{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T07:25:38Z","timestamp":1763018738901,"version":"3.37.3"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Research Foundation, Singapore, through its Strategic Capability Research Centres Funding Initiative","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Infocomm Media Development Authority through its Future Communications Research and Development Programme"},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20B2049","U21B2018"],"award-info":[{"award-number":["U20B2049","U21B2018"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2024.3515792","type":"journal-article","created":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T22:29:47Z","timestamp":1733956187000},"page":"531-546","source":"Crossref","is-referenced-by-count":1,"title":["Augmenting Model Extraction Attacks Against Disruption-Based Defenses"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2190-8117","authenticated-orcid":false,"given":"Xueluan","family":"Gong","sequence":"first","affiliation":[{"name":"Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-6063-8817","authenticated-orcid":false,"given":"Shuaike","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1382-0679","authenticated-orcid":false,"given":"Yanjiao","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Electrical Engineering, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-5120-0758","authenticated-orcid":false,"given":"Mingzhe","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]},{"given":"Rubin","family":"Wei","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8967-8525","authenticated-orcid":false,"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7479-7970","authenticated-orcid":false,"given":"Kwok-Yan","family":"Lam","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Jurong West, Singapore"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00020"},{"key":"ref5","first-page":"1","article-title":"Prediction poisoning: Towards defenses against DNN model stealing attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Orekondy"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_4"},{"volume-title":"Threat Modeling AI\/ML Systems and Dependencies","year":"2022","author":"Marshall","key":"ref7"},{"volume-title":"Microsoft Azure","year":"2022","key":"ref8"},{"volume-title":"Face+","year":"2022","key":"ref9"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179406"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1989.1.4.541"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref13","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv:1409.1556"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2000196"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"ref17","volume-title":"Introduction To Reinforcement Learning","volume":"135","author":"Sutton","year":"1998"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"ref19","first-page":"1309","article-title":"Exploring connections between active learning and model extraction","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Chandrasekaran"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1137\/120880811"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.2307\/2333709"},{"key":"ref28","first-page":"1","article-title":"Protecting DNNs from theft using an ensemble of diverse models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Kariyappa"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref30","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","volume-title":"Proc. 23rd Secur. Symp.","author":"Fredrikson"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1142\/9789811232701_0003"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3069258"},{"key":"ref33","first-page":"1126","article-title":"Model-agnostic meta-learning for fast adaptation of deep networks","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","author":"Finn"},{"key":"ref34","article-title":"Reptile: A scalable metalearning algorithm","author":"Nichol","year":"2018","journal-title":"arXiv:1803.02999"},{"key":"ref35","article-title":"Rapid learning or feature reuse? Towards understanding the effectiveness of MAML","author":"Raghu","year":"2019","journal-title":"arXiv:1909.09157"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.324"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1312.6114"},{"key":"ref38","first-page":"3","article-title":"Rectifier nonlinearities improve neural network acoustic models","volume-title":"Proc. ICML","author":"Maas"},{"article-title":"MNIST handwritten digit database","year":"2010","author":"LeCun","key":"ref39"},{"key":"ref40","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref41"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"ref43","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NIPS)","author":"Krizhevsky"},{"volume-title":"Real-World Affective Faces Database","year":"2022","key":"ref44"},{"issue":"11","key":"ref45","article-title":"Visualizing data using t-SNE","volume":"9","author":"Van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10793405.pdf?arnumber=10793405","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,6]],"date-time":"2025-01-06T19:23:15Z","timestamp":1736191395000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10793405\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":45,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3515792","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2025]]}}}