{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T06:44:16Z","timestamp":1778049856407,"version":"3.51.4"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Rapid-Rich Object Search (ROSE) Laboratory, Nanyang Technological University (NTU), Singapore"},{"DOI":"10.13039\/501100001381","name":"National Research Foundation, Singapore, and the Infocomm Media Development Authority under its Trust Tech Funding Initiative","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012457","name":"Basic and Frontier Research Project of Pengcheng Laboratory","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012457","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Major Key Project of PCL"},{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2024A1515010454"],"award-info":[{"award-number":["2024A1515010454"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3553043","type":"journal-article","created":{"date-parts":[[2025,3,19]],"date-time":"2025-03-19T18:43:01Z","timestamp":1742409781000},"page":"3745-3757","source":"Crossref","is-referenced-by-count":10,"title":["Toward Model Resistant to Transferable Adversarial Examples via Trigger Activation"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2730-9553","authenticated-orcid":false,"given":"Yi","family":"Yu","sequence":"first","affiliation":[{"name":"Rapid-Rich Object Search (ROSE) Laboratory, Interdisciplinary Graduate Programme, Nanyang Technological University, Jurong West, Singapore"}]},{"given":"Song","family":"Xia","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8387-4245","authenticated-orcid":false,"given":"Xun","family":"Lin","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Beihang University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3958-6489","authenticated-orcid":false,"given":"Chenqi","family":"Kong","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1692-0069","authenticated-orcid":false,"given":"Wenhan","family":"Yang","sequence":"additional","affiliation":[{"name":"Pengcheng Laboratory, Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6766-2506","authenticated-orcid":false,"given":"Shijian","family":"Lu","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}]},{"given":"Yap-Peng","family":"Tan","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6262-8125","authenticated-orcid":false,"given":"Alex C.","family":"Kot","sequence":"additional","affiliation":[{"name":"School of Electrical and Electronic Engineering, Nanyang Technological University, Jurong West, Singapore"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref2","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2021.102141"},{"key":"ref4","article-title":"Safeguarding medical image segmentation datasets against unauthorized training via contour- and texture-aware perturbations","author":"Lin","year":"2024","journal-title":"arXiv:2403.14250"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2019.2934069"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.320"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00592"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP48485.2024.10446953"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01179"},{"key":"ref10","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref11","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref12","first-page":"10932","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","volume":"32","author":"Cheng"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2023.3333556"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2023.3307908"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2024.3360891"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2023.3284649"},{"key":"ref17","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016","journal-title":"arXiv:1605.07277"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00790"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01575"},{"key":"ref20","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Liu"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref22","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Tram\u00e8r"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref25","first-page":"7472","article-title":"Theoretically principled trade-off between robustness and accuracy","volume-title":"Proc. 36th Int. Conf. Mach. Learn. (ICML)","volume":"97","author":"Zhang"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref27","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Guo"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref29","article-title":"PixelDefend: Leveraging generative models to understand and defend against adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Song"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00624"},{"key":"ref32","first-page":"16805","article-title":"Diffusion models for adversarial purification","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Nie"},{"key":"ref33","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref35","article-title":"Transferable adversarial attack based on integrated gradients","author":"Huang","year":"2022","journal-title":"arXiv:2205.13152"},{"key":"ref36","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"Cheng","year":"2018","journal-title":"arXiv:1807.04457"},{"key":"ref37","first-page":"12921","article-title":"Decision-based black-box attack against vision transformers via patch-wise adversarial removal","volume-title":"Proc. Annual Conf. Neural Inf. Process. Syst.","volume":"35","author":"Shi"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01333"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref41","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","author":"Lin","year":"2019","journal-title":"arXiv:1908.06281"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00437"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02297"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02291"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00816"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01457"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/233"},{"key":"ref52","first-page":"2894","article-title":"Diffusion-based adversarial sample generation for improved stealthiness and controllability","volume-title":"Proc. Annual Conf. Neural Inf. Process. Syst.","volume":"36","author":"Xue"},{"key":"ref53","article-title":"Adversarial machine learning at scale","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Kurakin"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref55","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Xie"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00095"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref58","article-title":"Score-based generative modeling through stochastic differential equations","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Song"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01578"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i6.28330"},{"key":"ref61","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref62","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.5555\/3298023.3298188"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10934010.pdf?arnumber=10934010","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,24]],"date-time":"2025-04-24T17:04:31Z","timestamp":1745514271000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10934010\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":65,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3553043","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}