{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T02:01:55Z","timestamp":1780020115710,"version":"3.53.1"},"reference-count":68,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100007162","name":"Department of Science and Technology of Guangdong Province","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100007162","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Knowledge-Based Systems"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.knosys.2026.116226","type":"journal-article","created":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T06:48:44Z","timestamp":1779173324000},"page":"116226","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Towards transferable adversarial attacks with multi-scale structure-frequency transformations"],"prefix":"10.1016","volume":"346","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-5366-2056","authenticated-orcid":false,"given":"Long","family":"He","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pian","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1510-3443","authenticated-orcid":false,"given":"Yatie","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2439-3518","authenticated-orcid":false,"given":"Kongyang","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingxiao","family":"Guan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5783-9243","authenticated-orcid":false,"given":"Zhenbang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.knosys.2026.116226_b1","unstructured":"A. Krizhevsky, I. Sutskever, G.E. Hinton, ImageNet Classification with Deep Convolutional Neural Networks, in: Proceedings of the Advances in Neural Information Processing Systems, 2012, pp. 1106\u20131114."},{"key":"10.1016\/j.knosys.2026.116226_b2","doi-asserted-by":"crossref","unstructured":"J. Redmon, S.K. Divvala, R.B. Girshick, A. Farhadi, You Only Look Once: Unified, Real-Time Object Detection, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2016, pp. 779\u2013788.","DOI":"10.1109\/CVPR.2016.91"},{"key":"10.1016\/j.knosys.2026.116226_b3","doi-asserted-by":"crossref","unstructured":"K. He, X. Zhang, S. Ren, J. Sun, Deep Residual Learning for Image Recognition, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2016, pp. 770\u2013778.","DOI":"10.1109\/CVPR.2016.90"},{"key":"10.1016\/j.knosys.2026.116226_b4","doi-asserted-by":"crossref","unstructured":"G. Huang, Z. Liu, L. Van Der Maaten, K.Q. Weinberger, Densely Connected Convolutional Networks, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2017, pp. 4700\u20134708.","DOI":"10.1109\/CVPR.2017.243"},{"key":"10.1016\/j.knosys.2026.116226_b5","unstructured":"S. Ren, K. He, R.B. Girshick, J. Sun, Faster R-CNN: Towards Real-Time Object Detection with Region Proposal Networks, in: Proceedings of the Advances in Neural Information Processing Systems, 2015, pp. 91\u201399."},{"key":"10.1016\/j.knosys.2026.116226_b6","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I.J. Goodfellow, R. Fergus, Intriguing Properties of Neural Networks, in: Proceedings of the International Conference on Learning Representations, 2014."},{"key":"10.1016\/j.knosys.2026.116226_b7","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2023.111319","article-title":"Chaotic neural network quantization and its robustness against adversarial attacks","volume":"286","author":"Osama","year":"2024","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116226_b8","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2026.115992","article-title":"TFPA: Enhancing adversarial attack on speech recognition via time\u2013frequency pre-alignment","volume":"343","author":"Ye","year":"2026","journal-title":"Knowl.-Based Syst."},{"issue":"5","key":"10.1016\/j.knosys.2026.116226_b9","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3234150","article-title":"A survey on deep learning: Algorithms, techniques, and applications","volume":"51","author":"Pouyanfar","year":"2018","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.knosys.2026.116226_b10","doi-asserted-by":"crossref","unstructured":"M. Sharif, S. Bhagavatula, L. Bauer, M.K. Reiter, Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition, in: Proceedings of the 2016 Acm Sigsac Conference on Computer and Communications Security, 2016, pp. 1528\u20131540.","DOI":"10.1145\/2976749.2978392"},{"key":"10.1016\/j.knosys.2026.116226_b11","unstructured":"A. Ilyas, L. Engstrom, A. Athalye, J. Lin, Black-box Adversarial Attacks with Limited Queries and Information, in: Proceedings of the International Conference on Machine Learning, 2018, pp. 2142\u20132151."