{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,11]],"date-time":"2025-07-11T10:25:13Z","timestamp":1752229513380,"version":"3.37.3"},"reference-count":72,"publisher":"Springer Science and Business Media LLC","issue":"9","license":[{"start":{"date-parts":[[2023,10,17]],"date-time":"2023-10-17T00:00:00Z","timestamp":1697500800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,10,17]],"date-time":"2023-10-17T00:00:00Z","timestamp":1697500800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62072200"],"award-info":[{"award-number":["62072200"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Process Lett"],"published-print":{"date-parts":[[2023,12]]},"DOI":"10.1007\/s11063-023-11428-5","type":"journal-article","created":{"date-parts":[[2023,10,17]],"date-time":"2023-10-17T11:03:01Z","timestamp":1697540581000},"page":"12459-12480","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Singular Value Manipulating: An Effective DRL-Based Adversarial Attack on Deep Convolutional Neural Network"],"prefix":"10.1007","volume":"55","author":[{"given":"Shuai","family":"He","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cai","family":"Fu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guanyun","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianqiang","family":"Lv","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fengyang","family":"Deng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,10,17]]},"reference":[{"key":"11428_CR1","doi-asserted-by":"crossref","unstructured":"Szegedy C, Liu W, Jia Y, Sermanet P, Reed S, Anguelov D, Erhan D, Vanhoucke V, Rabinovich A (2015) Going deeper with convolutions. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 1\u20139","DOI":"10.1109\/CVPR.2015.7298594"},{"issue":"3","key":"11428_CR2","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","volume":"115","author":"O Russakovsky","year":"2015","unstructured":"Russakovsky O, Deng J, Su H, Krause J, Satheesh S, Ma S, Huang Z, Karpathy A, Khosla A, Bernstein M (2015) Imagenet large scale visual recognition challenge. Int J Comput Vis 115(3):211\u2013252","journal-title":"Int J Comput Vis"},{"key":"11428_CR3","doi-asserted-by":"crossref","unstructured":"He K, Gkioxari G, Doll\u00e1r P, Girshick RB (2017) Mask r-cnn. In: Proceedings of the IEEE international conference on computer vision, pp. 2961\u20132969","DOI":"10.1109\/ICCV.2017.322"},{"key":"11428_CR4","doi-asserted-by":"crossref","unstructured":"Redmon J, Farhadi A (2017) Yolo9000: better, faster, stronger. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 7263\u20137271","DOI":"10.1109\/CVPR.2017.690"},{"key":"11428_CR5","doi-asserted-by":"crossref","unstructured":"Cai Z, Vasconcelos N (2018) Cascade r-cnn: delving into high quality object detection. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 6154\u20136162","DOI":"10.1109\/CVPR.2018.00644"},{"key":"11428_CR6","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2013) Intriguing properties of neural networks"},{"key":"11428_CR7","unstructured":"Brown TB, Man\u00e9 D, Roy A, Abadi M, Gilmer J (2017) Adversarial patch"},{"key":"11428_CR8","unstructured":"Inkawhich N, Liang K, Carin L, Chen Y (2020) Transferable perturbations of deep feature distributions. In: International conference on learning representations . https:\/\/openreview.net\/forum?id=rJxAo2VYwr"},{"key":"11428_CR9","unstructured":"Dolatabadi HM, Erfani SM, Leckie C (2020) Advflow: inconspicuous black-box adversarial attacks using normalizing flows. In: Larochelle H, Ranzato M, Hadsell R, Balcan M, Lin H (Eds) Advances in neural information processing systems 33: annual conference on neural information