{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T16:26:38Z","timestamp":1773246398567,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,10,27]],"date-time":"2023-10-27T00:00:00Z","timestamp":1698364800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,10,27]]},"DOI":"10.1145\/3650215.3650258","type":"proceedings-article","created":{"date-parts":[[2024,4,16]],"date-time":"2024-04-16T22:11:20Z","timestamp":1713305480000},"page":"245-250","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["A survey of gradient normalization adversarial attack methods"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-3194-4765","authenticated-orcid":false,"given":"Jun","family":"Chen","sequence":"first","affiliation":[{"name":"Department of Information Engineering, Army Academy of Artillery and Air Defense, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-9865-4227","authenticated-orcid":false,"given":"Qidong","family":"Huang","sequence":"additional","affiliation":[{"name":"Department of Information Engineering, Army Academy of Artillery and Air Defense, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-7674-6626","authenticated-orcid":false,"given":"Yunpeng","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Information Engineering, Army Academy of Artillery and Air Defense, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,4,16]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1038\/nature14539"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/3086952"},{"key":"e_1_3_2_1_3_1","volume-title":"IEEE Conference on Computer Vision and Pattern Recognition","author":"Chen","year":"2022","unstructured":"Chen H, Wang P, Wang F, EPro-PnP: Generalized End-to-End Probabilistic Perspective-n-Points for Monocular Object Pose Estimation[C]. IEEE Conference on Computer Vision and Pattern Recognition, 2022."},{"key":"e_1_3_2_1_4_1","volume-title":"IEEE Conference on Computer Vision and Pattern Recognition","author":"Zhenyu","year":"2023","unstructured":"Zhenyu W, Yali L, Xi C, Detecting Everything in the Open World: Towards Universal Object Detection[C]. IEEE Conference on Computer Vision and Pattern Recognition, 2023."},{"key":"e_1_3_2_1_5_1","volume-title":"Speech Denoising without Clean Training Data: a Noise2Noise Approach [C]","author":"Kashyap","year":"2021","unstructured":"Kashyap M, Tambwekar A, Manohara K, Speech Denoising without Clean Training Data: a Noise2Noise Approach [C], 2021."},{"key":"e_1_3_2_1_6_1","volume-title":"Content-Context Factorized Representations for Automated Speech Recognition [C]","author":"Chan","year":"2022","unstructured":"Chan D, Ghosh S. Content-Context Factorized Representations for Automated Speech Recognition [C], 2022."},{"key":"e_1_3_2_1_7_1","volume-title":"ACL","author":"Liu","year":"2022","unstructured":"Liu Q, Zheng R, Bao R, Flooding-X: Improving BERT's Resistance to Adversarial Attacks via Loss-Restricted Fine-Tuning [C]. ACL, 2022."},{"key":"e_1_3_2_1_8_1","volume-title":"A Simple Hash-Based Early Exiting Approach For Language Understanding and Generation [C]. ACL","author":"Sun","year":"2022","unstructured":"Sun T, Liu X, Zhu W, A Simple Hash-Based Early Exiting Approach For Language Understanding and Generation [C]. ACL, 2022."},{"key":"e_1_3_2_1_9_1","volume-title":"CoRR abs\/1312.6199","author":"Christian","year":"2013","unstructured":"Szegedy, Christian \u201cIntriguing properties of neural networks.\u201d CoRR abs\/1312.6199, 2013."},{"key":"e_1_3_2_1_10_1","volume-title":"Towards Adversarially Robust Text Classifiers by Learning to Reweight Clean Examples. Findings [C]. ACL","author":"Xu","year":"2022","unstructured":"Xu J, Zhang C, Zheng X, Towards Adversarially Robust Text Classifiers by Learning to Reweight Clean Examples. Findings [C]. ACL, 2022."