{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T15:43:05Z","timestamp":1785512585030,"version":"3.56.0"},"reference-count":30,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100005047","name":"Natural Science Foundation of Liaoning Province","doi-asserted-by":"publisher","award":["2019ZD0243"],"award-info":[{"award-number":["2019ZD0243"]}],"id":[{"id":"10.13039\/501100005047","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3384841","type":"journal-article","created":{"date-parts":[[2024,4,3]],"date-time":"2024-04-03T17:38:55Z","timestamp":1712165935000},"page":"4728-4740","source":"Crossref","is-referenced-by-count":11,"title":["AugSteal: Advancing Model Steal With Data Augmentation in Active Learning Frameworks"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3350-0362","authenticated-orcid":false,"given":"Lijun","family":"Gao","sequence":"first","affiliation":[{"name":"School of Computer Science, Shenyang Aerospace University, Shenyang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4994-9495","authenticated-orcid":false,"given":"Wenjun","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science, Shenyang Aerospace University, Shenyang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-2256-0750","authenticated-orcid":false,"given":"Kai","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science, Shenyang Aerospace University, Shenyang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiehong","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Computer Science, Shenyang Aerospace University, Shenyang, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3036801"},{"key":"ref3","first-page":"1937","article-title":"Entangled watermarks as a defense against model extraction","volume-title":"Proc. USENIX Secur. Symp.","author":"Jia"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3246766"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3320609"},{"key":"ref6","first-page":"1345","article-title":"High accuracy and high fidelity extraction of neural networks","volume-title":"Proc. 29th USENIX Conf. Secur. Symp.","author":"Jagielski"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3287560.3287562"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref9","first-page":"1901","article-title":"DRMI: A dataset reduction technology based on mutual information for black-box attacks","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"He"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref12","article-title":"Defending against machine learning model stealing attacks using deceptive perturbations","author":"Lee","year":"2018","journal-title":"arXiv:1806.00054"},{"key":"ref13","article-title":"Prediction poisoning: Towards defenses against DNN model stealing attacks","author":"Orekondy","year":"2019","journal-title":"arXiv:1906.10908"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20065-6_12"},{"key":"ref16","article-title":"Zero-shot knowledge transfer via adversarial belief matching","volume-title":"33rd Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Micaelli"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00031"},{"key":"ref18","first-page":"1","article-title":"Knowledge extraction with no observable data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Yoo"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3472291"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00032"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00018"},{"key":"ref25","article-title":"Deep batch active learning by diverse","volume-title":"Proc. 8th Int. Conf. Learn. Represent. (ICLR)","author":"Ash"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.48550\/arxiv.1710.09412"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00612"},{"key":"ref28","article-title":"GridMask data augmentation","author":"Chen","year":"2020","journal-title":"arXiv:2001.04086"},{"key":"ref29","first-page":"20120","article-title":"Black-box ripper: Copying black-box models using generative evolutionary algorithms","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Barbalau"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/336"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/10319981\/10490222.pdf?arnumber=10490222","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,5,8]],"date-time":"2024-05-08T04:47:26Z","timestamp":1715143646000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10490222\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":30,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3384841","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]}}}