{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T15:01:34Z","timestamp":1781190094519,"version":"3.54.1"},"reference-count":43,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100004753","name":"Southwest Petroleum University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004753","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.neunet.2026.109196","type":"journal-article","created":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T16:34:19Z","timestamp":1780331659000},"page":"109196","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Different direction adversarial sample for diffusion model"],"prefix":"10.1016","volume":"203","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8409-3870","authenticated-orcid":false,"given":"Shan","family":"He","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0719-1881","authenticated-orcid":false,"given":"Hai","family":"Da","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3966-1933","authenticated-orcid":false,"given":"Jun","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-7559-9598","authenticated-orcid":false,"given":"JiaYang","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5440-211X","authenticated-orcid":false,"given":"FuGui","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.109196_bib0001","unstructured":"Aitasai (2023). Darksushimixmix. https:\/\/civitai.com\/models\/24779\/dark-sushi-mix-mix."},{"key":"10.1016\/j.neunet.2026.109196_bib0002","unstructured":"Bi\u0144kowski, M., Sutherland, D. J., Arbel, M. et al. (2018). Demystifying MMD GANs. 10.48550\/arXiv.1801.01401."},{"key":"10.1016\/j.neunet.2026.109196_bib0003","series-title":"2017 IEEE symposium on security and privacy (SP)","first-page":"39","article-title":"Towards evaluating the robustness of neural networks","author":"Carlini","year":"2017"},{"key":"10.1016\/j.neunet.2026.109196_bib0004","series-title":"AI-generated art sparks furious backlash from Japan\u2019s anime community","volume":"22","author":"Deck","year":"2022"},{"key":"10.1016\/j.neunet.2026.109196_bib0005","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"9185","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2018"},{"key":"10.1016\/j.neunet.2026.109196_bib0006","unstructured":"Gal, R., Alaluf, Y., Atzmon, Y. et al. (2022). An image is worth one word: Personalizing text-to-image generation using textual inversion. arXiv: 2208.01618."},{"key":"10.1016\/j.neunet.2026.109196_bib0007","unstructured":"_GhostInShell_ (2023). Ghostmix. https:\/\/civitai.com\/models\/36520\/ghostmix."},{"key":"10.1016\/j.neunet.2026.109196_bib0008","first-page":"2672","article-title":"Generative adversarial nets","volume":"27","author":"Goodfellow","year":"2014","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109196_bib0009","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"Computer Science"},{"key":"10.1016\/j.neunet.2026.109196_bib0010","unstructured":"GSDF (2024). Counterfeit-v3.0: A fine-tuned anime-style diffusion model. https:\/\/huggingface.co\/gsdf\/Counterfeit-V3.0."},{"key":"10.1016\/j.neunet.2026.109196_bib0011","unstructured":"Gu, T., Dolan-Gavitt, B., & Garg, S. (2017). BadNets: Identifying vulnerabilities in the machine learning model supply chain. arXiv: 1708.06733."},{"key":"10.1016\/j.neunet.2026.109196_bib0012","article-title":"Generative artificial intelligence and copyright: Both sides of the black box","author":"Hayes","year":"2023","journal-title":"Available at SSRN 4517799"},{"key":"10.1016\/j.neunet.2026.109196_bib0013","unstructured":"Heusel, M., Ramsauer, H., Unterthiner, T. et al. (2017). Gans trained by a two time-scale update rule converge to a local nash equilibrium. 10.48550\/arXiv.1706.08500."},{"key":"10.1016\/j.neunet.2026.109196_bib0014","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume":"33","author":"Ho","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"issue":"2","key":"10.1016\/j.neunet.2026.109196_bib0015","first-page":"3","article-title":"LORA: Low-rank adaptation of large language models","volume":"1","author":"Hu","year":"2022","journal-title":"ICLR"},{"key":"10.1016\/j.neunet.2026.109196_bib0016","unstructured":"Kingma, D. P., & Welling, M. (2014). Auto-encoding variational bayes. 10.48550\/arXiv.1312.6114."},{"key":"10.1016\/j.neunet.2026.109196_bib0017","series-title":"Artificial intelligence safety and security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.neunet.2026.109196_bib0018","series-title":"Making art with generative AI tools","first-page":"226","article-title":"Ethical dilemmas of AI perspectives towards common digital art and digital crafting: AI artistic view on morality","author":"Le-Nguyen","year":"2024"},{"key":"10.1016\/j.neunet.2026.109196_bib0019","unstructured":"Li, A., Mo, Y., Li, M. et al. (2024). PID: Prompt-independent data protection against latent diffusion models. arXiv: 2406.15305."},{"key":"10.1016\/j.neunet.2026.109196_bib0020","series-title":"International conference on machine learning","first-page":"19730","article-title":"Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models","author":"Li","year":"2023"},{"key":"10.1016\/j.neunet.2026.109196_bib0021","unstructured":"Liang, C., & Wu, X. (2023). Mist: Towards improved adversarial examples for diffusion models. arXiv: 2305.12683."},{"key":"10.1016\/j.neunet.2026.109196_bib0022","unstructured":"Liang, C., Wu, X., Hua, Y. et al. (2023). Adversarial example does good: Preventing painting imitation from diffusion models via adversarial examples. abs\/2302.04578. 10.48550\/arXiv.2302.04578."},{"key":"10.1016\/j.neunet.2026.109196_bib0023","unstructured":"Madry, A., Makelov, A., Schmidt, L. et al. (2017). Towards deep learning models resistant to adversarial attacks. 10.48550\/arXiv.1706.06083."