{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T23:19:41Z","timestamp":1768519181889,"version":"3.49.0"},"reference-count":30,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,12,14]],"date-time":"2025-12-14T00:00:00Z","timestamp":1765670400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,14]],"date-time":"2025-12-14T00:00:00Z","timestamp":1765670400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,12,14]]},"DOI":"10.1109\/icpads67057.2025.11322888","type":"proceedings-article","created":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T20:36:54Z","timestamp":1768423014000},"page":"01-10","source":"Crossref","is-referenced-by-count":0,"title":["A Universal and Dynamically Aware Multi-Attack Adversarial Patch Generation Framework"],"prefix":"10.1109","author":[{"given":"Yiwen","family":"Wang","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering (School of Cyber Security), University of Electronic Science and Technology of China,Chengdu,China"}]},{"given":"Sheng","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (School of Cyber Security), University of Electronic Science and Technology of China,Chengdu,China"}]},{"given":"Xiaosong","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering (School of Cyber Security), University of Electronic Science and Technology of China,Chengdu,China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01101"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1049\/cit2.12028"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1049\/cit2.12028"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.3390\/bioengineering10020194"},{"key":"ref5","first-page":"arXiv","article-title":"Comprehensive assessment of jailbreak attacks against 11 ms","author":"Chu","year":"2024","journal-title":"arXiv e-prints"},{"key":"ref6","article-title":"Prompt injection attack against llm-integrated applications","author":"Liu","year":"2023","journal-title":"arXiv preprint"},{"key":"ref7","article-title":"Certified defenses for data poisoning attacks","volume":"30","author":"Steinhardt","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref8","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML). PMLR","author":"Radford","year":"2021"},{"key":"ref9","first-page":"4904","article-title":"Scaling up visual and vision-language representation learning with noisy text supervision","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML). PMLR","author":"Jia","year":"2021"},{"key":"ref10","first-page":"23716","article-title":"Flamingo: a visual language model for few-shot learning","volume":"35","author":"Alayrac","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref11","first-page":"1288812900","article-title":"BLIP: Bootstrapping language-image pre-training for unified vision-language understanding and generation","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML). PMLR","author":"Li","year":"2022"},{"key":"ref12","author":"Chen","year":"2025","journal-title":"Janus-Pro: Unified multimodal understanding and generation with data and model scaling"},{"key":"ref13","author":"Bai","year":"2025","journal-title":"Qwen2.5-VL technical report"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612454"},{"key":"ref15","author":"Luo","year":"2024","journal-title":"An image is worth 1000 lies: Adversarial transferability across prompts on vision-language models"},{"key":"ref16","author":"Ma","year":"2024","journal-title":"Visual-RolePlay: Universal jailbreak attack on multimodal large language models via role-playing image character"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i22.34568"},{"key":"ref18","author":"Chen","year":"2023","journal-title":"Can language models be instructed to protect personal information?"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.198"},{"key":"ref20","author":"Lu","year":"2024","journal-title":"Test-time backdoor attacks on multimodal large language models"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D17-1323"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2024.3520306"},{"key":"ref23","author":"Luo","year":"2024","journal-title":"JailbreakV: A benchmark for assessing the robustness of multimodal large language models against jailbreak attacks"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref25","article-title":"Adversarial training for free!","volume":"32","author":"Shafahi","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref26","author":"Touvron","year":"2023","journal-title":"LLaMA: Open and efficient foundation language models"},{"key":"ref27","article-title":"Certified adversarial robustness with additive noise","volume":"32","author":"Li","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-023-10631-z"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2024.findings-acl.178"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/591"}],"event":{"name":"2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)","location":"Hefei, China","start":{"date-parts":[[2025,12,14]]},"end":{"date-parts":[[2025,12,18]]}},"container-title":["2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11322805\/11322871\/11322888.pdf?arnumber=11322888","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,15]],"date-time":"2026-01-15T07:28:26Z","timestamp":1768462106000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11322888\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,14]]},"references-count":30,"URL":"https:\/\/doi.org\/10.1109\/icpads67057.2025.11322888","relation":{},"subject":[],"published":{"date-parts":[[2025,12,14]]}}}