{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T14:11:05Z","timestamp":1779372665147,"version":"3.53.1"},"reference-count":58,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:00:00Z","timestamp":1779321600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["62372037, U24B20179, 62272255, 62302248"],"award-info":[{"award-number":["62372037, U24B20179, 62272255, 62302248"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Jinan \u201cNew 20 Universities\u201d\u2013Project of Introducing Innovation Team","award":["202534038"],"award-info":[{"award-number":["202534038"]}]},{"DOI":"10.13039\/501100014890","name":"Qilu University of Technology","doi-asserted-by":"crossref","award":["2024JDJH05"],"award-info":[{"award-number":["2024JDJH05"]}],"id":[{"id":"10.13039\/501100014890","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Ministry of Finance, PR China","award":["GY2024G-6"],"award-info":[{"award-number":["GY2024G-6"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Multimedia Comput. Commun. Appl."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Transferable adversarial examples (AEs) have attracted considerable attention due to their ability to expose vulnerabilities in black-box deep neural networks (DNNs). However, achieving superior transferability for targeted attacks remains a challenge. In this article, inspired by the observation that AEs with smaller intra-class distances and larger inter-class distances tend to exhibit higher transferability, we propose a novel targeted attack based on Feature Contrastive Optimization (FCO). This attack enhances adversarial transferability by minimizing intra-class distances and maximizing inter-class distances. Specifically, we first define positive samples (belonging to the target class) and negative samples (belonging to non-target classes) that correspond to targeted AEs. Subsequently, leveraging these defined positive and negative samples, we propose two metrics\u2014Intra-class Compactness (IC) and Inter-class Separability (IS)\u2014to construct a novel Feature Contrastive (FC) loss. By integrating this plug-and-play FC loss into standard adversarial objectives, the generated AEs are encouraged to better align with the target class distribution while diverging from those of non-target classes. Extensive experiments on the ImageNet-compatible dataset demonstrate that our approach consistently improves targeted transferability across a broad range of DNN architectures.<\/jats:p>","DOI":"10.1145\/3811823","type":"journal-article","created":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T13:21:46Z","timestamp":1777728106000},"page":"1-21","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Boosting Targeted Adversarial Transferability with Feature Contrastive Optimization"],"prefix":"10.1145","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-9005-1337","authenticated-orcid":false,"given":"Jingtian","family":"Wang","sequence":"first","affiliation":[{"name":"Institute of Information Science, Beijing Key Laboratory of Advanced Information Science and Network Technology, Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6111-9000","authenticated-orcid":false,"given":"Xiaolong","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Information Science, Beijing Key Laboratory of Advanced Information Science and Network Technology, Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5182-2798","authenticated-orcid":false,"given":"Jian","family":"Li","sequence":"additional","affiliation":[{"name":"Qilu University of Technology, Jinan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9030-7393","authenticated-orcid":false,"given":"Bin","family":"Ma","sequence":"additional","affiliation":[{"name":"Qilu University of Technology, Jinan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8581-9554","authenticated-orcid":false,"given":"Yao","family":"Zhao","sequence":"additional","affiliation":[{"name":"Institute of Information Science, Beijing Key Laboratory of Advanced Information Science and Network Technology, Beijing Jiaotong University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6371-6490","authenticated-orcid":false,"given":"Jinhua","family":"Zeng","sequence":"additional","affiliation":[{"name":"Academy of Forensic Science, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,5,21]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02361"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3435937"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.195"},{"key":"e_1_3_1_5_2","first-page":"9355","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","volume":"34","author":"Chu Xiangxiang","year":"2021","unstructured":"Xiangxiang Chu, Zhi Tian, Yuqing Wang, Bo Zhang, Haibing Ren, Xiaolin Wei, Huaxia Xia, and Chunhua Shen. 2021. Twins: Revisiting the design of spatial attention in vision transformers. In Proceedings of the Advances in Neural Information Processing Systems, Vol. 34, 9355\u20139366."},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00482"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"e_1_3_1_9_2","first-page":"611","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Dosovitskiy Alexey","year":"2021","unstructured":"Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, et al. 2021. An image is worth 16x16 words: Transformers for image recognition at scale. In Proceedings of the International Conference on Learning Representations, 611\u2013631."},{"key":"e_1_3_1_10_2","first-page":"2286","volume-title":"Proceedings of the International Conference on Machine Learning","author":"d\u2019Ascoli St\u00e9phane","year":"2021","unstructured":"St\u00e9phane d\u2019Ascoli, Hugo Touvron, Matthew L. Leavitt, Ari S. Morcos, Giulio Biroli, and Levent Sagun. 