{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T12:04:16Z","timestamp":1784203456525,"version":"3.55.0"},"reference-count":48,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100002701","name":"Ministry of Education","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100002701","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62462047"],"award-info":[{"award-number":["62462047"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.neunet.2026.109032","type":"journal-article","created":{"date-parts":[[2026,4,27]],"date-time":"2026-04-27T16:42:45Z","timestamp":1777308165000},"page":"109032","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["AIIT: An adjustable integration adversarial attack based on image transformation"],"prefix":"10.1016","volume":"202","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-7432-7104","authenticated-orcid":false,"given":"Yunong","family":"Guo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2598-1963","authenticated-orcid":false,"given":"Yang","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4641-1326","authenticated-orcid":false,"given":"Jing","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.109032_bib0001","unstructured":"Bonet, C., Berg, P., Courty, N., Septier, F., Drumetz, L., & Pham, M.-T. (2022). Spherical sliced-wasserstein. arXiv preprint arXiv:2206.08780."},{"key":"10.1016\/j.neunet.2026.109032_bib0002","unstructured":"Cai, Q.-Z., Du, M., Liu, C., & Song, D. (2018). Curriculum adversarial training. arXiv preprint arXiv:1805.04807."},{"key":"10.1016\/j.neunet.2026.109032_bib0003","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision (ICCV)","first-page":"4489","article-title":"An adaptive model ensemble adversarial attack for boosting adversarial transferability","author":"Chen","year":"2023"},{"key":"10.1016\/j.neunet.2026.109032_bib0004","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"24625","article-title":"On the robustness of large multimodal models against image adversarial attacks","author":"Cui","year":"2024"},{"key":"10.1016\/j.neunet.2026.109032_bib0005","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"248","article-title":"Imagenet: A large-scale hierarchical image database","author":"Deng","year":"2009"},{"key":"10.1016\/j.neunet.2026.109032_bib0006","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"9185","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2018"},{"key":"10.1016\/j.neunet.2026.109032_bib0007","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"4312","article-title":"Evading defenses to transferable adversarial examples by translation-invariant attacks","author":"Dong","year":"2019"},{"key":"10.1016\/j.neunet.2026.109032_bib0008","unstructured":"Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., Gelly, S. et al. (2020). An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929."},{"key":"10.1016\/j.neunet.2026.109032_bib0009","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572."},{"key":"10.1016\/j.neunet.2026.109032_bib0010","unstructured":"Guo, C., Rana, M., Cisse, M., & Van Der Maaten, L. (2017). Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117."},{"key":"10.1016\/j.neunet.2026.109032_bib0011","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.neunet.2026.109032_bib0012","doi-asserted-by":"crossref","unstructured":"Jia, J., Cao, X., Wang, B., & Gong, N. Z. (2019a). Certified robustness for top-k predictions against adversarial perturbations via randomized smoothing. arXiv preprint arXiv:1912.09899.","DOI":"10.1145\/3366423.3380029"},{"key":"10.1016\/j.neunet.2026.109032_bib0013","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"6084","article-title":"Comdefend: An efficient image compression model to defend adversarial examples","author":"Jia","year":"2019"},{"key":"10.1016\/j.neunet.2026.109032_bib0014","unstructured":"Kariyappa, S., & Qureshi, M. K. (2019). Improving adversarial robustness of ensembles with diversity training. arXiv preprint arXiv:1901.09981."},{"key":"10.1016\/j.neunet.2026.109032_bib0015","series-title":"Proceedings of the European conference on computer vision (ECCV)","first-page":"491","article-title":"Big transfer (bit): General visual representation learning","author":"Kolesnikov","year":"2020"},{"key":"10.1016\/j.neunet.2026.109032_bib0016","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"5258","article-title":"Sliced wasserstein kernels for probability distributions","author":"Kolouri","year":"2016"},{"key":"10.1016\/j.neunet.2026.109032_bib0017","series-title":"Proceedings of the international conference on learning representations (ICLR)","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2017"},{"key":"10.1016\/j.neunet.2026.109032_bib0018","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"10285","article-title":"Sliced wasserstein discrepancy for unsupervised domain adaptation","author":"Lee","year":"2019"},{"key":"10.1016\/j.neunet.2026.109032_bib0019","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"1778","article-title":"Defense against adversarial attacks using high-level representation guided denoiser","author":"Liao","year":"2018"},{"key":"10.1016\/j.neunet.2026.109032_bib0020","unstructured":"Liu, Y., Chen, X., Liu, C., & Song, D. (2016). Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770."},{"key":"10.1016\/j.neunet.2026.109032_bib0021","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"10012","article-title":"Swin transformer: Hierarchical vision transformer using shifted windows","author":"Liu","year":"2021"},{"key":"10.1016\/j.neunet.2026.109032_bib0022","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"860","article-title":"Feature distillation: Dnn-oriented jpeg compression against adversarial examples","author":"Liu","year":"2019"},{"key":"10.1016\/j.neunet.2026.109032_bib0023","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106461","article-title":"Hygloadattack: Hard-label black-box textual adversarial attacks via hybrid optimization","volume":"178","author":"Liu","year":"2024","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109032_bib0024","series-title":"Proceedings of the European conference on computer vision (ECCV)","first-page":"549","article-title":"Frequency domain model augmentation for adversarial attack","author":"Long","year":"2022"},{"key":"10.1016\/j.neunet.2026.109032_bib0025","unstructured":"Madry, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083."