{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:43:03Z","timestamp":1763192583604,"version":"3.45.0"},"reference-count":59,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1109\/ijcnn64981.2025.11228300","type":"proceedings-article","created":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T18:46:15Z","timestamp":1763145975000},"page":"1-9","source":"Crossref","is-referenced-by-count":0,"title":["Cascade Adversarial Attack Search"],"prefix":"10.1109","author":[{"given":"Ziwen","family":"Wang","sequence":"first","affiliation":[{"name":"Anhui University,School of Computer Science and Technology,China"}]},{"given":"Daoli","family":"Shen","sequence":"additional","affiliation":[{"name":"Anhui University,School of Electrical Engineering and Automation,China"}]},{"given":"Xiangkun","family":"Sun","sequence":"additional","affiliation":[{"name":"Anhui University,School of Computer Science and Technology,China"}]},{"given":"Shangshang","family":"Yang","sequence":"additional","affiliation":[{"name":"Anhui University,School of Artificial Intelligence,China"}]},{"given":"Xiaoshan","family":"Yu","sequence":"additional","affiliation":[{"name":"Anhui University,School of Artificial Intelligence,China"}]},{"given":"Ye","family":"Tian","sequence":"additional","affiliation":[{"name":"Anhui University,School of Computer Science and Technology,China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"article-title":"Deep learning: Technical introduction","year":"2017","author":"Epelbaum","key":"ref2"},{"article-title":"Intriguing properties of neural networks","year":"2013","author":"Szegedy","key":"ref3"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"Goodfellow","key":"ref4"},{"article-title":"Unsolved problems in ml safety","year":"2021","author":"Hendrycks","key":"ref5"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1126\/science.adn0117"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1155\/2021\/4907754"},{"article-title":"Adversarial attacks and defences: A survey","year":"2018","author":"Chakraborty","key":"ref8"},{"article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","year":"2019","author":"Lin","key":"ref9"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3637528.3671711"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3615287"},{"key":"ref14","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"International conference on machine learning","author":"Ilyas"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"article-title":"Technical report on the cleverhans v2. 1.0 adversarial examples library","year":"2016","author":"Papernot","key":"ref16"},{"article-title":"Foolbox: A python toolbox to benchmark the robustness of machine learning models","year":"2017","author":"Rauber","key":"ref17"},{"article-title":"Advertorch v0. 1: An adversarial robustness toolbox based on pytorch","year":"2019","author":"Ding","key":"ref18"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2023.126465"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140449"},{"article-title":"Adversarial attacks on neural network policies","year":"2017","author":"Huang","key":"ref21"},{"article-title":"Towards deep learning models resistant to adversarial attacks","year":"2017","author":"Madry","key":"ref22"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00445"},{"key":"ref27","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"International conference on machine learning","author":"Croce"},{"article-title":"Adversarial machine learning at scale","year":"2016","author":"Kurakin","key":"ref28"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00930"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2020.106622"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2024.3429180"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.110052"},{"key":"ref35","first-page":"19 520","article-title":"Evolutionary neural architecture search for transformer in knowledge tracing","volume":"36","author":"Yang","year":"2023","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3638529.3654017"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3061630"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3349497"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TETCI.2024.3400867"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2487575.2487629"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/2908812.2908918"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330648"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05318-5_6"},{"article-title":"Performance evaluation of adversarial attacks: Discrepancies and solutions","year":"2021","author":"Wu","key":"ref44"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-022-33266-0"},{"key":"ref46","first-page":"8588","article-title":"A closer look at accuracy vs. robustness","volume":"33","author":"Yang","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref47","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009","journal-title":"Tech. Rep."},{"article-title":"Very deep convolutional networks for large-scale image recognition","year":"2014","author":"Simonyan","key":"ref48"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"article-title":"Mobilenets: Efficient convolutional neural networks for mobile vision applications","year":"2017","author":"Howard","key":"ref51"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.4324\/9781410605337-29"},{"key":"ref54","first-page":"6105","article-title":"Efficientnet: Rethinking model scaling for convolutional neural networks","volume-title":"International conference on machine learning","author":"Tan"},{"article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","year":"2019","author":"Lin","key":"ref55"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref58","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"International conference on machine learning","author":"Zhang"},{"key":"ref59","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"International conference on machine learning","author":"Croce"}],"event":{"name":"2025 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2025,6,30]]},"location":"Rome, Italy","end":{"date-parts":[[2025,7,5]]}},"container-title":["2025 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11227166\/11227148\/11228300.pdf?arnumber=11228300","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T07:39:06Z","timestamp":1763192346000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11228300\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":59,"URL":"https:\/\/doi.org\/10.1109\/ijcnn64981.2025.11228300","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]}}}