{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T18:45:34Z","timestamp":1780512334288,"version":"3.54.1"},"reference-count":33,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,4,1]],"date-time":"2024-04-01T00:00:00Z","timestamp":1711929600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key R&#x0026;D Program of China","award":["2022YFB3102100"],"award-info":[{"award-number":["2022YFB3102100"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22B2027"],"award-info":[{"award-number":["U22B2027"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62172297"],"award-info":[{"award-number":["62172297"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102262"],"award-info":[{"award-number":["62102262"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61902276"],"award-info":[{"award-number":["61902276"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272311"],"award-info":[{"award-number":["62272311"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Tianjin Intelligent Manufacturing Special Fund Project","award":["20211097"],"award-info":[{"award-number":["20211097"]}]},{"DOI":"10.13039\/501100018525","name":"Key Research and Development Program of Sichuan Province","doi-asserted-by":"publisher","award":["21SYSX0082"],"award-info":[{"award-number":["21SYSX0082"]}],"id":[{"id":"10.13039\/501100018525","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Comput."],"published-print":{"date-parts":[[2024,4]]},"DOI":"10.1109\/tc.2023.3236872","type":"journal-article","created":{"date-parts":[[2023,1,13]],"date-time":"2023-01-13T21:55:45Z","timestamp":1673646945000},"page":"956-969","source":"Crossref","is-referenced-by-count":21,"title":["OFEI: A Semi-Black-Box Android Adversarial Sample Attack Framework Against DLaaS"],"prefix":"10.1109","volume":"73","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8701-3944","authenticated-orcid":false,"given":"Guangquan","family":"Xu","sequence":"first","affiliation":[{"name":"Big Data School, Qingdao Huanghai University, Qingdao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9525-0728","authenticated-orcid":false,"given":"Guohua","family":"Xin","sequence":"additional","affiliation":[{"name":"Tianjin Key Laboratory of Advanced Networking (TANK), College of Intelligence and Computing, Tianjin University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Litao","family":"Jiao","sequence":"additional","affiliation":[{"name":"Big Data School, Qingdao Huanghai University, Qingdao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9104-2975","authenticated-orcid":false,"given":"Jian","family":"Liu","sequence":"additional","affiliation":[{"name":"Tianjin Key Laboratory of Advanced Networking (TANK), College of Intelligence and Computing, Tianjin University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5944-2714","authenticated-orcid":false,"given":"Shaoying","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Informatics and Data Science, Hiroshima Univesrity, Hiroshima, Japan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meiqi","family":"Feng","sequence":"additional","affiliation":[{"name":"Tianjin Key Laboratory of Advanced Networking (TANK), College of Intelligence and Computing, Tianjin University, Tianjin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2572-2355","authenticated-orcid":false,"given":"Xi","family":"Zheng","sequence":"additional","affiliation":[{"name":"Department of Computing, Macquarie University, Macquarie Park, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00020"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3321707.3321749"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23247"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/PerCom45495.2020.9127389"},{"key":"ref6","article-title":"Detecting adversarial samples from artifacts","author":"Feinman","year":"2017"},{"key":"ref7","article-title":"Explaining and harnessing adversarial examples","volume":"1050","author":"Goodfellow","year":"2015","journal-title":"Stat"},{"key":"ref8","article-title":"Transferability of adversarial examples to attack cloud-based image classifier service","author":"Goodman","year":"2020"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3338466.3358928"},{"key":"ref10","article-title":"Attacking and defending machine learning applications of public cloud","author":"Goodman","year":"2020"},{"key":"ref11","article-title":"Adversarial perturbations against deep neural networks for malware classification","author":"Grosse","year":"2016"},{"issue":"4","key":"ref12","first-page":"187","article-title":"Malware detection in cloud computing","volume":"5","author":"Hatem","year":"2014","journal-title":"Int. J. Adv Comput. Sci. Appl."},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2017.0-172"},{"key":"ref14","article-title":"Query-efficient black-box adversarial examples (superceded)","author":"Ilyas","year":"2017"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.5555\/3295222.3295309"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3003571"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3008010"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2016.12.038"},{"key":"ref19","article-title":"Delving into transferable adversarial examples and black-box attacks","author":"Liu","year":"2016"},{"key":"ref20","first-page":"1","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","volume-title":"Proc. 6th Int. Conf. Learn. Representations","author":"Ma"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref22","article-title":"A review on the use of deep learning in android malware detection","author":"Naway","year":"2018"},{"key":"ref23","volume-title":"Bayesian Learning for Neural Networks","volume":"118","author":"RadfordNeal","year":"2012"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3048038"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/s11265-006-0002-0"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref29","article-title":"Gaussian process optimization in the bandit setting: No regret and experimental design","author":"Srinivas","year":"2009"},{"key":"ref30","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2015.2457918"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.001.1900440"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-60239-0_19"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TCYB.2019.2931957"}],"container-title":["IEEE Transactions on Computers"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/12\/10470450\/10016677.pdf?arnumber=10016677","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,16]],"date-time":"2025-06-16T18:57:00Z","timestamp":1750100220000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10016677\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4]]},"references-count":33,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tc.2023.3236872","relation":{},"ISSN":["0018-9340","1557-9956","2326-3814"],"issn-type":[{"value":"0018-9340","type":"print"},{"value":"1557-9956","type":"electronic"},{"value":"2326-3814","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4]]}}}