REVIEW 4 major objections 5 minor 1 cited by
AdvSerial generates printable garment textures that suppress pedestrian detection in high-angle surveillance, achieving 74.8% physical attack success on YOLO-v5 and cutting mean confidence from 84.30% to 39.38%.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · deepseek-v4-flash
2026-08-01 19:06 UTC pith:EKPHISB6
load-bearing objection A solid, extensive attack paper whose empirical results are plausible; the FSQ 'bound' in Eq. 8 is overclaimed and should be treated as heuristic. the 4 major comments →
AdvSerial: Physical Adversarial Attacks on Infrastructure-mounted Pedestrian Detectors via Semantic Feature Suppression
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
AdvSerial is a framework that optimizes a single garment texture against pedestrian detectors under elevated viewing angles. It combines a 2D digital attack branch with sparse- and continuous-frame 3D rendering of a UV-mapped human model, and suppresses person-specific semantic features by driving detector confidence below threshold. The Feature Smooth Quilting strategy routes the seams of tiled textures through detector-insensitive regions, bounding cross-seam feature discontinuities; the Serial Frame Loss penalizes broken suppression streaks, steering optimization to flat temporal minima. In physical-world tests the printed texture achieves 74.8% ASR on YOLO-v5, lowers mean person confiden
What carries the argument
Feature Smooth Quilting (FSQ): a seam-selection strategy that weights the standard pixel-domain boundary-cut error by the detector's gradient-magnitude sensitivity map, routing seams through low-sensitivity regions so that cross-seam feature discontinuities are theoretically bounded (bound-tightening property). Serial Frame Loss (SFL): a differentiable suppression score combined with streak-dependent weights that penalizes re-detection after long successful suppression, promoting temporally consistent failure. The 2D–3D joint optimization: a learnable texture UV-mapped onto 3D garments, rendered under random poses, views, and lighting, with the same texture shared across a continuous frame s
Load-bearing premise
FSQ's bound-tightening assumes that per-pixel gradient magnitude is positively correlated with the local Lipschitz constant of the detector; if that correlation fails, seams chosen by gradient magnitude do not cap cross-seam feature discontinuities and the theoretical defense-evasion advantage collapses.
What would settle it
Measure, on a real YOLO-v5 or Faster R-CNN detector, the spatial map of local Lipschitz constants (via perturbation probes) and compare it to the gradient-magnitude map used by FSQ; if the two are not positively correlated at seam locations, then an FSQ seam will sit in high-Lipschitz regions, producing measurable cross-seam feature discontinuities and higher detectability by a boundary-aware defense.
If this is right
- If correct, a printed garment can disable pedestrian detection in infrastructure surveillance for sustained stretches (median ~11 consecutive frames), which breaks downstream tracking in detection-based pipelines.
- Attack success transfers across detector architectures and paradigms, including anchor-free and transformer detectors, implying that the vulnerability is not a quirk of a single model family.
- Defenses that look for high-frequency patch boundaries can be bypassed when seams are routed through detector-insensitive regions, so boundary-based defense signals alone are insufficient.
- Temporal fusion models can be fooled if the attack maintains consistent suppression across frames, meaning temporal aggregation is not an inherent defense.
- The results motivate motion-aware, 3D-aware defense mechanisms and caution against relying on high camera angles as natural protection.
Where Pith is reading between the lines
- The bound-tightening guarantee (Eq. 8) rests on gradient magnitude correlating with local Lipschitz constants; on detectors where that correlation weakens, FSQ's advantage may shrink—this could be tested by measuring both quantities per pixel.
- The same serial-frame loss and semantic-suppression idea could extend to other surveillance tasks like person re-identification, action recognition, or multi-camera tracking, where temporal consistency is equally critical.
- Physical ASR (74.8%) is below digital ASR (89.71%), suggesting a simulation-to-reality gap that could be narrowed by modeling more clothing deformation, lighting, and camera noise.
- Because the patch works on printed clothing, it is a realistic low-cost threat; red-teaming deployments should include such garment textures in adversary testing.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes AdvSerial, a framework for generating physical adversarial garment textures against infrastructure-mounted pedestrian detectors. It combines 2D digital attacks, 3D sparse-frame rendering, and 3D continuous-frame rendering with a serial-frame loss, and introduces Feature Smooth Quilting (FSQ) to route tile seams through detector-insensitive regions. The central empirical claim is that AdvSerial achieves sustained detection suppression in high-angle surveillance: physical-world experiments report 74.8% ASR on YOLO-v5 and a mean confidence drop from 84.30% to 39.38%, while digital experiments report 89.71% ASR on YOLO-v2, transfer across eight detectors, and resistance to NapGuard and Sparse4D-v3. The paper also presents t-SNE and Grad-CAM analyses arguing for a suppression-centric mechanism rather than attention hijacking.
