{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T00:00:55Z","timestamp":1780963255955,"version":"3.54.1"},"reference-count":38,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.jisa.2026.104495","type":"journal-article","created":{"date-parts":[[2026,5,9]],"date-time":"2026-05-09T08:55:18Z","timestamp":1778316918000},"page":"104495","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["QAEAS: A quantum adaptive ensemble attack system against robust deep neural networks"],"prefix":"10.1016","volume":"100","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-3287-552X","authenticated-orcid":false,"given":"Ali","family":"Mohammadi Ruzbahani","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8669-9777","authenticated-orcid":false,"given":"Abbas","family":"Yazdinejad","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hadis","family":"Karimipour","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.jisa.2026.104495_bib0001","unstructured":"Szegedy C., Zaremba W., Sutskever I., Bruna J., Erhan D., Goodfellow I., Fergus R., Intriguing properties of neural networks. 2013. arXiv preprint arXiv: 13126199."},{"key":"10.1016\/j.jisa.2026.104495_bib0002","unstructured":"Goodfellow I. J., Shlens J., Szegedy C.. Explaining and harnessing adversarial examples. 2014. arXiv preprint arXiv: 14126572."},{"key":"10.1016\/j.jisa.2026.104495_bib0003","series-title":"Artificial intelligence in the operation and control of digitalized power systems","first-page":"209","article-title":"Investigation of detection mechanisms against false data injection attacks based on machine learning approaches","author":"Khaleghi","year":"2024"},{"key":"10.1016\/j.jisa.2026.104495_bib0004","unstructured":"Lloyd S., Mohseni M., Rebentrost P.. Quantum algorithms for supervised and unsupervised machine learning. 2013. arXiv preprint arXiv: 13070411."},{"key":"10.1016\/j.jisa.2026.104495_bib0005","article-title":"D2DSec: an efficient quantum-safe authentication scheme for secure in coverage device-to-device communication in 5g networks","volume":"93","author":"Borgohain","year":"2025","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104495_bib0006","series-title":"2020 Second IEEE international conference on trust, privacy and security in intelligent systems and applications (TPS-ISA)","first-page":"128","article-title":"Quantum adversarial machine learning: status, challenges and perspectives","author":"Edwards","year":"2020"},{"key":"10.1016\/j.jisa.2026.104495_bib0007","article-title":"Multi-party quantum homomorphic encryption scheme based on quantum teleportation","volume":"93","author":"Li","year":"2025","journal-title":"J Inf Secur Appl"},{"key":"10.1016\/j.jisa.2026.104495_bib0008","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"9185","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2018"},{"key":"10.1016\/j.jisa.2026.104495_bib0009","series-title":"Proceedings of the 2024\u202fACM conference on fairness, accountability, and transparency","first-page":"2113","article-title":"Fairness feedback loops: training on synthetic data amplifies bias","author":"Wyllie","year":"2024"},{"issue":"2","key":"10.1016\/j.jisa.2026.104495_bib0010","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1007\/BF00934765","article-title":"On the convergence of a basic iterative method for the implicit complementarity problem","volume":"37","author":"Pang","year":"1982","journal-title":"J Optim Theory Appl"},{"key":"10.1016\/j.jisa.2026.104495_bib0011","unstructured":"Madry A., Makelov A., Schmidt L., Tsipras D., Vladu A.. Towards deep learning models resistant to adversarial attacks. 2017. arXiv preprint arXiv: 170606083."},{"key":"10.1016\/j.jisa.2026.104495_bib0012","series-title":"2017 IEEE symposium on security and privacy (sp)","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.jisa.2026.104495_bib0013","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"2574","article-title":"DeepFool: a simple and accurate method to fool deep neural networks","author":"Moosavi-Dezfooli","year":"2016"},{"key":"10.1016\/j.jisa.2026.104495_bib0014","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111263","article-title":"Query-efficient black-box ensemble attack via dynamic surrogate weighting","volume":"161","author":"Hu","year":"2025","journal-title":"Pattern Recognit"},{"key":"10.1016\/j.jisa.2026.104495_bib0015","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"2730","article-title":"Improving transferability of adversarial examples with input diversity","author":"Xie","year":"2019"},{"key":"10.1016\/j.jisa.2026.104495_bib0016","series-title":"International conference on information and communications security","first-page":"603","article-title":"An adversarial attack based on multi-objective optimization in the black-box scenario: MOEA-APGA II","author":"Zhang","year":"2019"},{"issue":"13","key":"10.1016\/j.jisa.2026.104495_bib0017","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevLett.113.130503","article-title":"Quantum support vector machine for big data classification","volume":"113","author":"Rebentrost","year":"2014","journal-title":"Phys Rev Lett"},{"key":"10.1016\/j.jisa.2026.104495_bib0018","unstructured":"Farhi E., Neven H.. Classification with quantum neural networks on near term processors. 2018. arXiv preprint arXiv: 180206002."