{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T18:22:19Z","timestamp":1772907739057,"version":"3.50.1"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272116"],"award-info":[{"award-number":["62272116"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62302110"],"award-info":[{"award-number":["62302110"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010256","name":"Guangzhou Science and Technology Project","doi-asserted-by":"publisher","award":["2023A03J0114"],"award-info":[{"award-number":["2023A03J0114"]}],"id":[{"id":"10.13039\/501100010256","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010256","name":"Guangzhou Science and Technology Project","doi-asserted-by":"publisher","award":["2023A04J0387"],"award-info":[{"award-number":["2023A04J0387"]}],"id":[{"id":"10.13039\/501100010256","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Circuits Syst. Video Technol."],"published-print":{"date-parts":[[2024,4]]},"DOI":"10.1109\/tcsvt.2023.3307150","type":"journal-article","created":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T18:08:40Z","timestamp":1692641320000},"page":"2289-2303","source":"Crossref","is-referenced-by-count":28,"title":["Cross-Shaped Adversarial Patch Attack"],"prefix":"10.1109","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-7062-9486","authenticated-orcid":false,"given":"Yu","family":"Ran","sequence":"first","affiliation":[{"name":"School of Computer Science and Cyber Engineering, Guangzhou University, Guangzhou, China"}]},{"given":"Weijia","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Information Technology, Deakin University, Waurn Ponds Campus, Geelong, VIC, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3565-1180","authenticated-orcid":false,"given":"Mingjie","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Cyber Engineering, Guangzhou University, Guangzhou, China"}]},{"given":"Lin-Cheng","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Cyber Engineering, Guangzhou University, Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3010-4196","authenticated-orcid":false,"given":"Yuan-Gen","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Cyber Engineering, Guangzhou University, Guangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0385-8793","authenticated-orcid":false,"given":"Jin","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00529"},{"key":"ref3","first-page":"3104","article-title":"Sequence to sequence learning with neural networks","volume-title":"Proc. NeurIPS","volume":"27","author":"Sutskever"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TASLP.2014.2339736"},{"key":"ref5","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. ICLR","author":"Szegedy"},{"key":"ref6","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. ICLR","author":"Goodfellow"},{"key":"ref7","first-page":"1","article-title":"Adversarial examples in the physical world","volume-title":"Proc. ICLR","author":"Kurakin"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.3047084"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1002\/rob.21918"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2015.2406191"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1038\/nature21056"},{"key":"ref13","article-title":"Towards the science of security and privacy in machine learning","author":"Papernot","year":"2016","journal-title":"arXiv:1611.03814"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref16","first-page":"1","article-title":"Certified defenses for adversarial patches","volume-title":"Proc. ICLR","author":"Chiang"},{"key":"ref17","first-page":"2237","article-title":"PatchGuard: A provably robust defense against adversarial patches via small receptive fields and masking","volume-title":"Proc. USS","author":"Xiang"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.3017006"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3536425"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref22","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. ICML","author":"Ilyas"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00482"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref25","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. ICML","author":"Guo"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.137"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58574-7_41"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20595"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428443"},{"key":"ref31","first-page":"1","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. ICLR","author":"Liu"},{"key":"ref32","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","volume-title":"Proc. USS","author":"Demontis"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref34","first-page":"1","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","volume-title":"Proc. ICLR","author":"Brendel"},{"key":"ref35","first-page":"1","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","volume-title":"Proc. ICLR","author":"Cheng"},{"key":"ref36","first-page":"1","article-title":"Sign-OPT: A query-efficient hard-label adversarial attack","volume-title":"Proc. ICLR","author":"Cheng"},{"key":"ref37","first-page":"1","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","volume-title":"Proc. ICLR","author":"Ilyas"},{"key":"ref38","first-page":"1","article-title":"Query-efficient meta attack to deep neural networks","volume-title":"Proc. ICLR","author":"Du"},{"key":"ref39","first-page":"1","article-title":"Adversarial patch","volume-title":"Proc. NeurIPS","author":"Brown"},{"key":"ref40","first-page":"14963","article-title":"Transferable sparse adversarial attack","volume-title":"Proc. CVPR","author":"He"},{"key":"ref41","first-page":"1","article-title":"Imagenet-trained CNNs are biased towards texture; Increasing shape bias improves accuracy and robustness","volume-title":"Proc. ICLR","author":"Geirhos"},{"key":"ref42","first-page":"1","article-title":"Shape-texture debiased neural network training","volume-title":"Proc. ICLR","author":"Li"},{"key":"ref43","first-page":"19000","article-title":"The origins and prevalence of texture bias in convolutional neural networks","volume-title":"Proc. NeurIPS","volume":"33","author":"Hermann"},{"key":"ref44","first-page":"1","article-title":"Shape or texture: Understanding discriminative features in CNNs","volume-title":"Proc. ICLR","author":"Islam"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_31"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref47","first-page":"1","article-title":"Structured adversarial attack: Towards general implementation and better interpretability","volume-title":"Proc. ICLR","author":"Xu"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/s10208-015-9296-2"},{"key":"ref49","first-page":"1","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. NeurIPS","author":"Cheng"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01166"},{"key":"ref51","first-page":"2507","article-title":"LaVAN: Localized and visible adversarial noise","volume-title":"Proc. ICML","author":"Karmon"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3176760"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref56","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref57","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. ICLR","author":"Simonyan"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/1873951.1874254"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref60","article-title":"A study of the effect of JPG compression on adversarial images","author":"Dziugaite","year":"2016","journal-title":"arXiv:1608.00853"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"}],"container-title":["IEEE Transactions on Circuits and Systems for Video Technology"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/76\/10492617\/10225573.pdf?arnumber=10225573","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,9]],"date-time":"2025-01-09T20:11:30Z","timestamp":1736453490000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10225573\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4]]},"references-count":61,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tcsvt.2023.3307150","relation":{},"ISSN":["1051-8215","1558-2205"],"issn-type":[{"value":"1051-8215","type":"print"},{"value":"1558-2205","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4]]}}}