{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T23:23:19Z","timestamp":1778800999778,"version":"3.51.4"},"reference-count":69,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T00:00:00Z","timestamp":1772236800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T00:00:00Z","timestamp":1772236800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100011697","name":"R\u00e9gion Bretagne","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100011697","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006021","name":"Direction G\u00e9n\u00e9rale de l\u2019Armement","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100006021","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1007\/s00521-025-11734-0","type":"journal-article","created":{"date-parts":[[2026,2,28]],"date-time":"2026-02-28T08:12:41Z","timestamp":1772266361000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Adversarial threats to vision transformers: evaluating robustness beyond CNNs"],"prefix":"10.1007","volume":"38","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7624-5253","authenticated-orcid":false,"given":"Ahmed","family":"Aldahdooh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wassim","family":"Hamidouche","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Olivier","family":"D\u00e9forges","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,2,28]]},"reference":[{"key":"11734_CR1","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition, p 770\u2013778","DOI":"10.1109\/CVPR.2016.90"},{"key":"11734_CR2","doi-asserted-by":"crossref","unstructured":"Yuan L, Chen Y, Wang T, Yu W, Shi Y, Tay FEH et al (2021) Tokens-to-token ViT: training vision transformers from scratch on imagenet. CoRR. arxiv:2101.11986","DOI":"10.1109\/ICCV48922.2021.00060"},{"key":"11734_CR3","unstructured":"Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez AN et al (2017) Attention is all you need. In: Advances in neural information processing systems 30, 4-9 December 2017, Long Beach, CA, USA. p 5998\u20136008"},{"key":"11734_CR4","unstructured":"Dosovitskiy A, Beyer L, Kolesnikov A, Weissenborn D, Zhai X, Unterthiner T et al (2021) An image is worth 16x16 words: transformers for image recognition at scale. In: 9th International conference on learning representations, ICLR 2021, Virtual Event, Austria. OpenReview.net, 3-7May 2021"},{"key":"11734_CR5","doi-asserted-by":"crossref","unstructured":"Sun C, Shrivastava A, Singh S, Gupta A (2017) Revisiting unreasonable effectiveness of data in deep learning era. In: IEEE international conference on computer vision, ICCV 2017, Venice, Italy. IEEE Computer Society. p 843\u2013852, 22-29 October 2017","DOI":"10.1109\/ICCV.2017.97"},{"key":"11734_CR6","doi-asserted-by":"crossref","unstructured":"Deng J, Dong W, Socher R, Li LJ, Li K, Fei-Fei L (2009) ImageNet: a large-scale hierarchical image database. In: 2009 IEEE conference on computer vision and pattern recognition, p 248\u2013255","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"11734_CR7","doi-asserted-by":"crossref","unstructured":"Han K, Xiao A, Wu E, Guo J, Xu C, Wang Y (2021) Transformer in transformer. CoRR. arxiv:2103.00112","DOI":"10.1007\/s11063-022-11124-w"},{"key":"11734_CR8","doi-asserted-by":"crossref","unstructured":"Wu H, Xiao B, Codella N, Liu M, Dai X, Yuan L et al (2021) CvT: introducing convolutions to vision transformers. CoRR. arxiv:abs\/2103.15808","DOI":"10.1109\/ICCV48922.2021.00009"},{"key":"11734_CR9","unstructured":"Simonyan K, Zisserman A (2015) Very deep convolutional networks for large-scale image recognition. In: Bengio Y, LeCun Y (ed). 