{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T18:37:17Z","timestamp":1775068637986,"version":"3.50.1"},"reference-count":37,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/access.2025.3588113","type":"journal-article","created":{"date-parts":[[2025,7,11]],"date-time":"2025-07-11T17:45:10Z","timestamp":1752255910000},"page":"129185-129194","source":"Crossref","is-referenced-by-count":1,"title":["Perceptual Carlini-Wagner Attack: A Robust and Imperceptible Adversarial Attack Using LPIPS"],"prefix":"10.1109","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-6917-6382","authenticated-orcid":false,"given":"Liming","family":"Fan","sequence":"first","affiliation":[{"name":"Department of Electrical Engineering, Faculty of Engineering, Universiti Malaya, Kuala Lumpur, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9873-4779","authenticated-orcid":false,"given":"Anis Salwa Mohd","family":"Khairuddin","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Faculty of Engineering, Universiti Malaya, Kuala Lumpur, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0559-5552","authenticated-orcid":false,"given":"Haichuan","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Faculty of Engineering, Universiti Malaya, Kuala Lumpur, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0471-3820","authenticated-orcid":false,"given":"Khairunnisa Binti","family":"Hasikin","sequence":"additional","affiliation":[{"name":"Department of Biomedical Engineering, Faculty of Engineering, Universiti Malaya, Kuala Lumpur, Malaysia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref4","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref5","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref6","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01501"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/824"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00112"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref13","article-title":"Towards deep learning models resistant to adversarial attacks","author":"M\u0105dry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00211"},{"key":"ref15","first-page":"6808","article-title":"Wasserstein adversarial examples via projected sinkhorn iterations","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wong"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11499"},{"key":"ref17","article-title":"Perceptually constrained adversarial attacks","author":"Zaid Hameed","year":"2021","journal-title":"arXiv:2102.07140"},{"key":"ref18","article-title":"Perceptual adversarial robustness: Defense against unseen threat models","author":"Laidlaw","year":"2020","journal-title":"arXiv:2006.12655"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.109760"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3367773"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01477"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01488"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359441"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN54540.2023.10191049"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-8565-4_20"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3480519"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00421"},{"key":"ref29","first-page":"1","article-title":"Content-based unrestricted adversarial attack","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72952-2_6"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3483896"},{"key":"ref32","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref34","article-title":"Countering adversarial images using input transformations","author":"Guo","year":"2017","journal-title":"arXiv:1711.00117"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219910"},{"key":"ref36","first-page":"17579","article-title":"Fixing data augmentation to improve adversarial robustness","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR)","author":"Rebuffi"},{"key":"ref37","first-page":"3533","article-title":"Do adversarially robust ImageNet models transfer better","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Salman"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/6287639\/10820123\/11078278.pdf?arnumber=11078278","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,26]],"date-time":"2025-07-26T06:30:59Z","timestamp":1753511459000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11078278\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":37,"URL":"https:\/\/doi.org\/10.1109\/access.2025.3588113","relation":{},"ISSN":["2169-3536"],"issn-type":[{"value":"2169-3536","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}