{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T16:05:25Z","timestamp":1775837125433,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2006,3,21]],"date-time":"2006-03-21T00:00:00Z","timestamp":1142899200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2006,3,21]]},"DOI":"10.1145\/1128817.1128824","type":"proceedings-article","created":{"date-parts":[[2006,5,8]],"date-time":"2006-05-08T21:40:43Z","timestamp":1147124443000},"page":"16-25","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":532,"title":["Can machine learning be secure?"],"prefix":"10.1145","author":[{"given":"Marco","family":"Barreno","sequence":"first","affiliation":[{"name":"University of California, Berkeley"}]},{"given":"Blaine","family":"Nelson","sequence":"additional","affiliation":[{"name":"University of California, Berkeley"}]},{"given":"Russell","family":"Sears","sequence":"additional","affiliation":[{"name":"University of California, Berkeley"}]},{"given":"Anthony D.","family":"Joseph","sequence":"additional","affiliation":[{"name":"University of California, Berkeley"}]},{"given":"J. D.","family":"Tygar","sequence":"additional","affiliation":[{"name":"University of California, Berkeley"}]}],"member":"320","published-online":{"date-parts":[[2006,3,21]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"9","volume-title":"Proceedings of the Workshop on Machine Learning in the New Information Age","author":"Androutsopoulos I.","year":"2000"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1022821128753"},{"key":"e_1_3_2_1_3_1","unstructured":"Apache http:\/\/spamassassin.apache.org\/. Spam Assassin.]]  Apache http:\/\/spamassassin.apache.org\/. Spam Assassin.]]"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0304-3975(97)00019-4"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01254543"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0304-3975(01)00403-0"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/258128.258179"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014066"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/s001820050024"},{"key":"e_1_3_2_1_10_1","unstructured":"J. Graham-Cumming. How to beat an adaptive spam filter. Presentation at the MIT Spam Conference Jan. 2004.]]  J. Graham-Cumming. How to beat an adaptive spam filter. Presentation at the MIT Spam Conference Jan. 2004.]]"},{"key":"e_1_3_2_1_11_1","volume-title":"Inference and Prediction. Springer","author":"Hastie T.","year":"2003"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2000.914187"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1007424614876"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 2nd DARPA-JFACC Symposium on Advances in Enterprise Control","author":"Hespanha J. P.","year":"2000"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1137\/0222052"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972733.3"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/BF01243643"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.5555\/647253.720290"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-49380-8_18"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1006\/inco.1994.1009"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1081870.1081950"},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the Second Conference on Email and Anti-Spam (CEAS)","author":"Lowd D.","year":"2005"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/775047.775102"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2002.1007774"},{"key":"e_1_3_2_1_25_1","unstructured":"B. Nelson. Designing Implementing and Analyzing a System for Virus Detection. Master's thesis University of California at Berkeley Dec. 2005.]]  B. Nelson. Designing Implementing and Analyzing a System for Virus Detection. Master's thesis University of California at Berkeley Dec. 2005.]]"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/S1389-1286(99)00112-7"},{"key":"e_1_3_2_1_27_1","volume-title":"Proceedings of the 13th USENIX Security Symposium","author":"Provos N.","year":"2004"},{"key":"e_1_3_2_1_28_1","volume-title":"Neural Information Processing Systems Workshop on Inductive Transfer: 10 Years Later","author":"Raina R.","year":"2005"},{"issue":"3","key":"e_1_3_2_1_29_1","first-page":"527","article-title":"Effect of correlation in a simple deception game","volume":"35","author":"Sakaguchi M.","year":"1990","journal-title":"Mathematica Japonica"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1162\/153244304773936072"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.5555\/975545"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1080\/00029890.1973.11993302"},{"key":"e_1_3_2_1_33_1","volume-title":"Mathematical Methods","author":"Stolfo S. J.","year":"2003"},{"key":"e_1_3_2_1_34_1","volume-title":"ACM Transactions on Internet Technology","author":"Stolfo S. J.","year":"2004"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1968.1972"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.5555\/1625135.1625242"},{"key":"e_1_3_2_1_37_1","first-page":"371","volume-title":"Proceeding of the 7th Annual Workshop on Computational Learning Theory","author":"Vovk V.","year":"1990"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/64.621229"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the First Conference on Email and Anti-Spam (CEAS)","author":"Wittel G. L.","year":"2004"},{"key":"e_1_3_2_1_40_1","volume-title":"Theory and Applications","author":"Xu W.","year":"2004"},{"key":"e_1_3_2_1_41_1","first-page":"385","volume-title":"Proceedings of the Sixteenth International Conference on Pattern Recognition","author":"Yeung D.-Y.","year":"2002"},{"key":"e_1_3_2_1_42_1","volume-title":"Neural Information Processing Systems Workshop on Inductive Transfer: 10 Years Later","author":"Yu K.","year":"2005"}],"event":{"name":"Asia CCS06: ACM Symposium on Information, Computer and Communications Security 2006","location":"Taipei Taiwan","acronym":"Asia CCS06","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2006 ACM Symposium on Information, computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1128817.1128824","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1128817.1128824","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T15:06:17Z","timestamp":1750259177000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1128817.1128824"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2006,3,21]]},"references-count":42,"alternative-id":["10.1145\/1128817.1128824","10.1145\/1128817"],"URL":"https:\/\/doi.org\/10.1145\/1128817.1128824","relation":{},"subject":[],"published":{"date-parts":[[2006,3,21]]},"assertion":[{"value":"2006-03-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}