{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T00:06:36Z","timestamp":1783123596598,"version":"3.54.6"},"reference-count":62,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62276038"],"award-info":[{"award-number":["62276038"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62221005"],"award-info":[{"award-number":["62221005"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1016\/j.eswa.2026.131677","type":"journal-article","created":{"date-parts":[[2026,2,17]],"date-time":"2026-02-17T00:27:15Z","timestamp":1771288035000},"page":"131677","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":2,"special_numbering":"C","title":["Dynamic gradient fusion method with local spatial and multi-scale frequency transformations for transferable adversarial attacks"],"prefix":"10.1016","volume":"314","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2026-3911","authenticated-orcid":false,"given":"Jun","family":"Hu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8354-6091","authenticated-orcid":false,"given":"Huanghui","family":"Ran","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0266-6220","authenticated-orcid":false,"given":"Chen","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6154-4656","authenticated-orcid":false,"given":"Qinghua","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8521-5232","authenticated-orcid":false,"given":"Guoyin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.131677_bib0001","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2021.107373","article-title":"Deep learning and multilingual sentiment analysis on social media data: An overview","volume":"107","author":"Ag\u00fcero-Torales","year":"2021","journal-title":"Applied Soft Computing."},{"key":"10.1016\/j.eswa.2026.131677_bib0002","series-title":"Proceedings of the european conference on computer vision","first-page":"484","article-title":"Square attack: A query-efficient black-box adversarial attack via random search","author":"Andriushchenko","year":"2020"},{"key":"10.1016\/j.eswa.2026.131677_bib0003","series-title":"Proceedings of the 2017\u202fIEEE symposium on security and privacy","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.eswa.2026.131677_bib0004","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.127998","article-title":"Towards robust and generalizable adversarial purification for deep image classification under unknown attacks","volume":"286","author":"Chen","year":"2025","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.131677_bib0005","series-title":"Proceedings of the international conference on machine learning","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","author":"Cohen","year":"2019"},{"key":"10.1016\/j.eswa.2026.131677_bib0006","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"9185","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0007","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"4312","article-title":"Evading defenses to transferable adversarial examples by translation-invariant attacks","author":"Dong","year":"2019"},{"key":"10.1016\/j.eswa.2026.131677_bib0008","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"7506","article-title":"Advdrop: Adversarial attack to DNNs by dropping information","author":"Duan","year":"2021"},{"key":"10.1016\/j.eswa.2026.131677_bib0009","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"1625","article-title":"Robust physical-world attacks on deep learning visual classification","author":"Eykholt","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0010","doi-asserted-by":"crossref","first-page":"70141","DOI":"10.52202\/075280-3073","article-title":"Boosting adversarial transferability by achieving flat local maxima","volume":"36","author":"Ge","year":"2023","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.eswa.2026.131677_bib0011","series-title":"Proceedings of the 31st ACM international conference on multimedia","first-page":"4440","article-title":"Improving the transferability of adversarial examples with arbitrary style transfer","author":"Ge","year":"2023"},{"key":"10.1016\/j.eswa.2026.131677_bib0012","series-title":"Proceedings of the international conference on learning representations","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015"},{"key":"10.1016\/j.eswa.2026.131677_bib0013","series-title":"Proceedings of the 35th conference on uncertainty in artificial intelligence","first-page":"1127","article-title":"Low frequency adversarial perturbation","volume":"vol. 115","author":"Guo","year":"2019"},{"key":"10.1016\/j.eswa.2026.131677_bib0014","series-title":"Proceedings of the international conference on learning representations","article-title":"Countering adversarial images using input transformations","author":"Guo","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0015","first-page":"85","article-title":"Backpropagating linearly improves transferability of adversarial examples","volume":"33","author":"Guo","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.eswa.2026.131677_bib0016","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2019.107184","article-title":"Ensemble adversarial black-box attacks against deep learning systems","volume":"101","author":"Hang","year":"2020","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.eswa.2026.131677_bib0017","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.neunet.2022.02.025","article-title":"Boosting the transferability of adversarial examples via stochastic serial attack","volume":"150","author":"Hao","year":"2022","journal-title":"Neural Networks"},{"key":"10.1016\/j.eswa.2026.131677_bib0018","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"issue":"1","key":"10.1016\/j.eswa.2026.131677_bib0019","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1162\/neco.1997.9.1.1","article-title":"Flat minima","volume":"9","author":"Hochreiter","year":"1997","journal-title":"Neural Computation"},{"key":"10.1016\/j.eswa.2026.131677_bib0020","series-title":"Proceedings of the international conference on machine learning","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","author":"Ilyas","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0021","unstructured":"Izmailov, P., Podoprikhin, D., Garipov, T., Vetrov, D., & Wilson, A. G. (2018). Averaging weights leads to wider optima and better generalization. arXiv: 1803.05407."