{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T17:17:05Z","timestamp":1779383825863,"version":"3.53.1"},"reference-count":49,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100004000","name":"Guangzhou Science and Technology Program Key Projects","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100004000","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003453","name":"Guangdong Provincial Natural Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003453","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Pattern Recognition"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.patcog.2026.113360","type":"journal-article","created":{"date-parts":[[2026,2,25]],"date-time":"2026-02-25T16:13:12Z","timestamp":1772035992000},"page":"113360","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Towards structural transformation-based attack for boosting transferability of adversarial examples"],"prefix":"10.1016","volume":"178","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1510-3443","authenticated-orcid":false,"given":"Yatie","family":"Xiao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1788-3746","authenticated-orcid":false,"given":"Chi-Man","family":"Pun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8053-4587","authenticated-orcid":false,"given":"Fei","family":"Peng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2439-3518","authenticated-orcid":false,"given":"Kongyang","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8193-1234","authenticated-orcid":false,"given":"Qingxiao","family":"Guan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.patcog.2026.113360_bib0001","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2025.111466","article-title":"CDN4: a cross-view deep nearest neighbor neural network for fine-grained few-shot classification","volume":"163","author":"Li","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113360_bib0002","series-title":"14th European Conference on Computer Vision","first-page":"630","article-title":"Identity mappings in deep residual networks","volume":"9908","author":"He","year":"2016"},{"key":"10.1016\/j.patcog.2026.113360_bib0003","series-title":"Proceedings of the International Conference on Learning Representations","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2014"},{"key":"10.1016\/j.patcog.2026.113360_bib0004","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24336","article-title":"Boosting adversarial transferability by block shuffle and rotation","author":"Wang","year":"2024"},{"key":"10.1016\/j.patcog.2026.113360_bib0005","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"19175","article-title":"Boosting adversarial transferability through augmentation in hypothesis space","author":"Guo","year":"2025"},{"key":"10.1016\/j.patcog.2026.113360_bib0006","series-title":"Proceedings of the IEEE International Conference on Computer Vision","first-page":"618","article-title":"Grad-CAM: visual explanations from deep networks via gradient-based localization","author":"Selvaraju","year":"2017"},{"key":"10.1016\/j.patcog.2026.113360_bib0007","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","article-title":"Boosting adversarial attacks with momentum","author":"Dong","year":"2018"},{"key":"10.1016\/j.patcog.2026.113360_bib0008","series-title":"Proceedings of the 5th International Conference on Learning Representations","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2017"},{"key":"10.1016\/j.patcog.2026.113360_bib0009","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"2730","article-title":"Improving transferability of adversarial examples with input diversity","author":"Xie","year":"2019"},{"key":"10.1016\/j.patcog.2026.113360_bib0010","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"2600","article-title":"AttackBench: evaluating gradient-based attacks for adversarial examples","volume":"39","author":"Cin\u00e0","year":"2025"},{"key":"10.1016\/j.patcog.2026.113360_bib0011","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"4733","article-title":"Enhancing adversarial example transferability with an intermediate level attack","author":"Huang","year":"2019"},{"key":"10.1016\/j.patcog.2026.113360_bib0012","series-title":"Proceedings of the 10th International Conference on Learning Representations","article-title":"Transferable adversarial attack based on integrated gradients","author":"Huang","year":"2022"},{"key":"10.1016\/j.patcog.2026.113360_bib0013","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"14993","article-title":"Improving adversarial transferability via neuron attribution-based attacks","author":"Zhang","year":"2022"},{"key":"10.1016\/j.patcog.2026.113360_bib0014","series-title":"Proceedings