{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T03:58:57Z","timestamp":1769745537389,"version":"3.49.0"},"reference-count":41,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2022,7,1]],"date-time":"2022-07-01T00:00:00Z","timestamp":1656633600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,7,1]],"date-time":"2022-07-01T00:00:00Z","timestamp":1656633600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,7,1]],"date-time":"2022-07-01T00:00:00Z","timestamp":1656633600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Innovation Fund of Xidian University","award":["19151110473"],"award-info":[{"award-number":["19151110473"]}]},{"DOI":"10.13039\/100006377","name":"Purdue University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100006377","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004543","name":"China Scholarship Council","doi-asserted-by":"publisher","award":["201906960075"],"award-info":[{"award-number":["201906960075"]}],"id":[{"id":"10.13039\/501100004543","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61932015"],"award-info":[{"award-number":["61932015"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key R&amp;D Project","award":["2017YFB0802203"],"award-info":[{"award-number":["2017YFB0802203"]}]},{"name":"Shaanxi Innovation Team Project","award":["2018TD-007"],"award-info":[{"award-number":["2018TD-007"]}]},{"DOI":"10.13039\/501100013314","name":"Higher Education Discipline Innovation Project","doi-asserted-by":"publisher","award":["B16037"],"award-info":[{"award-number":["B16037"]}],"id":[{"id":"10.13039\/501100013314","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1836203"],"award-info":[{"award-number":["U1836203"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2022,7,1]]},"DOI":"10.1109\/tdsc.2021.3069258","type":"journal-article","created":{"date-parts":[[2021,3,29]],"date-time":"2021-03-29T20:52:00Z","timestamp":1617051120000},"page":"2680-2694","source":"Crossref","is-referenced-by-count":44,"title":["Monitoring-Based Differential Privacy Mechanism Against Query Flooding-Based Model Extraction Attack"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1784-6091","authenticated-orcid":false,"given":"Haonan","family":"Yan","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x0027;an, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1839-1607","authenticated-orcid":false,"given":"Xiaoguang","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x0027;an, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8310-7169","authenticated-orcid":false,"given":"Hui","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x0027;an, China"}]},{"given":"Jiamin","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x0027;an, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0458-0092","authenticated-orcid":false,"given":"Wenhai","family":"Sun","sequence":"additional","affiliation":[{"name":"Department of Computer and Information Technology, Purdue University, West Lafayette, IN, USA"}]},{"given":"Fenghua","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Information Security, Institute of Information Engineering, Chinese Academic of Sciences, Beijing, China"}]}],"member":"263","reference":[{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/COMITCon.2019.8862178"},{"key":"ref5","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","volume-title":"Proc. 25th USENIX Conf. Secur. Symp.","author":"Tram\u00e8r"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref8","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","volume-title":"23rd USENIX Secur. Symp.","author":"Fredrikson"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/THS.2017.7943475"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274740"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-62144-5_4"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2663337"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2940714"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_4"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.07.001"},{"key":"ref21","article-title":"Stealing neural networks via timing side channels","author":"Duddu","year":"2018"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref24","article-title":"Defending against model stealing attacks using deceptive perturbations","author":"Lee","year":"2018"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00041"},{"key":"ref26","first-page":"1003","article-title":"Regression model fitting under differential privacy and model inversion attack","volume-title":"Proc. Int. Conf. Artif. Intell.","author":"Wang"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2019.00063"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW.2009.93"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref31","article-title":"Semi-supervised knowledge transfer for deep learning from private training data","author":"Papernot","year":"2016"},{"issue":"Mar","key":"ref32","first-page":"1069","article-title":"Differentially private empirical risk minimization","volume":"12","author":"Chaudhuri","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref33","article-title":"Understanding gradient clipping in private SGD: A geometric perspective","volume":"33","author":"Chen","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref34","article-title":"Auditing differentially private machine learning: How private is private SGD?","volume":"33","author":"Jagielski","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref35","article-title":"Bypassing the ambient dimension: Private SGD with gradient subspace identification","author":"Zhou","year":"2020"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1111\/j.1469-1809.1972.tb00293.x"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1967.10482916"},{"key":"ref38","first-page":"127","article-title":"Speaker, environment and channel change detection and clustering via the Bayesian information criterion","volume-title":"Proc. DARPA Broadcast News Transcription Understanding Workshop","volume":"8","author":"Chen"},{"issue":"1","key":"ref39","first-page":"108","article-title":"Confidence intervals for double exponential distribution: A simulation approach","volume":"6","author":"Alrasheedi","year":"2012","journal-title":"Int. J. Comput. Math. Sci."},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00296-0_5"},{"key":"ref41","first-page":"2825","article-title":"Scikit-learn: Machine learning in python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"ref43","volume-title":"Digital Design and Computer Architecture: Arm Edition","author":"Harris","year":"2015"},{"key":"ref44","article-title":"Distilling the knowledge in a neural network","author":"Hinton","year":"2015"},{"key":"ref45","first-page":"524","article-title":"Combining the predictions of multiple classifiers: Using competitive learning to initialize neural networks","volume-title":"Proc. Int. Joint Conf. Artif. Intell.","author":"Maclin"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/9821019\/09389670.pdf?arnumber=9389670","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,9]],"date-time":"2024-01-09T23:49:06Z","timestamp":1704844146000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9389670\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,7,1]]},"references-count":41,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2021.3069258","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,7,1]]}}}