{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,21]],"date-time":"2026-06-21T04:17:29Z","timestamp":1782015449353,"version":"3.54.5"},"reference-count":68,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21A20463"],"award-info":[{"award-number":["U21A20463"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102052"],"award-info":[{"award-number":["62102052"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100005230","name":"Natural Science Foundation of Chongqing, China","doi-asserted-by":"publisher","award":["cstc2021jcyj-msxmX0744"],"award-info":[{"award-number":["cstc2021jcyj-msxmX0744"]}],"id":[{"id":"10.13039\/501100005230","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001381","name":"Singapore National Research Foundation under its National Cybersecurity Research and Development Program under NCR","doi-asserted-by":"publisher","award":["NRF2018NCR-NCR009-0001"],"award-info":[{"award-number":["NRF2018NCR-NCR009-0001"]}],"id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001459","name":"Singapore Ministry of Education","doi-asserted-by":"publisher","award":["AcRF Tier 2 MOET2EP20121-0006"],"award-info":[{"award-number":["AcRF Tier 2 MOET2EP20121-0006"]}],"id":[{"id":"10.13039\/501100001459","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001459","name":"Singapore Ministry of Education","doi-asserted-by":"publisher","award":["AcRF Tier 1 RS02\/19"],"award-info":[{"award-number":["AcRF Tier 1 RS02\/19"]}],"id":[{"id":"10.13039\/501100001459","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001475","name":"Nanyang Technological University (NTU) Start-Up Grant","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001475","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Circuits Syst. Video Technol."],"published-print":{"date-parts":[[2022,11]]},"DOI":"10.1109\/tcsvt.2022.3184644","type":"journal-article","created":{"date-parts":[[2022,6,21]],"date-time":"2022-06-21T19:46:11Z","timestamp":1655840771000},"page":"8078-8093","source":"Crossref","is-referenced-by-count":18,"title":["Ownership Verification of DNN Architectures via Hardware Cache Side Channels"],"prefix":"10.1109","volume":"32","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9510-1300","authenticated-orcid":false,"given":"Xiaoxuan","family":"Lou","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6443-5308","authenticated-orcid":false,"given":"Shangwei","family":"Guo","sequence":"additional","affiliation":[{"name":"College of Computer Science, Chongqing University, Chongqing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiwei","family":"Li","sequence":"additional","affiliation":[{"name":"Shannon.AI, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6595-6650","authenticated-orcid":false,"given":"Tianwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2016.90"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3105723"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3063165"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.3045735"},{"key":"ref6","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018","journal-title":"arXiv:1810.04805"},{"key":"ref7","article-title":"Language models are few-shot learners","author":"Brown","year":"2020","journal-title":"arXiv:2005.14165"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-019-1923-7"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2009.2035975"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2019.2911042"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.3009349"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3138795"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3055072"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3065199"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2021.3052468"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"ref18","first-page":"1615","article-title":"Turning your weakness into a strength: Watermarking deep neural networks by backdooring","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Adi"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6976"},{"key":"ref20","first-page":"314","article-title":"Temporal watermarks for deep reinforcement learning models","volume-title":"Proc. 20th Int. Conf. Auton. Agents MultiAgent Syst.","author":"Chen"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TCSVT.2020.3030671"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453079"},{"key":"ref23","article-title":"On the robustness of the backdoor-based watermarking in deep neural networks","author":"Shafieinejad","year":"2019","journal-title":"arXiv:1906.07745"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/icpr48806.2021.9412684"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/500"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329808"},{"key":"ref27","article-title":"Neural network laundering: Removing black-box backdoor watermarks from deep neural networks","author":"Aiken","year":"2020","journal-title":"arXiv:2004.11368"},{"key":"ref28","first-page":"2003","article-title":"Cache telepathy: Leveraging shared resource attacks to learn DNN