{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,5]],"date-time":"2026-02-05T05:53:15Z","timestamp":1770270795801,"version":"3.49.0"},"reference-count":51,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62227805"],"award-info":[{"award-number":["62227805"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072398"],"award-info":[{"award-number":["62072398"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2020AAA0107700"],"award-info":[{"award-number":["2020AAA0107700"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Alibaba\u2013Zhejiang University Joint Institute of Frontier Technologies"},{"name":"Zhejiang Key Research and Development Plan","award":["2021C01116"],"award-info":[{"award-number":["2021C01116"]}]},{"name":"Leading Innovative and Entrepreneur Team Introduction Program of Zhejiang","award":["2018R01005"],"award-info":[{"award-number":["2018R01005"]}]},{"DOI":"10.13039\/100017132","name":"Research Institute of Cyberspace Governance in Zhejiang University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100017132","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key Laboratory of Science and Technology on Information System Security","award":["6142111210301"],"award-info":[{"award-number":["6142111210301"]}]},{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing"},{"name":"Open Foundation of Henan Key Laboratory of Cyberspace Situation Awareness","award":["HNTS2022001"],"award-info":[{"award-number":["HNTS2022001"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tifs.2022.3226572","type":"journal-article","created":{"date-parts":[[2023,2,2]],"date-time":"2023-02-02T19:27:35Z","timestamp":1675366055000},"page":"789-803","source":"Crossref","is-referenced-by-count":16,"title":["SAGE: Steering the Adversarial Generation of Examples With Accelerations"],"prefix":"10.1109","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1455-4330","authenticated-orcid":false,"given":"Ziming","family":"Zhao","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2195-0799","authenticated-orcid":false,"given":"Zhaoxuan","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6087-8243","authenticated-orcid":false,"given":"Fan","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"given":"Ziqi","family":"Yang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"given":"Shuang","family":"Luo","sequence":"additional","affiliation":[{"name":"School of Computer Science (National Pilot Software Engineering School), Beijing University of Posts and Telecommunications, Beijing, China"}]},{"given":"Tingting","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0002-5593","authenticated-orcid":false,"given":"Rui","family":"Zhang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1969-2591","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1","article-title":"There are no bit parts for sign bits in black-box attacks","volume":"abs\/1902.06894","author":"Al-Dujaili","year":"2019","journal-title":"CoRR"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3023274"},{"key":"ref3","first-page":"1","article-title":"Exploring the space of black-box attacks on deep neural networks","volume":"abs\/1712.09491","author":"Bhagoji","year":"2017","journal-title":"CoRR"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3138616"},{"key":"ref5","first-page":"1","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","volume-title":"Proc. ICLR","author":"Brendel"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00506"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339815"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref11","first-page":"10932","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. NeurIPS","author":"Cheng"},{"key":"ref12","volume-title":"Google Vision API","author":"Cloud","year":"2021"},{"key":"ref13","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","volume-title":"Proc. USENIX Secur. Symp.","author":"Demontis"},{"key":"ref14","first-page":"10159","article-title":"A spectral view of adversarially robust features","volume-title":"Proc. NeurIPS","author":"Garg"},{"key":"ref15","first-page":"2280","article-title":"Adversarial examples are a natural consequence of test error in noise","volume-title":"Proc. ICML","volume":"97","author":"Gilmer"},{"key":"ref16","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. ICLR","author":"Ian Goodfellow"},{"key":"ref17","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. ICML","volume":"97","author":"Guo"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref19","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"80","author":"Ilyas"},{"key":"ref20","first-page":"1","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","volume-title":"Proc. ICLR","author":"Ilyas"},{"key":"ref21","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. NeurIPS","author":"Ilyas"},{"key":"ref22","volume-title":"Imagenet Large Scale Visual Recognition Challenge 2012 (ILSVRC2012)","year":"2021"},{"key":"ref23","first-page":"17148","article-title":"Distilling robust and non-robust features in adversarial examples by information bottleneck","volume-title":"Proc. NeurIPS","author":"Kim"},{"issue":"4","key":"ref24","first-page":"1","article-title":"Learning multiple layers of features from tiny images","volume":"1","author":"Krizhevsky","year":"2009"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00159"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23202"},{"key":"ref27","first-page":"6577","article-title":"Uncovering the connections between adversarial transferability and knowledge transferability","volume-title":"Proc. ICML","volume":"139","author":"Liang"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00023"},{"key":"ref29","first-page":"1","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. ICLR","author":"Liu"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11499"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23415"},{"key":"ref32","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00091"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00668"},{"key":"ref41","first-page":"1327","article-title":"Hybrid batch attacks: Finding black-box adversarial examples with limited queries","volume-title":"Proc. USENIX Secur. Symp.","author":"Suya"},{"key":"ref42","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. ICLR","author":"Szegedy"},{"key":"ref43","first-page":"1","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. ICLR","author":"Tram\u00e8r"},{"key":"ref44","first-page":"1","article-title":"The space of transferable adversarial examples","volume":"abs\/1704.03453","author":"Tram\u00e8r","year":"2017","journal-title":"CoRR"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3002390"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3026543"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3021899"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036801"},{"key":"ref51","first-page":"11609","article-title":"Learning adversarially robust representations via worst-case mutual information maximization","volume-title":"Proc. ICML","volume":"119","author":"Zhu"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9970396\/10035539.pdf?arnumber=10035539","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,13]],"date-time":"2024-02-13T13:29:13Z","timestamp":1707830953000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10035539\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/tifs.2022.3226572","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}