{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T22:07:32Z","timestamp":1771625252121,"version":"3.50.1"},"reference-count":26,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,5]],"date-time":"2025-10-05T00:00:00Z","timestamp":1759622400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,5]],"date-time":"2025-10-05T00:00:00Z","timestamp":1759622400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,5]]},"DOI":"10.1109\/smc58881.2025.11342475","type":"proceedings-article","created":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T20:54:44Z","timestamp":1769633684000},"page":"1604-1609","source":"Crossref","is-referenced-by-count":0,"title":["Boundary Box-Guided Targeted Adversarial Attacks with Semantic Perturbation"],"prefix":"10.1109","author":[{"given":"Hongtian","family":"Zhao","sequence":"first","affiliation":[{"name":"Xinjiang University,Urumqi,China"}]},{"given":"Wenzhuo","family":"Shi","sequence":"additional","affiliation":[{"name":"Xinjiang University,Urumqi,China"}]},{"given":"Chang","family":"Liu","sequence":"additional","affiliation":[{"name":"Tsinghua University,Beijing,China"}]},{"given":"Yiquan","family":"Wang","sequence":"additional","affiliation":[{"name":"Xinjiang University,Urumqi,China"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. ICLR","author":"Goodfellow"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01453"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02069"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2021.102141"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2024.3378923"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00072"},{"key":"ref9","article-title":"A survey on transferability of adversarial examples across deep neural networks","volume":"2024","author":"Gu","year":"2024","journal-title":"Trans. Mach. Learn. Res"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_42"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"ref13","first-page":"12 885","article-title":"Cross-domain transferability of adversarial perturbations","volume-title":"Proc. NeurIPS","author":"Naseer"},{"key":"ref14","first-page":"14 837","article-title":"Generating diverse high-fidelity images with VQ-VAE-2","volume-title":"Proc. NeurIPS","author":"Razavi"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2019.2918284"},{"key":"ref16","article-title":"Learning multiple layers of features from tiny images","volume-title":"Master\u2019s thesis, Department of Computer Science, University of Toronto","author":"Krizhevsky","year":"2009"},{"key":"ref17","article-title":"Tiny imagenet visual recognition challenge","author":"Le","year":"2015"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref19","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. ICLR","author":"Simonyan"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref22","article-title":"Adv-bnn: Improved adversarial defense through robust bayesian neural network","volume-title":"Proc. ICLR","author":"Liu"},{"key":"ref23","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","volume-title":"Proc. ICML","author":"Croce"},{"key":"ref24","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","volume-title":"Proc. ICLR","author":"Lin"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-023-04532-5"},{"key":"ref26","article-title":"Torchattacks: A pytorch repository for adversarial attacks","author":"Kim","year":"2020"}],"event":{"name":"2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)","location":"Vienna, Austria","start":{"date-parts":[[2025,10,5]]},"end":{"date-parts":[[2025,10,8]]}},"container-title":["2025 IEEE International Conference on Systems, Man, and Cybernetics (SMC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11342430\/11342431\/11342475.pdf?arnumber=11342475","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T21:12:40Z","timestamp":1771621960000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11342475\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,5]]},"references-count":26,"URL":"https:\/\/doi.org\/10.1109\/smc58881.2025.11342475","relation":{},"subject":[],"published":{"date-parts":[[2025,10,5]]}}}