{"id":"https://openalex.org/W4364297112","doi":"https://doi.org/10.1109/aipr57179.2022.10092200","title":"Detecting Physical Adversarial Patch Attacks with Object Detectors","display_name":"Detecting Physical Adversarial Patch Attacks with Object Detectors","publication_year":2022,"publication_date":"2022-10-11","ids":{"openalex":"https://openalex.org/W4364297112","doi":"https://doi.org/10.1109/aipr57179.2022.10092200"},"language":"en","primary_location":{"id":"doi:10.1109/aipr57179.2022.10092200","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1109/aipr57179.2022.10092200","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Applied Imagery Pattern Recognition Workshop (AIPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048164746","display_name":"Melanie Jutras","orcid":"https://orcid.org/0009-0004-0758-6718"},"institutions":[{"id":"https://openalex.org/I44896327","display_name":"Mitre (United States)","ror":"https://ror.org/03ks2a131","country_code":"US","type":"company","lineage":["https://openalex.org/I44896327"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Melanie Jutras","raw_affiliation_strings":["Ops Research MITRE,Bedford,Massachusetts,USA","Ops Research MITRE, Bedford, Massachusetts, USA"],"affiliations":[{"raw_affiliation_string":"Ops Research MITRE,Bedford,Massachusetts,USA","institution_ids":["https://openalex.org/I44896327"]},{"raw_affiliation_string":"Ops Research MITRE, Bedford, Massachusetts, USA","institution_ids":["https://openalex.org/I44896327"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034175389","display_name":"Ethan Liang","orcid":"https://orcid.org/0000-0002-6851-6981"},"institutions":[{"id":"https://openalex.org/I4210142635","display_name":"PATH To Reading","ror":"https://ror.org/0482xmh13","country_code":"US","type":"other","lineage":["https://openalex.org/I4210142635"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ethan Liang","raw_affiliation_strings":["AI Security and Perception MITRE,San Diego,California,USA","AI Security and Perception MITRE, San Diego, California, USA"],"affiliations":[{"raw_affiliation_string":"AI Security and Perception MITRE,San Diego,California,USA","institution_ids":["https://openalex.org/I4210142635"]},{"raw_affiliation_string":"AI Security and Perception MITRE, San Diego, California, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039098491","display_name":"Sara Leary","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Sara Leary","raw_affiliation_strings":["Advanced Processing &#x0026; Exploitation Tech MITRE,McLean,Virginia,USA"],"affiliations":[{"raw_affiliation_string":"Advanced Processing &#x0026; Exploitation Tech MITRE,McLean,Virginia,USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005283589","display_name":"Chris M. Ward","orcid":null},"institutions":[{"id":"https://openalex.org/I4210142635","display_name":"PATH To Reading","ror":"https://ror.org/0482xmh13","country_code":"US","type":"other","lineage":["https://openalex.org/I4210142635"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Chris Ward","raw_affiliation_strings":["AI Security and Perception MITRE,San Diego,California,USA","AI Security and Perception MITRE, San Diego, California, USA"],"affiliations":[{"raw_affiliation_string":"AI Security and Perception MITRE,San Diego,California,USA","institution_ids":["https://openalex.org/I4210142635"]},{"raw_affiliation_string":"AI Security and Perception MITRE, San Diego, California, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5059827146","display_name":"Keith Manville","orcid":null},"institutions":[{"id":"https://openalex.org/I44896327","display_name":"Mitre (United States)","ror":"https://ror.org/03ks2a131","country_code":"US","type":"company","lineage":["https://openalex.org/I44896327"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Keith Manville","raw_affiliation_strings":["AI Security and Perception MITRE,McLean,Virginia,USA","AI Security and Perception MITRE, McLean, Virginia, USA"],"affiliations":[{"raw_affiliation_string":"AI Security and Perception MITRE,McLean,Virginia,USA","institution_ids":["https://openalex.org/I44896327"]},{"raw_affiliation_string":"AI Security and Perception MITRE, McLean, Virginia, USA","institution_ids":["https://openalex.org/I44896327"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5048164746"],"corresponding_institution_ids":["https://openalex.org/I44896327"],"apc_list":null,"apc_paid":null,"fwci":0.2652,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.63679753,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"7"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9886000156402588,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9825999736785889,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.9172405004501343},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.83072829246521},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.7221226692199707},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6089656352996826},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.5597639083862305},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5528148412704468},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.5238290429115295},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5166033506393433},{"id":"https://openalex.org/keywords/object","display_name":"Object (grammar)","score":0.49075254797935486},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.4605637192726135},{"id":"https://openalex.org/keywords/physical-security","display_name":"Physical security","score":0.44367411732673645},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.41912174224853516},{"id":"https://openalex.org/keywords/detector","display_name":"Detector","score":0.41116583347320557},{"id":"https://openalex.org/keywords/object-detection","display_name":"Object detection","score":0.411003977060318},{"id":"https://openalex.org/keywords/human\u2013computer-interaction","display_name":"Human\u2013computer