{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,10]],"date-time":"2025-11-10T13:04:07Z","timestamp":1762779847224},"reference-count":23,"publisher":"IEEE","license":[{"start":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T00:00:00Z","timestamp":1601510400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T00:00:00Z","timestamp":1601510400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,10,1]],"date-time":"2020-10-01T00:00:00Z","timestamp":1601510400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020,10]]},"DOI":"10.1109\/icip40778.2020.9191063","type":"proceedings-article","created":{"date-parts":[[2020,9,30]],"date-time":"2020-09-30T20:45:18Z","timestamp":1601498718000},"page":"648-652","source":"Crossref","is-referenced-by-count":15,"title":["Substitute Model Generation for Black-Box Adversarial Attack Based on Knowledge Distillation"],"prefix":"10.1109","author":[{"given":"Weiyu","family":"Cui","sequence":"first","affiliation":[]},{"given":"Xiaorui","family":"Li","sequence":"additional","affiliation":[]},{"given":"Jiawei","family":"Huang","sequence":"additional","affiliation":[]},{"given":"Wenyi","family":"Wang","sequence":"additional","affiliation":[]},{"given":"Shuai","family":"Wang","sequence":"additional","affiliation":[]},{"given":"Jianwen","family":"Chen","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref10","article-title":"Distilling the knowledge in a neural network","author":"hinton","year":"2015","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013771"},{"key":"ref12","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2017","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2017-614"},{"key":"ref15","article-title":"Apprentice: Using knowledge distillation techniques to improve low-precision network accuracy","author":"mishra","year":"2017","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref16","article-title":"Ensemble adversarial training: Attacks and defenses","author":"tramer","year":"2018","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33014886"},{"journal-title":"Learning multiple layers of features from tiny images","year":"2009","author":"alex","key":"ref18"},{"key":"ref19","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2015","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref4","article-title":"Deep-fool: A simple and accurate method to fool deep neural networks","author":"moosavi-dezfooli","year":"2016","journal-title":"IEEE Conference on Computer Vision and Pattern Recognition (CVPR)"},{"key":"ref3","article-title":"Explaining and harnessing adversarial examples","author":"goodfellow","year":"2015","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref2","article-title":"Defensive quantization: When efficiency meets robustness","author":"lin j","year":"2019","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref1","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref9","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"liu","year":"2017","journal-title":"International Conference on Learning Representations (ICLR)"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.308"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298594"}],"event":{"name":"2020 IEEE International Conference on Image Processing (ICIP)","start":{"date-parts":[[2020,10,25]]},"location":"Abu Dhabi, United Arab Emirates","end":{"date-parts":[[2020,10,28]]}},"container-title":["2020 IEEE International Conference on Image Processing (ICIP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9184803\/9190635\/09191063.pdf?arnumber=9191063","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,28]],"date-time":"2022-06-28T00:17:40Z","timestamp":1656375460000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9191063\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10]]},"references-count":23,"URL":"https:\/\/doi.org\/10.1109\/icip40778.2020.9191063","relation":{},"subject":[],"published":{"date-parts":[[2020,10]]}}}