{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T15:05:01Z","timestamp":1775228701669,"version":"3.50.1"},"reference-count":63,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2021YFB3100300"],"award-info":[{"award-number":["2021YFB3100300"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20A20178"],"award-info":[{"award-number":["U20A20178"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072395"],"award-info":[{"award-number":["62072395"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62206207"],"award-info":[{"award-number":["62206207"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,7]]},"DOI":"10.1109\/tdsc.2024.3520599","type":"journal-article","created":{"date-parts":[[2025,1,2]],"date-time":"2025-01-02T14:46:08Z","timestamp":1735829168000},"page":"3179-3191","source":"Crossref","is-referenced-by-count":4,"title":["FDINet: Protecting Against DNN Model Extraction Using Feature Distortion Index"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4680-5536","authenticated-orcid":false,"given":"Hongwei","family":"Yao","sequence":"first","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Zhejiang, China"}]},{"given":"Zheng","family":"Li","sequence":"additional","affiliation":[{"name":"German National Big Science Institution within the Helmholtz Association, Saarbr&#x00FC;cken, Germany"}]},{"given":"Haiqin","family":"Weng","sequence":"additional","affiliation":[{"name":"Department of Security and Trust Division, Ant Group, Hangzhou, China"}]},{"given":"Feng","family":"Xue","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7872-6969","authenticated-orcid":false,"given":"Zhan","family":"Qin","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Zhejiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1969-2591","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"The State Key Laboratory of Blockchain and Data Security, Zhejiang University, Zhejiang, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3414535"},{"key":"ref2","article-title":"Machine learning as a service market size","year":"2023"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref4","first-page":"1345","article-title":"High accuracy and high fidelity extraction of neural networks","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Jagielski"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833607"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr52729.2023.01571"},{"key":"ref7","article-title":"Thieves on sesame street! Model extraction of bert-based APIs","volume-title":"Proc. 8th Int. Conf. Learn. Representations","author":"Krishna"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2000196"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00473"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01166"},{"key":"ref14","article-title":"Interpreting blackbox models via model extraction","author":"Bastani","year":"2017"},{"key":"ref15","article-title":"MEME: Generating RNN model explanations via model extraction","author":"Kazhdan","year":"2020"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274740"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref18","article-title":"Hardness of samples is all you need: Protecting deep learning models using hardness of samples","author":"Sadeghzadeh","year":"2021"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486863"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/100"},{"key":"ref21","article-title":"Protecting DNNs from theft using an ensemble of diverse models","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Kariyappa"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_4"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3043382"},{"key":"ref24","article-title":"Prediction poisoning: Towards defenses against DNN model stealing attacks","volume-title":"Proc. 8th Int. Conf. Learn. Representations","author":"Orekondy"},{"key":"ref25","article-title":"Increasing the cost of model extraction with calibrated proof of work","volume-title":"Proc. 10th Int. Conf. Learn. Representations","author":"Dziedzic"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"ref27","article-title":"Stateful detection of model extraction attacks","author":"Pal","year":"2021"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"ref30","first-page":"1309","article-title":"Exploring connections between active learning and model extraction","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Chandrasekaran"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"ref32","first-page":"2669","article-title":"Stealing links from graph neural networks","volume-title":"Proc. USENIX Secur. Symp.","author":"He"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3531146.3533188"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"key":"ref35","first-page":"20120","article-title":"Black-box ripper: Copying black-box models using generative evolutionary algorithms","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Barbalau"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3665451.3665533"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/336"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3234355"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475591"},{"key":"ref43","first-page":"1937","article-title":"Entangled watermarks as a defense against model extraction","volume-title":"USENIX Secur. Symp.","author":"Jia"},{"key":"ref44","article-title":"Deep neural network fingerprinting by conferrable adversarial examples","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Lukas"},{"key":"ref45","first-page":"3593","article-title":"Teacher model fingerprinting attacks against transfer learning","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Chen"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539257"},{"key":"ref47","article-title":"Dataset inference: Ownership resolution in machine learning","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Maini"},{"key":"ref48","article-title":"Dataset inference for self-supervised models","author":"Dziedzic","year":"2022"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20036"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20036"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00041"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00020"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-71852-7_2"},{"key":"ref54","article-title":"Increasing the cost of model extraction with calibrated proof of work","volume-title":"Proc. 10th Int. Conf. Learn. Representations","author":"Dziedzic"},{"key":"ref55","first-page":"15241","article-title":"How to steer your adversary: Targeted and efficient model stealing defenses with gradient redirection","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Mazeika"},{"key":"ref56","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"issue":"2018","key":"ref58","article-title":"Large-scale celebfaces attributes (CelebA) dataset","volume":"15","author":"Liu","year":"2018"},{"key":"ref59","article-title":"Skin lesion analysis toward melanoma detection 2018: A challenge hosted by the international skin imaging collaboration (ISIC)","author":"Codella","year":"2019"},{"key":"ref60","article-title":"Cinic-10 is not imagenet or cifar-10","author":"Darlow","year":"2018"},{"key":"ref61","first-page":"1","article-title":"Labeled faces in the wild: A database forstudying face recognition in unconstrained environments","volume-title":"Proc. Workshop faces in\u2019Real-Life\u2019Images: Detection Alignment, Recognit.","author":"Huang"},{"key":"ref62","article-title":"BCN20000: Dermoscopic lesions in the wild","author":"Combalia","year":"2019"},{"key":"ref63","first-page":"12278","article-title":"Grey-box extraction of natural language models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zanella-Beguelin"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11077775\/10820168.pdf?arnumber=10820168","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,11]],"date-time":"2025-07-11T22:48:55Z","timestamp":1752274135000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10820168\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7]]},"references-count":63,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2024.3520599","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7]]}}}