{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T20:26:09Z","timestamp":1782419169359,"version":"3.54.5"},"reference-count":54,"publisher":"Springer Science and Business Media LLC","issue":"11","license":[{"start":{"date-parts":[[2025,8,27]],"date-time":"2025-08-27T00:00:00Z","timestamp":1756252800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,8,27]],"date-time":"2025-08-27T00:00:00Z","timestamp":1756252800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62032006"],"award-info":[{"award-number":["62032006"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int J Comput Vis"],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1007\/s11263-025-02552-x","type":"journal-article","created":{"date-parts":[[2025,8,27]],"date-time":"2025-08-27T15:58:42Z","timestamp":1756310322000},"page":"8041-8058","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["What Do Visual Models Look At? Dilated Attention for Targeted Transferable Attacks"],"prefix":"10.1007","volume":"133","author":[{"given":"Zhipeng","family":"Wei","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jingjing","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu-Gang","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,8,27]]},"reference":[{"key":"2552_CR1","unstructured":"Agarap, A.F.: Deep learning using rectified linear units (relu). arxiv preprint arXiv:1803.08375 (2018)"},{"key":"2552_CR2","doi-asserted-by":"crossref","unstructured":"Byun, J., Cho, S., Kwon, M.-J., Kim, H.-S., Kim, C.: Improving the transferability of targeted adversarial examples through object-based diverse input. In: CVPR, pp. 15244\u201315253 (2022)","DOI":"10.1109\/CVPR52688.2022.01481"},{"key":"2552_CR3","doi-asserted-by":"crossref","unstructured":"Byun, J., Kwon, M.-J., Cho, S., Kim, Y., Kim, C.: Introducing competition to boost the transferability of targeted adversarial examples through clean feature mixup. In: CVPR, pp. 24648\u201324657 (2023)","DOI":"10.1109\/CVPR52729.2023.02361"},{"key":"2552_CR4","doi-asserted-by":"crossref","unstructured":"Chattopadhay, A., Sarkar, A., Howlader, P., Balasubramanian, V.N.: Grad-cam++: Generalized gradient-based visual explanations for deep convolutional networks. In: WACV, pp. 839\u2013847 (2018). IEEE","DOI":"10.1109\/WACV.2018.00097"},{"key":"2552_CR5","unstructured":"Chen, H., Zhang, Y., Dong, Y., Yang, X., Su, H., Zhu, J.: Rethinking model ensemble in transfer-based adversarial attacks. arXiv preprint arXiv:2303.09105 (2023)"},{"key":"2552_CR6","unstructured":"Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., Gelly, S., Uszkoreit, J., Houlsby, N.: An image is worth 16x16 words: Transformers for image recognition at scale. In: ICLR (2021)"},{"key":"2552_CR7","doi-asserted-by":"crossref","unstructured":"Dong, Y., Liao, F., Pang, T., Su, H., Zhu, J., Hu, X., Li, J.: Boosting adversarial attacks with momentum. In: CVPR, pp. 9185\u20139193 (2018)","DOI":"10.1109\/CVPR.2018.00957"},{"key":"2552_CR8","doi-asserted-by":"crossref","unstructured":"Dong, Y., Pang, T., Su, H., Zhu, J.: Evading defenses to transferable adversarial examples by translation-invariant attacks. In: CVPR, pp. 4312\u20134321 (2019)","DOI":"10.1109\/CVPR.2019.00444"},{"key":"2552_CR9","unstructured":"Diao, Y., Wu, B., Zhang, R., Liu, A., Hao, X., Wei, X., Wang, M., Wang, H.: Tasar: Transfer-based attack on skeletal action recognition. arXiv preprint arXiv:2409.02483 (2024)"},{"key":"2552_CR10","first-page":"85","volume":"33","author":"Y Guo","year":"2020","unstructured":"Guo, Y., Li, Q., & Chen, H. (2020). Backpropagating linearly improves transferability of adversarial examples, 33, 85\u201395.","journal-title":"Backpropagating linearly improves transferability of adversarial examples"},{"key":"2552_CR11","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: ICLR (2015)"},{"key":"2552_CR12","doi-asserted-by":"crossref","unstructured":"Huang, Y., Dong, Y., Ruan, S., Yang, X., Su, H., Wei, X.: Towards transferable targeted 3d adversarial attack in the physical world. In: CVPR, pp. 24512\u201324522 (2024)","DOI":"10.1109\/CVPR52733.2024.02314"},{"key":"2552_CR13","unstructured":"Huang, Y., Kong, A.W.