{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T18:38:57Z","timestamp":1783967937206,"version":"3.55.0"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T00:00:00Z","timestamp":1765497600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T00:00:00Z","timestamp":1768262400000},"content-version":"vor","delay-in-days":32,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"name":"the University Stability Support Program of Shenzhen","award":["GXWD20231130113127003"],"award-info":[{"award-number":["GXWD20231130113127003"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Complex Intell. Syst."],"published-print":{"date-parts":[[2026,2]]},"DOI":"10.1007\/s40747-025-02184-1","type":"journal-article","created":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T08:18:30Z","timestamp":1765527510000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Llm-ga: A gradient-based multi-label adversarial attack by large language models"],"prefix":"10.1007","volume":"12","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8357-1655","authenticated-orcid":false,"given":"Yujiang","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yamin","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhijian","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiyin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenjian","family":"Luo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,12,12]]},"reference":[{"key":"2184_CR1","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2013) Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199"},{"key":"2184_CR2","doi-asserted-by":"publisher","unstructured":"Zhou H, Li W, Kong Z, Guo J, Zhang Y, Yu B, Zhang L, Liu C (2020) Deepbillboard: Systematic physical-world testing of autonomous driving systems. In: Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, pp. 347\u2013358. https:\/\/doi.org\/10.1145\/3377811.3380422","DOI":"10.1145\/3377811.3380422"},{"key":"2184_CR3","doi-asserted-by":"publisher","unstructured":"Yang X, Liu C, Xu L, Wang Y, Dong Y, Chen N, Su H, Zhu J (2023) Towards effective adversarial textured 3d meshes on physical face recognition. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4119\u20134128. https:\/\/doi.org\/10.1109\/cvpr52729.2023.00401","DOI":"10.1109\/cvpr52729.2023.00401"},{"key":"2184_CR4","doi-asserted-by":"publisher","unstructured":"Wang X, He K (2021) Enhancing the transferability of adversarial attacks through variance tuning. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, p. 1924\u20131933. https:\/\/doi.org\/10.1109\/CVPR46437.2021.00196","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"2184_CR5","doi-asserted-by":"publisher","first-page":"109037","DOI":"10.1016\/j.patcog.2022.109037","volume":"133","author":"Y Bai","year":"2023","unstructured":"Bai Y, Wang Y, Zeng Y, Jiang Y, Xia S-T (2023) Query efficient black-box adversarial attack on deep neural networks. Pattern Recogn 133:109037. https:\/\/doi.org\/10.1016\/j.patcog.2022.109037","journal-title":"Pattern Recogn"},{"key":"2184_CR6","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Frossard P (2016) Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 2574\u20132582. https:\/\/doi.org\/10.1109\/CVPR.2016.282","DOI":"10.1109\/CVPR.2016.282"},{"key":"2184_CR7","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli S-M, Fawzi A, Fawzi O, Frossard P (2017) Universal adversarial perturbations. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 1765\u20131773","DOI":"10.1109\/CVPR.2017.17"},{"key":"2184_CR8","doi-asserted-by":"publisher","unstructured":"Dabouei A, Soleymani S, Taherkhani F, Dawson J, Nasrabadi N (2020) Smoothfool: an efficient framework for computing smooth adversarial perturbations. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pp. 2665\u20132674. https:\/\/doi.org\/10.1109\/wacv45572.2020.9093429","DOI":"10.1109\/wacv45572.2020.9093429"},{"key":"2184_CR9","doi-asserted-by":"publisher","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A, The limitations of deep learning in adversarial settings. In: 2016 IEEE European Symposium on Security and Privacy (EuroS &P). IEEE 2016:372\u2013387. https:\/\/doi.org\/10.1109\/EuroSP.2016.36","DOI":"10.1109\/EuroSP.2016.36"},{"key":"2184_CR10","doi-asserted-by":"publisher","unstructured":"Carlini N, Wagner D, Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Srivacy (SP). Ieee 2017:39\u201357. https:\/\/doi.org\/10.1109\/sp.2017.49","DOI":"10.1109\/sp.2017.49"},{"key":"2184_CR11","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/access.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar N, Mian A (2018) Threat of adversarial attacks on deep learning in computer vision: a survey. IEEE Access 6:14410\u201314430. https:\/\/doi.org\/10.1109\/access.2018.2807385","journal-title":"IEEE Access"},{"key":"2184_CR12","doi-asserted-by":"publisher","unstructured":"Zhou N, Luo W, Lin X, Xu P, Zhang Z, Generating multi-label adversarial examples by linear programming. In: 2020 international joint conference on neural networks (IJCNN). IEEE 2020:1\u20138. https:\/\/doi.org\/10.1109\/ijcnn48605.2020.9206614","DOI":"10.1109\/ijcnn48605.2020.9206614"},{"key":"2184_CR13","doi-asserted-by":"publisher","unstructured":"Zhou N, Luo W, Zhang J, Kong L, Zhang H (2021) Hiding all labels for multi-label images: an empirical study of adversarial examples. In: 2021 International Joint Conference on Neural Networks (IJCNN), IEEE, pp. 1\u20138. https:\/\/doi.org\/10.1109\/ijcnn52387.2021.9534067","DOI":"10.1109\/ijcnn52387.2021.9534067"},{"key":"2184_CR14","doi-asserted-by":"publisher","unstructured":"Hu S, Ke L, Wang X, Lyu S (2021) Tkml-ap: Adversarial attacks to top-k multi-label learning. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 7649\u20137657. https:\/\/doi.org\/10.1109\/iccv48922.2021.00755","DOI":"10.1109\/iccv48922.2021.00755"},{"key":"2184_CR15","doi-asserted-by":"publisher","unstructured":"Ma M, Zheng W, Lv W, Ren L, Su H, Yin Z (2023) Multi-label adversarial attack based on label correlation. In: 2023 IEEE International Conference on Image Processing (ICIP), IEEE, pp. 2050\u20132054. https:\/\/doi.org\/10.1109\/icip49359.2023.10222512","DOI":"10.1109\/icip49359.2023.10222512"},{"key":"2184_CR16","doi-asserted-by":"publisher","DOI":"10.1109\/tip.2024.3411927","author":"F Su","year":"2024","unstructured":"Su F, Wu O, Zhu W (2024) Multi-label adversarial attack with new measures and self-paced constraint weighting. IEEE Trans Image Process. https:\/\/doi.org\/10.1109\/tip.2024.3411927","journal-title":"IEEE Trans Image Process"},{"issue":"9","key":"2184_CR17","doi-asserted-by":"publisher","first-page":"1757","DOI":"10.1016\/j.patcog.2004.03.009","volume":"37","author":"MR Boutell","year":"2004","unstructured":"Boutell MR, Luo J, Shen X, Brown CM (2004) Learning multi-label scene classification. Pattern Recogn 37(9):1757\u20131771. https:\/\/doi.org\/10.1016\/j.patcog.2004.03.009","journal-title":"Pattern Recogn"},{"issue":"8","key":"2184_CR18","doi-asserted-by":"publisher","first-page":"1819","DOI":"10.1109\/TKDE.2013.39","volume":"26","author":"M-L Zhang","year":"2013","unstructured":"Zhang M-L, Zhou Z-H (2013) A review on multi-label learning algorithms. IEEE Trans Knowl Data Eng 26(8):1819\u20131837","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"2184_CR19","doi-asserted-by":"publisher","unstructured":"Kurata G, Xiang B, Zhou B (2016) Improved neural network-based multi-label classification with better initialization leveraging label co-occurrence. In: Proceedings of the 2016 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, pp. 521\u2013526. https:\/\/doi.org\/10.18653\/v1\/N16-1063","DOI":"10.18653\/v1\/N16-1063"},{"key":"2184_CR20","doi-asserted-by":"publisher","first-page":"6667","DOI":"10.1007\/s40747-024-01506-z","volume":"10","author":"Z Chen","year":"2024","unstructured":"Chen