3rd international conference on learning representations, ICLR 2015, San Diego, CA, USA, Conference track proceedings, 7-9 May 2015"},{"key":"11734_CR10","doi-asserted-by":"crossref","unstructured":"Szegedy C, Vanhoucke V, Ioffe S, Shlens J, Wojna Z (2016) Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE conference on computer vision and pattern recognition. p 2818\u20132826","DOI":"10.1109\/CVPR.2016.308"},{"key":"11734_CR11","unstructured":"Howard AG, Zhu M, Chen B, Kalenichenko D, Wang W, Weyand T et al (2017) MobileNets: efficient convolutional neural networks for mobile vision applications. arXiv preprint arXiv:1704.04861"},{"key":"11734_CR12","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow IJ, et al (2014) Intriguing properties of neural networks. In: 2nd international conference on learning representations, ICLR 2014, Banff, AB, Canada, Conference track proceedings, 14-16 April 2014"},{"key":"11734_CR13","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Adversarial examples are not easily detected: bypassing ten detection methods. In: Proceedings of the 10th ACM workshop on artificial intelligence and security, p 3\u201314","DOI":"10.1145\/3128572.3140444"},{"key":"11734_CR14","unstructured":"Ilyas A, Santurkar S, Tsipras D, Engstrom L, Tran B, Madry A (2019) Adversarial examples are not bugs, they are features. In: Advances in neural information processing systems, p 125\u2013136"},{"key":"11734_CR15","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar N, Mian A (2018) Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6:14410\u201314430","journal-title":"IEEE Access"},{"issue":"2","key":"11734_CR16","doi-asserted-by":"publisher","first-page":"151","DOI":"10.1007\/s11633-019-1211-x","volume":"17","author":"HXYM Hao-Chen","year":"2020","unstructured":"Hao-Chen HXYM, Deb LD, Anil HLJLT, Jain K (2020) Adversarial attacks and defenses in images, graphs and text: a review. Int J Autom Comput 17(2):151\u2013178","journal-title":"Int J Autom Comput"},{"key":"11734_CR17","doi-asserted-by":"crossref","unstructured":"Bhojanapalli S, Chakrabarti A, Glasner D, Li D, Unterthiner T, Veit A (2021) Understanding robustness of transformers for image classification. CoRR. arxiv:2103.14586","DOI":"10.1109\/ICCV48922.2021.01007"},{"key":"11734_CR18","unstructured":"Shao R, Shi Z, Yi J, Chen P, Hsieh C (2021) On the adversarial robustness of visual transformers. CoRR. arxiv:2103.15670"},{"key":"11734_CR19","doi-asserted-by":"crossref","unstructured":"Mahmood K, Mahmood R, Van Dijk M (2021) On the robustness of vision transformers to adversarial examples. In: Proceedings of the IEEE\/CVF international conference on computer vision, p 7838\u20137847","DOI":"10.1109\/ICCV48922.2021.00774"},{"key":"11734_CR20","unstructured":"Paul S, Chen P (2021) Vision transformers are robust learners. CoRR. arxiv:2105.07581"},{"issue":"9","key":"11734_CR21","doi-asserted-by":"publisher","first-page":"2805","DOI":"10.1109\/TNNLS.2018.2886017","volume":"30","author":"X Yuan","year":"2019","unstructured":"Yuan X, He P, Zhu Q, Li X (2019) Adversarial examples: attacks and defenses for deep learning. IEEE Trans Neural Netw Learn Sys 30(9):2805\u20132824","journal-title":"IEEE Trans Neural Netw Learn Sys"},{"key":"11734_CR22","unstructured":"Chakraborty A, Alam M, Dey V, Chattopadhyay A, Mukhopadhyay D (2018) Adversarial attacks and defences: a survey. CoRR. arxiv:1810.00069"},{"key":"11734_CR23","unstructured":"Aldahdooh A, Hamidouche W, Fezza SA, D\u00e9forges O (2021) Adversarial example detection for DNN models: a review. CoRR. arxiv:2105.00203"},{"key":"11734_CR24","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. In: 3rd international conference on learning representations, ICLR 2015, San Diego, CA, USA, Conference