{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,24]],"date-time":"2026-02-24T08:54:19Z","timestamp":1771923259586,"version":"3.50.1"},"reference-count":60,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccvw69036.2025.00621","type":"proceedings-article","created":{"date-parts":[[2026,2,23]],"date-time":"2026-02-23T20:44:02Z","timestamp":1771879442000},"page":"5962-5972","source":"Crossref","is-referenced-by-count":0,"title":["TAIGen: Training-Free Adversarial Image Generation via Diffusion Models"],"prefix":"10.1109","author":[{"given":"Susim","family":"Roy","sequence":"first","affiliation":[{"name":"University at Buffalo"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anubhooti","family":"Jain","sequence":"additional","affiliation":[{"name":"IIT Jodhpur"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mayank","family":"Vatsa","sequence":"additional","affiliation":[{"name":"IIT Jodhpur"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Richa","family":"Singh","sequence":"additional","affiliation":[{"name":"IIT Jodhpur"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2018.8698548"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3051529"},{"key":"ref3","author":"Ahn","year":"2024","journal-title":"A noise is worth diffusion guidance"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref5","author":"Blau","year":"2022","journal-title":"Threat model-agnostic adversarial de-fense using diffusion models"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3361474"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01475"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00421"},{"key":"ref10","article-title":"Content-based unrestricted adversarial attack","volume-title":"Proceedings of the 37th International Conference on Neural Information Processing Systems","author":"Chen"},{"key":"ref11","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proceedings of the 37th International Conference on Machine Learning","author":"Croce"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3261988"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72952-2_6"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref15","first-page":"8780","article-title":"Diffusion models beat gans on image synthesis","volume-title":"NeurIPS","author":"Dhariwal","year":"2021"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref17","author":"Engstrom","year":"2019","journal-title":"Robustness (python library)"},{"key":"ref18","article-title":"Explaining and harnessing adversarial examples","volume-title":"3rd In-ternational Conference on Learning Representations, ICLR","author":"Goodfellow"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.12341"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref21","article-title":"Stochastic security: Adversarial defense using long-run dy-namics of energy-based models","volume-title":"9th International Conference on Learning Representations, ICLR 2021","author":"Hill"},{"key":"ref22","article-title":"Denoising diffusion probabilistic models","volume-title":"Proceedings of the 34th International Conference on Neural Information Processing Systems","author":"Ho"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00686"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00140"},{"key":"ref25","author":"Iandola","year":"2016","journal-title":"Squeezenet: Alexnet-level accuracy with 50x fewer parameters and <0.5mb model size"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/wacv57701.2024.00507"},{"key":"ref27","article-title":"Diffattack: Evasion attacks against diffusion-based adversarial purification","author":"Kang","year":"2023","journal-title":"NeurIPS"},{"key":"ref28","article-title":"Progressive growing of gans for improved quality, stability, and variation","author":"Karras","year":"2017","journal-title":"CoRR, abs\/1710.10196"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00014"},{"key":"ref30","first-page":"32","author":"Krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images"},{"key":"ref31","article-title":"Diffusion models already have a semantic latent space","volume-title":"The Eleventh International Conference on Learning Representations","author":"Kwon"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01971"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i4.28147"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i13.29323"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_8"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref37","article-title":"When adversarial training meets vision trans-formers: Recipes from training to architecture","author":"Mo","year":"2022","journal-title":"NeurIPS"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-25056-9_30"},{"key":"ref39","first-page":"16805","article-title":"Diffusion models for adversarial purification","volume-title":"ICML","author":"Nie","year":"2022"},{"key":"ref40","article-title":"Diffusion models for adversarial purification","volume-title":"International Conference on Machine Learning (ICML)","author":"Nie"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01542"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref43","article-title":"Do adversarially robust im-agenet models transfer better?","author":"Salman","year":"2020","journal-title":"CoRR, abs\/2007.08489"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00123"},{"key":"ref46","article-title":"Very deep convo-lutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"CoRR, abs\/1409.1556"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52733.2024.02329"},{"key":"ref48","first-page":"8322","article-title":"Constructing unrestricted adversarial examples with generative models","author":"Song","year":"2018","journal-title":"NeurIPS"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/488"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02321"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref52","author":"Tan","year":"2019","journal-title":"Efficientnet: Rethinking model scaling for convolutional neural networks"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00293"},{"key":"ref54","first-page":"5032","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","volume-title":"Proceedings of the 35th International Conference on Machine Learning, ICML 2018","author":"Uesato"},{"key":"ref55","article-title":"AT-GAN: A generative attack model for adversarial transferring on gen-erative adversarial nets","author":"Wang","year":"2019","journal-title":"CoRR, abs\/1904.07793"},{"key":"ref56","article-title":"Diffusion-based adversarial sample generation for improved stealthiness and controllability","author":"Xue","year":"2023","journal-title":"NeurIPS"},{"key":"ref57","first-page":"12062","article-title":"Adversarial purification with score-based generative models","volume-title":"Proceedings of the 38th International Conference on Machine Learning, ICML 2021","author":"Yoon"},{"key":"ref58","article-title":"Wide residual net-works","author":"Zagoruyko","year":"2016","journal-title":"BMVC"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/iccv48922.2021.00778"},{"key":"ref60","article-title":"Boundary guided learning-free semantic control with diffusion models","volume-title":"Conference on Neural Information Processing Systems (NeurIPS)","author":"Zhu"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision Workshops (ICCVW)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,20]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision Workshops (ICCVW)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11373940\/11374285\/11375602.pdf?arnumber=11375602","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,24]],"date-time":"2026-02-24T07:49:43Z","timestamp":1771919383000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11375602\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":60,"URL":"https:\/\/doi.org\/10.1109\/iccvw69036.2025.00621","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}