processing systems 2020, NeurIPS 2020, December 6-12, 2020, Virtual . https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/b6cf334c22c8f4ce8eb920bb7b512ed0-Abstract.html"},{"key":"11428_CR10","unstructured":"Fan H, Wang B, Zhou P, Li A, Pang M, Xu Z, Fu C, Li H, Chen Y (2020) Reinforcement learning-based black-box evasion attacks to link prediction in dynamic graphs"},{"key":"11428_CR11","doi-asserted-by":"publisher","unstructured":"Ma C, Chen L, Yong J (2021) Simulating unknown target models for query-efficient black-box attacks. In: IEEE conference on computer vision and pattern recognition, CVPR 2021, Virtual, June 19-25, 2021, pp. 11835\u201311844. Computer Vision Foundation\/IEEE. https:\/\/doi.org\/10.1109\/CVPR46437.2021.01166 . https:\/\/openaccess.thecvf.com\/content\/CVPR2021\/html\/Ma_Simulating_Unknown_Target_Models_for_Query-Efficient_Black-Box_Attacks_CVPR_2021_paper.html","DOI":"10.1109\/CVPR46437.2021.01166"},{"key":"11428_CR12","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. In: International conference on learning representations . https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"issue":"8","key":"11428_CR13","doi-asserted-by":"publisher","first-page":"7427","DOI":"10.1109\/TCYB.2020.3041481","volume":"52","author":"D Wang","year":"2022","unstructured":"Wang D, Li C, Wen S, Han Q-L, Nepal S, Zhang X, Xiang Y (2022) Daedalus: breaking nonmaximum suppression in object detection via adversarial examples. IEEE Trans Cybern 52(8):7427\u20137440. https:\/\/doi.org\/10.1109\/TCYB.2020.3041481","journal-title":"IEEE Trans Cybern"},{"key":"11428_CR14","doi-asserted-by":"publisher","first-page":"102676","DOI":"10.1016\/j.cose.2022.102676","volume":"117","author":"T Chen","year":"2022","unstructured":"Chen T, Ling J, Sun Y (2022) White-box content camouflage attacks against deep learning. Comput Secur 117:102676. https:\/\/doi.org\/10.1016\/j.cose.2022.102676","journal-title":"Comput Secur"},{"key":"11428_CR15","first-page":"10408","volume":"32","author":"C Laidlaw","year":"2019","unstructured":"Laidlaw C, Feizi S (2019) Functional adversarial attacks. Adv Neural Inf Process Syst 32:10408\u201310418","journal-title":"Adv Neural Inf Process Syst"},{"key":"11428_CR16","unstructured":"Ma J, Ding S, Mei Q (2020) Towards more practical adversarial attacks on graph neural networks. Advances in neural information processing systems"},{"key":"11428_CR17","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: 2016 IEEE European symposium on security and privacy, pp. 372\u2013387 . IEEE","DOI":"10.1109\/EuroSP.2016.36"},{"key":"11428_CR18","doi-asserted-by":"publisher","unstructured":"Tian B, Juefei-Xu F, Guo Q, Xie X, Li X, Liu Y (2021) Ava: adversarial vignetting attack against visual recognition. In: Zhou Z-H (Ed) Proceedings of the thirtieth international joint conference on artificial intelligence, IJCAI-21, pp. 1046\u20131053. International Joint Conferences on Artificial Intelligence Organization. https:\/\/doi.org\/10.24963\/ijcai.2021\/145 . Main Track","DOI":"10.24963\/ijcai.2021\/145"},{"key":"11428_CR19","doi-asserted-by":"publisher","unstructured":"Wang X, He K (2021) Enhancing the transferability of adversarial attacks through variance tuning. In: 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 1924\u20131933 . https:\/\/doi.org\/10.1109\/CVPR46437.2021.00196","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"11428_CR20","doi-asserted-by":"publisher","first-page":"102676","DOI":"10.1016\/j.cose.2022.102876","volume":"122","author":"H Zhang","year":"2022","unstructured":"Zhang H, Ma X (2022) Misleading attention and classification: an adversarial attack to