},{"key":"10.1016\/j.eswa.2026.131677_bib0022","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"6084","article-title":"Comdefend: An efficient image compression model to defend adversarial examples","author":"Jia","year":"2019"},{"key":"10.1016\/j.eswa.2026.131677_bib0023","series-title":"Proceedings of the 34th international conference on machine learning (ICML)","first-page":"2521","article-title":"On large-batch training for deep learning: Generalization gap and sharp minima","volume":"vol. 70","author":"Keskar","year":"2017"},{"key":"10.1016\/j.eswa.2026.131677_bib0024","series-title":"Artificial intelligence safety and security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0025","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"1221","article-title":"Qeba: Query-efficient boundary-based blackbox attack","author":"Li","year":"2020"},{"key":"10.1016\/j.eswa.2026.131677_bib0026","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"1778","article-title":"Defense against adversarial attacks using high-level representation guided denoiser","author":"Liao","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0027","doi-asserted-by":"crossref","DOI":"10.1016\/j.inffus.2024.102660","article-title":"Frontiers and developments of data augmentation for image: From unlearnable to learnable","volume":"114","author":"Lin","year":"2025","journal-title":"Information Fusion"},{"key":"10.1016\/j.eswa.2026.131677_bib0028","series-title":"Proceedings of the international conference on learning representations","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","author":"Lin","year":"2020"},{"key":"10.1016\/j.eswa.2026.131677_bib0029","series-title":"Proceedings of the international conference on learning representations","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"Liu","year":"2017"},{"key":"10.1016\/j.eswa.2026.131677_bib0030","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"860","article-title":"Feature distillation: Dnn-oriented jpeg compression against adversarial examples","author":"Liu","year":"2019"},{"key":"10.1016\/j.eswa.2026.131677_bib0031","series-title":"Proceedings of the european conference on computer vision","first-page":"549","article-title":"Frequency domain model augmentation for adversarial attack","author":"Long","year":"2022"},{"key":"10.1016\/j.eswa.2026.131677_bib0032","series-title":"Proceedings of the international conference on learning representations","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0033","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"2574","article-title":"Deepfool: A simple and accurate method to fool deep neural networks","author":"Moosavi-Dezfooli","year":"2016"},{"key":"10.1016\/j.eswa.2026.131677_bib0034","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"262","article-title":"A self-supervised approach for adversarial robustness","author":"Naseer","year":"2020"},{"key":"10.1016\/j.eswa.2026.131677_bib0035","series-title":"Proceedings of the 2017\u202fACM asia conference on computer and communications security","first-page":"506","article-title":"Practical black-box attacks against machine learning","author":"Papernot","year":"2017"},{"key":"10.1016\/j.eswa.2026.131677_bib0036","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"779","article-title":"You only look once: Unified, real-time object detection","author":"Redmon","year":"2016"},{"key":"10.1016\/j.eswa.2026.131677_bib0037","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"618","article-title":"Grad-cam: Visual explanations from deep networks via gradient-based localization","author":"Selvaraju","year":"2017"},{"key":"10.1016\/j.eswa.2026.131677_bib0038","series-title":"Proceedings of the 2016\u202fACM SIGSAC conference on computer and communications security","first-page":"1528","article-title":"Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition","author":"Sharif","year":"2016"},{"key":"10.1016\/j.eswa.2026.131677_bib0039","series-title":"Proceedings of the 28th international joint conference on artificial intelligence","first-page":"3389","article-title":"On the effectiveness of low frequency perturbations","author":"Sharma","year":"2019"},{"key":"10.1016\/j.eswa.2026.131677_bib0040","unstructured":"Simonyan, K., & Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv: 1409.1556."