{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T01:10:24Z","timestamp":1755825024588,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,6,30]]},"DOI":"10.1145\/3731715.3733325","type":"proceedings-article","created":{"date-parts":[[2025,6,25]],"date-time":"2025-06-25T18:29:43Z","timestamp":1750876183000},"page":"1858-1867","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing Adversarial Transferability via Self-Ensemble Feature Alignment"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-7997-5415","authenticated-orcid":false,"given":"Zhiming","family":"Zhao","sequence":"first","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5894-662X","authenticated-orcid":false,"given":"Jiahao","family":"Chen","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7410-4345","authenticated-orcid":false,"given":"Qingming","family":"Li","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0081-0946","authenticated-orcid":false,"given":"Chunyi","family":"Zhou","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"Zhejiang University, Hangzhou, Zhejiang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,6,30]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109037"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Shouvik Chakraborty and Kalyani Mali. 2020. An overview of biomedical image analysis from the deep learning perspective. Applications of advanced machine intelligence in computer vision and object recognition: emerging research and opportunities (2020) 197--218.","DOI":"10.4018\/978-1-7998-2736-8.ch008"},{"key":"e_1_3_2_1_4_1","volume-title":"Rethinking model ensemble in transfer-based adversarial attacks. arXiv preprint arXiv:2303.09105","author":"Chen Huanran","year":"2023","unstructured":"Huanran Chen, Yichi Zhang, Yinpeng Dong, Xiao Yang, Hang Su, and Jun Zhu. 2023. Rethinking model ensemble in transfer-based adversarial attacks. arXiv preprint arXiv:2303.09105 (2023)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i2.32203"},{"key":"e_1_3_2_1_6_1","first-page":"795","article-title":"Algorithms for learning kernels based on centered alignment","volume":"13","author":"Cortes Corinna","year":"2012","unstructured":"Corinna Cortes, Mehryar Mohri, and Afshin Rostamizadeh. 2012. Algorithms for learning kernels based on centered alignment. The Journal of Machine Learning Research, Vol. 13 (2012), 795--828.","journal-title":"The Journal of Machine Learning Research"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3395118"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_2_1_9_1","volume-title":"An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929","author":"Dosovitskiy Alexey","year":"2020","unstructured":"Alexey Dosovitskiy. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)."},{"key":"e_1_3_2_1_10_1","unstructured":"Stanislav Fort and Balaji Lakshminarayanan. 2024. Ensemble everything everywhere: Multi-scale aggregation for adversarial robustness. arxiv: 2408.05446 [cs.CV] https:\/\/arxiv.org\/abs\/2408.05446"},{"key":"e_1_3_2_1_11_1","first-page":"70141","article-title":"Boosting adversarial transferability by achieving flat local maxima","volume":"36","author":"Ge Zhijin","year":"2023","unstructured":"Zhijin Ge, Hongying Liu, Wang Xiaosen, Fanhua Shang, and Yuanyuan Liu. 2023. Boosting adversarial transferability by achieving flat local maxima. Advances in Neural Information Processing Systems, Vol. 36 (2023), 70141--70161.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.18637\/jss.v023.i12"},{"key":"e_1_3_2_1_13_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01204"},{"key":"e_1_3_2_1_15_1","unstructured":"Jindong Gu Xiaojun Jia Pau de Jorge Wenqain Yu Xinwei Liu Avery Ma Yuan Xun Anjun Hu Ashkan Khakzar Zhijiang Li Xiaochun Cao and Philip Torr. 2024. A Survey on Transferability of Adversarial Examples across Deep Neural Networks. arxiv: 2310.17626 [cs.CV] https:\/\/arxiv.org\/abs\/2310.17626"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_35"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.array.2021.100057"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01172"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"volume-title":"An introduction to statistical learning: With applications in python","author":"James Gareth","key":"e_1_3_2_1_22_1","unstructured":"Gareth James, Daniela Witten, Trevor Hastie, Robert Tibshirani, and Jonathan Taylor. 2023. Linear regression. In An introduction to statistical learning: With applications in python. Springer, 69--134."