},{"key":"10.1016\/j.neunet.2026.109196_bib0024","unstructured":"Nguyen, S. (2024). The copyright and plagiarism dilemma: AI-generated design works derived from existing works. Bachelor\u2019s thesis, Haaga-Helia University of Applied Sciences. https:\/\/urn.fi\/URN:NBN:fi:amk-2024092725728."},{"key":"10.1016\/j.neunet.2026.109196_bib0025","series-title":"Computer graphics forum","first-page":"e15063","article-title":"State of the art on diffusion models for visual computing","volume":"vol. 43","author":"Po","year":"2024"},{"key":"10.1016\/j.neunet.2026.109196_bib0026","series-title":"International conference on machine learning","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","author":"Radford","year":"2021"},{"key":"10.1016\/j.neunet.2026.109196_bib0027","unstructured":"Radford, A., Kim, J. W., Hallacy, C. et al. (2021b). Learning transferable visual models from natural language supervision. 10.48550\/arXiv.2103.00020."},{"key":"10.1016\/j.neunet.2026.109196_bib0028","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"10684","article-title":"High-resolution image synthesis with latent diffusion models","author":"Rombach","year":"2022"},{"key":"10.1016\/j.neunet.2026.109196_bib0029","series-title":"Medical image computing and computer-assisted intervention\u2013MICCAI 2015: 18th international conference, Munich, Germany, October 5-9, 2015, proceedings, Part III 18","first-page":"234","article-title":"U-Net: Convolutional networks for biomedical image segmentation","author":"Ronneberger","year":"2015"},{"key":"10.1016\/j.neunet.2026.109196_bib0030","unstructured":"Salman, H., Khaddaj, A., Leclerc, G. et al. (2023). Raising the cost of malicious AI-powered image editing. arXiv: 2302.06588."},{"key":"10.1016\/j.neunet.2026.109196_bib0031","first-page":"25278","article-title":"Laion-5b: An open large-scaledataset for training next generation image-text models","volume":"35","author":"Schuhmann","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109196_bib0032","series-title":"32nd USENIX security symposium (USENIX security 23)","first-page":"2187","article-title":"Glaze: Protecting artists from style mimicry by {Text-to-Image} models","author":"Shan","year":"2023"},{"key":"10.1016\/j.neunet.2026.109196_bib0033","series-title":"29th USENIX security symposium (USENIX security 20)","first-page":"1589","article-title":"Fawkes: Protecting privacy against unauthorized deep learning models","author":"Shan","year":"2020"},{"issue":"10","key":"10.1016\/j.neunet.2026.109196_bib0034","doi-asserted-by":"crossref","first-page":"1338","DOI":"10.1007\/s40319-021-01119-w","article-title":"When art meets technology or vice versa: Key challenges at the crossroads of AI-generated artworks and copyright law","volume":"52","author":"\u0160kilji\u0107","year":"2021","journal-title":"IIC-International Review of Intellectual Property and Competition Law"},{"key":"10.1016\/j.neunet.2026.109196_bib0035","series-title":"International conference on machine learning","first-page":"2256","article-title":"Deep unsupervised learning using nonequilibrium thermodynamics","author":"Sohl-Dickstein","year":"2015"},{"key":"10.1016\/j.neunet.2026.109196_bib0036","unstructured":"Song, Y., Sohl-Dickstein, J., Kingma, D. P., Kumar, A., Ermon, S., & Poole, B. (2020). Score-based generative modeling through stochastic differential equations. arXiv: 2011.13456."},{"key":"10.1016\/j.neunet.2026.109196_bib0037","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I. et al. (2013). Intriguing properties of neural networks. arXiv: 1312.6199."},{"issue":"4","key":"10.1016\/j.neunet.2026.109196_bib0038","article-title":"Image quality assessment: From error visibility to structural similarity","volume":"13","author":"Wang","year":"2004","journal-title":"IEEE Transactions on Image Processing"},{"issue":"3","key":"10.1016\/j.neunet.2026.109196_bib0039","doi-asserted-by":"crossref","DOI":"10.69554\/TYWR8541","article-title":"Privacy and AI: Protecting individuals in the age of AI by Federico Marengo","volume":"6","author":"Wilkinson","year":"2024","journal-title":"Journal of Data Protection & Privacy"},{"issue":"4","key":"10.1016\/j.neunet.2026.109196_bib0040","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3626235","article-title":"Diffusion models: A comprehensive survey of methods and applications","volume":"56","author":"Yang","year":"2023","journal-title":"ACM Computing Surveys"},{"issue":"12","key":"10.1016\/j.neunet.2026.109196_bib0041","doi-asserted-by":"crossref","first-page":"15098","DOI":"10.1109\/TPAMI.2023.3305243","article-title":"Multimodal image synthesis and editing: The generative AI era","volume":"45","author":"Zhan","year":"2023","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.neunet.2026.109196_bib0042","series-title":"Proceedings of the IEEE\/CVF international conference on computer vision","first-page":"3836","article-title":"Adding conditional control to text-to-image diffusion models","author":"Zhang","year":"2023"},{"key":"10.1016\/j.neunet.2026.109196_bib0043","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"586","article-title":"The unreasonable effectiveness of deep features as a perceptual metric","author":"Zhang","year":"2018"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S089360802600657X?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S089360802600657X?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T14:20:01Z","timestamp":1781187601000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S089360802600657X"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":43,"alternative-id":["S089360802600657X"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109196","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Different direction adversarial sample for diffusion model","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109196","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"109196"}}