{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T20:13:55Z","timestamp":1778184835606,"version":"3.51.4"},"reference-count":57,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2024YFB3108100"],"award-info":[{"award-number":["2024YFB3108100"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62476250"],"award-info":[{"award-number":["62476250"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472335"],"award-info":[{"award-number":["62472335"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372137"],"award-info":[{"award-number":["62372137"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21A20463"],"award-info":[{"award-number":["U21A20463"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62506339"],"award-info":[{"award-number":["62506339"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Zhejiang Provincial Natural Science Foundation of China","award":["LQN25F010018"],"award-info":[{"award-number":["LQN25F010018"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Circuits Syst. Video Technol."],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1109\/tcsvt.2025.3642704","type":"journal-article","created":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T18:34:28Z","timestamp":1765391668000},"page":"6258-6272","source":"Crossref","is-referenced-by-count":0,"title":["RPA: Recursive Perturbation-Based Universal Adversarial Attacks on Multimodal Generative Tasks"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4056-9755","authenticated-orcid":false,"given":"Yaguan","family":"Qian","sequence":"first","affiliation":[{"name":"School of Artificial Intelligence and Information Engineering, Zhejiang University of Science and Technology, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-8797-1059","authenticated-orcid":false,"given":"Zhihao","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence and Information Engineering, Zhejiang University of Science and Technology, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1703-6090","authenticated-orcid":false,"given":"Qiqi","family":"Bao","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence and Information Engineering, Zhejiang University of Science and Technology, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7757-0659","authenticated-orcid":false,"given":"Chang","family":"Zong","sequence":"additional","affiliation":[{"name":"School of Information and Electronic Engineering and Technology, Zhejiang University of Science and Technology, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8970-6269","authenticated-orcid":false,"given":"Fei","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Information and Electronic Engineering, Liaoning University of Technology, Anshan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bin","family":"Wang","sequence":"additional","affiliation":[{"name":"Zhejiang Key Laboratory of Artificial Intelligence of Things (AIoT) Network and Data Security, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7546-852X","authenticated-orcid":false,"given":"Zhaoquan","family":"Gu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0791-189X","authenticated-orcid":false,"given":"Zhen","family":"Lei","sequence":"additional","affiliation":[{"name":"Center for Biometrics and Security Research, National Laboratory of Pattern Recognition, Institute of Automation, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"12888","article-title":"BLIP: Bootstrapping language-image pre-training for unified vision-language understanding and generation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref2","first-page":"25994","article-title":"Multi-grained vision language pre-training: Aligning texts with visual concepts","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zeng"},{"key":"ref3","first-page":"19730","article-title":"BLIP-2: Bootstrapping language-image pre-training with frozen image encoders and large language models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2142"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2024.3460172"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72998-0_25"},{"issue":"1","key":"ref7","first-page":"1","article-title":"On evaluating adversarial robustness of large vision-language models","volume":"36","author":"Zhao","year":"2024","journal-title":"J. Mach. Learn. Res."},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3430508"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2023.3299278"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3226905"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3653021"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i7.28499"},{"key":"ref13","first-page":"23701","article-title":"An image is worth 1000 lies: Transferability of adversarial images across prompts on vision-language models","volume-title":"Proc. 12th Int. Conf. Learn. Represent. (ICLR)","volume":"2024","author":"Luo"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2024.3510735"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2024.3502693"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref17","article-title":"Doubly-universal adversarial perturbations: Deceiving vision-language models across both images and text with a single perturbation","author":"Kim","year":"2024","journal-title":"arXiv:2412.08108"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3626772.3657781"},{"key":"ref19","article-title":"One perturbation is enough: On generating universal adversarial perturbations against vision-language pre-training models","author":"Fang","year":"2024","journal-title":"arXiv:2406.05491"},{"key":"ref20","article-title":"Efficient and effective universal adversarial attack against vision-language pre-training models","author":"Yang","year":"2024","journal-title":"arXiv:2410.11639"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1516"},{"key":"ref22","article-title":"MiniGPT-4: Enhancing vision-language understanding with advanced large language models","volume-title":"Proc. 12th Int. Conf. Learn. Represent.","author":"Zhu"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3547801"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00016"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00102"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3402179"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612454"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3686835"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49660.2025.10890418"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2025.3525725"},{"key":"ref31","first-page":"1","article-title":"X-transfer attacks: Towards super transferable adversarial attacks on CLIP","volume-title":"Proc. ICML","author":"Huang"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2025.3546702"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2023.3263054"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-016-0965-7"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00904"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.670"},{"key":"ref39","first-page":"311","article-title":"Bleu: A method for automatic evaluation of machine translation","volume-title":"Proc. 40th Annu. Meeting Assoc. Comput. Linguistics","author":"Papineni"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7299087"},{"key":"ref41","first-page":"65","article-title":"METEOR: An automatic metric for MT evaluation with improved correlation with human judgments","volume-title":"Proc. ACL Workshop Intrinsic Extrinsic Eval. Measures Mach. Transl. Summarization","author":"Banerjee"},{"key":"ref42","first-page":"74","article-title":"ROUGE: A package for automatic evaluation of summaries","volume-title":"Proc. Workshop Text Summarization Branches Out","author":"Lin"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46454-1_24"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1108\/00220410410560582"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1810.04805"},{"key":"ref46","first-page":"24185","article-title":"InternVL: Scaling up vision foundation models and aligning for generic visual-linguistic tasks","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit.","author":"Chen"},{"key":"ref47","article-title":"Otter: A multi-modal model with in-context instruction tuning","author":"Li","year":"2023","journal-title":"arxiv: 305.03726"},{"key":"ref48","article-title":"Pandagpt: One model to instruction-follow them all","author":"Su","year":"2023","journal-title":"arXiv:2305.16355"},{"key":"ref49","article-title":"Qwen-VL: A frontier large vision-language model with versatile abilities","author":"Bai","year":"2023","journal-title":"arXiv:2308.12966"},{"key":"ref50","first-page":"1","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. 6th Int. Conf. Learn. Represent.","author":"Guo"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref52","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref53","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref54","first-page":"21480","article-title":"When does contrastive learning preserve adversarial robustness from pretraining to finetuning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Fan"},{"key":"ref55","article-title":"Diffusion models for adversarial purification","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Nie"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.3390\/s25175261"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"}],"container-title":["IEEE Transactions on Circuits and Systems for Video Technology"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/76\/11511351\/11296917.pdf?arnumber=11296917","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,7]],"date-time":"2026-05-07T19:56:34Z","timestamp":1778183794000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11296917\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":57,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tcsvt.2025.3642704","relation":{},"ISSN":["1051-8215","1558-2205"],"issn-type":[{"value":"1051-8215","type":"print"},{"value":"1558-2205","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5]]}}}