of the European Conference on Computer Vision","first-page":"307","article-title":"Patch-wise attack for fooling deep neural network","author":"Gao","year":"2020"},{"key":"10.1016\/j.patcog.2026.113360_bib0015","series-title":"Proceedings of the 8th International Conference on Learning Representations","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","author":"Lin","year":"2020"},{"key":"10.1016\/j.patcog.2026.113360_bib0016","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"4312","article-title":"Evading defenses to transferable adversarial examples by translation-invariant attacks","author":"Dong","year":"2019"},{"key":"10.1016\/j.patcog.2026.113360_bib0017","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"16158","article-title":"Admix: enhancing the transferability of adversarial attacks","author":"Wang","year":"2021"},{"key":"10.1016\/j.patcog.2026.113360_bib0018","series-title":"Proceedings of the European Conference on Computer Vision (ECCV)","first-page":"452","article-title":"Transferable adversarial perturbations","author":"Zhou","year":"2018"},{"key":"10.1016\/j.patcog.2026.113360_bib0019","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"6731","article-title":"Improving integrated gradient-based transferable adversarial examples by refining the integration path","volume":"39","author":"Ren","year":"2025"},{"key":"10.1016\/j.patcog.2026.113360_bib0020","series-title":"Proceedings of the 42nd International Conference on Machine Learning","first-page":"39853","article-title":"Pixel2feature attack (p2FA): rethinking the perturbed space to enhance adversarial transferability","volume":"267","author":"Liu","year":"2025"},{"key":"10.1016\/j.patcog.2026.113360_bib0021","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"7639","article-title":"Feature importance-aware transferable adversarial attacks","author":"Wang","year":"2021"},{"key":"10.1016\/j.patcog.2026.113360_bib0022","doi-asserted-by":"crossref","first-page":"1462","DOI":"10.1109\/TIFS.2025.3526067","article-title":"Enhancing the transferability of adversarial attacks via multi-Feature attention","volume":"20","author":"Zheng","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.patcog.2026.113360_bib0023","doi-asserted-by":"crossref","first-page":"5563","DOI":"10.1109\/TIFS.2025.3574989","article-title":"Boosting the transferability of adversarial examples through gradient aggregation","volume":"20","author":"Gan","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.patcog.2026.113360_bib0024","series-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","first-page":"25071","article-title":"Improving adversarial transferability on vision transformers via forward propagation refinement","author":"Ren","year":"2025"},{"key":"10.1016\/j.patcog.2026.113360_bib0025","first-page":"1778","article-title":"Defense against adversarial attacks using high-Level representation guided denoiser","author":"Liao","year":"2017","journal-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113360_bib0026","series-title":"Proceedings of the 36th International Conference on Machine Learning","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume":"97","author":"Cohen","year":"2019"},{"key":"10.1016\/j.patcog.2026.113360_bib0027","series-title":"Proceedings of the 6th International Conference on Learning Representations","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2018"},{"key":"10.1016\/j.patcog.2026.113360_bib0028","series-title":"Proceedings of the International Conference on Learning Representations","article-title":"Ensemble adversarial training: attacks and defenses","author":"Tram\u00e8r","year":"2018"},{"key":"10.1016\/j.patcog.2026.113360_bib0029","series-title":"International Conference on Machine Learning, ICML","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume":"97","author":"Zhang","year":"2019"},{"key":"10.1016\/j.patcog.2026.113360_bib0030","series-title":"Proceedings of the 7th International Conference on Learning Representations","article-title":"Improving adversarial robustness requires revisiting misclassified examples","author":"Wang","year":"2019"},{"key":"10.1016\/j.patcog.2026.113360_bib0031","series-title":"Proceedings of the International Conference on Machine Learning","first-page":"17258","article-title":"Robustness and accuracy could be reconcilable by (proper) definition","author":"Pang","year":"2022"},{"key":"10.1016\/j.patcog.2026.113360_bib0032","series-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","first-page":"15701","article-title":"Learnable boundary guided adversarial training","author":"Cui","year":"2021"},{"key":"10.1016\/j.patcog.2026.113360_bib0033","unstructured":"S.