{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T07:25:23Z","timestamp":1740122723320,"version":"3.37.3"},"reference-count":60,"publisher":"Springer Science and Business Media LLC","issue":"23","license":[{"start":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T00:00:00Z","timestamp":1726012800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T00:00:00Z","timestamp":1726012800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National key R&D Program of China","doi-asserted-by":"crossref","award":["J2019-V-0001-0092"],"award-info":[{"award-number":["J2019-V-0001-0092"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Xinjiang Ethnic Minority Science and Technology Talent Special Cultivation Program","award":["2022D03041"],"award-info":[{"award-number":["2022D03041"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2024,12]]},"DOI":"10.1007\/s10489-024-05820-4","type":"journal-article","created":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T07:02:39Z","timestamp":1726038159000},"page":"12194-12214","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Improving the transferability of adversarial examples with path tuning"],"prefix":"10.1007","volume":"54","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-4797-7144","authenticated-orcid":false,"given":"Tianyu","family":"Li","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoyu","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2068-3198","authenticated-orcid":false,"given":"Wuping","family":"Ke","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuwei","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Desheng","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,9,11]]},"reference":[{"doi-asserted-by":"crossref","unstructured":"Alhussan AA, Talaat FM, El-kenawy ESM, Abdelhamid AA, Ibrahim A, Khafaga DS, Alnaggar M (2023) Facial expression recognition model depending on optimized support vector machine. Computers, Materials & Continua 76 (1)","key":"5820_CR1","DOI":"10.32604\/cmc.2023.039368"},{"doi-asserted-by":"crossref","unstructured":"Ammad M, Misro MY, Ramli A (2022) A novel generalized trigonometric b\u00e9zier curve: properties, continuity conditions and applications to the curve modeling. Math Comput Simul 194:744\u2013763","key":"5820_CR2","DOI":"10.1016\/j.matcom.2021.12.011"},{"doi-asserted-by":"crossref","unstructured":"Arnab A, Miksik O, Torr PHS (2019) On the robustness of semantic segmentation models to adversarial attacks. IEEE Trans Pattern Anal Mach Intell 42(12):3040\u20133053","key":"5820_CR3","DOI":"10.1109\/TPAMI.2019.2919707"},{"doi-asserted-by":"crossref","unstructured":"Aumann RJ, Shapley LS (2015) Values of non-atomic games. Princeton University Press, Princeton, NJ, 2015","key":"5820_CR4","DOI":"10.1515\/9781400867080"},{"doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: IEEE symposium on security and privacy (SP), pp 39\u201357","key":"5820_CR5","DOI":"10.1109\/SP.2017.49"},{"doi-asserted-by":"crossref","unstructured":"Chen G, Chenb S, Fan L, Du X, Zhao Z, Song F, Liu Y (2021) Who is real bob? adversarial attacks on speaker recognition systems. In: IEEE symposium on security and privacy (SP), pp 694\u2013711","key":"5820_CR6","DOI":"10.1109\/SP40001.2021.00004"},{"doi-asserted-by":"crossref","unstructured":"Chowdhury PN, Bhunia AK, Sain A, Koley S, Xiang T, Song YZ (2023) What can human sketches do for object detection? In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 15083\u201315094","key":"5820_CR7","DOI":"10.1109\/CVPR52729.2023.01448"},{"doi-asserted-by":"crossref","unstructured":"Cores D, Brea VM, Mucientes M (2023) Spatiotemporal tubelet feature aggregation and object linking for small object detection in videos. Appl Intell 53(1):1205\u20131217","key":"5820_CR8","DOI":"10.1007\/s10489-022-03529-w"},{"doi-asserted-by":"crossref","unstructured":"Costa G, Montemurro M, Pailh\u00e8s J (2021) Nurbs hyper-surfaces for 3d topology optimization problems. Mech Adv Mater Struct 28(7):665\u2013684","key":"5820_CR9","DOI":"10.1080\/15376494.2019.1582826"},{"doi-asserted-by":"crossref","unstructured":"Dong Y, Liao F, Pang T, Su H, Zhu J, Hu X, Li J (2018) Boosting adversarial attacks with momentum. