{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T05:08:23Z","timestamp":1777871303107,"version":"3.51.4"},"reference-count":54,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Knowledge-Based Systems"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1016\/j.knosys.2026.115919","type":"journal-article","created":{"date-parts":[[2026,4,4]],"date-time":"2026-04-04T13:03:30Z","timestamp":1775307810000},"page":"115919","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["One perturbation fools all: An adversarial perturbation can attack different vision models"],"prefix":"10.1016","volume":"342","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-5472-3640","authenticated-orcid":false,"given":"Jinyan","family":"Cai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9469-8178","authenticated-orcid":false,"given":"Tianhao","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6877-780X","authenticated-orcid":false,"given":"Hongliang","family":"Liang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiuping","family":"Yi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.knosys.2026.115919_bib0001","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"21001","article-title":"Adv-cpg: a customized portrait generation framework with facial adversarial attacks","author":"Wang","year":"2025"},{"key":"10.1016\/j.knosys.2026.115919_bib0002","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"4770","article-title":"A2RNet: adversarial attack resilient network for robust infrared and visible image fusion","volume":"39","author":"Li","year":"2025"},{"key":"10.1016\/j.knosys.2026.115919_bib0003","article-title":"Enhancing the transferability of adversarial attacks via multi-feature attention","author":"Zheng","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.knosys.2026.115919_bib0004","series-title":"2017 IEEE Symposium on Security and Privacy (sp)","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.knosys.2026.115919_bib0005","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus, Intriguing properties of neural networks, arXiv preprint arXiv: 1312.6199(2013)."},{"key":"10.1016\/j.knosys.2026.115919_bib0006","first-page":"87545","article-title":"Transferable adversarial attacks on sam and its downstream models","volume":"37","author":"Xia","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.knosys.2026.115919_bib0007","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24625","article-title":"On the robustness of large multimodal models against image adversarial attacks","author":"Cui","year":"2024"},{"key":"10.1016\/j.knosys.2026.115919_bib0008","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"9185","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2018"},{"key":"10.1016\/j.knosys.2026.115919_bib0009","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.112152","article-title":"Boosting transferability of adversarial samples via saliency distribution and frequency domain enhancement","volume":"300","author":"Wang","year":"2024","journal-title":"Knowl. Based Syst."},{"key":"10.1016\/j.knosys.2026.115919_bib0010","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"6120","article-title":"Trafficpredict: trajectory prediction for heterogeneous traffic-agents","volume":"33","author":"Ma","year":"2019"},{"key":"10.1016\/j.knosys.2026.115919_bib0011","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24452","article-title":"Physical 3D adversarial attacks against monocular depth estimation in autonomous driving","author":"Zheng","year":"2024"},{"key":"10.1016\/j.knosys.2026.115919_bib0012","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"1028","article-title":"Perceptual-sensitive gan for generating adversarial patches","volume":"33","author":"Liu","year":"2019"},{"key":"10.1016\/j.knosys.2026.115919_bib0013","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"20524","article-title":"Proximal splitting adversarial attack for semantic segmentation","author":"Rony","year":"2023"},{"key":"10.1016\/j.knosys.2026.115919_bib0014","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"7639","article-title":"Feature importance-aware transferable adversarial attacks","author":"Wang","year":"2021"},{"key":"10.1016\/j.knosys.2026.115919_bib0015","series-title":"ICASSP 2025-2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","first-page":"1","article-title":"PB-UAP: Hybride universal adversarial attack for image segmentation","author":"Song","year":"2025"},{"key":"10.1016\/j.knosys.2026.115919_bib0016","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"888","article-title":"On the robustness of semantic segmentation models to adversarial attacks","author":"Arnab","year":"2018"},{"key":"10.1016\/j.knosys.2026.115919_bib0017","series-title":"Proceedings of the IEEE International Conference on Computer Vision","first-page":"2755","article-title":"Universal adversarial perturbations against semantic image segmentation","author":"Hendrik Metzen","year":"2017"},{"key":"10.1016\/j.knosys.2026.115919_bib0018","unstructured":"Tier IV, Autoware documentation, 2015, (https:\/\/autowarefoundation.github.io\/autoware-documentation\/main\/)."