{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T20:18:06Z","timestamp":1783455486802,"version":"3.55.0"},"reference-count":83,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"8","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Korea government","award":["RS-2024-00457216"],"award-info":[{"award-number":["RS-2024-00457216"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1109\/tpami.2026.3681244","type":"journal-article","created":{"date-parts":[[2026,4,6]],"date-time":"2026-04-06T19:56:01Z","timestamp":1775505361000},"page":"9372-9383","source":"Crossref","is-referenced-by-count":0,"title":["Robust Adaptation of Foundation Models With Black-Box Visual Prompting"],"prefix":"10.1109","volume":"48","author":[{"given":"Changdae","family":"Oh","sequence":"first","affiliation":[{"name":"Department of Computer Sciences, University of Wisconsin-Madison, Madison, WI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gyeongdeok","family":"Seo","sequence":"additional","affiliation":[{"name":"Department of Statistics and Data Science, Yonsei University, Seoul, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-4337-4706","authenticated-orcid":false,"given":"Geunyoung","family":"Jung","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, University of Seoul, Seoul, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1720-2085","authenticated-orcid":false,"given":"Zhi-Qi","family":"Cheng","sequence":"additional","affiliation":[{"name":"Tacoma School of Engineering &#x0026; Technology, University of Washington, Tacoma, WA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hosik","family":"Choi","sequence":"additional","affiliation":[{"name":"Department of Urban Big Data Convergence, University of Seoul, Seoul, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9316-9750","authenticated-orcid":false,"given":"Jiyoung","family":"Jung","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, University of Seoul, Seoul, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0082-4280","authenticated-orcid":false,"given":"Kyungwoo","family":"Song","sequence":"additional","affiliation":[{"name":"Department of Statistics and Data Science, Yonsei University, Seoul, South Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"8748","article-title":"Learning transferable visual models from natural language supervision","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Radford"},{"key":"ref2","article-title":"GPT-4 technical report","author":"Achiam","year":"2023"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1516"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.acl-long.353"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19827-4_41"},{"key":"ref6","article-title":"Visual prompting: Modifying pixel space to adapt pre-trained models","author":"Bahng","year":"2022"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01832"},{"key":"ref8","article-title":"An image is worth 16 \u00d7 16 words: Transformers for image recognition at scale","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Dosovitskiy"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19833-5_7"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-022-01653-1"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01631"},{"key":"ref12","article-title":"Unified vision and language prompt learning","author":"Zang","year":"2022"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/9.119632"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02320"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1212"},{"key":"ref16","article-title":"Vision transformer adapter for dense predictions","volume-title":"Proc. 11th Int. Conf. Learn. Representations","author":"Chen"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-023-01891-x"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19833-5_29"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01424"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1576"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-022-01653-1"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01435"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0551"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01047"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01834"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1086"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0944"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0668"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.52202\/075280-1569"},{"key":"ref31","first-page":"9614","article-title":"Transfer learning without knowing: Reprogramming black-box machine learning models with scarce data and limited resources","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Tsai"},{"key":"ref32","first-page":"20841","article-title":"Black-box tuning for language-model-as-a-service","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sun"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.259"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.222"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1162\/106365601750190398"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1162\/106365603321828970"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.3003837"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2011.09.005"},{"issue":"4","key":"ref39","first-page":"482","article-title":"An overview of the simultaneous perturbation method for efficient optimization","volume":"19","author":"Spall","year":"1998","journal-title":"Johns Hopkins APL Tech. Dig."},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00295"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00951"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01553"},{"key":"ref43","article-title":"Benchmarking detection transfer learning with vision transformers","author":"Li","year":"2021"},{"key":"ref44","article-title":"Self-supervised learning is more robust to dataset imbalance","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Liu"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3199617"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/iccv51070.2023.00574"},{"key":"ref47","article-title":"Towards understanding why mask-reconstruction pretraining helps in downstream tasks","author":"Pan","year":"2022"},{"key":"ref48","article-title":"PyTorch image models","author":"Wightman","year":"2019"},{"key":"ref49","first-page":"512","article-title":"What is being transferred in transfer learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Neyshabur"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1016\/S0005-1098(96)00149-5"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1002\/0471722138"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TNN.2007.912315"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2013-181"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.23919\/ECC51009.2020.9143831"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TAC.2000.880982"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.1997.657661"},{"key":"ref57","first-page":"543","article-title":"A method for solving the convex programming problem with convergence rate $o(1\/k^{2})$o(1\/k2)","volume-title":"Proc. USSR Acad. Sci.","volume":"269","author":"Nesterov","year":"1983"},{"key":"ref58","first-page":"1139","article-title":"On the importance of initialization and momentum in deep learning","volume-title":"Proc. 30th Int. Conf. Mach. Learn.","author":"Sutskever"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1137\/120880811"},{"key":"ref60","first-page":"24173","article-title":"Generative pretraining for black-box optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Mashkaria"},{"key":"ref61","article-title":"ZIP: An efficient zeroth-order prompt tuning for black-box vision-language models","volume-title":"Proc. 13th Int. Conf. Learn. Representations","author":"Park"},{"key":"ref62","first-page":"5637","article-title":"WILDS: A benchmark of in-the-wild distribution shifts","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Koh"},{"key":"ref63","first-page":"3731","article-title":"Zeroth-order stochastic variance reduction for nonconvex optimization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Liu"},{"key":"ref64","first-page":"528","article-title":"Learning de-biased representations with biased representations","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bahng"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.461"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/JSTARS.2019.2918242"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2017.2675998"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.215"},{"key":"ref70","article-title":"The intrinsic dimension of images and its impact on learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Pope"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-84858-7"},{"key":"ref72","volume-title":"The Fast Fourier Transform and its Applications","author":"Brigham","year":"1988"},{"key":"ref73","article-title":"AutoVP: An automated visual prompting framework and benchmark","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tsao"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1007\/BF00992696"},{"key":"ref75","first-page":"7204","article-title":"ZO-AdaMM: Zeroth-order adaptive momentum method for black-box optimization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01438"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01206"},{"key":"ref78","first-page":"777","article-title":"Maximum likelihood estimation of intrinsic dimension","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Levina"},{"key":"ref79","article-title":"Comments on \u2018Maximum Likelihood Estimation of Intrinsic Dimension\u2019 by E. Levine and P. Bickel (2004)","author":"MacKay","year":"2005"},{"key":"ref80","first-page":"1310","article-title":"Certified adversarial robustness via randomized smoothing","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Cohen"},{"key":"ref81","article-title":"Certified adversarial robustness via anisotropic randomized smoothing","author":"Hong","year":"2022"},{"issue":"134","key":"ref82","first-page":"1","article-title":"Stochastic gradient descent as approximate Bayesian inference","volume":"18","author":"Stephan","year":"2017","journal-title":"J. Mach. Learn. Res."},{"key":"ref83","article-title":"Revisiting the characteristics of stochastic gradient noise and dynamics","author":"Wu","year":"2021"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/34\/11595778\/11475202.pdf?arnumber=11475202","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T19:45:14Z","timestamp":1783453514000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11475202\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":83,"journal-issue":{"issue":"8"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2026.3681244","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,8]]}}}