{"id":"https://openalex.org/W3154333995","doi":"https://doi.org/10.1145/3474085.3475378","title":"Towards Adversarial Patch Analysis and Certified Defense against Crowd Counting","display_name":"Towards Adversarial Patch Analysis and Certified Defense against Crowd Counting","publication_year":2021,"publication_date":"2021-10-17","ids":{"openalex":"https://openalex.org/W3154333995","doi":"https://doi.org/10.1145/3474085.3475378","mag":"3154333995"},"language":"en","primary_location":{"id":"doi:10.1145/3474085.3475378","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3474085.3475378","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 29th ACM International Conference on Multimedia","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2104.10868","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Qiming Wu","orcid":null},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Qiming Wu","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Zhikang Zou","orcid":null},"institutions":[{"id":"https://openalex.org/I98301712","display_name":"Baidu (China)","ror":"https://ror.org/03vs3wt56","country_code":"CN","type":"company","lineage":["https://openalex.org/I98301712"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhikang Zou","raw_affiliation_strings":["Baidu Inc., Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Baidu Inc., Shenzhen, China","institution_ids":["https://openalex.org/I98301712"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Pan Zhou","orcid":null},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Pan Zhou","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Xiaoqing Ye","orcid":null},"institutions":[{"id":"https://openalex.org/I98301712","display_name":"Baidu (China)","ror":"https://ror.org/03vs3wt56","country_code":"CN","type":"company","lineage":["https://openalex.org/I98301712"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaoqing Ye","raw_affiliation_strings":["Baidu Inc., Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Baidu Inc., Shanghai, China","institution_ids":["https://openalex.org/I98301712"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Binghui Wang","orcid":null},"institutions":[{"id":"https://openalex.org/I180949307","display_name":"Illinois Institute of Technology","ror":"https://ror.org/037t3ry66","country_code":"US","type":"education","lineage":["https://openalex.org/I180949307"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Binghui Wang","raw_affiliation_strings":["Illinois Institute of Technology, Chicago, IL, USA"],"affiliations":[{"raw_affiliation_string":"Illinois Institute of Technology, Chicago, IL, USA","institution_ids":["https://openalex.org/I180949307"]}]},{"author_position":"last","author":{"id":null,"display_name":"Ang Li","orcid":null},"institutions":[{"id":"https://openalex.org/I170897317","display_name":"Duke University","ror":"https://ror.org/00py81415","country_code":"US","type":"education","lineage":["https://openalex.org/I170897317"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ang Li","raw_affiliation_strings":["Duke University, Durham, NC, USA"],"affiliations":[{"raw_affiliation_string":"Duke University, Durham, NC, USA","institution_ids":["https://openalex.org/I170897317"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":["https://openalex.org/I47720641"],"apc_list":null,"apc_paid":null,"fwci":0.14,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.52946072,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"2195","last_page":"2204"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.996999979019165,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.89410001039505},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6836000084877014},{"id":"https://openalex.org/keywords/generality","display_name":"Generality","score":0.5669999718666077},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.42879998683929443},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4156999886035919},{"id":"https://openalex.org/keywords/binary-number","display_name":"Binary number","score":0.3828999996185303},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.3763999938964844}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.89410001039505},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6859999895095825},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6836000084877014},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5885999798774719},{"id":"https://openalex.org/C2780767217","wikidata":"https://www.wikidata.org/wiki/Q5532421","display_name":"Generality","level":2,"score":0.5669999718666077},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.42879998683929443},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4156999886035919},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.40459999442100525},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.39239999651908875},{"id":"https://openalex.org/C48372109","wikidata":"https://www.wikidata.org/wiki/Q3913","display_name":"Binary number","level":2,"score":0.3828999996185303},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.3763999938964844},{"id":"https://openalex.org/C87007009","wikidata":"https://www.wikidata.org/wiki/Q210832","display_name":"Statistical hypothesis