},{"key":"10.1016\/j.knosys.2026.116226_b12","unstructured":"S. Cheng, Y. Dong, T. Pang, H. Su, J. Zhu, Improving Black-box Adversarial Attacks with a Transfer-based Prior, in: Proceedings of the Advances in Neural Information Processing Systems, 2019, pp. 10932\u201310942."},{"key":"10.1016\/j.knosys.2026.116226_b13","unstructured":"W. Brendel, J. Rauber, M. Bethge, Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models, in: Proceedings of the International Conference on Learning Representations, 2018."},{"issue":"6","key":"10.1016\/j.knosys.2026.116226_b14","doi-asserted-by":"crossref","first-page":"7849","DOI":"10.1109\/TDSC.2025.3601175","article-title":"DP-TRAE: A dual-phase merging transferable reversible adversarial example for image privacy protection","volume":"22","author":"Du","year":"2025","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.knosys.2026.116226_b15","doi-asserted-by":"crossref","unstructured":"S.-M. Moosavi-Dezfooli, A. Fawzi, P. Frossard, Deepfool: A Simple and Accurate Method to Fool Deep Neural Networks, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2016, pp. 2574\u20132582.","DOI":"10.1109\/CVPR.2016.282"},{"key":"10.1016\/j.knosys.2026.116226_b16","unstructured":"A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards Deep Learning Models Resistant to Adversarial Attacks, in: Proceedings of the International Conference on Learning Representations, 2018."},{"key":"10.1016\/j.knosys.2026.116226_b17","series-title":"Artificial Intelligence Safety and Security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.knosys.2026.116226_b18","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2021.107102","article-title":"A low-query black-box adversarial attack based on transferability","volume":"226","author":"Ding","year":"2021","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116226_b19","doi-asserted-by":"crossref","unstructured":"C. Xie, Z. Zhang, Y. Zhou, S. Bai, J. Wang, Z. Ren, A.L. Yuille, Improving Transferability of Adversarial Examples with Input Diversity, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2019, pp. 2730\u20132739.","DOI":"10.1109\/CVPR.2019.00284"},{"key":"10.1016\/j.knosys.2026.116226_b20","doi-asserted-by":"crossref","unstructured":"X. Wang, X. He, J. Wang, K. He, Admix: Enhancing the Transferability of Adversarial Attacks, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 16158\u201316167.","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"10.1016\/j.knosys.2026.116226_b21","doi-asserted-by":"crossref","unstructured":"X. Wang, Z. Zhang, J. Zhang, Structure Invariant Transformation for Better Adversarial Transferability, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2023, pp. 4607\u20134619.","DOI":"10.1109\/ICCV51070.2023.00425"},{"key":"10.1016\/j.knosys.2026.116226_b22","doi-asserted-by":"crossref","unstructured":"K. Wang, X. He, W. Wang, X. Wang, Boosting Adversarial Transferability by Block Shuffle and Rotation, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24336\u201324346.","DOI":"10.1109\/CVPR52733.2024.02297"},{"key":"10.1016\/j.knosys.2026.116226_b23","doi-asserted-by":"crossref","unstructured":"Y. Guo, W. Liu, Q. Xu, S. Zheng, S. Huang, Y. Zang, S. Shen, C. Wen, C. Wang, Boosting Adversarial Transferability through Augmentation in Hypothesis Space, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2025.","DOI":"10.1109\/CVPR52734.2025.01786"},{"key":"10.1016\/j.knosys.2026.116226_b24","doi-asserted-by":"crossref","unstructured":"Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, J. Li, Boosting Adversarial Attacks with Momentum, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2018, pp. 9185\u20139193.