Significance. If the empirical results hold, AdvSerial addresses a relevant and underexplored scenario—high-angle infrastructure surveillance—and the physical-world validation across detectors, distances, azimuths, and postures is a useful contribution. The paper includes extensive experiments, ablations with standard deviations, and multiple defense evaluations, which are strengths. However, the formal FSQ bound-tightening claim in Sec. 3.3 is not actually derived, and the Sparse4D-v3 evaluation is underspecified. The empirical attack results may survive without the formal guarantee, but the advertised theoretical contribution needs to be either proven or explicitly downgraded to a heuristic.
major comments (4)
- [Sec. 3.3, Eq. (8)] The bound-tightening inequality Φ_ℓ(S_feat) ≤ Φ_ℓ(S_std) does not follow from the stated assumptions. Positive correlation between w_ij and L_ℓ(i,j) does not imply that the minimizer of Σ(1+μŵ_ij)e_ij has a smaller max over S of L_ij√e_ij than the minimizer of Σe_ij; reweighting can move the seam to a pixel with smaller ŵ but larger √e and unobserved L. The quantities are also mismatched: w_ij in Eq. (2) is aggregated over detection-head layers and min-max normalized, whereas L_ℓ is stage-specific and is never measured. Moreover, the DP minimizes a cumulative cost along the seam, while Φ_ℓ in Eq. (7) is a worst-case max over seam pixels; no argument links the two. The empirical validations in Tab. 10 and Sec. 4.5.3 show correlations, not a proof. Please either derive Eq. (8) under explicit assumptions, or replace the formal guarantee with a clearly labeled heuristic and remove 'provably
- [Sec. 4.5.3, Tab. 8] The Sparse4D-v3 evaluation protocol is severely under-specified. nuScenes is a multi-camera, 3D detection benchmark; it is not clear how the 2D garment texture is placed in the 3D scene, which camera views are attacked, how many sequences are used, how ASR is defined for a 3D detector, or whether the texture is optimized on Sparse4D-v3 or transferred from a 2D model. Without this, the reported 65.84% ASR cannot be reproduced or compared against the Clean baseline. Please provide the exact rendering, placement, training/test split, association criterion, and evaluation code or pseudo-code.
- [Sec. 4.6 and Sec. 4.7.1] The physical-world headline numbers are point estimates without confidence intervals or trial-level detail. The 74.8% ASR is derived from 525 images (Sec. 4.7.1); Sec. 4.6 states that 10 videos were collected (5 indoor, 5 outdoor) but does not report the number of subjects, repetitions per condition, or lighting variations. The claim that 'no significant difference' exists between indoor and outdoor is stated without a statistical test. Please report per-subject/per-video variation, confidence intervals, and the specific test (or remove the significance claim).
- [Sec. 4.4, Tab. 5] The ablation component 'TQ' is not isolated to FSQ: it does not compare Feature Smooth Quilting against standard minimum-error-boundary-cut quilting within the same joint optimization pipeline. Fig. 13 compares AdvReal with direct tiling versus AdvSerial with quilting, which confounds method differences. To support the causal role of feature-weighted seam selection, please add an ablation that replaces the FSQ cost in Eq. (3) with the standard pixel error while keeping all other components fixed.
minor comments (5)
- [Sec. 3.3] Typo 'startegy' should be 'strategy'.
- [Sec. 3.5.2] Equation (13) is notationally dense; the inner sum/product over i should be defined more carefully (e.g., with explicit bounds and an explanation that empty products are 1).
- [Sec. 4.3.3] 'mTSR' appears where 'ASR-T' is meant; also the text refers to 'mTSR' while Table 4 uses 'ASR-T'.
- [Sec. 4.3.2] In Table 3, AdvSerial's F1 on YOLO-v12n (94.91%) is only marginally better than several baselines; the claim of 'strong transferability' should be qualified.
- [General] No code availability statement is provided. Given the complexity of the pipeline, even a partial release or detailed training pseudocode would materially aid reproducibility.
