{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T20:08:30Z","timestamp":1778789310046,"version":"3.51.4"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"11","license":[{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,11,1]],"date-time":"2022-11-01T00:00:00Z","timestamp":1667260800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1931871"],"award-info":[{"award-number":["1931871"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2019548"],"award-info":[{"award-number":["2019548"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008982","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2019536"],"award-info":[{"award-number":["2019536"]}],"id":[{"id":"10.13039\/501100008982","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Pattern Anal. Mach. Intell."],"published-print":{"date-parts":[[2022,11,1]]},"DOI":"10.1109\/tpami.2021.3112932","type":"journal-article","created":{"date-parts":[[2021,9,16]],"date-time":"2021-09-16T20:34:21Z","timestamp":1631824461000},"page":"7928-7939","source":"Crossref","is-referenced-by-count":56,"title":["T-BFA: <u>T<\/u>argeted <u>B<\/u>it-<u>F<\/u>lip Adversarial Weight <u>A<\/u>ttack"],"prefix":"10.1109","volume":"44","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6056-2625","authenticated-orcid":false,"given":"Adnan Siraj","family":"Rakin","sequence":"first","affiliation":[{"name":"Electrical, Computer, and Energy Engineering, Arizona State University, Tempe, AZ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhezhi","family":"He","sequence":"additional","affiliation":[{"name":"CSE, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4250-869X","authenticated-orcid":false,"given":"Jingtao","family":"Li","sequence":"additional","affiliation":[{"name":"Electrical, Computer, and Energy Engineering, Arizona State University, Tempe, AZ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0360-5641","authenticated-orcid":false,"given":"Fan","family":"Yao","sequence":"additional","affiliation":[{"name":"ECE, University of Central Florida, Orlando, FL, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9859-7778","authenticated-orcid":false,"given":"Chaitali","family":"Chakrabarti","sequence":"additional","affiliation":[{"name":"Electrical, Computer, and Energy Engineering, Arizona State University, Tempe, AZ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7989-6297","authenticated-orcid":false,"given":"Deliang","family":"Fan","sequence":"additional","affiliation":[{"name":"Electrical, Computer, and Energy Engineering, Arizona State University, Tempe, AZ, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Cifar-10 (Canadian Institute for Advanced Research)","author":"Krizhevsky","year":"2010"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2916183"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-0029-9_40"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/K15-1031"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/s11192-020-03385-w"},{"key":"ref7","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Madry"},{"key":"ref8","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Goodfellow"},{"key":"ref9","first-page":"2003","article-title":"Cache telepathy: Leveraging shared resource attacks to learn DNN architectures","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Yan"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TCSII.2020.2973007"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/HOST45689.2020.9300274"},{"key":"ref12","first-page":"1","article-title":"X-deepSCA: Cross-device deep learning side channel attack","volume-title":"Proc. 56th Annu. Des. Automat. Conf.","author":"Das"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2013.17"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2014.6853210"},{"key":"ref15","first-page":"1","article-title":"Flip feng shui: Hammering a needle in the software stack","volume-title":"Proc. 25th USENIX Secur. Symp.","author":"Razavi"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00130"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ICCAD.2017.8203770"},{"key":"ref18","first-page":"497","article-title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Hong"},{"key":"ref19","first-page":"1463","article-title":"DeepHammer: Depleting the intelligence of deep neural networks through targeted chain of bit flips","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Yao"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref22","first-page":"1","article-title":"Fault sneaking attack: A stealthy framework for misleading deep neural networks","volume-title":"Proc. 56th ACM\/IEEE Des. Automat. Conf.","author":"Zhao"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3079856.3080246"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/IOLTS.2010.5560194"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01321"},{"key":"ref26","article-title":"Estimating or propagating gradients through stochastic neurons for conditional computation","author":"Bengio","year":"2013"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref31","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01410"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241139"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00031"},{"key":"ref36","article-title":"Adversarial weight perturbation helps robust generalization","volume-title":"Proc. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref37","article-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tramer"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00089"}],"container-title":["IEEE Transactions on Pattern Analysis and Machine Intelligence"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/34\/9910240\/9540274-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/34\/9910240\/09540274.pdf?arnumber=9540274","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,4]],"date-time":"2025-04-04T19:39:45Z","timestamp":1743795585000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9540274\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,1]]},"references-count":38,"journal-issue":{"issue":"11"},"URL":"https:\/\/doi.org\/10.1109\/tpami.2021.3112932","relation":{},"ISSN":["0162-8828","2160-9292","1939-3539"],"issn-type":[{"value":"0162-8828","type":"print"},{"value":"2160-9292","type":"electronic"},{"value":"1939-3539","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,11,1]]}}}