{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T20:39:09Z","timestamp":1782938349591,"version":"3.54.5"},"reference-count":62,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"HK RGC GRF","award":["15201323"],"award-info":[{"award-number":["15201323"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3702560","type":"journal-article","created":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T20:01:07Z","timestamp":1781121667000},"page":"5946-5959","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing Targeted Adversarial Attacks on Large Vision-Language Models via Intermediate Projector"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-5953-496X","authenticated-orcid":false,"given":"Yiming","family":"Cao","sequence":"first","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hung Hom, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8859-8331","authenticated-orcid":false,"given":"Yanjie","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hung Hom, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8297-6378","authenticated-orcid":false,"given":"Kaisheng","family":"Liang","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hung Hom, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4223-8220","authenticated-orcid":false,"given":"Bin","family":"Xiao","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Hung Hom, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"19730","article-title":"Blip-2: Bootstrapping language-image pre-training with frozen image encoders and large language models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1516"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i21.30552"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00102"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02325"},{"key":"ref6","article-title":"Dissecting adversarial robustness of multimodal LM agents","author":"Henry Wu","year":"2024","journal-title":"arXiv:2406.12814"},{"key":"ref7","first-page":"54111","article-title":"On evaluating adversarial robustness of large vision-language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Cheung"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3518072"},{"key":"ref9","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"139","author":"Radford"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.01368"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02308"},{"key":"ref12","first-page":"49250","article-title":"InstructBLIP: Towards general-purpose vision-language models with instruction tuning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Dai"},{"key":"ref13","article-title":"MiniGPT-4: Enhancing vision-language understanding with advanced large language models","author":"Zhu","year":"2023","journal-title":"arXiv:2304.10592"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02495"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2024\/1023"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.00799"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00686"},{"key":"ref20","article-title":"GPT-4 technical report","volume-title":"arXiv:2303.08774","author":"Achiam","year":"2023"},{"key":"ref21","article-title":"EVA-CLIP: Improved training techniques for CLIP at scale","author":"Sun","year":"2023","journal-title":"arXiv:2303.15389"},{"key":"ref22","volume-title":"LLaVA-NeXT: Improved Reasoning, OCR, and World Knowledge","author":"Liu","year":"2024"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-emnlp.1111"},{"key":"ref24","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3594869"},{"key":"ref26","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.02403"},{"key":"ref29","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref30","first-page":"2991","article-title":"Transferability of white-box perturbations: Query-efficient adversarial attacks against commercial dnn services","volume-title":"Proc. 33rd USENIX Secur. Symp. (USENIX Secur.)","author":"Shen"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3547801"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00016"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3664647.3680779"},{"key":"ref34","first-page":"14061","article-title":"Improving zero-shot adversarial robustness in vision-language models by closed-form alignment of adversarial path simplices","volume-title":"Proc. 42nd Int. Conf. Mach. Learn.","author":"Dong"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.01853"},{"key":"ref36","article-title":"Transferable and stealthy adversarial attacks on large vision-language models","volume-title":"Proc. 14th Int. Conf. Learn. Represent.","author":"Yao"},{"key":"ref37","first-page":"136551","article-title":"AdvEDM: Fine-grained adversarial attack against VLM-based embodied agents","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"38","author":"Wang"},{"key":"ref38","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICVGIP.2008.47"},{"key":"ref40","article-title":"Fine-grained visual classification of aircraft","volume-title":"arXiv:1306.5151","author":"Maji","year":"2013"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/JSTARS.2019.2918242"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6248092"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.461"},{"issue":"70","key":"ref44","first-page":"1","article-title":"Scaling instruction-finetuned language models","volume":"25","author":"Chung","year":"2024","journal-title":"J. Mach. Learn. Res."},{"key":"ref45","volume-title":"Vicuna: An Open-Source Chatbot Impressing GPT-4 With 90%* ChatGPT Quality","author":"Chiang","year":"2023"},{"key":"ref46","article-title":"Qwen technical report","volume-title":"arXiv:2309.16609","author":"Bai","year":"2023"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01182"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02297"},{"key":"ref49","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Lin"},{"key":"ref50","first-page":"6840","article-title":"Denoising diffusion probabilistic models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Ho"},{"key":"ref51","first-page":"3519","article-title":"Similarity of neural network representations revisited","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Kornblith"},{"key":"ref52","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"Xu","year":"2017","journal-title":"arXiv:1704.01155"},{"key":"ref53","article-title":"A study of the effect of JPG compression on adversarial images","author":"Karolina Dziugaite","year":"2016","journal-title":"arXiv:1608.00853"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref55","article-title":"Diffusion models for adversarial purification","author":"Nie","year":"2022","journal-title":"arXiv:2205.07460"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.01855"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.01413"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51701.2025.01955"},{"key":"ref59","article-title":"Robust CLIP: Unsupervised adversarial fine-tuning of vision embeddings for robust large vision-language models","author":"Schlarmann","year":"2024","journal-title":"arXiv:2402.12336"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.3045810"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11557371.pdf?arnumber=11557371","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:35:38Z","timestamp":1782934538000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11557371\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":62,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3702560","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}