{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T12:14:15Z","timestamp":1781525655164,"version":"3.54.1"},"reference-count":55,"publisher":"Springer Science and Business Media LLC","issue":"12","license":[{"start":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T00:00:00Z","timestamp":1752710400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T00:00:00Z","timestamp":1752710400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22A2063"],"award-info":[{"award-number":["U22A2063"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key Research and Development Project of China","award":["2022YFF0900070"],"award-info":[{"award-number":["2022YFF0900070"]}]},{"name":"Major Program of National Natural Science Foundation of China","award":["71790614"],"award-info":[{"award-number":["71790614"]}]},{"DOI":"10.13039\/501100013314","name":"111 Project","doi-asserted-by":"crossref","award":["B16009"],"award-info":[{"award-number":["B16009"]}],"id":[{"id":"10.13039\/501100013314","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Vis Comput"],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1007\/s00371-025-03997-4","type":"journal-article","created":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T20:23:59Z","timestamp":1752783839000},"page":"9749-9763","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Enhancing Adversarial Transferability through Dual-Domain Gradient Flatness Optimization"],"prefix":"10.1007","volume":"41","author":[{"given":"Kaibo","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tong","family":"Jia","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weihua","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,7,17]]},"reference":[{"issue":"1","key":"3997_CR1","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1109\/T-C.1974.223784","volume":"100","author":"N Ahmed","year":"1974","unstructured":"Ahmed, N., Natarajan, T., Rao, K.R.: Discrete cosine transform. IEEE Trans. Comput. 100(1), 90\u201393 (1974)","journal-title":"IEEE Trans. Comput."},{"issue":"11","key":"3997_CR2","doi-asserted-by":"publisher","first-page":"5293","DOI":"10.1007\/s00371-022-02660-6","volume":"39","author":"A Amirkhani","year":"2023","unstructured":"Amirkhani, A., Karimi, M.P., Banitalebi-Dehkordi, A.: A survey on adversarial attacks and defenses for object detection and their applications in autonomous vehicles. Vis. Comput. 39(11), 5293\u20135307 (2023)","journal-title":"Vis. Comput."},{"issue":"2","key":"3997_CR3","doi-asserted-by":"publisher","first-page":"570","DOI":"10.1016\/j.cam.2008.12.024","volume":"230","author":"N Andrei","year":"2009","unstructured":"Andrei, N.: Accelerated conjugate gradient algorithm with finite difference hessian\/vector product approximation for unconstrained optimization. J. Comput. Appl. Math. 230(2), 570\u2013582 (2009)","journal-title":"J. Comput. Appl. Math."},{"key":"3997_CR4","doi-asserted-by":"crossref","unstructured":"Andriushchenko, M., Croce, F., Flammarion, N. et\u00a0al (2020) Square attack: a query-efficient black-box adversarial attack via random search. In: Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part XXIII, Springer, pp 484\u2013501","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"3997_CR5","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 ieee symposium on security and privacy (sp), Ieee, pp 39\u201357 (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"3997_CR6","unstructured":"Cohen, J., Rosenfeld, E., Kolter, Z.: Certified adversarial robustness via randomized smoothing. In: international conference on machine learning, PMLR, pp 1310\u20131320 (2019)"},{"key":"3997_CR7","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., et\u00a0al.: Imagenet: A large-scale hierarchical image database. In: 2009 IEEE conference on computer vision and pattern recognition, Ieee, pp 248\u2013255 (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"3997_CR8","doi-asserted-by":"crossref","unstructured":"Deng, J., Guo, J., Xue, N., et\u00a0al.: Arcface: Additive angular margin loss for deep face recognition. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 4690\u20134699 (2019)","DOI":"10.1109\/CVPR.2019.00482"},{"key":"3997_CR9","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., Pang, T., et\u00a0al.: Boosting adversarial attacks with momentum. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 9185\u20139193 (2018)","DOI":"10.1109\/CVPR.2018.00957"},{"key":"3997_CR10","doi-asserted-by":"crossref","unstructured":"Dong, Y., Pang, T., Su, H., et\u00a0al.: Evading defenses to transferable adversarial examples by translation-invariant attacks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 4312\u20134321 (2019)","DOI":"10.1109\/CVPR.2019.00444"},{"key":"3997_CR11","unstructured":"Dosovitskiy, A., Beyer, L., Kolesnikov, A., et\u00a0al.: An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)"},{"key":"3997_CR12","doi-asserted-by":"crossref","unstructured":"Duan, R., Chen, Y., Niu, D., et\u00a0al.: Advdrop: Adversarial attack to dnns by dropping information. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 7506\u20137515 (2021)","DOI":"10.1109\/ICCV48922.2021.00741"},{"key":"3997_CR13","doi-asserted-by":"crossref","unstructured":"Efros, A.A., Freeman, W.T.: Image quilting for texture synthesis and transfer. In: Proceedings of the 28th annual conference on Computer graphics and interactive techniques, pp 341\u2013346 (2001)","DOI":"10.1145\/383259.383296"},{"key":"3997_CR14","doi-asserted-by":"crossref","unstructured":"Ganeshan, A., BS, V., Babu, R.V.: Fda: Feature disruptive attack. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 8069\u20138079 (2019)","DOI":"10.1109\/ICCV.2019.00816"},{"key":"3997_CR15","doi-asserted-by":"crossref","unstructured":"Gao, L., Zhang, Q., Song, J., et\u00a0al.: Patch-wise attack for fooling deep neural network. In: Computer Vision\u2013ECCV 2020: 16th European Conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part XXVIII 16, Springer, pp 307\u2013322 (2020)","DOI":"10.1007\/978-3-030-58604-1_19"},{"key":"3997_CR16","first-page":"70141","volume":"36","author":"Z Ge","year":"2023","unstructured":"Ge, Z., Liu, H., Xiaosen, W., et al.: Boosting adversarial transferability by achieving flat local maxima. Adv. Neural. Inf. Process. Syst. 36, 70141\u201370161 (2023)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"3997_CR17","unstructured":"Ge, Z., Xiaosen, W., Liu, H., et\u00a0al.: Boosting adversarial transferability by achieving flat local maxima. Advances in Neural Information Processing Systems 36 (2024)"},{"key":"3997_CR18","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"3997_CR19","unstructured":"Guo, C., Frank, J.S., Weinberger, K.Q.: Low frequency adversarial perturbation. arXiv preprint arXiv:1809.08758 (2018)"},{"key":"3997_CR20","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., et\u00a0al.: Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"3997_CR21","unstructured":"Ilyas, A., Engstrom, L., Athalye, A., et al.: Black-box adversarial attacks with limited queries and information. In: International conference on machine learning, PMLR, pp 2137\u20132146 (2018a)"},{"key":"3997_CR22","unstructured":"Ilyas, A., Engstrom, L., Madry, A.: Prior convictions: Black-box adversarial attacks with bandits and priors. arXiv preprint arXiv:1807.07978 (2018b)"},{"key":"3997_CR23","doi-asserted-by":"crossref","unstructured":"Jia, S., Ma, C., Yao, T., et\u00a0al.: Exploring frequency adversarial attacks for face forgery detection. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 4103\u20134112 (2022)","DOI":"10.1109\/CVPR52688.2022.00407"},{"key":"3997_CR24","doi-asserted-by":"crossref","unstructured":"Jia, X., Wei, X., Cao, X., et\u00a0al.: Comdefend: An efficient image compression model to defend adversarial examples. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 6084\u20136092 (2019)","DOI":"10.1109\/CVPR.2019.00624"},{"key":"3997_CR25","doi-asserted-by":"crossref","unstructured":"Jin, Z., Zhang, J., Zhu, Z., et\u00a0al.: Benchmarking transferable adversarial attacks. CoRR (2024)","DOI":"10.14722\/aiscc.2024.23017"},{"key":"3997_CR26","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. In: Artificial intelligence safety and security. Chapman and Hall\/CRC, p 99\u2013112 (2018)","DOI":"10.1201\/9781351251389-8"},{"issue":"8","key":"3997_CR27","doi-asserted-by":"publisher","first-page":"3315","DOI":"10.3390\/app14083315","volume":"14","author":"C Li","year":"2024","unstructured":"Li, C., Liu, Y., Zhang, X., et al.: Exploiting frequency characteristics for boosting the invisibility of adversarial attacks. Appl. Sci. 14(8), 3315 (2024)","journal-title":"Appl. Sci."