},{"key":"10.1016\/j.jisa.2026.104495_bib0019","doi-asserted-by":"crossref","DOI":"10.1103\/PhysRevLett.122.040504","article-title":"Quantum machine learning in feature hilbert spaces","volume":"122","author":"Schuld","year":"2019","journal-title":"Phys Rev Lett"},{"issue":"1","key":"10.1016\/j.jisa.2026.104495_bib0020","doi-asserted-by":"crossref","DOI":"10.1002\/qute.202000003","article-title":"Variational quantum generators: generative adversarial quantum machine learning for continuous distributions","volume":"4","author":"Romero","year":"2021","journal-title":"Adv Quantum Technol"},{"key":"10.1016\/j.jisa.2026.104495_bib0021","series-title":"2024\u202fIEEE International symposium on information theory (ISIT)","first-page":"789","article-title":"Adversarial quantum machine learning: an information-theoretic generalization analysis","author":"Georgiou","year":"2024"},{"issue":"1","key":"10.1016\/j.jisa.2026.104495_bib0022","article-title":"Quantum generative adversarial network: a survey","volume":"64","author":"Li","year":"2020","journal-title":"Comput Mater Contin"},{"key":"10.1016\/j.jisa.2026.104495_bib0023","unstructured":"Karl M., Soelch M., Bayer J., Van der Smagt P.. Deep variational bayes filters: Unsupervised learning of state space models from raw data. 2016. arXiv preprint arXiv: 160506432."},{"key":"10.1016\/j.jisa.2026.104495_bib0024","series-title":"International conference on machine learning","first-page":"5156","article-title":"Transformers are rnns: fast autoregressive transformers with linear attention","author":"Katharopoulos","year":"2020"},{"key":"10.1016\/j.jisa.2026.104495_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104272","article-title":"Evaluation framework for quantum security risk assessment: a comprehensive strategy for quantum-safe transition","volume":"150","author":"Baseri","year":"2025","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104495_bib0026","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101825","article-title":"The impact of quantum computing on real-world security: a 5G case study","volume":"93","author":"Mitchell","year":"2020","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104495_bib0027","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2019.101572","article-title":"Attack trees in isabelle extended with probabilities for quantum cryptography","volume":"87","author":"Kamm\u00fcller","year":"2019","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104495_bib0028","series-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"issue":"2","key":"10.1016\/j.jisa.2026.104495_bib0029","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1109\/JPROC.1996.482233","article-title":"Kalman filtering: theory and practice [book reviews]","volume":"84","author":"Bass","year":"1996","journal-title":"Proc IEEE"},{"key":"10.1016\/j.jisa.2026.104495_bib0030","series-title":"International workshop on multiple classifier systems","first-page":"1","article-title":"Ensemble methods in machine learning","author":"Dietterich","year":"2000"},{"key":"10.1016\/j.jisa.2026.104495_bib0031","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.jisa.2026.104495_bib0032","series-title":"International conference on machine learning","first-page":"6105","article-title":"EfficientNet: rethinking model scaling for convolutional neural networks","author":"Tan","year":"2019"},{"key":"10.1016\/j.jisa.2026.104495_bib0033","unstructured":"Zagoruyko S., Komodakis N.. Wide residual networks. 2016. arXiv preprint arXiv: 160507146."},{"key":"10.1016\/j.jisa.2026.104495_bib0034","unstructured":"Dosovitskiy A., Beyer L., Kolesnikov A., Weissenborn D., Zhai X., Unterthiner T., Dehghani M., Minderer M., Heigold G., Gelly S., et al. An image is worth 16x16 words: Transformers for image recognition at scale. 2020. arXiv preprint arXiv: 201011929."},{"key":"10.1016\/j.jisa.2026.104495_bib0035","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"586","article-title":"The unreasonable effectiveness of deep features as a perceptual metric","author":"Zhang","year":"2018"},{"key":"10.1016\/j.jisa.2026.104495_bib0036","series-title":"International conference on machine learning","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","author":"Zhang","year":"2019"},{"key":"10.1016\/j.jisa.2026.104495_bib0037","series-title":"International conference on learning representations","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"Wang","year":"2020"},{"key":"10.1016\/j.jisa.2026.104495_bib0038","first-page":"2958","article-title":"Adversarial weight perturbation helps robust generalization","volume":"33","author":"Wu","year":"2020","journal-title":"Adv Neural Inf Process Syst"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001250?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626001250?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T23:29:40Z","timestamp":1780961380000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212626001250"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":38,"alternative-id":["S2214212626001250"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104495","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"QAEAS: A quantum adaptive ensemble attack system against robust deep neural networks","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104495","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104495"}}