},{"key":"10.1016\/j.knosys.2026.115919_bib0019","unstructured":"Baidu, Apollo github, 2017, (https:\/\/github.com\/ApolloAuto\/apollo)."},{"issue":"10","key":"10.1016\/j.knosys.2026.115919_bib0020","doi-asserted-by":"crossref","first-page":"2452","DOI":"10.1109\/TPAMI.2018.2861800","article-title":"Generalizable data-free objective for crafting universal adversarial perturbations","volume":"41","author":"Mopuri","year":"2018","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.knosys.2026.115919_bib0021","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"940","article-title":"Enhancing cross-task black-box transferability of adversarial examples with dispersion reduction","author":"Lu","year":"2020"},{"key":"10.1016\/j.knosys.2026.115919_bib0022","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"15305","article-title":"Dta: physical camouflage attacks using differentiable transformation network","author":"Suryanto","year":"2022"},{"key":"10.1016\/j.knosys.2026.115919_bib0023","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"2414","article-title":"Fca: learning a 3d full-coverage vehicle camouflage for multi-view physical adversarial attack","volume":"36","author":"Wang","year":"2022"},{"key":"10.1016\/j.knosys.2026.115919_bib0024","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, R. Fergus, Intriguing properties of neural networks, arXiv preprint arXiv: 1312.6199(2013)."},{"key":"10.1016\/j.knosys.2026.115919_bib0025","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"15453","article-title":"Rat: adversarial attacks on deep reinforcement agents for targeted behaviors","volume":"39","author":"Bai","year":"2025"},{"key":"10.1016\/j.knosys.2026.115919_bib0026","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"9508","article-title":"Adversarial-Inspired backdoor defense via bridging backdoor and adversarial attacks","volume":"39","author":"Yin","year":"2025"},{"key":"10.1016\/j.knosys.2026.115919_bib0027","series-title":"2020 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","first-page":"1158","article-title":"Boosting the transferability of adversarial samples via attention","author":"Wu","year":"2020"},{"key":"10.1016\/j.knosys.2026.115919_bib0028","unstructured":"Y. Dong, F. Liao, T. Pang, X. Hu, J. Zhu, Discovering adversarial examples with momentum, 5. arXiv preprint arXiv: 1710.06081 (2017)."},{"key":"10.1016\/j.knosys.2026.115919_bib0029","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"2730","article-title":"Improving transferability of adversarial examples with input diversity","author":"Xie","year":"2019"},{"key":"10.1016\/j.knosys.2026.115919_bib0030","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"14963","article-title":"Transferable sparse adversarial attack","author":"He","year":"2022"},{"key":"10.1016\/j.knosys.2026.115919_bib0031","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24696","article-title":"Transferable structural sparse adversarial attack via exact group sparsity training","author":"Ming","year":"2024"},{"key":"10.1016\/j.knosys.2026.115919_bib0032","series-title":"Proceedings of the Thirty-Third International Joint Conference on Artificial Intelligence","first-page":"1733","article-title":"GenSeg: on generating unified adversary for segmentation","author":"Zhang","year":"2024"},{"key":"10.1016\/j.knosys.2026.115919_bib0033","doi-asserted-by":"crossref","unstructured":"Y. Song, Z. Zhou, Q. Lu, H. Zhang, Y. Hu, L. Xue, S. Hu, M. Li, L.Y. Zhang, Segtrans: Transferable adversarial examples for segmentation models, arXiv preprint arXiv: 2510.08922(2025).","DOI":"10.1109\/TMM.2026.3668652"},{"key":"10.1016\/j.knosys.2026.115919_bib0034","series-title":"2024 International Joint Conference on Neural Networks (IJCNN)","first-page":"1","article-title":"Cross-task attack: a self-supervision generative framework based on attention shift","author":"Zeng","year":"2024"},{"key":"10.1016\/j.knosys.2026.115919_bib0035","unstructured":"A. Brock, J. Donahue, K. Simonyan, Large scale GAN training for high fidelity natural image synthesis, arXiv preprint arXiv: 1809.11096(2018)."},{"key":"10.1016\/j.knosys.2026.115919_bib0036","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.knosys.2026.115919_bib0037","unstructured":"K. Simonyan, A. Zisserman, Very deep convolutional networks for large-scale image recognition, arXiv preprint arXiv: 1409.1556(2014)."