{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T15:46:04Z","timestamp":1759333564789,"version":"3.37.3"},"reference-count":32,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/100015539","name":"Australian Government","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100015539","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179380","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"1348-1365","source":"Crossref","is-referenced-by-count":8,"title":["PublicCheck: Public Integrity Verification for Services of Run-time Deep Models"],"prefix":"10.1109","author":[{"given":"Shuo","family":"Wang","sequence":"first","affiliation":[{"name":"CSIRO&#x2019;s Data61,Australia"}]},{"given":"Sharif","family":"Abuadbba","sequence":"additional","affiliation":[{"name":"CSIRO&#x2019;s Data61,Australia"}]},{"given":"Sidharth","family":"Agarwal","sequence":"additional","affiliation":[{"name":"Indian Institute of Technology,Delhi,India"}]},{"given":"Kristen","family":"Moore","sequence":"additional","affiliation":[{"name":"CSIRO&#x2019;s Data61,Australia"}]},{"given":"Ruoxi","family":"Sun","sequence":"additional","affiliation":[{"name":"CSIRO&#x2019;s Data61,Australia"}]},{"given":"Minhui","family":"Xue","sequence":"additional","affiliation":[{"name":"CSIRO&#x2019;s Data61,Australia"}]},{"given":"Surya","family":"Nepal","sequence":"additional","affiliation":[{"name":"CSIRO&#x2019;s Data61,Australia"}]},{"given":"Seyit","family":"Camtepe","sequence":"additional","affiliation":[{"name":"CSIRO&#x2019;s Data61,Australia"}]},{"given":"Salil","family":"Kanhere","sequence":"additional","affiliation":[{"name":"University of New South Wales,Australia"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484576"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3375751"},{"article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","year":"2017","author":"Chen","key":"ref4"},{"article-title":"Clean-label backdoor attacks","year":"2018","author":"Turner","key":"ref5"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23069"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00486"},{"article-title":"Quantization backdoors to deep learning models","year":"2021","author":"Ma","key":"ref9"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3160359"},{"key":"ref11","first-page":"1615","article-title":"Turning your weakness into a strength: Watermarking deep neural networks by backdooring","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Adi"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"article-title":"Deep neural network fingerprinting by conferrable adversarial examples","volume-title":"International Conference on Learning Representations","author":"Lukas","key":"ref13"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ITCC.2000.844203"},{"key":"ref15","first-page":"2649","article-title":"Disentangling by factorising","volume-title":"International Conference on Machine Learning","author":"Kim"},{"article-title":"Understanding disentangling in beta-vae","year":"2018","author":"Burgess","key":"ref16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref18","first-page":"14 866","article-title":"Generating diverse high-fidelity images with vq-vae-2","author":"Razavi","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref19","article-title":"Neural discrete representation learning","author":"Van Den Oord","year":"2017","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref21","first-page":"3866","article-title":"Nattack: Learning the distributions of adversarial examples for an improved black-box attack on deep neural networks","volume-title":"International Conference on Machine Learning","author":"Li"},{"issue":"1","key":"ref22","first-page":"949","article-title":"Natural evolution strategies","volume":"15","author":"Wierstra","year":"2014","journal-title":"The Journal of Machine Learning Research"},{"key":"ref23","first-page":"15 871","article-title":"Advflow: Inconspicuous black-box adversarial attacks using normalizing flows","volume":"33","author":"Mohaghegh Dolatabadi","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref25"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00813"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"article-title":"Very deep convolutional networks for large-scale image recognition","year":"2014","author":"Simonyan","key":"ref29"},{"article-title":"Trojanzoo: Everything you ever wanted to know about neural backdoors (but were afraid to ask)","year":"2020","author":"Pang","key":"ref30"},{"article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","year":"2017","author":"Gu","key":"ref31"},{"key":"ref32","first-page":"10 675","article-title":"Zero-shot knowledge distillation from a decision-based black-box model","volume-title":"International Conference on Machine Learning","author":"Wang"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","start":{"date-parts":[[2023,5,21]]},"location":"San Francisco, CA, USA","end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179380.pdf?arnumber=10179380","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:11:20Z","timestamp":1721452280000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179380\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":32,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179380","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}