{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T02:36:11Z","timestamp":1778812571707,"version":"3.51.4"},"reference-count":68,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61976165"],"award-info":[{"award-number":["61976165"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Evol. Computat."],"published-print":{"date-parts":[[2022,10]]},"DOI":"10.1109\/tevc.2022.3151373","type":"journal-article","created":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T20:48:54Z","timestamp":1644958134000},"page":"976-990","source":"Crossref","is-referenced-by-count":52,"title":["An Approximated Gradient Sign Method Using Differential Evolution for Black-Box Adversarial Attack"],"prefix":"10.1109","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2391-7319","authenticated-orcid":false,"given":"Chao","family":"Li","sequence":"first","affiliation":[{"name":"School of Artificial Intelligence, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4805-3780","authenticated-orcid":false,"given":"Handing","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence and the Collaborative Innovation Center of Quantum Information of Shaanxi Province, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9424-7028","authenticated-orcid":false,"given":"Jun","family":"Zhang","sequence":"additional","affiliation":[{"name":"Defense Innovation Institute, Chinese Academy of Military Science, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5224-9834","authenticated-orcid":false,"given":"Wen","family":"Yao","sequence":"additional","affiliation":[{"name":"Defense Innovation Institute, Chinese Academy of Military Science, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tingsong","family":"Jiang","sequence":"additional","affiliation":[{"name":"Defense Innovation Institute, Chinese Academy of Military Science, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2017.01.019"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIM.2020.2984465"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2020.03.025"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2019.107164"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.swevo.2019.05.010"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2916183"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref8","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2017.94"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref14","article-title":"Towards the science of security and privacy in machine learning","author":"Papernot","year":"2016","journal-title":"arXiv:1611.03814"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CEC.2019.8790213"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3351088"},{"key":"ref17","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref21","first-page":"3825","article-title":"Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks","volume-title":"Advances in Neural Information Processing Systems","author":"Guo","year":"2019"},{"key":"ref22","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","author":"Ilyas","year":"2018","journal-title":"arXiv:1807.07978"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref24","article-title":"Query-efficient meta attack to deep neural networks","author":"Du","year":"2019","journal-title":"arXiv:1906.02398"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.swevo.2019.100631"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-55849-3_41"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2014.2322602"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2010.2059031"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/2791291"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref33","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref36","first-page":"6808","article-title":"Wasserstein adversarial examples via projected sinkhorn iterations","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wong"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref39","article-title":"Skip connections matter: On the transferability of adversarial examples generated with ResNets","author":"Wu","year":"2020","journal-title":"arXiv:2002.05990"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3033291"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref42","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref43","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017","journal-title":"arXiv:1712.04248"},{"key":"ref44","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"Cheng","year":"2018","journal-title":"arXiv:1807.04457"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref46","article-title":"Understanding the one-pixel attack: Propagation maps and locality analysis","author":"Vargas","year":"2019","journal-title":"arXiv:1902.02947"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-34062-8_69"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1016\/j.chemolab.2013.07.004"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1016\/j.cie.2015.04.012"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/3PGCIC.2014.43"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/EMS.2008.64"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2011.09.001"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/LGRS.2014.2306263"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TAP.2014.2341293"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/LGRS.2013.2285476"},{"key":"ref56","article-title":"Evolving robust neural architectures to defend from adversarial attacks","author":"Vargas","year":"2019","journal-title":"arXiv:1906.11667"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2948146"},{"key":"ref58","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref60","article-title":"Striving for simplicity: The all convolutional net","author":"Springenberg","year":"2014","journal-title":"arXiv:1412.6806"},{"key":"ref61","article-title":"Network in network","author":"Lin","year":"2013","journal-title":"arXiv:1312.4400"},{"key":"ref62","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.5555\/2999134.2999257"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1162\/106365603321828970"},{"key":"ref65","article-title":"Adversarial robustness assessment: Why both $L_{0}$\n and $L_{\\infty}$\n attacks are necessary","author":"Kotyan","year":"2019","journal-title":"arXiv:1906.06026"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.485"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref68","article-title":"Keeping the bad guys out: Protecting and vaccinating deep learning with jpeg compression","author":"Das","year":"2017","journal-title":"arXiv:1705.02900"}],"container-title":["IEEE Transactions on Evolutionary Computation"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/4235\/9906461\/09714259.pdf?arnumber=9714259","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,17]],"date-time":"2024-01-17T23:56:52Z","timestamp":1705535812000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9714259\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10]]},"references-count":68,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tevc.2022.3151373","relation":{},"ISSN":["1089-778X","1089-778X","1941-0026"],"issn-type":[{"value":"1089-778X","type":"print"},{"value":"1089-778X","type":"print"},{"value":"1941-0026","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10]]}}}