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"10.1016\/j.knosys.2026.116226_b25","doi-asserted-by":"crossref","unstructured":"Y. Dong, T. Pang, H. Su, J. Zhu, Evading Defenses to Transferable Adversarial Examples by Translation-Invariant Attacks, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2019, pp. 4312\u20134321.","DOI":"10.1109\/CVPR.2019.00444"},{"key":"10.1016\/j.knosys.2026.116226_b26","unstructured":"J. Lin, C. Song, K. He, L. Wang, J.E. Hopcroft, Nesterov Accelerated Gradient and Scale Invariance for Adversarial Attacks, in: Proceedings of the International Conference on Learning Representations, 2020."},{"key":"10.1016\/j.knosys.2026.116226_b27","doi-asserted-by":"crossref","unstructured":"Z. Wang, H. Guo, Z. Zhang, W. Liu, Z. Qin, K. Ren, Feature Importance-Aware Transferable Adversarial Attacks, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 7639\u20137648.","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"10.1016\/j.knosys.2026.116226_b28","doi-asserted-by":"crossref","unstructured":"J. Zhang, W. Wu, J.-t. Huang, Y. Huang, W. Wang, Y. Su, M.R. Lyu, Improving Adversarial Transferability via Neuron Attribution-Based Attacks, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 14993\u201315002.","DOI":"10.1109\/CVPR52688.2022.01457"},{"key":"10.1016\/j.knosys.2026.116226_b29","first-page":"6731","article-title":"Improving integrated gradient-based transferable adversarial examples by refining the integration path","volume":"vol. 39","author":"Ren","year":"2025"},{"key":"10.1016\/j.knosys.2026.116226_b30","doi-asserted-by":"crossref","unstructured":"C. Szegedy, V. Vanhoucke, S. Ioffe, J. Shlens, Z. Wojna, Rethinking the Inception Architecture for Computer Vision, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2016, pp. 2818\u20132826.","DOI":"10.1109\/CVPR.2016.308"},{"key":"10.1016\/j.knosys.2026.116226_b31","article-title":"Inception-v4, inception-resnet and the impact of residual connections on learning","volume":"vol. 31","author":"Szegedy","year":"2017"},{"key":"10.1016\/j.knosys.2026.116226_b32","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113602","article-title":"SFA: Spatial-frequency adversarial attack method","volume":"320","author":"Tang","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116226_b33","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.112576","article-title":"Efficient physical image attacks using adversarial fast autoaugmentation methods","volume":"304","author":"Du","year":"2024","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116226_b34","unstructured":"C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I.J. Goodfellow, R. Fergus, Intriguing properties of neural networks, in: Proceedings of the International Conference on Learning Representations, 2014."},{"key":"10.1016\/j.knosys.2026.116226_b35","unstructured":"I.J. Goodfellow, J. Shlens, C. Szegedy, Explaining and Harnessing Adversarial Examples, in: Proceedings of the International Conference on Learning Representations, 2015."},{"key":"10.1016\/j.knosys.2026.116226_b36","first-page":"16020","article-title":"Adversarial attack generation empowered by min-max optimization","volume":"vol. 34","author":"Wang","year":"2021"},{"key":"10.1016\/j.knosys.2026.116226_b37","first-page":"23063","article-title":"Indicators of attack failure: Debugging and improving optimization of adversarial examples","volume":"35","author":"Pintor","year":"2022"},{"key":"10.1016\/j.knosys.2026.116226_b38","first-page":"10293","article-title":"Improving generalization of universal adversarial perturbation via dynamic maximin optimization","volume":"vol. 39","author":"Zhang","year":"2025"},{"key":"10.1016\/j.knosys.2026.116226_b39","series-title":"2017 IEEE Symposium on Security and Privacy","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.knosys.2026.116226_b40","doi-asserted-by":"crossref","unstructured":"K. Liang, X. Dai, Y. Li, D. Wang, B. Xiao, Improving Transferable Targeted Attacks with Feature Tuning Mixup, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2025, pp. 25802\u201325811.","DOI":"10.1109\/CVPR52734.2025.02403"},{"key":"10.1016\/j.knosys.2026.116226_b41","first-page":"128260","article-title":"Query-based adversarial prompt generation","volume":"vol. 37","author":"Hayase","year":"2024"},{"key":"10.1016\/j.knosys.2026.116226_b42","doi-asserted-by":"crossref","unstructured":"Z. Fang, T. Wang, L. Zhao, S. Zhang, B. Li, Y. Ge, Q. Li, C. Shen, Q. Wang, Zero-query adversarial attack on black-box automatic speech recognition