-A. Rebuffi, S. Gowal, D.A. Calian, F. Stimberg, O. Wiles, T.A. Mann, Fixing data augmentation to improve adversarial robustness, ArXiv abs\/2103.01946(2021)."},{"key":"10.1016\/j.patcog.2026.113360_bib0034","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"6222","article-title":"Efficient robust training via backward smoothing","author":"Chen","year":"2022"},{"key":"10.1016\/j.patcog.2026.113360_bib0035","first-page":"259","article-title":"A self-supervised approach for adversarial robustness","author":"Naseer","year":"2020","journal-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113360_bib0036","series-title":"The mnist database of handwritten digits","author":"LeCun","year":"2005"},{"key":"10.1016\/j.patcog.2026.113360_bib0037","series-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"10.1016\/j.patcog.2026.113360_bib0038","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"248","article-title":"ImageNet: a large-scale hierarchical image database","author":"Deng","year":"2009"},{"key":"10.1016\/j.patcog.2026.113360_bib0039","first-page":"4510","article-title":"MobileNetV2: inverted residuals and linear bottlenecks","author":"Sandler","year":"2018","journal-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113360_bib0040","series-title":"Proceedings of the European Conference on Computer Vision","first-page":"122","article-title":"ShuffleNet V2: practical guidelines for efficient CNN architecture design","volume":"11218","author":"Ma","year":"2018"},{"key":"10.1016\/j.patcog.2026.113360_bib0041","first-page":"13728","article-title":"RepVGG: making VGG-style ConvNets great again","author":"Ding","year":"2021","journal-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition"},{"key":"10.1016\/j.patcog.2026.113360_bib0042","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"2818","article-title":"Rethinking the inception architecture for computer vision","author":"Szegedy","year":"2016"},{"key":"10.1016\/j.patcog.2026.113360_bib0043","series-title":"Proceedings of the Thirty-First AAAI Conference on Artificial Intelligence","first-page":"4278","article-title":"Inception-v4, inception-ResNet and the impact of residual connections on learning","author":"Szegedy","year":"2017"},{"key":"10.1016\/j.patcog.2026.113360_bib0044","series-title":"9th International Conference on Learning Representations, ICLR","article-title":"An image is worth 16x16 words: transformers for image recognition at scale","author":"Dosovitskiy","year":"2021"},{"key":"10.1016\/j.patcog.2026.113360_bib0045","series-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, New Orleans, LA, USA","first-page":"11999","article-title":"Swin transformer V2: scaling up capacity and resolution","author":"Liu","year":"2022"},{"key":"10.1016\/j.patcog.2026.113360_bib0046","series-title":"Proceedings of the European Conference on Computer Vision","first-page":"301","article-title":"Scaling adversarial training to large perturbation bounds","author":"Addepalli","year":"2022"},{"key":"10.1016\/j.patcog.2026.113360_bib0047","series-title":"Proceedings of the 10th International Conference on Learning Representations","article-title":"Robust learning meets generative models: can proxy distributions improve adversarial robustness?","author":"Sehwag","year":"2022"},{"key":"10.1016\/j.patcog.2026.113360_bib0048","series-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS)","article-title":"Decoupled Kullback-Leibler divergence loss","author":"Cui","year":"2024"},{"key":"10.1016\/j.patcog.2026.113360_bib0049","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.110394","article-title":"Data filtering for efficient adversarial training","volume":"151","author":"Chen","year":"2024","journal-title":"Pattern Recognit."}],"container-title":["Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326003250?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326003250?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T16:57:55Z","timestamp":1779382675000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0031320326003250"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":49,"alternative-id":["S0031320326003250"],"URL":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113360","relation":{},"ISSN":["0031-3203"],"issn-type":[{"value":"0031-3203","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Towards structural transformation-based attack for boosting transferability of adversarial examples","name":"articletitle","label":"Article Title"},{"value":"Pattern Recognition","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113360","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"113360"}}