{"id":"https://openalex.org/W4414230226","doi":"https://doi.org/10.1109/tpami.2025.3610085","title":"Revisiting Transferable Adversarial Images: Systemization, Evaluation, and New Insights","display_name":"Revisiting Transferable Adversarial Images: Systemization, Evaluation, and New Insights","publication_year":2025,"publication_date":"2025-09-16","ids":{"openalex":"https://openalex.org/W4414230226","doi":"https://doi.org/10.1109/tpami.2025.3610085","pmid":"https://pubmed.ncbi.nlm.nih.gov/40956694"},"language":"en","primary_location":{"id":"doi:10.1109/tpami.2025.3610085","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2025.3610085","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","pubmed"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://inria.hal.science/hal-05267252","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Zhengyu Zhao","orcid":"https://orcid.org/0000-0003-0745-4294"},"institutions":[{"id":"https://openalex.org/I87445476","display_name":"Xi'an Jiaotong University","ror":"https://ror.org/017zhmm22","country_code":"CN","type":"education","lineage":["https://openalex.org/I87445476"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhengyu Zhao","raw_affiliation_strings":["Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China","Xi&#x0027;an Jiaotong University, Xi&#x0027;an, China"],"raw_orcid":"https://orcid.org/0000-0003-0745-4294","affiliations":[{"raw_affiliation_string":"Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China","institution_ids":["https://openalex.org/I87445476"]},{"raw_affiliation_string":"Xi&#x0027;an Jiaotong University, Xi&#x0027;an, China","institution_ids":["https://openalex.org/I87445476"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107307159","display_name":"Hanwei Zhang","orcid":"https://orcid.org/0000-0002-9690-6952"},"institutions":[{"id":"https://openalex.org/I4210128818","display_name":"Institute of Software","ror":"https://ror.org/033dfsn42","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210128818"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hanwei Zhang","raw_affiliation_strings":["Institute of Intelligent Software, Guangzhou, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Institute of Intelligent Software, Guangzhou, China","institution_ids":["https://openalex.org/I4210128818"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058992602","display_name":"Renjue Li","orcid":"https://orcid.org/0000-0003-2472-0021"},"institutions":[{"id":"https://openalex.org/I3174185376","display_name":"China South Industries Group (China)","ror":"https://ror.org/04n0f2b96","country_code":"CN","type":"company","lineage":["https://openalex.org/I3174185376"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Renjue Li","raw_affiliation_strings":["Institute of AI for Industries/CAS, Nanjing, China","Institute of AI for Industries&#x002F;CAS, Nanjing, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Institute of AI for Industries/CAS, Nanjing, China","institution_ids":["https://openalex.org/I3174185376"]},{"raw_affiliation_string":"Institute of AI for Industries&#x002F;CAS, Nanjing, China","institution_ids":["https://openalex.org/I3174185376"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113027757","display_name":"Ronan Sicre","orcid":null},"institutions":[{"id":"https://openalex.org/I4210114274","display_name":"Laboratoire d\u2019Informatique et Syst\u00e8mes","ror":"https://ror.org/0257sgk90","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I143002897","https://openalex.org/I21491767","https://openalex.org/I4210114274"]},{"id":"https://openalex.org/I4210142724","display_name":"Centrale Marseille","ror":"https://ror.org/040baw385","country_code":"FR","type":"education","lineage":["https://openalex.org/I4210142724"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Ronan Sicre","raw_affiliation_strings":["LIS - Ecole Centrale Marseille, Marseille, France"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"LIS - Ecole Centrale Marseille, Marseille, France","institution_ids":["https://openalex.org/I4210114274","https://openalex.org/I4210142724"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002848228","display_name":"Laurent Amsaleg","orcid":"https://orcid.org/0000-0003-0204-0930"},"institutions":[{"id":"https://openalex.org/I1294671590","display_name":"Centre National de la Recherche Scientifique","ror":"https://ror.org/02feahw73","country_code":"FR","type":"government","lineage":["https://openalex.org/I1294671590"]},{"id":"https://openalex.org/I2802519937","display_name":"Institut de Recherche en Informatique et Syst\u00e8mes Al\u00e9atoires","ror":"https://ror.org/00myn0z94","country_code":"FR","type":"facility","lineage":["https://openalex.org/I1294671590","https://openalex.org/I1294671590","https://openalex.org/I1326498283","https://openalex.org/I205703379","https://openalex.org/I2802204017","https://openalex.org/I2802519937","https://openalex.org/I28221208","https://openalex.org/I4210127572","https://openalex.org/I4210159245","https://openalex.org/I56067802"]},{"id":"https://openalex.org/I56067802","display_name":"Universit\u00e9 