Z, Luo W, Naseem ML, Kong L, Yang X (2024) Comprehensive comparisons of gradient-based multi-label adversarial attacks. Complex Intell Syst 10:6667\u20136692. https:\/\/doi.org\/10.1007\/s40747-024-01506-z","journal-title":"Complex Intell Syst"},{"key":"2184_CR21","doi-asserted-by":"publisher","DOI":"10.1109\/tai.2024.3522869","author":"L Kong","year":"2024","unstructured":"Kong L, Luo W, Ye Z, Zhou Q, Jia Y (2024) Multi-label black-box adversarial attacks only with predicted labels. IEEE Transa Artif Intell. https:\/\/doi.org\/10.1109\/tai.2024.3522869","journal-title":"IEEE Transa Artif Intell"},{"key":"2184_CR22","doi-asserted-by":"publisher","unstructured":"Sel B, Al-Tawaha A, Khattar V, Jia R, Jin M (2023) Algorithm of thoughts: Enhancing exploration of ideas in large language models. https:\/\/doi.org\/10.48550\/arXiv.2308.10379. arXiv preprint arXiv:2308.10379","DOI":"10.48550\/arXiv.2308.10379"},{"issue":"7995","key":"2184_CR23","doi-asserted-by":"publisher","first-page":"468","DOI":"10.1038\/s41586-023-06924-6","volume":"625","author":"B Romera-Paredes","year":"2024","unstructured":"Romera-Paredes B, Barekatain M, Novikov A, Balog M, Kumar MP, Dupont E, Ruiz FJ, Ellenberg JS, Wang P, Fawzi O et al (2024) Mathematical discoveries from program search with large language models. Nature 625(7995):468\u2013475. https:\/\/doi.org\/10.1038\/s41586-023-06924-6","journal-title":"Nature"},{"key":"2184_CR24","unstructured":"Wu X, Zhong Y, Wu J, Tan KC (2023) As-llm: when algorithm selection meets large language model. arXiv preprint arXiv:2311.13184"},{"key":"2184_CR25","doi-asserted-by":"publisher","unstructured":"Nasir MU, Earle S, Togelius J, James S, Cleghorn C (2024) Llmatic: neural architecture search via large language models and quality diversity optimization. In: Proceedings of the Genetic and Evolutionary Computation Conference, pp. 1110\u20131118. https:\/\/doi.org\/10.1145\/3638529.3654017","DOI":"10.1145\/3638529.3654017"},{"key":"2184_CR26","unstructured":"Liu F, Xialiang T, Yuan M, Lin X, Luo F, Wang Z, Lu Z, Zhang Q (2024) Evolution of heuristics: Towards efficient automatic algorithm design using large language model. In: International Conference on Machine Learning, PMLR, pp. 32201\u201332223"},{"key":"2184_CR27","unstructured":"Goodfellow IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572"},{"key":"2184_CR28","doi-asserted-by":"crossref","unstructured":"Kurakin A, Goodfellow IJ, Bengio S (2018) Adversarial examples in the physical world. In: Artificial intelligence safety and security. Chapman and Hall\/CRC, pp. 99\u2013112","DOI":"10.1201\/9781351251389-8"},{"key":"2184_CR29","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2017) Towards deep learning models resistant to adversarial attacks. Stat 1050(9)"},{"key":"2184_CR30","doi-asserted-by":"publisher","unstructured":"Dong Y, Liao F, Pang T, Su H, Zhu J, Hu X, Li J (2018) Boosting adversarial attacks with momentum. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 9185\u20139193. https:\/\/doi.org\/10.1109\/cvpr.2018.00957","DOI":"10.1109\/cvpr.2018.00957"},{"key":"2184_CR31","doi-asserted-by":"publisher","unstructured":"Song Q, Jin H, Huang X, Hu X (2018) Multi-label adversarial perturbations. In: 2018 IEEE International Conference on Data Mining (ICDM), IEEE, pp. 1242\u20131247. https:\/\/doi.org\/10.1109\/ICDM.2018.00166","DOI":"10.1109\/ICDM.2018.00166"},{"key":"2184_CR32","doi-asserted-by":"publisher","unstructured":"Sun Y, Xu Q, Wang Z, Huang Q (2023) When measures are unreliable: imperceptible adversarial perturbations toward top-k multi-label learning. In: Proceedings of the 31st ACM International Conference on Multimedia, pp. 1515\u20131526. https:\/\/doi.org\/10.1145\/3581783.3611846","DOI":"10.1145\/3581783.3611846"},{"issue":"3","key":"2184_CR33","doi-asserted-by":"publisher","first-page":"562","DOI":"10.1109\/tai.2022.3198629","volume":"4","author":"L