Circularity Check
No circular derivation: AdvSerial's empirical results are externally measured, and the FSQ Eq. 8 bound is unsupported but not a reduction of inputs to outputs.
full rationale
The paper's central claims are physical/digital attack success rates, transferability, and defense evasion. These are all measured after optimization on held-out rendered/real data and compared against external baselines (Table 2, Table 3, Table 9, Section 4.6); no target constant is fitted and then reported as a prediction. The FSQ derivation in Sec. 3.3 defines a gradient-magnitude sensitivity w (Eq. 2), uses it to reweight seam cost (Eq. 3), and then asserts the bound-tightening inequality Φ(S_feat) ≤ Φ(S_std) (Eq. 8) from an assumed positive correlation with local Lipschitz constants [22]. This is not a circular step: S_feat is selected by minimizing a weighted pixel error, while Φ is defined with an independently unmeasured Lipschitz map L; the inequality is not an input to the optimization. What it lacks is a proof: positive correlation between w and L does not imply that the minimizer of Σ(1+μŵ)e has smaller max L√e than the minimizer of Σe. That is a correctness/soundness concern, not a self-referential reduction, and it is partly acknowledged by the paper's own hedge: 'a tighter upper bound alone cannot guarantee small feature discontinuity in practice.' The citations used for the Lipschitz background ([21], [22]) are external, not self-citations. The only self-citations ([4] for the AdvReal baseline and UV extraction, [42] for scenario-generation context) are not load-bearing for the paper's main results. Therefore no circularity is established; the minor self-citations justify a score of 2 rather than 0.
Axiom & Free-Parameter Ledger
free parameters (6)
- Loss weights lambda_det, lambda_ser, lambda_tv =
0.5 / 0.5 / 0.1
- FSQ weighting strength mu =
not reported (stated mu >= 0, mu=0 recovers standard quilting)
- Serial loss transition sharpness beta and detection threshold tau =
beta not reported; tau=0.5 used in experiments
- Temporal decay alpha and streak penalty lambda in Eq. (13) =
not reported
- Quilting parameters (block size, overlap, scaling, error tolerance) =
80x80, 25, 5, 0.3
- Serial frame length, batch size, input resolution =
8 frames per sequence; 64 total batch; 416x416
axioms (4)
- domain assumption Per-pixel gradient magnitude w_{i,j} is a proxy for, and positively correlated with, the local Lipschitz constant L_l(i,j) of the detector.
- domain assumption Detector feature maps satisfy a local Lipschitz bound and PyTorch3D soft-blending rendering satisfies the smoothness bound in Eq. (5) with finite constants.
- domain assumption Randomly posed and rendered 3D clothed humans with alpha-blended backgrounds are a sufficient training proxy for real printed garments under high-angle cameras.
- domain assumption The confidence of the highest-IoU box in Eq. (10) is an adequate surrogate for person-specific semantic feature suppression.
read the original abstract
AI-based visual perception systems are increasingly deployed in infrastructure surveillance, including roadside monitoring units, highway cameras, and smart-city pedestrian management systems. The security vulnerability of these systems to physical adversarial attacks poses a direct threat to the reliable operation of transportation infrastructure. We propose AdvSerial, a dynamic 2D--3D joint optimization framework for generating continuous high-angle physical adversarial patches against pedestrian detectors in infrastructure-based scenarios. We UV-map a boundary-aware quilted texture onto 3D garments, combine 2D digital attacks with 3D sparse- and continuous-frame rendering, and explicitly suppress person-specific semantic features while enforcing temporal continuity. A Feature Smooth Quilting strategy reduces visible patch boundaries and bounds cross-seam feature discontinuities. A serial-frame loss encourages long uninterrupted sequences of detection failures. In physical world experiments, AdvSerial achieves a 74.8% attack success rate on YOLO-v5 and degrades mean detection confidence from 84.30% to 39.38%. Experiments spanning eight detectors with different architectures demonstrate strong transferability. Notably, it achieves an $89.71%$ attack success rate on YOLO-v2 and resists both patch-detection defenses (NapGuard) and 3D-temporal perception (Sparse4D-v3). The results reveal persistent, temporally consistent failure modes under high-angle surveillance, and motivate the design of motion-aware and 3D-aware defenses for security-critical infrastructure deployments.
