{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T14:19:36Z","timestamp":1766067576604,"version":"3.37.3"},"reference-count":51,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2022,5,1]],"date-time":"2022-05-01T00:00:00Z","timestamp":1651363200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,5]]},"DOI":"10.1109\/sp46214.2022.9833783","type":"proceedings-article","created":{"date-parts":[[2022,7,27]],"date-time":"2022-07-27T19:28:05Z","timestamp":1658950085000},"page":"1423-1439","source":"Crossref","is-referenced-by-count":10,"title":["Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision Settings"],"prefix":"10.1109","author":[{"given":"Yuhao","family":"Mao","sequence":"first","affiliation":[{"name":"Zhejiang University"}]},{"given":"Chong","family":"Fu","sequence":"additional","affiliation":[{"name":"Zhejiang University"}]},{"given":"Saizhuo","family":"Wang","sequence":"additional","affiliation":[{"name":"Zhejiang University"}]},{"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"Zhejiang University"}]},{"given":"Xuhong","family":"Zhang","sequence":"additional","affiliation":[{"name":"Zhejiang University"}]},{"given":"Zhenguang","family":"Liu","sequence":"additional","affiliation":[{"name":"Zhejiang Gongshang University"}]},{"given":"Jun","family":"Zhou","sequence":"additional","affiliation":[{"name":"Ant Group"}]},{"given":"Alex X.","family":"Liu","sequence":"additional","affiliation":[{"name":"Ant Group"}]},{"given":"Raheem","family":"Beyah","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology"}]},{"given":"Ting","family":"Wang","sequence":"additional","affiliation":[{"name":"Pennsylvania State University"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref15","first-page":"321","article-title":"Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning Attacks","author":"demontis","year":"2019","journal-title":"28th USENIX Security Symposium (USENIX Security 19)"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3033291"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1111\/j.2517-6161.1964.tb00553.x"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1146\/annurev-conmatphys-031119-050745"},{"key":"ref17","first-page":"4171","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","volume":"1","author":"devlin","year":"2019","journal-title":"In Proceedings of the 2019 Conference of the North American Chapter of the Association for Computational Linguistics Human Language Technologies"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref19","article-title":"Explaining and Harnessing Adversarial Examples","author":"goodfellow","year":"2015","journal-title":"In International Conference on Learning Representations"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2014.2359646"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TCI.2016.2644865"},{"key":"ref50","first-page":"5753","article-title":"Xlnet: Generalized autoregressive pretraining for language understanding","author":"yang","year":"2019","journal-title":"in Advances in Neural Information Processing Systems 32"},{"key":"ref46","article-title":"Ensemble Adversarial Training: Attacks and Defenses","author":"tram\u00e8","year":"2018","journal-title":"In 6th International Conference on Learning Representations ICLR 2018"},{"key":"ref45","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tram\u00e8","year":"2018","journal-title":"6th International Conference on Learning Representations ICLR 2018"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.2307\/3001968"},{"journal-title":"Attention is all you need","year":"2017","author":"vaswani","key":"ref47"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref44","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"In International Conference on Learning Representations"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref49","first-page":"arxiv: 1802.09707","article-title":"Understanding and Enhancing the Transferability of Adversarial Examples","author":"wu","year":"2018","journal-title":"arXiv 1802 09707 [cs stat]"},{"journal-title":"PyTorch","year":"0","key":"ref8"},{"journal-title":"Google Open Images","year":"0","key":"ref7"},{"key":"ref9","first-page":"43z","volume":"t23","year":"2020","journal-title":"Pytorch\/vision"},{"journal-title":"Baidu CloudDisk","year":"0","key":"ref4"},{"journal-title":"AWS Rekognition documentation","year":"0","key":"ref3"},{"journal-title":"Google cloud vision","year":"0","key":"ref6"},{"journal-title":"Definition of additively separable functions","year":"0","key":"ref5"},{"key":"ref40","first-page":"arxiv: 1409.1556","article-title":"Very Deep Convolutional Networks for Large-Scale Image Recognition","author":"simonyan","year":"2015","journal-title":"arXiv 1409 1556"},{"key":"ref35","article-title":"TROJANZOO: everything you ever wanted to know about neural backdoors (but were afraid to ask)","author":"pang","year":"2020","journal-title":"CoRR abs\/2012 09302"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403241"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref36","article-title":"Transferability in machine learning: from phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016","journal-title":"arXiv preprint arXiv 1605 07761"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref30","article-title":"Towards Deep Learning Models Resistant to Adversarial Attacks","author":"madry","year":"2018","journal-title":"In 6th International Conference on Learning Representations ICLR 2018"},{"key":"ref33","article-title":"On the security risks of automl","author":"pang","year":"2021","journal-title":"CoRR abs\/2110 06018"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"journal-title":"AWS rekognition","year":"0","key":"ref2"},{"journal-title":"Alibaba cloud","year":"0","key":"ref1"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485370"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref24","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"In 5th International Conference on Learning Representations ICLR 2017"},{"journal-title":"Adversarial machine learning at scale","year":"2016","author":"kurakin","key":"ref23"},{"key":"ref26","article-title":"Seeing is living? rethinking the security of facial liveness verification in the deepfake era","author":"li","year":"2022","journal-title":"CoRR abs\/2202 10673"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"journal-title":"Learning multiple layers of features from tiny images","year":"0","author":"krizhevsky","key":"ref22"},{"key":"ref21","first-page":"arxiv: 1804.08598","article-title":"Black-box Adversarial Attacks with Limited Queries and Information","author":"ilyas","year":"2018","journal-title":"ICMLC 2018"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00023"},{"key":"ref27","first-page":"1933","article-title":"Adversarial examples versus cloud-based detectors: A black-box empirical study","volume":"18","author":"li","year":"2021","journal-title":"IEEE Trans Dependable Secur Comput"},{"key":"ref29","article-title":"Delving into Transferable Adversarial Examples and Black-box Attacks","author":"liu","year":"2017","journal-title":"In 5th International Conference on Learning Representations ICLR 2017"}],"event":{"name":"2022 IEEE Symposium on Security and Privacy (SP)","start":{"date-parts":[[2022,5,22]]},"location":"San Francisco, CA, USA","end":{"date-parts":[[2022,5,26]]}},"container-title":["2022 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9833550\/9833558\/09833783.pdf?arnumber=9833783","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,8]],"date-time":"2023-11-08T23:27:44Z","timestamp":1699486064000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9833783\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/sp46214.2022.9833783","relation":{},"subject":[],"published":{"date-parts":[[2022,5]]}}}