{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T16:34:11Z","timestamp":1783528451255,"version":"3.55.0"},"reference-count":75,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2025,1,13]],"date-time":"2025-01-13T00:00:00Z","timestamp":1736726400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["42301381"],"award-info":[{"award-number":["42301381"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["J. Imaging"],"abstract":"<jats:p>The increasing reliance on deep neural network-based object detection models in various applications has raised significant security concerns due to their vulnerability to adversarial attacks. In physical 3D environments, existing adversarial attacks that target object detection (3D-AE) face significant challenges. These attacks often require large and dispersed modifications to objects, making them easily noticeable and reducing their effectiveness in real-world scenarios. To maximize the attack effectiveness, large and dispersed attack camouflages are often employed, which makes the camouflages overly conspicuous and reduces their visual stealth. The core issue is how to use minimal and concentrated camouflage to maximize the attack effect. Addressing this, our research focuses on developing more subtle and efficient attack methods that can better evade detection in practical settings. Based on these principles, this paper proposes a local 3D attack method driven by a Maximum Aggregated Region Sparseness (MARS) strategy. In simpler terms, our approach strategically concentrates the attack modifications to specific areas to enhance effectiveness while maintaining stealth. To maximize the aggregation of attack-camouflaged regions, an aggregation regularization term is designed to constrain the mask aggregation matrix based on the face-adjacency relationships. To minimize the attack camouflage regions, a sparseness regularization is designed to make the mask weights tend toward a U-shaped distribution and limit extreme values. Additionally, neural rendering is used to obtain gradient-propagating multi-angle augmented data and suppress the model\u2019s detection to locate universal critical decision regions from multiple angles. These technical strategies ensure that the adversarial modifications remain effective across different viewpoints and conditions. We test the attack effectiveness of different region selection strategies. On the CARLA dataset, the average attack efficiency of attacking the YOLOv3 and v5 series networks reaches 1.724, which represents an improvement of 0.986 (134%) compared to baseline methods. These results demonstrate a significant enhancement in attack performance, highlighting the potential risks to real-world object detection systems. The experimental results demonstrate that our attack method achieves both stealth and aggressiveness from different viewpoints. Furthermore, we explore the transferability of the decision regions. The results indicate that our method can be effectively combined with different texture optimization methods, with the average precision decreasing by 0.488 and 0.662 across different networks, which indicates a strong attack effectiveness.<\/jats:p>","DOI":"10.3390\/jimaging11010025","type":"journal-article","created":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T03:29:43Z","timestamp":1736825383000},"page":"25","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Local Adversarial Attack with a Maximum Aggregated Region Sparseness Strategy for 3D Objects"],"prefix":"10.3390","volume":"11","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6103-1113","authenticated-orcid":false,"given":"Ling","family":"Zhao","sequence":"first","affiliation":[{"name":"Department of School of Geosciences and Info-Physics, Central South University, Changsha 410083, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xun","family":"Lv","sequence":"additional","affiliation":[{"name":"Department of School of Geosciences and Info-Physics, Central South University, Changsha 410083, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lili","family":"Zhu","sequence":"additional","affiliation":[{"name":"Department of Hunan Provincial Institute of Land and Resources Planning, Hunan Key Laboratory of Land Resources Evaluation and Utilization, Changsha 410083, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-8946-6848","authenticated-orcid":false,"given":"Binyan","family":"Luo","sequence":"additional","affiliation":[{"name":"Department of School of Geosciences and Info-Physics, Central South University, Changsha 410083, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hang","family":"Cao","sequence":"additional","affiliation":[{"name":"Department of School of Geosciences and Info-Physics, Central South University, Changsha 410083, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiahao","family":"Cui","sequence":"additional","affiliation":[{"name":"Department of School of Geosciences and Info-Physics, Central South University, Changsha 