{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T21:30:53Z","timestamp":1771536653953,"version":"3.50.1"},"reference-count":62,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U23A20307"],"award-info":[{"award-number":["U23A20307"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62501444"],"award-info":[{"award-number":["62501444"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U25A20429"],"award-info":[{"award-number":["U25A20429"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2436206"],"award-info":[{"award-number":["U2436206"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62406239"],"award-info":[{"award-number":["62406239"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"Postdoctoral Fellowship Program of China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["GZB20250406"],"award-info":[{"award-number":["GZB20250406"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2023M742739"],"award-info":[{"award-number":["2023M742739"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Postdoctoral Research Project of Shanxi Province","award":["2024BSHEDZZ015"],"award-info":[{"award-number":["2024BSHEDZZ015"]}]},{"name":"111 Center under","award":["B16037"],"award-info":[{"award-number":["B16037"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3661794","type":"journal-article","created":{"date-parts":[[2026,2,6]],"date-time":"2026-02-06T20:47:28Z","timestamp":1770410848000},"page":"2116-2131","source":"Crossref","is-referenced-by-count":0,"title":["PROTheft: A Projector-Based Model Extraction Attack in the Physical World"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0159-0594","authenticated-orcid":false,"given":"Xinjing","family":"Liu","sequence":"first","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2811-2667","authenticated-orcid":false,"given":"Yilong","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0843-165X","authenticated-orcid":false,"given":"Taifeng","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-1274-4325","authenticated-orcid":false,"given":"Hao","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9330-2662","authenticated-orcid":false,"given":"Leo Yu","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Information and Communication Technology, Griffith University, Brisbane, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5611-3483","authenticated-orcid":false,"given":"Yanjun","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6276-1468","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6023-2864","authenticated-orcid":false,"given":"Zhuo","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref2","volume-title":"Autopilot and Full Self-Driving (Supervised)","year":"2014"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"ref4","first-page":"1309","article-title":"Exploring connections between active learning and model extraction","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Secur. 20)","author":"Chandrasekaran"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20056-4_13"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2020.3036768"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2024.3372031"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.91"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.l007\/978-3-319-46448-0_2"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2577031"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.322"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3595292"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp.2019.00044"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485838"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833607"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3503161.3548416"},{"key":"ref22","article-title":"MEAOD: Model extraction attack against object detectors","author":"Li","year":"2023","journal-title":"arXiv:2312.14677"},{"key":"ref23","first-page":"36571","article-title":"Are you stealing my model? Sample correlation for fingerprinting deep neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Guan"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3360880"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833743"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.3389\/fdata.2021.729663"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475591"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2025.3561225"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW.2019.00012"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00846"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00775"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00080"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58548-8_1"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02308"},{"key":"ref36","first-page":"284","article-title":"Synthesizing robust adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Athalye"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2023.104861"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02366"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423359"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01373"},{"key":"ref41","first-page":"1","article-title":"You can\u2019t see me: Physical removal attacks on LiDAR-based autonomous vehicles driving frameworks","volume-title":"Proc. 32nd USENIX Conf. Secur. Symp.","author":"Cao"},{"key":"ref42","first-page":"881","article-title":"Rocking drones with intentional sound noise on gyroscopic sensors","volume-title":"Proc. 24th USENIX Secur. Symp. (USENIX Secur.)","author":"Son"},{"key":"ref43","volume-title":"Apollo","year":"2017"},{"key":"ref44","first-page":"6929","article-title":"That person moves like a car: Misclassification attack detection for autonomous systems using spatiotemporal consistency","volume-title":"Proc. 32nd USENIX Secur. Symp. (USENIX Secur.)","author":"Man"},{"key":"ref45","volume-title":"Openpilot","year":"2016"},{"key":"ref46","first-page":"931","article-title":"Drift with devil: Security of multi-sensor fusion based localization in high-level autonomous driving under GPS spoofing","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Secur. 20)","author":"Shen"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2015.2459898"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.81"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2023.3328811"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01711"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i7.28595"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00440"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2012.6248074"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00271"},{"key":"ref55","first-page":"661","article-title":"TPatch: A triggered physical adversarial patch","volume-title":"Proc. 32th Secur. Symp. (USENIX Secur.)","author":"Zhu"},{"key":"ref56","volume-title":"Introducing ChatGPT","year":"2025"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2018.00957"},{"key":"ref58","volume-title":"AI & Robotics","year":"2025"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"ref60","first-page":"1","article-title":"Protecting object detection models from model extraction attack via feature space coverage","volume-title":"Proc. IJCAI","author":"Li"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/100"},{"key":"ref62","first-page":"1","article-title":"Prediction poisoning: Towards defenses against DNN model stealing attacks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Orekondy"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11373280.pdf?arnumber=11373280","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T20:56:46Z","timestamp":1771534606000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11373280\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":62,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3661794","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}