{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,7]],"date-time":"2026-04-07T16:50:40Z","timestamp":1775580640168,"version":"3.50.1"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["ECCS-1810256"],"award-info":[{"award-number":["ECCS-1810256"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-1718195"],"award-info":[{"award-number":["CCF-1718195"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["HR00112090095"],"award-info":[{"award-number":["HR00112090095"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100000923","name":"Australian Research Council Future Fellowship Award funded by the Australian Government","doi-asserted-by":"publisher","award":["FT210100268"],"award-info":[{"award-number":["FT210100268"]}],"id":[{"id":"10.13039\/501100000923","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2023.3275737","type":"journal-article","created":{"date-parts":[[2023,5,12]],"date-time":"2023-05-12T17:38:29Z","timestamp":1683913109000},"page":"1561-1575","source":"Crossref","is-referenced-by-count":9,"title":["Low-Rank and Sparse Decomposition for Low-Query Decision-Based Adversarial Attacks"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1564-1962","authenticated-orcid":false,"given":"Ashkan","family":"Esmaeili","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Central Florida, Orlando, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1269-1190","authenticated-orcid":false,"given":"Marzieh","family":"Edraki","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Central Florida, Orlando, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nazanin","family":"Rahnavard","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Central Florida, Orlando, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5206-3842","authenticated-orcid":false,"given":"Ajmal","family":"Mian","sequence":"additional","affiliation":[{"name":"Department of Computer Science, The University of Western Australia, Perth, WA, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8216-1128","authenticated-orcid":false,"given":"Mubarak","family":"Shah","sequence":"additional","affiliation":[{"name":"Center for Research in Computer Vision, University of Central Florida, Orlando, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2018.2807385"},{"key":"ref2","first-page":"1","article-title":"Sign bits are all you need for black-box attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Al-Dujaili"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3321707.3321749"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref5","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_10"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1201\/b20190"},{"key":"ref8","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017","journal-title":"arXiv:1712.04248"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00506"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2020.3044130"},{"key":"ref11","first-page":"513","article-title":"Hidden voice commands","volume-title":"Proc. 25th USENIX Secur. Symp. (USENIX Security)","author":"Carlini"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58555-6_17"},{"key":"ref18","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"Cheng","year":"2018","journal-title":"arXiv:1807.04457"},{"key":"ref19","article-title":"Sign-OPT: A query-efficient hard-label adversarial attack","author":"Cheng","year":"2019","journal-title":"arXiv:1909.10773"},{"key":"ref20","first-page":"10934","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Cheng"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20595"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00482"},{"key":"ref23","article-title":"GreedyFool: Distortion-aware sparse adversarial attack","author":"Dong","year":"2020","journal-title":"arXiv:2010.13773"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58542-6_3"},{"key":"ref27","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref28","article-title":"Adversarial perturbations against deep neural networks for malware classification","author":"Grosse","year":"2016","journal-title":"arXiv:1606.04435"},{"key":"ref29","article-title":"Simple black-box adversarial attacks","author":"Guo","year":"2019","journal-title":"arXiv:1905.07121"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref31","article-title":"Black-box attacks against RNN based malware detection algorithms","author":"Hu","year":"2017","journal-title":"arXiv:1705.08131"},{"key":"ref32","article-title":"Black-box adversarial attack with transferable model-based embedding","author":"Huang","year":"2019","journal-title":"arXiv:1911.07140"},{"key":"ref33","article-title":"Black-box adversarial attacks with limited queries and information","author":"Ilyas","year":"2018","journal-title":"arXiv:1804.08598"},{"key":"ref34","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","author":"Ilyas","year":"2018","journal-title":"arXiv:1807.07978"},{"key":"ref35","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00130"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2015.2419084"},{"key":"ref39","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"Liu","year":"2016","journal-title":"arXiv:1611.02770"},{"key":"ref40","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00930"},{"key":"ref42","first-page":"1","article-title":"AdvFlow: Inconspicuous black-box adversarial attacks using normalizing flows","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Dolatabadi"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.172"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1002\/mrm.25240"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00847"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1162\/neco_a_00990"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"ref51","article-title":"Simple and efficient hard label black-box adversarial attacks in low query budget regimes","author":"Shukla","year":"2020","journal-title":"arXiv:2007.07210"},{"issue":"2","key":"ref52","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1080\/10618600.2012.681250","article-title":"A sparse-group lasso","volume":"22","author":"Noah","year":"2013","journal-title":"J. Comput. Graph. Stat."},{"key":"ref53","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.2200\/s00861ed1v01y201806aim039"},{"key":"ref56","article-title":"Fast is better than free: Revisiting adversarial training","author":"Wong","year":"2020","journal-title":"arXiv:2001.03994"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2008.79"},{"key":"ref58","first-page":"12288","article-title":"Learning black-box attackers with transferable priors and query feedback","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Yang"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01161"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1016\/j.dsp.2016.07.010"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2011.5995484"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00021"},{"key":"ref63","first-page":"33","article-title":"GoDec: Randomized low-rank & sparse matrix decomposition in noisy case","volume-title":"Proc. 28th Int. Conf. Mach. Learn. (ICML)","author":"Zhou"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/10319981\/10124099.pdf?arnumber=10124099","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,12]],"date-time":"2024-01-12T01:09:08Z","timestamp":1705021748000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10124099\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":63,"URL":"https:\/\/doi.org\/10.1109\/tifs.2023.3275737","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}