{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T03:56:23Z","timestamp":1779162983327,"version":"3.51.4"},"reference-count":72,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["52005505"],"award-info":[{"award-number":["52005505"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62001502"],"award-info":[{"award-number":["62001502"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. on Image Process."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tip.2023.3345136","type":"journal-article","created":{"date-parts":[[2023,12,27]],"date-time":"2023-12-27T19:52:28Z","timestamp":1703706748000},"page":"722-737","source":"Crossref","is-referenced-by-count":20,"title":["Improving Transferability of Universal Adversarial Perturbation With Feature Disruption"],"prefix":"10.1109","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4685-8232","authenticated-orcid":false,"given":"Donghua","family":"Wang","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5224-9834","authenticated-orcid":false,"given":"Wen","family":"Yao","sequence":"additional","affiliation":[{"name":"Defense Innovation Institute, Chinese Academy of Military Science, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1637-2928","authenticated-orcid":false,"given":"Tingsong","family":"Jiang","sequence":"additional","affiliation":[{"name":"Defense Innovation Institute, Chinese Academy of Military Science, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9255-3371","authenticated-orcid":false,"given":"Xiaoqian","family":"Chen","sequence":"additional","affiliation":[{"name":"Defense Innovation Institute, Chinese Academy of Military Science, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref3","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","volume-title":"Proc. 9th Int. Conf. Learn. Represent. (ICLR)","author":"Dosovitskiy"},{"key":"ref4","first-page":"91","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"28","author":"Ren"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.322"},{"key":"ref8","article-title":"Adversarial machine learning at scale","author":"Kurakin","year":"2016","journal-title":"arXiv:1611.01236"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref10","article-title":"Black-box adversarial attack with transferable model-based embedding","volume-title":"Proc. 8th Int. Conf. Learn. Represent. (ICLR)","author":"Huang"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2022.3151373"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00816"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3127849"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00846"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20141"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00249"},{"key":"ref19","first-page":"4455","article-title":"RFLA: A stealthy reflected light adversarial attack in the physical world","volume-title":"Proc. IEEE\/CVF Int. Conf. Comput. Vis.","author":"Wang"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP42928.2021.9506325"},{"key":"ref22","article-title":"On procedural adversarial noise attack and defense","author":"Yan","year":"2021","journal-title":"arXiv:2108.04409"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.5244\/C.31.30"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2018.2861800"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00303"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.23915\/distill.00007"},{"key":"ref27","first-page":"1","article-title":"How transferable are features in deep neural networks?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"27","author":"Yosinski"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"issue":"1","key":"ref29","first-page":"1929","article-title":"Dropout: A simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref30","article-title":"Pruning filters for efficient convnets","author":"Li","year":"2016","journal-title":"arXiv:1608.08710"},{"key":"ref31","article-title":"Network trimming: A data-driven neuron pruning approach towards efficient deep architectures","author":"Hu","year":"2016","journal-title":"arXiv:1607.03250"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.155"},{"key":"ref33","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Represent. (ICLR)","author":"Goodfellow"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403225"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_28"},{"key":"ref38","article-title":"Task-generalizable adversarial attack based on perceptual metric","author":"Naseer","year":"2018","journal-title":"arXiv:1811.09020"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00893"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20023"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP40778.2020.9191288"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01453"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00777"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00084"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00015"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2020.04.025"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i4.16441"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i1.19982"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01240-3_2"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3345660"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/2623330.2623612"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref55","first-page":"8024","article-title":"PyTorch: An imperative style, high-performance deep learning library","author":"Paszke","year":"2019","journal-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, December 8\u201314, 2019, Vancouver, BC, Canada"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref58","first-page":"6105","article-title":"EfficientNet: Rethinking model scaling for convolutional neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Tan"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00293"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-014-0733-5"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-014-0748-y"},{"key":"ref65","article-title":"Do adversarially robust ImageNet models transfer better?","author":"Salman","year":"2020","journal-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6\u201312, 2020, Virtual"},{"key":"ref66","article-title":"Adversarial machine learning at scale","volume-title":"Proc. 5th Int. Conf. Learn. Represent. (ICLR)","author":"Kurakin"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00095"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref69","article-title":"Countering adversarial images using input transformations","volume-title":"Proc. 6th Int. Conf. Learn. Represent. (ICLR)","author":"Guo"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108249"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref72","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. 6th Int. Conf. Learn. Represent. (ICLR)","author":"Tram\u00e8r"}],"container-title":["IEEE Transactions on Image Processing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/83\/10346232\/10375304.pdf?arnumber=10375304","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,18]],"date-time":"2024-01-18T00:56:33Z","timestamp":1705539393000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10375304\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":72,"URL":"https:\/\/doi.org\/10.1109\/tip.2023.3345136","relation":{},"ISSN":["1057-7149","1941-0042"],"issn-type":[{"value":"1057-7149","type":"print"},{"value":"1941-0042","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}