},{"key":"e_1_3_2_1_11_1","volume-title":"IEEE Conference on Computer Vision and Pattern Recognition","author":"Li","year":"2023","unstructured":"Li Y, Li Y, Dai X, Physical-World Optical Adversarial Attacks on 3D Face Recognition[C]. IEEE Conference on Computer Vision and Pattern Recognition, 2023."},{"key":"e_1_3_2_1_12_1","volume-title":"ASIACCS","author":"Du","year":"2019","unstructured":"Du T, Ji S, Li J, SirenAttack: Generating Adversarial Audio for End-to-End Acoustic Systems[C]. ASIACCS, 2019."},{"key":"e_1_3_2_1_13_1","volume-title":"International Conference On Learning Representations","author":"Goodfellow I J","year":"2015","unstructured":"Goodfellow I J, Shlens J, Szegedy C. Explaining and harnessing adversarial examples [C]. International Conference On Learning Representations, 2015."},{"issue":"1","key":"e_1_3_2_1_14_1","first-page":"190","article-title":"A review of robustness research on deep learning models","volume":"45","author":"Shouling Ji","year":"2022","unstructured":"Ji Shouling, Du Tianyu, Deng Shuiguang, A review of robustness research on deep learning models. Journal of Computer Science and Technology, 2022, 45(1):190-206.","journal-title":"Journal of Computer Science and Technology"},{"key":"e_1_3_2_1_15_1","volume-title":"International Conference on Machine Learning","author":"Li Y D","year":"2019","unstructured":"Li Y D, Li L J, Wang L Q, Nattack: learning the distributions of adversarial examples for an improved black-box attack on deep neural networks[C]. International Conference on Machine Learning, 2019."},{"key":"e_1_3_2_1_16_1","volume-title":"International Conference on Learning Representations","author":"Huang","year":"2022","unstructured":"Huang Y, Kong A W. Transferable adversarial attack based on integrated gradients[C]. International Conference on Learning Representations, 2022."},{"key":"e_1_3_2_1_17_1","author":"Wenwen Pan","year":"2019","unstructured":"Pan Wenwen, Wang Xinyu, Song Mingli, Overview of Generative Adversarial Network (GAN) [J]. Journal of Software, 2019.","journal-title":"Journal of Software"},{"key":"e_1_3_2_1_18_1","volume-title":"IEEE Conference on Computer Vision and Pattern Recognition","author":"Dong Y P","unstructured":"Dong Y P, Liao F, Pang T, Boosting adversarial Attacks with Momentum[C]. IEEE Conference on Computer Vision and Pattern Recognition, 2018: 9185\u20139193."},{"key":"e_1_3_2_1_19_1","first-page":"86","volume-title":"2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","year":"2016","unstructured":"Moosavi-Dezfooli, Seyed-Mohsen \u201cUniversal Adversarial Perturbations.\u201d 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2016, 86-94."},{"key":"e_1_3_2_1_20_1","volume-title":"International Conference On Learning Representations","author":"Kurakin","year":"2017","unstructured":"Kurakin A, Goodfellow I J, Bengio S. Adversarial examples in the physical world [C]. International Conference On Learning Representations, 2017."},{"key":"e_1_3_2_1_21_1","unstructured":"Madry Aleksander \u201cTowards Deep Learning Models Resistant to Adversarial Attacks.\u201d ArXiv abs\/1706.06083 2017."},{"key":"e_1_3_2_1_22_1","volume-title":"An overview of gradient descent optimization algorithms","author":"Ruder","year":"2016","unstructured":"Ruder S. An overview of gradient descent optimization algorithms, 2016."},{"key":"e_1_3_2_1_23_1","unstructured":"Yang T Lin Q Li Z. Unified Convergence Analysis of Stochastic Momentum Methods for Convex and Non-convex Optimization 2016."},{"key":"e_1_3_2_1_24_1","volume-title":"International Conference On Learning Representations","author":"Lin","year":"2020","unstructured":"Lin J, Song C, He K, Nesterov accelerated gradient and scale invariance for adversarial attacks [C]. International Conference On Learning Representations, 2020."