{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,25]],"date-time":"2025-09-25T16:07:21Z","timestamp":1758816441777},"reference-count":23,"publisher":"IEEE","license":[{"start":{"date-parts":[[2019,7,1]],"date-time":"2019-07-01T00:00:00Z","timestamp":1561939200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2019,7,1]],"date-time":"2019-07-01T00:00:00Z","timestamp":1561939200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2019,7,1]],"date-time":"2019-07-01T00:00:00Z","timestamp":1561939200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019,7]]},"DOI":"10.1109\/ijcnn.2019.8851798","type":"proceedings-article","created":{"date-parts":[[2019,9,30]],"date-time":"2019-09-30T23:44:32Z","timestamp":1569887072000},"page":"1-8","source":"Crossref","is-referenced-by-count":11,"title":["Stealing Knowledge from Protected Deep Neural Networks Using Composite Unlabeled Data"],"prefix":"10.1109","author":[{"given":"Itay","family":"Mosafi","sequence":"first","affiliation":[]},{"given":"Eli Omid","family":"David","sequence":"additional","affiliation":[]},{"given":"Nathan S.","family":"Netanyahu","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"article-title":"Adversarial frontier stitching for remote neural network watermarking","year":"2017","author":"merrer","key":"ref10"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/s13735-018-0147-1"},{"article-title":"Deepsigns: A generic watermarking framework for IP protection of deep learning models","year":"2018","author":"rouhani","key":"ref12"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/s13735-018-0147-1"},{"article-title":"Have you stolen my model&#x0192; evasion attacks against deep neural network watermarking techniques","year":"2018","author":"hitaj","key":"ref14"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref16","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","author":"tramer","year":"2016","journal-title":"Proceedings of the USENIX Security Symposium"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","year":"2017","author":"gu","key":"ref19"},{"key":"ref4","first-page":"2722","article-title":"DeepDriving: Learning affordance for direct perception in autonomous driving","author":"chen","year":"2015","journal-title":"Proceedings of the IEEE International Conference on Computer Vision"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-68612-7_11"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/D15-1166"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2003.815962"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-92957-4_31"},{"key":"ref2","first-page":"91","article-title":"Faster R-CNN: Towards realtime object detection with region proposal networks","author":"ren","year":"2015","journal-title":"Advances in neural information processing systems"},{"key":"ref1","first-page":"1440","article-title":"Fast R-CNN","author":"girshick","year":"2015","journal-title":"Proceedings of the IEEE International Conference on Computer Vision"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"article-title":"Defending against model stealing attacks using deceptive perturbations","year":"2018","author":"lee","key":"ref20"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref21","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009","journal-title":"Tech Rep"},{"article-title":"Very deep convolutional networks for large-scale image recognition","year":"2014","author":"simonyan","key":"ref23"}],"event":{"name":"2019 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2019,7,14]]},"location":"Budapest, Hungary","end":{"date-parts":[[2019,7,19]]}},"container-title":["2019 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8840768\/8851681\/08851798.pdf?arnumber=8851798","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,17]],"date-time":"2022-07-17T17:51:28Z","timestamp":1658080288000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8851798\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,7]]},"references-count":23,"URL":"https:\/\/doi.org\/10.1109\/ijcnn.2019.8851798","relation":{},"subject":[],"published":{"date-parts":[[2019,7]]}}}