Figures
Forward citations
Cited by 1 Pith paper
-
Detectors Learn the Wrong Thing: Shortcut-Resistant Adversarial Training Against Physically Realizable Attacks
InsCAT adds a contrastive loss that aligns adversarially clothed people with clean people and pushes away from texture-only images, reducing texture false positives from 46.9% to 7.3% while lifting average attack AP to 82.3%.
Reference graph
Works this paper leans on
-
[1]
J. Hu, J. Wang, L. Jing, H. Li, H. Liu, H. Qin, A. Liu, K. Xu, X. Liu, Exploring semantic-constrained adversar- ial example with instruction uncertainty reduction, arXiv preprint arXiv:2510.22981 (2025). 17
arXiv 2025
-
[2]
K. Xu, G. Zhang, S. Liu, Q. Fan, M. Sun, H. Chen, P.-Y . Chen, Y . Wang, X. Lin, Adversarial t-shirt! evading per- son detectors in a physical world, in: Computer vision– ECCV 2020: 16th European conference, glasgow, UK, August 23–28, 2020, proceedings, part v 16, Springer, 2020, pp. 665–681
2020
-
[3]
Huang, Z
H. Huang, Z. Chen, H. Chen, Y . Wang, K. Zhang, T-sea: Transfer-based self-ensemble attack on object detection, in: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2023, pp. 20514–20523
2023
-
[4]
Huang, Y
Y . Huang, Y . Ren, J. Wang, L. Huo, X. Bai, J. Zhang, H. Yu, Advreal: Physical adversarial patch generation framework for security evaluation of object detection sys- tems, Expert Systems with Applications 296 (2026) 128967
2026
-
[5]
Hingun, C
N. Hingun, C. Sitawarin, J. Li, D. Wagner, Reap: a large- scale realistic adversarial patch benchmark, in: Proceed- ings of the IEEE/CVF International Conference on Com- puter Vision, 2023, pp. 4640–4651
2023
-
[6]
Suryanto, Y
N. Suryanto, Y . Kim, H. Kang, H. T. Larasati, Y . Yun, T.-T.-H. Le, H. Yang, S.-Y . Oh, H. Kim, Dta: Physi- cal camouflage attacks using differentiable transformation network, in: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 15305–15314
2022
-
[7]
J. Hu, X. Liu, J. Wang, J. Zhang, X. Yang, H. Qin, Y . Ma, K. Xu, Dynamicpae: Generating scene-aware physical adversarial examples in real-time, IEEE Transactions on Pattern Analysis and Machine Intelligence (2025)
2025
-
[8]
M. Dong, K. Xu, X. Jiang, Z. Zhao, T. Sun, Feature-aware transferable adversarial attacks on visual object tracking, IEEE Transactions on Circuits and Systems for Video Technology (2025)
2025
-
[9]
D. Gu, W. Jin, W. Chen, L. Xu, Assessing multi- ple construction workers’ physical fatigue risks in 3d space, Computer-Aided Civil and Infrastructure Engineer- ing (2026) 100060
2026
-
[10]
Z. Hu, S. Huang, X. Zhu, F. Sun, B. Zhang, X. Hu, Ad- versarial texture for fooling person detectors in the phys- ical world, in: Proceedings of the IEEE/CVF confer- ence on computer vision and pattern recognition, 2022, pp. 13307–13316
2022
-
[11]
Y . Duan, J. Chen, X. Zhou, J. Zou, Z. He, J. Zhang, W. Zhang, Z. Pan, Learning coated adversarial camou- flages for object detectors, in: L. D. Raedt (Ed.), Pro- ceedings of the Thirty-First International Joint Confer- ence on Artificial Intelligence, IJCAI-22, International Joint Conferences on Artificial Intelligence Organiza- tion, 2022, pp. 891–897. ...