architectures","volume-title":"Proc. USENIX Secur. Symp.","author":"Yan"},{"key":"ref29","article-title":"How to 0wn NAS in your spare time","author":"Hong","year":"2020","journal-title":"arXiv:2002.06776"},{"key":"ref30","article-title":"Neural architecture search with reinforcement learning","author":"Zoph","year":"2016","journal-title":"arXiv:1611.01578"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00907"},{"key":"ref32","article-title":"Efficient neural architecture search via parameter sharing","author":"Pham","year":"2018","journal-title":"arXiv:1802.03268"},{"key":"ref33","article-title":"Hierarchical representations for efficient architecture search","author":"Liu","year":"2017","journal-title":"arXiv:1711.00436"},{"key":"ref34","article-title":"SMASH: One-shot model architecture search through HyperNetworks","author":"Brock","year":"2017","journal-title":"arXiv:1708.05344"},{"key":"ref35","article-title":"DARTS: Differentiable architecture search","author":"Liu","year":"2018","journal-title":"arXiv:1806.09055"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00186"},{"key":"ref37","first-page":"515","article-title":"CSI NN: Reverse engineering of neural network architectures through electromagnetic side channel","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Batina"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378460"},{"key":"ref39","article-title":"Security analysis of deep neural networks operating in the presence of cache side-channel attacks","author":"Hong","year":"2018","journal-title":"arXiv:1810.03487"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-05318-5_3"},{"key":"ref41","article-title":"NAS-Bench-201: Extending the scope of reproducible neural architecture search","author":"Dong","year":"2020","journal-title":"arXiv:2001.00326"},{"key":"ref42","article-title":"FairNAS: Rethinking evaluation fairness of weight sharing neural architecture search","author":"Chu","year":"2019","journal-title":"arXiv:1907.01845"},{"key":"ref43","first-page":"550","article-title":"Understanding and simplifying one-shot architecture search","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bender"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33014780"},{"key":"ref45","article-title":"Efficient multi-objective neural architecture search via Lamarckian evolution","author":"Elsken","year":"2018","journal-title":"arXiv:1804.09081"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58555-6_28"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"ref48","first-page":"1","article-title":"FLUSH+RELOAD: A high resolution, low noise, L3 cache side-channel attack","volume-title":"Proc. USENIX Secur. Symp.","author":"Yarom"},{"key":"ref49","article-title":"Do deep nets really need to be deep?","author":"Ba","year":"2013","journal-title":"arXiv:1312.6184"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/2487726.2488368"},{"key":"ref52","volume-title":"AMD memory encryption","author":"Kaplan","year":"2016"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_1"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00031"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22038-9_9"},{"key":"ref56","article-title":"The wolf in SGX clothing","author":"Marschalek","year":"2018"},{"key":"ref57","first-page":"1","article-title":"Software grand exposure: SGX cache attacks are practical","volume-title":"Proc. USENIX Workshop Offensive Technol.","author":"Brasser"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3065913.3065915"},{"key":"ref59","first-page":"1","article-title":"High-resolution side channels for untrusted operating systems","volume-title":"Proc. USENIX ATC","author":"H\u00e4hnel"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833714"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-019-04434-z"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359801"},{"key":"ref64","article-title":"Stealing neural networks via timing side channels","author":"Duddu","year":"2018","journal-title":"arXiv:1812.11720"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/DAC.2018.8465773"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01246-5_2"},{"key":"ref67","article-title":"Binarized neural networks: Training deep neural networks with weights and activations constrained to +1 or \u22121","author":"Courbariaux","year":"2016","journal-title":"arXiv:1602.02830"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/1356052.1356053"}],"container-title":["IEEE Transactions on Circuits and Systems for Video Technology"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/76\/9931687\/09801864.pdf?arnumber=9801864","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T04:34:20Z","timestamp":1706762060000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9801864\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11]]},"references-count":68,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tcsvt.2022.3184644","relation":{},"ISSN":["1051-8215","1558-2205"],"issn-type":[{"value":"1051-8215","type":"print"},{"value":"1558-2205","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11]]}}}