testing","level":2,"score":0.3474000096321106},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.3384000062942505},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.3206000030040741},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.31619998812675476},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.27559998631477356},{"id":"https://openalex.org/C191795146","wikidata":"https://www.wikidata.org/wiki/Q3878446","display_name":"Norm (philosophy)","level":2,"score":0.2678000032901764},{"id":"https://openalex.org/C66905080","wikidata":"https://www.wikidata.org/wiki/Q17005494","display_name":"Binary classification","level":3,"score":0.26579999923706055},{"id":"https://openalex.org/C149441793","wikidata":"https://www.wikidata.org/wiki/Q200726","display_name":"Probability distribution","level":2,"score":0.2646999955177307}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3474085.3475378","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3474085.3475378","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 29th ACM International Conference on Multimedia","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2104.10868","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2104.10868","pdf_url":"https://arxiv.org/pdf/2104.10868","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2104.10868","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2104.10868","pdf_url":"https://arxiv.org/pdf/2104.10868","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5817064308","display_name":null,"funder_award_id":"61972448","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":28,"referenced_works":["https://openalex.org/W295732247","https://openalex.org/W1203557841","https://openalex.org/W2072232009","https://openalex.org/W2075875861","https://openalex.org/W2119112357","https://openalex.org/W2135167904","https://openalex.org/W2180612164","https://openalex.org/W2243397390","https://openalex.org/W2331128040","https://openalex.org/W2463631526","https://openalex.org/W2611576673","https://openalex.org/W2618043096","https://openalex.org/W2729018917","https://openalex.org/W2774644650","https://openalex.org/W2789524546","https://openalex.org/W2886443245","https://openalex.org/W2897949738","https://openalex.org/W2949333977","https://openalex.org/W2962700793","https://openalex.org/W2962720716","https://openalex.org/W2962843949","https://openalex.org/W2963857521","https://openalex.org/W2964082701","https://openalex.org/W2964209782","https://openalex.org/W2967069910","https://openalex.org/W2991203386","https://openalex.org/W2998293245","https://openalex.org/W3004672782"],"related_works":[],"abstract_inverted_index":{"Crowd":[0],"counting":[1,27,76,147,161,206],"has":[2],"drawn":[3],"much":[4],"attention":[5],"due":[6],"to":[7,37,49,69,83,95,114],"its":[8],"importance":[9],"in":[10],"safety-critical":[11],"surveillance":[12],"systems.":[13],"Especially,":[14,102],"deep":[15],"neural":[16],"network":[17],"(DNN)":[18],"methods":[19],"have":[20,31],"significantly":[21],"reduced":[22],"estimation":[23],"errors":[24],"for":[25],"crowd":[26,75,146,160,205],"missions.":[28],"Recent":[29],"studies":[30],"demonstrated":[32],"that":[33,88,130],"DNNs":[34,48],"are":[35],"vulnerable":[36],"adversarial":[38,86,117,157,199],"attacks,":[39],"i.e.,":[40],"normal":[41],"images":[42,113],"with":[43,66],"human-imperceptible":[44],"perturbations":[45],"could":[46],"mislead":[47],"make":[50],"false":[51],"predictions.":[52],"In":[53],"this":[54],"work,":[55],"we":[56,163],"propose":[57,164],"a":[58,120],"robust":[59,116],"attack":[60,105],"strategy":[61],"called":[62],"Adversarial":[63,177],"Patch":[64],"Attack":[65],"Momentum":[67],"(APAM)":[68],"systematically":[70],"evaluate":[71],"the":[72,79,103,107,143,156,165,209,214],"robustness":[73,158],"of":[74,111,122,136,145,159,183,213],"models,":[77,162],"where":[78],"attacker's":[80],"goal":[81],"is":[82,173,185],"create":[84],"an":[85],"perturbation":[87],"severely":[89,141],"degrades":[90],"their":[91],"performances,":[92],"thus":[93],"leading":[94],"public":[96],"safety":[97],"accidents":[98],"(e.g.,":[99,124],"stampede":[100],"accidents).":[101],"proposed":[104,215],"leverages":[106],"extreme-density":[108],"background":[109],"information":[110],"input":[112],"generate":[115],"patches":[118],"via":[119],"series":[121],"transformations":[123],"interpolation,":[125],"rotation,":[126],"etc.).":[127],"We":[128],"observe":[129],"by":[131],"perturbing":[132],"less":[133],"than":[134,176,188,196],"6%":[135],"image":[137],"pixels,":[138],"our":[139],"attacks":[140],"degrade":[142],"performance":[144],"systems,":[148],"both":[149],"digitally":[150],"and":[151,193,211],"physically.":[152],"To":[153],"better":[154],"enhance":[155],"first":[166],"regression":[167],"model-based":[168],"Randomized":[169],"Ablation":[170],"(RA),":[171],"which":[172],"more":[174],"sufficient":[175],"Training":[178],"(ADT)":[179],"(Mean":[180],"Absolute":[181],"Error":[182],"RA":[184],"5":[186],"lower":[187,195],"ADT":[189,197],"on":[190,198,203],"clean":[191],"samples":[192],"30":[194],"examples).":[200],"Extensive":[201],"experiments":[202],"five":[204],"models":[207],"demonstrate":[208],"effectiveness":[210],"generality":[212],"method.":[216]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2022,"cited_by_count":1}],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2021-04-26T00:00:00"}