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 9185\u20139193","key":"5820_CR10","DOI":"10.1109\/CVPR.2018.00957"},{"doi-asserted-by":"crossref","unstructured":"Dong Y, Pang T, Su H, Zhu J (2019) Evading defenses to transferable adversarial examples by translation-invariant attacks. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 4312\u20134321","key":"5820_CR11","DOI":"10.1109\/CVPR.2019.00444"},{"doi-asserted-by":"crossref","unstructured":"Friedman EJ (2004) Paths and consistency in additive cost sharing. Int J Game Theory 32(4):501\u2013518","key":"5820_CR12","DOI":"10.1007\/s001820400173"},{"doi-asserted-by":"crossref","unstructured":"Ganeshan A, BS V, Babu RV (2019) Fda: feature disruptive attack. In: Proceedings of the IEEE international conference on computer vision (ICCV), pp 8069\u20138079","key":"5820_CR13","DOI":"10.1109\/ICCV.2019.00816"},{"doi-asserted-by":"crossref","unstructured":"Gao L, Zhang Q, Song J, Liu X, Shen HT (2020) Patch-wise attack for fooling deep neural network. In: Proceedings of the European conference on computer vision (ECCV), pages 307\u2013322, 2020","key":"5820_CR14","DOI":"10.1007\/978-3-030-58604-1_19"},{"unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2015) Explaining and harnessing adversarial examples. Stat, 1050:20","key":"5820_CR15"},{"doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 770\u2013778","key":"5820_CR16","DOI":"10.1109\/CVPR.2016.90"},{"doi-asserted-by":"crossref","unstructured":"Howard A, Sandler M, Chu G, Chen LC, Chen B, Tan M, Wang W, Zhu Y, Pang R, Vasudevan V etal (2019) Searching for mobilenetv3. In Proceedings of the IEEE\/CVF international conference on computer vision, pp 1314\u20131324","key":"5820_CR17","DOI":"10.1109\/ICCV.2019.00140"},{"doi-asserted-by":"crossref","unstructured":"Hu J, Shen L, Albanie S, Sun G, Wu E (2020) Squeeze-and-excitation networks. IEEE Trans Pattern Anal Mach Intell 42(08):2011\u20132023","key":"5820_CR18","DOI":"10.1109\/TPAMI.2019.2913372"},{"doi-asserted-by":"crossref","unstructured":"Huang G, Liu Z, Pleiss G, Der\u00a0Maaten LV, Weinberger KQ (2019) Convolutional networks with dense connectivity. IEEE Trans Pattern Anal Mach Intell 44 (12): 8704\u20138716","key":"5820_CR19","DOI":"10.1109\/TPAMI.2019.2918284"},{"doi-asserted-by":"crossref","unstructured":"Huang Q, Katsman I, He H, Gu Z, Belongie S, Lim SN (2019) Enhancing adversarial example transferability with an intermediate level attack. In: Proceedings of the IEEE international conference on computer vision (ICCV)","key":"5820_CR20","DOI":"10.1109\/ICCV.2019.00483"},{"unstructured":"Ilyas A, Santurkar S, Tsipras D, Engstrom L, Tran B, Madry A (2019) Adversarial examples are not bugs, they are features. In: Advances in neural information processing systems (NeurIPS), pp 125\u2013136","key":"5820_CR21"},{"doi-asserted-by":"crossref","unstructured":"Jin Z, Zhu Z, Wang X, Zhang J, Shen J, Chen H (2023) Danaa: towards transferable attacks with double adversarial neuron attribution. In: Advanced data mining and applications, pp 456\u2013470. Springer Nature Switzerland","key":"5820_CR22","DOI":"10.1007\/978-3-031-46664-9_31"},{"doi-asserted-by":"crossref","unstructured":"Kim WJ, Hong