},{"key":"3997_CR28","doi-asserted-by":"crossref","unstructured":"Li, H., Xu, X., Zhang, X., et\u00a0al.: Qeba: Query-efficient boundary-based blackbox attack. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 1221\u20131230 (2020)","DOI":"10.1109\/CVPR42600.2020.00130"},{"key":"3997_CR29","doi-asserted-by":"crossref","unstructured":"Liao, F., Liang, M., Dong, Y., et\u00a0al.: Defense against adversarial attacks using high-level representation guided denoiser. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 1778\u20131787 (2018)","DOI":"10.1109\/CVPR.2018.00191"},{"key":"3997_CR30","unstructured":"Lin, J., Song, C., He, K., et\u00a0al.: Nesterov accelerated gradient and scale invariance for adversarial attacks. arXiv preprint arXiv:1908.06281 (2019)"},{"key":"3997_CR31","doi-asserted-by":"crossref","unstructured":"Liu, Z., Liu, Q., Liu, T., et\u00a0al.: Feature distillation: Dnn-oriented jpeg compression against adversarial examples. In: 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), IEEE, pp 860\u2013868 (2019)","DOI":"10.1109\/CVPR.2019.00095"},{"key":"3997_CR32","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1007\/978-3-031-19772-7_32","volume-title":"Computer Vision-ECCV 2022: 17th European Conference, Tel Aviv, Israel, October 23\u201327, 2022, Proceedings","author":"Y Long","year":"2022","unstructured":"Long, Y., Zhang, Q., Zeng, B., et al.: Frequency domain model augmentation for adversarial attack. In: Part, I.V. (ed.) Computer Vision-ECCV 2022: 17th European Conference, Tel Aviv, Israel, October 23\u201327, 2022, Proceedings, pp. 549\u2013566. Springer (2022)"},{"key":"3997_CR33","unstructured":"Madry, A., Makelov, A., Schmidt, L., et\u00a0al.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"key":"3997_CR34","unstructured":"Maiya, S.R., Ehrlich, M., Agarwal, V., et\u00a0al.: A frequency perspective of adversarial robustness. arXiv preprint arXiv:2111.00861 (2021)"},{"key":"3997_CR35","unstructured":"Naseer, M., Khan, S.H., Rahman, S., et al.: Task-generalizable adversarial attack based on perceptual metric. arXiv preprint arXiv:1811.09020"},{"key":"3997_CR36","doi-asserted-by":"crossref","unstructured":"Naseer, M., Khan, S., Hayat, M., et al.: A self-supervised approach for adversarial robustness. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 262\u2013271 (2020)","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"3997_CR37","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., et al.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia conference on computer and communications security, pp 506\u2013519 (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"3997_CR38","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)"},{"key":"3997_CR39","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Vanhoucke, V., Ioffe, S., et al.: Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 2818\u20132826 (2016)","DOI":"10.1109\/CVPR.2016.308"},{"key":"3997_CR40","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Ioffe, S., Vanhoucke, V., et\u00a0al.: Inception-v4, inception-resnet and the impact of residual connections on learning. In: Proceedings of the AAAI conference on artificial intelligence (2017)","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"3997_CR41","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., et al.: Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)"},{"key":"3997_CR42","doi-asserted-by":"crossref","unstructured":"Tu, Z., Talebi, H., Zhang, H., et\u00a0al.: Maxvit: Multi-axis vision transformer. In: European conference on computer vision, Springer, pp 459\u2013479 (2022)","DOI":"10.1007\/978-3-031-20053-3_27"},{"issue":"8","key":"3997_CR43","doi-asserted-by":"publisher","first-page":"6155","DOI":"10.1007\/s10462-020-09845-2","volume":"53","author":"R Wadawadagi","year":"2020","unstructured":"Wadawadagi, R., Pagi, V.: Sentiment analysis with deep neural networks: comparative study and performance assessment. Artif. Intell. Rev. 53(8), 6155\u20136195 (2020)","journal-title":"Artif. Intell. Rev."},{"key":"3997_CR44","doi-asserted-by":"crossref","unstructured":"Wang, H., Wu, X., Huang, Z., et al.: High-frequency component helps explain the generalization of convolutional neural networks. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 8684\u2013869 (2020)","DOI":"10.1109\/CVPR42600.2020.00871"},{"key":"3997_CR45","doi-asserted-by":"crossref","unstructured":"Wang, Z., Guo, H., Zhang, Z., et al.: Feature importance-aware transferable adversarial attacks. In: Proceedings of the IEEE\/CVF international conference on computer vision, pp 7639\u20137648 (2021)","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"3997_CR46","doi-asserted-by":"crossref","unstructured":"Wu, S.,Tan, Ya., Wang, Y., et al.: Towards transferable adversarial attacks with centralized perturbation. In: Proceedings of the AAAI Conference on Artificial Intelligence, pp 6109\u20136116 (2024)","DOI":"10.1609\/aaai.v38i6.28427"},{"key":"3997_CR47","unstructured":"Xie, C., Wang, J., Zhang, Z., et al.: Mitigating adversarial effects through randomization. arXiv preprint arXiv:1711.01991 (2017)"},{"key":"3997_CR48","doi-asserted-by":"crossref","unstructured":"Xie, C., Zhang, Z., Zhou, Y., et al.: Improving transferability of adversarial examples with input diversity. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 2730\u20132739 (2019)","DOI":"10.1109\/CVPR.2019.00284"},{"key":"3997_CR49","unstructured":"Yin, D., Gontijo Lopes, R., Shlens, J., et al.: A fourier perspective on model robustness in computer vision. Advances in Neural Information Processing Systems 32 (2019)"},{"issue":"4","key":"3997_CR50","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1016\/j.vrih.2023.06.005","volume":"6","author":"L Yujie","year":"2024","unstructured":"Yujie, L., Xiaorui, S., Wenbin, S., et al.: S2anet: Combining local spectral and spatial point grouping for point cloud processing. Virtual Reality & Intelligent Hardware 6(4), 267\u2013279 (2024)","journal-title":"Virtual Reality & Intelligent Hardware"},{"key":"3997_CR51","doi-asserted-by":"crossref","unstructured":"Zeng, Y., Pun, C.M.: Frequency-constrained transferable adversarial attack on image manipulation detection and localization. The Visual Computer 1\u201312 (2024)","DOI":"10.1007\/s00371-024-03482-4"},{"key":"3997_CR52","doi-asserted-by":"crossref","unstructured":"Zhang, J., Wu, W., Huang, J.t., et al.: Improving adversarial transferability via neuron attribution-based attacks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 14993\u201315002 (2022)","DOI":"10.1109\/CVPR52688.2022.01457"},{"key":"3997_CR53","doi-asserted-by":"crossref","unstructured":"Zhang, M., Tian, X.: Transformer architecture based on mutual attention for image-anomaly detection. Virtual Reality & Intelligent Hardware 5(1), 57\u201367 (2023)","DOI":"10.1016\/j.vrih.2022.07.006"},{"key":"3997_CR54","doi-asserted-by":"crossref","unstructured":"Zhu, H., Ren, Y., Sui, X., et\u00a0al.: Boosting adversarial transferability via gradient relevance attack. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 4741\u20134750 (2023a)","DOI":"10.1109\/ICCV51070.2023.00437"},{"key":"3997_CR55","doi-asserted-by":"crossref","unstructured":"Zhu, Z., Chen, H., Zhang, J., et\u00a0al.: Improving adversarial transferability via frequency-based stationary point search. In: Proceedings of the 32nd ACM International Conference on Information and Knowledge Management, pp 3626\u20133635 (2023b)","DOI":"10.1145\/3583780.3614927"}],"container-title":["The Visual Computer"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00371-025-03997-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00371-025-03997-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00371-025-03997-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,15]],"date-time":"2025-09-15T09:38:37Z","timestamp":1757929117000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00371-025-03997-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,17]]},"references-count":55,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2025,9]]}},"alternative-id":["3997"],"URL":"https:\/\/doi.org\/10.1007\/s00371-025-03997-4","relation":{},"ISSN":["0178-2789","1432-2315"],"issn-type":[{"value":"0178-2789","type":"print"},{"value":"1432-2315","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,17]]},"assertion":[{"value":"12 May 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 July 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}]}}