{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T00:25:04Z","timestamp":1772583904945,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":88,"publisher":"ACM","license":[{"start":{"date-parts":[[2019,11,6]],"date-time":"2019-11-06T00:00:00Z","timestamp":1572998400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2019,11,6]]},"DOI":"10.1145\/3319535.3354222","type":"proceedings-article","created":{"date-parts":[[2019,11,7]],"date-time":"2019-11-07T13:08:32Z","timestamp":1573132112000},"page":"2005-2021","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":49,"title":["AdVersarial"],"prefix":"10.1145","author":[{"given":"Florian","family":"Tram\u00e8r","sequence":"first","affiliation":[{"name":"Stanford University, Stanford, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pascal","family":"Dupr\u00e9","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbrucken, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gili","family":"Rusak","sequence":"additional","affiliation":[{"name":"Stanford University, Stanford, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giancarlo","family":"Pellegrino","sequence":"additional","affiliation":[{"name":"Stanford University, CISPA Helmholtz Center for Information Security, Saarbrucken, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Boneh","sequence":"additional","affiliation":[{"name":"Stanford University, Stanford, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2019,11,6]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Adblock Plus. Issue 7088: Implement hide-if-contains-image snippet. https:\/\/issues.adblockplus.org\/ticket\/7088.  Adblock Plus. Issue 7088: Implement hide-if-contains-image snippet. https:\/\/issues.adblockplus.org\/ticket\/7088."},{"key":"e_1_3_2_2_2_1","unstructured":"Adblock Plus. 2018a. Customize Facebook with Adblock Plus. https:\/\/facebook.adblockplus.me\/.  Adblock Plus. 2018a. Customize Facebook with Adblock Plus. https:\/\/facebook.adblockplus.me\/."},{"key":"e_1_3_2_2_3_1","unstructured":"Adblock Plus. 2018b. Sentinel. https:\/\/adblock.ai\/.  Adblock Plus. 2018b. Sentinel. https:\/\/adblock.ai\/."},{"key":"e_1_3_2_2_4_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Nicholas Carlini , and David Wagner . 2018 a. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples . In International Conference on Machine Learning (ICML). Anish Athalye, Nicholas Carlini, and David Wagner. 2018a. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_2_5_1","volume-title":"International Conference on Machine Learning (ICML).","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Logan Engstrom , Andrew Ilyas , and Kevin Kwok . 2018 b. Synthesizing robust adversarial examples . In International Conference on Machine Learning (ICML). Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok. 2018b. Synthesizing robust adversarial examples. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_2_6_1","volume-title":"ACM Transactions on graphics","author":"Avidan Shai","unstructured":"Shai Avidan and Ariel Shamir . 2007. Seam carving for content-aware image resizing . In ACM Transactions on graphics , Vol. 26 . 10. Shai Avidan and Ariel Shamir. 2007. Seam carving for content-aware image resizing. In ACM Transactions on graphics, Vol. 26. 10."},{"key":"e_1_3_2_2_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2666652.2666662"},{"key":"e_1_3_2_2_8_1","volume-title":"USENIX Workshop on Offensive Technologies. USENIX.","author":"Bursztein Elie","year":"2014","unstructured":"Elie Bursztein , Jonathan Aigrain , Angelika Moscicki , and John C Mitchell . 2014 . The End is Nigh: Generic Solving of Text-based CAPTCHAs .. In USENIX Workshop on Offensive Technologies. USENIX. Elie Bursztein, Jonathan Aigrain, Angelika Moscicki, and John C Mitchell. 2014. The End is Nigh: Generic Solving of Text-based CAPTCHAs.. In USENIX Workshop on Offensive Technologies. USENIX."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"crossref","unstructured":"Nicholas Carlini and David Wagner. 2018. Audio adversarial examples: Targeted attacks on speech-to-text. In DLS.  Nicholas Carlini and David Wagner. 