2021. ConViT: Improving vision transformers with soft convolutional inductive biases. In Proceedings of the International Conference on Machine Learning, 2286\u20132296."},{"key":"e_1_3_1_11_2","first-page":"41882","volume-title":"Advances in Neural Information Processing Systems","volume":"37","author":"Fan Mingyuan","year":"2025","unstructured":"Mingyuan Fan, Xiaodan Li, Cen Chen, Wenmeng Zhou, and Yaliang Li. 2025. Transferability bound theory: Exploring relationship between adversarial transferability and flatness. In Advances in Neural Information Processing Systems, Vol. 37, 41882\u201341908."},{"key":"e_1_3_1_12_2","first-page":"1","volume-title":"Proceedings of the European Conference on Computer Vision","author":"Fang Hao","year":"2024","unstructured":"Hao Fang, Jiawei Kong, Bin Chen, Tao Dai, Hao Wu, and Shu-Tao Xia. 2024. Clip-guided generative networks for transferable targeted adversarial attacks. In Proceedings of the European Conference on Computer Vision, 1\u201319."},{"key":"e_1_3_1_13_2","first-page":"70141","volume-title":"Advances in Neural Information Processing Systems","volume":"36","author":"Ge Zhijin","year":"2023","unstructured":"Zhijin Ge, Hongying Liu, Wang Xiaosen, Fanhua Shang, and Yuanyuan Liu. 2023. Boosting adversarial transferability by achieving flat local maxima. In Advances in Neural Information Processing Systems, Vol. 36, 70141\u201370161."},{"key":"e_1_3_1_14_2","first-page":"1","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In Proceedings of the International Conference on Learning Representations, 1\u201311."},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01204"},{"key":"e_1_3_1_16_2","first-page":"4914","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Guo Chuan","year":"2018","unstructured":"Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens van der Maaten. 2018. Countering adversarial images using input transformations. In Proceedings of the International Conference on Learning Representations, 4914\u20134925."},{"key":"e_1_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01172"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_1_21_2","first-page":"9695","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Inkawhich Nathan","year":"2020","unstructured":"Nathan Inkawhich, Kevin Liang, Lawrence Carin, and Yiran Chen. 2020. Transferable perturbations of deep feature distributions. In Proceedings of the International Conference on Learning Representations, 9695\u20139708."},{"key":"e_1_3_1_22_2","first-page":"20791","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Inkawhich Nathan","year":"2020","unstructured":"Nathan Inkawhich, Kevin Liang, Binghui Wang, Matthew Inkawhich, Lawrence Carin, and Yiran Chen. 2020. Perturbing across the feature hierarchy to improve standard and strict blackbox attack transferability. In Advances in Neural Information Processing Systems, Vol. 33, 20791\u201320801."},{"key":"e_1_3_1_23_2","first-page":"278","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin, Ian J. Goodfellow, and Samy Bengio. 2017. Adversarial machine learning at scale. In Proceedings of the International Conference on Learning Representations, 278\u2013294."},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00072"},{"key":"e_1_3_1_26_2","doi-asserted-by":"crossref","first-page":"4941","DOI":"10.1609\/aaai.v39i5.32523","article-title":"AIM: Additional image guided generation of transferable adversarial attacks","volume":"39","author":"Li Teng","year":"2025","unstructured":"Teng Li, Xingjun Ma, and Yu-Gang Jiang. 2025. AIM: Additional image guided generation of transferable adversarial attacks. In Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 39, 4941\u20134949.","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"e_1_3_1_27_2","first-page":"25802","volume-title":"Proceedings of the Computer Vision and Pattern Recognition Conference","author":"Liang Kaisheng","year":"2025","unstructured":"Kaisheng Liang, Xuelong Dai, Yanjie Li, Dong Wang, and Bin Xiao. 2025. Improving transferable targeted attacks with feature tuning mixup. In Proceedings of the Computer Vision and Pattern Recognition Conference, 25802\u201325811."},{"key":"e_1_3_1_28_2","first-page":"2854","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Lin Jiadong","year":"2020","unstructured":"Jiadong Lin, Chuanbiao Song, Kun He, Liwei Wang, and John E. Hopcroft. 2020. Nesterov accelerated gradient and scale invariance for adversarial attacks. In Proceedings of the International Conference on Learning Representations, 2854\u20132865."},{"key":"e_1_3_1_29_2","first-page":"860","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Liu Zihao","year":"2019","unstructured":"Zihao Liu, Qi Liu, Tao Liu, Nuo Xu, Xue Lin, Yanzhi Wang, and Wujie Wen. 2019. Feature distillation: DNN-oriented JPEG compression against adversarial examples. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 860\u2013868."},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19772-7_32"},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00427"},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00761"},{"key":"e_1_3_1_33_2","first-page":"29845","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","volume":"35","author":"Qin Zeyu","year":"2022","unstructured":"Zeyu Qin, Yanbo Fan, Yi Liu, Li Shen, Yong Zhang, Jue Wang, and Baoyuan Wu. 2022. Boosting the transferability of adversarial attacks with reverse adversarial perturbation. In Proceedings of the Advances in Neural Information Processing Systems, Vol. 35, 29845\u201329858."