Kong","year":"2022","unstructured":"Kong L, Luo W, Zhang H, Liu Y, Shi Y (2022) Evolutionary multilabel adversarial examples: an effective black-box attack. IEEE Trans Artif Intell 4(3):562\u2013572. https:\/\/doi.org\/10.1109\/tai.2022.3198629","journal-title":"IEEE Trans Artif Intell"},{"issue":"4","key":"2184_CR34","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1007\/s40747-025-01805-z","volume":"11","author":"Z Chen","year":"2025","unstructured":"Chen Z, Zhou Q, Liu Y, Luo W (2025) A comprehensive transplanting of black-box adversarial attacks from multi-class to multi-label models. Complex Intell Syst 11(4):201","journal-title":"Complex Intell Syst"},{"key":"2184_CR35","first-page":"24824","volume":"35","author":"J Wei","year":"2022","unstructured":"Wei J, Wang X, Schuurmans D, Bosma M, Xia F, Chi E, Le QV, Zhou D et al (2022) Chain-of-thought prompting elicits reasoning in large language models. Adv Neural Inf Process Syst 35:24824\u201324837","journal-title":"Adv Neural Inf Process Syst"},{"key":"2184_CR36","doi-asserted-by":"crossref","unstructured":"Liu Y, Luo W, Chen Z, Naseem ML (2024) Showing many labels in multi-label classification models: An empirical study of adversarial examples. arXiv preprint arXiv:2409.17568","DOI":"10.1007\/978-981-95-0006-2_27"},{"key":"2184_CR37","doi-asserted-by":"publisher","first-page":"303","DOI":"10.1007\/s11263-009-0275-4","volume":"88","author":"M Everingham","year":"2010","unstructured":"Everingham M, Van Gool L, Williams CK, Winn J, Zisserman A (2010) The PASCAL visual object classes (VOC) challenge. Int J Comput Vision 88:303\u2013338. https:\/\/doi.org\/10.1007\/s11263-009-0275-4","journal-title":"Int J Comput Vision"},{"key":"2184_CR38","doi-asserted-by":"publisher","unstructured":"Lin T-Y, Maire M, Belongie S, Hays J, Perona P, Ramanan D, Doll\u00e1r P, Zitnick CL (2014) Microsoft COCO: Common Objects in Context. In: Computer Vision\u2013ECCV 2014: 13th European Conference, Zurich, Switzerland, September 6-12, 2014, Proceedings, Part V 13, Springer, pp. 740\u2013755. https:\/\/doi.org\/10.1007\/978-3-319-10602-1_48","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"2184_CR39","doi-asserted-by":"publisher","unstructured":"Chua T-S, Tang J, Hong R, Li H, Luo Z, Zheng Y (2009) NUS-WIDE: A Real-World Web Image Database from National University of Singapore. In: Proceedings of the ACM international conference on image and video retrieval, pp. 1\u20139. https:\/\/doi.org\/10.1145\/1646396.1646452","DOI":"10.1145\/1646396.1646452"},{"key":"2184_CR40","doi-asserted-by":"publisher","unstructured":"Chen Z-M, Wei X-S, Wang P, Guo Y (2019) Multi-label image recognition with graph convolutional networks. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp. 5177\u20135186. https:\/\/doi.org\/10.1109\/cvpr.2019.00532","DOI":"10.1109\/cvpr.2019.00532"}],"container-title":["Complex &amp; Intelligent Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s40747-025-02184-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s40747-025-02184-1","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s40747-025-02184-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,16]],"date-time":"2026-02-16T08:24:04Z","timestamp":1771230244000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s40747-025-02184-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,12]]},"references-count":40,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,2]]}},"alternative-id":["2184"],"URL":"https:\/\/doi.org\/10.1007\/s40747-025-02184-1","relation":{},"ISSN":["2199-4536","2198-6053"],"issn-type":[{"value":"2199-4536","type":"print"},{"value":"2198-6053","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,12]]},"assertion":[{"value":"28 June 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 November 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 December 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"71"}}