{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T00:28:02Z","timestamp":1780100882032,"version":"3.54.0"},"reference-count":27,"publisher":"IEEE","license":[{"start":{"date-parts":[[2021,12,12]],"date-time":"2021-12-12T00:00:00Z","timestamp":1639267200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,12,12]],"date-time":"2021-12-12T00:00:00Z","timestamp":1639267200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,12,12]]},"DOI":"10.1109\/host49136.2021.9702279","type":"proceedings-article","created":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T06:21:12Z","timestamp":1644906072000},"page":"248-258","source":"Crossref","is-referenced-by-count":24,"title":["NeurObfuscator: A Full-stack Obfuscation Tool to Mitigate Neural Architecture Stealing"],"prefix":"10.1109","author":[{"given":"Jingtao","family":"Li","sequence":"first","affiliation":[{"name":"School of Electrical Computer and Energy Engineering, Arizona State University,Tempe,AZ,85287"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhezhi","family":"He","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University,Department of Computer Science and Engineering,Shanghai"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Adnan Siraj","family":"Rakin","sequence":"additional","affiliation":[{"name":"School of Electrical Computer and Energy Engineering, Arizona State University,Tempe,AZ,85287"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Deliang","family":"Fan","sequence":"additional","affiliation":[{"name":"School of Electrical Computer and Energy Engineering, Arizona State University,Tempe,AZ,85287"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaitali","family":"Chakrabarti","sequence":"additional","affiliation":[{"name":"School of Electrical Computer and Energy Engineering, Arizona State University,Tempe,AZ,85287"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300259"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3330345.3330389"},{"key":"ref12","first-page":"578","article-title":"(TVM): An automated end-to-end optimizing compiler for deep learning","author":"chen","year":"0","journal-title":"13th USENIX Symposium on Operating Systems Design and Implementation (OSDI 18)"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/375360.375365"},{"key":"ref14","article-title":"Learning to optimize tensor programs","author":"chen","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300274"},{"key":"ref17","article-title":"Neural network model extraction attacks in edge devices by hearing architectural hints","author":"hu","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref18","first-page":"2139","article-title":"Ren dered insecure: Gpu side channel attacks are practical","author":"naghibijouybari","year":"0","journal-title":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2019.00238"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00037"},{"key":"ref27","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref3","article-title":"Stealing neural networks via timing side channels","author":"duddu","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref6","first-page":"601","article-title":"Stealing machine learning models via prediction apis","author":"tramer","year":"0","journal-title":"25th (USENIX) Security Symposium ((USENIX) Security 16)"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2014-80"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/2775054.2694385"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48063.2020.00031"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516660"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378460"},{"key":"ref20","article-title":"Net2net: Accelerating learning via knowledge transfer","author":"chen","year":"2015","journal-title":"ArXiv Preprint"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/BF00058655"},{"key":"ref21","first-page":"243","article-title":"Deep learning architecture search by neuro-cell-based evolution with function-preserving mutations","author":"wistuba","year":"2018","journal-title":"Joint European Con ference on Machine Learning and Knowledge Discovery in Databases"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref23","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref26","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref25","article-title":"Mobilenets: Efficient convo-lutional neural networks for mobile vision applications","author":"howard","year":"2017","journal-title":"ArXiv Preprint"}],"event":{"name":"2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)","location":"Tysons Corner, VA, USA","start":{"date-parts":[[2021,12,12]]},"end":{"date-parts":[[2021,12,15]]}},"container-title":["2021 IEEE International Symposium on Hardware Oriented Security and Trust (HOST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9702149\/9702266\/09702279.pdf?arnumber=9702279","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,16]],"date-time":"2022-05-16T20:44:30Z","timestamp":1652733870000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9702279\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,12]]},"references-count":27,"URL":"https:\/\/doi.org\/10.1109\/host49136.2021.9702279","relation":{},"subject":[],"published":{"date-parts":[[2021,12,12]]}}}