{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T21:30:54Z","timestamp":1771536654912,"version":"3.50.1"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3663053","type":"journal-article","created":{"date-parts":[[2026,2,9]],"date-time":"2026-02-09T21:03:45Z","timestamp":1770671025000},"page":"2102-2115","source":"Crossref","is-referenced-by-count":0,"title":["AdvScan: Black-Box Adversarial Example Detection at Runtime Through Power Analysis"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7367-8432","authenticated-orcid":false,"given":"Robi","family":"Paul","sequence":"first","affiliation":[{"name":"Rochester Institute of Technology, Rochester, NY, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0356-9393","authenticated-orcid":false,"given":"Michael","family":"Zuzak","sequence":"additional","affiliation":[{"name":"Rochester Institute of Technology, Rochester, NY, USA"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3294111"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/LES.2024.3475470"},{"key":"ref3","article-title":"Benchmarking TinyML systems: Challenges and direction","author":"Banbury","year":"2020","journal-title":"arXiv:2003.04821"},{"key":"ref4","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3412841.3441892"},{"key":"ref10","first-page":"1","article-title":"Fusion is not enough: Single modal attacks on fusion models for 3D object detection","volume-title":"Proc. 12th Int. Conf. Learn. Represent.","author":"Cheng"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3381180"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3359820"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00068"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3269012"},{"key":"ref16","first-page":"5498","article-title":"The odds are odd: A statistical test for detecting adversarial examples","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Roth"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-023-05253-5"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/EIECT64462.2024.10866183"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134057"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2021.3092582"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/OJSP.2023.3275053"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/IPDPSW55747.2022.00160"},{"key":"ref23","article-title":"Detecting adversarial samples from artifacts","author":"Feinman","year":"2017","journal-title":"arXiv:1703.00410"},{"key":"ref24","article-title":"Detecting adversarial examples in convolutional neural networks","author":"Pertigkiozoglou","year":"2018","journal-title":"arXiv:1812.03303"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-97-9743-1_17"},{"key":"ref27","article-title":"GraN: An efficient gradient-norm based detector for adversarial and misclassified examples","author":"Lust","year":"2020","journal-title":"arXiv:2004.09179"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.615"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/DSC59305.2023.00074"},{"key":"ref30","article-title":"Feature squeezing: Detecting adversarial examples in deep neural networks","author":"Xu","year":"2017","journal-title":"arXiv:1704.01155"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00009"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.2307\/2331554"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-28632-5_2"},{"key":"ref34","article-title":"Design and analysis of power distribution networks in VLSI circuits","author":"Pant","year":"2008"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-31034-8_8"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TCAD.2025.3551652"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3093336.3037703"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2023.3335876"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3582827"},{"key":"ref40","first-page":"9","article-title":"WattsUpDoc: Power side channels to nonintrusively discover untargeted malware on embedded medical devices","volume-title":"Proc. USENIX Workshop Health Inf. Technol. (HealthTech)","author":"Clark"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICDIS.2019.00016"},{"key":"ref42","volume-title":"Mobileye\u2019s New EyeQ5: How Open is Open?","year":"2026"},{"key":"ref43","volume-title":"Valeo Has Produced Its 20 Millionth Front Camera System Integrating Mobileye EyeQ Technology","year":"2026"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18074.2021.9586290"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3630180.3631201"},{"key":"ref46","article-title":"MLPerf tiny benchmark","author":"Banbury","year":"2021","journal-title":"arXiv:2106.07597"},{"key":"ref47","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45871-7_5"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/HOST64725.2025.11050062"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.46586\/tches.v2022.i1.345-366"},{"key":"ref51","article-title":"Mathematical analysis of adversarial attacks","author":"Dou","year":"2018","journal-title":"arXiv:1811.06492"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3148990"},{"key":"ref53","first-page":"1","article-title":"AdvHunter: Detecting adversarial perturbations in black-box neural networks through hardware performance counters","volume-title":"Proc. 61st ACM\/IEEE Design Autom. Conf.","author":"Alam"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11386831.pdf?arnumber=11386831","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T20:56:47Z","timestamp":1771534607000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11386831\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":53,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3663053","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}