{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,11]],"date-time":"2026-06-11T15:58:51Z","timestamp":1781193531307,"version":"3.54.1"},"reference-count":90,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100021171","name":"Basic and Applied Basic Research Foundation of Guangdong Province","doi-asserted-by":"publisher","award":["2024B1515020095"],"award-info":[{"award-number":["2024B1515020095"]}],"id":[{"id":"10.13039\/501100021171","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Shenzhen Science and Technology Program","award":["RCYX20210609103057050"],"award-info":[{"award-number":["RCYX20210609103057050"]}]},{"name":"Shenzhen Science and Technology Program","award":["JCYJ20240813113608011"],"award-info":[{"award-number":["JCYJ20240813113608011"]}]},{"name":"Sub-topic of Key R&#x0026;D Projects of the Ministry of Science and Technology","award":["2023YFC3304804"],"award-info":[{"award-number":["2023YFC3304804"]}]},{"name":"Longgang District Key Laboratory of Intelligent Digital Economy Security"},{"name":"Guangdong Provincial Program","award":["2023TQ07A352"],"award-info":[{"award-number":["2023TQ07A352"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tpami.2025.3574432","type":"journal-article","created":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T13:58:33Z","timestamp":1748440713000},"page":"7867-7885","source":"Crossref","is-referenced-by-count":15,"title":["BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks"],"prefix":"10.1109","volume":"47","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-9955-9117","authenticated-orcid":false,"given":"Meixi","family":"Zheng","sequence":"first","affiliation":[{"name":"School of Data Science, Chinese University of Hong Kong, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuanchen","family":"Yan","sequence":"additional","affiliation":[{"name":"School of Data Science, Chinese University of Hong Kong, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1225-1718","authenticated-orcid":false,"given":"Zihao","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Data Science, Chinese University of Hong Kong, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5997-3041","authenticated-orcid":false,"given":"Hongrui","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Data Science, Chinese University of Hong Kong, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2183-5990","authenticated-orcid":false,"given":"Baoyuan","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Data Science, Chinese University of Hong Kong, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3126733"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3169802"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00425"},{"key":"ref4","first-page":"1","article-title":"Making substitute models more Bayesian can enhance transferability of adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Li"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.2978474"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3341639"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3169217"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3286772"},{"key":"ref9","article-title":"Physically adversarial attacks and defenses in computer vision: A survey","author":"Wei","year":"2022"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00428"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/851"},{"key":"ref12","article-title":"MultiRobustBench: Benchmarking robustness against multiple attacks","author":"Dai","year":"2023"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/BTAS.2018.8698567"},{"key":"ref14","article-title":"Adversarial GLUE: A multi-task benchmark for robustness evaluation of language models","author":"Wang","year":"2021"},{"key":"ref15","article-title":"Graph robustness benchmark: Benchmarking the adversarial robustness of graph machine learning","author":"Zheng","year":"2021"},{"key":"ref16","first-page":"1","article-title":"Robustbench: A standardized adversarial robustness benchmark","volume-title":"Proc. Conf. Neural Inf. Process. Syst. Datasets Benchmarks Track","author":"Croce"},{"key":"ref17","article-title":"Technical report on the CleverHans v2. 1.0 adversarial examples library","author":"Papernot","year":"2016"},{"key":"ref18","article-title":"Foolbox: A Python toolbox to benchmark the robustness of machine learning models","author":"Rauber","year":"2017"},{"key":"ref19","article-title":"Adversarial robustness toolbox v1.0.0","author":"Nicolae","year":"2018"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00023"},{"key":"ref21","article-title":"Advertorch v0. 1: An adversarial robustness toolbox based on PyTorch","author":"Ding","year":"2019"},{"key":"ref22","article-title":"secml: A Python library for secure and explainable machine learning","author":"Pintor","year":"2019"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00040"},{"key":"ref24","article-title":"Advbox: A toolbox to generate adversarial examples that fool neural networks","author":"Goodman","year":"2020"},{"key":"ref25","article-title":"DeepRobust: A PyTorch library for adversarial attacks and defenses","author":"Li","year":"2020"},{"key":"ref26","article-title":"Revisiting transferable adversarial image examples: Attack categorization, evaluation guidelines, and new insights","author":"Zhao","year":"2023"},{"key":"ref27","article-title":"TorchAttacks: A PyTorch repository for adversarial attacks","author":"Kim","year":"2020"},{"key":"ref28","article-title":"Towards evaluating transfer-based attacks systematically, practically, and fairly","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref29","article-title":"Adversarial machine learning: A systematic survey of backdoor attack, weight attack and adversarial example","author":"Wu","year":"2023"},{"key":"ref30","first-page":"2484","article-title":"Simple black-box adversarial attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref31","first-page":"4636","article-title":"Parsimonious black-box adversarial attacks via efficient combinatorial optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Moon"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00044"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_19"},{"key":"ref35","first-page":"2142","article-title":"Black-box adversarial attacks with limited queries and information","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Ilyas"},{"key":"ref36","article-title":"Prior convictions: Black-box adversarial attacks with bandits and priors","author":"Ilyas","year":"2018"},{"key":"ref37","first-page":"8061","article-title":"signSGD via zeroth-order Oracle","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu"},{"key":"ref38","first-page":"6837","article-title":"Sign bits are all you need for black-box attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Al-Dujaili"},{"key":"ref39","article-title":"AdvFlow: Inconspicuous black-box adversarial attacks using normalizing flows","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Mohaghegh Dolatabadi"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58595-2_7"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01467"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3194988"},{"key":"ref43","first-page":"3820","article-title":"Subspace attack: Exploiting promising subspaces for query-efficient black-box attacks","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Guo"},{"key":"ref44","first-page":"5348","article-title":"Blackbox attacks via surrogate ensemble search","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Cai"},{"key":"ref45","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00847"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58555-6_17"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3403225"},{"key":"ref50","article-title":"Query-efficient hard-label black-box attack: An optimization-based approach","author":"Cheng","year":"2018"},{"key":"ref51","article-title":"Sign-OPT: A query-efficient hard-label adversarial attack","author":"Cheng","year":"2019"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_10"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00130"},{"key":"ref55","first-page":"3142","article-title":"Nonlinear projection based gradient estimation for query efficient blackbox attacks","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Li"},{"key":"ref56","first-page":"12479","article-title":"Progressive-scale boundary blackbox attack via projective gradient estimation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref59","first-page":"2854","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Lin"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.5244\/C.35.186"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref65","article-title":"Boosting the transferability of adversarial attacks with reverse adversarial perturbation","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Qin"},{"key":"ref66","article-title":"Backpropagating linearly improves transferability of adversarial examples","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Guo"},{"key":"ref67","first-page":"12164","article-title":"Skip connections matter: On the transferability of adversarial examples generated with ResNets","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wu"},{"key":"ref68","first-page":"70141","article-title":"Boosting adversarial transferability by achieving flat local maxima","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Ge"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01457"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_35"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6810"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2022.3211736"},{"key":"ref75","first-page":"1","article-title":"Rethinking adversarial transferability from a data distribution perspective","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhu"},{"key":"ref76","first-page":"1","article-title":"Rethinking model ensemble in transfer-based adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chen"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00414"},{"key":"ref78","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016"},{"key":"ref79","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01333"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref84","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Simonyan"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01167"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2010.11929"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00774"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00986"},{"key":"ref90","first-page":"2235","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/11118328\/11016822.pdf?arnumber=11016822","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,7]],"date-time":"2025-08-07T17:44:23Z","timestamp":1754588663000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11016822\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":90,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2025.3574432","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}