{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T17:25:22Z","timestamp":1763227522822,"version":"3.40.4"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272020","U20B2069","SKLSDE2023ZX-16"],"award-info":[{"award-number":["62272020","U20B2069","SKLSDE2023ZX-16"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003787","name":"Natural Science Foundation of Hebei Province","doi-asserted-by":"publisher","award":["F2024202047"],"award-info":[{"award-number":["F2024202047"]}],"id":[{"id":"10.13039\/501100003787","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Fundamental Research Funds for Central Universities"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Signal Process. Lett."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/lsp.2025.3553791","type":"journal-article","created":{"date-parts":[[2025,3,22]],"date-time":"2025-03-22T00:56:52Z","timestamp":1742605012000},"page":"1550-1554","source":"Crossref","is-referenced-by-count":0,"title":["Vector Quantization Based Query-Efficient Attack via Direct Preference Optimization"],"prefix":"10.1109","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2836-8005","authenticated-orcid":false,"given":"Ruijie","family":"Yang","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Beihang University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4592-8083","authenticated-orcid":false,"given":"Yuanfang","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Beihang University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1437-9573","authenticated-orcid":false,"given":"Chao","family":"Zhou","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Beihang University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-1016-5528","authenticated-orcid":false,"given":"Guohao","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Beihang University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8001-2703","authenticated-orcid":false,"given":"Yunhong","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Beihang University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"19730","article-title":"Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li","year":"2023"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2024.3358696"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2024.3509335"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2022.3208417"},{"key":"ref5","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1002\/stvr.1848"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i6.28365"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00425"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i2.25362"},{"key":"ref15","article-title":"Black-box adversarial attack with transferable model-based embedding","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Huang","year":"2020"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i4.28156"},{"key":"ref17","first-page":"3866","article-title":"NATTACK: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"97","author":"Li","year":"2019"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2021.3111820"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2022.3229558"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58517-4_15"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2022.3226118"},{"key":"ref23","article-title":"ILA-DA: Improving transferability of intermediate level attack with data augmentation","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Yan","year":"2023"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2024.3383797"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01467"},{"key":"ref26","first-page":"53728","article-title":"Direct preference optimization: Your language model is secretly a reward model","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Rafailov","year":"2023"},{"key":"ref27","article-title":"Attacking deep networks with surrogate-based adversarial black-box methods is easy","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Lord","year":"2022"},{"key":"ref28","first-page":"6309","article-title":"Neural discrete representation learning","volume-title":"Proc. 31st Int. Conf. Conf. Neural Inf. Process. Syst.","author":"Oord","year":"2017"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref30","article-title":"The curious case of neural text degeneration","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Holtzman","year":"2020"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref33","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Simonyan","year":"2015"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"article-title":"SqueezeNet: Alexnet-level accuracy with 50x fewer parameters and <0.5 mb model size","year":"2016","author":"Iandola","key":"ref35"},{"key":"ref36","first-page":"4536","article-title":"Diversity can be transferred: Output diversification for white-and black-box attacks","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","volume":"33","author":"Tashiro","year":"2020"},{"key":"ref37","first-page":"10934","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. 33rd Int. Conf. Conf. Neural Inf. Process. Syst.","author":"Cheng","year":"2019"},{"key":"ref38","first-page":"5348","article-title":"Blackbox attacks via surrogate ensemble search","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Cai","year":"2022"}],"container-title":["IEEE Signal Processing Letters"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/97\/10802935\/10937111.pdf?arnumber=10937111","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,18]],"date-time":"2025-04-18T04:48:25Z","timestamp":1744951705000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10937111\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/lsp.2025.3553791","relation":{},"ISSN":["1070-9908","1558-2361"],"issn-type":[{"type":"print","value":"1070-9908"},{"type":"electronic","value":"1558-2361"}],"subject":[],"published":{"date-parts":[[2025]]}}}