2018. Audio adversarial examples: Targeted attacks on speech-to-text. In DLS.","DOI":"10.1109\/SPW.2018.00009"},{"key":"e_1_3_2_2_12_1","volume-title":"Stateful Detection of Black-Box Adversarial Attacks. arXiv preprint arXiv:1907.05587","author":"Chen Steven","year":"2019","unstructured":"Steven Chen , Nicholas Carlini , and David Wagner . 2019. Stateful Detection of Black-Box Adversarial Attacks. arXiv preprint arXiv:1907.05587 ( 2019 ). Steven Chen, Nicholas Carlini, and David Wagner. 2019. Stateful Detection of Black-Box Adversarial Attacks. arXiv preprint arXiv:1907.05587 (2019)."},{"key":"e_1_3_2_2_13_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen , Chang Liu , Bo Li , Kimberly Lu , and Dawn Song . 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 ( 2017 ). Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_2_14_1","volume-title":"Sentinet: Detecting physical attacks against deep learning systems. arXiv preprint arXiv:1812.00292","author":"Chou Edward","year":"2018","unstructured":"Edward Chou , Florian Tram\u00e8r , Giancarlo Pellegrino , and Dan Boneh . 2018 . Sentinet: Detecting physical attacks against deep learning systems. arXiv preprint arXiv:1812.00292 (2018). Edward Chou, Florian Tram\u00e8r, Giancarlo Pellegrino, and Dan Boneh. 2018. Sentinet: Detecting physical attacks against deep learning systems. arXiv preprint arXiv:1812.00292 (2018)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866310"},{"key":"e_1_3_2_2_16_1","unstructured":"Justin Crites and Mathias Ricken. 2004. Automatic ad blocking: Improving AdBlock for the Mozilla platform. (2004).  Justin Crites and Mathias Ricken. 2004. Automatic ad blocking: Improving AdBlock for the Mozilla platform. (2004)."},{"key":"e_1_3_2_2_17_1","unstructured":"Digital Advertising Alliance (DAA). 2009. Self Regulatory Principles for Online Behavioral Advertising. https:\/\/digitaladvertisingalliance.org\/sites\/aboutads\/files\/DAA_files\/seven-principles-07-01-09.pdf.  Digital Advertising Alliance (DAA). 2009. Self Regulatory Principles for Online Behavioral Advertising. https:\/\/digitaladvertisingalliance.org\/sites\/aboutads\/files\/DAA_files\/seven-principles-07-01-09.pdf."},{"key":"e_1_3_2_2_18_1","unstructured":"Digital Advertising Alliance (DAA). 2013. DAA Icon Ad Marker Creative Guidelines. https:\/\/digitaladvertisingalliance.org\/sites\/aboutads\/files\/DAA_files\/DAA_Icon_Ad_Creative_Guidelines.pdf.  Digital Advertising Alliance (DAA). 2013. DAA Icon Ad Marker Creative Guidelines. https:\/\/digitaladvertisingalliance.org\/sites\/aboutads\/files\/DAA_files\/DAA_Icon_Ad_Creative_Guidelines.pdf."},{"key":"e_1_3_2_2_19_1","unstructured":"Benjamin Edelman. 2009. False and Deceptive Display Ads at Yahoo's Right Media. http:\/\/www.benedelman.org\/rightmedia-deception.  Benjamin Edelman. 2009. False and Deceptive Display Ads at Yahoo's Right Media. http:\/\/www.benedelman.org\/rightmedia-deception."},{"key":"e_1_3_2_2_20_1","volume-title":"A rotation and a translation suffice: Fooling CNNs with simple transformations. arXiv preprint arXiv:1712.02779","author":"Engstrom Logan","year":"2017","unstructured":"Logan Engstrom , Dimitris Tsipras , Ludwig Schmidt , and Aleksander Madry . 2017. A rotation and a translation suffice: Fooling CNNs with simple transformations. arXiv preprint arXiv:1712.02779 ( 2017 ). Logan Engstrom, Dimitris Tsipras, Ludwig Schmidt, and Aleksander Madry. 2017. A rotation and a translation suffice: Fooling CNNs with simple transformations. arXiv preprint arXiv:1712.02779 (2017)."},{"key":"e_1_3_2_2_21_1","volume-title":"Physical Adversarial Examples for Object Detectors. In USENIX Workshop on Offensive Technologies. USENIX.","author":"Eykholt Kevin","year":"2018","unstructured":"Kevin Eykholt , Ivan Evtimov , Earlence Fernandes , Bo Li , Amir Rahmati , Florian Tram\u00e8r , Atul Prakash , Tadayoshi Kohno , and Dawn Song . 2018 a. Physical Adversarial Examples for Object Detectors. In USENIX Workshop on Offensive Technologies. USENIX. Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Florian Tram\u00e8r, Atul Prakash, Tadayoshi Kohno, and Dawn Song. 2018a. Physical Adversarial Examples for Object Detectors. In USENIX Workshop on Offensive Technologies. USENIX."},{"key":"e_1_3_2_2_22_1","volume-title":"Robust Physical-World Attacks on Deep Learning Visual Classification. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 1625--1634","author":"Eykholt Kevin","year":"2018","unstructured":"Kevin Eykholt , Ivan Evtimov , Earlence Fernandes , Bo Li , Amir Rahmati , Chaowei Xiao , Atul Prakash , Tadayoshi Kohno , and Dawn Song . 2018 b. Robust Physical-World Attacks on Deep Learning Visual Classification. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 1625--1634 . Kevin Eykholt, Ivan Evtimov, Earlence Fernandes, Bo Li, Amir Rahmati, Chaowei Xiao, Atul Prakash, Tadayoshi Kohno, and Dawn Song. 2018b. Robust Physical-World Attacks on Deep Learning Visual Classification. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 1625--1634."},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_2_24_1","volume-title":"Motivating the rules of the game for adversarial example research. arXiv preprint arXiv:1807.06732","author":"Gilmer Justin","year":"2018","unstructured":"Justin Gilmer , Ryan P Adams , Ian Goodfellow , David Andersen , and George E Dahl . 2018a. Motivating the rules of the game for adversarial example research. arXiv preprint arXiv:1807.06732 ( 2018 ). Justin Gilmer, Ryan P Adams, Ian Goodfellow, David Andersen, and George E Dahl. 2018a. Motivating the rules of the game for adversarial example research. arXiv preprint arXiv:1807.06732 (2018)."},{"key":"e_1_3_2_2_25_1","volume-title":"Adversarial spheres. arXiv preprint arXiv:1801.02774","author":"Gilmer Justin","year":"2018","unstructured":"Justin Gilmer , Luke Metz , Fartash Faghri , Samuel S Schoenholz , Maithra Raghu , Martin Wattenberg , and Ian Goodfellow . 2018b. Adversarial spheres. arXiv preprint arXiv:1801.02774 ( 2018 ). Justin Gilmer, Luke Metz, Fartash Faghri, Samuel S Schoenholz, Maithra Raghu, Martin Wattenberg, and Ian Goodfellow. 2018b. Adversarial spheres. arXiv preprint arXiv:1801.02774 (2018)."},{"key":"e_1_3_2_2_26_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Goodfellow Ian J","year":"2015","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and harnessing adversarial examples . In International Conference on Learning Representations (ICLR). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_27_1","volume-title":"On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280","author":"Grosse Kathrin","year":"2017","unstructured":"Kathrin Grosse , Praveen Manoharan , Nicolas Papernot , Michael Backes , and Patrick McDaniel . 2017a. On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280 ( 2017 ). Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel. 2017a. On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280 (2017)."},{"key":"e_1_3_2_2_28_1","unstructured":"Kathrin Grosse Nicolas Papernot Praveen Manoharan Michael Backes and Patrick McDaniel. 2017b. Adversarial perturbations against deep neural networks for malware classification In ESORICS. arXiv preprint arXiv:1606.04435.  Kathrin Grosse Nicolas Papernot Praveen Manoharan Michael Backes and Patrick McDaniel. 2017b. Adversarial perturbations against deep neural networks for malware classification In ESORICS. arXiv preprint arXiv:1606.04435."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2015-0018"},{"key":"e_1_3_2_2_30_1","volume-title":"Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong. arXiv preprint arXiv:1706.04701","author":"He Warren","year":"2017","unstructured":"Warren He , James Wei , Xinyun Chen , Nicholas Carlini , and Dawn Song . 2017. Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong. arXiv preprint arXiv:1706.04701 ( 2017 ). Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song. 2017. Adversarial Example Defenses: Ensembles of Weak Defenses are not Strong. arXiv preprint arXiv:1706.04701 (2017)."},{"key":"e_1_3_2_2_31_1","unstructured":"Jovanni Hernandez Akshay Jagadeesh and Jonathan Mayer. 2011. Tracking the trackers: The AdChoices icon. http:\/\/cyberlaw.stanford.edu\/blog\/2011\/08\/tracking-trackers-adchoices-icon.  Jovanni Hernandez Akshay Jagadeesh and Jonathan Mayer. 2011. Tracking the trackers: The AdChoices icon. http:\/\/cyberlaw.stanford.edu\/blog\/2011\/08\/tracking-trackers-adchoices-icon."},{"key":"e_1_3_2_2_32_1","volume-title":"ACM International conference on Multimedia. In ICM. ACM, 637--640","author":"Hsu Chao-Yung","year":"2009","unstructured":"Chao-Yung Hsu , Chun-Shien Lu , and Soo-Chang Pei . 