{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T18:26:06Z","timestamp":1780511166504,"version":"3.54.1"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031171420","type":"print"},{"value":"9783031171437","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-17143-7_21","type":"book-chapter","created":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T04:04:22Z","timestamp":1663905862000},"page":"425-444","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["MaleficNet: Hiding Malware into\u00a0Deep Neural Networks Using Spread-Spectrum Channel Coding"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5686-3831","authenticated-orcid":false,"given":"Dorjan","family":"Hitaj","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4626-6045","authenticated-orcid":false,"given":"Giulio","family":"Pagnotta","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5925-3027","authenticated-orcid":false,"given":"Briland","family":"Hitaj","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4859-2191","authenticated-orcid":false,"given":"Luigi V.","family":"Mancini","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8996-5076","authenticated-orcid":false,"given":"Fernando","family":"Perez-Cruz","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,9,24]]},"reference":[{"key":"21_CR1","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1504\/IJSN.2015.071829","volume":"10","author":"G Ateniese","year":"2015","unstructured":"Ateniese, G., Mancini, L.V., Spognardi, A., Villani, A., Vitali, D., Felici, G.: Hacking smart machines with smarter ones: how to extract meaningful data from machine learning classifiers. Int. J. Secur. Networks 10, 137\u2013150 (2015)","journal-title":"Int. J. Secur. Networks"},{"key":"21_CR2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4899-3276-1","volume-title":"Error Correcting Codes A Mathematical Introduction","author":"DJ Baylis","year":"1998","unstructured":"Baylis, D.J.: Error Correcting Codes A Mathematical Introduction. Chapman and Hall\/CRC, Boca Raton (1998)"},{"key":"21_CR3","unstructured":"Berti, J.: AI-based supply chains: using intelligent automation to build resiliency (2021). https:\/\/www.ibm.com\/blogs\/supply-chain\/ai-based-supply-chains-using-intelligent-automation-to-build-resiliency\/"},{"key":"21_CR4","unstructured":"Brown, T., et al.: Language models are few-shot learners. In: Advances in Neural Information Processing Systems. Curran Associates, Inc. (2020)"},{"key":"21_CR5","doi-asserted-by":"publisher","first-page":"727","DOI":"10.1016\/j.sigpro.2009.08.010","volume":"90","author":"A Cheddad","year":"2010","unstructured":"Cheddad, A., Condell, J., Curran, K., Mc Kevitt, P.: Digital image steganography: survey and analysis of current methods. Signal Process. 90, 727\u2013752 (2010)","journal-title":"Signal Process."},{"key":"21_CR6","doi-asserted-by":"crossref","unstructured":"Chollet, F.: Xception: deep learning with depthwise separable convolutions. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition (2017)","DOI":"10.1109\/CVPR.2017.195"},{"key":"21_CR7","unstructured":"Christian, S., Liu, W., Jia, Y.: Going deeper with convolutions. In: IEEE Conference on Computer Vision and Pattern Recognition (2015)"},{"key":"21_CR8","volume-title":"Elements of Information Theory","author":"TM Cover","year":"2006","unstructured":"Cover, T.M., Thomas, J.A.: Elements of Information Theory. Wiley, Hoboken (2006)"},{"key":"21_CR9","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/TASL.2011.2134090","volume":"20","author":"GE Dahl","year":"2012","unstructured":"Dahl, G.E., Yu, D., Deng, L., Acero, A.: Context-dependent pre-trained deep neural networks for large-vocabulary speech recognition. IEEE Trans. Audio Speech Lang. Process. 20, 30\u201342 (2012)","journal-title":"IEEE Trans. Audio Speech Lang. Process."},{"key":"21_CR10","doi-asserted-by":"publisher","unstructured":"De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., Mancini, L.V.: Evading behavioral classifiers: a comprehensive analysis on evading ransomware detection techniques. Neural Comput. Appl. 1\u201320 (2022). https:\/\/doi.org\/10.1007\/s00521-022-07096-6","DOI":"10.1007\/s00521-022-07096-6"},{"key":"21_CR11","doi-asserted-by":"crossref","unstructured":"De Gaspari, F., Hitaj, D., Pagnotta, G., De Carli, L., Mancini, L.V.: Reliable detection of compressed and encrypted data. Neural Comput. Appl. (2022)","DOI":"10.1007\/s00521-022-07586-7"},{"key":"21_CR12","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., Fei-Fei, L.: Imagenet: a large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition (2009)","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"21_CR13","unstructured":"Devlin, J., Chang, M., Lee, K., Toutanova, K.: BERT: pre-training of deep