{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T05:35:55Z","timestamp":1764740155294,"version":"3.46.0"},"reference-count":66,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>The traditional process for learning patch-based adversarial attacks, conducted in the digital domain and later applied in the physical domain (e.g., via printed stickers), may suffer reduced performance due to adversarial patches\u2019 limited transferability between domains. Given that previous studies have considered using film projectors to apply adversarial attacks, we ask: Can adversarial learning (i.e., patch generation) be performed entirely in the physical domain using a film projector? In this work, we propose the Physical-domain Adversarial Patch Learning Augmentation (PAPLA) framework, a novel end-to-end (E2E) framework that shifts adversarial learning from the digital domain to the physical domain using a film projector. We evaluate PAPLA in scenarios, including controlled laboratory and realistic outdoor settings, demonstrating its ability to ensure attack success compared to conventional digital learning\u2013physical application (DL-PA) methods. We also analyze how environmental factors such as projection surface color, projector strength, ambient light, distance, and the target object\u2019s angle relative to the camera affect patch effectiveness. Finally, we demonstrate the feasibility of the attack against a parked car and a stop sign in a real-world outdoor environment. Our results show that under specific conditions, E2E adversarial learning in the physical domain eliminates transferability issues and ensures evasion of object detectors. We also discuss the challenges and opportunities of adversarial learning in the physical domain and identify where this approach is more effective than using a sticker.<\/jats:p>","DOI":"10.3390\/jcp5040108","type":"journal-article","created":{"date-parts":[[2025,12,2]],"date-time":"2025-12-02T08:49:22Z","timestamp":1764665362000},"page":"108","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Towards an End-to-End (E2E) Adversarial Learning and Application in the Physical World"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7865-0308","authenticated-orcid":false,"given":"Dudi","family":"Biton","sequence":"first","affiliation":[{"name":"Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva 8410501, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jacob","family":"Shams","sequence":"additional","affiliation":[{"name":"Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva 8410501, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9187-9625","authenticated-orcid":false,"given":"Satoru","family":"Koda","sequence":"additional","affiliation":[{"name":"Fujitsu Limited, 4-1-1 Kamikodanaka, Nakahara-ku, Kawasaki-shi, Kanagawa 211-8588, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Asaf","family":"Shabtai","sequence":"additional","affiliation":[{"name":"Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva 8410501, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9641-128X","authenticated-orcid":false,"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[{"name":"Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva 8410501, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3453-2120","authenticated-orcid":false,"given":"Ben","family":"Nassi","sequence":"additional","affiliation":[{"name":"Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beer-Sheva 8410501, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,1]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Ouardirhi, Z., Mahmoudi, S.A., and Zbakh, M. (2024). Enhancing Object Detection in Smart Video Surveillance: A Survey of Occlusion-Handling Approaches. Electronics, 13.","DOI":"10.3390\/electronics13030541"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Mufti, N., and Shah, S.A.A. (2021). Automatic number plate Recognition: A detailed survey of relevant algorithms. Sensors, 21.","DOI":"10.3390\/s21093028"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Juyal, A., Sharma, S., and Matta, P. (2021, January 3\u20135). Deep learning methods for object detection in autonomous vehicles. Proceedings of the 2021 5th International Conference on Trends in Electronics and Informatics (ICOEI), Tirunelveli, India.","DOI":"10.1109\/ICOEI51242.2021.9452932"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Hu, Y.C.T., Kung, B.H., Tan, D.S., Chen, J.C., Hua, K.L., and Cheng, W.H. (2021, January 10\u201317). Naturalistic physical adversarial patch for object detectors. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Montreal, QC, Canada.","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Chen, J., Jordan, M.I., and Wainwright, M.J. (2020, January 18\u201321). Hopskipjumpattack: A query-efficient decision-based attack. Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref_6","unstructured":"Guo, C., Gardner, J., You, Y., Wilson, A.G., and Weinberger, K. (2019, January 9\u201315). Simple black-box adversarial attacks. Proceedings of the 36th International Conference on Machine Learning, Long Beach, CA, USA."},{"key":"ref_7","unstructured":"Brendel, W., Rauber, J., and Bethge, M. (2017). Decision-based adversarial attacks: Reliable attacks against black-box machine learning models. arXiv."},{"key":"ref_8","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K. (2018). Synthesizing Robust Adversarial Examples. arXiv."},{"key":"ref_9","unstructured":"Song, D., Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Tramer, F., Prakash, A., and Kohno, T. (2018, January 13\u201314). Physical adversarial examples for object detectors. Proceedings of the 12th USENIX Workshop on Offensive Technologies (WOOT 18), Baltimore, MD, USA."},{"key":"ref_10","unstructured":"Lee, M., and Kolter, Z. (2019). On physical adversarial patches for object detection. arXiv."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D. (2018, January 18\u201322). Robust physical-world attacks on deep learning visual classification. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref_12","unstructured":"Katzav, R., Giloni, A., Grolman, E., Saito, H., Shibata, T., Omino, T., Komatsu, M., Hanatani, Y., Elovici, Y., and Shabtai, A. (September, January 4). Adversarialeak: External information leakage attack using adversarial samples on face recognition systems. Proceedings of the European Conference on Computer Vision, Milan, Italy."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Chen, S.T., Cornelius, C., Martin, J., and Chau, D.H. (2018, January 10\u201314). Shapeshifter: Robust physical adversarial attack on faster R-CNN object detector. Proceedings of the Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2018, Dublin, Ireland.","DOI":"10.1007\/978-3-030-10925-7_4"},{"key":"ref_14","unstructured":"Liu, X., Yang, H., Liu, Z., Song, L., Li, H., and Chen, Y. (2018). Dpatch: An adversarial patch attack on object detectors. arXiv."},{"key":"ref_15","unstructured":"Zhang, Y., Foroosh, H., David, P., and Gong, B. (May, January 30). CAMOU: Learning physical vehicle camouflages to adversarially attack detectors in the wild. Proceedings of the 6th International Conference on Learning Representations, Vancouver, BC, Canada."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Thys, S., Van Ranst, W., and Goedem\u00e9, T. (2019, January 16\u201317). Fooling automated surveillance cameras: Adversarial patches to attack person detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, Long Beach, CA, USA.","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Xu, K., Zhang, G., Liu, S., Fan, Q., Sun, M., Chen, H., Chen, P.Y., Wang, Y., and Lin, X. (2020). Adversarial t-shirt! evading person detectors in a physical world. Computer Vision\u2014ECCV 2020, Proceedings of the 16th European Conference, Glasgow, UK, 23\u201328 August 2020, Springer. Proceedings, Part V 16.","DOI":"10.1007\/978-3-030-58558-7_39"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Huang, L., Gao, C., Zhou, Y., Xie, C., Yuille, A.L., Zou, C., and Liu, N. (2020, January 13\u201319). Universal physical camouflage attacks on object detectors. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Wu, Z., Lim, S.N., Davis, L.S., and Goldstein, T. (2020). Making an invisibility cloak: Real world adversarial attacks on object detectors. Computer Vision\u2014ECCV 2020, Proceedings of the 16th European Conference, Glasgow, UK, 23\u201328 August 2020, Springer. Proceedings, Part IV 16.","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Zolfi, A., Kravchik, M., Elovici, Y., and Shabtai, A. (2021, January 20\u201325). The translucent patch: A physical and universal attack on object detectors. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Nashville, TN, USA.","DOI":"10.1109\/CVPR46437.2021.01498"},{"key":"ref_21","unstructured":"Jing, P., Tang, Q., Du, Y., Xue, L., Luo, X., Wang, T., Nie, S., and Wu, S. (2021, January 11\u201313). Too good to be safe: Tricking lane detection in autonomous driving with crafted perturbations. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Virtual Event."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Tan, J., Ji, N., Xie, H., and Xiang, X. (2021, January 20\u201324). Legitimate adversarial patches: Evading human eyes and detection models in the physical world. Proceedings of the 29th ACM International Conference on Multimedia, Chengdu, China.","DOI":"10.1145\/3474085.3475653"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Suryanto, N., Kim, Y., Kang, H., Larasati, H.T., Yun, Y., Le, T.T.H., Yang, H., Oh, S.Y., and Kim, H. (2022, January 18\u201324). DTA: Physical camouflage attacks using differentiable transformation network. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.01487"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Hu, Z., Huang, S., Zhu, X., Sun, F., Zhang, B., and Hu, X. (2022, January 18\u201324). Adversarial texture for fooling person detectors in the physical world. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.01295"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Biton, D., Misra, A., Levy, E., Kotak, J., Bitton, R., Schuster, R., Papernot, N., Elovici, Y., and Nassi, B. (2023, January 30). The Adversarial Implications of Variable-Time Inference. Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security, Copenhagen, Denmark.","DOI":"10.1145\/3605764.3623912"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Jia, W., Lu, Z., Zhang, H., Liu, Z., Wang, J., and Qu, G. (2022). Fooling the eyes of autonomous vehicles: Robust physical adversarial examples against traffic sign recognition systems. arXiv.","DOI":"10.14722\/ndss.2022.24130"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Huang, H., Chen, Z., Chen, H., Wang, Y., and Zhang, K. (2023, January 17\u201324). T-SEA: Transfer-based self-ensemble attack on object detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPR52729.2023.01965"},{"key":"ref_28","unstructured":"Zhu, W., Ji, X., Cheng, Y., Zhang, S., and Xu, W. (2023, January 9\u201311). {TPatch}: A Triggered Physical Adversarial Patch. Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Hu, Z., Chu, W., Zhu, X., Zhang, H., Zhang, B., and Hu, X. (2023, January 17\u201324). Physically realizable natural-looking clothing textures evade person detectors via 3d modeling. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPR52729.2023.01628"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Guesmi, A., Ding, R., Hanif, M.A., Alouani, I., and Shafique, M. (2024, January 16\u201322). Dap: A dynamic adversarial patch for evading person detectors. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR52733.2024.02322"},{"key":"ref_31","unstructured":"Wei, H., Wang, Z., Zhang, K., Hou, J., Liu, Y., Tang, H., and Wang, Z. (2024, January 10\u201315). Revisiting Adversarial Patches for Designing Camera-Agnostic Attacks against Person Detection. Proceedings of the Thirty-Eighth Annual Conference on Neural Information Processing Systems, Vancouver, BC, Canada."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Cheng, Z., Hu, Z., Liu, Y., Li, J., Su, H., and Hu, X. (2024, January 10\u201315). Full-Distance Evasion of Pedestrian Detectors in the Physical World. Proceedings of the Thirty-Eighth Annual Conference on Neural Information Processing Systems, Vancouver, BC, Canada.","DOI":"10.52202\/079017-3250"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Zhu, X., Hu, Z., Huang, S., Li, J., and Hu, X. (2022, January 18\u201324). Infrared invisible clothing: Hiding from infrared detectors at multiple angles in real world. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.01296"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Wei, H., Wang, Z., Jia, X., Zheng, Y., Tang, H., Satoh, S., and Wang, Z. (2023, January 7\u201314). Hotcold block: Fooling thermal infrared detectors with a novel wearable design. Proceedings of the AAAI Conference on Artificial Intelligence, Washington, DC, USA.","DOI":"10.1609\/aaai.v37i12.26777"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1928","DOI":"10.1007\/s11263-023-01963-y","article-title":"Infrared adversarial patches with learnable shapes and locations in the physical world","volume":"132","author":"Wei","year":"2024","journal-title":"Int. J. Comput. Vis."