{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,7]],"date-time":"2025-11-07T13:35:24Z","timestamp":1762522524817,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,11,2]],"date-time":"2020-11-02T00:00:00Z","timestamp":1604275200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation","award":["SaTC-1929300, TWC-1563697, IUCRC 1916762"],"award-info":[{"award-number":["SaTC-1929300, TWC-1563697, IUCRC 1916762"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,11,2]]},"DOI":"10.1145\/3400302.3418782","type":"proceedings-article","created":{"date-parts":[[2020,12,18]],"date-time":"2020-12-18T01:19:19Z","timestamp":1608254359000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["New passive and active attacks on deep neural networks in medical applications"],"prefix":"10.1145","author":[{"given":"Cheng","family":"Gongye","sequence":"first","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongjia","family":"Li","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiang","family":"Zhang","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Majid","family":"Sabbagh","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Geng","family":"Yuan","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xue","family":"Lin","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thomas","family":"Wahl","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yunsi","family":"Fei","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,12,17]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"On Subnormal Floating Point and Abnormal Timing. In 2015 IEEE Symposium on Security and Privacy, SP 2015","author":"Andrysco Marc","year":"2015","unstructured":"Marc Andrysco , David Kohlbrenner , Keaton Mowery , Ranjit Jhala , Sorin Lerner , and Hovav Shacham . 2015 . On Subnormal Floating Point and Abnormal Timing. In 2015 IEEE Symposium on Security and Privacy, SP 2015 , San Jose, CA, USA, May 17--21 , 2015. IEEE Computer Society, 623--639. Marc Andrysco, David Kohlbrenner, Keaton Mowery, Ranjit Jhala, Sorin Lerner, and Hovav Shacham. 2015. On Subnormal Floating Point and Abnormal Timing. In 2015 IEEE Symposium on Security and Privacy, SP 2015, San Jose, CA, USA, May 17--21, 2015. IEEE Computer Society, 623--639."},{"key":"e_1_3_2_1_2_1","volume-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye , Nicholas Carlini , and David Wagner . 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420 ( 2018 ). Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv preprint arXiv:1802.00420 (2018)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2012.2188769"},{"key":"e_1_3_2_1_4_1","volume-title":"CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel. In 28th USENIX Security Symposium (USENIX Security 19)","author":"Batina Lejla","year":"2019","unstructured":"Lejla Batina , Shivam Bhasin , Dirmanto Jap , and Stjepan Picek . 2019 . CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel. In 28th USENIX Security Symposium (USENIX Security 19) . USENIX Association, Santa Clara, CA, 515--532. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/batina Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek. 2019. CSI NN: Reverse Engineering of Neural Network Architectures Through Electromagnetic Side Channel. In 28th USENIX Security Symposium (USENIX Security 19). USENIX Association, Santa Clara, CA, 515--532. https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/batina"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","unstructured":"Jakub Breier Xiaolu Hou and et.al. 2018. Practical fault attack on deep neural networks. In CCS. 2204--2206.  Jakub Breier Xiaolu Hou and et.al. 2018. Practical fault attack on deep neural networks. In CCS. 2204--2206.","DOI":"10.1145\/3243734.3278519"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-28632-5_2"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.29007\/nwj8"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44371-2_25"},{"key":"e_1_3_2_1_9_1","volume-title":"Proc. Design Automation Conference.","author":"Gongye Cheng","year":"2020","unstructured":"Cheng Gongye , Yunsi Fei , and Thomas Wahl . 2020 . Reverse-Engineering Deep Neural Networks Using Floating-Point Timing Side-Channels . In Proc. Design Automation Conference. Cheng Gongye, Yunsi Fei, and Thomas Wahl. 2020. Reverse-Engineering Deep Neural Networks Using Floating-Point Timing Side-Channels. In Proc. Design Automation Conference."