2009 . ACM International conference on Multimedia. In ICM. ACM, 637--640 . Chao-Yung Hsu, Chun-Shien Lu, and Soo-Chang Pei. 2009. ACM International conference on Multimedia. In ICM. ACM, 637--640."},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.123"},{"key":"e_1_3_2_2_34_1","volume-title":"Black-box Adversarial Attacks with Limited Queries and Information. In International Conference on Machine Learning (ICML).","author":"Ilyas Andrew","year":"2018","unstructured":"Andrew Ilyas , Logan Engstrom , Anish Athalye , and Jessy Lin . 2018 . Black-box Adversarial Attacks with Limited Queries and Information. In International Conference on Machine Learning (ICML). Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin. 2018. Black-box Adversarial Attacks with Limited Queries and Information. In International Conference on Machine Learning (ICML)."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3131365.3131387"},{"key":"e_1_3_2_2_36_1","volume-title":"AdGraph: A Machine Learning Approach to Automatic and Effective Adblocking. arXiv preprint arXiv:1805.09155","author":"Iqbal Umar","year":"2018","unstructured":"Umar Iqbal , Zubair Shafiq , Peter Snyder , Shitong Zhu , Zhiyun Qian , and Benjamin Livshits . 2018. AdGraph: A Machine Learning Approach to Automatic and Effective Adblocking. arXiv preprint arXiv:1805.09155 ( 2018 ). Umar Iqbal, Zubair Shafiq, Peter Snyder, Shitong Zhu, Zhiyun Qian, and Benjamin Livshits. 2018. AdGraph: A Machine Learning Approach to Automatic and Effective Adblocking. arXiv preprint arXiv:1805.09155 (2018)."},{"key":"e_1_3_2_2_37_1","unstructured":"Ilker Koksal. 2018. How Alexa Is Changing The Future Of Advertising. https:\/\/www.forbes.com\/sites\/ilkerkoksal\/2018\/12\/11\/how-alexa-is-changing-the-future-of-advertising.  Ilker Koksal. 2018. How Alexa Is Changing The Future Of Advertising. https:\/\/www.forbes.com\/sites\/ilkerkoksal\/2018\/12\/11\/how-alexa-is-changing-the-future-of-advertising."},{"key":"e_1_3_2_2_38_1","unstructured":"Zico Kolter and Eric Wong. 2017. Provable defenses against adversarial examples via the convex outer adversarial polytope. In ICML.  Zico Kolter and Eric Wong. 2017. Provable defenses against adversarial examples via the convex outer adversarial polytope. In ICML."},{"key":"e_1_3_2_2_39_1","volume-title":"Tracking protection in Firefox for privacy and performance. arXiv preprint arXiv:1506.04104","author":"Kontaxis Georgios","year":"2015","unstructured":"Georgios Kontaxis and Monica Chew . 2015. Tracking protection in Firefox for privacy and performance. arXiv preprint arXiv:1506.04104 ( 2015 ). Georgios Kontaxis and Monica Chew. 2015. Tracking protection in Firefox for privacy and performance. arXiv preprint arXiv:1506.04104 (2015)."},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2008.10"},{"key":"e_1_3_2_2_41_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . 2017 a. Adversarial examples in the physical world . In International Conference on Learning Representations (ICLR). Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2017a. Adversarial examples in the physical world. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_42_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . 2017 b. Adversarial Machine Learning at Scale . In International Conference on Learning Representations (ICLR). Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2017b. Adversarial Machine Learning at Scale. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2381966.2381970"},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382267"},{"key":"e_1_3_2_2_45_1","doi-asserted-by":"publisher","DOI":"10.1023\/B:VISI.0000029664.99615.94"},{"key":"e_1_3_2_2_46_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2018 . Towards deep learning models resistant to adversarial attacks . In International Conference on Learning Representations (ICLR). Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987460"},{"key":"e_1_3_2_2_48_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Metzen Jan Hendrik","year":"2017","unstructured":"Jan Hendrik Metzen , Tim Genewein , Volker Fischer , and Bastian Bischoff . 