track proceedings, 7-9 May 2015"},{"key":"11734_CR25","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: 6th international conference on learning representations, ICLR 2018, Vancouver, Canada, 2018. OpenReview.net"},{"key":"11734_CR26","doi-asserted-by":"crossref","unstructured":"Deng J, Dong W, Socher R, Li LJ, Li K, Fei-Fei L (2009) ImageNet: a large-scale hierarchical image database. In: 2009 IEEE conference on computer vision and pattern recognition, p 248\u2013255","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"11734_CR27","doi-asserted-by":"crossref","unstructured":"Kolesnikov A, Beyer L, Zhai X, Puigcerver J, Yung J, Gelly S et al (2020) Big Transfer (BiT): general visual representation learning. In: Computer vision - ECCV 2020 - 16th european conference, Glasgow, UK, 23-28 August 2020, Proceedings, Part V. vol. 12350 of Lecture Notes in Computer Science, Springer, p 491\u2013507","DOI":"10.1007\/978-3-030-58558-7_29"},{"key":"11734_CR28","unstructured":"Croce F, Hein M (2020) Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: Proceedings of the 37th international conference on machine learning, ICML 2020, 13-18 July 2020, Virtual Event. vol. 119 of Proceedings of Machine Learning Research. PMLR, p 2206\u20132216"},{"key":"11734_CR29","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 2017 ieee symposium on security and privacy (sp). IEEE, p 39\u201357","DOI":"10.1109\/SP.2017.49"},{"key":"11734_CR30","doi-asserted-by":"crossref","unstructured":"Dong Y, Liao F, Pang T, Su H, Zhu J, Hu X et al (2018) Boosting adversarial attacks with momentum. In: 2018 IEEE conference on computer vision and pattern recognition, CVPR 2018, Salt Lake City, UT, USA, 18-22 June 2018. Computer vision foundation \/ ieee computer society, p 9185\u20139193","DOI":"10.1109\/CVPR.2018.00957"},{"key":"11734_CR31","unstructured":"Athalye A, Carlini N, Wagner DA (2018) Obfuscated gradients give a false sense of security: circumventing defenses to adversarial examples. In: Proceedings of the 35th international conference on machine learning, ICML 2018, Stockholmsm\u00e4ssan, Stockholm, Sweden, 10-15 July 2018. vol.\u00a080 of Proceedings of Machine Learning Research. PMLR, p 274\u2013283"},{"key":"11734_CR32","unstructured":"Song Y, Shu R, Kushman N, Ermon S (2018) Constructing unrestricted adversarial examples with generative models. In: Proceedings of the 32nd international conference on neural information processing systems. NIPS\u201918. Red Hook, NY, USA: Curran Associates Inc, p 8322\u20138333"},{"key":"11734_CR33","unstructured":"Kuzina A, Welling M, Tomczak JM (2024) Alleviating adversarial attacks on variational autoencoders with MCMC. In: Proceedings of the 36th international conference on neural information processing systems. NIPS \u201922. Red Hook, NY, USA: Curran Associates Inc"},{"key":"11734_CR34","unstructured":"Sooksatra K, Bejarano G, Rivas P. Evaluating robustness of generative models with adversarial networks. Available from https:\/\/openreview.net\/forum?id=ZTPzwWtKW7o"},{"issue":"6","key":"11734_CR35","doi-asserted-by":"publisher","first-page":"3083","DOI":"10.1109\/TAI.2023.3340982","volume":"5","author":"K Liu","year":"2024","unstructured":"Liu K, Wu D, Wu Y, Wang Y, Feng D, Tan B et al (2024) Manipulation attacks on learned image compression. IEEE Trans Artif Intell 5(6):3083\u20133097. https:\/\/doi.org\/10.1109\/TAI.2023.3340982","journal-title":"IEEE Trans Artif Intell"},{"key":"11734_CR36","doi-asserted-by":"crossref","unstructured":"Ma J, Wang R (2024) An imperceptible adversarial attack against reconstruction for learned image compression. In: 2024 data compression conference (DCC), p 