{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T08:07:00Z","timestamp":1761898020891,"version":"3.28.0"},"reference-count":56,"publisher":"IEEE","license":[{"start":{"date-parts":[[2024,6,30]],"date-time":"2024-06-30T00:00:00Z","timestamp":1719705600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,6,30]],"date-time":"2024-06-30T00:00:00Z","timestamp":1719705600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,6,30]]},"DOI":"10.1109\/ijcnn60899.2024.10650104","type":"proceedings-article","created":{"date-parts":[[2024,9,9]],"date-time":"2024-09-09T17:35:05Z","timestamp":1725903305000},"page":"1-8","source":"Crossref","is-referenced-by-count":1,"title":["STMS: An Out-Of-Distribution Model Stealing Method Based on Causality"],"prefix":"10.1109","author":[{"given":"Yunfei","family":"Yang","sequence":"first","affiliation":[{"name":"University of Chinese Academy of Sciences,School of Cyber Security,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojun","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Chinese Academy of Sciences,School of Cyber Security,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhendong","family":"Zhao","sequence":"additional","affiliation":[{"name":"University of Chinese Academy of Sciences,School of Cyber Security,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuexin","family":"Xuan","sequence":"additional","affiliation":[{"name":"University of Chinese Academy of Sciences,School of Cyber Security,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bisheng","family":"Tang","sequence":"additional","affiliation":[{"name":"University of Chinese Academy of Sciences,School of Cyber Security,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaoying","family":"Li","sequence":"additional","affiliation":[{"name":"University of Chinese Academy of Sciences,School of Cyber Security,Beijing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.23919\/EUSIPCO.2017.8081663"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1002\/rob.21918"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.5244\/C.29.41"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.2197\/ipsjjip.28.1010"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"ref12","article-title":"Mexmi: Pool-based active model extraction crossover membership inference","author":"Xiao","year":"2022","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00473"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"article-title":"The space of transferable adversarial examples","year":"2017","author":"Tram\u00e8r","key":"ref16"},{"key":"ref17","first-page":"1115","article-title":"Adversarial attack on graph structured data","volume-title":"International conference on machine learning","author":"Dai"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00765"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref20","first-page":"1964","article-title":"Label-only membership inference attacks","volume-title":"International conference on machine learning","author":"Choquette-Choo"},{"article-title":"Dikaios: Privacy auditing of algorithmic fairness via attribute inference attacks","year":"2022","author":"Aalmoes","key":"ref21"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00361"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"article-title":"Towards out-of-distribution generalization: A survey","year":"2021","author":"Shen","key":"ref25"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_12"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i8.26150"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5757"},{"key":"ref29","article-title":"Robust classification under sample selection bias","volume":"27","author":"Liu","year":"2014","journal-title":"Advances in neural information processing systems"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.6024"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1111\/rssb.12167"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220082"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v27i1.8576"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5876"},{"key":"ref35","first-page":"454","article-title":"Independently interpretable lasso: A new regularizer for sparse regression with uncorrelated variables","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Takada"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00533"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/tpami.2023.3321097"},{"article-title":"Improving multi-interest network with stable learning","year":"2022","author":"Liu","key":"ref38"},{"article-title":"Decorrelate irrelevant, purify relevant: Overcome textual spurious correlations from a feature perspective","year":"2022","author":"Dou","key":"ref39"},{"key":"ref40","article-title":"Random features for large-scale kernel machines","volume":"20","author":"Rahimi","year":"2007","journal-title":"Advances in neural information processing systems"},{"key":"ref41","article-title":"A kernel statistical test of independence","volume":"20","author":"Gretton","year":"2007","journal-title":"Advances in neural information processing systems"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1561\/2200000036"},{"key":"ref43","article-title":"Kernel measures of conditional dependence","volume":"20","author":"Fukumizu","year":"2007","journal-title":"Advances in neural information processing systems"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1214\/13-AOS1145"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW53098.2021.00194"},{"article-title":"Categorical reparameterization with gumbel-softmax","year":"2016","author":"Jang","key":"ref46"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.591"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref48"},{"article-title":"Reading digits in natural images with unsupervised feature learning","volume-title":"Proceedings of the NIPS Workshop on Deep Learning and Unsupervised Feature Learning","author":"Yuval","key":"ref49"},{"issue":"7","key":"ref50","first-page":"3","article-title":"Tiny imagenet visual recognition challenge","volume":"7","author":"Le","year":"2015","journal-title":"CS 231N"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"article-title":"Prediction poisoning: Towards defenses against dnn model stealing attacks","year":"2019","author":"Orekondy","key":"ref52"},{"article-title":"Protecting dnns from theft using an ensemble of diverse models","volume-title":"International Conference on Learning Representations","author":"Kariyappa","key":"ref53"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref55","first-page":"1937","article-title":"Entangled watermarks as a defense against model extraction","volume-title":"USENIX Security Symposium","author":"Jia"},{"article-title":"Dataset inference: Ownership resolution in machine learning","year":"2021","author":"Maini","key":"ref56"}],"event":{"name":"2024 International Joint Conference on Neural Networks (IJCNN)","start":{"date-parts":[[2024,6,30]]},"location":"Yokohama, Japan","end":{"date-parts":[[2024,7,5]]}},"container-title":["2024 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10649807\/10649898\/10650104.pdf?arnumber=10650104","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,10]],"date-time":"2024-09-10T05:00:40Z","timestamp":1725944440000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10650104\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,30]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/ijcnn60899.2024.10650104","relation":{},"subject":[],"published":{"date-parts":[[2024,6,30]]}}}