-
[12]
S. Liu, T. Li, W. Chen, H. Li, Soft rasterizer: A differen- tiable renderer for image-based 3d reasoning, in: Proceed- ings of the IEEE/CVF international conference on com- puter vision, 2019, pp. 7708–7717
2019
-
[13]
N. Ravi, J. Reizenstein, D. Novotny, T. Gordon, W.-Y . Lo, J. Johnson, G. Gkioxari, Accelerating 3d deep learning with pytorch3d, arXiv preprint arXiv:2007.08501 (2020)
Pith/arXiv arXiv 2007
-
[14]
J. Liang, S. Liang, J. Huang, C. Si, M. Zhang, X. Cao, Physical adversarial camouflage through gradient calibra- tion and regularization, arXiv preprint arXiv:2508.05414 (2025)
Pith/arXiv arXiv 2025
-
[15]
Liang, S
J. Liang, S. Liang, T. Lou, M. Zhang, W. Li, D. Fan, X. Cao, Gradient-reweighted adversarial camouflage for physical object detection evasion, in: Proceedings of the IEEE/CVF International Conference on Computer Vision, 2025, pp. 13880–13889
2025
-
[16]
Zhang, Z
Y . Zhang, Z. Gong, Y . Zhang, K. Bin, Y . Li, J. Qi, H. Wen, P. Zhong, Boosting transferability of physical attack against detectors by redistributing separable atten- tion, Pattern Recognition 138 (2023) 109435
2023
-
[17]
Geirhos, P
R. Geirhos, P. Rubisch, C. Michaelis, M. Bethge, F. A. Wichmann, W. Brendel, Imagenet-trained cnns are biased towards texture; increasing shape bias improves accuracy and robustness, in: International conference on learning representations, 2018
2018
-
[18]
Burgert, O
T. Burgert, O. Stoll, P. Rota, B. Demir, Imagenet-trained cnns are not biased towards texture: Revisiting feature reliance through controlled suppression, Advances in Neural Information Processing Systems 38 (2026) 60809– 60830
2026
-
[19]
K. Deng, Q. Chen, Y . Zhang, Z. Lin, S. Gong, Z. Liang, A. Peng, X. Yang, D. Lian, Targeted attack via adversarial patch outside bounding box, Pattern Recognition (2025) 112244
2025
-
[20]
Dabouei, S
A. Dabouei, S. Soleymani, F. Taherkhani, J. Dawson, N. Nasrabadi, Smoothfool: An efficient framework for computing smooth adversarial perturbations, in: Proceed- ings of the IEEE/CVF Winter Conference on Applications of Computer Vision, 2020, pp. 2665–2674
2020
-
[21]
Gatys, A
L. Gatys, A. S. Ecker, M. Bethge, Texture synthesis using convolutional neural networks, Advances in neural infor- mation processing systems 28 (2015)
2015
-
[22]
Khromov, S
G. Khromov, S. P. Singh, Some fundamental aspects about lipschitz continuity of neural networks, in: Inter- national conference on learning representations, volume 2024, 2024, pp. 4261–4305
2024
-
[23]
S. Wu, J. Wang, J. Zhao, Y . Wang, X. Liu, Napguard: To- wards detecting naturalistic adversarial patches, in: Pro- ceedings of the IEEE/CVF Conference on Computer Vi- sion and Pattern Recognition (CVPR), 2024, pp. 24367– 24376. 18
2024
-
[24]
R. Pony, I. Naeh, S. Mannor, Over-the-air adversarial flickering attacks against video recognition networks, in: Proceedings of the IEEE/CVF conference on computer vi- sion and pattern recognition, 2021, pp. 515–524
2021
-
[25]
H.-S. Kim, M. Son, M. Kim, M.-J. Kwon, C. Kim, Break- ing temporal consistency: Generating video universal ad- versarial perturbations using image models, in: Proceed- ings of the IEEE/CVF International Conference on Com- puter Vision, 2023, pp. 4325–4334
2023
-
[26]
Redmon, A
J. Redmon, A. Farhadi, Yolo9000: better, faster, stronger, in: Proceedings of the IEEE conference on computer vi- sion and pattern recognition, 2017, pp. 7263–7271
2017
-
[27]
J. Redmon, A. Farhadi, Yolov3: An incremental improve- ment, 2018. URL:https://arxiv.org/abs/1804. 02767.arXiv:1804.02767
Pith/arXiv arXiv 2018
-
[28]
Jocher, A
G. Jocher, A. Stoken, J. Borovec, L. Changyu, A. Hogan, L. Diaconu, J. Poznanski, L. Yu, P. Rai, R. Ferriday, et al., ultralytics/yolov5: v3. 0, Zenodo (2020)
2020
-
[29]
Jocher, A
G. Jocher, A. Chaurasia, J. Qiu, Ultralytics yolov8,
-
[30]