},{"key":"10.1016\/j.neunet.2026.109032_bib0026","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"262","article-title":"A self-supervised approach for adversarial robustness","author":"Naseer","year":"2020"},{"key":"10.1016\/j.neunet.2026.109032_bib0027","series-title":"Proceedings of the international conference on machine learning (ICML)","first-page":"4970","article-title":"Improving adversarial robustness via promoting ensemble diversity","author":"Pang","year":"2019"},{"key":"10.1016\/j.neunet.2026.109032_bib0028","unstructured":"Szegedy, C. (2013). Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199."},{"key":"10.1016\/j.neunet.2026.109032_bib0029","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"1","article-title":"Going deeper with convolutions","author":"Szegedy","year":"2015"},{"key":"10.1016\/j.neunet.2026.109032_bib0030","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"2818","article-title":"Rethinking the inception architecture for computer vision","author":"Szegedy","year":"2016"},{"key":"10.1016\/j.neunet.2026.109032_bib0031","series-title":"Proceedings of the international conference on machine learning (ICML)","first-page":"10347","article-title":"Training data-efficient image transformers & distillation through attention","author":"Touvron","year":"2021"},{"key":"10.1016\/j.neunet.2026.109032_bib0032","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I., Boneh, D., & McDaniel, P. (2017). Ensemble adversarial training: Attacks and defenses. arXiv preprint arXiv:1705.07204."},{"key":"10.1016\/j.neunet.2026.109032_bib0033","unstructured":"Vayer, T., Flamary, R., Tavenard, R., Chapel, L., & Courty, N. (2019). Sliced gromov-wasserstein. arXiv preprint arXiv:1905.10124."},{"key":"10.1016\/j.neunet.2026.109032_bib0034","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"24336","article-title":"Boosting adversarial transferability by block shuffle and rotation","author":"Wang","year":"2024"},{"key":"10.1016\/j.neunet.2026.109032_bib0035","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision (ICCV)","first-page":"16158","article-title":"Admix: Enhancing the transferability of adversarial attacks","author":"Wang","year":"2021"},{"issue":"5","key":"10.1016\/j.neunet.2026.109032_bib0036","doi-asserted-by":"crossref","first-page":"3772","DOI":"10.1109\/TPAMI.2023.3347835","article-title":"Adaptive cross-modal transferable adversarial attacks from images to videos","volume":"46","author":"Wei","year":"2023","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.neunet.2026.109032_bib0037","unstructured":"Xie, C., Wang, J., Zhang, Z., Ren, Z., & Yuille, A. (2017). Mitigating adversarial effects through randomization. arXiv preprint arXiv:1711.01991."},{"key":"10.1016\/j.neunet.2026.109032_bib0038","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"2730","article-title":"Improving transferability of adversarial examples with input diversity","author":"Xie","year":"2019"},{"key":"10.1016\/j.neunet.2026.109032_bib0039","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"14983","article-title":"Stochastic variance reduced ensemble adversarial attack for boosting the adversarial transferability","author":"Xiong","year":"2022"},{"key":"10.1016\/j.neunet.2026.109032_bib0040","doi-asserted-by":"crossref","unstructured":"Xu, W. (2017). Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155.","DOI":"10.14722\/ndss.2018.23198"},{"key":"10.1016\/j.neunet.2026.109032_bib0041","article-title":"Dverge: Diversifying vulnerabilities for enhanced robust generation of ensembles","author":"Yang","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109032_bib0042","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1109\/TMM.2021.3124083","article-title":"AutoMA: Towards automatic model augmentation for transferable adversarial attacks","volume":"25","author":"Yuan","year":"2021","journal-title":"IEEE Transactions on Multimedia"},{"key":"10.1016\/j.neunet.2026.109032_bib0043","series-title":"Proceedings of the European conference on computer vision (ECCV)","first-page":"1","article-title":"Adaptive image transformations for transfer-based adversarial attack","author":"Yuan","year":"2022"},{"key":"10.1016\/j.neunet.2026.109032_bib0044","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., & Komodakis, N. (2016). Wide residual networks. arXiv preprint arXiv:1605.07146.","DOI":"10.5244\/C.30.87"},{"key":"10.1016\/j.neunet.2026.109032_bib0045","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","first-page":"8173","article-title":"Improving the transferability of adversarial samples by path-augmented method","author":"Zhang","year":"2023"},{"key":"10.1016\/j.neunet.2026.109032_bib0046","series-title":"Proceedings of the international conference on machine learning (ICML)","first-page":"11278","article-title":"Attacks which do not kill training make adversarial learning stronger","author":"Zhang","year":"2020"},{"key":"10.1016\/j.neunet.2026.109032_bib0047","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2025.107341","article-title":"Improving transferability of adversarial examples via statistical attribution-based attacks","volume":"187","author":"Zhu","year":"2025","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109032_bib0048","series-title":"Proceedings of the European conference on computer vision (ECCV)","first-page":"563","article-title":"Improving the transferability of adversarial examples with resized-diverse-inputs, diversity-ensemble and region fitting","author":"Zou","year":"2020"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026004922?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026004922?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T11:12:04Z","timestamp":1784200324000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0893608026004922"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":48,"alternative-id":["S0893608026004922"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109032","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"AIIT: An adjustable integration adversarial attack based on image transformation","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109032","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"109032"}}