2017 . On detecting adversarial perturbations . In International Conference on Learning Representations (ICLR). Jan Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff. 2017. On detecting adversarial perturbations. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_49_1","volume-title":"Universal Adversarial Perturbations. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 1765--1773","author":"Moosavi-Dezfooli Seyed-Mohsen","year":"2017","unstructured":"Seyed-Mohsen Moosavi-Dezfooli , Alhussein Fawzi , Omar Fawzi , and Pascal Frossard . 2017 . Universal Adversarial Perturbations. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 1765--1773 . Seyed-Mohsen Moosavi-Dezfooli, Alhussein Fawzi, Omar Fawzi, and Pascal Frossard. 2017. Universal Adversarial Perturbations. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 1765--1773."},{"key":"e_1_3_2_2_50_1","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2017-0032"},{"key":"e_1_3_2_2_51_1","volume-title":"A first look at ad-block detection: A new arms race on the web. arXiv preprint arXiv:1605.05841","author":"Mughees Muhammad Haris","year":"2016","unstructured":"Muhammad Haris Mughees , Zhiyun Qian , Zubair Shafiq , Karishma Dash , and Pan Hui . 2016. A first look at ad-block detection: A new arms race on the web. arXiv preprint arXiv:1605.05841 ( 2016 ). Muhammad Haris Mughees, Zhiyun Qian, Zubair Shafiq, Karishma Dash, and Pan Hui. 2016. A first look at ad-block detection: A new arms race on the web. arXiv preprint arXiv:1605.05841 (2016)."},{"key":"e_1_3_2_2_52_1","unstructured":"Meghan Neal. 2016. You're Going to Need an Ad Blocker for Your Next TV. https:\/\/motherboard.vice.com\/en_us\/article\/mg7ek8\/youre-going-to-need-an-ad-blocker-for-your-next-tv.  Meghan Neal. 2016. You're Going to Need an Ad Blocker for Your Next TV. https:\/\/motherboard.vice.com\/en_us\/article\/mg7ek8\/youre-going-to-need-an-ad-blocker-for-your-next-tv."},{"key":"e_1_3_2_2_53_1","volume-title":"USENIX Workshop on Free and Open Communications on the Internet.","author":"Nithyanand Rishab","year":"2016","unstructured":"Rishab Nithyanand , Sheharbano Khattak , Mobin Javed , Narseo Vallina-Rodriguez , Marjan Falahrastegar , Julia E Powles , ED Cristofaro , Hamed Haddadi , and Steven J Murdoch . 2016 . Adblocking and counter blocking: A slice of the arms race . In USENIX Workshop on Free and Open Communications on the Internet. Rishab Nithyanand, Sheharbano Khattak, Mobin Javed, Narseo Vallina-Rodriguez, Marjan Falahrastegar, Julia E Powles, ED Cristofaro, Hamed Haddadi, and Steven J Murdoch. 2016. Adblocking and counter blocking: A slice of the arms race. In USENIX Workshop on Free and Open Communications on the Internet."},{"key":"e_1_3_2_2_54_1","unstructured":"Paraska Oleksandr. 2018. Towards more intelligent ad blocking on the web. https:\/\/medium.com\/@shoniko\/towards-more-intelligent-ad-blocking-on-the-web-9f67bf2a12b5.  Paraska Oleksandr. 2018. Towards more intelligent ad blocking on the web. https:\/\/medium.com\/@shoniko\/towards-more-intelligent-ad-blocking-on-the-web-9f67bf2a12b5."},{"key":"e_1_3_2_2_55_1","unstructured":"George Paliy. 2018. The Future Of Advertising In Virtual Reality. https:\/\/stopad.io\/blog\/future-virtual-reality-advertising.  George Paliy. 2018. The Future Of Advertising In Virtual Reality. https:\/\/stopad.io\/blog\/future-virtual-reality-advertising."},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_2_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_2_58_1","volume-title":"Towards the Science of Security and Privacy in Machine Learning. arXiv preprint arXiv:1611.03814","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot , Patrick McDaniel , Arunesh Sinha , and Michael Wellman . 2016b. Towards the Science of Security and Privacy in Machine Learning. arXiv preprint arXiv:1611.03814 ( 2016 ). Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael Wellman. 2016b. Towards the Science of Security and Privacy in Machine Learning. arXiv preprint arXiv:1611.03814 (2016)."},{"key":"e_1_3_2_2_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133959"},{"key":"e_1_3_2_2_60_1","volume-title":"USENIX Workshop on Offensive Technologies.","author":"Pellegrino Giancarlo","year":"2015","unstructured":"Giancarlo Pellegrino , Christian Rossow , Fabrice J Ryba , Thomas C Schmidt , and Matthias W\"ahlisch. 