{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T01:16:25Z","timestamp":1783041385704,"version":"3.54.6"},"reference-count":33,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20B2072"],"award-info":[{"award-number":["U20B2072"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61976137"],"award-info":[{"award-number":["61976137"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Signal Process. Lett."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/lsp.2022.3208417","type":"journal-article","created":{"date-parts":[[2022,9,21]],"date-time":"2022-09-21T19:25:53Z","timestamp":1663788353000},"page":"2088-2092","source":"Crossref","is-referenced-by-count":5,"title":["Explore Adversarial Attack via Black Box Variational Inference"],"prefix":"10.1109","volume":"29","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4583-4258","authenticated-orcid":false,"given":"Chenglong","family":"Zhao","sequence":"first","affiliation":[{"name":"Department of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7339-028X","authenticated-orcid":false,"given":"Bingbing","family":"Ni","sequence":"additional","affiliation":[{"name":"Department of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shibin","family":"Mei","sequence":"additional","affiliation":[{"name":"Department of Electronic Information and Electrical Engineering, Shanghai Jiaotong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1021\/ct2009208"},{"key":"ref2","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2015.2421935"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2021.3089908"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref6","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2017"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2019.2922498"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref9","first-page":"1","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","volume-title":"Proc. Int. Con. Learn. Representations","author":"Ilyas","year":"2019"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01240-3_2"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref13","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. Mach. Learn. Res.","author":"Guo","year":"2019"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2021.3111820"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2016.2521441"},{"issue":"1","key":"ref16","first-page":"1303","article-title":"Stochastic variational inference","volume":"14","author":"Hoffman","year":"2013","journal-title":"J. Mach. Learn. Res."},{"issue":"1","key":"ref17","article-title":"Auto-encoding variational bayes","volume":"1050","author":"Kingma","year":"2014","journal-title":"stat"},{"key":"ref18","first-page":"814","article-title":"Black box variational inference","volume-title":"Proc. Artif. Intell. Statist.","author":"Ranganath","year":"2014"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4757-3071-5"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref22","first-page":"10934","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Cheng","year":"2019"},{"key":"ref23","first-page":"3825","article-title":"Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Guo","year":"2019"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3029270"},{"key":"ref25","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas","year":"2018"},{"key":"ref26","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Simonyan","year":"2015"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2016.90"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.195"},{"key":"ref29","first-page":"3866","article-title":"Nattack : Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li","year":"2019"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00348"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00262"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"}],"container-title":["IEEE Signal Processing Letters"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/97\/9686799\/09896950.pdf?arnumber=9896950","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,24]],"date-time":"2024-01-24T02:15:40Z","timestamp":1706062540000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9896950\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":33,"URL":"https:\/\/doi.org\/10.1109\/lsp.2022.3208417","relation":{},"ISSN":["1070-9908","1558-2361"],"issn-type":[{"value":"1070-9908","type":"print"},{"value":"1558-2361","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}