{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:29:20Z","timestamp":1760146160601,"version":"build-2065373602"},"reference-count":24,"publisher":"MDPI AG","issue":"19","license":[{"start":{"date-parts":[[2024,10,6]],"date-time":"2024-10-06T00:00:00Z","timestamp":1728172800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Korea Ministry of SMEs and Startups","award":["RS-2022-00140535"],"award-info":[{"award-number":["RS-2022-00140535"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Object detection systems are used in various fields such as autonomous vehicles and facial recognition. In particular, object detection using deep learning networks enables real-time processing in low-performance edge devices and can maintain high detection rates. However, edge devices that operate far from administrators are vulnerable to various physical attacks by malicious adversaries. In this paper, we implement a function for detecting traffic signs by using You Only Look Once (YOLO) as well as Faster-RCNN, which can be adopted by edge devices of autonomous vehicles. Then, assuming the role of a malicious attacker, we executed adversarial patch attacks with Adv-Patch and Dpatch. Trying to cause misdetection of traffic stop signs by using Adv-Patch and Dpatch, we confirmed the attacks can succeed with a high probability. To defeat these attacks, we propose an image reconstruction method using an autoencoder and the Structural Similarity Index Measure (SSIM). We confirm that the proposed method can sufficiently defend against an attack, attaining a mean Average Precision (mAP) of 91.46% even when two adversarial attacks are launched.<\/jats:p>","DOI":"10.3390\/s24196461","type":"journal-article","created":{"date-parts":[[2024,10,7]],"date-time":"2024-10-07T07:30:18Z","timestamp":1728286218000},"page":"6461","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["SSIM-Based Autoencoder Modeling to Defeat Adversarial Patch Attacks"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-2954-1243","authenticated-orcid":false,"given":"Seungyeol","family":"Lee","sequence":"first","affiliation":[{"name":"Department of Information Security, Hoseo University, Asan 31499, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-3173-6229","authenticated-orcid":false,"given":"Seongwoo","family":"Hong","sequence":"additional","affiliation":[{"name":"Department of Information Security, Hoseo University, Asan 31499, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9243-4697","authenticated-orcid":false,"given":"Gwangyeol","family":"Kim","sequence":"additional","affiliation":[{"name":"Sinsiway Inc., Songpa-gu, Seoul 05836, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3730-5580","authenticated-orcid":false,"given":"Jaecheol","family":"Ha","sequence":"additional","affiliation":[{"name":"Department of Information Security, Hoseo University, Asan 31499, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2024,10,6]]},"reference":[{"key":"ref_1","unstructured":"Brown, T.B., Man\u00e9m, D., Roy, A., Abadi, M., and Gilmer, J. (2017, January 8). Adversarial patch. Proceedings of the NIPS 2017 Workshop on Machine Learning and Computer Security, Long Beach, CA, USA."},{"key":"ref_2","first-page":"156","article-title":"Easily deployed stickers could disrupt traffic sign recognition","volume":"19","author":"Lengyel","year":"2019","journal-title":"Perner\u2019s Contacts"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Thys, S., Van Ranst, W., and Goedem\u00e9, T. (2019, January 16\u201317). Fooling automated surveillance cameras: Adversarial patches to attack person detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, Long Beach, CA, USA.","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref_4","unstructured":"Liu, X., Yang, H., Yang, L.Z., Song, L., Li, H., and Chen, Y. (2018, January 2\u20137). DPatch: An adversarial patch attack on object detectors. Proceedings of the AAAI Workshops, New Orleans, LA, USA."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Xiao, C., Prakash, A., Kohno, T., and Song, D. (2018, January 18\u201323). Robust physical-world attacks on deep learning visual classification. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Hu, Y.C.T., Kung, B.H., Tan, D.S., Chen, J.C., Hua, K.L., and Cheng, W.H. (2021, January 10\u201317). Naturalistic physical adversarial patch for object detectors. Proceedings of the IEEE\/CVF International Conference on Computer Vision, Montreal, QC, Canada.","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Naseer, M., Khan, S., and Porikli, F. (2019, January 7\u201311). Local gradients smoothing: Defense against localized adversarial attacks. Proceedings of the 2019 IEEE Winter Conference on Applications of Computer Vision (WACV), Waikoloa Village, HI, USA.","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.neucom.2021.12.080","article-title":"Defending against adversarial attacks using spherical sampling-based variational auto-encoder","volume":"478","author":"Yin","year":"2022","journal-title":"Neurocomputing"},{"key":"ref_9","unstructured":"Jiang, L., Alexander, L., Chun, P.L., Rama, C., and Shheil, F. (2024, January 16\u201322). Segment and complete: Defending object detectors against adversarial patch attacks with robust patch detection. