1_180_2","unstructured":"Tong Wu Xuefei Ning Wenshuo Li Ranran Huang Huazhong Yang and Yu Wang. 2020. Physical adversarial attack on vehicle detector in the carla simulator. arXiv:2007.16118. Retrieved from https:\/\/arxiv.org\/abs\/2007.16118"},{"key":"e_1_3_1_181_2","volume-title":"ICLR","author":"Wu Tong","year":"2020","unstructured":"Tong Wu, Liang Tong, and Yevgeniy Vorobeychik. 2020. Defending against physically realizable attacks on image classification. In ICLR."},{"key":"e_1_3_1_182_2","unstructured":"Xugang Wu Xiaoping Wang Xu Zhou and Songlei Jian. 2019. STA: Adversarial attacks on siamese trackers. arXiv:1909.03413. Retrieved from https:\/\/arxiv.org\/abs\/1909.03413"},{"key":"e_1_3_1_183_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"e_1_3_1_184_2","first-page":"2237","volume-title":"Proceedings of the USENIX Security","author":"Xiang Chong","year":"2021","unstructured":"Chong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, and Prateek Mittal. 2021. \\(\\lbrace\\) PatchGuard \\(\\rbrace\\) : A provably robust defense against adversarial patches via small receptive fields and masking. In Proceedings of the USENIX Security. 2237\u20132254."},{"key":"e_1_3_1_185_2","volume-title":"Proceedings of the USENIX Security","author":"Xiang Chong","year":"2023","unstructured":"Chong Xiang, Tong Wu, Sihui Dai, Jonathan Petit, Suman Jana, and Prateek Mittal. 2023. Patchcure: Improving certifiable robustness, model utility, and computation efficiency of adversarial patch defenses. In Proceedings of the USENIX Security."},{"key":"e_1_3_1_186_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00706"},{"key":"e_1_3_1_187_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01167"},{"key":"e_1_3_1_188_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"e_1_3_1_189_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"e_1_3_1_190_2","unstructured":"Weilin Xu David Evans and Yanjun Qi. 2017. Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv:1704.01155. Retrieved from https:\/\/arxiv.org\/abs\/1704.01155"},{"key":"e_1_3_1_191_2","first-page":"102694","article-title":"NaturalAE: Natural and robust physical adversarial examples for object detectors","volume":"57","author":"Xue Mingfu","year":"2021","unstructured":"Mingfu Xue, Chengxiang Yuan, Can He, Jian Wang, and Weiqiang Liu. 2021. NaturalAE: Natural and robust physical adversarial examples for object detectors. JISA 57 (2021), 102694.","journal-title":"JISA"},{"key":"e_1_3_1_192_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3027372"},{"key":"e_1_3_1_193_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9053574"},{"key":"e_1_3_1_194_2","unstructured":"Jianwei Yang Zhile Ren Mingze Xu Xinlei Chen David Crandall Devi Parikh and Dhruv Batra. 2019. Embodied visual recognition. arXiv:1904.04404. Retrieved from https:\/\/arxiv.org\/abs\/1904.04404"},{"key":"e_1_3_1_195_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5459"},{"key":"e_1_3_1_196_2","volume-title":"ICLR","author":"Yatsura Maksym","year":"2023","unstructured":"Maksym Yatsura, Kaspar Sakmann, N. Grace Hua, Matthias Hein, and Jan Hendrik Metzen. 2023. Certified defences against adversarial patch attacks on semantic segmentation. In ICLR."},{"key":"e_1_3_1_197_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/173"},{"key":"e_1_3_1_198_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01612"},{"key":"e_1_3_1_199_2","unstructured":"Youngjoon Yu Hong Joo Lee Hakmin Lee and Yong Man Ro. 2022. Defending against person hiding adversarial patch attack with a universal white frame. arXiv:2204.13004. Retrieved from https:\/\/arxiv.org\/abs\/2204.13004"},{"key":"e_1_3_1_200_2","unstructured":"Shuai Yuan Hongwei Li Xingshuo Han Guowen Xu Wenbo Jiang Tao Ni Qingchuan Zhao and Yuguang Fang. 2024. ITPatch: An invisible and triggered physical adversarial patch against traffic sign recognition. arXiv:2409.12394. Retrieved from https:\/\/arxiv.org\/abs\/2409.12394"},{"key":"e_1_3_1_201_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00443"},{"key":"e_1_3_1_202_2","doi-asserted-by":"publisher","DOI":"10.1145\/3301551.3301588"},{"key":"e_1_3_1_203_2","article-title":"CAMOU: Learning a vehicle camouflage for physical adversarial attack on object detections in the wild","author":"Zhang Yang","year":"2019","unstructured":"Yang Zhang, P. D. Hassan Foroosh, and Boqing Gong. 2019. CAMOU: Learning a vehicle camouflage for physical adversarial attack on object detections in the wild. ICLR (2019).","journal-title":"ICLR"},{"key":"e_1_3_1_204_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00026"},{"key":"e_1_3_1_205_2","unstructured":"Shiji Zhao Xizhe Wang and Xingxing Wei. 2023. Mitigating the accuracy-robustness trade-off via multi-teacher adversarial distillation. arXiv:2306.16170. Retrieved from https:\/\/arxiv.org\/abs\/2306.16170"},{"key":"e_1_3_1_206_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_34"},{"key":"e_1_3_1_207_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02308"},{"key":"e_1_3_1_208_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01491"},{"key":"e_1_3_1_209_2","unstructured":"Zhe Zhou Di Tang Xiaofeng Wang Weili Han Xiangyu Liu and Kehuan Zhang. 2018. Invisible mask: Practical attacks on face recognition with infrared. arXiv:1803.04683. Retrieved from https:\/\/arxiv.org\/abs\/1803.04683"},{"key":"e_1_3_1_210_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49660.2025.10887780"},{"key":"e_1_3_1_211_2","unstructured":"Jianing Zhu Jiangchao Yao Bo Han Jingfeng Zhang Tongliang Liu Gang Niu Jingren Zhou Jianliang Xu and Hongxia Yang. 2021. Reliable adversarial distillation with unreliable teachers. arXiv:2106.04928. Retrieved from https:\/\/arxiv.org\/abs\/2106.04928"},{"key":"e_1_3_1_212_2","first-page":"661","volume-title":"Proceedings of the USENIX Security","author":"Zhu Wenjun","year":"2023","unstructured":"Wenjun Zhu, Xiaoyu Ji, Yushi Cheng, Shibo Zhang, and Wenyuan Xu. 2023. \\(\\lbrace\\) TPatch \\(\\rbrace\\) : A triggered physical adversarial patch. In Proceedings of the USENIX Security. 661\u2013678."},{"key":"e_1_3_1_213_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01296"},{"key":"e_1_3_1_214_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i4.16477"},{"key":"e_1_3_1_215_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485377"},{"key":"e_1_3_1_216_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01613"},{"key":"e_1_3_1_217_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01498"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3793659","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T20:42:34Z","timestamp":1775853754000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3793659"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,1]]},"references-count":216,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2026,7,31]]}},"alternative-id":["10.1145\/3793659"],"URL":"https:\/\/doi.org\/10.1145\/3793659","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,1]]},"assertion":[{"value":"2022-11-28","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-01-08","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-01","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}