},{"key":"e_1_3_2_1_10_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_11_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Goodfellow Ian J","year":"2015","unstructured":"Ian J Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and harnessing adversarial examples . In International Conference on Learning Representations (ICLR). Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_14"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3195970.3196105"},{"key":"e_1_3_2_1_15_1","unstructured":"IEEE Standard Association. 2008. IEEE Standard for Floating-Point Arithmetic. 58 pages. http:\/\/grouper.ieee.org\/groups\/754\/.  IEEE Standard Association. 2008. IEEE Standard for Floating-Point Arithmetic. 58 pages. http:\/\/grouper.ieee.org\/groups\/754\/."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3152701.3152709"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2002.1028917"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-10838-9_7"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.14245\/ns.1938396.198"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2678373.2665726"},{"key":"e_1_3_2_1_21_1","volume-title":"Joon Beom Seo, and Namkug Kim.","author":"Lee June-Goo","year":"2017","unstructured":"June-Goo Lee , Sanghoon Jun , Young-Won Cho , Hyunna Lee , Guk Bae Kim , Joon Beom Seo, and Namkug Kim. 2017 . Deep learning in medical imaging: general overview. Korean journal of radiology 18, 4 (2017), 570--584. June-Goo Lee, Sanghoon Jun, Young-Won Cho, Hyunna Lee, Guk Bae Kim, Joon Beom Seo, and Namkug Kim. 2017. Deep learning in medical imaging: general overview. Korean journal of radiology 18, 4 (2017), 570--584."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.43"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Yannan Liu Lingxiao Wei Bo Luo and Qiang Xu. 2017. Fault injection attack on deep neural network. 131--138.  Yannan Liu Lingxiao Wei Bo Luo and Qiang Xu. 2017. Fault injection attack on deep neural network. 131--138.","DOI":"10.1109\/ICCAD.2017.8203770"},{"key":"e_1_3_2_1_24_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry , Aleksandar Makelov , Ludwig Schmidt , Dimitris Tsipras , and Adrian Vladu . 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 ( 2017 ). Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2012.21"},{"key":"e_1_3_2_1_26_1","volume-title":"Chexnet: Radiologist-level pneumonia detection on chest x-rays with deep learning. arXiv preprint arXiv:1711.05225","author":"Rajpurkar Pranav","year":"2017","unstructured":"Pranav Rajpurkar , Jeremy Irvin , Kaylie Zhu , Brandon Yang , Hershel Mehta , Tony Duan , Daisy Ding , Aarti Bagul , Curtis Langlotz , Katie Shpanskaya , 2017 . Chexnet: Radiologist-level pneumonia detection on chest x-rays with deep learning. arXiv preprint arXiv:1711.05225 (2017). Pranav Rajpurkar, Jeremy Irvin, Kaylie Zhu, Brandon Yang, Hershel Mehta, Tony Duan, Daisy Ding, Aarti Bagul, Curtis Langlotz, Katie Shpanskaya, et al. 2017. Chexnet: Radiologist-level pneumonia detection on chest x-rays with deep learning. arXiv preprint arXiv:1711.05225 (2017)."},{"key":"e_1_3_2_1_27_1","volume-title":"USENIX Security Symp. 71--86","author":"Rane Ashay","year":"2016","unstructured":"Ashay Rane , Calvin Lin , and Mohit Tiwari . 2016 . Secure, Precise, and Fast Floating-Point Operations on x86 Processors . In USENIX Security Symp. 71--86 . Ashay Rane, Calvin Lin, and Mohit Tiwari. 2016. Secure, Precise, and Fast Floating-Point Operations on x86 Processors. In USENIX Security Symp. 71--86."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC18072.2020.9218690"},{"volume-title":"Evaluating Fault Resiliency of Compressed Deep Neural Networks. In IEEE Int. Conf. on Embedded Software & Systems (ICESS).","author":"Sabbagh M.","key":"e_1_3_2_1_29_1","unstructured":"M. Sabbagh , C. Gongye , Y. Fei , and Y. Wang . 2019 . Evaluating Fault Resiliency of Compressed Deep Neural Networks. In IEEE Int. Conf. on Embedded Software & Systems (ICESS). M. Sabbagh, C. Gongye, Y. Fei, and Y. Wang. 2019. Evaluating Fault Resiliency of Compressed Deep Neural Networks. In IEEE Int. Conf. on Embedded Software & Systems (ICESS)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.274"},{"key":"e_1_3_2_1_31_1","volume-title":"CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management. In 26th USENIX Security Symposium (USENIX Security 17)","author":"Tang Adrian","year":"2017","unstructured":"Adrian Tang , Simha Sethumadhavan , and Salvatore Stolfo . 