{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,2]],"date-time":"2026-04-02T15:53:44Z","timestamp":1775145224215,"version":"3.50.1"},"reference-count":49,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2019QY1300"],"award-info":[{"award-number":["2019QY1300"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2022]]},"DOI":"10.1109\/tifs.2022.3186743","type":"journal-article","created":{"date-parts":[[2022,6,27]],"date-time":"2022-06-27T20:28:32Z","timestamp":1656361712000},"page":"2437-2451","source":"Crossref","is-referenced-by-count":34,"title":["Minipatch: Undermining DNN-Based Website Fingerprinting With Adversarial Patches"],"prefix":"10.1109","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6644-1210","authenticated-orcid":false,"given":"Ding","family":"Li","sequence":"first","affiliation":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9559-8783","authenticated-orcid":false,"given":"Yuefei","family":"Zhu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou, China"}]},{"given":"Minghao","family":"Chen","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou, China"}]},{"given":"Jue","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Mathematical Engineering and Advanced Computing, Zhengzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23105"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243768"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354217"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0070"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2046556.2046570"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382260"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2517840.2517851"},{"key":"ref8","first-page":"143","article-title":"Effective attacks and provable defenses for website fingerprinting","volume-title":"Proc. 23rd USENIX Secur. Symp.","author":"Wang"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23477"},{"key":"ref10","first-page":"1187","article-title":"k-fingerprinting: A robust scalable website fingerprinting technique","volume-title":"Proc. 25th USENIX Secur. Symp.","author":"Hayes"},{"key":"ref11","first-page":"1","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Represent.","author":"Szegedy"},{"key":"ref12","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. 3rd Int. Conf. Learn. Represent.","author":"Goodfellow"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/543"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2018.2886017"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3039691"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC50000.2020.9219593"},{"key":"ref21","first-page":"2705","article-title":"Defeating DNN-based traffic analysis systems in real-time with blind adversarial perturbations","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Nasr"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3074295"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486875"},{"key":"ref24","article-title":"Adversarial patch","author":"Brown","year":"2017","journal-title":"arXiv:1712.09665"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58574-7_41"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00930"},{"key":"ref28","first-page":"15","article-title":"Fingerprinting attack on Tor anonymity using deep learning","volume":"42","author":"Abe","year":"2016","journal-title":"Proc. Asia\u2013Pacific Adv. Netw."},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0043"},{"key":"ref30","first-page":"1357","article-title":"Beauty and the Burst: Remote identification of encrypted video streams","volume-title":"Proc. 26th USENIX Secur. Symp.","author":"Schuster"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45744-4_2"},{"key":"ref32","first-page":"1375","article-title":"Walkie-Talkie: An efficient defense against passive website fingerprinting attacks","volume-title":"Proc. 26th USENIX Secur. Symp.","author":"Wang"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref34","first-page":"717","article-title":"Zero-delay lightweight defenses against website fingerprinting","volume-title":"29th USENIX Secur. Symp.","author":"Gong"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/S0378-4371(96)00271-3"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1126\/science.220.4598.671"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1016\/0375-9601(87)90796-1"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1016\/S0375-9601(97)00474-X"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/34.295910"},{"key":"ref40","first-page":"1309","article-title":"Exploring connections between active learning and model extraction","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Chandrasekaran"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"issue":"1","key":"ref42","first-page":"949","article-title":"Natural evolution strategies","volume":"15","author":"Wierstra","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00790"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3394171.3413713"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00097"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.2993193"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660368"},{"key":"ref48","article-title":"Measuring the transferability of adversarial examples","author":"Petrov","year":"2019","journal-title":"arXiv:1907.06291"},{"key":"ref49","first-page":"321","article-title":"Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Demontis"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9652463\/09808155.pdf?arnumber=9808155","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,1]],"date-time":"2024-02-01T05:03:31Z","timestamp":1706763811000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9808155\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"references-count":49,"URL":"https:\/\/doi.org\/10.1109\/tifs.2022.3186743","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]}}}