S, Yoon SE (2022) Diverse generative perturbations on attention space for transferable adversarial attacks. In: 2022 IEEE international conference on image processing (ICIP), pp 281\u2013285. IEEE","key":"5820_CR23","DOI":"10.1109\/ICIP46576.2022.9897346"},{"unstructured":"Kurakin A, Goodfellow IJ, Bengio S (2017) Adversarial machine learning at scale. In: International conference on learning representations (ICLR)","key":"5820_CR24"},{"doi-asserted-by":"crossref","unstructured":"Li J, Liu C, Liu S (2022) The quartic catmull\u2013rom spline with local adjustability and its shape optimization. Adv Contin Discret Model 2022(1):59","key":"5820_CR25","DOI":"10.1186\/s13662-022-03730-8"},{"doi-asserted-by":"crossref","unstructured":"Li P, Liu F, Jiao L, Li S, Li L, Liu X, Huang X (2023) Knowledge transduction for cross-domain few-shot learning. Pattern Recog 141:109652","key":"5820_CR26","DOI":"10.1016\/j.patcog.2023.109652"},{"unstructured":"Li Y, Yosinski J, Clune J, Lipson H, Hopcroft J (2015) Convergent learning: do different neural networks learn the same representations? In: Proceedings of machine learning research (PMLR), vol 44. pp 196\u2013212","key":"5820_CR27"},{"unstructured":"Lin J, Song C, He K, Wang L, Hopcroft JE (2020) Nesterov accelerated gradient and scale invariance for adversarial attacks. In: International conference on learning representations (ICLR)","key":"5820_CR28"},{"unstructured":"Lundberg SM, Lee SI (2017) A unified approach to interpreting model predictions. In: Advances in neural information processing systems (NeurIPS), pp 4765\u20134774","key":"5820_CR29"},{"unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: International conference on learning representations (ICLR)","key":"5820_CR30"},{"doi-asserted-by":"crossref","unstructured":"Maho T, Furon T, Le\u00a0Merrer E (2021) Surfree: a fast surrogate-free black-box attack. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 10430\u201310439","key":"5820_CR31","DOI":"10.1109\/CVPR46437.2021.01029"},{"doi-asserted-by":"crossref","unstructured":"Marques G, Agarwal D, de la\u00a0Torre D\u00ecez I (2020) Automated medical diagnosis of covid-19 through efficientnet convolutional neural network. Applied Soft Computing, 96:106691","key":"5820_CR32","DOI":"10.1016\/j.asoc.2020.106691"},{"doi-asserted-by":"crossref","unstructured":"Modas A, Sanchez-Matilla R, Frossard P, Cavallaro A (2020) Toward robust sensing for autonomous vehicles: an adversarial perspective. IEEE Signal Process Mag 37(4):14\u201323","key":"5820_CR33","DOI":"10.1109\/MSP.2020.2985363"},{"doi-asserted-by":"crossref","unstructured":"Montavon G, Binder A, Lapuschkin S, Samek W, Klaus-Robert M (2019) An overview, layer-wise relevance propagation","key":"5820_CR34","DOI":"10.1007\/978-3-030-28954-6_10"},{"doi-asserted-by":"crossref","unstructured":"Ruiz A, Agudo A, Moreno-Noguer F (2021) Generating attribution maps with disentangled masked backpropagation. In: Proceedings of the IEEE international conference on computer vision (ICCV), pp 905\u2013914","key":"5820_CR35","DOI":"10.1109\/ICCV48922.2021.00094"},{"doi-asserted-by":"crossref","unstructured":"Olga R, Jia D, Su H, Jonathan K, Sanjeev S, Sean M, Zhiheng H, Andrej K, Aditya K, Michael B et al (2015) Imagenet large scale visual recognition challenge. Int J Comput Vision 115(3):211\u2013252","key":"5820_CR36","DOI":"10.1007\/s11263-015-0816-y"},{"doi-asserted-by":"crossref","unstructured":"Sarvar A, Amirmazlaghani M (2023) Defense against adversarial examples based on wavelet domain analysis. Appl Intell 53(1):423\u2013439","key":"5820_CR37","DOI":"10.1007\/s10489-022-03159-2"},{"doi-asserted-by":"crossref","unstructured":"Selvaraju RR, Cogswell