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Zhu, X., Liu, Y., Hu, Z., Li, J., and Hu, X. (2024, January 16\u201322). Infrared Adversarial Car Stickers. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR52733.2024.02292"},{"key":"ref_37","unstructured":"Lovisotto, G., Turner, H., Sluganovic, I., Strohmeier, M., and Martinovic, I. (2021, January 11\u201313). {SLAP}: Improving physical adversarial examples with {Short-Lived} adversarial perturbations. Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), Virtual Event."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"28931","DOI":"10.1109\/JIOT.2024.3405006","article-title":"OptiCloak: Blinding Vision-Based Autonomous Driving Systems Through Adversarial Optical Projection","volume":"11","author":"Wen","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"104861","DOI":"10.1016\/j.imavis.2023.104861","article-title":"Adversarial color projection: A projector-based physical-world attack to DNNs","volume":"140","author":"Hu","year":"2023","journal-title":"Image Vis. Comput."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Hwang, R.H., Lin, J.Y., Hsieh, S.Y., Lin, H.Y., and Lin, C.L. (2023). Adversarial patch attacks on deep-learning-based face recognition systems using generative adversarial networks. Sensors, 23.","DOI":"10.3390\/s23020853"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Komkov, S., and Petiushko, A. (2021, January 10\u201315). Advhat: Real-world adversarial attack on arcface face id system. Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR), Milan, Italy.","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Lin, C.S., Hsu, C.Y., Chen, P.Y., and Yu, C.M. (2022, January 23\u201327). Real-world adversarial examples via makeup. Proceedings of the ICASSP 2022\u20142022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), Singapore.","DOI":"10.1109\/ICASSP43922.2022.9747469"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Wei, X., Huang, Y., Sun, Y., and Yu, J. (2023, January 1\u20136). Unified adversarial patch for cross-modal attacks in the physical world. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Paris, France.","DOI":"10.1109\/ICCV51070.2023.00410"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Nassi, B., Mirsky, Y., Nassi, D., Ben-Netanel, R., Drokin, O., and Elovici, Y. (2020, January 9\u201313). Phantom of the adas: Securing advanced driver-assistance systems from split-second phantom attacks. Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event.","DOI":"10.1145\/3372297.3423359"},{"key":"ref_45","unstructured":"Redmon, J., and Farhadi, A. (2018). Yolov3: An incremental improvement. arXiv."},{"key":"ref_46","unstructured":"Bochkovskiy, A., Wang, C.Y., and Liao, H.Y.M. (2020). Yolov4: Optimal speed and accuracy of object detection. arXiv."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"1137","DOI":"10.1109\/TPAMI.2016.2577031","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","volume":"39","author":"Ren","year":"2016","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Choi, J.I., and Tian, Q. (2022, January 4\u20139). Adversarial attack and defense of yolo detectors in autonomous driving scenarios. Proceedings of the 2022 IEEE Intelligent Vehicles Symposium (IV), Aachen, Germany.","DOI":"10.1109\/IV51971.2022.9827222"},{"key":"ref_49","unstructured":"Nicolae, M.I., Sinn, M., Tran, M.N., Buesser, B., Rawat, A., Wistuba, M., Zantedeschi, V., Baracaldo, N., Chen, B., and Ludwig, H. (2018). Adversarial Robustness Toolbox v1.0.0. arXiv."},{"key":"ref_50","unstructured":"Ross, T.Y., and Doll\u00e1r, G. (2017, January 21\u201326). Focal loss for dense object detection. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Liu, W., Anguelov, D., Erhan, D., Szegedy, C., Reed, S., Fu, C.Y., and Berg, A.C. (2016). SSD: Single shot multibox detector. Computer Vision\u2014ECCV 2016, Proceedings of the 14th European Conference, Amsterdam, The Netherlands, 11\u201314 October 2016, Springer. Proceedings, Part I 14.","DOI":"10.1007\/978-3-319-46448-0_2"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Pautov, M., Melnikov, G., Kaziakhmedov, E., Kireev, K., and Petiushko, A. (2019, January 21\u201327). On adversarial patches: Real-world attack on arcface-100 face recognition system. Proceedings of the 2019 International Multi-Conference on Engineering, Computer and Information Sciences (SIBIRCON), Novosibirsk, Russia.","DOI":"10.1109\/SIBIRCON48586.2019.8958134"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M.K. (2016, January 24\u201328). