{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,16]],"date-time":"2026-01-16T04:30:04Z","timestamp":1768537804380,"version":"3.49.0"},"reference-count":51,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,4,1]],"date-time":"2025-04-01T00:00:00Z","timestamp":1743465600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"NSFC Projects","award":["62025604"],"award-info":[{"award-number":["62025604"]}]},{"name":"NSFC Projects","award":["62441619"],"award-info":[{"award-number":["62441619"]}]},{"name":"NSFC Projects","award":["92370124"],"award-info":[{"award-number":["92370124"]}]},{"name":"NSFC Projects","award":["62350080"],"award-info":[{"award-number":["62350080"]}]},{"name":"Shenzhen Science and Technology Program","award":["KQTD20221101093559018"],"award-info":[{"award-number":["KQTD20221101093559018"]}]},{"DOI":"10.13039\/501100004826","name":"Beijing Natural Science Foundation","doi-asserted-by":"publisher","award":["L247011"],"award-info":[{"award-number":["L247011"]}],"id":[{"id":"10.13039\/501100004826","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2025,4]]},"DOI":"10.1109\/tpami.2025.3526188","type":"journal-article","created":{"date-parts":[[2025,1,6]],"date-time":"2025-01-06T19:29:42Z","timestamp":1736191782000},"page":"2849-2864","source":"Crossref","is-referenced-by-count":4,"title":["Distributionally Location-Aware Transferable Adversarial Patches for Facial Images"],"prefix":"10.1109","volume":"47","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0778-8377","authenticated-orcid":false,"given":"Xingxing","family":"Wei","sequence":"first","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0481-5855","authenticated-orcid":false,"given":"Shouwei","family":"Ruan","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence, Beihang University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1299-683X","authenticated-orcid":false,"given":"Yinpeng","family":"Dong","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8294-6315","authenticated-orcid":false,"given":"Hang","family":"Su","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Institute for Artificial Intelligence, Beijing National Research Center for Information Science and Technology, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7141-708X","authenticated-orcid":false,"given":"Xiaochun","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shenzhen Campus of Sun Yat-Sen University, Shenzhen, China"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref2","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref4","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3317611"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-26409-2_19"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412236"},{"key":"ref10","article-title":"Adversarial patch","author":"Brown","year":"2017"},{"key":"ref11","article-title":"On physical adversarial patches for object detection","author":"Lee","year":"2019"},{"key":"ref12","first-page":"1","article-title":"Generative dynamic patch attack","volume-title":"Proc. Brit. Mach. Vis. Conf.","author":"Li"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3176760"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3231886"},{"key":"ref15","article-title":"Certified defenses for adversarial patches","author":"Chiang","year":"2020"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-68238-5_32"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58574-7_41"},{"key":"ref18","first-page":"2507","article-title":"LaVAN: Localized and visible adversarial noise","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Karmon"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011028"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1002\/int.22349"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-023-00145-0"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3027372"},{"key":"ref23","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICIEVicIVPR48672.2020.9306675"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00401"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2018.00210"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01455"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2019.00143"},{"key":"ref29","article-title":"Meta adversarial training against universal patches","author":"Metzen","year":"2021"},{"key":"ref30","first-page":"3976","article-title":"Knowledge enhanced machine learning pipeline against diverse adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"G\u00fcrel"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/LSP.2016.2603342"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00552"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.713"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.220"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.244"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.3389\/fpsyg.2019.01089"},{"key":"ref38","first-page":"8270","article-title":"Adversarial distributional training for robust deep learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Dong"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.244"},{"key":"ref41","first-page":"2017","article-title":"Spatial transformer networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Jaderberg"},{"key":"ref42","first-page":"2951","article-title":"Practical Bayesian optimization of machine learning algorithms","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Snoek"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref44","first-page":"1","article-title":"Labeled faces in the wild: A database forstudying face recognition in unconstrained environments","volume-title":"Proc. Workshop Faces Real-Life\u2019Images: Detection, Alignment, Recognit.","author":"Huang"},{"key":"ref45","article-title":"Large-scale celebfaces attributes (celeba) dataset","volume":"15","author":"Liu","year":"2018","journal-title":"Retrieved"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-97909-0_46"},{"key":"ref48","article-title":"Meaningful adversarial stickers for face recognition in physical world","author":"Guo","year":"2021"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20595"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9206626"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1213\/ane.0000000000002864"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/10916529\/10829780.pdf?arnumber=10829780","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,7]],"date-time":"2025-03-07T18:40:19Z","timestamp":1741372819000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10829780\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4]]},"references-count":51,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2025.3526188","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4]]}}}