{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T07:41:50Z","timestamp":1783064510361,"version":"3.54.6"},"reference-count":44,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179406","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"382-399","source":"Crossref","is-referenced-by-count":19,"title":["D-DAE: Defense-Penetrating Model Extraction Attacks"],"prefix":"10.1109","author":[{"given":"Yanjiao","family":"Chen","sequence":"first","affiliation":[{"name":"Wuhan University,School of Computer Science,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rui","family":"Guan","sequence":"additional","affiliation":[{"name":"Wuhan University,School of Mathematics and Statistics,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xueluan","family":"Gong","sequence":"additional","affiliation":[{"name":"Wuhan University,School of Computer Science,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianshuo","family":"Dong","sequence":"additional","affiliation":[{"name":"Wuhan University,School of Cyber Science and Engineering,China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meng","family":"Xue","sequence":"additional","affiliation":[{"name":"Wuhan University,School of Computer Science,China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref3","article-title":"Threat Modeling AI\/ML Systems and Dependencies","author":"Kiciman","year":"2022"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref5","first-page":"1309","article-title":"Exploring connections between active learning and model extraction","volume-title":"USENIX Security Symposium","author":"Chandrasekaran"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1142\/9789811232701_0003"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2017.7966217"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref11","author":"Fang","year":"2019","journal-title":"Data-free adversarial distillation"},{"key":"ref12","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","volume-title":"USENIX Security Symposium","author":"Fredrikson"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1137\/120880811"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2000196"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"ref16","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref18","article-title":"Distilling the knowledge in a neural network","author":"Hinton","year":"2015"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref20","article-title":"Protecting dnns from theft using an ensemble of diverse models","volume-title":"International Conference on Learning Representations","author":"Kariyappa"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"ref23","article-title":"Auto-encoding variational bayes","author":"Kingma","year":"2014","journal-title":"CoRR"},{"key":"ref24","author":"Krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.5555\/2999134.2999257"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1989.1.4.541"},{"key":"ref27","author":"LeCun","year":"2010","journal-title":"Mnist handwritten digit database"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00020"},{"key":"ref29","author":"Maas","year":"2013","journal-title":"Rectifier nonlinearities improve neural network acoustic models"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref31","article-title":"Prediction poisoning: Towards defenses against dnn model stealing attacks","volume-title":"International Conference on Learning Representations","author":"Orekondy"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref34","volume-title":"Real-world Affective Faces Database","year":"2022"},{"key":"ref35","article-title":"Adversarial manipulation of deep representations","volume-title":"International Conference on Learning Representations","author":"Sabour"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.2307\/2333709"},{"key":"ref37","author":"Simonyan","year":"2014","journal-title":"Very deep convolutional networks for large-scale image recognition"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"ref39","volume-title":"Introduction to reinforcement learning","volume":"135","author":"Sutton","year":"1998"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"ref42","article-title":"Fashion-mnist: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00034"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3069258"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_4"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179406.pdf?arnumber=10179406","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:16:35Z","timestamp":1721452595000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179406\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":44,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179406","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}