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978392"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Zhu, Z.A., Lu, Y.Z., and Chiang, C.K. (2019, January 22\u201325). Generating adversarial examples by makeup attacks on face recognition. Proceedings of the 2019 IEEE International Conference on Image Processing (ICIP), Taipei, Taiwan.","DOI":"10.1109\/ICIP.2019.8803269"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Yin, B., Wang, W., Yao, T., Guo, J., Kong, Z., Ding, S., Li, J., and Liu, C. (2021). Adv-makeup: A new imperceptible and transferable attack on face recognition. arXiv.","DOI":"10.24963\/ijcai.2021\/173"},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Sato, T., Bhupathiraju, S.H.V., Clifford, M., Sugawara, T., Chen, Q.A., and Rampazzi, S. (2024). Invisible Reflections: Leveraging Infrared Laser Reflections to Target Traffic Sign Perception. arXiv.","DOI":"10.14722\/ndss.2024.241053"},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Duan, R., Mao, X., Qin, A.K., Chen, Y., Ye, S., He, Y., and Yang, Y. (2021, January 20\u201325). Adversarial laser beam: Effective physical-world attack to dnns in a blink. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Nashville, TN, USA.","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"ref_58","unstructured":"Zhou, Z., Tang, D., Wang, X., Han, W., Liu, X., and Zhang, K. (2018). Invisible Mask: Practical Attacks on Face Recognition with Infrared. arXiv."},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1145\/3351261","article-title":"VLA: A practical visible light-based attack on face recognition systems in physical world","volume":"3","author":"Shen","year":"2019","journal-title":"Proc. ACM Interact. Mob. Wearable Ubiquitous Technol."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Zhu, X., Li, X., Li, J., Wang, Z., and Hu, X. (2021, January 2\u20139). Fooling thermal infrared pedestrian detectors in real world using small bulbs. Proceedings of the AAAI Conference on Artificial Intelligence, Virtual Event.","DOI":"10.1609\/aaai.v35i4.16477"},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"103345","DOI":"10.1016\/j.cose.2023.103345","article-title":"Light can be dangerous: Stealthy and effective physical-world adversarial attack by spot light","volume":"132","author":"Yufeng","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Wang, W., Yao, Y., Liu, X., Li, X., Hao, P., and Zhu, T. (2021, January 15\u201319). I can see the light: Attacks on autonomous vehicles using invisible lights. Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, Virtual Event.","DOI":"10.1145\/3460120.3484766"},{"key":"ref_63","doi-asserted-by":"crossref","unstructured":"Chou, E., Tramer, F., and Pellegrino, G. (2020, January 21). Sentinet: Detecting localized universal attacks against deep learning systems. Proceedings of the 2020 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"ref_64","doi-asserted-by":"crossref","unstructured":"Liu, J., Levine, A., Lau, C.P., Chellappa, R., and Feizi, S. (2022, January 18\u201324). Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"ref_65","doi-asserted-by":"crossref","unstructured":"Geng, G., Zhou, S., Tang, J., Zhang, X., Liu, Q., and Yuan, D. (2025). Self-Supervised Visual Tracking via Image Synthesis and Domain Adversarial Learning. Sensors, 25.","DOI":"10.3390\/s25154621"},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Li, Q., Tan, K., Yuan, D., and Liu, Q. (2025). Progressive Domain Adaptation for Thermal Infrared Tracking. Electronics, 14.","DOI":"10.3390\/electronics14010162"}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/108\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T05:31:50Z","timestamp":1764739910000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/108"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,1]]},"references-count":66,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040108"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040108","relation":{},"ISSN":["2624-800X"],"issn-type":[{"type":"electronic","value":"2624-800X"}],"subject":[],"published":{"date-parts":[[2025,12,1]]}}}