},{"key":"e_1_3_2_1_23_1","volume-title":"The Relationship Between Network Similarity and Transferability of Adversarial Attacks. arXiv preprint arXiv:2501.18629","author":"Klause Gerrit","year":"2024","unstructured":"Gerrit Klause and Niklas Bunzel. 2024. The Relationship Between Network Similarity and Transferability of Adversarial Attacks. arXiv preprint arXiv:2501.18629 (2024)."},{"key":"e_1_3_2_1_24_1","unstructured":"Gerrit Klause and Niklas Bunzel. 2025. The Relationship Between Network Similarity and Transferability of Adversarial Attacks. arxiv: 2501.18629 [cs.CR] https:\/\/arxiv.org\/abs\/2501.18629"},{"key":"e_1_3_2_1_25_1","volume-title":"International conference on machine learning. PMLR, 3519--3529","author":"Kornblith Simon","year":"2019","unstructured":"Simon Kornblith, Mohammad Norouzi, Honglak Lee, and Geoffrey Hinton. 2019. Similarity of neural network representations revisited. In International conference on machine learning. PMLR, 3519--3529."},{"volume-title":"Artificial intelligence safety and security","author":"Kurakin Alexey","key":"e_1_3_2_1_26_1","unstructured":"Alexey Kurakin, Ian J Goodfellow, and Samy Bengio. 2018. Adversarial examples in the physical world. In Artificial intelligence safety and security. Chapman and Hall\/CRC, 99--112."},{"key":"e_1_3_2_1_27_1","volume-title":"YOLO with adaptive frame control for real-time object detection applications. Multimedia tools and applications","author":"Lee Jeonghun","year":"2022","unstructured":"Jeonghun Lee and Kwang-il Hwang. 2022. YOLO with adaptive frame control for real-time object detection applications. Multimedia tools and applications, Vol. 81, 25 (2022), 36375--36396."},{"key":"e_1_3_2_1_28_1","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Li Qizhang","year":"2024","unstructured":"Qizhang Li, Yiwen Guo, Wangmeng Zuo, and Hao Chen. 2024. Improving adversarial transferability via intermediate-level perturbation decay. Advances in Neural Information Processing Systems, Vol. 36 (2024)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6810"},{"key":"e_1_3_2_1_30_1","volume-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks. arXiv preprint arXiv:1908.06281","author":"Lin Jiadong","year":"2019","unstructured":"Jiadong Lin, Chuanbiao Song, Kun He, Liwei Wang, and John E Hopcroft. 2019. Nesterov accelerated gradient and scale invariance for adversarial attacks. arXiv preprint arXiv:1908.06281 (2019)."},{"key":"e_1_3_2_1_31_1","volume-title":"Delving into Transferable Adversarial Examples and Black-box Attacks. arXiv e-prints","author":"Liu Yanpei","year":"2016","unstructured":"Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2016a. Delving into Transferable Adversarial Examples and Black-box Attacks. arXiv e-prints (2016), arXiv--1611."},{"key":"e_1_3_2_1_32_1","volume-title":"Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770","author":"Liu Yanpei","year":"2016","unstructured":"Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2016b. Delving into transferable adversarial examples and black-box attacks. arXiv preprint arXiv:1611.02770 (2016)."},{"key":"e_1_3_2_1_33_1","volume-title":"Wortman Vaughan (Eds.)","volume":"34","author":"Nakka Krishna","year":"2021","unstructured":"Krishna kanth Nakka and Mathieu Salzmann. 2021. Learning Transferable Adversarial Perturbations. In Advances in Neural Information Processing Systems, M. Ranzato, A. Beygelzimer, Y. Dauphin, P.S. Liang, and J. Wortman Vaughan (Eds.), Vol. 34. Curran Associates, Inc., 13950--13962. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2021\/file\/7486cef2522ee03547cfb970a404a874-Paper.pdf"},{"key":"e_1_3_2_1_34_1","volume-title":"Do Wide and Deep Networks Learn the Same Things. Uncovering How Neural Network Representations Vary with Width and Depth Cs. Lg: arXiv","author":"Nguyen Thao","year":"2010","unstructured":"Thao Nguyen, Maithra Raghu, and Simon Kornblith. 2021. Do Wide and Deep Networks Learn the Same Things. Uncovering How Neural Network Representations Vary with Width and Depth Cs. Lg: arXiv: 2010.15327 (2021)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.3390\/app9050909"},{"key":"e_1_3_2_1_36_1","volume-title":"Wortman Vaughan (Eds.)","volume":"34","author":"Raghu Maithra","year":"2021","unstructured":"Maithra Raghu, Thomas Unterthiner, Simon Kornblith, Chiyuan Zhang, and Alexey Dosovitskiy. 2021. Do Vision Transformers See Like Convolutional Neural Networks?. In Advances in Neural Information Processing Systems, M. Ranzato, A. Beygelzimer, Y. Dauphin, P.S. Liang, and J. Wortman Vaughan (Eds.), Vol. 34. Curran Associates, Inc., 12116--12128. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2021\/file\/652cf38361a209088302ba2b8b7f51e0-Paper.pdf"},{"key":"e_1_3_2_1_37_1","volume-title":"Florian Stimberg, Olivia Wiles, and Timothy A. Mann.","author":"Rebuffi Sylvestre-Alvise","year":"2021","unstructured":"Sylvestre-Alvise Rebuffi, Sven Gowal, Dan Andrei Calian, Florian Stimberg, Olivia Wiles, and Timothy A. Mann. 2021. Fixing Data Augmentation to Improve Adversarial Robustness. ArXiv, Vol. abs\/2103.01946 (2021). https:\/\/api.semanticscholar.org\/CorpusID:232092181"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"crossref","unstructured":"Olga Russakovsky Jia Deng Hao Su Jonathan Krause Sanjeev Satheesh Sean Ma Zhiheng Huang Andrej Karpathy Aditya Khosla Michael Bernstein et al. 2015. Imagenet large scale visual recognition challenge. International journal of computer vision Vol. 115 (2015) 211--252.","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2018.05.198"},{"key":"e_1_3_2_1_40_1","volume-title":"Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very deep convolutional networks for large-scale image recognition. arXiv preprint arXiv:1409.1556 (2014)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v31i1.11231"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_2_1_43_1","volume-title":"International conference on machine learning. PMLR, 6105--6114","author":"Tan Mingxing","year":"2019","unstructured":"Mingxing Tan and Quoc Le. 2019. Efficientnet: Rethinking model scaling for convolutional neural networks. In International conference on machine learning. PMLR, 6105--6114."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00010"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02297"},{"key":"e_1_3_2_1_46_1","unstructured":"Tao Wang Zijian Ying Qianmu Li et al. 2023. Boost Adversarial Transferability by Uniform Scale and Mix Mask Method. arXiv preprint arXiv:2311.12051 (2023)."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"e_1_3_2_1_48_1","unstructured":"Ross Wightman. 2019. PyTorch image models scripts pretrained weights. https:\/\/github.com\/pprp\/timm."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02324"},{"key":"e_1_3_2_1_50_1","volume-title":"Learning similarity with cosine similarity ensemble. Information sciences","author":"Xia Peipei","year":"2015","unstructured":"Peipei Xia, Li Zhang, and Fanzhang Li. 2015. Learning similarity with cosine similarity ensemble. Information sciences, Vol. 307 (2015), 39--52."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"crossref","unstructured":"Yaoyuan Zhang Yu-an Tan Tian Chen Xinrui Liu Quanxin Zhang and Yuanzhang Li. 2022. Enhancing the Transferability of Adversarial Examples with Random Patch.. In IJCAI. 1672--1678.","DOI":"10.24963\/ijcai.2022\/233"},{"key":"e_1_3_2_1_54_1","volume-title":"Face recognition: A literature survey. ACM computing surveys (CSUR)","author":"Zhao Wenyi","year":"2003","unstructured":"Wenyi Zhao, Rama Chellappa, P Jonathon Phillips, and Azriel Rosenfeld. 2003. Face recognition: A literature survey. ACM computing surveys (CSUR), Vol. 35, 4 (2003), 399--458."},{"key":"e_1_3_2_1_55_1","volume-title":"International Conference on Machine Learning. PMLR, 27378--27394","author":"Zhou Daquan","year":"2022","unstructured":"Daquan Zhou, Zhiding Yu, Enze Xie, Chaowei Xiao, Animashree Anandkumar, Jiashi Feng, and Jose M Alvarez. 2022. Understanding the robustness in vision transformers. In International Conference on Machine Learning. PMLR, 27378--27394."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00437"}],"event":{"name":"ICMR '25: International Conference on Multimedia Retrieval","sponsor":["SIGMM ACM Special Interest Group on Multimedia"],"location":"Chicago IL USA","acronym":"ICMR '25"},"container-title":["Proceedings of the 2025 International Conference on Multimedia Retrieval"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3731715.3733325","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T04:10:28Z","timestamp":1755749428000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3731715.3733325"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":56,"alternative-id":["10.1145\/3731715.3733325","10.1145\/3731715"],"URL":"https:\/\/doi.org\/10.1145\/3731715.3733325","relation":{},"subject":[],"published":{"date-parts":[[2025,6,30]]},"assertion":[{"value":"2025-06-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}