bidirectional transformers for language understanding. In: NAACL-HLT (2019)"},{"key":"21_CR14","doi-asserted-by":"crossref","unstructured":"Domhan, T., Hasler, E., Tran, K., Trenous, S., Byrne, B., Hieber, F.: The devil is in the details: on the pitfalls of vocabulary selection in neural machine translation. In: Proceedings of the 2022 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (2022)","DOI":"10.18653\/v1\/2022.naacl-main.136"},{"key":"21_CR15","doi-asserted-by":"crossref","unstructured":"Graves, A., Mohamed, A., Hinton, G.: Speech recognition with deep recurrent neural networks. In: 2013 IEEE International Conference on Acoustics, Speech and Signal Processing (2013)","DOI":"10.1109\/ICASSP.2013.6638947"},{"key":"21_CR16","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: BadNets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019)","journal-title":"IEEE Access"},{"key":"21_CR17","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: 2016 IEEE Conference on Computer Vision and Pattern Recognition (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"21_CR18","doi-asserted-by":"crossref","unstructured":"Hitaj, B., Gasti, P., Ateniese, G., Perez-Cruz, F.: PassGAN: a deep learning approach for password guessing. Appl. Cryptography Network Secur. (2019)","DOI":"10.1007\/978-3-030-21568-2_11"},{"key":"21_CR19","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der Maaten, L., Weinberger, K.Q.: Densely connected convolutional networks. In: 2017 IEEE Conference on Computer Vision and Pattern Recognition (2017)","DOI":"10.1109\/CVPR.2017.243"},{"key":"21_CR20","unstructured":"Koh, J.Y.: Model zoo. http:\/\/modelzoo.co\/. Accessed November 2021"},{"key":"21_CR21","unstructured":"Krizhevsky, A., Hinton, G.: Learning multiple layers of features from tiny images. Technical report, University of Toronto, Toronto, Ontario (2009)"},{"key":"21_CR22","unstructured":"Krizhevsky, A., Sutskever, I., Hinton, G.E.: ImageNet classification with deep convolutional neural networks. In: Proceedings of the 25th International Conference on Neural Information Processing Systems (2012)"},{"key":"21_CR23","unstructured":"LeCun, Y., Cortes, C.: MNIST handwritten digit database. https:\/\/yann.lecun.com\/exdb\/mnist\/ (2010)"},{"key":"21_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"K Liu","year":"2018","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: defending against backdooring attacks on deep neural networks. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) RAID 2018. LNCS, vol. 11050, pp. 273\u2013294. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13"},{"key":"21_CR25","doi-asserted-by":"crossref","unstructured":"Liu, T., Liu, Z., Liu, Q., Wen, W., Xu, W., Li, M.: StegoNet: turn deep neural network into a stegomalware. In: Annual Computer Security Applications Conference (2020)","DOI":"10.1145\/3427228.3427268"},{"key":"21_CR26","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"384","DOI":"10.1007\/978-3-030-86514-6_24","volume-title":"Machine Learning and Knowledge Discovery in Databases. Applied Data Science Track","author":"MA Lozano","year":"2021","unstructured":"Lozano, M.A., et al.: Open data science to fight COVID-19: winning the 500k XPRIZE pandemic response challenge. In: Dong, Y., Kourtellis, N., Hammer, B., Lozano, J.A. (eds.) ECML PKDD 2021. LNCS (LNAI), vol. 12978, pp. 384\u2013399. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-86514-6_24"},{"key":"21_CR27","unstructured":"Metadefender: Multiple security engines. https:\/\/www.metadefender.com\/. Accessed Apr 2022"},{"key":"21_CR28","volume-title":"Machine Learning","author":"TM Mitchell","year":"1997","unstructured":"Mitchell, T.M.: Machine Learning. McGraw-Hill Inc, New York (1997)"},{"key":"21_CR29","unstructured":"Nativ, Y.: thezoo - a live malware repository. https:\/\/thezoo.morirt.com\/. Accessed Nov 2021"},{"key":"21_CR30","doi-asserted-by":"crossref","unstructured":"Pagnotta, G., Hitaj, D., De Gaspari, F., Mancini, L.V.: Passflow: guessing passwords with generative flows. In: 2022 52nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (2022)","DOI":"10.1109\/DSN53405.2022.00035"},{"key":"21_CR31","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9780511791338","volume-title":"Modern Coding Theory","author":"T Richardson","year":"2008","unstructured":"Richardson, T., Urbanke, R.: Modern Coding Theory. Cambridge University Press, Cambridge (2008)"},{"key":"21_CR32","doi-asserted-by":"publisher","first-page":"1261","DOI":"10.1109\/18.335940","volume":"40","author":"M Rupf","year":"1994","unstructured":"Rupf, M., Massey, J.L.: Optimum sequence multisets for synchronous code-division multiple-access channels. IEEE Trans. Inf. Theory 40, 1261\u20131266 (1994)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"21_CR33","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition (2014)"},{"key":"21_CR34","unstructured":"Stevens, R., Suciu, O., Ruef, A., Hong, S., Hicks, M., Dumitra\u00e7, T.: Summoning demons: the pursuit of exploitable bugs in machine learning (2017)"},{"key":"21_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"496","DOI":"10.1007\/978-3-319-16745-9_27","volume-title":"Information Security and Cryptology","author":"G Suarez-Tangil","year":"2015","unstructured":"Suarez-Tangil, G., Tapiador, J.E., Peris-Lopez, P.: Stegomalware: playing hide and seek with malicious components in smartphone apps. In: Lin, D., Yung, M., Zhou, J. (eds.) Inscrypt 2014. LNCS, vol. 8957, pp. 496\u2013515. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-16745-9_27"},{"key":"21_CR36","doi-asserted-by":"publisher","first-page":"549","DOI":"10.1007\/978-3-030-75343-6_9","volume-title":"Principles of Spread-Spectrum Communication Systems","author":"D Torrieri","year":"2022","unstructured":"Torrieri, D.: Iterative channel estimation, demodulation, and decoding. In: Principles of Spread-Spectrum Communication Systems, pp. 549\u2013594. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-030-75343-6_9"},{"key":"21_CR37","unstructured":"Vaidya, S.: Openstego. https:\/\/github.com\/syvaidya\/openstego\/. Accessed Apr 2022"},{"key":"21_CR38","volume-title":"Multiuser Detection","author":"S Verdu","year":"1998","unstructured":"Verdu, S.: Multiuser Detection. Cambridge University Press, Cambridge (1998)"},{"key":"21_CR39","unstructured":"Verdu, S.: Capacity region of gaussian CDMA channels: the symbol synchronous case. In: Proceedings of the 24th Allerton Conference (1986)"},{"key":"21_CR40","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/MWC.2002.1028876","volume":"9","author":"S Verdu","year":"2002","unstructured":"Verdu, S.: Recent results on the capacity of wideband channels in the low-power regime. IEEE Wirel. Commun. 9, 40\u201345 (2002)","journal-title":"IEEE Wirel. Commun."},{"key":"21_CR41","doi-asserted-by":"publisher","first-page":"1984","DOI":"10.1109\/18.782121","volume":"45","author":"P Viswanath","year":"1999","unstructured":"Viswanath, P., Anantharam, V.: Optimal sequences and sum capacity of synchronous CDMA systems. IEEE Trans. Inf. Theory 45, 1984\u20131991 (1999)","journal-title":"IEEE Trans. Inf. Theory"},{"key":"21_CR42","doi-asserted-by":"crossref","unstructured":"Wang, Z., Liu, C., Cui, X.: Evilmodel: hiding malware inside of neural network models. In: 2021 IEEE Symposium on Computers and Communications (2021)","DOI":"10.1109\/ISCC53001.2021.9631425"},{"key":"21_CR43","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102807","volume":"120","author":"Z Wang","year":"2022","unstructured":"Wang, Z., Liu, C., Cui, X., Yin, J., Wang, X.: Evilmodel 2.0: bringing neural network models into malware attacks. Comput. Secur. 120, 102807 (2022)","journal-title":"Comput. Secur."},{"key":"21_CR44","unstructured":"Xiao, H., Rasul, K., Vollgraf, R.: Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. ArXiv:abs\/1708.07747 (2017)"},{"key":"21_CR45","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"818","DOI":"10.1007\/978-3-319-10590-1_53","volume-title":"Computer Vision \u2013 ECCV 2014","author":"MD Zeiler","year":"2014","unstructured":"Zeiler, M.D., Fergus, R.: Visualizing and understanding convolutional networks. In: Fleet, D., Pajdla, T., Schiele, B., Tuytelaars, T. (eds.) ECCV 2014. LNCS, vol. 8689, pp. 818\u2013833. Springer, Cham (2014). https:\/\/doi.org\/10.1007\/978-3-319-10590-1_53"},{"key":"21_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, W., Zhai, M., Huang, Z., Liu, C., Li, W., Cao, Y.: Towards end-to-end speech recognition with deep multipath convolutional neural networks. In: Intelligent Robotics and Applications (2019)","DOI":"10.1007\/978-3-030-27529-7_29"}],"container-title":["Lecture Notes in Computer Science","Computer Security \u2013 ESORICS 2022"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-17143-7_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,9,23]],"date-time":"2022-09-23T04:08:12Z","timestamp":1663906092000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-17143-7_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031171420","9783031171437"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-17143-7_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"24 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2022.compute.dtu.dk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"562","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"104","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3.4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"12","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}