{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T07:55:42Z","timestamp":1781510142649,"version":"3.54.1"},"reference-count":56,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neurocomputing"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.neucom.2026.134144","type":"journal-article","created":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T16:34:34Z","timestamp":1780331674000},"page":"134144","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Enhancing adversarial transferability via hybrid data and model augmentation"],"prefix":"10.1016","volume":"697","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-6793-0119","authenticated-orcid":false,"given":"Yannan","family":"Jia","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shihui","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lize","family":"Gu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neucom.2026.134144_bib0005","doi-asserted-by":"crossref","first-page":"6525","DOI":"10.1109\/TPAMI.2026.3658949","article-title":"Fine-grained alignment supervision matters in vision-and-language navigation","volume":"48","author":"He","year":"2026","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.neucom.2026.134144_bib0010","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"13782","article-title":"Opendrivevla: Towards end-to-end autonomous driving with large vision language action model","volume":"vol. 40","author":"Zhou","year":"2026"},{"key":"10.1016\/j.neucom.2026.134144_bib0015","article-title":"Few-shot medical image segmentation via clip-driven dual contrastive learning","author":"Zou","year":"2026","journal-title":"Neurocomputing"},{"key":"10.1016\/j.neucom.2026.134144_bib0020","author":"Szegedy"},{"key":"10.1016\/j.neucom.2026.134144_bib0025","author":"Goodfellow"},{"key":"10.1016\/j.neucom.2026.134144_bib0030","author":"Madry"},{"key":"10.1016\/j.neucom.2026.134144_bib0035","series-title":"proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"7714","article-title":"Efficient decision-based black-box adversarial attacks on face recognition","author":"Dong","year":"2019"},{"key":"10.1016\/j.neucom.2026.134144_bib0040","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24452","article-title":"Physical 3d adversarial attacks against monocular depth estimation in autonomous driving","author":"Zheng","year":"2024"},{"key":"10.1016\/j.neucom.2026.134144_bib0045","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"9185","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2018"},{"key":"10.1016\/j.neucom.2026.134144_bib0050","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"2730","article-title":"Improving transferability of adversarial examples with input diversity","author":"Xie","year":"2019"},{"key":"10.1016\/j.neucom.2026.134144_bib0055","article-title":"Bidirectional gradient optimization for enhancing adversarial transferability","author":"Kuang","year":"2025","journal-title":"Neurocomputing"},{"key":"10.1016\/j.neucom.2026.134144_bib0060","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"1924","article-title":"Enhancing the transferability of adversarial attacks through variance tuning","author":"Wang","year":"2021"},{"key":"10.1016\/j.neucom.2026.134144_bib0065","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"3662","article-title":"Making adversarial examples more transferable and indistinguishable","volume":"vol. 36","author":"Zou","year":"2022"},{"key":"10.1016\/j.neucom.2026.134144_bib0070","doi-asserted-by":"crossref","first-page":"70141","DOI":"10.52202\/075280-3073","article-title":"Boosting adversarial transferability by achieving flat local maxima","volume":"36","author":"Ge","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.neucom.2026.134144_bib0075","author":"Qiu"},{"key":"10.1016\/j.neucom.2026.134144_bib0080","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"4312","article-title":"Evading defenses to transferable adversarial examples by translation-invariant attacks","author":"Dong","year":"2019"},{"key":"10.1016\/j.neucom.2026.134144_bib0085","author":"Lin"},{"key":"10.1016\/j.neucom.2026.134144_bib0090","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"16158","article-title":"Admix: Enhancing the transferability of adversarial attacks","author":"Wang","year":"2021"},{"key":"10.1016\/j.neucom.2026.134144_bib0095","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"4607","article-title":"Structure invariant transformation for better adversarial transferability","author":"Wang","year":"2023"},{"key":"10.1016\/j.neucom.2026.134144_bib0100","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"3459","article-title":"Boosting adversarial transferability across model genus by deformation-constrained warping","volume":"vol. 38","author":"Lin","year":"2024"},{"key":"10.1016\/j.neucom.2026.134144_bib0105","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"24336","article-title":"Boosting adversarial transferability by block shuffle and rotation","author":"Wang","year":"2024"},{"key":"10.1016\/j.neucom.2026.134144_bib0110","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"19175","article-title":"Boosting adversarial transferability through augmentation in hypothesis space","author":"Guo","year":"2025"},{"key":"10.1016\/j.neucom.2026.134144_bib0115","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"Moosavi-Dezfooli","year":"2016"},{"key":"10.1016\/j.neucom.2026.134144_bib0120","series-title":"2017 ieee symposium on security and privacy (sp)","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.neucom.2026.134144_bib0125","doi-asserted-by":"crossref","first-page":"7428","DOI":"10.1109\/TPAMI.2025.3572245","article-title":"Data id extraction networks for unsupervised class-and classifier-free detection of adversarial examples","volume":"47","author":"Kong","year":"2025","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.neucom.2026.134144_bib0130","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"7654","article-title":"Nitrofusion: High-fidelity single-step diffusion through dynamic adversarial