{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T03:39:07Z","timestamp":1780544347792,"version":"3.54.1"},"reference-count":115,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFE0209800"],"award-info":[{"award-number":["2023YFE0209800"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62406240"],"award-info":[{"award-number":["62406240"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U244120060"],"award-info":[{"award-number":["U244120060"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tpami.2025.3610085","type":"journal-article","created":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T17:33:51Z","timestamp":1758044031000},"page":"765-780","source":"Crossref","is-referenced-by-count":4,"title":["Revisiting Transferable Adversarial Images: Systemization, Evaluation, and New Insights"],"prefix":"10.1109","volume":"48","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0745-4294","authenticated-orcid":false,"given":"Zhengyu","family":"Zhao","sequence":"first","affiliation":[{"name":"Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hanwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Intelligent Software, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Renjue","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of AI for Industries\/CAS, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ronan","family":"Sicre","sequence":"additional","affiliation":[{"name":"LIS - Ecole Centrale Marseille, Marseille, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0204-0930","authenticated-orcid":false,"given":"Laurent","family":"Amsaleg","sequence":"additional","affiliation":[{"name":"Inria\/University of Rennes\/CNRS\/IRISA, Rennes, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Backes","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr&#x00FC;cken, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8776-8730","authenticated-orcid":false,"given":"Qi","family":"Li","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8967-8525","authenticated-orcid":false,"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6959-0569","authenticated-orcid":false,"given":"Chao","family":"Shen","sequence":"additional","affiliation":[{"name":"Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow","year":"2015"},{"key":"ref2","article-title":"Intriguing properties of neural networks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Szegedy","year":"2014"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref4","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu","year":"2017"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML59370.2024.00027"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3385003.3410925"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_28"},{"key":"ref9","article-title":"Skip connections matter: On the transferability of adversarial examples generated with ResNets","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wu","year":"2020"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00723"},{"key":"ref14","first-page":"85","article-title":"Backpropagating linearly improves transferability of adversarial examples","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"33","author":"Guo","year":"2020"},{"key":"ref15","article-title":"Cross-domain transferability of adversarial perturbations","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Naseer","year":"2019"},{"key":"ref16","article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Lin","year":"2020"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"ref18","first-page":"9759","article-title":"A little robustness goes a long way: Leveraging robust features for targeted transfer attacks","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"34","author":"Springer","year":"2021"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00761"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.5244\/C.35.186"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00754"},{"key":"ref23","article-title":"Rethinking adversarial transferability from a data distribution perspective","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhu","year":"2022"},{"key":"ref24","first-page":"13950","article-title":"Learning transferable adversarial perturbations","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"34","author":"Nakka","year":"2021"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01585"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01457"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI59109.2023.00098"},{"key":"ref28","article-title":"Beyond imagenet attack: Towards crafting adversarial examples for black-box domains","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang","year":"2022"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/cvprw.2018.00211"},{"key":"ref30","first-page":"9561","article-title":"Fundamental tradeoffs between invariance and sensitivity to adversarial perturbations","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Tram\u00e8r","year":"2020"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/icassp49357.2023.10096892"},{"key":"ref32","article-title":"Defending against transfer attacks from public models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Sitawarin","year":"2024"},{"key":"ref33","article-title":"Google cloud vision API","year":"2024"},{"key":"ref34","first-page":"41707","article-title":"Towards evaluating transfer-based attacks systematically, practically, and fairly","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"36","author":"Li","year":"2023"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00790"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00425"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833783"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00059"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00894"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00034"},{"key":"ref43","article-title":"Mitigating adversarial effects through randomization","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie","year":"2018"},{"key":"ref44","first-page":"16805","article-title":"Diffusion models for adversarial purification","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Nie","year":"2022"},{"key":"ref45","first-page":"3533","article-title":"Do adversarially robust imagenet models transfer better?","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"33","author":"Salman","year":"2020"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01333"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1016\/0041-5553(64)90137-5"},{"key":"ref50","first-page":"543","article-title":"A method of solving a convex programming problem with convergence rate $o(1\/k^{2})$o(1\/k2)","volume":"269","author":"Nesterov","year":"1983","journal-title":"Doklady Akademii Nauk"},{"key":"ref51","first-page":"6577","article-title":"Uncovering the connections between adversarial transferability and knowledge