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA."},{"key":"ref_10","unstructured":"Tsuruoka, G., Sato, T., Chen, Q.A., Nomoto, K., Tanaka, Y., Kobayashi, R., and Mori, T. (2024, January 19\u201323). WIP: Adversarial Retroreflective Patches: A Novel Stealthy Attack on Traffic Sign Recognition at Night. Proceedings of the Symposium on Vehicle Security and Privacy, San Francisco, CA, USA."},{"key":"ref_11","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2015, January 7\u20139). Explaining and harnessing adversarial examples. Proceedings of the International Conference on Learning Representations (ICLR\u201915), San Diego, CA, USA."},{"key":"ref_12","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017, January 24\u201326). Towards deep learning models resistant to adversarial attacks. Proceedings of the International Conference on Learning Representations (ICLR\u201918), Toulon, France."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201326). Towards evaluating the robustness of neural networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., and Frossard, P. (2016, January 27\u201330). Deepfool: A simple and accurate method to fool deep neural networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., and Swami, A. (2016, January 21\u201324). The limitations of deep learning in adversarial settings. Proceedings of the 2016 IEEE European Symposium on Security and Privacy, Saarbrucken, Germany.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Lin, X., Li, Y., Hsiao, J., Ho, C., and Kong, Y. (2023, January 17\u201324). Catch missing details: Image reconstruction with frequency augmented variational autoencoder. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada.","DOI":"10.1109\/CVPR52729.2023.00173"},{"key":"ref_17","unstructured":"Suganuma, M., Ozay, M., and Okatani, T. (2018, January 10\u201315). Exploiting the potential of standard convolutional autoencoders for image restoration by evolutionary search. Proceedings of the International Conference on Machine Learning, Stockholm, Sweden."},{"key":"ref_18","unstructured":"Mao, X.J., Shen, C., and Yang, Y.B. (2016, January 5\u201310). Image restoration using convolutional auto-encoders with symmetric skip connections. Proceedings of the Neural Information Processing Systems, Barcelona, Spain."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"600","DOI":"10.1109\/TIP.2003.819861","article-title":"Image quality assessment: From error visibility to structural similarity","volume":"13","author":"Wang","year":"2004","journal-title":"IEEE Trans. Image Process."},{"key":"ref_20","unstructured":"Song, D., Eykholt, K., Evtimov, I., Fernandes, E., Li, B., Rahmati, A., Tramer, F., Prakash, A., and Kohno, T. (2018, January 13\u201314). Physical adversarial examples for object detectors. Proceedings of the 12th USENIX Workshop on Offensive Technologies (WOOT 18), Baltimore, MD, USA."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Pavlitska, S., Lambing, N., and Z\u00f6llner, J.M. (2023, January 19\u201321). Adversarial attacks on traffic sign recognition: A survey. Proceedings of the 2023 3rd International Conference on Electrical, Computer, Communications and Mechatronics Engineering (ICECCME), Tenerife, Canary Islands, Spain.","DOI":"10.1109\/ICECCME57830.2023.10252727"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Lin, T.Y., Maire, M., Belongie, S., Hays, J., Perona, P., Ramanan, D., Doll\u00e1r, P., and Zitnick, C.L. (2014). Microsoft coco: Common objects in context. Proceedings of the Computer Vision\u2014ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6\u201312, 2014, Part V, Springer.","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1484","DOI":"10.1109\/TITS.2012.2209421","article-title":"Vision-based traffic sign detection and analysis for intelligent driver assistance systems: Perspectives and survey","volume":"13","author":"Mogelmose","year":"2012","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"ref_24","unstructured":"Ch\u00e3n, H.L. (2024, July 26). TrafficSign detection Dataset [Open Source Dataset]. Available online: https:\/\/universe.roboflow.com\/myworkspace-het5h\/trafficsigndetection\/dataset\/2."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/19\/6461\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T16:11:51Z","timestamp":1760112711000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/19\/6461"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,6]]},"references-count":24,"journal-issue":{"issue":"19","published-online":{"date-parts":[[2024,10]]}},"alternative-id":["s24196461"],"URL":"https:\/\/doi.org\/10.3390\/s24196461","relation":{},"ISSN":["1424-8220"],"issn-type":[{"type":"electronic","value":"1424-8220"}],"subject":[],"published":{"date-parts":[[2024,10,6]]}}}