M, Das A, Vedantam R, Parikh D, Batra D (2017) Grad-cam: Visual explanations from deep networks via gradient-based localization. In: Proceedings of the IEEE international conference on computer vision (ICCV), pp 618\u2013626","key":"5820_CR38","DOI":"10.1109\/ICCV.2017.74"},{"unstructured":"Simonyan K, Vedaldi A, Zisserman A (2014) Deep inside convolutional networks: visualising image classification models and saliency maps. In: International conference on learning representations (ICLR)","key":"5820_CR39"},{"unstructured":"Struppek L, Hintersdorf D, Correira ADA, Adler A, Kersting K (2022) Plug & play attacks: towards robust and flexible model inversion attacks. In: International conference on machine learning (ICML), pp 20522\u201320545","key":"5820_CR40"},{"unstructured":"Sundararajan M, Taly A, Yan Q (2017) Axiomatic attribution for deep networks. In: Proceedings of the international conference on machine learning (ICML), pp 3319\u20133328","key":"5820_CR41"},{"unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2014) Intriguing properties of neural networks. In: International conference on learning representations (ICLR)","key":"5820_CR42"},{"doi-asserted-by":"crossref","unstructured":"Szegedy C, Vanhoucke V, Ioffe S, Shlens J, Wojna Z (2016) Rethinking the inception architecture for computer vision. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 2818\u20132826","key":"5820_CR43","DOI":"10.1109\/CVPR.2016.308"},{"doi-asserted-by":"crossref","unstructured":"Szegedy C, Ioffe S, Vanhoucke V, Alemi A (2017) Inception-v4, inception-resnet and the impact of residual connections on learning. In: Proceedings of the AAAI conference on artificial intelligence (AAAI), pp 4278\u20134284","key":"5820_CR44","DOI":"10.1609\/aaai.v31i1.11231"},{"unstructured":"Tan M, Le Q (2019) Efficientnet: rethinking model scaling for convolutional neural networks. In: International conference on machine learning, pp 6105\u20136114. PMLR","key":"5820_CR45"},{"unstructured":"Tram\u00e8r F, Kurakin A, Papernot N, Goodfellow I, Boneh D, McDaniel P (2018) Ensemble adversarial training: attacks and defenses. In: International conference on learning representations (ICLR)","key":"5820_CR46"},{"unstructured":"Wang L, Hu L, Gu J, Hu Z, Wu Y, He K, Hopcroft J (2018) Towards understanding learning representations: to what extent do different neural networks learn the same representation. In: Advances in neural information processing systems (NeurIPS), pp 9607\u20139616","key":"5820_CR47"},{"doi-asserted-by":"crossref","unstructured":"Wang S, Wang Z, Li H, Chang J, Ouyang W, Tian Q (2024) Accurate fine-grained object recognition with structure-driven relation graph networks. Int J Comput Vis 132(1):137\u2013160","key":"5820_CR48","DOI":"10.1007\/s11263-023-01873-z"},{"doi-asserted-by":"crossref","unstructured":"Wang Z, Guo H, Zhang Z, Liu W, Qin Z, Ren K (2021) Feature importance-aware transferable adversarial attacks. In: Proceedings of the IEEE international conference on computer vision (ICCV), pp 7639\u20137648","key":"5820_CR49","DOI":"10.1109\/ICCV48922.2021.00754"},{"doi-asserted-by":"crossref","unstructured":"Wu W, Su Y, Chen X, Zhao S, King I, Lyu MR, Tai YW (2020) Boosting the transferability of adversarial samples via attention. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 1161\u20131170","key":"5820_CR50","DOI":"10.1109\/CVPR42600.2020.00124"},{"doi-asserted-by":"crossref","unstructured":"Xiao C, Li B, Zhu JY, He W, Liu M, Song D (2018) Generating adversarial examples with adversarial networks. In: International joint conference on artificial intelligence (IJCAI), pp 3905\u20133911","key":"5820_CR51","DOI":"10.24963\/ijcai.2018\/543"},{"doi-asserted-by":"crossref","unstructured":"Xie C, Zhang Z, Zhou Y, Bai S, Wang J, Ren Z, Yuille AL (2019) Improving transferability of adversarial examples with input diversity. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 2730\u20132739","key":"5820_CR52","DOI":"10.1109\/CVPR.2019.00284"},{"doi-asserted-by":"crossref","unstructured":"Yeh R, Nashed YSG, Peterka T, Tricoche X (2020) Fast automatic knot placement method for accurate b-spline curve fitting. Computer-aided design, 128:102905","key":"5820_CR53","DOI":"10.1016\/j.cad.2020.102905"},{"doi-asserted-by":"crossref","unstructured":"Zhang J, Wu W, Huang JT, Huang Y, Wang W, Su Y, Lyu MR (2022) Improving adversarial transferability via neuron attribution-based attacks. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 14993\u201315002","key":"5820_CR54","DOI":"10.1109\/CVPR52688.2022.01457"},{"doi-asserted-by":"crossref","unstructured":"Zhang Y, Jia R, Pei H, Wang W, Li B, Song D (2020) The secret revealer: generative model-inversion attacks against deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 253\u2013261","key":"5820_CR55","DOI":"10.1109\/CVPR42600.2020.00033"},{"doi-asserted-by":"crossref","unstructured":"Zhang Z, Xue Z, Chen Y, Liu S, Zhang Y, Liu J, Zhang M (2023) Boosting verified training for robust image classifications via abstraction. In: Proceedings of the IEEE conference on computer vision and pattern recognition (CVPR), pp 16251\u201316260","key":"5820_CR56","DOI":"10.1109\/CVPR52729.2023.01559"},{"doi-asserted-by":"crossref","unstructured":"Zheng D, Ke W, Li X, Zhang S, Yin G, Qian W, Zhou Y, Min F, Yang S (2024) Channel-augmented joint transformation for transferable adversarial attacks. Appl Intell 54(1):428\u2013442","key":"5820_CR57","DOI":"10.1007\/s10489-023-05171-6"},{"doi-asserted-by":"crossref","unstructured":"Zhou W, Hou X, ChenY, Tang M, Huang X, Gan X, YangY (2018) Transferable adversarial perturbations. In: Proceedings of the European conference on computer vision (ECCV)","key":"5820_CR58","DOI":"10.1007\/978-3-030-01264-9_28"},{"doi-asserted-by":"crossref","unstructured":"Zhu H, Ren Y, Sui X, Yang L, Jiang W (2023) Boosting adversarial transferability via gradient relevance attack. In: Proceedings of the IEEE international conference on computer vision (ICCV), pp 4741\u20134750","key":"5820_CR59","DOI":"10.1109\/ICCV51070.2023.00437"},{"doi-asserted-by":"crossref","unstructured":"Zhu Z, Chen H, Wang X, Zhang J, Jin Z, Choo KKR, Shen J, Yuan D (2024) Ge-advgan: improving the transferability of adversarial samples by gradient editing-based adversarial generative model. In: Proceedings of the 2024 SIAM international conference on data mining (SDM), pp 706\u2013714. SIAM","key":"5820_CR60","DOI":"10.1137\/1.9781611978032.81"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-024-05820-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-024-05820-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-024-05820-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,30]],"date-time":"2024-09-30T13:10:37Z","timestamp":1727701837000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-024-05820-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,11]]},"references-count":60,"journal-issue":{"issue":"23","published-print":{"date-parts":[[2024,12]]}},"alternative-id":["5820"],"URL":"https:\/\/doi.org\/10.1007\/s10489-024-05820-4","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"type":"print","value":"0924-669X"},{"type":"electronic","value":"1573-7497"}],"subject":[],"published":{"date-parts":[[2024,9,11]]},"assertion":[{"value":"28 August 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 September 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}