},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_1_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"e_1_3_1_36_2","first-page":"1","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. In Proceedings of the International Conference on Learning Representations, 1\u201314."},{"key":"e_1_3_1_37_2","first-page":"4278","article-title":"Inception-v4, inception-ResNet and the impact of residual connections on learning","author":"Szegedy Christian","year":"2017","unstructured":"Christian Szegedy, Sergey Ioffe, Vincent Vanhoucke, and Alexander Alemi. 2017. Inception-v4, inception-ResNet and the impact of residual connections on learning. In Proceedings of the AAAI Conference on Artificial Intelligence, 4278\u20134284.","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"e_1_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"e_1_3_1_39_2","first-page":"1","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In Proceedings of the International Conference on Learning Representations, 1\u201310."},{"key":"e_1_3_1_40_2","first-page":"6105","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Tan Mingxing","year":"2019","unstructured":"Mingxing Tan and Quoc Le. 2019. EfficientNet: Rethinking model scaling for convolutional neural networks. In Proceedings of the International Conference on Machine Learning, 6105\u20136114."},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3665496"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00552"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2024.124757"},{"key":"e_1_3_1_44_2","doi-asserted-by":"publisher","DOI":"10.1145\/3766545"},{"key":"e_1_3_1_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02297"},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00196"},{"key":"e_1_3_1_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00425"},{"key":"e_1_3_1_48_2","first-page":"55","volume-title":"Proceedings of the European Conference on Computer Vision","author":"Wang Xiaofeng","year":"2024","unstructured":"Xiaofeng Wang, Zheng Zhu, Guan Huang, Xinze Chen, Jiagang Zhu, and Jiwen Lu. 2024. DriveDreamer: Towards real-world-drive world models for autonomous driving. In Proceedings of the European Conference on Computer Vision. Springer, 55\u201372."},{"key":"e_1_3_1_49_2","first-page":"20534","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Wang Zhibo","year":"2023","unstructured":"Zhibo Wang, Hongshan Yang, Yunhe Feng, Peng Sun, Hengchang Guo, Zhifei Zhang, and Kui Ren. 2023. Towards transferable targeted adversarial examples. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 20534\u201320543."},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01182"},{"key":"e_1_3_1_51_2","first-page":"3561","volume-title":"IEEE Transactions on Information Forensics and Security","volume":"18","author":"Weng Juanjuan","year":"2023","unstructured":"Juanjuan Weng, Zhiming Luo, Shaozi Li, Nicu Sebe, and Zhun Zhong. 2023. Logit margin matters: Improving transferable targeted adversarial attack by logit calibration. IEEE Transactions on Information Forensics and Security 18 (2023), 3561\u20133574."},{"key":"e_1_3_1_52_2","first-page":"960","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Xie Cihang","year":"2018","unstructured":"Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan Yuille. 2018. Mitigating adversarial effects through randomization. In Proceedings of the International Conference on Learning Representations, 960\u2013975."},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00696"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"e_1_3_1_57_2","first-page":"3309","volume-title":"Proceedings of the IEEE International Conference on Image Processing","author":"Zeng Hui","year":"2023","unstructured":"Hui Zeng, Tong Zhang, Biwei Chen, and Anjie Peng. 2023. Enhancing targeted transferability via suppressing high-confidence labels. In Proceedings of the IEEE International Conference on Image Processing, 3309\u20133313."},{"key":"e_1_3_1_58_2","first-page":"8486","volume-title":"Proceedings of the ACM International Conference on Multimedia","author":"Zhang Chaoning","year":"2023","unstructured":"Chaoning Zhang, Philipp Benz, Adil Karjauv, In So Kweon, and Choong Seon Hong. 2023. Simple techniques are sufficient for boosting adversarial transferability. In Proceedings of the ACM International Conference on Multimedia, 8486\u20138494."},{"key":"e_1_3_1_59_2","first-page":"6115","volume-title":"Advances in Neural Information Processing Systems","volume":"34","author":"Zhao Zhengyu","year":"2021","unstructured":"Zhengyu Zhao, Zhuoran Liu, and Martha Larson. 2021. On success and simplicity: A second look at transferable targeted attacks. In Advances in Neural Information Processing Systems, Vol. 34, 6115\u20136128."}],"container-title":["ACM Transactions on Multimedia Computing, Communications, and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3811823","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T13:33:22Z","timestamp":1779370402000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3811823"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,21]]},"references-count":58,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3811823"],"URL":"https:\/\/doi.org\/10.1145\/3811823","relation":{},"ISSN":["1551-6857","1551-6865"],"issn-type":[{"value":"1551-6857","type":"print"},{"value":"1551-6865","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,21]]},"assertion":[{"value":"2025-10-09","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-15","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-05-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}