{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T15:57:39Z","timestamp":1780934259887,"version":"3.54.1"},"reference-count":38,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Pattern Recognition"],"published-print":{"date-parts":[[2026,12]]},"DOI":"10.1016\/j.patcog.2026.113908","type":"journal-article","created":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T15:36:53Z","timestamp":1777995413000},"page":"113908","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PA","title":["Regarding general robust-feature as trigger: A transferable backdoor attack against black-box models"],"prefix":"10.1016","volume":"180","author":[{"given":"Jinbo","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruijin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fengli","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.patcog.2026.113908_b1","series-title":"The Fourteenth International Conference on Learning Representations","article-title":"Vid-LLM: A compact video-based 3D multimodal LLM with reconstruction\u2013reasoning synergy","author":"Chen","year":"2026"},{"key":"10.1016\/j.patcog.2026.113908_b2","doi-asserted-by":"crossref","unstructured":"Zhaoyi Liu, Huan Zhang, Stealthy Backdoor Attack in Self-Supervised Learning Vision Encoders for Large Vision Language Models, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2025, pp. 25060\u201325070.","DOI":"10.1109\/CVPR52734.2025.02333"},{"key":"10.1016\/j.patcog.2026.113908_b3","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111262","article-title":"A trigger-perceivable backdoor attack framework driven by image steganography","volume":"161","author":"Tang","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113908_b4","series-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"10.1016\/j.patcog.2026.113908_b5","doi-asserted-by":"crossref","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","article-title":"BadNets: Evaluating backdooring attacks on deep neural networks","volume":"7","author":"Gu","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.patcog.2026.113908_b6","series-title":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","first-page":"2863","article-title":"Towards backdoor stealthiness in model parameter space","author":"Xu","year":"2025"},{"key":"10.1016\/j.patcog.2026.113908_b7","doi-asserted-by":"crossref","unstructured":"Xiang Li, Lannan Luo, Qiang Zeng, Backdoor attacks on neural networks via one-bit flip, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2025, pp. 4328\u20134338.","DOI":"10.1109\/ICCV51701.2025.00412"},{"key":"10.1016\/j.patcog.2026.113908_b8","series-title":"33rd USENIX Security Symposium (USENIX Security 24)","first-page":"2883","article-title":"Neural network semantic backdoor detection and mitigation: A Causality-Based approach","author":"Sun","year":"2024"},{"issue":"7","key":"10.1016\/j.patcog.2026.113908_b9","first-page":"6657","article-title":"Mutual-modality adversarial attack with semantic perturbation","volume":"38","author":"Ye","year":"2024","journal-title":"Proc. the AAAI Conf. Artif. Intell."},{"key":"10.1016\/j.patcog.2026.113908_b10","series-title":"33rd USENIX Security Symposium (USENIX Security 24)","first-page":"6867","article-title":"Hijacking attacks against neural network by analyzing training data","author":"Ge","year":"2024"},{"key":"10.1016\/j.patcog.2026.113908_b11","series-title":"2024 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"24615","article-title":"Improving transferable targeted adversarial attacks with model self-enhancement","author":"Wu","year":"2024"},{"key":"10.1016\/j.patcog.2026.113908_b12","doi-asserted-by":"crossref","unstructured":"Zhibo Wang, Hengchang Guo, Zhifei Zhang, Wenxin Liu, Zhan Qin, Kui Ren, Feature importance-aware transferable adversarial attacks, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 7639\u20137648.","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"10.1016\/j.patcog.2026.113908_b13","series-title":"2021 IEEE\/CVF International Conference on Computer Vision","first-page":"7688","article-title":"On generating transferable targeted perturbations","author":"Naseer","year":"2021"},{"key":"10.1016\/j.patcog.2026.113908_b14","doi-asserted-by":"crossref","unstructured":"Shixin Li, Chaoxiang He, Xiaojing Ma, Bin Benjamin Zhu, Shuo Wang, Hongsheng Hu, Dongmei Zhang, Linchen Yu, Enhancing Adversarial Transferability with Checkpoints of a Single Model\u2019s Training, in: Proceedings of the Computer Vision and Pattern Recognition Conference, 2025, pp. 20685\u201320694.","DOI":"10.1109\/CVPR52734.2025.01926"},{"key":"10.1016\/j.patcog.2026.113908_b15","series-title":"Advances in Neural Information Processing Systems","first-page":"9759","article-title":"A little robustness goes a long way: Leveraging robust features for targeted transfer attacks","volume":"Vol. 34","author":"Springer","year":"2021"},{"issue":"4","key":"10.1016\/j.patcog.2026.113908_b16","doi-asserted-by":"crossref","first-page":"3328","DOI":"10.1109\/TDSC.2022.3196646","article-title":"Poisoning-assisted property inference attack against federated learning","volume":"20","author":"Wang","year":"2023","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.patcog.2026.113908_b17","series-title":"International Conference on Learning Representations","article-title":"Sharpness-aware minimization for efficiently improving generalization","author":"Foret","year":"2021"},{"issue":"8","key":"10.1016\/j.patcog.2026.113908_b18","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3711121","article-title":"Knowledge distillation on graphs: A survey","volume":"57","author":"Tian","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.patcog.2026.113908_b19","series-title":"Proceedings of the 34th International Conference on Machine Learning - Volume 70","first-page":"1126","article-title":"Model-agnostic meta-learning for fast adaptation of deep networks","author":"Finn","year":"2017"},{"key":"10.1016\/j.patcog.2026.113908_b20","unstructured":"Wanyun Xie, Fabian Latorre, Kimon Antonakopoulos, Thomas Pethick, Volkan Cevher, Improving SAM Requires Rethinking its Optimization Formulation, in: International Conference on Machine Learning, ICML, 2024."