{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T15:57:11Z","timestamp":1776182231607,"version":"3.50.1"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-2007210"],"award-info":[{"award-number":["CCF-2007210"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-2106610"],"award-info":[{"award-number":["CCF-2106610"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-2106754"],"award-info":[{"award-number":["CCF-2106754"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Emerg. Top. Comput. Intell."],"published-print":{"date-parts":[[2022,10]]},"DOI":"10.1109\/tetci.2022.3147508","type":"journal-article","created":{"date-parts":[[2022,3,3]],"date-time":"2022-03-03T20:25:09Z","timestamp":1646339109000},"page":"1258-1270","source":"Crossref","is-referenced-by-count":38,"title":["ES Attack: Model Stealing Against Deep Neural Networks Without Data Hurdles"],"prefix":"10.1109","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0782-4187","authenticated-orcid":false,"given":"Xiaoyong","family":"Yuan","sequence":"first","affiliation":[{"name":"College of Computing, Michigan Technological University, Houghton, MI, USA"}]},{"given":"Leah","family":"Ding","sequence":"additional","affiliation":[{"name":"Department of Computer Science, American University, Washington, DC, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7144-9089","authenticated-orcid":false,"given":"Lan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Michigan Technological University, Houghton, MI, USA"}]},{"given":"Xiaolin","family":"Li","sequence":"additional","affiliation":[{"name":"Deep Learning, Cognization Lab, Palo Alto, CA, USA"}]},{"given":"Dapeng Oliver","family":"Wu","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, University of Florida, Gainesville, FL, USA"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Chiron: Privacy-preserving machine learning as a service","author":"Hunt","year":"2018"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"ref5","article-title":"A framework for the extraction of deep neural networks by leveraging public data","author":"Pal","year":"2019"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref10","article-title":"Adam: A method for stochastic optimization","volume-title":"Proc. 3rd Int. Conf. Learn. Representations","author":"Kingma","year":"2015"},{"key":"ref11","first-page":"2642","article-title":"Conditional image synthesis with auxiliary classifier gans","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","author":"Odena","year":"2017"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00152"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref14","article-title":"Deep learning for classical japanese literature","author":"Clanuwat","year":"2018"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref16","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref18","article-title":"Amazon rekognition pricing","author":"Amazon","year":"2020"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5963"},{"key":"ref20","first-page":"2234","article-title":"Improved techniques for training gans","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Salimans","year":"2016"},{"key":"ref21","first-page":"6626","article-title":"Gans trained by a two time-scale update rule converge to a local nash equilibrium","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Heusel","year":"2017"},{"key":"ref22","first-page":"700","article-title":"Are GANs created equal? A large-scale study","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Lucic","year":"2018"},{"key":"ref23","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Representations","author":"Szegedy","year":"2014"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref27","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"Papernot","year":"2016"},{"key":"ref28","article-title":"Delving into transferable adversarial examples and black-box attacks","volume-title":"Proc. 5th Int. Conf. Learn. Representations","author":"Liu","year":"2017"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274740"},{"key":"ref32","article-title":"Distilling the knowledge in a neural network","author":"Hinton","year":"2015"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1150402.1150464"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00361"},{"key":"ref35","article-title":"Data-free knowledge distillation for deep neural networks","author":"Lopes","year":"2017"},{"key":"ref36","first-page":"4743","article-title":"Zero-shot knowledge distillation in deep networks","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Nayak","year":"2019"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00852"}],"container-title":["IEEE Transactions on Emerging Topics in Computational Intelligence"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/7433297\/9900106\/9726514-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/7433297\/9900106\/09726514.pdf?arnumber=9726514","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,1,17]],"date-time":"2024-01-17T23:02:31Z","timestamp":1705532551000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9726514\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10]]},"references-count":38,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tetci.2022.3147508","relation":{},"ISSN":["2471-285X"],"issn-type":[{"value":"2471-285X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10]]}}}