2015 . Cashing Out the Great Cannon? On Browser-Based DDoS Attacks and Economics .. In USENIX Workshop on Offensive Technologies. Giancarlo Pellegrino, Christian Rossow, Fabrice J Ryba, Thomas C Schmidt, and Matthias W\"ahlisch. 2015. Cashing Out the Great Cannon? On Browser-Based DDoS Attacks and Economics.. In USENIX Workshop on Offensive Technologies."},{"key":"e_1_3_2_2_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/2815675.2815705"},{"key":"e_1_3_2_2_62_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Raghunathan Aditi","year":"2018","unstructured":"Aditi Raghunathan , Jacob Steinhardt , and Percy Liang . 2018 . Certified defenses against adversarial examples . In International Conference on Learning Representations (ICLR). Aditi Raghunathan, Jacob Steinhardt, and Percy Liang. 2018. Certified defenses against adversarial examples. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_63_1","volume-title":"Real-Time Object Detection. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 779--788","author":"Redmon Joseph","year":"2016","unstructured":"Joseph Redmon , Santosh Kumar Divvala , Ross B. Girshick , and Ali Farhadi . 2016 . You Only Look Once: Unified , Real-Time Object Detection. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 779--788 . Joseph Redmon, Santosh Kumar Divvala, Ross B. Girshick, and Ali Farhadi. 2016. You Only Look Once: Unified, Real-Time Object Detection. In Conference on Computer Vision and Pattern Recognition (CVPR). IEEE, 779--788."},{"key":"e_1_3_2_2_64_1","volume-title":"Stronger. In Conference on Computer Vision and Pattern Recognition (CVPR), IEEE (Ed.).","author":"Redmon Joseph","year":"2017","unstructured":"Joseph Redmon and Ali Farhadi . 2017 . YOLO9000: Better, Faster , Stronger. In Conference on Computer Vision and Pattern Recognition (CVPR), IEEE (Ed.). Joseph Redmon and Ali Farhadi. 2017. YOLO9000: Better, Faster, Stronger. In Conference on Computer Vision and Pattern Recognition (CVPR), IEEE (Ed.)."},{"key":"e_1_3_2_2_65_1","volume-title":"YOLOv3: An Incremental Improvement. arXiv preprint arXiv:1804.02767","author":"Redmon Joseph","year":"2018","unstructured":"Joseph Redmon and Ali Farhadi . 2018. YOLOv3: An Incremental Improvement. arXiv preprint arXiv:1804.02767 ( 2018 ). Joseph Redmon and Ali Farhadi. 2018. YOLOv3: An Incremental Improvement. arXiv preprint arXiv:1804.02767 (2018)."},{"key":"e_1_3_2_2_66_1","volume-title":"Evolution strategies as a scalable alternative to reinforcement learning. arXiv preprint arXiv:1703.03864","author":"Salimans Tim","year":"2017","unstructured":"Tim Salimans , Jonathan Ho , Xi Chen , Szymon Sidor , and Ilya Sutskever . 2017. Evolution strategies as a scalable alternative to reinforcement learning. arXiv preprint arXiv:1703.03864 ( 2017 ). Tim Salimans, Jonathan Ho, Xi Chen, Szymon Sidor, and Ilya Sutskever. 2017. Evolution strategies as a scalable alternative to reinforcement learning. arXiv preprint arXiv:1703.03864 (2017)."},{"key":"e_1_3_2_2_67_1","unstructured":"Ludwig Schmidt Shibani Santurkar Dimitris Tsipras Kunal Talwar and Aleksander Madry. 2018. Adversarially robust generalization requires more data. In Advances in Neural Information Processing Systems. 5014--5026.  Ludwig Schmidt Shibani Santurkar Dimitris Tsipras Kunal Talwar and Aleksander Madry. 2018. Adversarially robust generalization requires more data. In Advances in Neural Information Processing Systems. 5014--5026."},{"key":"e_1_3_2_2_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978392"},{"key":"e_1_3_2_2_69_1","volume-title":"Attacking the Madry Defense Model with $ L_1 $-based Adversarial Examples. arXiv preprint arXiv:1710.10733","author":"Sharma Yash","year":"2017","unstructured":"Yash Sharma and Pin-Yu Chen . 2017. Attacking the Madry Defense Model with $ L_1 $-based Adversarial Examples. arXiv preprint arXiv:1710.10733 ( 2017 ). Yash Sharma and Pin-Yu Chen. 2017. Attacking the Madry Defense Model with $ L_1 $-based Adversarial Examples. arXiv preprint arXiv:1710.10733 (2017)."},{"key":"e_1_3_2_2_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_2_71_1","volume-title":"IEEE International Conference on Industrial Technology. IEEE.","author":"Singh Ashish Kumar","year":"2009","unstructured":"Ashish Kumar Singh and Vidyasagar Potdar . 