},{"key":"10.1016\/j.patcog.2026.113908_b21","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2025.107429","article-title":"Neighborhood relation-based knowledge distillation for image classification","volume":"188","author":"Gou","year":"2025","journal-title":"Neural Netw."},{"key":"10.1016\/j.patcog.2026.113908_b22","doi-asserted-by":"crossref","unstructured":"Guoqiang Gong, Jiaxing Wang, Jin Xu, Deping Xiang, Zicheng Zhang, Leqi Shen, Yifeng Zhang, JunhuaShu JunhuaShu, ZhaolongXing ZhaolongXing, Zhen Chen, et al., Beyond logits: Aligning feature dynamics for effective knowledge distillation, in: Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), 2025, pp. 23067\u201323077.","DOI":"10.18653\/v1\/2025.acl-long.1125"},{"key":"10.1016\/j.patcog.2026.113908_b23","series-title":"Proceedings of the 40th International Conference on Machine Learning","article-title":"Cross-entropy loss functions: theoretical analysis and applications","author":"Mao","year":"2023"},{"key":"10.1016\/j.patcog.2026.113908_b24","series-title":"International Encyclopedia of Statistical Science","first-page":"1307","article-title":"Kullback-leibler divergence","author":"Joyce","year":"2025"},{"issue":"7","key":"10.1016\/j.patcog.2026.113908_b25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3776588","article-title":"From tiny machine learning to tiny deep learning: A survey","volume":"58","author":"Somvanshi","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.patcog.2026.113908_b26","series-title":"NIPS Workshop on Deep Learning and Unsupervised Feature Learning 2011","article-title":"Reading digits in natural images with unsupervised feature learning","author":"Netzer","year":"2011"},{"issue":"4","key":"10.1016\/j.patcog.2026.113908_b27","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1007\/s10462-024-10721-6","article-title":"A review of convolutional neural networks in computer vision","volume":"57","author":"Zhao","year":"2024","journal-title":"Artif. Intell. Rev."},{"key":"10.1016\/j.patcog.2026.113908_b28","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2024.109890","article-title":"Development of residual learning in deep neural networks for computer vision: A survey","volume":"142","author":"Xu","year":"2025","journal-title":"Eng. Appl. Artif. Intell."},{"issue":"3","key":"10.1016\/j.patcog.2026.113908_b29","doi-asserted-by":"crossref","first-page":"195","DOI":"10.3390\/info16030195","article-title":"Deep convolutional neural networks in medical image analysis: A review","volume":"16","author":"Mienye","year":"2025","journal-title":"Information"},{"key":"10.1016\/j.patcog.2026.113908_b30","doi-asserted-by":"crossref","DOI":"10.1016\/j.compbiomed.2024.109507","article-title":"A review of convolutional neural network based methods for medical image classification","volume":"185","author":"Chen","year":"2025","journal-title":"Comput. Biol. Med."},{"key":"10.1016\/j.patcog.2026.113908_b31","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.110967","article-title":"HTR-VT: Handwritten text recognition with vision transformer","volume":"158","author":"Li","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113908_b32","doi-asserted-by":"crossref","unstructured":"Aravind Srinivas, Tsung-Yi Lin, Niki Parmar, Jonathon Shlens, Pieter Abbeel, Ashish Vaswani, Bottleneck Transformers for Visual Recognition, in: 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR, 2021, pp. 16514\u201316524.","DOI":"10.1109\/CVPR46437.2021.01625"},{"key":"10.1016\/j.patcog.2026.113908_b33","doi-asserted-by":"crossref","unstructured":"Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, Jianguo Li, Boosting adversarial attacks with momentum, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2018, pp. 9185\u20139193.","DOI":"10.1109\/CVPR.2018.00957"},{"issue":"4\u20135","key":"10.1016\/j.patcog.2026.113908_b34","doi-asserted-by":"crossref","first-page":"185","DOI":"10.1016\/0925-2312(93)90006-O","article-title":"Backpropagation and stochastic gradient descent method","volume":"5","author":"Amari","year":"1993","journal-title":"Neurocomputing"},{"key":"10.1016\/j.patcog.2026.113908_b35","series-title":"3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015"},{"key":"10.1016\/j.patcog.2026.113908_b36","series-title":"International Conference on Learning Representations","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2018"},{"key":"10.1016\/j.patcog.2026.113908_b37","series-title":"Proceedings of the 29th International Conference on Neural Information Processing Systems - Volume 1","first-page":"1135","article-title":"Learning both weights and connections for efficient neural networks","author":"Han","year":"2015"},{"key":"10.1016\/j.patcog.2026.113908_b38","unstructured":"Yuezun Li, Yiming Li, Baoyuan Wu, Longkang Li, Ran He, Siwei Lyu, Invisible backdoor attack with sample-specific triggers, in: Proceedings of the IEEE\/CVF International Conference on Computer Vision, 2021, pp. 16463\u201316472."}],"container-title":["Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326008733?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326008733?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T14:58:42Z","timestamp":1780930722000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0031320326008733"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,12]]},"references-count":38,"alternative-id":["S0031320326008733"],"URL":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113908","relation":{},"ISSN":["0031-3203"],"issn-type":[{"value":"0031-3203","type":"print"}],"subject":[],"published":{"date-parts":[[2026,12]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Regarding general robust-feature as trigger: A transferable backdoor attack against black-box models","name":"articletitle","label":"Article Title"},{"value":"Pattern Recognition","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113908","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"113908"}}