},{"key":"e_1_3_2_1_25_1","first-page":"2725","volume-title":"2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","year":"2018","unstructured":"Xie, Cihang \u201cImproving Transferability of Adversarial Examples With Input Diversity.\u201d 2019 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2018, 2725-2734."},{"key":"e_1_3_2_1_26_1","volume-title":"Why Gradient Clipping Accelerates Training: A Theoretical Justification for Adaptivity","author":"J.","year":"2019","unstructured":"Zhang, J. \u201cWhy Gradient Clipping Accelerates Training: A Theoretical Justification for Adaptivity.\u201d arXiv: Optimization and Control, 2019."},{"key":"e_1_3_2_1_27_1","first-page":"02519","article-title":"Improved Analysis of Clipping Algorithms for Non-convex Optimization","year":"2010","unstructured":"Zhang, Bohang \u201cImproved Analysis of Clipping Algorithms for Non-convex Optimization.\u201d ArXiv abs\/2010.02519. 2020. n. pag.","journal-title":"ArXiv abs\/"},{"key":"e_1_3_2_1_28_1","volume-title":"International Conference on Machine Learning.","author":"Mikael Johansson Vien","year":"2021","unstructured":"Mai, Vien V. and Mikael Johansson. \u201cStability and Convergence of Stochastic Gradient Clipping: Beyond Lipschitz Continuity and Smoothness.\u201d International Conference on Machine Learning. 2021."},{"key":"e_1_3_2_1_29_1","volume-title":"ArXiv abs\/1707.04822","author":"Adams Wei","year":"2017","unstructured":"Yu, Adams Wei \u201cNormalized Gradient with Adaptive Stepsize Method for Deep Neural Network Training.\u201d ArXiv abs\/1707.04822, 2017"},{"key":"e_1_3_2_1_30_1","volume-title":"ArXiv abs\/1611.04831","author":"Yehuda Kfir","year":"2016","unstructured":"Levy, Kfir Yehuda. \u201cThe Power of Normalization: Faster Evasion of Saddle Points.\u201d ArXiv abs\/1611.04831, 2016."},{"key":"e_1_3_2_1_31_1","volume-title":"NIPS","year":"2015","unstructured":"Hazan, Elad \u201cBeyond Convexity: Stochastic Quasi-Convex Optimization.\u201d NIPS, 2015."},{"key":"e_1_3_2_1_32_1","volume-title":"ICLR","author":"Wu Dongxian","year":"2020","unstructured":"Dongxian Wu, Yisen Wang, Shu-Tao Xia, James Bailey, and Xingjun Ma. Skip connections matter: On the transferability of adversarial examples generated with resnets. In ICLR, 2020."},{"key":"e_1_3_2_1_33_1","volume-title":"Backpropagating linearly improves transferability of adversarial examples. Advances in neural information processing systems, 33:85\u201395","author":"Guo Yiwen","year":"2020","unstructured":"Yiwen Guo, Qizhang Li, and Hao Chen. Backpropagating linearly improves transferability of adversarial examples. Advances in neural information processing systems, 33:85\u201395, 2020."},{"issue":"07","key":"e_1_3_2_1_34_1","doi-asserted-by":"crossref","first-page":"11458","DOI":"10.1609\/aaai.v34i07.6810","article-title":"Learning transferable adversarial examples via ghost networks","volume":"34","author":"Li Yingwei","year":"2020","unstructured":"Yingwei Li, Song Bai, Yuyin Zhou, Cihang Xie, Zhishuai Zhang, and Alan Yuille. Learning transferable adversarial examples via ghost networks. Proceedings of the AAAI Conference on Artificial Intelligence, 34(07):11458\u201311465, 2020. AAAI 2022\/10\/30.","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"e_1_3_2_1_35_1","first-page":"13950","article-title":"Learning transferable adversarial perturbations","volume":"34","author":"Salzmann Mathieu","year":"2021","unstructured":"Mathieu Salzmann Learning transferable adversarial perturbations. Advances in Neural Information Processing Systems, 34:13950\u201313962, 2021.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_36_1","first-page":"176","volume-title":"2017 IEEE International Joint Conference on Biometrics (IJCB)","author":"Rozsa Andras","unstructured":"Andras Rozsa, Manuel G\u00fcnther, and Terranee E Boult. Lots about attacking deep features. In 2017 IEEE International Joint Conference on Biometrics (IJCB), pages 168\u2013176. IEEE, 2017."