{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T13:26:29Z","timestamp":1740144389395,"version":"3.37.3"},"reference-count":82,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2022YFF0604503"],"award-info":[{"award-number":["2022YFF0604503"]}]},{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"publisher","award":["62272224","62341201","62302207","62272215"],"award-info":[{"award-number":["62272224","62341201","62302207","62272215"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Leading Edge Technology Program of Jiangsu Natural Science Foundation","award":["BK20202001"],"award-info":[{"award-number":["BK20202001"]}]},{"name":"Science Foundation for Youths of Jiangsu Province","award":["BK20220772"],"award-info":[{"award-number":["BK20220772"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/tifs.2024.3455761","type":"journal-article","created":{"date-parts":[[2024,9,6]],"date-time":"2024-09-06T17:46:21Z","timestamp":1725644781000},"page":"8188-8203","source":"Crossref","is-referenced-by-count":0,"title":["TIM: Enabling Large-Scale White-Box Testing on In-App Deep Learning Models"],"prefix":"10.1109","volume":"19","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0980-9805","authenticated-orcid":false,"given":"Hao","family":"Wu","sequence":"first","affiliation":[{"name":"National Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0253-6587","authenticated-orcid":false,"given":"Yuhang","family":"Gong","sequence":"additional","affiliation":[{"name":"National Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-0039-4013","authenticated-orcid":false,"given":"Xiaopeng","family":"Ke","sequence":"additional","affiliation":[{"name":"National Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-1915-6692","authenticated-orcid":false,"given":"Hanzhong","family":"Liang","sequence":"additional","affiliation":[{"name":"National Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3388-7544","authenticated-orcid":false,"given":"Fengyuan","family":"Xu","sequence":"additional","affiliation":[{"name":"National Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7352-8955","authenticated-orcid":false,"given":"Yunxin","family":"Liu","sequence":"additional","affiliation":[{"name":"Institute for AI Industry Research, Tsinghua University, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6581-8730","authenticated-orcid":false,"given":"Sheng","family":"Zhong","sequence":"additional","affiliation":[{"name":"National Key Laboratory for Novel Software Technology, Nanjing University, Nanjing, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1155\/2018\/7068349"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-14596-5"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/comptelix.2017.8003957"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.07.045"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/s11265-020-01596-1"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-021-01453-z"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3578938"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313591"},{"key":"ref9","first-page":"1955","article-title":"Mind your weight(s): A large-scale study on insufficient machine learning model protection in mobile apps","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Security)","author":"Sun"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487863"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00038"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3395363.3397346"},{"volume-title":"TensorFlow Lite Model Optimization","year":"2024","key":"ref13"},{"volume-title":"TVM Doc","year":"2024","key":"ref14"},{"key":"ref15","article-title":"Backdoor attacks and countermeasures on deep learning: A comprehensive review","author":"Gao","year":"2020","journal-title":"arXiv:2007.10760"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100270"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559388"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref20","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3485133"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3331087"},{"key":"ref23","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017","journal-title":"arXiv:1706.06083"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11302"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1631\/FITEE.1700808"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-022-01756-8"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00118"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM52516.2021.00031"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3417051"},{"volume-title":"ONNX","year":"2024","key":"ref32"},{"key":"ref33","article-title":"Benchmarking of DL libraries and models on mobile devices","author":"Zhang","year":"2022","journal-title":"arXiv:2202.06512"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP52600.2021.00019"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1002\/smr.2528"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/1250734.1250748"},{"issue":"35","key":"ref37","article-title":"The Soot framework for Java program analysis: A retrospective","volume-title":"Proc. Cetus Users Compiler Infastruct. Workshop (CETUS)","volume":"15","author":"Lam"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3302424.3303989"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3551349.3561339"},{"key":"ref40","first-page":"7357","article-title":"Decompiling \u00d786 deep neural network executables","volume-title":"Proc. 32nd USENIX Secur. Symp. (USENIX Security)","author":"Liu"},{"key":"ref41","first-page":"2135","article-title":"DnD: A cross-architecture deep neural network decompiler","volume-title":"Proc. 31st USENIX Secur. Symp. (USENIX Security)","author":"Wu"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/3595292"},{"key":"ref44","first-page":"1973","article-title":"Hermes attack: Steal DNN models with lossless inference accuracy","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Security)","author":"Zhu"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3338498.3358646"},{"key":"ref47","first-page":"8178","article-title":"Reverse-engineering deep ReLU networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Rolnick"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"ref49","first-page":"5233","article-title":"SoK: All you need to know about on-device ml model extraction\u2014The gap between research and practice","volume-title":"Proc. 33rd USENIX Security Symp. (USENIX Security)","author":"Nayan"},{"key":"ref50","first-page":"5305","article-title":"ModelGuard: Information-theoretic defense against model extraction attacks","volume-title":"Proc. 33rd USENIX Secur. Symp. (Security)","author":"Tang"},{"key":"ref51","first-page":"1687","article-title":"AI Psychiatry: Forensic investigation of deep learning networks in memory images","volume-title":"Proc. 33rd USENIX Security Symp. (USENIX Security)","author":"Oygenblik"},{"volume-title":"Information Technology Technical Requirements of Collaborative Learning Systems for Heterogeneous Computing","year":"2024","key":"ref52"},{"volume-title":"Information Technology Data Quality Requirements for Heterogeneous Computing","year":"2024","key":"ref53"},{"key":"ref54","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","author":"Brendel","year":"2017","journal-title":"arXiv:1712.04248"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23296"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2020.2996433"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00105"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453093"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-10602-1_48"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-009-0275-4"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"volume-title":"Download Apk Free Online Downloader","year":"2024","key":"ref62"},{"volume-title":"360 App Store","year":"2024","key":"ref63"},{"volume-title":"Baidu App Store","year":"2024","key":"ref64"},{"volume-title":"Xiaomi App Store","year":"2024","key":"ref65"},{"volume-title":"Anzhi Market","year":"2024","key":"ref66"},{"volume-title":"Volcengine","year":"2024","key":"ref67"},{"volume-title":"SenseTime","year":"2024","key":"ref68"},{"volume-title":"TensorFlow: Large-Scale Machine Learning on Heterogeneous Systems","year":"2015","author":"Abadi","key":"ref69"},{"volume-title":"TensorFlow Lite","year":"2021","key":"ref70"},{"volume-title":"NCNN","year":"2024","key":"ref71"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/2647868.2654889"},{"key":"ref73","first-page":"1","article-title":"MNN: A universal and efficient inference engine","volume-title":"Proc. Mach. Learn. Syst.","volume":"2","author":"Jiang"},{"volume-title":"TNN","year":"2024","key":"ref74"},{"volume-title":"Kwai, Fantastic Social Video Network","year":"2024","key":"ref75"},{"volume-title":"Mindspore","year":"2024","key":"ref76"},{"volume-title":"HUYA","year":"2024","key":"ref77"},{"volume-title":"Meicam","year":"2024","key":"ref78"},{"key":"ref79","article-title":"Intriguing properties of neural networks","author":"Szegedy","year":"2013","journal-title":"arXiv:1312.6199"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616653"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179382"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1145\/3539618.3591661"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10319981\/10669107.pdf?arnumber=10669107","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,18]],"date-time":"2024-09-18T06:34:26Z","timestamp":1726641266000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10669107\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":82,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3455761","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2024]]}}}