410083, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1173-6593","authenticated-orcid":false,"given":"Haifeng","family":"Li","sequence":"additional","affiliation":[{"name":"Department of School of Geosciences and Info-Physics, Central South University, Changsha 410083, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1820-4015","authenticated-orcid":false,"given":"Jian","family":"Peng","sequence":"additional","affiliation":[{"name":"Department of Precision Instrument, Tsinghua University, Beijing 100084, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,1,13]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Chen, A., Zhang, K., Zhang, R., Wang, Z., Lu, Y., Guo, Y., and Zhang, S. (2023, January 17\u201324). Pimae: Point cloud and image interactive masked autoencoders for 3d object detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPR52729.2023.00512"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Feng, C., Jie, Z., Zhong, Y., Chu, X., and Ma, L. (2023, January 17\u201324). Aedet: Azimuth-invariant multi-view 3d object detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPR52729.2023.02067"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","article-title":"Threat of adversarial attacks on deep learning in computer vision: A survey","volume":"6","author":"Akhtar","year":"2018","journal-title":"IEEE Access"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Xiong, K., Gong, S., Ye, X., Tan, X., Wan, J., Ding, E., Wang, J., and Bai, X. (2023, January 17\u201324). Cape: Camera view position embedding for multi-view 3d object detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPR52729.2023.02066"},{"key":"ref_5","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2016). Adversarial machine learning at scale. arXiv."},{"key":"ref_6","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv."},{"key":"ref_7","first-page":"40786","article-title":"BIRD: Generalizable backdoor detection and removal for deep reinforcement learning","volume":"36","author":"Chen","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Hu, Z., Huang, S., Zhu, X., Sun, F., Zhang, B., and Hu, X. (2022, January 18\u201324). Adversarial texture for fooling person detectors in the physical world. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.01295"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Zheng, J., Lin, C., Sun, J., Zhao, Z., Li, Q., and Shen, C. (2024, January 16\u201322). Physical 3D adversarial attacks against monocular depth estimation in autonomous driving. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR52733.2024.02308"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I.J., and Bengio, S. (2018). Adversarial examples in the physical world. Artificial Intelligence Safety and Security, Chapman and Hall\/CRC.","DOI":"10.1201\/9781351251389-8"},{"key":"ref_11","unstructured":"Mosbach, M., Andriushchenko, M., Trost, T., Hein, M., and Klakow, D. (2018). Logit pairing methods can fool gradient-based attacks. arXiv."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Suryanto, N., Kim, Y., Kang, H., Larasati, H.T., Yun, Y., Le, T.T.H., Yang, H., Oh, S.Y., and Kim, H. (2022, January 18\u201324). Dta: Physical camouflage attacks using differentiable transformation network. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.01487"},{"key":"ref_13","unstructured":"Wang, D., Jiang, T., Sun, J., Zhou, W., Gong, Z., Zhang, X., Yao, W., and Chen, X. (March, January 28). Fca: Learning a 3d full-coverage vehicle camouflage for multi-view physical adversarial attack. Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, BC, Canada."},{"key":"ref_14","unstructured":"Zhang, Y., Foroosh, H., David, P., and Gong, B. (2018, January 2\u20137). CAMOU: Learning physical vehicle camouflages to adversarially attack detectors in the wild. Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"5632418","DOI":"10.1109\/TGRS.2024.3428360","article-title":"Adversarial Examples for Vehicle Detection with Projection Transformation","volume":"62","author":"Cui","year":"2024","journal-title":"IEEE Trans. Geosci. Remote Sens."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Komkov, S., and Petiushko, A. (2021, January 10\u201315). Advhat: Real-world adversarial attack on arcface face id system. Proceedings of the IEEE 2020 25th International Conference on Pattern Recognition (ICPR), Milan, Italy.","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Nguyen, D.L., Arora, S.S., Wu, Y., and Yang, H. (2020, January 14\u201319). Adversarial light projection attacks on face recognition systems: A feasibility study. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, Seattle, WA, USA.","DOI":"10.1109\/CVPRW50498.2020.00415"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Pautov, M., Melnikov, G., Kaziakhmedov, E., Kireev, K., and Petiushko, A. (2019, January 21\u201327). On adversarial patches: Real-world attack on arcface-100 face recognition system. Proceedings of the IEEE 2019 International Multi-Conference on Engineering, Computer and Information Sciences (SIBIRCON), Novosibirsk, Russia.","DOI":"10.1109\/SIBIRCON48586.2019.8958134"},{"key":"ref_19","unstructured":"Chen, S.T., Cornelius, C., Martin, J., and Chau, D.H. (2018, January 10\u201314). Shapeshifter: Robust physical adversarial attack on faster r-cnn object detector. Proceedings of the Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2018, Dublin, Ireland. Part I 18."