systems, in: Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, 2024, pp. 630\u2013644.","DOI":"10.1145\/3658644.3670309"},{"key":"10.1016\/j.knosys.2026.116226_b43","series-title":"2024 IEEE Symposium on Security and Privacy","first-page":"1270","article-title":"Bounceattack: A query-efficient decision-based adversarial attack by bouncing into the wild","author":"Wan","year":"2024"},{"key":"10.1016\/j.knosys.2026.116226_b44","article-title":"Efficient black-box adversarial attacks via alternate query and boundary augmentation","volume":"321","author":"Wang","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116226_b45","first-page":"26955","article-title":"MORA: Improving ensemble robustness evaluation with model reweighing attack","volume":"vol. 35","author":"Gao","year":"2022"},{"key":"10.1016\/j.knosys.2026.116226_b46","doi-asserted-by":"crossref","unstructured":"B. Tang, Z. Wang, Y. Bin, Q. Dou, Y. Yang, H.T. Shen, Ensemble diversity facilitates adversarial transferability, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2024, pp. 24377\u201324386.","DOI":"10.1109\/CVPR52733.2024.02301"},{"key":"10.1016\/j.knosys.2026.116226_b47","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.114079","article-title":"Improving adversarial transferability via adaptive ensemble attack with post-optimization","volume":"326","author":"Zhang","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116226_b48","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2024.112506","article-title":"AGS: Transferable adversarial attack for person re-identification by adaptive gradient similarity attack","volume":"304","author":"Tao","year":"2024","journal-title":"Knowl.-Based Syst."},{"key":"10.1016\/j.knosys.2026.116226_b49","doi-asserted-by":"crossref","unstructured":"H. Huang, Z. Chen, H. Chen, Y. Wang, K. Zhang, T-sea: Transfer-based self-ensemble attack on object detection, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2023, pp. 20514\u201320523.","DOI":"10.1109\/CVPR52729.2023.01965"},{"key":"10.1016\/j.knosys.2026.116226_b50","series-title":"IEEE International Conference on Trust, Security and Privacy in Computing and Communications","first-page":"197","article-title":"OFLGI: An optimization-based feature-level gradient inversion attack","author":"Lu","year":"2024"},{"key":"10.1016\/j.knosys.2026.116226_b51","series-title":"2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications","first-page":"802","article-title":"RPG-diff: Precise adversarial defense based on regional positioning guidance","author":"Wang","year":"2024"},{"key":"10.1016\/j.knosys.2026.116226_b52","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.110394","article-title":"Data filtering for efficient adversarial training","volume":"151","author":"Chen","year":"2024","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.knosys.2026.116226_b53","doi-asserted-by":"crossref","unstructured":"M. Naseer, S. Khan, M. Hayat, F.S. Khan, F. Porikli, A Self-Supervised Approach for Adversarial Robustness, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2020, pp. 262\u2013271.","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"10.1016\/j.knosys.2026.116226_b54","first-page":"18599","article-title":"When adversarial training meets vision transformers: Recipes from training to architecture","volume":"vol. 35","author":"Mo","year":"2022"},{"key":"10.1016\/j.knosys.2026.116226_b55","doi-asserted-by":"crossref","unstructured":"F. Liao, M. Liang, Y. Dong, T. Pang, X. Hu, J. Zhu, Defense Against Adversarial Attacks Using High-Level Representation Guided Denoiser, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2018, pp. 1778\u20131787.","DOI":"10.1109\/CVPR.2018.00191"},{"key":"10.1016\/j.knosys.2026.116226_b56","doi-asserted-by":"crossref","unstructured":"D. Hendrycks, S. Basart, N. Mu, S. Kadavath, F. Wang, E. Dorundo, R. Desai, T. Zhu, S. Parajuli, M. Guo, et al., The Many Faces of Robustness: A Critical Analysis of Out-of-Distribution Generalization, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 8340\u20138349.","DOI":"10.1109\/ICCV48922.2021.00823"},{"key":"10.1016\/j.knosys.2026.116226_b57","unstructured":"R. Geirhos, P. Rubisch, C. Michaelis, M. Bethge, F.A. Wichmann, W. Brendel, ImageNet-Trained CNNs Are Biased Towards Texture; Increasing Shape Bias Improves Accuracy and Robustness, in: International Conference on Learning Representations, 2019."