fool object detection models in the real world. Comput Secur 122:102676. https:\/\/doi.org\/10.1016\/j.cose.2022.102876","journal-title":"Comput Secur"},{"key":"11428_CR21","doi-asserted-by":"publisher","first-page":"510","DOI":"10.1007\/978-3-031-25072-9_35","volume-title":"Computer Vision - ECCV 2022 Workshops","author":"S Pavlitskaya","year":"2023","unstructured":"Pavlitskaya S, Polley N, Weber M, Z\u00f6llner JM (2023) Adversarial vulnerability of temporal feature networks for object detection. In: Karlinsky L, Michaeli T, Nishino K (eds) Computer Vision - ECCV 2022 Workshops. Springer, Cham, pp 510\u2013525"},{"key":"11428_CR22","first-page":"103410","volume":"72","author":"Y Zhang","year":"2023","unstructured":"Zhang Y, Tan Y-A, Lu M, Liu L, Wang D, Zhang Q, Li Y (2023) Towards interpreting vulnerability of object detection models via adversarial distillation. J Inf Secur Appl 72:103410","journal-title":"J Inf Secur Appl"},{"key":"11428_CR23","doi-asserted-by":"crossref","unstructured":"Wang Z, Zhang C (2022) Attacking object detector by simultaneously learning perturbations and locations. Neural Process Lett. pp 1\u201316","DOI":"10.1007\/s11063-022-10983-7"},{"key":"11428_CR24","first-page":"12214","volume":"32","author":"J-B Alayrac","year":"2019","unstructured":"Alayrac J-B, Uesato J, Huang P-S, Fawzi A, Stanforth R, Kohli P (2019) Are labels required for improving adversarial robustness? Adv Neural Inf Process Syst 32:12214\u201312223","journal-title":"Adv Neural Inf Process Syst"},{"key":"11428_CR25","doi-asserted-by":"crossref","unstructured":"Aldahdooh A, Hamidouche W, Fezza S (2021) Adversarial example detection for DNN models: a review","DOI":"10.1007\/s10462-021-10125-w"},{"key":"11428_CR26","doi-asserted-by":"crossref","unstructured":"Zhang C, Benz P, Lin C, Karjauv A, Wu J, Kweon IS (2021) A survey on universal adversarial attack","DOI":"10.24963\/ijcai.2021\/635"},{"key":"11428_CR27","doi-asserted-by":"crossref","unstructured":"Co KT, Mu\"\u00f1oz-Gonz\u00e1lez L, Maupeou S, Lupu EC (2019) Procedural noise adversarial examples for black-box attacks on deep convolutional networks. In: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, pp. 275\u2013289","DOI":"10.1145\/3319535.3345660"},{"key":"11428_CR28","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Adversarial examples are not easily detected: bypassing ten detection methods. In: Proceedings of the 10th ACM workshop on artificial intelligence and security, pp. 3\u201314","DOI":"10.1145\/3128572.3140444"},{"key":"11428_CR29","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Fawzi O, Frossard P (2017) Universal adversarial perturbations. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 1765\u20131773","DOI":"10.1109\/CVPR.2017.17"},{"key":"11428_CR30","doi-asserted-by":"crossref","unstructured":"Khrulkov V, Oseledets I (2018) Art of singular vectors and universal adversarial perturbations. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 8562\u20138570","DOI":"10.1109\/CVPR.2018.00893"},{"key":"11428_CR31","doi-asserted-by":"crossref","unstructured":"Li J, Ji R, Liu H, Hong X, Gao Y, Tian Q (2019) Universal perturbation attack against image retrieval. In: Proceedings of the IEEE\/CVF international conference on computer vision, pp. 4899\u20134908","DOI":"10.1109\/ICCV.2019.00500"},{"key":"11428_CR32","unstructured":"Mopuri K, Garg U, Venkatesh\u00a0Babu R (2017) Fast feature fool: a data independent approach to universal adversarial perturbations. In: British machine vision conference 2017, BMVC 2017 . BMVA Press"},{"key":"11428_CR33","unstructured":"Li Y, Li L, Wang L, Zhang T, Gong B (2019) Nattack: learning