},{"key":"10.1016\/j.eswa.2026.131677_bib0041","series-title":"Proceedings of the AAAI conference on artificial intelligence.","article-title":"Inception-v4, inception-resnet and the impact of residual connections on learning","volume":"vol. 31","author":"Szegedy","year":"2017"},{"key":"10.1016\/j.eswa.2026.131677_bib0042","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"2818","article-title":"Rethinking the inception architecture for computer vision","author":"Szegedy","year":"2016"},{"key":"10.1016\/j.eswa.2026.131677_bib0043","series-title":"Proceedings of the international conference on learning representations","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"key":"10.1016\/j.eswa.2026.131677_bib0044","series-title":"Proceedings of the international conference on learning representations","article-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0045","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"8684","article-title":"High-frequency component helps explain the generalization of convolutional neural networks","author":"Wang","year":"2020"},{"key":"10.1016\/j.eswa.2026.131677_bib0046","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.124757","article-title":"Boosting the transferability of adversarial attacks with global momentum initialization","volume":"255","author":"Wang","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.131677_bib0047","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"24336","article-title":"Boosting adversarial transferability by block shuffle and rotation","author":"Wang","year":"2024"},{"key":"10.1016\/j.eswa.2026.131677_bib0048","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"1924","article-title":"Enhancing the transferability of adversarial attacks through variance tuning","author":"Wang","year":"2021"},{"key":"10.1016\/j.eswa.2026.131677_bib0049","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"16158","article-title":"Admix: Enhancing the transferability of adversarial attacks","author":"Wang","year":"2021"},{"key":"10.1016\/j.eswa.2026.131677_bib0050","series-title":"Proceedings of the 33rd ACM international conference on information and knowledge management","first-page":"2410","article-title":"Improving adversarial transferability via frequency-guided sample relevance attack","author":"Wang","year":"2024"},{"key":"10.1016\/j.eswa.2026.131677_bib0051","series-title":"Proceedings of the 32nd british machine vision conference","article-title":"Boosting adversarial transferability through enhanced momentum","author":"Wang","year":"2021"},{"key":"10.1016\/j.eswa.2026.131677_bib0052","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"4607","article-title":"Structure invariant transformation for better adversarial transferability","author":"Wang","year":"2023"},{"key":"10.1016\/j.eswa.2026.131677_bib0053","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.112152","article-title":"Boosting transferability of adversarial samples via saliency distribution and frequency domain enhancement","volume":"300","author":"Wang","year":"2024","journal-title":"Knowledge-Based Systems"},{"key":"10.1016\/j.eswa.2026.131677_bib0054","unstructured":"Wang, Z., Yang, Y., Shrivastava, A., Rawal, V., & Ding, Z. (2020b). Towards frequency-based explanation for robust CNN. arXiv: 2005.03141."},{"key":"10.1016\/j.eswa.2026.131677_bib0055","series-title":"Proceedings of the international conference on learning representations","article-title":"Skip connections matter: On the transferability of adversarial examples generated with resnets","author":"Wu","year":"2020"},{"key":"10.1016\/j.eswa.2026.131677_bib0056","series-title":"Proceedings of the international conference on learning representations","article-title":"Mitigating adversarial effects through randomization","author":"Xie","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0057","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"2730","article-title":"Improving transferability of adversarial examples with input diversity","author":"Xie","year":"2019"},{"key":"10.1016\/j.eswa.2026.131677_bib0058","series-title":"Network and distributed system security symposium","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"Xu","year":"2018"},{"key":"10.1016\/j.eswa.2026.131677_bib0059","first-page":"13255","article-title":"A fourier perspective on model robustness in computer vision","volume":"32","author":"Yin","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.eswa.2026.131677_bib0060","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"586","article-title":"The unreasonable effectiveness of deep features as a perceptual metric","author":"Zhang","year":"2018"},{"issue":"1","key":"10.1016\/j.eswa.2026.131677_bib0061","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1007\/s40747-024-01628-4","article-title":"Enhancing adversarial transferability with local transformation","volume":"11","author":"Zhang","year":"2025","journal-title":"Complex & Intelligent Systems"},{"key":"10.1016\/j.eswa.2026.131677_bib0062","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"4741","article-title":"Boosting adversarial transferability via gradient relevance attack","author":"Zhu","year":"2023"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426005907?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426005907?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T17:45:39Z","timestamp":1778780739000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426005907"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":62,"alternative-id":["S0957417426005907"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.131677","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Dynamic gradient fusion method with local spatial and multi-scale frequency transformations for transferable adversarial attacks","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.131677","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"131677"}}