interaction","score":0.347654789686203},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.1721435785293579}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.9172405004501343},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.83072829246521},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.7221226692199707},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6089656352996826},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.5597639083862305},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5528148412704468},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.5238290429115295},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5166033506393433},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.49075254797935486},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.4605637192726135},{"id":"https://openalex.org/C2776157020","wikidata":"https://www.wikidata.org/wiki/Q851598","display_name":"Physical security","level":2,"score":0.44367411732673645},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.41912174224853516},{"id":"https://openalex.org/C94915269","wikidata":"https://www.wikidata.org/wiki/Q1834857","display_name":"Detector","level":2,"score":0.41116583347320557},{"id":"https://openalex.org/C2776151529","wikidata":"https://www.wikidata.org/wiki/Q3045304","display_name":"Object detection","level":3,"score":0.411003977060318},{"id":"https://openalex.org/C107457646","wikidata":"https://www.wikidata.org/wiki/Q207434","display_name":"Human\u2013computer interaction","level":1,"score":0.347654789686203},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.1721435785293579},{"id":"https://openalex.org/C120665830","wikidata":"https://www.wikidata.org/wiki/Q14620","display_name":"Optics","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/aipr57179.2022.10092200","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1109/aipr57179.2022.10092200","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Applied Imagery Pattern Recognition Workshop (AIPR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","score":0.6600000262260437,"id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":36,"referenced_works":["https://openalex.org/W639708223","https://openalex.org/W1673923490","https://openalex.org/W2243397390","https://openalex.org/W2535873859","https://openalex.org/W2890054895","https://openalex.org/W2890883923","https://openalex.org/W2902867332","https://openalex.org/W2943642558","https://openalex.org/W2952716587","https://openalex.org/W2953610242","https://openalex.org/W2963302614","https://openalex.org/W2963857521","https://openalex.org/W2988535323","https://openalex.org/W3017485054","https://openalex.org/W3035182590","https://openalex.org/W3090358134","https://openalex.org/W3094984771","https://openalex.org/W3105806188","https://openalex.org/W3107956775","https://openalex.org/W3108360118","https://openalex.org/W3138047508","https://openalex.org/W3204155906","https://openalex.org/W4226232092","https://openalex.org/W4283071535","https://openalex.org/W4288363831","https://openalex.org/W4297896551","https://openalex.org/W6620707391","https://openalex.org/W6637162671","https://openalex.org/W6741036071","https://openalex.org/W6751839145","https://openalex.org/W6754363872","https://openalex.org/W6755312952","https://openalex.org/W6765410593","https://openalex.org/W6786170441","https://openalex.org/W6792389622","https://openalex.org/W6839210163"],"related_works":["https://openalex.org/W4320018150","https://openalex.org/W4239582170","https://openalex.org/W3048732067","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W4383468834","https://openalex.org/W2135200719","https://openalex.org/W4283221438","https://openalex.org/W2900159906"],"abstract_inverted_index":{"Machine":[0],"learning":[1,19],"models":[2,199],"are":[3,43],"vulnerable":[4],"to":[5,127,134,233,256],"adversarial":[6,73,97,170,183,195,214],"attacks":[7,23,42],"which":[8,109],"can":[9,24,34,91,110,144,167,230,254],"cause":[10],"integrity":[11],"violations":[12],"in":[13,27,147],"real-":[14],"world":[15,30],"systems":[16,36,70],"with":[17,172,200,243],"machine":[18,58],"components.":[20],"Alarmingly,":[21],"these":[22],"also":[25],"manifest":[26],"the":[28,64,83,106,115,118,124,227],"physical":[29,72,96],"where":[31,149],"an":[32],"adversary":[33],"disrupt":[35],"without":[37,113],"gaining":[38],"digital":[39],"access.":[40],"These":[41],"becoming":[44],"more":[45],"concerning":[46],"as":[47,51],"safety-critical":[48],"infrastructure":[49],"such":[50],"healthcare":[52],"and":[53,131,158,203,250],"transportation":[54],"increasingly":[55],"rely":[56],"on":[57,129,180,247],"learning.This":[59],"work":[60],"is":[61,139,152,188],"motivated":[62],"by":[63],"need":[65],"for":[66,78,102],"safeguarding":[67],"vision-":[68],"based":[69],"against":[71],"pattern":[74],"attacks\u2014an":[75],"important":[76],"domain":[77],"autonomous":[79],"vehicles.":[80],"We":[81],"propose":[82],"use":[84],"of":[85,105,117,190,194,211,237,260],"a":[86,135,140,150,155,192,208,258],"separate":[87,136],"detection":[88,228],"module":[89,229],"that":[90,94,143,165,224],"identify":[92,234],"inputs":[93],"contain":[95],"patterns.":[98],"This":[99,121],"approach":[100,142],"allows":[101,123],"independent":[103],"development":[104],"defensive":[107],"mechanism":[108],"be":[111,160,231],"updated":[112,232],"affecting":[114],"performance":[116,130],"protected":[119],"model.":[120],"methodology":[122],"model":[125,151],"developers":[126],"focus":[128],"leave":[132],"security":[133,146],"team.":[137],"It":[138],"practical":[141],"provide":[145],"cases":[148],"acquired":[153],"from":[154,198],"third":[156],"party":[157],"cannot":[159],"re-trained.We":[161],"perform":[162],"experimentation":[163,222],"demonstrating":[164],"we":[166,206,217,241],"detect":[168],"unknown":[169],"patterns":[171,196],"high":[173],"accuracy":[174],"using":[175],"standard":[176],"object":[177],"detectors":[178,244],"trained":[179,197,245,246],"datasets":[181,202],"containing":[182],"patches.":[184,220],"A":[185],"single":[186],"detector":[187],"capable":[189],"detecting":[191,257],"variety":[193,259],"different":[201],"tasks.":[204],"Additionally,":[205],"introduce":[207],"new":[209],"class":[210],"visually":[212],"distinct":[213],"patch":[215,238,262],"attack":[216],"call":[218],"GAN":[219],"Our":[221],"shows":[223],"once":[225],"observed":[226],"additional":[235],"classes":[236],"attacks.":[239,263],"Finally,":[240],"experiment":[242],"innocuous":[248],"patches":[249],"examine":[251],"how":[252],"they":[253],"generalize":[255],"known":[261]},"counts_by_year":[{"year":2024,"cited_by_count":2}],"updated_date":"2025-12-24T23:09:58.560324","created_date":"2025-10-10T00:00:00"}