},{"key":"10.1016\/j.knosys.2026.115919_bib0038","article-title":"Faster r-cnn: towards real-time object detection with region proposal networks","volume":"28","author":"Ren","year":"2015","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.knosys.2026.115919_bib0039","series-title":"Proceedings of the IEEE International Conference on Computer Vision","first-page":"2980","article-title":"Focal loss for dense object detection","author":"Lin","year":"2017"},{"key":"10.1016\/j.knosys.2026.115919_bib0040","article-title":"Ultralytics\/yolov5: v3. 0","author":"Jocher","year":"2020","journal-title":"Zenodo"},{"key":"10.1016\/j.knosys.2026.115919_bib0041","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"3431","article-title":"Fully convolutional networks for semantic segmentation","author":"Long","year":"2015"},{"key":"10.1016\/j.knosys.2026.115919_bib0042","unstructured":"L.-C. Chen, G. Papandreou, F. Schroff, H. Adam, Rethinking atrous convolution for semantic image segmentation, arXiv preprint arXiv: 1706.05587(2017)."},{"key":"10.1016\/j.knosys.2026.115919_bib0043","series-title":"Proceedings of the IEEE International Conference on Computer Vision","first-page":"2961","article-title":"Mask r-cnn","author":"He","year":"2017"},{"key":"10.1016\/j.knosys.2026.115919_bib0044","series-title":"2017 IEEE International Conference on Computer Vision (ICCV)","first-page":"618","article-title":"Grad-CAM: visual explanations from deep networks via gradient-Based localization","author":"Selvaraju","year":"2017"},{"key":"10.1016\/j.knosys.2026.115919_bib0045","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"12259","article-title":"Levit: a vision transformer in convnet\u2019s clothing for faster inference","author":"Graham","year":"2021"},{"key":"10.1016\/j.knosys.2026.115919_bib0046","first-page":"9355","article-title":"Twins: revisiting the design of spatial attention in vision transformers","volume":"34","author":"Chu","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.knosys.2026.115919_bib0047","series-title":"International Conference on Machine Learning","first-page":"2286","article-title":"Convit: improving vision transformers with soft convolutional inductive biases","author":"d\u2019Ascoli","year":"2021"},{"key":"10.1016\/j.knosys.2026.115919_bib0048","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"4015","article-title":"Segment anything","author":"Kirillov","year":"2023"},{"key":"10.1016\/j.knosys.2026.115919_bib0049","unstructured":"C. Zhang, D. Han, Y. Qiao, J.U. Kim, S.-H. Bae, S. Lee, C.S. Hong, Faster segment anything: Towards lightweight sam for mobile applications, arXiv preprint arXiv: 2306.14289(2023)."},{"key":"10.1016\/j.knosys.2026.115919_bib0050","first-page":"29914","article-title":"Segment anything in high quality","volume":"36","author":"Ke","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.knosys.2026.115919_bib0051","series-title":"Proceedings of the Advances in Neural Information Processing Systems","first-page":"20887","article-title":"Boosting the transferability of adversarial attack on vision transformer with adaptive token tuning","volume":"37","author":"Ming","year":"2024"},{"key":"10.1016\/j.knosys.2026.115919_bib0052","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV)","first-page":"530","article-title":"Boosting generative adversarial transferability with self-supervised vision transformer features","author":"Wu","year":"2025"},{"key":"10.1016\/j.knosys.2026.115919_bib0053","unstructured":"D. Hendrycks, N. Mu, E.D. Cubuk, B. Zoph, J. Gilmer, B. Lakshminarayanan, Augmix: A simple data processing method to improve robustness and uncertainty, arXiv preprint arXiv: 1912.02781(2019)."},{"key":"10.1016\/j.knosys.2026.115919_bib0054","unstructured":"R. Geirhos, P. Rubisch, C. Michaelis, M. Bethge, F.A. Wichmann, W. Brendel, ImageNet-trained CNNs are biased towards texture; increasing shape bias improves accuracy and robustness, arXiv preprint arXiv: 1811.12231(2018)."}],"container-title":["Knowledge-Based Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126006453?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126006453?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T17:11:19Z","timestamp":1777569079000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0950705126006453"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":54,"alternative-id":["S0950705126006453"],"URL":"https:\/\/doi.org\/10.1016\/j.knosys.2026.115919","relation":{},"ISSN":["0950-7051"],"issn-type":[{"value":"0950-7051","type":"print"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"One perturbation fools all: An adversarial perturbation can attack different vision models","name":"articletitle","label":"Article Title"},{"value":"Knowledge-Based Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.knosys.2026.115919","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"115919"}}