{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,8]],"date-time":"2026-02-08T06:02:14Z","timestamp":1770530534981,"version":"3.49.0"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Swarnajayanti Fellowship by the Government of India"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/tip.2022.3204206","type":"journal-article","created":{"date-parts":[[2022,9,12]],"date-time":"2022-09-12T19:52:23Z","timestamp":1663012343000},"page":"7338-7349","source":"Crossref","is-referenced-by-count":13,"title":["Crafting Adversarial Perturbations via Transformed Image Component Swapping"],"prefix":"10.1109","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7362-4752","authenticated-orcid":false,"given":"Akshay","family":"Agarwal","sequence":"first","affiliation":[{"name":"Department of Data Science and Engineering, IISER Bhopal, Bhauri, Madhya Pradesh, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7913-5722","authenticated-orcid":false,"given":"Nalini","family":"Ratha","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Electrical Engineering, University at Buffalo, Buffalo, NY, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5952-2274","authenticated-orcid":false,"given":"Mayank","family":"Vatsa","sequence":"additional","affiliation":[{"name":"Department of Computer Science Engineering, IIT Jodhpur, Jodhpur, India"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4060-4573","authenticated-orcid":false,"given":"Richa","family":"Singh","sequence":"additional","affiliation":[{"name":"Department of Computer Science Engineering, IIT Jodhpur, Jodhpur, India"}]}],"member":"263","reference":[{"key":"ref39","article-title":"Adversarial machine learning in image classification: A survey towards the Defender&#x2019;s perspective","author":"machado","year":"2020","journal-title":"arXiv 2009 03728"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6810"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00467"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3470493"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00017"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref37","article-title":"Vision transformer for small-size datasets","author":"lee","year":"2021","journal-title":"arXiv 2112 13492"},{"key":"ref36","article-title":"Adversarial machine learning at scale","author":"kurakin","year":"2016","journal-title":"arXiv 1611 01236"},{"key":"ref35","first-page":"32","author":"krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images"},{"key":"ref34","article-title":"Adam: A method for stochastic optimization","author":"kingma","year":"2014","journal-title":"arXiv 1412 6980"},{"key":"ref28","article-title":"Transferable universal adversarial perturbations using generative models","author":"hashemi","year":"2020","journal-title":"arXiv 2010 14919"},{"key":"ref27","article-title":"Watch out! Motion is blurring the vision of your deep neural networks","author":"guo","year":"2020","journal-title":"arXiv 2002 03500"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref2","first-page":"1","article-title":"Benchmarking robustness beyond lp norm adversaries","author":"agarwal","year":"2022","journal-title":"Proc Eur Conf Comput Vis Workshops"},{"key":"ref1","article-title":"TensorFlow: Large-scale machine learning on heterogeneous distributed systems","author":"abadi","year":"2016","journal-title":"arXiv 1603 04467"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00741"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2005.853048"},{"key":"ref21","first-page":"28","author":"edwards","year":"1991","journal-title":"Discrete Wavelet Transforms Theory and Implementation"},{"key":"ref24","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"arXiv 1412 6572"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2021.3079723"},{"key":"ref26","article-title":"Low frequency adversarial perturbation","author":"guo","year":"2018","journal-title":"arXiv 1809 08758"},{"key":"ref25","author":"gosthipaty","year":"2021","journal-title":"Train a Vision Transformer on Small Datasets"},{"key":"ref50","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"arXiv 1409 1556"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_28"},{"key":"ref58","article-title":"Wide residual networks","author":"zagoruyko","year":"2016","journal-title":"arXiv 1605 07146"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref56","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"xiao","year":"2017","journal-title":"ArXiv 1708 07747"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i3.20169"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/833"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00871"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00752"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref40","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"arXiv 1706 06083"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref14","author":"chollet","year":"2017","journal-title":"R interface to keras"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2020.04.025"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01166"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref19","article-title":"An image is worth 16 &#x00D7; 16 words: Transformers for image recognition at scale","author":"dosovitskiy","year":"2020","journal-title":"arXiv 2010 11929"},{"key":"ref4","first-page":"1","article-title":"Black-box adversarial entry in finance through credit card fraud detection","author":"agarwal","year":"2021","journal-title":"Proc CIKM Workshops"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00030"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2021.01.032"},{"key":"ref5","first-page":"1","article-title":"On the robustness of stock market regressors","author":"agarwal","year":"2022","journal-title":"Proc ECML-PKDD Workshops"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-66415-2_10"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW50498.2020.00395"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/470"},{"key":"ref9","first-page":"284","article-title":"Synthesizing robust adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref46","article-title":"Towards practical verification of machine learning: The case of computer vision systems","author":"pei","year":"2017","journal-title":"arXiv 1712 01785"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref48","article-title":"Defending against adversarial images using basis functions transformations","author":"shaham","year":"2018","journal-title":"arXiv 1803 10840"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3398394"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00774"},{"key":"ref44","article-title":"On the limitations of denoising strategies as adversarial defenses","author":"niu","year":"2020","journal-title":"arXiv 2012 09384"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2017.172"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/9626658\/09887823.pdf?arnumber=9887823","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,19]],"date-time":"2022-12-19T19:53:38Z","timestamp":1671479618000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9887823\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":59,"URL":"https:\/\/doi.org\/10.1109\/tip.2022.3204206","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"value":"1057-7149","type":"print"},{"value":"1941-0042","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}