A. Wang, H. Chen, L. Liu, K. Chen, Z. Lin, J. Han, G. Ding, Yolov10: Real-time end-to-end object detec- tion, Advances in neural information processing systems 37 (2024) 107984–108011
2024
-
[31]
Y . Tian, Q. Ye, D. Doermann, Yolov12: Attention- centric real-time object detectors, arXiv preprint arXiv:2502.12524 (2025)
Pith/arXiv arXiv 2025
-
[32]
S. Ren, K. He, R. Girshick, J. Sun, Faster r-cnn: Towards real-time object detection with region proposal networks, IEEE transactions on pattern analysis and machine intelli- gence 39 (2016) 1137–1149
2016
-
[33]
X. Zhu, W. Su, L. Lu, B. Li, X. Wang, J. Dai, Deformable detr: Deformable transformers for end-to-end object de- tection, arXiv preprint arXiv:2010.04159 (2020)
Pith/arXiv arXiv 2010
-
[34]
S. Thys, W. Van Ranst, T. Goedemé, Fooling automated surveillance cameras: adversarial patches to attack person detection, in: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition workshops, 2019, pp. 0–0
2019
-
[35]
Hu, B.-H
Y .-C.-T. Hu, B.-H. Kung, D. S. Tan, J.-C. Chen, K.-L. Hua, W.-H. Cheng, Naturalistic physical adversarial patch for object detectors, in: Proceedings of the IEEE/CVF International Conference on Computer Vision, 2021, pp. 7848–7857
2021
-
[36]
X. Wang, J. Chen, Z. Zhang, K. He, Z. Wu, R. Du, Q. Li, G. Liu, Transferable and robust dynamic adversarial at- tack against object detection models, IEEE Internet of Things Journal (2025)
2025
-
[37]
T.-Y . Lin, M. Maire, S. Belongie, J. Hays, P. Perona, D. Ramanan, P. Dollár, C. L. Zitnick, Microsoft coco: Common objects in context, in: Computer vision–ECCV 2014: 13th European conference, zurich, Switzerland, September 6-12, 2014, proceedings, part v 13, Springer, 2014, pp. 740–755
2014
-
[38]
Wojke, A
N. Wojke, A. Bewley, D. Paulus, Simple online and realtime tracking with a deep association metric, in: 2017 IEEE international conference on image processing (ICIP), IEEE, 2017, pp. 3645–3649
2017
-
[39]
Zhang, P
Y . Zhang, P. Sun, Y . Jiang, D. Yu, F. Weng, Z. Yuan, P. Luo, W. Liu, X. Wang, Bytetrack: Multi-object tracking by associating every detection box, in: European confer- ence on computer vision, Springer, 2022, pp. 1–21
2022
-
[40]
J. Pang, L. Qiu, X. Li, H. Chen, Q. Li, T. Darrell, F. Yu, Quasi-dense similarity learning for multiple object track- ing, in: Proceedings of the IEEE/CVF conference on com- puter vision and pattern recognition, 2021, pp. 164–173
2021
-
[41]
B. Li, W. Wu, Q. Wang, F. Zhang, J. Xing, J. Yan, Siamrpn++: Evolution of siamese visual tracking with very deep networks, in: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2019, pp. 4282–4291
2019
-
[42]
X. Cai, X. Bai, Z. Cui, D. Xie, D. Fu, H. Yu, Y . Ren, Text2scenario: Text-driven scenario generation for au- tonomous driving test, Automotive Innovation (2026) 1– 26
2026
-
[43]
J. Lian, J. Pan, L. Wang, Y . Wang, S. Mei, L.-P. Chau, Padetbench: Towards benchmarking texture- and patch-based physical attacks against object detection, Knowledge-Based Systems (2025) 114395
2025
-
[44]
X. Lin, Z. Pei, T. Lin, L. Huang, Z. Su, Sparse4d v3: Advancing end-to-end 3d detection and tracking, arXiv preprint arXiv:2311.11722 (2023)
Pith/arXiv arXiv 2023
-
[45]
R. R. Selvaraju, M. Cogswell, A. Das, R. Vedantam, D. Parikh, D. Batra, Grad-cam: Visual explanations from deep networks via gradient-based localization, in: Pro- ceedings of the IEEE international conference on com- puter vision, 2017, pp. 618–626
2017
-
[46]
Y . Man, R. Muller, M. Li, Z. B. Celik, R. Gerdes, That person moves like a car: Misclassification attack detec- tion for autonomous systems using spatiotemporal consis- tency, in: 32nd USENIX Security Symposium (USENIX Security 23), 2023, pp. 6929–6946. 19
2023
-
[2023]
URL:https://github.com/ultralytics/ ultralytics
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.