},{"key":"e_1_3_2_1_37_1","volume-title":"Transferable perturbations of deep feature distributions. arXiv preprint arXiv:2004.12519","author":"Inkawhich Nathan","year":"2020","unstructured":"Nathan Inkawhich, Kevin J Liang, Lawrence Carin, and Yiran Chen. Transferable perturbations of deep feature distributions. arXiv preprint arXiv:2004.12519, 2020."},{"key":"e_1_3_2_1_38_1","first-page":"1360","article-title":"Closer look at the transferability of adversarial examples: How they fool different models differently In","author":"Waseda Futa","year":"2023","unstructured":"Futa Waseda, Sosuke Nishikawa, Trung-Nghia Le, Huy H Nguyen, and Isao Echizen. Closer look at the transferability of adversarial examples: How they fool different models differently In Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pages 1360\u20131368, 2023.","journal-title":"Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pages"},{"key":"e_1_3_2_1_39_1","first-page":"7827","volume-title":"Proceedings of the IEEE\/CVF International Conference on Computer Vision","author":"Benz Philipp","year":"2021","unstructured":"Philipp Benz, Chaoning Zhang, and In So Kweon. Batch normalization increases adversarial vulnerability and decreases adversarial transferability: A non-robust feature perspective. In Proceedings of the IEEE\/CVF International Conference on Computer Vision, pages 7818\u20137827, 2021."},{"key":"e_1_3_2_1_40_1","volume-title":"Proceedings of 5th International Conference on Learning Representations","author":"Liu Yanpei","year":"2017","unstructured":"Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. Delving into transferable adversarial examples and black-box attacks. In Proceedings of 5th International Conference on Learning Representations, 2017."},{"key":"e_1_3_2_1_41_1","first-page":"618","volume-title":"Proceedings, Part IV","author":"Gubri Martin","unstructured":"Martin Gubri, Maxime Cordy, Mike Papadakis, Yves Le Traon, and Koushik Sen. Lgv: Boosting adversarial example transferability from large geometric vicinity. In Computer Vision\u2013ECCV 2022: 17th European Conference, Tel Aviv, Israel, October 23\u201327, 2022, Proceedings, Part IV,pages 603\u2013618. Springer, 2022."},{"key":"e_1_3_2_1_42_1","volume-title":"Making substitute models more bayesian can enhance transferability of adversarial examples. arXiv preprint arXiv:2302.05086","author":"Li Qizhang","year":"2023","unstructured":"Qizhang Li, Yiwen Guo, Wangmeng Zuo, and Hao Chen. Making substitute models more bayesian can enhance transferability of adversarial examples. arXiv preprint arXiv:2302.05086, 2023."},{"key":"e_1_3_2_1_43_1","volume-title":"International Conference on Learning Representations","author":"Zhu Yao","year":"2021","unstructured":"Yao Zhu, Jiacheng Sun, and Zhenguo Li. Rethinking adversarial transferability from a data distribution perspective. In International Conference on Learning Representations, 2021."}],"event":{"name":"ICMLCA 2023: 2023 4th International Conference on Machine Learning and Computer Application","location":"Hangzhou China","acronym":"ICMLCA 2023"},"container-title":["2023 4th International Conference on Machine Learning and Computer Application"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3650215.3650258","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3650215.3650258","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:58:10Z","timestamp":1750294690000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3650215.3650258"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,10,27]]},"references-count":43,"alternative-id":["10.1145\/3650215.3650258","10.1145\/3650215"],"URL":"https:\/\/doi.org\/10.1145\/3650215.3650258","relation":{},"subject":[],"published":{"date-parts":[[2023,10,27]]},"assertion":[{"value":"2024-04-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}