{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T20:17:09Z","timestamp":1779135429499,"version":"3.51.4"},"reference-count":73,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272255"],"award-info":[{"award-number":["62272255"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62302248"],"award-info":[{"award-number":["62302248"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014103","name":"Key Technology Research and Development Program of Shandong Province","doi-asserted-by":"publisher","award":["2023CXGC010102"],"award-info":[{"award-number":["2023CXGC010102"]}],"id":[{"id":"10.13039\/100014103","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014103","name":"Key Technology Research and Development Program of Shandong Province","doi-asserted-by":"publisher","award":["2023TZXD049"],"award-info":[{"award-number":["2023TZXD049"]}],"id":[{"id":"10.13039\/100014103","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Taishan Scholars Program of Shandong Province","award":["tstp20240829"],"award-info":[{"award-number":["tstp20240829"]}]},{"name":"China University Industry-University-Research Innovation Fund","award":["2025SE007"],"award-info":[{"award-number":["2025SE007"]}]},{"DOI":"10.13039\/501100007129","name":"Natural Science Foundation of Shandong Province","doi-asserted-by":"publisher","award":["ZR2022LZH011"],"award-info":[{"award-number":["ZR2022LZH011"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007129","name":"Natural Science Foundation of Shandong Province","doi-asserted-by":"publisher","award":["ZR2023QF018"],"award-info":[{"award-number":["ZR2023QF018"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Jinan\u201cNew 20 Universities\u201d Project of Introducing Innovation Team","award":["202534038"],"award-info":[{"award-number":["202534038"]}]},{"DOI":"10.13039\/501100019074","name":"Major Innovation Project of the Pilot Program for Integration of Science","doi-asserted-by":"publisher","award":["2024ZDZX08"],"award-info":[{"award-number":["2024ZDZX08"]}],"id":[{"id":"10.13039\/501100019074","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3689286","type":"journal-article","created":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T19:46:41Z","timestamp":1777578401000},"page":"4785-4800","source":"Crossref","is-referenced-by-count":0,"title":["Security Enhancement for Person Re-Identification Through Diffusion Driven Semantic Attacks"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-7690-6224","authenticated-orcid":false,"given":"Kaixin","family":"Du","sequence":"first","affiliation":[{"name":"Key Laboratory of Computing Power Network and Information Security, Ministry of Education, Shandong Computer Science Center (National Supercomputer Center in Jinan), Qilu University of Technology (Shandong Academy of Sciences), Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9030-7393","authenticated-orcid":false,"given":"Bin","family":"Ma","sequence":"additional","affiliation":[{"name":"Key Laboratory of Computing Power Network and Information Security, Ministry of Education, Shandong Computer Science Center (National Supercomputer Center in Jinan), Qilu University of Technology (Shandong Academy of Sciences), Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Meihong","family":"Yang","sequence":"additional","affiliation":[{"name":"Key Laboratory of Computing Power Network and Information Security, Ministry of Education, Shandong Computer Science Center (National Supercomputer Center in Jinan), Qilu University of Technology (Shandong Academy of Sciences), Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jian","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Computer and Information Technology, Shandong University of Finance and Economics, Shandong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6111-9000","authenticated-orcid":false,"given":"Xiaolong","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer and Information Technology, Beijing Jiaotong University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00042"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2025.128541"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01216-8_18"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2024.112506"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01482"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00357"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20023"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2019-1353"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00777"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00893"},{"key":"ref12","article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","author":"Gao","year":"2020","journal-title":"arXiv:2007.10760"},{"key":"ref13","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref14","article-title":"Can you really backdoor federated learning?","author":"Sun","year":"2019","journal-title":"arXiv:1911.07963"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref16","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Wang"},{"key":"ref17","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01616"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3322659"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00421"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72952-2_6"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0129"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2253"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2024.3514361"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-72114-4_62"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3162397"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref31","first-page":"18944","article-title":"Backdoor attack with imperceptible input and latent modification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Doan"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01615"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref34","article-title":"Backdoor attack in the physical world","author":"Li","year":"2021","journal-title":"arXiv:2104.02361"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00409"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2023.3345136"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.133"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107584"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3416030"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3240508.3240552"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2019.2958756"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3054775"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01225-0_30"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01474"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/WACVW58289.2023.00009"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3081247"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.52202\/079017-0735"},{"key":"ref49","article-title":"DiffPhysBA: Diffusion-based physical backdoor attack against person re-identification in real-world","author":"Sun","year":"2024","journal-title":"arXiv:2405.19990"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.52202\/079017-4292"},{"key":"ref51","first-page":"37970","article-title":"Graph your own prompt","volume-title":"Proc. 39th Annu. Conf. Neural Inf. Process. Syst.","volume":"38","author":"Ding"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.106"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.2983686"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2019.2938758"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2025.3645918"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2025.3559891"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3148707"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3104166"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2023.3334556"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2699184"},{"key":"ref62","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Radford"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.405"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3069237"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2023.3294816"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref67","article-title":"WaNet\u2014Imperceptible warping-based backdoor attack","author":"Nguyen","year":"2021","journal-title":"arXiv:2102.10369"},{"key":"ref68","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref69","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref70","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427264"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00843"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11501273.pdf?arnumber=11501273","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T19:45:31Z","timestamp":1779133531000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11501273\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":73,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3689286","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}