573\u2013573","DOI":"10.1109\/DCC58796.2024.00090"},{"key":"11734_CR37","doi-asserted-by":"publisher","first-page":"160397","DOI":"10.1109\/ACCESS.2019.2951526","volume":"7","author":"Y Bakhti","year":"2019","unstructured":"Bakhti Y, Fezza SA, Hamidouche W, D\u00e9forges O (2019) DDSA: a defense against adversarial attacks using deep denoising sparse autoencoder. IEEE Access 7:160397\u2013160407. https:\/\/doi.org\/10.1109\/ACCESS.2019.2951526","journal-title":"IEEE Access"},{"key":"11734_CR38","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1109\/OJSP.2023.3275053","volume":"4","author":"Y Ji","year":"2023","unstructured":"Ji Y, Le TN, Nguyen HH, Echizen I (2023) Purifying adversarial images using adversarial autoencoder with conditional normalizing flows. IEEE Open J Signal Process 4:267\u2013274. https:\/\/doi.org\/10.1109\/OJSP.2023.3275053","journal-title":"IEEE Open J Signal Process"},{"key":"11734_CR39","doi-asserted-by":"crossref","unstructured":"Bai W, Quan C, Luo Z (2017) Alleviating adversarial attacks via convolutional autoencoder. In: 2017 18th IEEE\/ACIS international conference on software engineering, artificial intelligence, networking and parallel\/distributed computing (SNPD), p 53\u201358","DOI":"10.1109\/SNPD.2017.8022700"},{"key":"11734_CR40","unstructured":"Hendrycks D, Gimpel K 2016 Gaussian error linear units (GELUs). CoRR. arxiv:1606.08415"},{"key":"11734_CR41","unstructured":"Wightman R. PyTorch image models. GitHub. https:\/\/github.com\/rwightman\/pytorch-image-models"},{"key":"11734_CR42","doi-asserted-by":"crossref","unstructured":"Xie S, Girshick RB, Doll\u00e1r P, Tu Z, He K (2017) Aggregated residual transformations for deep neural networks. In: 2017 IEEE conference on computer vision and pattern recognition, CVPR 2017, Honolulu, HI, USA, 21-26 July 2017. IEEE computer society, p 5987\u20135995","DOI":"10.1109\/CVPR.2017.634"},{"key":"11734_CR43","unstructured":"Li Z, Yang W, Peng S, Liu F (2020) A survey of convolutional neural networks: analysis, applications, and prospects. CoRR. arxiv:2004.02806"},{"key":"11734_CR44","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: 2016 IEEE european symposium on security and privacy (EuroS&P). IEEE, p 372\u2013387","DOI":"10.1109\/EuroSP.2016.36"},{"key":"11734_CR45","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli SM, Fawzi A, Fawzi O, Frossard P (2017) Universal adversarial perturbations. In: Proceedings of the IEEE conference on computer vision and pattern recognition, p 1765\u20131773","DOI":"10.1109\/CVPR.2017.17"},{"key":"11734_CR46","doi-asserted-by":"crossref","unstructured":"Andriushchenko M, Croce F, Flammarion N, Hein M (2020) Square attack: a query-efficient black-box adversarial attack via random search. In: European conference on computer vision, Springer, p 484\u2013501","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"11734_CR47","doi-asserted-by":"crossref","unstructured":"Chen J, Gu Q (2020) Rays: a ray searching method for hard-label adversarial attack. In: Proceedings of the 26th ACM SIGKDD international conference on knowledge discovery & data mining, p 1739\u20131747","DOI":"10.1145\/3394486.3403225"},{"issue":"2","key":"11734_CR48","doi-asserted-by":"publisher","first-page":"181","DOI":"10.1109\/TAI.2020.3046167","volume":"1","author":"J Kantipudi","year":"2020","unstructured":"Kantipudi J, Dubey SR, Chakraborty S (2020) Color channel perturbation attacks for fooling convolutional neural networks and a defense against such attacks. IEEE Trans Artif Intell 1(2):181\u2013191. https:\/\/doi.org\/10.1109\/TAI.2020.3046167","journal-title":"IEEE Trans Artif Intell"},{"key":"11734_CR49","unstructured":"Croce F, Hein