{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T03:09:40Z","timestamp":1777604980591,"version":"3.51.4"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100002873","name":"Chulalongkorn University, AUN\/SEED-Net","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100002873","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001691","name":"Japan Society for the Promotion of Science KAKENHI","doi-asserted-by":"publisher","award":["JP20K23341"],"award-info":[{"award-number":["JP20K23341"]}],"id":[{"id":"10.13039\/501100001691","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/access.2021.3134840","type":"journal-article","created":{"date-parts":[[2021,12,10]],"date-time":"2021-12-10T20:37:07Z","timestamp":1639168627000},"page":"164379-164393","source":"Crossref","is-referenced-by-count":0,"title":["Evolving Architectures With Gradient Misalignment Toward Low Adversarial Transferability"],"prefix":"10.1109","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1838-0251","authenticated-orcid":false,"given":"Kevin Richard G.","family":"Operiano","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1170-2177","authenticated-orcid":false,"given":"Wanchalerm","family":"Pora","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7815-0306","authenticated-orcid":false,"given":"Hitoshi","family":"Iba","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9830-0436","authenticated-orcid":false,"given":"Hiroshi","family":"Kera","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","first-page":"837","article-title":"Towards understanding and improving the transferability of adversarial examples in deep neural networks","author":"wu","year":"2020","journal-title":"Proc Asian Conf Mach Learn"},{"key":"ref38","first-page":"1","article-title":"Skip connections matter: On the transferability of adversarial examples generated with resnets","author":"wu","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref33","article-title":"Deep learning for classical Japanese literature","author":"clanuwat","year":"2018","journal-title":"arXiv 1812 01718"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref31","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref30","article-title":"Monomial-agnostic computation of vanishing ideals","author":"kera","year":"2021","journal-title":"arXiv 2101 00243"},{"key":"ref37","article-title":"SqueezeNet: AlexNet-level accuracy with 50X fewer parameters and < 0.5 MB model size","author":"iandola","year":"2016","journal-title":"arXiv 1602 07360"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref35","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv 1409 1556"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5869"},{"key":"ref27","article-title":"Improving adversarial robustness of ensembles with diversity training","author":"kariyappa","year":"2019","journal-title":"arXiv 1901 09981"},{"key":"ref29","article-title":"Border basis computation with gradient-weighted norm","author":"kera","year":"2021","journal-title":"arXiv 2101 00401"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref1","first-page":"1","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref20","article-title":"Tiny adversarial mulit-objective oneshot neural architecture search","author":"xie","year":"2021","journal-title":"arXiv 2103 00363"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref21","first-page":"1","article-title":"Countering adversarial images using input transformations","author":"guo","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1162\/106365602320169811"},{"key":"ref23","article-title":"Adversarial attacks and defences: A survey","author":"chakraborty","year":"2018","journal-title":"arXiv 1810 00069"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3005961"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2020.2983860"},{"key":"ref50","first-page":"3319","article-title":"Axiomatic attribution for deep networks","author":"sundararajan","year":"2017","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref51","first-page":"1","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref59","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"xiao","year":"2017","journal-title":"ArXiv 1708 07747"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0242535"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TMI.2020.2993291"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1038\/s41524-018-0081-z"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1016\/j.artmed.2016.12.003"},{"key":"ref54","first-page":"8024","article-title":"Pytorch: An imperative style, high-performance deep learning library","author":"paszke","year":"2019","journal-title":"Advances in neural information processing systems"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/s10492-014-0069-z"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2016.2551748"},{"key":"ref10","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","author":"demontis","year":"2019","journal-title":"Proc USENIX Conf Secur Symp"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2015.84"},{"key":"ref11","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8r","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref12","first-page":"1","article-title":"DARTS: Differentiable architecture search","author":"liu","year":"2018","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref13","article-title":"On adversarial robustness: A neural architecture search perspective","author":"devaguptapu","year":"2020","journal-title":"arXiv 2007 08428"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3377929.3389962"},{"key":"ref15","first-page":"3358","article-title":"Adversarial training for free!","author":"shafahi","year":"2019","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref16","first-page":"1","article-title":"Fast is better than free: Revisiting adversarial training","author":"wong","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.111"},{"key":"ref18","first-page":"1","article-title":"Once-for-all: Train one network and specialize it for efficient deployment","author":"cai","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00071"},{"key":"ref4","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2016","journal-title":"arXiv 1611 02770"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref8","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv 1312 6199"},{"key":"ref49","article-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps","author":"simonyan","year":"2013","journal-title":"arXiv 1312 6034"},{"key":"ref7","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016","journal-title":"arXiv 1605 07277"},{"key":"ref9","article-title":"The space of transferable adversarial examples","author":"tram\u00e8r","year":"2017","journal-title":"arXiv 1704 03453"},{"key":"ref46","first-page":"1997","article-title":"Neural architecture search: A survey","volume":"20","author":"elsken","year":"2019","journal-title":"J Mach Learn Res"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33014780"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI47803.2020.9308453"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3071178.3071229"},{"key":"ref42","article-title":"Neural architecture search with reinforcement learning","author":"zoph","year":"2016","journal-title":"arXiv 1611 01578"},{"key":"ref41","first-page":"1","article-title":"Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients","author":"ross","year":"2018","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/B978-0-12-815480-9.00015-3"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00907"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/9312710\/09646964.pdf?arnumber=9646964","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,3,28]],"date-time":"2022-03-28T21:22:48Z","timestamp":1648502568000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9646964\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":59,"URL":"https:\/\/doi.org\/10.1109\/access.2021.3134840","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}