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Sharif, M., Bhagavatula, S., Bauer, L., and Reiter, M.K. (2016, January 24\u201328). Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition. Proceedings of the 2016 ACM Sigsac Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978392"},{"key":"ref_21","first-page":"9041","article-title":"Simultaneously optimizing perturbations and positions for black-box adversarial patch attacks","volume":"5","author":"Wei","year":"2022","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Abdelfattah, M., Yuan, K., Wang, Z.J., and Ward, R. (October, January 27). Adversarial attacks on camera-lidar models for 3d car detection. Proceedings of the 2021 IEEE\/RSJ International Conference on Intelligent Robots and Systems (IROS), Prague, Czech Republic.","DOI":"10.1109\/IROS51168.2021.9636638"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Tu, J., Ren, M., Manivasagam, S., Liang, M., Yang, B., Du, R., Cheng, F., and Urtasun, R. (2020, January 14\u201319). Physically realizable adversarial examples for lidar object detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.01373"},{"key":"ref_24","unstructured":"Brown, T.B., Man\u00e9, D., Roy, A., Abadi, M., and Gilmer, J. (2017). Adversarial patch. arXiv."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Ding, L., Wang, Y., Yuan, K., Jiang, M., Wang, P., Huang, H., and Wang, Z.J. (2021, January 2\u20139). Towards universal physical attacks on single object tracking. Proceedings of the AAAI Conference on Artificial Intelligence, Virtually.","DOI":"10.1609\/aaai.v35i2.16211"},{"key":"ref_26","unstructured":"Liu, A., Liu, X., Fan, J., Ma, Y., Zhang, A., Xie, H., and Tao, D. (27\u20131, January 27). Perceptual-sensitive gan for generating adversarial patches. Proceedings of the AAAI Conference on Artificial Intelligence, Honolulu, HI, USA."},{"key":"ref_27","unstructured":"Liu, A., Guo, J., Wang, J., Liang, S., Tao, R., Zhou, W., Liu, C., Liu, X., and Tao, D. (2023). X-adv: Physical adversarial object attacks against x-ray prohibited item detection. arXiv."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1109\/MCS.2006.1580148","article-title":"Robust advanced PID control (RaPID): PID tuning based on engineering specifications","volume":"26","author":"Oviedo","year":"2006","journal-title":"IEEE Control Syst. Mag."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2984","DOI":"10.1109\/TPAMI.2020.3044712","article-title":"Geometry-aware generation of adversarial point clouds","volume":"44","author":"Wen","year":"2020","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Duan, R., Mao, X., Qin, A.K., Chen, Y., Ye, S., He, Y., and Yang, Y. (2021, January 19\u201325). Adversarial laser beam: Effective physical-world attack to dnns in a blink. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Virtually.","DOI":"10.1109\/CVPR46437.2021.01580"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Gnanasambandam, A., Sherman, A.M., and Chan, S.H. (2021, January 11\u201317). Optical adversarial attack. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Virtually.","DOI":"10.1109\/ICCVW54120.2021.00016"},{"key":"ref_32","unstructured":"Nichols, N., and Jasper, R. (2018). Projecting trouble: Light based adversarial attacks on deep learning classifiers. arXiv."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Duan, Y., Chen, J., Zhou, X., Zou, J., He, Z., Zhang, W., and Pan, Z. (2021). Dpa: Learning robust physical adversarial camouflages for object detectors. arXiv.","DOI":"10.24963\/ijcai.2022\/125"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Huang, L., Gao, C., Zhou, Y., Xie, C., Yuille, A.L., Zou, C., and Liu, N. (2020, January 14\u201319). Universal physical camouflage attacks on object detectors. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Wen, R., Wang, J., Wu, C., and Xiong, J. Asa: Adversary situation awareness via heterogeneous graph convolutional networks. Proceedings of the Companion Proceedings of the Web Conference 2020, Taipei, Taiwan, 20\u201324 April 2020.","DOI":"10.1145\/3366424.3391266"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"5610426","DOI":"10.1109\/TGRS.2023.3276853","article-title":"Self-supervised remote sensing feature learning: Learning paradigms, challenges, and future works","volume":"61","author":"Tao","year":"2023","journal-title":"IEEE Trans. Geosci. Remote Sens."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"5626814","DOI":"10.1109\/TGRS.2023.3336285","article-title":"GraSS: Contrastive Learning With Gradient-Guided Sampling Strategy for Remote Sensing Image Semantic Segmentation","volume":"61","author":"Zhang","year":"2023","journal-title":"IEEE Trans. Geosci. Remote Sens."