{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,6]],"date-time":"2026-01-06T18:40:53Z","timestamp":1767724853075,"version":"3.48.0"},"reference-count":64,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472080"],"award-info":[{"award-number":["62472080"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62506321"],"award-info":[{"award-number":["62506321"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004735","name":"Natural Science Foundation of Hunan Province","doi-asserted-by":"publisher","award":["2024JJ6435"],"award-info":[{"award-number":["2024JJ6435"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2025.3648871","type":"journal-article","created":{"date-parts":[[2025,12,26]],"date-time":"2025-12-26T18:23:11Z","timestamp":1766773391000},"page":"532-546","source":"Crossref","is-referenced-by-count":0,"title":["Reinforcing Adversarial Transferability via Negative Class Guided Example Generation"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6501-4097","authenticated-orcid":false,"given":"Hegui","family":"Zhu","sequence":"first","affiliation":[{"name":"Department of Mathematics, College of Sciences, Northeastern University, Shenyang, Liaoning, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-5187-9397","authenticated-orcid":false,"given":"Wenqi","family":"Cui","sequence":"additional","affiliation":[{"name":"Department of Mathematics, College of Sciences, Northeastern University, Shenyang, Liaoning, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1019-8716","authenticated-orcid":false,"given":"Yue","family":"Yan","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Northeastern University, Shenyang, China"}]},{"given":"Ning","family":"Han","sequence":"additional","affiliation":[{"name":"School of Computer Science, Xiangtan University, Xiangtan, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548183"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01986"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TMI.2023.3253760"},{"key":"ref8","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Szegedy"},{"key":"ref9","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref10","first-page":"125","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Ilyas"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref12","first-page":"1","article-title":"PolaFormer: Polarity-aware linear attention for vision transformers","volume-title":"Proc. 13th Int. Conf. Learn. Represent.","author":"Meng"},{"key":"ref13","article-title":"An alternative surrogate loss for PGD-based adversarial testing","author":"Gowal","year":"2019","journal-title":"arXiv:1910.09338"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3393745"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref19","first-page":"1","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Lin"},{"key":"ref20","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref21","first-page":"1","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Brendel"},{"key":"ref22","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref23","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Uesato"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_10"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2025.3559103"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3430508"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3526067"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i5.32527"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00437"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP49359.2023.10223158"},{"key":"ref33","first-page":"70141","article-title":"Boosting adversarial transferability by achieving flat local maxima","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Ge"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.124757"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00425"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02297"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58517-4_15"},{"key":"ref42","first-page":"32900","article-title":"Improving adversarial transferability via intermediate-level perturbation decay","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref43","first-page":"85","article-title":"Backpropagating linearly improves transferability of adversarial examples","volume-title":"Proc. NIPS","author":"Guo"},{"key":"ref44","first-page":"1905","article-title":"Rethinking the backward propagation for adversarial transferability","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-73033-7_5"},{"key":"ref46","first-page":"13950","article-title":"Learning transferable adversarial perturbations","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Nakka"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP46576.2022.9897346"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611978032.81"},{"key":"ref49","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"Liu","year":"2016","journal-title":"arXiv:1611.02770"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00414"},{"key":"ref51","article-title":"Rethinking model ensemble in transfer-based adversarial attacks","author":"Chen","year":"2023","journal-title":"arXiv:2303.09105"},{"article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Tram\u00e8r","key":"ref52"},{"key":"ref53","first-page":"1","article-title":"Why adversarial training can hurt robust accuracy","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Clarysse"},{"key":"ref54","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref58"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref61","first-page":"1","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Dosovitskiy"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01172"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00063"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11316452.pdf?arnumber=11316452","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,6]],"date-time":"2026-01-06T18:34:45Z","timestamp":1767724485000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11316452\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":64,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3648871","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2026]]}}}