the distributions of adversarial examples for an improved black-box attack on deep neural networks. In: International conference on machine learning, pp. 3866\u20133876 . PMLR"},{"key":"11428_CR34","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Frossard, P (2016) Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 2574\u20132582","DOI":"10.1109\/CVPR.2016.282"},{"key":"11428_CR35","doi-asserted-by":"crossref","unstructured":"Lin Y-C, Hong Z-W, Liao Y-H, Shih M-L, Liu M-Y, Sun M (2017) Tactics of adversarial attack on deep reinforcement learning agents","DOI":"10.24963\/ijcai.2017\/525"},{"key":"11428_CR36","unstructured":"Ilyas A, Engstrom L, Athalye A, Lin J (2018) Black-box adversarial attacks with limited queries and information. In: International conference on machine learning, pp. 2137\u20132146 . PMLR"},{"key":"11428_CR37","doi-asserted-by":"crossref","unstructured":"Chen P-Y, Zhang H, Sharma Y, Yi J, Hsieh C-J (2017) Zoo: zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM workshop on artificial intelligence and security, pp. 15\u201326","DOI":"10.1145\/3128572.3140448"},{"issue":"5","key":"11428_CR38","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su J, Vargas DV, Sakurai K (2019) One pixel attack for fooling deep neural networks. IEEE Trans Evol Comput 23(5):828\u2013841","journal-title":"IEEE Trans Evol Comput"},{"key":"11428_CR39","doi-asserted-by":"crossref","unstructured":"Liu H, Ji R, Li J, Zhang B, Gao Y, Wu Y, Huang F (2019) Universal adversarial perturbation via prior driven uncertainty approximation. In: Proceedings of the IEEE\/CVF international conference on computer vision, pp. 2941\u20132949","DOI":"10.1109\/ICCV.2019.00303"},{"key":"11428_CR40","unstructured":"Moon S, An G, Song HO (2019) Parsimonious black-box adversarial attacks via efficient combinatorial optimization. In: International conference on machine learning, pp. 4636\u20134645 . PMLR"},{"key":"11428_CR41","doi-asserted-by":"crossref","unstructured":"Hayes J, Danezis G (2018) Learning universal adversarial perturbations with generative models. In: 2018 IEEE security and privacy workshops (SPW), pp. 43\u201349 . IEEE","DOI":"10.1109\/SPW.2018.00015"},{"key":"11428_CR42","unstructured":"Perolat J, Malinowski M, Piot B, Pietquin O (2018) Playing the game of universal adversarial perturbations"},{"key":"11428_CR43","unstructured":"Mirza M, Osindero, S (2014) Conditional generative adversarial nets"},{"key":"11428_CR44","doi-asserted-by":"crossref","unstructured":"Tsingenopoulos I, Preuveneers D, Joosen W (2019) Autoattacker: a reinforcement learning approach for black-box adversarial attacks. In: 2019 IEEE European symposium on security and privacy workshops (EuroS &PW), pp. 229\u2013237 . IEEE","DOI":"10.1109\/EuroSPW.2019.00032"},{"key":"11428_CR45","unstructured":"Kurakin A, Goodfellow IJ, Bengio S (2016) Adversarial examples in the physical world"},{"key":"11428_CR46","unstructured":"Athalye A, Engstrom L, Ilyas A, Kwok K (2018) Synthesizing robust adversarial examples. In: International conference on machine learning, pp. 284\u2013293 . PMLR"},{"key":"11428_CR47","doi-asserted-by":"crossref","unstructured":"Chen P-C, Kung B-H, Chen J-C (2021) Class-aware robust adversarial training for object detection. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR), pp. 10420\u201310429","DOI":"10.1109\/CVPR46437.2021.01028"},{"key":"11428_CR48","first-page":"12905","volume":"32","author":"MM Naseer","year":"2019","unstructured":"Naseer MM, Khan SH, Khan MH, Shahbaz Khan F, Porikli F (2019) Cross-domain transferability of adversarial perturbations. Adv Neural Inf Process Syst 32:12905\u201312915","journal-title":"Adv Neural Inf Process Syst"},{"key":"11428_CR49","doi-asserted-by":"publisher","unstructured":"Wei X, Liang S, Chen N, Cao X (2019) Transferable adversarial attacks for image and video object detection. In: Proceedings of the twenty-eighth international joint conference on artificial intelligence, pp. 954\u2013960. International Joint Conferences on Artificial Intelligence Organization, https:\/\/doi.org\/10.24963\/ijcai.2019\/134","DOI":"10.24963\/ijcai.2019\/134"},{"key":"11428_CR50","doi-asserted-by":"crossref","unstructured":"Xie C, Wang J, Zhang Z, Zhou Y, Xie L, Yuille A (2017) Adversarial examples for semantic segmentation and object detection. In: Proceedings of the IEEE international conference on computer vision, pp. 1369\u20131378","DOI":"10.1109\/ICCV.2017.153"},{"key":"11428_CR51","doi-asserted-by":"crossref","unstructured":"Chen S-T, Cornelius C, Martin J, Chau DH (2018) Robust physical adversarial attack on faster r-cnn object detector. In: ECML\/PKDD","DOI":"10.1007\/978-3-030-10925-7_4"},{"key":"11428_CR52","doi-asserted-by":"crossref","unstructured":"Zolfi A, Kravchik M, Elovici Y, Shabtai A (2021) The translucent patch: a physical and universal attack on object detectors. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp. 15232\u201315241","DOI":"10.1109\/CVPR46437.2021.01498"},{"key":"11428_CR53","unstructured":"Mirsky Y (2021) IPatch: a remote adversarial patch"},{"key":"11428_CR54","unstructured":"Liu X, Yang H, Liu Z, Song L, Chen Y, Li H (2019) Dpatch: an adversarial patch attack on object detectors. In: SafeAI@ AAAI"},{"key":"11428_CR55","doi-asserted-by":"crossref","unstructured":"Jia S, Song Y, Ma C, Yang X (2021) Iou attack: towards temporally coherent black-box adversarial attack for visual object tracking. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp. 6709\u20136718","DOI":"10.1109\/CVPR46437.2021.00664"},{"key":"11428_CR56","unstructured":"Hendrycks D, Gimpel K (2016) Early methods for detecting adversarial images"},{"key":"11428_CR57","doi-asserted-by":"crossref","unstructured":"Rony J, Hafemann LG, Oliveira LS, Ayed IB, Sabourin R, Granger E (2019) Decoupling direction and norm for efficient gradient-based l2 adversarial attacks and defenses. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp. 4322\u20134330","DOI":"10.1109\/CVPR.2019.00445"},{"key":"11428_CR58","doi-asserted-by":"crossref","unstructured":"Carlini N, Wagner D (2017) Towards evaluating the robustness of neural networks. In: 2017 IEEE symposium on security and privacy (sp), pp. 39\u201357 . IEEE","DOI":"10.1109\/SP.2017.49"},{"key":"11428_CR59","doi-asserted-by":"crossref","unstructured":"Kim Y-D, Park E, Yoo S, Choi T, Yang L, Shin D (2015) Compression of deep convolutional neural networks for fast and low power mobile applications","DOI":"10.14257\/astl.2016.140.36"},{"issue":"2","key":"11428_CR60","doi-asserted-by":"publisher","first-page":"695","DOI":"10.1137\/120868323","volume":"23","author":"L Sorber","year":"2013","unstructured":"Sorber L, Van Barel M, De Lathauwer L (2013) Optimization-based algorithms for tensor decompositions: canonical polyadic decomposition, decomposition in rank-(l_r, l_r,1) terms, and a new generalization. SIAM J Optim 23(2):695\u2013720","journal-title":"SIAM J Optim"},{"key":"11428_CR61","unstructured":"Everingham M, Winn J (2011) The pascal visual object classes challenge 2012 (voc2012) development kit. Pattern Analysis, Statistical Modelling and Computational Learning, Tech Rep. 8"},{"key":"11428_CR62","doi-asserted-by":"crossref","unstructured":"Lin T-Y, Maire M, Belongie S, Hays J, Perona P, Ramanan D, Doll\u00e1r P, Zitnick CL (2014) Microsoft coco: common objects in context. In: European conference on computer vision, pp. 740\u2013755 . Springer","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"11428_CR63","doi-asserted-by":"crossref","unstructured":"Cohen G, Afshar S, Tapson J, Van\u00a0Schaik A (2017) Emnist: extending mnist to handwritten letters. In: 2017 International joint conference on neural networks (IJCNN), pp. 2921\u20132926 . IEEE","DOI":"10.1109\/IJCNN.2017.7966217"},{"key":"11428_CR64","unstructured":"Jocher G (2020) yolov5. Accessed: 2020-07-10 . https:\/\/github.com\/ultralytics\/yolov5"},{"key":"11428_CR65","doi-asserted-by":"crossref","unstructured":"Girshick R (2015) Fast r-cnn. In: Proceedings of the IEEE International conference on computer vision, pp. 1440\u20131448","DOI":"10.1109\/ICCV.2015.169"},{"key":"11428_CR66","doi-asserted-by":"crossref","unstructured":"He K, Zhang X, Ren S, Sun J (2016) Deep residual learning for image recognition. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 770\u2013778","DOI":"10.1109\/CVPR.2016.90"},{"key":"11428_CR67","unstructured":"Ilyas A, Engstrom L, Athalye A, Lin J (2018) Black-box adversarial attacks with limited queries and information. In: International conference on machine learning, pp. 2137\u20132146 . PMLR"},{"key":"11428_CR68","unstructured":"Liu S, Chen P-Y, Chen X, Hong M (2017) signsgd via zeroth-order oracle. In: International conference on learning representations"},{"key":"11428_CR69","unstructured":"Al-Dujaili A, O\u2019Reilly U-M (2020) Sign bits are all you need for black-box attacks. In: International conference on learning representations"},{"key":"11428_CR70","doi-asserted-by":"crossref","unstructured":"Andriushchenko M, Croce F, Flammarion N, Hein M (2020) Square attack: a query-efficient black-box adversarial attack via random search. In: Computer Vision\u2013ECCV 2020: 16th European conference, Glasgow, UK, August 23\u201328, 2020, Proceedings, Part XXIII, pp. 484\u2013501 . Springer","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"11428_CR71","doi-asserted-by":"crossref","unstructured":"Liang S, Wu B, Fan Y, Wei X, Cao X (2021) Parallel rectangle flip attack: a query-based black-box attack against object detection. In: Proceedings of the IEEE\/CVF international conference on computer vision, pp. 7697\u20137707","DOI":"10.1109\/ICCV48922.2021.00760"},{"key":"11428_CR72","doi-asserted-by":"crossref","unstructured":"Zhu Z, Liang D, Zhang S, Huang X, Li B, Hu S (2016) Traffic-sign detection and classification in the wild. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 2110\u20132118 (2016)","DOI":"10.1109\/CVPR.2016.232"}],"container-title":["Neural Processing Letters"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11063-023-11428-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11063-023-11428-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11063-023-11428-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,12,27]],"date-time":"2023-12-27T09:25:59Z","timestamp":1703669159000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11063-023-11428-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,17]]},"references-count":72,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2023,12]]}},"alternative-id":["11428"],"URL":"https:\/\/doi.org\/10.1007\/s11063-023-11428-5","relation":{},"ISSN":["1370-4621","1573-773X"],"issn-type":[{"type":"print","value":"1370-4621"},{"type":"electronic","value":"1573-773X"}],"subject":[],"published":{"date-parts":[[2023,10,17]]},"assertion":[{"value":"26 September 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 October 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}