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"16439","DOI":"10.1109\/TNNLS.2023.3294495","article-title":"Lifelong learning with cycle memory networks","volume":"35","author":"Peng","year":"2023","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"120916","DOI":"10.1016\/j.ins.2024.120916","article-title":"CAT: A Causal Graph Attention Network for Trimming Heterophilic Graphs","volume":"677","author":"He","year":"2024","journal-title":"Inf. Sci."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"294","DOI":"10.1016\/j.isprsjprs.2024.09.009","article-title":"Homogeneous Tokenizer Matters: Homogeneous Visual Tokenizer for Remote Sensing Image Understanding","volume":"18","author":"Shao","year":"2024","journal-title":"ISPRS J. Photogramm. Remote Sens."},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"11157","DOI":"10.1109\/TNNLS.2023.3248871","article-title":"Augmentation-free graph contrastive learning of invariant-discriminative representations","volume":"35","author":"Li","year":"2023","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"15055","DOI":"10.1109\/TITS.2021.3136287","article-title":"KST-GCN: A knowledge-driven spatial-temporal graph convolutional network for traffic forecasting","volume":"23","author":"Zhu","year":"2022","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"111637","DOI":"10.1016\/j.knosys.2024.111637","article-title":"LSTTN: A Long-Short Term Transformer-based spatiotemporal neural network for traffic flow forecasting","volume":"293","author":"Luo","year":"2024","journal-title":"Knowl.-Based Syst."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"128913","DOI":"10.1016\/j.physa.2023.128913","article-title":"STGC-GNNs: A GNN-based traffic prediction framework with a spatial\u2013temporal Granger causality graph","volume":"623","author":"He","year":"2023","journal-title":"Phys. A Stat. Mech. Its Appl."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Shao, R., Yang, C., Li, Q., Xu, L., Yang, X., Li, X., Li, M., Zhu, Q., Zhang, Y., and Li, Y. (2025). AllSpark: A Multimodal Spatio-Temporal General Intelligence Model with Ten Modalities via Language as a Reference Framework. IEEE Trans. Geosci. Remote Sens., 1.","DOI":"10.1109\/TGRS.2025.3526725"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"9797","DOI":"10.1109\/TPAMI.2024.3430860","article-title":"Physical adversarial attack meets computer vision: A decade survey","volume":"46","author":"Wei","year":"2024","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Akhtar, Z. (2023). Deepfakes generation and detection: A short survey. J. Imaging, 9.","DOI":"10.3390\/jimaging9010018"},{"key":"ref_48","unstructured":"Tsai, T., Yang, K., Ho, T.Y., and Jin, Y. (2020, January 7\u201312). Robust adversarial objects against deep learning models. Proceedings of the AAAI Conference on Artificial Intelligence, New York, NY, USA."},{"key":"ref_49","unstructured":"Lee, K., Chen, Z., Yan, X., Urtasun, R., and Yumer, E. (2020). Shapeadv: Generating shape-aware adversarial 3d point clouds. arXiv."},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Liu, D., Yu, R., and Su, H. (2019, January 22\u201325). Extending adversarial attacks and defenses to deep 3d point cloud classifiers. Proceedings of the 2019 IEEE International Conference on Image Processing (ICIP), Taipei, Taiwan.","DOI":"10.1109\/ICIP.2019.8803770"},{"key":"ref_51","unstructured":"Kotuliak, M., Schoenborn, S.E., and Dan, A. (2020). Synthesizing unrestricted false positive adversarial objects using generative models. arXiv."},{"key":"ref_52","unstructured":"Cao, Y., Xiao, C., Yang, D., Fang, J., Yang, R., Liu, M., and Li, B. (2019). Adversarial objects against lidar-based autonomous driving systems. arXiv."},{"key":"ref_53","unstructured":"Hu, C., and Shi, W. (2022). Adversarial zoom lens: A novel physical-world attack to dnns. arXiv."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Zolfi, A., Kravchik, M., Elovici, Y., and Shabtai, A. (2021, January 19\u201325). The translucent patch: A physical and universal attack on object detectors. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Virtually.","DOI":"10.1109\/CVPR46437.2021.01498"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Li, Y., Li, Y., Dai, X., Guo, S., and Xiao, B. (2023, January 17\u201324). Physical-world optical adversarial attacks on 3d face recognition. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPR52729.2023.02366"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"103345","DOI":"10.1016\/j.cose.2023.103345","article-title":"Light can be dangerous: Stealthy and effective physical-world adversarial attack by spot light","volume":"132","author":"Yufeng","year":"2023","journal-title":"Comput. Secur."},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Zhong, Y., Liu, X., Zhai, D., Jiang, J., and Ji, X. (2022, January 18\u201324). Shadows can be dangerous: Stealthy and effective physical-world adversarial attack by natural phenomenon. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.01491"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Wang, D., Yao, W., Jiang, T., Li, C., and Chen, X. (2023, January 4\u20136). Rfla: A stealthy reflected light adversarial attack in the physical world. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Paris, France.","DOI":"10.1109\/ICCV51070.2023.00411"},{"key":"ref_59","first-page":"2711","article-title":"Adversarial sticker: A stealthy attack method in the physical world","volume":"45","author":"Wei","year":"2022","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"Wang, J., Liu, A., Yin, Z., Liu, S., Tang, S., and Liu, X. (2021, January 19\u201325). Dual attention suppression attack: Generate adversarial camouflage in physical world. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Virtually.","DOI":"10.1109\/CVPR46437.2021.00846"},{"key":"ref_61","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1145\/1275808.1276427","article-title":"Rendering for an interactive 360 light field display","volume":"Volume 26","author":"Jones","year":"2007","journal-title":"ACM SIGGRAPH 2007 Papers"},{"key":"ref_62","doi-asserted-by":"crossref","unstructured":"Su, H., Qi, C.R., Li, Y., and Guibas, L.J. (2015, January 7\u201313). Render for cnn: Viewpoint estimation in images using cnns trained with rendered 3D model views. Proceedings of the IEEE International Conference on Computer Vision, Santiago, Chile.","DOI":"10.1109\/ICCV.2015.308"},{"key":"ref_63","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3272127.3275055","article-title":"Differentiable Monte Carlo ray tracing through edge sampling","volume":"37","author":"Li","year":"2018","journal-title":"ACM Trans. Graph. (TOG)"},{"key":"ref_64","doi-asserted-by":"crossref","unstructured":"Loper, M.M., and Black, M.J. (2014, January 6\u201312). OpenDR: An approximate differentiable renderer. Proceedings of the Computer Vision-ECCV 2014, Zurich, Switzerland. Part VII 13.","DOI":"10.1007\/978-3-319-10584-0_11"},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3355089.3356510","article-title":"Reparameterizing discontinuous integrands for differentiable rendering","volume":"38","author":"Loubet","year":"2019","journal-title":"ACM Trans. Graph. (TOG)"},{"key":"ref_66","unstructured":"Athalye, A., Engstrom, L., Ilyas, A., and Kwok, K. (2018, January 10\u201315). Synthesizing robust adversarial examples. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_67","unstructured":"Wu, X., Wang, X., Zhou, X., and Jian, S. (2019). STA: Adversarial attacks on Siamese trackers. arXiv."},{"key":"ref_68","doi-asserted-by":"crossref","unstructured":"Kato, H., Ushiku, Y., and Harada, T. (2017, January 21\u201326). Neural 3d mesh renderer. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2018.00411"},{"key":"ref_69","unstructured":"Xiao, C., Yang, D., Li, B., Deng, J., and Liu, M. (2018, January 18\u201322). Meshadv: Adversarial meshes for visual recognition. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA."},{"key":"ref_70","unstructured":"Yang, D., Xiao, C., Li, B., Deng, J., and Liu, M. (2018). Realistic adversarial examples in 3d meshes. arXiv."},{"key":"ref_71","unstructured":"Kolotouros, N. (2025, January 08). Pytorch Implememtation of the Neural Mesh Renderer. Available online: https:\/\/scholar.google.fr\/citations?view_op=view_citation&hl=zh-CN&user=397EbTsAAAAJ&citation_for_view=397EbTsAAAAJ:WF5omc3nYNoC."},{"key":"ref_72","unstructured":"Liu, H.T.D., Tao, M., Li, C.L., Nowrouzezahrai, D., and Jacobson, A. (2018). Adversarial geometry and lighting using a differentiable renderer. CoRR."},{"key":"ref_73","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3306346.3322974","article-title":"Mitsuba 2: A retargetable forward and inverse renderer","volume":"38","author":"Vicini","year":"2019","journal-title":"ACM Trans. Graph. (TOG)"},{"key":"ref_74","unstructured":"Paszke, A., Gross, S., Chintala, S., Chanan, G., Yang, E., DeVito, Z., Lin, Z., Desmaison, A., Antiga, L., and Lerer, A. (,  2017). Automatic differentiation in pytorch. Proceedings of the NIPS 2017 Workshop Autodiff Submission, Available online: https:\/\/openreview.net\/forum?id=BJJsrmfCZ."},{"key":"ref_75","unstructured":"Dosovitskiy, A., Ros, G., Codevilla, F., Lopez, A., and Koltun, V. (2017, January 11\u201313). CARLA: An open urban driving simulator. Proceedings of the Conference on Robot Learning, Sydney, NSW, Australia."}],"container-title":["Journal of Imaging"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2313-433X\/11\/1\/25\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T10:28:09Z","timestamp":1759919289000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2313-433X\/11\/1\/25"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,13]]},"references-count":75,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,1]]}},"alternative-id":["jimaging11010025"],"URL":"https:\/\/doi.org\/10.3390\/jimaging11010025","relation":{},"ISSN":["2313-433X"],"issn-type":[{"value":"2313-433X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,13]]}}}