},{"issue":"4","key":"10.1016\/j.knosys.2026.116226_b58","doi-asserted-by":"crossref","first-page":"600","DOI":"10.1109\/TIP.2003.819861","article-title":"Image quality assessment: From error visibility to structural similarity","volume":"13","author":"Wang","year":"2004","journal-title":"IEEE Trans. Image Process."},{"issue":"90","key":"10.1016\/j.knosys.2026.116226_b59","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1090\/S0025-5718-1965-0178586-1","article-title":"An algorithm for the machine calculation of complex Fourier series","volume":"19","author":"Cooley","year":"1965","journal-title":"Math. Comp."},{"key":"10.1016\/j.knosys.2026.116226_b60","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","article-title":"Imagenet large scale visual recognition challenge","volume":"115","author":"Russakovsky","year":"2015","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.knosys.2026.116226_b61","doi-asserted-by":"crossref","unstructured":"S. Xie, R. Girshick, P. Doll\u00e1r, Z. Tu, K. He, Aggregated Residual Transformations for Deep Neural Networks, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2017, pp. 1492\u20131500.","DOI":"10.1109\/CVPR.2017.634"},{"key":"10.1016\/j.knosys.2026.116226_b62","unstructured":"K. Simonyan, A. Zisserman, Very Deep Convolutional Networks for Large-Scale Image Recognition, in: Proceedings of the International Conference on Learning Representations, 2015."},{"key":"10.1016\/j.knosys.2026.116226_b63","unstructured":"A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, X. Zhai, T. Unterthiner, M. Dehghani, M. Minderer, G. Heigold, S. Gelly, J. Uszkoreit, N. Houlsby, An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale, in: Proceedings of the International Conference on Learning Representations, 2021."},{"key":"10.1016\/j.knosys.2026.116226_b64","unstructured":"H. Touvron, M. Cord, M. Douze, F. Massa, A. Sablayrolles, H. J\u00e9gou, Training Data-Efficient Image Transformers & Distillation Through Attention, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 10347\u201310357."},{"key":"10.1016\/j.knosys.2026.116226_b65","doi-asserted-by":"crossref","unstructured":"Z. Liu, Y. Lin, Y. Cao, H. Hu, Y. Wei, Z. Zhang, S. Lin, B. Guo, Swin Transformer: Hierarchical Vision Transformer Using Shifted Windows, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 10012\u201310022.","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"10.1016\/j.knosys.2026.116226_b66","first-page":"9355","article-title":"Twins: Revisiting the design of spatial attention in vision transformers","volume":"vol. 34","author":"Chu","year":"2021"},{"issue":"2","key":"10.1016\/j.knosys.2026.116226_b67","doi-asserted-by":"crossref","first-page":"567","DOI":"10.1007\/s11263-024-02196-3","article-title":"A comprehensive study on robustness of image classification models: Benchmarking and rethinking","volume":"133","author":"Liu","year":"2025","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.knosys.2026.116226_b68","doi-asserted-by":"crossref","unstructured":"H. Zhu, Y. Ren, X. Sui, L. Yang, W. Jiang, Boosting Adversarial Transferability via Gradient Relevance Attack, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2023, pp. 4741\u20134750.","DOI":"10.1109\/ICCV51070.2023.00437"}],"container-title":["Knowledge-Based Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126009524?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126009524?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T01:05:17Z","timestamp":1780016717000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0950705126009524"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":68,"alternative-id":["S0950705126009524"],"URL":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116226","relation":{},"ISSN":["0950-7051"],"issn-type":[{"value":"0950-7051","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Towards transferable adversarial attacks with multi-scale structure-frequency transformations","name":"articletitle","label":"Article Title"},{"value":"Knowledge-Based Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116226","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"116226"}}