de Rennes","ror":"https://ror.org/015m7wh34","country_code":"FR","type":"education","lineage":["https://openalex.org/I56067802"]}],"countries":["FR"],"is_corresponding":false,"raw_author_name":"Laurent Amsaleg","raw_affiliation_strings":["Inria/University of Rennes/CNRS/IRISA, Rennes, France","Inria&#x002F;Univ Rennes&#x002F;CNRS&#x002F;IRISA, Rennes, France"],"raw_orcid":"https://orcid.org/0000-0003-0204-0930","affiliations":[{"raw_affiliation_string":"Inria/University of Rennes/CNRS/IRISA, Rennes, France","institution_ids":["https://openalex.org/I2802519937","https://openalex.org/I56067802","https://openalex.org/I1294671590"]},{"raw_affiliation_string":"Inria&#x002F;Univ Rennes&#x002F;CNRS&#x002F;IRISA, Rennes, France","institution_ids":["https://openalex.org/I2802519937","https://openalex.org/I56067802","https://openalex.org/I1294671590"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112854694","display_name":"Michael Backes","orcid":null},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Backes","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security, Saarbr&#x00FC;cken, Germany","CISPA Helmholtz Center for Information Security, Saarbrucken, Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security, Saarbr&#x00FC;cken, Germany","institution_ids":["https://openalex.org/I4210128801"]},{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security, Saarbrucken, Germany","institution_ids":["https://openalex.org/I4210128801"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Qi Li","orcid":"https://orcid.org/0000-0001-8776-8730"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qi Li","raw_affiliation_strings":["Tsinghua University, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-8776-8730","affiliations":[{"raw_affiliation_string":"Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Qian Wang","orcid":"https://orcid.org/0000-0002-8967-8525"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qian Wang","raw_affiliation_strings":["Wuhan University, Wuhan, China"],"raw_orcid":"https://orcid.org/0000-0002-8967-8525","affiliations":[{"raw_affiliation_string":"Wuhan University, Wuhan, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101843177","display_name":"Chao Shen","orcid":"https://orcid.org/0000-0002-6959-0569"},"institutions":[{"id":"https://openalex.org/I87445476","display_name":"Xi'an Jiaotong University","ror":"https://ror.org/017zhmm22","country_code":"CN","type":"education","lineage":["https://openalex.org/I87445476"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chao Shen","raw_affiliation_strings":["Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China","Xi&#x0027;an Jiaotong University, Xi&#x0027;an, China"],"raw_orcid":"https://orcid.org/0000-0002-6959-0569","affiliations":[{"raw_affiliation_string":"Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China","institution_ids":["https://openalex.org/I87445476"]},{"raw_affiliation_string":"Xi&#x0027;an Jiaotong University, Xi&#x0027;an, China","institution_ids":["https://openalex.org/I87445476"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":9,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":2.8048,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.91618043,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":"48","issue":"1","first_page":"765","last_page":"780"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9836999773979187,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9836999773979187,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13114","display_name":"Image Processing Techniques and Applications","score":0.9817000031471252,"subfield":{"id":"https://openalex.org/subfields/2214","display_name":"Media Technology"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11105","display_name":"Advanced Image Processing Techniques","score":0.9761999845504761,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8823999762535095},{"id":"https://openalex.org/keywords/pipeline","display_name":"Pipeline (software)","score":0.5332000255584717},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.39890000224113464},{"id":"https://openalex.org/keywords/transfer-of-learning","display_name":"Transfer of learning","score":0.3880999982357025},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.361299991607666},{"id":"https://openalex.org/keywords/hyperparameter","display_name":"Hyperparameter","score":0.34060001373291016}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8823999762535095},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7121000289916992},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5674999952316284},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.5332000255584717},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.40540000796318054},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.39890000224113464},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.3880999982357025},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.361299991607666},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3497999906539917},{"id":"https://