transferability","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Liang","year":"2021"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58542-6_34"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_1"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52734.2025.02334"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58621-8_46"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01481"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01182"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_32"},{"key":"ref59","article-title":"How transferable are features in deep neural networks?","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Yosinski","year":"2014"},{"key":"ref60","first-page":"3519","article-title":"Similarity of neural network representations revisited","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Kornblith","year":"2019"},{"key":"ref61","article-title":"Task-generalizable adversarial attack based on perceptual metric","author":"Naseer","year":"2018"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00816"},{"key":"ref63","first-page":"306","article-title":"Who\u2019s afraid of adversarial queries? The impact of image modifications on content-based image retrieval","volume-title":"Proc. Int. Conf. Multimedia Retrieval","author":"Liu","year":"2019"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58517-4_15"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00124"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref68","first-page":"3319","article-title":"Axiomatic attribution for deep networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sundararajan","year":"2017"},{"key":"ref69","article-title":"Transferable perturbations of deep feature distributions","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Inkawhich","year":"2020"},{"key":"ref70","first-page":"20791","article-title":"Perturbing across the feature hierarchy to improve standard and strict blackbox attack transferability","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"33","author":"Inkawhich","year":"2020"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00072"},{"key":"ref72","first-page":"6115","article-title":"On success and simplicity: A second look at transferable targeted attacks","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"34","author":"Zhao","year":"2021"},{"key":"ref73","first-page":"25179","article-title":"Adversarial training helps transfer learning via better representations","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"34","author":"Deng","year":"2021"},{"key":"ref74","article-title":"Adversarially-trained deep nets transfer better: Illustration on image classification","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Utrera","year":"2021"},{"key":"ref75","article-title":"Early stop and adversarial training yield better surrogate model: Very non-robust features harm adversarial transferability","volume-title":"Proc. OpenReview","author":"Zhang","year":"2021"},{"key":"ref76","article-title":"Backpropagating smoothly improves transferability of adversarial examples","volume-title":"Proc. Workshop Adversarial Mach. Learn. Real-World Comput. Vis. Syst. Online Challenges","author":"Zhang","year":"2021"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i7.32722"},{"key":"ref78","article-title":"Adversarial examples are not bugs, they are features","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Ilyas","year":"2019"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_42"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref83","article-title":"On evaluating adversarial robustness","author":"Carlini","year":"2019"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2016.58"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00482"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11499"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1186\/s13635-020-00112-z"},{"key":"ref89","article-title":"Spatially transformed adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xiao","year":"2018"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00467"},{"key":"ref91","first-page":"6991","article-title":"ADef: An iterative algorithm to construct adversarial deformations","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Alaifari","year":"2019"},{"key":"ref92","first-page":"6808","article-title":"Wasserstein adversarial examples via projected sinkhorn iterations","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Wong","year":"2019"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00112"},{"key":"ref94","article-title":"Unrestricted adversarial examples via semantic manipulation","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Bhattad","year":"2020"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00123"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3275057"},{"key":"ref97","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume-title":"Proc. Neural Inf. Process. Syst.","volume":"33","author":"Tramer","year":"2020"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref101","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Simonyan","year":"2015"},{"key":"ref102","article-title":"An image is worth 16x16 words: Transformers for image recognition at scale","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Dosovitskiy","year":"2021"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"ref104","doi-asserted-by":"publisher","DOI":"10.1002\/col.1049"},{"key":"ref105","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10590-1_53"},{"key":"ref107","article-title":"Computer vision with a single (Robust) classifier","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Santurkar","year":"2019"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1109\/WACV.2018.00097"},{"key":"ref109","first-page":"274","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye","year":"2018"},{"key":"ref110","article-title":"Adversarial training for free!","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Shafahi","year":"2019"},{"key":"ref111","article-title":"Fast is better than free: Revisiting adversarial training","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Wong","year":"2020"},{"key":"ref112","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i3.20169"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3547989"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01575"},{"key":"ref115","article-title":"Perceptual adversarial robustness: Defense against unseen threat models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Laidlaw","year":"2021"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/11275622\/11164808.pdf?arnumber=11164808","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T21:01:33Z","timestamp":1764882093000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11164808\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":115,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2025.3610085","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}