{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T05:32:57Z","timestamp":1777354377015,"version":"3.51.4"},"reference-count":59,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62002336"],"award-info":[{"award-number":["62002336"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20B2047"],"award-info":[{"award-number":["U20B2047"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"SenseTime Research Fund for Young Scholars"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Multimedia"],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tmm.2021.3124083","type":"journal-article","created":{"date-parts":[[2021,11,2]],"date-time":"2021-11-02T21:21:38Z","timestamp":1635888098000},"page":"203-213","source":"Crossref","is-referenced-by-count":22,"title":["AutoMA: Towards Automatic Model Augmentation for Transferable Adversarial Attacks"],"prefix":"10.1109","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3027-3109","authenticated-orcid":false,"given":"Haojie","family":"Yuan","sequence":"first","affiliation":[{"name":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3028-0755","authenticated-orcid":false,"given":"Qi","family":"Chu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4309-170X","authenticated-orcid":false,"given":"Feng","family":"Zhu","sequence":"additional","affiliation":[{"name":"SenseTime Ltd., Shenzhen, China"}]},{"given":"Rui","family":"Zhao","sequence":"additional","affiliation":[{"name":"SenseTime Ltd., Shenzhen, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3977-8800","authenticated-orcid":false,"given":"Bin","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4417-9316","authenticated-orcid":false,"given":"Nenghai","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, University of Science and Technology of China, Hefei, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.5555\/2999134.2999257"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref3","first-page":"48","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Simonyan","year":"2015"},{"key":"ref4","first-page":"91","article-title":"Faster R-CNN: Towards real-time object detection with region proposal networks","volume-title":"Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"28","author":"Ren","year":"2015"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.l007\/978-3-319-46448-0_2"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2699184"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298965"},{"key":"ref9","first-page":"252","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learning Representations","author":"Szegedy","year":"2014"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2018.2887018"},{"key":"ref11","first-page":"10791","article-title":"Cross-modal learning with adversarial samples","volume-title":"Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"32","author":"Li","year":"2019"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2018.2882908"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2020.3013376"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref15","first-page":"1944","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu","year":"2017"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref17","first-page":"4608","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Lin","year":"2019"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58542-6_34"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICVGIP.2008.47"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2004.383"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00723"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_28"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00124"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00072"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2021.3079723"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6810"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref30","first-page":"300","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref31","first-page":"1908","article-title":"Ensemble adversarial training: Attacks and defenses","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tramr","year":"2018"},{"key":"ref32","first-page":"3353","article-title":"Adversarial training for free!","volume-title":"Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"32","author":"Shafahi","year":"2019"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00126"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2020.2969784"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref36","first-page":"2808","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie","year":"2018"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00624"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TMM.2021.3050057"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01446"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_24"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00020"},{"key":"ref42","first-page":"4848","article-title":"Adversarial autoaugment","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang","year":"2020"},{"key":"ref43","article-title":"Data augmentation by pairing samples for images classification","author":"Inoue","year":"2018"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"ref45","first-page":"1057","article-title":"Policy gradient methods for reinforcement learning with function approximation","volume-title":"Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"13","author":"Sutton","year":"2000"},{"key":"ref46","article-title":"Proximal policy optimization algorithms","author":"Schulman","year":"2017"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.5555\/2999134.2999257"},{"key":"ref49","article-title":"SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and 0.5 mb model size","author":"Iandola","year":"2016"},{"key":"ref50","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00716"},{"key":"ref52","article-title":"MobileNets: Efficient convolutional neural networks for mobile vision applications","author":"Howard","year":"2017"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.634"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00293"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref58","first-page":"860","article-title":"Feature distillation with guided adversarial contrastive learning","volume-title":"Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit.","author":"Bai","year":"2020"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"}],"container-title":["IEEE Transactions on Multimedia"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6046\/10016790\/09599534.pdf?arnumber=9599534","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,6]],"date-time":"2025-06-06T17:42:46Z","timestamp":1749231766000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9599534\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":59,"URL":"https:\/\/doi.org\/10.1109\/tmm.2021.3124083","relation":{},"ISSN":["1520-9210","1941-0077"],"issn-type":[{"value":"1520-9210","type":"print"},{"value":"1941-0077","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}