M (2020) Minimally distorted adversarial examples with a fast adaptive boundary attack. In: International conference on machine learning. PMLR, p 2196\u20132205"},{"key":"11734_CR50","doi-asserted-by":"crossref","unstructured":"Xu W, Evans D, Qi Y (2018) Feature squeezing: detecting adversarial examples in deep neural networks. In: 25th annual network and distributed system security symposium, NDSS 2018, San Diego, California, USA, 18-21 February 2018. The internet society","DOI":"10.14722\/ndss.2018.23198"},{"key":"11734_CR51","unstructured":"Guo C, Rana M, Ciss\u00e9 M, van der Maaten L (2018) Countering adversarial images using input transformations. In: 6th international conference on learning representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3 2018, Conference track proceedings. OpenReview.net"},{"key":"11734_CR52","unstructured":"Dziugaite GK, Ghahramani Z, Roy DM (2016) A study of the effect of JPG compression on adversarial images. CoRR. arxiv:1608.00853"},{"key":"11734_CR53","unstructured":"Das N, Shanbhogue M, Chen S, Hohman F, Chen L, Kounavis ME et al (2017) Keeping the bad guys out: protecting and vaccinating deep learning with jpeg compression. CoRR. arxiv:1705.02900"},{"key":"11734_CR54","doi-asserted-by":"crossref","unstructured":"Graese A, Rozsa A, Boult TE (2016) Assessing threat of adversarial examples on deep neural networks. In: 2016 15th IEEE international conference on machine learning and applications (ICMLA). IEEE, p 69\u201374","DOI":"10.1109\/ICMLA.2016.0020"},{"key":"11734_CR55","unstructured":"Samangouei P, Kabkab M, Chellappa R (2018) Defense-GAN: protecting classifiers against adversarial attacks using generative models. In: International conference on learning representations"},{"key":"11734_CR56","unstructured":"Song Y, Kim T, Nowozin S, Ermon S, Kushman N (2018) Pixeldefend: Leveraging generative models to understand and defend against adversarial examples. In: International conference on learning representations"},{"key":"11734_CR57","unstructured":"Nie W, Guo B, Huang Y, Xiao C, Vahdat A, Anandkumar A (2022) Diffusion models for adversarial purification. In: International conference on machine learning (ICML)"},{"key":"11734_CR58","doi-asserted-by":"crossref","unstructured":"Ghosh P, Losalka A, Black MJ (2019) Resisting adversarial attacks using Gaussian mixture variational autoencoders. In: Proceedings of the thirty-third AAAI conference on artificial intelligence and thirty-first innovative applications of artificial intelligence conference and ninth AAAI symposium on educational advances in artificial intelligence. AAAI\u201919\/IAAI\u201919\/EAAI\u201919. AAAI Press. Available from: https:\/\/doi.org\/10.1609\/aaai.v33i01.3301541","DOI":"10.1609\/aaai.v33i01.3301541"},{"key":"11734_CR59","doi-asserted-by":"publisher","first-page":"126582","DOI":"10.1109\/ACCESS.2019.2939352","volume":"7","author":"U Hwang","year":"2019","unstructured":"Hwang U, Park J, Jang H, Yoon S, Cho NI (2019) PuVAE: a variational autoencoder to purify adversarial examples. IEEE Access 7:126582\u2013126593. https:\/\/doi.org\/10.1109\/ACCESS.2019.2939352","journal-title":"IEEE Access"},{"issue":"3","key":"11734_CR60","doi-asserted-by":"publisher","first-page":"425","DOI":"10.1093\/biomet\/81.3.425","volume":"81","author":"DL Donoho","year":"1994","unstructured":"Donoho DL, Johnstone JM (1994) Ideal spatial adaptation by wavelet shrinkage. Biometrics 81(3):425\u2013455","journal-title":"Biometrics"},{"issue":"1","key":"11734_CR61","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1023\/B:JMIV.0000011325.36760.1e","volume":"20","author":"A Chambolle","year":"2004","unstructured":"Chambolle A (2004) An