training","author":"Chen","year":"2025"},{"key":"10.1016\/j.neucom.2026.134144_bib0135","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"6084","article-title":"Comdefend: An efficient image compression model to defend adversarial examples","author":"Jia","year":"2019"},{"key":"10.1016\/j.neucom.2026.134144_bib0140","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"1778","article-title":"Defense against adversarial attacks using high-level representation guided denoiser","author":"Liao","year":"2018"},{"key":"10.1016\/j.neucom.2026.134144_bib0145","author":"Xie"},{"key":"10.1016\/j.neucom.2026.134144_bib0150","series-title":"2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","first-page":"860","article-title":"Feature distillation: Dnn-oriented jpeg compression against adversarial examples","author":"Liu","year":"2019"},{"key":"10.1016\/j.neucom.2026.134144_bib0155","series-title":"international conference on machine learning, PMLR","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","author":"Cohen","year":"2019"},{"key":"10.1016\/j.neucom.2026.134144_bib0160","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"262","article-title":"A self-supervised approach for adversarial robustness","author":"Naseer","year":"2020"},{"key":"10.1016\/j.neucom.2026.134144_bib0165","author":"Nie"},{"key":"10.1016\/j.neucom.2026.134144_bib0170","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"29268","article-title":"Divide and conquer: Heterogeneous noise integration for diffusion-based adversarial purification","author":"Pei","year":"2025"},{"key":"10.1016\/j.neucom.2026.134144_bib0175","series-title":"Artificial intelligence safety and security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.neucom.2026.134144_bib0180","author":"Wenzel"},{"key":"10.1016\/j.neucom.2026.134144_bib0185","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"6132","article-title":"Noisegrad\u00e2\u20ac\u201denhancing explanations by introducing stochasticity to model weights","volume":"vol. 36","author":"Bykov","year":"2022"},{"issue":"3","key":"10.1016\/j.neucom.2026.134144_bib0190","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","article-title":"Imagenet large scale visual recognition challenge","volume":"115","author":"Russakovsky","year":"2015","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.neucom.2026.134144_bib0195","series-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"10.1016\/j.neucom.2026.134144_bib0200","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"2818","article-title":"Rethinking the inception architecture for computer vision","author":"Szegedy","year":"2016"},{"key":"10.1016\/j.neucom.2026.134144_bib0205","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"4278","article-title":"Inception-v4, inception-resnet and the impact of residual connections on learning","volume":"vol. 31","author":"Szegedy","year":"2017"},{"key":"10.1016\/j.neucom.2026.134144_bib0210","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.neucom.2026.134144_bib0215","author":"Howard"},{"key":"10.1016\/j.neucom.2026.134144_bib0220","author":"Simonyan"},{"key":"10.1016\/j.neucom.2026.134144_bib0225","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"1","article-title":"Going deeper with convolutions","author":"Szegedy","year":"2015"},{"key":"10.1016\/j.neucom.2026.134144_bib0230","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"4700","article-title":"Densely connected convolutional networks","author":"Huang","year":"2017"},{"key":"10.1016\/j.neucom.2026.134144_bib0235","author":"Tram\u00e8r"},{"key":"10.1016\/j.neucom.2026.134144_bib0240","author":"Dosovitskiy"},{"key":"10.1016\/j.neucom.2026.134144_bib0245","series-title":"International conference on machine learning, PMLR","first-page":"10347","article-title":"Training data-efficient image transformers & distillation through attention","author":"Touvron","year":"2021"},{"key":"10.1016\/j.neucom.2026.134144_bib0250","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"11936","article-title":"Rethinking spatial dimensions of vision transformers","author":"Heo","year":"2021"},{"key":"10.1016\/j.neucom.2026.134144_bib0255","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"589","article-title":"Visformer: The vision-friendly transformer","author":"Chen","year":"2021"},{"key":"10.1016\/j.neucom.2026.134144_bib0260","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"10012","article-title":"Swin transformer: Hierarchical vision transformer using shifted windows","author":"Liu","year":"2021"},{"issue":"4","key":"10.1016\/j.neucom.2026.134144_bib0265","doi-asserted-by":"crossref","first-page":"600","DOI":"10.1109\/TIP.2003.819861","article-title":"Image quality assessment: from error visibility to structural similarity","volume":"13","author":"Wang","year":"2004","journal-title":"IEEE Trans. Image Process."},{"key":"10.1016\/j.neucom.2026.134144_bib0270","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"586","article-title":"The unreasonable effectiveness of deep features as a perceptual metric","author":"Zhang","year":"2018"},{"key":"10.1016\/j.neucom.2026.134144_bib0275","author":"Liu"},{"issue":"11","key":"10.1016\/j.neucom.2026.134144_bib0280","article-title":"Visualizing data using t-sne","volume":"9","author":"Van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."}],"container-title":["Neurocomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0925231226015420?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0925231226015420?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T07:45:25Z","timestamp":1781509525000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0925231226015420"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":56,"alternative-id":["S0925231226015420"],"URL":"https:\/\/doi.org\/10.1016\/j.neucom.2026.134144","relation":{},"ISSN":["0925-2312"],"issn-type":[{"value":"0925-2312","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Enhancing adversarial transferability via hybrid data and model augmentation","name":"articletitle","label":"Article Title"},{"value":"Neurocomputing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neucom.2026.134144","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"134144"}}