2009 . Blocking online advertising-A state of the art . In IEEE International Conference on Industrial Technology. IEEE. Ashish Kumar Singh and Vidyasagar Potdar. 2009. Blocking online advertising-A state of the art. In IEEE International Conference on Industrial Technology. IEEE."},{"key":"e_1_3_2_2_72_1","volume-title":"Fooling OCR Systems with Adversarial Text Images. arXiv preprint arXiv:1802.05385","author":"Song Congzheng","year":"2018","unstructured":"Congzheng Song and Vitaly Shmatikov . 2018. Fooling OCR Systems with Adversarial Text Images. arXiv preprint arXiv:1802.05385 ( 2018 ). Congzheng Song and Vitaly Shmatikov. 2018. Fooling OCR Systems with Adversarial Text Images. arXiv preprint arXiv:1802.05385 (2018)."},{"key":"e_1_3_2_2_73_1","volume-title":"IEEE Symposium on Security and Privacy.","author":"Srndic Nedim","year":"2014","unstructured":"Nedim Srndic and Pavel Laskov . 2014 . Practical evasion of a learning-based classifier: A case study . In IEEE Symposium on Security and Privacy. Nedim Srndic and Pavel Laskov. 2014. Practical evasion of a learning-based classifier: A case study. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_2_74_1","volume-title":"The Future of Ad Blocking: An Analytical Framework and New Techniques. arXiv preprint arXiv:1705.08568","author":"Storey Grant","year":"2017","unstructured":"Grant Storey , Dillon Reisman , Jonathan Mayer , and Arvind Narayanan . 2017a. The Future of Ad Blocking: An Analytical Framework and New Techniques. arXiv preprint arXiv:1705.08568 ( 2017 ). Grant Storey, Dillon Reisman, Jonathan Mayer, and Arvind Narayanan. 2017a. The Future of Ad Blocking: An Analytical Framework and New Techniques. arXiv preprint arXiv:1705.08568 (2017)."},{"key":"e_1_3_2_2_75_1","volume-title":"Perceptual Ad Highlighter. Chrome Extension: https:\/\/chrome.google.com\/webstore\/detail\/perceptual-ad-highlighter\/mahgiflleahghaapkboihnbhdplhnchp","author":"Storey Grant","unstructured":"Grant Storey , Dillon Reisman , Jonathan Mayer , and Arvind Narayanan . 2017b. Perceptual Ad Highlighter. Chrome Extension: https:\/\/chrome.google.com\/webstore\/detail\/perceptual-ad-highlighter\/mahgiflleahghaapkboihnbhdplhnchp ; Source code: https:\/\/github.com\/citp\/ad-blocking. Grant Storey, Dillon Reisman, Jonathan Mayer, and Arvind Narayanan. 2017b. Perceptual Ad Highlighter. Chrome Extension: https:\/\/chrome.google.com\/webstore\/detail\/perceptual-ad-highlighter\/mahgiflleahghaapkboihnbhdplhnchp; Source code: https:\/\/github.com\/citp\/ad-blocking."},{"key":"e_1_3_2_2_76_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2014 . Intriguing properties of neural networks . In International Conference on Learning Representations (ICLR). Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_77_1","volume-title":"et almbox","author":"Tigas Panagiotis","year":"2019","unstructured":"Panagiotis Tigas , Samuel T King , Benjamin Livshits , et almbox . 2019 . Percival : Making In-Browser Perceptual Ad Blocking Practical With Deep Learning . arXiv preprint arXiv:1905.07444 (2019). Panagiotis Tigas, Samuel T King, Benjamin Livshits, et almbox. 2019. Percival: Making In-Browser Perceptual Ad Blocking Practical With Deep Learning. arXiv preprint arXiv:1905.07444 (2019)."},{"key":"e_1_3_2_2_78_1","volume-title":"Adversarial Training and Robustness for Multiple Perturbations. arXiv preprint arXiv:1904.13000","author":"Tram\u00e8r Florian","year":"2019","unstructured":"Florian Tram\u00e8r and Dan Boneh . 2019. Adversarial Training and Robustness for Multiple Perturbations. arXiv preprint arXiv:1904.13000 ( 2019 ). Florian Tram\u00e8r and Dan Boneh. 2019. Adversarial Training and Robustness for Multiple Perturbations. arXiv preprint arXiv:1904.13000 (2019)."},{"key":"e_1_3_2_2_79_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Tram\u00e8r Florian","year":"2018","unstructured":"Florian Tram\u00e8r , Alexey Kurakin , Nicolas Papernot , Ian Goodfellow , Dan Boneh , and Patrick McDaniel . 2018 . Ensemble adversarial training: Attacks and defenses . In International Conference on Learning Representations (ICLR). Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2018. Ensemble adversarial training: Attacks and defenses. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_80_1","volume-title":"USENIX Security Symposium.","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r , Fan Zhang , Ari Juels , Michael K Reiter , and Thomas Ristenpart . 2016 . Stealing machine learning models via prediction apis . In USENIX Security Symposium. Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction apis. In USENIX Security Symposium."},{"key":"e_1_3_2_2_81_1","unstructured":"uBlockOrigin. Issue 3367: Facebook. https:\/\/github.com\/uBlockOrigin\/uAssets\/issues\/3367.  uBlockOrigin. Issue 3367: Facebook. https:\/\/github.com\/uBlockOrigin\/uAssets\/issues\/3367."},{"key":"e_1_3_2_2_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/2335356.2335362"},{"key":"e_1_3_2_2_83_1","unstructured":"Enn\u00e8l van Eeden and Wilson Chow. 2018. Perspectives from the Global Entertainment & Media Outlook 2018--2022. https:\/\/www.statista.com\/topics\/1176\/online-advertising\/.  Enn\u00e8l van Eeden and Wilson Chow. 2018. Perspectives from the Global Entertainment & Media Outlook 2018--2022. https:\/\/www.statista.com\/topics\/1176\/online-advertising\/."},{"key":"e_1_3_2_2_84_1","volume-title":"Who Filters the Filters: Understanding the Growth, Usefulness and Efficiency of Crowdsourced Ad Blocking. arXiv preprint arXiv:1810.09160","author":"Vastel Antoine","year":"2018","unstructured":"Antoine Vastel , Peter Snyder , and Benjamin Livshits . 2018. Who Filters the Filters: Understanding the Growth, Usefulness and Efficiency of Crowdsourced Ad Blocking. arXiv preprint arXiv:1810.09160 ( 2018 ). Antoine Vastel, Peter Snyder, and Benjamin Livshits. 2018. Who Filters the Filters: Understanding the Growth, Usefulness and Efficiency of Crowdsourced Ad Blocking. arXiv preprint arXiv:1810.09160 (2018)."},{"key":"e_1_3_2_2_85_1","doi-asserted-by":"publisher","DOI":"10.1109\/HotWeb.2016.21"},{"key":"e_1_3_2_2_86_1","volume-title":"Understanding Malvertising Through Ad-Injecting Browser Extensions. In International Conference on World Wide Web.","author":"Xing Xinyu","year":"2015","unstructured":"Xinyu Xing , Wei Meng , Byoungyoung Lee , Udi Weinsberg , Anmol Sheth , Roberto Perdisci , and Wenke Lee . 2015 . Understanding Malvertising Through Ad-Injecting Browser Extensions. In International Conference on World Wide Web. Xinyu Xing, Wei Meng, Byoungyoung Lee, Udi Weinsberg, Anmol Sheth, Roberto Perdisci, and Wenke Lee. 2015. Understanding Malvertising Through Ad-Injecting Browser Extensions. In International Conference on World Wide Web."},{"key":"e_1_3_2_2_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243754"},{"key":"e_1_3_2_2_88_1","volume-title":"Measuring and Disrupting Anti-Adblockers Using Differential Execution Analysis. In Network and Distributed System Security Symposium (NDSS).","author":"Zhu Shitong","year":"2018","unstructured":"Shitong Zhu , Xunchao Hu , Zhiyun Qian , Zubair Shafiq , and Heng Yin . 2018 . Measuring and Disrupting Anti-Adblockers Using Differential Execution Analysis. In Network and Distributed System Security Symposium (NDSS). Shitong Zhu, Xunchao Hu, Zhiyun Qian, Zubair Shafiq, and Heng Yin. 2018. Measuring and Disrupting Anti-Adblockers Using Differential Execution Analysis. In Network and Distributed System Security Symposium (NDSS)."}],"event":{"name":"CCS '19: 2019 ACM SIGSAC Conference on Computer and Communications Security","location":"London United Kingdom","acronym":"CCS '19","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354222","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3319535.3354222","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T23:24:03Z","timestamp":1750202643000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3319535.3354222"}},"subtitle":["Perceptual Ad Blocking meets Adversarial Machine Learning"],"short-title":[],"issued":{"date-parts":[[2019,11,6]]},"references-count":88,"alternative-id":["10.1145\/3319535.3354222","10.1145\/3319535"],"URL":"https:\/\/doi.org\/10.1145\/3319535.3354222","relation":{},"subject":[],"published":{"date-parts":[[2019,11,6]]},"assertion":[{"value":"2019-11-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}