{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,8]],"date-time":"2026-02-08T05:32:41Z","timestamp":1770528761510,"version":"3.49.0"},"reference-count":28,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,7,18]],"date-time":"2022-07-18T00:00:00Z","timestamp":1658102400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,7,18]],"date-time":"2022-07-18T00:00:00Z","timestamp":1658102400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"publisher","award":["2020AAA0107701"],"award-info":[{"award-number":["2020AAA0107701"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"publisher","award":["U20B2049,U21B2018,62161160337,62132011"],"award-info":[{"award-number":["U20B2049,U21B2018,62161160337,62132011"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,7,18]]},"DOI":"10.1109\/icme52920.2022.9859856","type":"proceedings-article","created":{"date-parts":[[2022,8,26]],"date-time":"2022-08-26T19:45:18Z","timestamp":1661543118000},"page":"1-6","source":"Crossref","is-referenced-by-count":6,"title":["Towards Black-Box Adversarial Attacks on Interpretable Deep Learning Systems"],"prefix":"10.1109","author":[{"given":"Yike","family":"Zhan","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Baolin","family":"Zheng","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ningping","family":"Mou","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Binqing","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University,Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,Hubei,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qi","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Network Sciences and Cyberspace &#x0026; BNRist, Tsinghua University,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chao","family":"Shen","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Xi&#x0027;an Jiaotong University,Shaanxi,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cong","family":"Wang","sequence":"additional","affiliation":[{"name":"City University of Hong Kong,Departrnent of Computer Science,HK SAR, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","first-page":"1277","article-title":"HopSkipJumpAttack: A query-efficient decision-based attack","author":"jianbo","year":"0","journal-title":"Proc of S&P"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref14","first-page":"6967","article-title":"Real time image saliency for black box classifiers","author":"dabkowski","year":"0","journal-title":"Proc of NeurIPS"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.371"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220027"},{"key":"ref17","first-page":"1659","article-title":"Interpretable deep learning under fire","author":"zhang","year":"0","journal-title":"Proc of USENIX Security"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013681"},{"key":"ref19","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","author":"ilyas","year":"0","journal-title":"Proc of ICLR"},{"key":"ref28","first-page":"1014","article-title":"Proper network interpretability helps adversarial robustness in classification","author":"boopathy","year":"0","journal-title":"Proc of ICML"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"christian","year":"0","journal-title":"Proc of ICLR"},{"key":"ref27","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"Proc of ICLR"},{"key":"ref3","article-title":"An empirical evaluation of deep learning on highway driving","author":"huval","year":"2015","journal-title":"CoRR"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref5","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","author":"ilyas","year":"0","journal-title":"Proc of ICML"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref7","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"0","journal-title":"Proc of ICLR"},{"key":"ref2","first-page":"195","article-title":"Deep Voice: Real-time neural text-to-speech","author":"arik","year":"0","journal-title":"Proc of ICML"},{"key":"ref9","article-title":"Sign-OPT: A query-efficient hard-label adversarial attack","author":"minhao","year":"0","journal-title":"Proc of ICLR"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref20","first-page":"2484","article-title":"Simple black-box adversarial attacks","author":"chuan","year":"0","journal-title":"Proc of ICML"},{"key":"ref22","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"cheng","year":"0","journal-title":"Proc of ICLR"},{"key":"ref21","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"0","journal-title":"Proc of ICLR"},{"key":"ref24","first-page":"1337","article-title":"The convergence of the random search method in the extremal control of a many parameter system","volume":"24","author":"rastrigin","year":"1963","journal-title":"Automation & Remote Control"},{"key":"ref23","first-page":"2921","article-title":"Fooling neural network interpretations via adversarial model manipulation","author":"heo","year":"0","journal-title":"Proc of NeurIPS"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.322"},{"key":"ref25","article-title":"MEAL V2: Boosting vanilla resnet-50 to 80%+ top-1 accuracy on ImageNet without tricks","author":"shen","year":"2020","journal-title":"ArXiv Preprint"}],"event":{"name":"2022 IEEE International Conference on Multimedia and Expo (ICME)","location":"Taipei, Taiwan","start":{"date-parts":[[2022,7,18]]},"end":{"date-parts":[[2022,7,22]]}},"container-title":["2022 IEEE International Conference on Multimedia and Expo (ICME)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9859562\/9858923\/09859856.pdf?arnumber=9859856","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,19]],"date-time":"2022-09-19T20:23:45Z","timestamp":1663619025000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9859856\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,18]]},"references-count":28,"URL":"https:\/\/doi.org\/10.1109\/icme52920.2022.9859856","relation":{},"subject":[],"published":{"date-parts":[[2022,7,18]]}}}