-K.: Transferable adversarial attack based on integrated gradients. In: ICLR (2022)"},{"key":"2552_CR14","doi-asserted-by":"crossref","unstructured":"Huang, Q., Katsman, I., He, H., Gu, Z., Belongie, S., Lim, S.-N.: Enhancing adversarial example transferability with an intermediate level attack. In: ICCV, pp. 4733\u20134742 (2019)","DOI":"10.1109\/ICCV.2019.00483"},{"key":"2552_CR15","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Weinberger, K.Q.: Densely connected convolutional networks. In: CVPR, pp. 2261\u20132269 (2017)","DOI":"10.1109\/CVPR.2017.243"},{"key":"2552_CR16","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: CVPR, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"2552_CR17","unstructured":"Inkawhich, N., Liang, K.J., Carin, L., Chen, Y.: Transferable perturbations of deep feature distributions. arXiv preprint arXiv:2004.12519 (2020)"},{"key":"2552_CR18","unstructured":"Inkawhich, N., Liang, K., Wang, B., Inkawhich, M., Carin, L., Chen, Y.: Perturbing across the feature hierarchy to improve standard and strict blackbox attack transferability. In: NeurIPS, vol. 33, pp. 20791\u201320801 (2020)"},{"key":"2552_CR19","unstructured":"Ioffe, S., Szegedy, C.: Batch normalization: Accelerating deep network training by reducing internal covariate shift. In: ICML, pp. 448\u2013456 (2015). pmlr"},{"key":"2552_CR20","doi-asserted-by":"crossref","unstructured":"Inkawhich, N., Wen, W., Li, H.H., Chen, Y.: Feature space perturbations yield more transferable adversarial examples. In: CVPR, pp. 7059\u20137067 (2019)","DOI":"10.1109\/CVPR.2019.00723"},{"key":"2552_CR21","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. In: Artificial Intelligence Safety and Security, pp. 99\u2013112 (2018)","DOI":"10.1201\/9781351251389-8"},{"key":"2552_CR22","unstructured":"Liu, Y., Chen, X., Liu, C., Song, D.: Delving into transferable adversarial examples and black-box attacks. In: ICLR (2017)"},{"key":"2552_CR23","unstructured":"Liu, C., Chen, H., Zhang, Y., Dong, Y., Zhu, J.: Scaling laws for black box adversarial attacks. arXiv preprint arXiv:2411.16782 (2024)"},{"key":"2552_CR24","doi-asserted-by":"crossref","unstructured":"Li, M., Deng, C., Li, T., Yan, J., Gao, X., Huang, H.: Towards transferable targeted attack. In: CVPR, pp. 638\u2013646 (2020)","DOI":"10.1109\/CVPR42600.2020.00072"},{"key":"2552_CR25","doi-asserted-by":"crossref","unstructured":"Liang, K., Dai, X., Li, Y., Wang, D., Xiao, B.: Improving transferable targeted attacks with feature tuning mixup. In: CVPR, pp. 25802\u201325811 (2025)","DOI":"10.1109\/CVPR52734.2025.02403"},{"key":"2552_CR26","doi-asserted-by":"crossref","unstructured":"Liang, J., Liang, S., Liu, A., Cao, X.: Vl-trojan: Multimodal instruction backdoor attacks against autoregressive visual language models. In: IJCV, pp. 1\u201320 (2025)","DOI":"10.1007\/s11263-025-02368-9"},{"key":"2552_CR27","doi-asserted-by":"crossref","unstructured":"Liu, A., Liu, X., Zhang, X., Xiao, Y., Zhou, Y., Liang, S., Wang, J., Cao, X., Tao, D.: Pre-trained trojan attacks for visual recognition. In: IJCV, vol. 133, pp. 3568\u20133585 (2025)","DOI":"10.1007\/s11263-024-02333-y"},{"key":"2552_CR28","unstructured":"Lin, J., Song, C., He, K., Wang, L., Hopcroft, J.E.: Nesterov accelerated gradient and scale invariance for adversarial attacks. In: ICLR (2020)"},{"key":"2552_CR29","doi-asserted-by":"crossref","unstructured":"Naseer, M., Khan, S., Hayat, M., Khan, F.S., Porikli, F.: On generating transferable targeted perturbations. In: ICCV, pp. 7708\u20137717 (2021)","DOI":"10.1109\/ICCV48922.2021.00761"},{"key":"2552_CR30","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A.: Practical black-box attacks against machine learning. In: ASIACCS, pp. 506\u2013519 (2017)","DOI":"10.1145\/3052973.3053009"},{"key":"2552_CR31","unstructured":"Qin, Z., Fan, Y., Liu, Y., Shen, L., Zhang, Y., Wang, J., Wu, B.: Boosting the transferability of adversarial attacks with reverse adversarial perturbation. In: NeurIPS, vol. 35, pp. 29845\u201329858 (2022)"},{"key":"2552_CR32","doi-asserted-by":"crossref","unstructured":"Selvaraju, R.R., Das, A., Vedantam, R., Cogswell, M., Parikh, D., Batra, D.: Grad-cam: Visual explanations from deep networks via gradient-based localization. In: IJCV, vol. 128, pp. 336\u2013359 (2017)","DOI":"10.1007\/s11263-019-01228-7"},{"key":"2552_CR33","unstructured":"Sundararajan, M., Taly, A., Yan, Q.: Axiomatic attribution for deep networks. In: ICML, pp. 3319\u20133328 (2017). PMLR"},{"key":"2552_CR34","doi-asserted-by":"crossref","unstructured":"Szegedy, C., Vanhoucke, V., Ioffe, S., Shlens, J., Wojna, Z.: Rethinking the inception architecture for computer vision. In: CVPR, pp. 2818\u20132826 (2016)","DOI":"10.1109\/CVPR.2016.308"},{"key":"2552_CR35","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014)"},{"key":"2552_CR36","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., Fergus, R.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)"},{"key":"2552_CR37","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., McDaniel, P.: Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204 (2017)"},{"key":"2552_CR38","doi-asserted-by":"crossref","unstructured":"Wei, Z., Chen, J., Goldblum, M., Wu, Z., Goldstein, T., Jiang, Y.-G.: Towards transferable adversarial attacks on vision transformers. In: AAAI, vol. 36, pp. 2668\u20132676 (2022)","DOI":"10.1609\/aaai.v36i3.20169"},{"key":"2552_CR39","doi-asserted-by":"crossref","unstructured":"Wei, Z., Chen, J., Wu, Z., Jiang, Y.-G.: Boosting the transferability of video adversarial examples via temporal translation. In: AAAI, vol. 36, pp. 2659\u20132667 (2022)","DOI":"10.1609\/aaai.v36i3.20168"},{"key":"2552_CR40","doi-asserted-by":"crossref","unstructured":"Wei, Z., Chen, J., Wu, Z., Jiang, Y.-G.: Enhancing the self-universality for transferable targeted attacks. In: CVPR, pp. 12281\u201312290 (2023)","DOI":"10.1109\/CVPR52729.2023.01182"},{"key":"2552_CR41","doi-asserted-by":"crossref","unstructured":"Wang, Z., Guo, H., Zhang, Z., Liu, W., Qin, Z., Ren, K.: Feature importance-aware transferable adversarial attacks. In: ICCV, pp. 7639\u20137648 (2021)","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"2552_CR42","doi-asserted-by":"crossref","unstructured":"Wang, X., He, K.: Enhancing the transferability of adversarial attacks through variance tuning. In: CVPR, pp. 1924\u20131933 (2021)","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"2552_CR43","doi-asserted-by":"crossref","unstructured":"Wang, X., He, X., Wang, J., He, K.: Admix: Enhancing the transferability of adversarial attacks. In: ICCV, pp. 16158\u201316167 (2021)","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"2552_CR44","doi-asserted-by":"crossref","unstructured":"Wei, X., Ruan, S., Dong, Y., Su, H., Cao, X.: Distributionally location-aware transferable adversarial patches for facial images. In: IEEE Transactions on PAMI (2025)","DOI":"10.1109\/TPAMI.2025.3526188"},{"key":"2552_CR45","doi-asserted-by":"crossref","unstructured":"Wu, W., Su, Y., Chen, X., Zhao, S., King, I., Lyu, M.R., Tai, Y.