algorithm for total variation minimization and applications. J Math Imaging Vis 20(1):89\u201397","journal-title":"J Math Imaging Vis"},{"key":"11734_CR62","unstructured":"Athalye A, Engstrom L, Ilyas A, Kwok K (2018) Synthesizing robust adversarial examples. In: International conference on machine learning. PMLR, p 284\u2013293"},{"issue":"2","key":"11734_CR63","doi-asserted-by":"publisher","first-page":"336","DOI":"10.1007\/s11263-019-01228-7","volume":"128","author":"RR Selvaraju","year":"2019","unstructured":"Selvaraju RR, Cogswell M, Das A, Vedantam R, Parikh D, Batra D (2019) Grad-CAM: visual explanations from deep networks via gradient-based localization. Int J Comput Vis 128(2):336\u2013359. https:\/\/doi.org\/10.1007\/s11263-019-01228-7","journal-title":"Int J Comput Vis"},{"key":"11734_CR64","unstructured":"Ortiz-Jim\u00e9nez G, Modas A, Moosavi-Dezfooli S, Frossard P (2020) Hold me tight! influence of discriminative features on deep network boundaries. In: Advances in neural information processing systems 33: NeurIPS 2020, 6-12 December 2020, virtual"},{"key":"11734_CR65","doi-asserted-by":"crossref","unstructured":"Fezza SA, Bakhti Y, Hamidouche W, D\u00e9forges O (2019) Perceptual evaluation of adversarial attacks for CNN-based image classification. In: 2019 eleventh international conference on quality of multimedia experience (QoMEX). IEEE, p 1\u20136","DOI":"10.1109\/QoMEX.2019.8743213"},{"issue":"4","key":"11734_CR66","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang Z, Bovik AC, Sheikh HR, Simoncelli EP (2004) Image quality assessment: from error visibility to structural similarity. IEEE Trans Image Process 13(4):600\u2013612","journal-title":"IEEE Trans Image Process"},{"issue":"1","key":"11734_CR67","doi-asserted-by":"publisher","DOI":"10.1117\/1.3267105","volume":"19","author":"EC Larson","year":"2010","unstructured":"Larson EC, Chandler DM (2010) Most apparent distortion: full-reference image quality assessment and the role of strategy. J Electron Imaging 19(1):011006","journal-title":"J Electron Imaging"},{"key":"11734_CR68","unstructured":"Gildenblat J, contributors.: PyTorch library for CAM methods. GitHub. https:\/\/github.com\/jacobgil\/pytorch-grad-cam"},{"key":"11734_CR69","doi-asserted-by":"crossref","unstructured":"Sharma Y, Ding GW, Brubaker MA (2019) On the effectiveness of low frequency perturbations. In: Proceedings of the 28th international joint conference on artificial intelligence. IJCAI\u201919. AAAI Press, p 3389\u20133396","DOI":"10.24963\/ijcai.2019\/470"}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-025-11734-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-025-11734-0","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-025-11734-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,25]],"date-time":"2026-03-25T04:51:37Z","timestamp":1774414297000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-025-11734-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,28]]},"references-count":69,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2026,3]]}},"alternative-id":["11734"],"URL":"https:\/\/doi.org\/10.1007\/s00521-025-11734-0","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,28]]},"assertion":[{"value":"4 September 2022","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 November 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 February 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Beside what is mentioned in the acknowledgements section, Section 5, there is no more Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Human or animal rights"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Informed consent"}}],"article-number":"92"}}