openalex.org/C8642999","wikidata":"https://www.wikidata.org/wiki/Q4171168","display_name":"Hyperparameter","level":2,"score":0.34060001373291016},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.3337000012397766},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.3095000088214874},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.30820000171661377},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.2849999964237213},{"id":"https://openalex.org/C521332185","wikidata":"https://www.wikidata.org/wiki/Q185816","display_name":"Analogy","level":2,"score":0.25519999861717224},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.25049999356269836}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/tpami.2025.3610085","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tpami.2025.3610085","pdf_url":null,"source":{"id":"https://openalex.org/S199944782","display_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","issn_l":"0162-8828","issn":["0162-8828","1939-3539","2160-9292"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence","raw_type":"journal-article"},{"id":"pmid:40956694","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/40956694","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE transactions on pattern analysis and machine intelligence","raw_type":null},{"id":"pmh:oai:HAL:hal-05267252v1","is_oa":true,"landing_page_url":"https://inria.hal.science/hal-05267252","pdf_url":null,"source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence, 2025, pp.1-16. &#x27E8;10.1109/TPAMI.2025.3610085&#x27E9;","raw_type":"Journal articles"}],"best_oa_location":{"id":"pmh:oai:HAL:hal-05267252v1","is_oa":true,"landing_page_url":"https://inria.hal.science/hal-05267252","pdf_url":null,"source":{"id":"https://openalex.org/S4306402512","display_name":"HAL (Le Centre pour la Communication Scientifique Directe)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1294671590","host_organization_name":"Centre National de la Recherche Scientifique","host_organization_lineage":["https://openalex.org/I1294671590"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Transactions on Pattern Analysis and Machine Intelligence, 2025, pp.1-16. &#x27E8;10.1109/TPAMI.2025.3610085&#x27E9;","raw_type":"Journal articles"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4199456221","display_name":null,"funder_award_id":"U244120060","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8481015266","display_name":null,"funder_award_id":"62406240","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Transferable":[0],"adversarial":[1,190],"images":[2,191],"raise":[3],"critical":[4],"security":[5],"concerns":[6],"for":[7,83,96],"computer":[8],"vision":[9],"systems":[10],"in":[11],"real-world,":[12],"black-box":[13],"attack":[14,84,97],"scenarios.":[15],"Although":[16],"many":[17],"transfer":[18,36,150],"attacks":[19,37,56,161,197],"have":[20,110],"been":[21],"proposed,":[22],"existing":[23,80],"research":[24],"lacks":[25],"a":[26,174],"systematic":[27],"and":[28,47,66,94,115,118,152,173,192,198],"comprehensive":[29,51],"evaluation.":[30],"In":[31,72],"this":[32],"paper,":[33],"we":[34,74],"systemize":[35],"into":[38],"five":[39],"categories":[40],"around":[41],"the":[42,49,62,67,140,156,194],"general":[43],"machine":[44],"learning":[45],"pipeline":[46],"provide":[48],"first":[50],"evaluation,":[52],"with":[53,90],"23":[54],"representative":[55,59],"against":[57],"11":[58],"defenses,":[60],"including":[61],"recent,":[63],"transfer-oriented":[64],"defense":[65],"real-world":[68],"Google":[69],"Cloud":[70],"Vision.":[71],"particular,":[73],"identify":[75],"two":[76],"main":[77],"problems":[78,109],"of":[79,87,100,196],"evaluations:":[81],"(1)":[82,128],"transferability,":[85],"lack":[86,99],"intra-category":[88],"analyses":[89,181],"fair":[91],"hyperparameter":[92],"settings,":[93],"(2)":[95,139],"stealthiness,":[98],"diverse":[101,168],"measures.":[102],"Our":[103],"evaluation":[104],"results":[105,166],"validate":[106],"that":[107,179],"these":[108],"indeed":[111],"caused":[112],"misleading":[113],"conclusions":[114],"missing":[116],"points,":[117],"addressing":[119],"them":[120],"leads":[121],"to":[122,148],"new,":[123],"consensus-challenging":[124],"insights,":[125],"such":[126],"as":[127,184],"an":[129],"early":[130],"attack,":[131],"DI,":[132],"even":[133,146,154],"outperforms":[134],"all":[135],"similar":[136],"follow-up":[137],"ones,":[138],"state-of-the-art":[141],"(white-box)":[142],"defense,":[143],"DiffPure,":[144],"is":[145],"vulnerable":[147],"(black-box)":[149],"attacks,":[151],"(3)":[153],"under":[155],"same":[157],"$L_{p}$Lp":[158],"constraint,":[159],"different":[160,164],"yield":[162],"dramatically":[163],"stealthiness":[165],"regarding":[167],"imperceptibility":[169],"metrics,":[170],"finer-grained":[171],"measures,":[172],"user":[175],"study.":[176],"We":[177],"hope":[178],"our":[180],"will":[182],"serve":[183],"guidance":[185],"on":[186],"properly":[187],"evaluating":[188],"transferable":[189],"advance":[193],"design":[195],"defenses.":[199]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
