{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T07:47:01Z","timestamp":1773215221757,"version":"3.50.1"},"reference-count":46,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2022,12,1]],"date-time":"2022-12-01T00:00:00Z","timestamp":1669852800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,12,1]],"date-time":"2022-12-01T00:00:00Z","timestamp":1669852800000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,12,1]],"date-time":"2022-12-01T00:00:00Z","timestamp":1669852800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,12,1]],"date-time":"2022-12-01T00:00:00Z","timestamp":1669852800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2020AAA0104304"],"award-info":[{"award-number":["2020AAA0104304"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61620106010"],"award-info":[{"award-number":["61620106010"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62061136001"],"award-info":[{"award-number":["62061136001"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61621136008"],"award-info":[{"award-number":["61621136008"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62076147"],"award-info":[{"award-number":["62076147"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U19B2034"],"award-info":[{"award-number":["U19B2034"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1811461"],"award-info":[{"award-number":["U1811461"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U19A2081"],"award-info":[{"award-number":["U19A2081"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NSF","award":["JQ19016"],"award-info":[{"award-number":["JQ19016"]}]},{"name":"Beijing Academy of Artificial Intelligence"},{"name":"Tsinghua-Huawei Joint Research Program"},{"name":"Tsinghua Institute for Guo Qiang"},{"name":"Tsinghua-OPPO Joint Research Center for Future Terminal Technology and Tsinghua-China Mobile Communications Group Co., Ltd. Joint Institute"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2022,12,1]]},"DOI":"10.1109\/tpami.2021.3126733","type":"journal-article","created":{"date-parts":[[2021,11,9]],"date-time":"2021-11-09T20:42:40Z","timestamp":1636490560000},"page":"9536-9548","source":"Crossref","is-referenced-by-count":51,"title":["Query-Efficient Black-Box Adversarial Attacks Guided by a Transfer-Based Prior"],"prefix":"10.1109","volume":"44","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1299-683X","authenticated-orcid":false,"given":"Yinpeng","family":"Dong","sequence":"first","affiliation":[{"name":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"}]},{"given":"Shuyu","family":"Cheng","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0639-6176","authenticated-orcid":false,"given":"Tianyu","family":"Pang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"}]},{"given":"Hang","family":"Su","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"}]},{"given":"Jun","family":"Zhu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Beijing National Research Center for Information Science and Technology, Tsinghua-Bosch Joint Center for Machine Learning, Institute for Artificial Intelligence, Tsinghua University, Beijing, China"}]}],"member":"263","reference":[{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref38","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2015","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref33","first-page":"4264","article-title":"Guided evolutionary strategies: Augmenting random search with surrogate gradients","author":"maheswaranathan","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00506"},{"key":"ref31","article-title":"Towards reverse-engineering black-box neural networks","author":"oh","year":"2018","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref30","first-page":"949","article-title":"Natural evolution strategies","volume":"15","author":"wierstra","year":"2014","journal-title":"J Mach Learn Res"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref36","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009","journal-title":"Univ Toronto"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01258-8_39"},{"key":"ref34","first-page":"1127","article-title":"Low frequency adversarial perturbation","author":"guo","year":"0"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref11","article-title":"Bag of tricks for adversarial training","author":"pang","year":"2021","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref12","first-page":"2137","article-title":"Black-box adversarial attacks with limited queries and information","author":"ilyas","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref13","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"brendel","year":"2018","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref17","first-page":"154","article-title":"Practical black-box attacks on deep neural networks using efficient query mechanisms","author":"nitin bhagoji","year":"2018","journal-title":"Proc Eur Conf Comput Vis"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.3301742"},{"key":"ref19","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","author":"ilyas","year":"2019","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-7946-8"},{"key":"ref4","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref27","first-page":"10?934","article-title":"Improving black-box adversarial attacks with a transfer-based prior","author":"cheng","year":"2019","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref3","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref6","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","author":"athalye","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref5","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"ref9","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2018","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref1","author":"goodfellow","year":"2016","journal-title":"Deep Learning"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref45","first-page":"3866","article-title":"NATTACK: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","author":"li","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref22","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2017","journal-title":"Proc Int Conf Learn Representations"},{"key":"ref21","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00745"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/s10208-015-9296-2"},{"key":"ref41","first-page":"2261","article-title":"Densely connected convolutional networks","author":"huang","year":"2017","journal-title":"Proc IEEE Conf Comput Vis Pattern Recognit"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref44","first-page":"5025","article-title":"Adversarial risk and the dangers of evaluating against weak attacks","author":"uesato","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2015.2409256"},{"key":"ref43","article-title":"Wide residual networks","author":"zagoruyko","year":"2016","journal-title":"Proc Brit Mach Vis Conf"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1137\/120880811"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/34\/9940446\/9609659-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/9940446\/09609659.pdf?arnumber=9609659","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,5]],"date-time":"2022-12-05T22:37:16Z","timestamp":1670279836000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9609659\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,1]]},"references-count":46,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2021.3126733","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,1]]}}}