-W.: Boosting the transferability of adversarial samples via attention. In: CVPR, pp. 1161\u20131170 (2020)","DOI":"10.1109\/CVPR42600.2020.00124"},{"key":"2552_CR46","unstructured":"Wu, D., Wang, Y., Xia, S.-T., Bailey, J., Ma, X.: Skip connections matter: On the transferability of adversarial examples generated with resnets. In: ICLR (2020)"},{"key":"2552_CR47","doi-asserted-by":"crossref","unstructured":"Wang, Z., Yang, H., Feng, Y., Sun, P., Guo, H., Zhang, Z., Ren, K.: Towards transferable targeted adversarial examples. In: CVPR, pp. 20534\u201320543 (2023)","DOI":"10.1109\/CVPR52729.2023.01967"},{"key":"2552_CR48","doi-asserted-by":"crossref","unstructured":"Wang, G., Yan, H., Wei, X.: Enhancing transferability of adversarial examples with spatial momentum. In: Chinese Conference on PRCV, pp. 593\u2013604 (2022)","DOI":"10.1007\/978-3-031-18907-4_46"},{"key":"2552_CR49","doi-asserted-by":"crossref","unstructured":"Wei, X., Zhao, S.: Boosting adversarial transferability with learnable patch-wise masks. In: IEEE Transactions on Multimedia, vol. 26, pp. 3778\u20133787 (2023)","DOI":"10.1109\/TMM.2023.3315550"},{"key":"2552_CR50","doi-asserted-by":"crossref","unstructured":"Xie, C., Zhang, Z., Zhou, Y., Bai, S., Wang, J., Ren, Z., Yuille, A.L.: Improving transferability of adversarial examples with input diversity. In: CVPR, pp. 2730\u20132739 (2019)","DOI":"10.1109\/CVPR.2019.00284"},{"key":"2552_CR51","unstructured":"Yosinski, J., Clune, J., Bengio, Y., Lipson, H.: How transferable are features in deep neural networks? In: NeurIPS, vol. 27 (2014)"},{"key":"2552_CR52","doi-asserted-by":"crossref","unstructured":"Yang, X., Dong, Y., Pang, T., Su, H., Zhu, J.: Boosting transferability of targeted adversarial examples via hierarchical generative networks. In: ECCV, pp. 725\u2013742 (2022). Springer","DOI":"10.1007\/978-3-031-19772-7_42"},{"key":"2552_CR53","doi-asserted-by":"crossref","unstructured":"Zhao, A., Chu, T., Liu, Y., Li, W., Li, J., Duan, L.: Minimizing maximum model discrepancy for transferable black-box targeted attacks. In: CVPR, pp. 8153\u20138162 (2023)","DOI":"10.1109\/CVPR52729.2023.00788"},{"key":"2552_CR54","unstructured":"Zhao, Z., Liu, Z., Larson, M.: On success and simplicity: A second look at transferable targeted attacks. In: NeurIPS, vol. 34, pp. 6115\u20136128 (2021)"}],"container-title":["International Journal of Computer Vision"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-025-02552-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11263-025-02552-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11263-025-02552-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T06:28:49Z","timestamp":1762928929000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11263-025-02552-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,27]]},"references-count":54,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2025,11]]}},"alternative-id":["2552"],"URL":"https:\/\/doi.org\/10.1007\/s11263-025-02552-x","relation":{},"ISSN":["0920-5691","1573-1405"],"issn-type":[{"value":"0920-5691","type":"print"},{"value":"1573-1405","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,8,27]]},"assertion":[{"value":"17 December 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 July 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 August 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}