{"id":"https://openalex.org/W4416252266","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228187","title":"A Physical Attack for Segmentation-Based Visual Foundation Models","display_name":"A Physical Attack for Segmentation-Based Visual Foundation Models","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4416252266","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228187"},"language":null,"primary_location":{"id":"doi:10.1109/ijcnn64981.2025.11228187","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228187","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5112898403","display_name":"Mengqi He","orcid":"https://orcid.org/0009-0004-3796-7175"},"institutions":[{"id":"https://openalex.org/I118347636","display_name":"Australian National University","ror":"https://ror.org/019wvm592","country_code":"AU","type":"education","lineage":["https://openalex.org/I118347636"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Mengqi He","raw_affiliation_strings":["Australian National University,ANU College of Systems and Society,Canberra,Australia"],"affiliations":[{"raw_affiliation_string":"Australian National University,ANU College of Systems and Society,Canberra,Australia","institution_ids":["https://openalex.org/I118347636"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086057132","display_name":"Jinhong Ni","orcid":null},"institutions":[{"id":"https://openalex.org/I118347636","display_name":"Australian National University","ror":"https://ror.org/019wvm592","country_code":"AU","type":"education","lineage":["https://openalex.org/I118347636"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Jinhong Ni","raw_affiliation_strings":["Australian National University,ANU College of Systems and Society,Canberra,Australia"],"affiliations":[{"raw_affiliation_string":"Australian National University,ANU College of Systems and Society,Canberra,Australia","institution_ids":["https://openalex.org/I118347636"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103063628","display_name":"Zhaoyuan Yang","orcid":"https://orcid.org/0009-0007-0294-4741"},"institutions":[{"id":"https://openalex.org/I1332737386","display_name":"General Electric (United States)","ror":"https://ror.org/013msgt25","country_code":"US","type":"company","lineage":["https://openalex.org/I1332737386"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zhaoyuan Yang","raw_affiliation_strings":["GE Research General Electric,New York"],"affiliations":[{"raw_affiliation_string":"GE Research General Electric,New York","institution_ids":["https://openalex.org/I1332737386"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107923354","display_name":"Yiwei Fu","orcid":null},"institutions":[{"id":"https://openalex.org/I1332737386","display_name":"General Electric (United States)","ror":"https://ror.org/013msgt25","country_code":"US","type":"company","lineage":["https://openalex.org/I1332737386"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yiwei Fu","raw_affiliation_strings":["GE Research General Electric,New York"],"affiliations":[{"raw_affiliation_string":"GE Research General Electric,New York","institution_ids":["https://openalex.org/I1332737386"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005907108","display_name":"John Karigiannis","orcid":"https://orcid.org/0009-0009-8921-1915"},"institutions":[{"id":"https://openalex.org/I1332737386","display_name":"General Electric (United States)","ror":"https://ror.org/013msgt25","country_code":"US","type":"company","lineage":["https://openalex.org/I1332737386"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"John Karigiannis","raw_affiliation_strings":["GE Vernova Advanced Research General Electric,New York"],"affiliations":[{"raw_affiliation_string":"GE Vernova Advanced Research General Electric,New York","institution_ids":["https://openalex.org/I1332737386"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5031646526","display_name":"Jing Zhang","orcid":"https://orcid.org/0000-0002-9496-4083"},"institutions":[{"id":"https://openalex.org/I118347636","display_name":"Australian National University","ror":"https://ror.org/019wvm592","country_code":"AU","type":"education","lineage":["https://openalex.org/I118347636"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Jing Zhang","raw_affiliation_strings":["Australian National University,ANU College of Systems and Society,Canberra,Australia"],"affiliations":[{"raw_affiliation_string":"Australian National University,ANU College of Systems and Society,Canberra,Australia","institution_ids":["https://openalex.org/I118347636"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5112898403"],"corresponding_institution_ids":["https://openalex.org/I118347636"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.19521824,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9765999913215637,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9765999913215637,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11448","display_name":"Face recognition and analysis","score":0.0024999999441206455,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.002300000051036477,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8770999908447266},{"id":"https://openalex.org/keywords/foundation","display_name":"Foundation (evidence)","score":0.6158000230789185},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.5045999884605408},{"id":"https://openalex.org/keywords/segmentation","display_name":"Segmentation","score":0.392300009727478},{"id":"https://openalex.org/keywords/action","display_name":"Action (physics)","score":0.3765000104904175},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.3553999960422516},{"id":"https://openalex.org/keywords/space","display_name":"Space (punctuation)","score":0.3481000065803528}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8770999908447266},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6366000175476074},{"id":"https://openalex.org/C2780966255","wikidata":"https://www.wikidata.org/wiki/Q5474306","display_name":"Foundation (evidence)","level":2,"score":0.6158000230789185},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.5045999884605408},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.47609999775886536},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.41119998693466187},{"id":"https://openalex.org/C89600930","wikidata":"https://www.wikidata.org/wiki/Q1423946","display_name":"Segmentation","level":2,"score":0.392300009727478},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.3765000104904175},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.3553999960422516},{"id":"https://openalex.org/C2778572836","wikidata":"https://www.wikidata.org/wiki/Q380933","display_name":"Space (punctuation)","level":2,"score":0.3481000065803528},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.30169999599456787},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.2955999970436096},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.2912999987602234},{"id":"https://openalex.org/C83665646","wikidata":"https://www.wikidata.org/wiki/Q42139305","display_name":"Feature vector","level":2,"score":0.2732999920845032},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.2639999985694885},{"id":"https://openalex.org/C2776157020","wikidata":"https://www.wikidata.org/wiki/Q851598","display_name":"Physical security","level":2,"score":0.25290000438690186}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn64981.2025.11228187","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228187","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":50,"referenced_works":["https://openalex.org/W1915485278","https://openalex.org/W2180612164","https://openalex.org/W2243397390","https://openalex.org/W2340897893","https://openalex.org/W2535873859","https://openalex.org/W2543927648","https://openalex.org/W2746600820","https://openalex.org/W2765424254","https://openalex.org/W2787091153","https://openalex.org/W2798302089","https://openalex.org/W2905311601","https://openalex.org/W2905423756","https://openalex.org/W2932026309","https://openalex.org/W2963448658","https://openalex.org/W2963542245","https://openalex.org/W2963726920","https://openalex.org/W2963857521","https://openalex.org/W2969664989","https://openalex.org/W2985390828","https://openalex.org/W3035447895","https://openalex.org/W3097573595","https://openalex.org/W3104218734","https://openalex.org/W3107990944","https://openalex.org/W3112265985","https://openalex.org/W3174032462","https://openalex.org/W3175451538","https://openalex.org/W3176380844","https://openalex.org/W3185095134","https://openalex.org/W3196107314","https://openalex.org/W3200450146","https://openalex.org/W3202707779","https://openalex.org/W3211490618","https://openalex.org/W3215515227","https://openalex.org/W4213360524","https://openalex.org/W4221139075","https://openalex.org/W4225786036","https://openalex.org/W4282936640","https://openalex.org/W4293846201","https://openalex.org/W4312248169","https://openalex.org/W4312420092","https://openalex.org/W4312918928","https://openalex.org/W4386066565","https://openalex.org/W4386076048","https://openalex.org/W4386076093","https://openalex.org/W4386083027","https://openalex.org/W4390872973","https://openalex.org/W4390873795","https://openalex.org/W4390874575","https://openalex.org/W4394598007","https://openalex.org/W4404612908"],"related_works":[],"abstract_inverted_index":{"We":[0,32],"formalize":[1],"a":[2,50,82],"threat":[3],"model":[4],"for":[5],"general":[6],"patch-based":[7,51],"attacks":[8,94],"on":[9,60,95],"visual":[10],"foundation":[11],"models":[12],"(VFMs),":[13],"highlighting":[14],"the":[15,23,66,73,77,89],"strong":[16],"assumptions":[17],"made":[18],"by":[19],"previous":[20],"approaches":[21],"regarding":[22],"proximity":[24],"of":[25,30,69],"adversarial":[26,74,93],"patches":[27],"to":[28,39,41,113],"objects":[29],"interest.":[31],"demonstrate":[33],"that":[34,55,102],"these":[35,46,61],"methods":[36],"often":[37],"fail":[38],"generalize":[40],"physical":[42,52,92],"domains.":[43],"To":[44],"address":[45],"limitations,":[47],"we":[48,80],"propose":[49],"attack":[53,115],"method":[54,87],"targets":[56],"VFMs":[57,70],"without":[58],"relying":[59],"assumptions.":[62],"By":[63],"operating":[64],"in":[65,76,116],"feature":[67],"space":[68],"and":[71,109],"excluding":[72],"patch":[75],"optimization":[78],"objective,":[79],"ensure":[81],"more":[83],"robust":[84],"attack.":[85],"Our":[86],"achieves":[88],"first":[90],"successful":[91],"segmentation-based":[96],"VFMs,":[97,105],"with":[98],"empirical":[99],"results":[100],"showing":[101],"transformer-based":[103],"segmentation":[104],"including":[106],"SAM,":[107],"SEEM,":[108],"CLIPSeg,":[110],"are":[111],"vulnerable":[112],"our":[114],"real-world":[117],"scenarios.":[118]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-11-14T00:00:00"}