2017 . CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management. In 26th USENIX Security Symposium (USENIX Security 17) . USENIX Association, Vancouver, BC, 1057--1074. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/tang Adrian Tang, Simha Sethumadhavan, and Salvatore Stolfo. 2017. CLKSCREW: Exposing the Perils of Security-Oblivious Energy Management. In 26th USENIX Security Symposium (USENIX Security 17). USENIX Association, Vancouver, BC, 1057--1074. https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/tang"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2017.16"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/FDTC.2011.12"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00943"},{"key":"e_1_3_2_1_35_1","unstructured":"Zhang Xianyi Wang Qian and Zaheer Chothia. 2019. OpenBLAS. http:\/\/www.openblas.net\/  Zhang Xianyi Wang Qian and Zaheer Chothia. 2019. OpenBLAS. http:\/\/www.openblas.net\/"},{"key":"e_1_3_2_1_36_1","volume-title":"Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155","author":"Xu Weilin","year":"2017","unstructured":"Weilin Xu , David Evans , and Yanjun Qi. 2017. Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155 ( 2017 ). Weilin Xu, David Evans, and Yanjun Qi. 2017. Feature squeezing: Detecting adversarial examples in deep neural networks. arXiv preprint arXiv:1704.01155 (2017)."},{"key":"e_1_3_2_1_37_1","volume-title":"Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures.","author":"Yan Mengjia","year":"2020","unstructured":"Mengjia Yan , Christopher W. Fletcher , and Josep Torrellas . 2020 . Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures. , 2003--2020 pages. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/yan Mengjia Yan, Christopher W. Fletcher, and Josep Torrellas. 2020. Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures., 2003--2020 pages. https:\/\/www.usenix.org\/conference\/usenixsecurity20\/presentation\/yan"},{"key":"e_1_3_2_1_38_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Yarom Yuval","year":"2014","unstructured":"Yuval Yarom and Katrina Falkner . 2014 . FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack . In 23rd USENIX Security Symposium (USENIX Security 14) . USENIX Association, San Diego, CA, 719--732. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/yarom Yuval Yarom and Katrina Falkner. 2014. FLUSH+RELOAD: A High Resolution, Low Noise, L3 Cache Side-Channel Attack. In 23rd USENIX Security Symposium (USENIX Security 14). USENIX Association, San Diego, CA, 719--732. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/yarom"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3316781.3317825"},{"key":"e_1_3_2_1_40_1","unstructured":"Yi Zhong. 2020. COVID-19-CXR: A Special And Simple DCNN Models. https:\/\/github.com\/ZY-ZRY\/COVID19-CXR.  Yi Zhong. 2020. COVID-19-CXR: A Special And Simple DCNN Models. https:\/\/github.com\/ZY-ZRY\/COVID19-CXR."},{"key":"e_1_3_2_1_41_1","volume-title":"Using Deep Convolutional Neural Networks to Diagnose COVID-19 From Chest X-Ray Images. arXiv preprint arXiv:2007.09695","author":"Zhong Yi","year":"2020","unstructured":"Yi Zhong . 2020. Using Deep Convolutional Neural Networks to Diagnose COVID-19 From Chest X-Ray Images. arXiv preprint arXiv:2007.09695 ( 2020 ). Yi Zhong. 2020. Using Deep Convolutional Neural Networks to Diagnose COVID-19 From Chest X-Ray Images. arXiv preprint arXiv:2007.09695 (2020)."}],"event":{"name":"ICCAD '20: IEEE\/ACM International Conference on Computer-Aided Design","sponsor":["SIGDA ACM Special Interest Group on Design Automation","IEEE CAS","IEEE CEDA","IEEE CS"],"location":"Virtual Event USA","acronym":"ICCAD '20"},"container-title":["Proceedings of the 39th International Conference on Computer-Aided Design"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3400302.3418782","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3400302.3418782","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3400302.3418782","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:38:43Z","timestamp":1750199923000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3400302.3418782"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,11,2]]},"references-count":41,"alternative-id":["10.1145\/3400302.3418782","10.1145\/3400302"],"URL":"https:\/\/doi.org\/10.1145\/3400302.3418782","relation":{},"subject":[],"published":{"date-parts":[[2020,11,2]]},"assertion":[{"value":"2020-12-17","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}