{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T16:35:02Z","timestamp":1784046902670,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":79,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,7,11]],"date-time":"2021-07-11T00:00:00Z","timestamp":1625961600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,7,11]]},"DOI":"10.1145\/3460319.3464816","type":"proceedings-article","created":{"date-parts":[[2021,7,8]],"date-time":"2021-07-08T22:18:43Z","timestamp":1625782723000},"page":"139-151","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":44,"title":["ModelDiff: testing-based DNN similarity comparison for model reuse detection"],"prefix":"10.1145","author":[{"given":"Yuanchun","family":"Li","sequence":"first","affiliation":[{"name":"Microsoft Research, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ziqi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Peking University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bingyan","family":"Liu","sequence":"additional","affiliation":[{"name":"Peking University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ziyue","family":"Yang","sequence":"additional","affiliation":[{"name":"Microsoft Research, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunxin","family":"Liu","sequence":"additional","affiliation":[{"name":"Tsinghua University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,7,11]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Adi Yossi","year":"2018","unstructured":"Yossi Adi , Carsten Baum , Moustapha Cisse , Benny Pinkas , and Joseph Keshet . 2018 . Turning your weakness into a strength: Watermarking deep neural networks by backdooring . In 27th USENIX Security Symposium (USENIX Security 18) . 1615\u20131631. Yossi Adi, Carsten Baum, Moustapha Cisse, Benny Pinkas, and Joseph Keshet. 2018. Turning your weakness into a strength: Watermarking deep neural networks by backdooring. In 27th USENIX Security Symposium (USENIX Security 18). 1615\u20131631."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338906.3338937"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102277"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSM.1998.738528"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/988241.988245"},{"key":"e_1_3_2_1_6_1","unstructured":"Xiaoyu Cao Jinyuan Jia and Neil Zhenqiang Gong. 2019. IPGuard: Protecting the Intellectual Property of Deep Neural Networks via Fingerprinting the Classification Boundary. arXiv preprint arXiv:1910.12903.  Xiaoyu Cao Jinyuan Jia and Neil Zhenqiang Gong. 2019. IPGuard: Protecting the Intellectual Property of Deep Neural Networks via Fingerprinting the Classification Boundary. arXiv preprint arXiv:1910.12903."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2505515.2507848"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3307650.3322251"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3323873.3325042"},{"key":"e_1_3_2_1_10_1","first-page":"102","article-title":"Dawnbench: An end-to-end deep learning benchmark and competition","volume":"100","author":"Coleman Cody","year":"2017","unstructured":"Cody Coleman , Deepak Narayanan , Daniel Kang , Tian Zhao , Jian Zhang , Luigi Nardi , Peter Bailis , Kunle Olukotun , Chris R\u00e9 , and Matei Zaharia . 2017 . Dawnbench: An end-to-end deep learning benchmark and competition . Training , 100 , 101 (2017), 102 . Cody Coleman, Deepak Narayanan, Daniel Kang, Tian Zhao, Jian Zhang, Luigi Nardi, Peter Bailis, Kunle Olukotun, Chris R\u00e9, and Matei Zaharia. 2017. Dawnbench: An end-to-end deep learning benchmark and competition. Training, 100, 101 (2017), 102.","journal-title":"Training"},{"key":"e_1_3_2_1_11_1","unstructured":"Dansplaining. 2018. How much did AlphaGo Zero cost? https:\/\/www.yuzeh.com\/data\/agz-cost.html  Dansplaining. 2018. How much did AlphaGo Zero cost? https:\/\/www.yuzeh.com\/data\/agz-cost.html"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304051"},{"key":"e_1_3_2_1_13_1","volume-title":"ICML workshop on understanding and improving generalization in deep learning.","author":"Davchev Todor","year":"2019","unstructured":"Todor Davchev , Timos Korres , Stathi Fotiadis , Nick Antonopoulos , and Subramanian Ramamoorthy . 2019 . An empirical evaluation of adversarial robustness under transfer learning . In ICML workshop on understanding and improving generalization in deep learning. Todor Davchev, Timos Korres, Stathi Fotiadis, Nick Antonopoulos, and Subramanian Ramamoorthy. 2019. An empirical evaluation of adversarial robustness under transfer learning. In ICML workshop on understanding and improving generalization in deep learning."},{"key":"e_1_3_2_1_14_1","volume-title":"Hasan Ferit Eniser, and Alper Sen","author":"Demir Samet","year":"2019","unstructured":"Samet Demir , Hasan Ferit Eniser, and Alper Sen . 2019 . DeepSmartFuzzer: Reward Guided Test Generation For Deep Learning . arXiv preprint arXiv:1911.10621. Samet Demir, Hasan Ferit Eniser, and Alper Sen. 2019. DeepSmartFuzzer: Reward Guided Test Generation For Deep Learning. arXiv preprint arXiv:1911.10621."},{"key":"e_1_3_2_1_15_1","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Demontis Ambra","year":"2019","unstructured":"Ambra Demontis , Marco Melis , Maura Pintor , Matthew Jagielski , Battista Biggio , Alina Oprea , Cristina Nita-Rotaru , and Fabio Roli . 2019 . Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks . In 28th USENIX Security Symposium (USENIX Security 19) . 321\u2013338. Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks. In 28th USENIX Security Symposium (USENIX Security 19). 321\u2013338."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00003"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00444"},{"key":"e_1_3_2_1_19_1","volume-title":"23rd USENIX Security Symposium (USENIX Security 14)","author":"Egele Manuel","year":"2014","unstructured":"Manuel Egele , Maverick Woo , Peter Chapman , and David Brumley . 2014 . Blanket execution: Dynamic similarity testing for program binaries and components . In 23rd USENIX Security Symposium (USENIX Security 14) . 303\u2013317. Manuel Egele, Maverick Woo, Peter Chapman, and David Brumley. 2014. Blanket execution: Dynamic similarity testing for program binaries and components. In 23rd USENIX Security Symposium (USENIX Security 14). 303\u2013317."},{"key":"e_1_3_2_1_20_1","volume-title":"Kam Woh Ng, and Chee Seng Chan","author":"Fan Lixin","year":"2019","unstructured":"Lixin Fan , Kam Woh Ng, and Chee Seng Chan . 2019 . Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks. In Advances in Neural Information Processing Systems . 4714\u20134723. Lixin Fan, Kam Woh Ng, and Chee Seng Chan. 2019. Rethinking deep neural network ownership verification: Embedding passports to defeat ambiguity attacks. In Advances in Neural Information Processing Systems. 4714\u20134723."},{"key":"e_1_3_2_1_21_1","volume-title":"International Conference on Machine Learning. 201\u2013210","author":"Gilad-Bachrach Ran","year":"2016","unstructured":"Ran Gilad-Bachrach , Nathan Dowlin , Kim Laine , Kristin Lauter , Michael Naehrig , and John Wernsing . 2016 . Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy . In International Conference on Machine Learning. 201\u2013210 . https:\/\/doi.org\/10.5555\/3045390.3045413 Ran Gilad-Bachrach, Nathan Dowlin, Kim Laine, Kristin Lauter, Michael Naehrig, and John Wernsing. 2016. Cryptonets: Applying neural networks to encrypted data with high throughput and accuracy. In International Conference on Machine Learning. 201\u2013210. https:\/\/doi.org\/10.5555\/3045390.3045413"},{"key":"e_1_3_2_1_22_1","unstructured":"Ian J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572.  Ian J Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572."},{"key":"e_1_3_2_1_23_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733.","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu , Brendan Dolan-Gavitt , and Siddharth Garg . 2017 . Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733. Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733."},{"key":"e_1_3_2_1_24_1","volume-title":"Andrew Gordon Wilson, and Kilian Q Weinberger","author":"Guo Chuan","year":"2019","unstructured":"Chuan Guo , Jacob R Gardner , Yurong You , Andrew Gordon Wilson, and Kilian Q Weinberger . 2019 . Simple black-box adversarial attacks. arXiv preprint arXiv:1905.07121. Chuan Guo, Jacob R Gardner, Yurong You, Andrew Gordon Wilson, and Kilian Q Weinberger. 2019. Simple black-box adversarial attacks. arXiv preprint arXiv:1905.07121."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240765.3240862"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196321.3196329"},{"key":"e_1_3_2_1_27_1","unstructured":"Song Han Huizi Mao and William J Dally. 2015. Deep compression: Compressing deep neural networks with pruning trained quantization and huffman coding. arXiv preprint arXiv:1510.00149.  Song Han Huizi Mao and William J Dally. 2015. Deep compression: Compressing deep neural networks with pruning trained quantization and huffman coding. arXiv preprint arXiv:1510.00149."},{"key":"e_1_3_2_1_28_1","unstructured":"Song Han Jeff Pool John Tran and William Dally. 2015. Learning both weights and connections for efficient neural network. In Advances in neural information processing systems. 1135\u20131143.  Song Han Jeff Pool John Tran and William Dally. 2015. Learning both weights and connections for efficient neural network. In Advances in neural information processing systems. 1135\u20131143."},{"key":"e_1_3_2_1_29_1","unstructured":"Irfan Ul Haq and Juan Caballero. 2019. A Survey of Binary Code Similarity. arXiv preprint arXiv:1909.11424.  Irfan Ul Haq and Juan Caballero. 2019. A Survey of Binary Code Similarity. arXiv preprint arXiv:1909.11424."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_31_1","unstructured":"Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531.  Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv preprint arXiv:1503.02531."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00483"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2010.62"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1572272.1572283"},{"key":"e_1_3_2_1_35_1","volume-title":"Novel Dataset for Fine-Grained Image Categorization. In First Workshop on Fine-Grained Visual Categorization, IEEE Conference on Computer Vision and Pattern Recognition","author":"Khosla Aditya","year":"2011","unstructured":"Aditya Khosla , Nityananda Jayadevaprakash , Bangpeng Yao , and Li Fei-Fei . 2011 . Novel Dataset for Fine-Grained Image Categorization. In First Workshop on Fine-Grained Visual Categorization, IEEE Conference on Computer Vision and Pattern Recognition . Colorado Springs, CO. Aditya Khosla, Nityananda Jayadevaprakash, Bangpeng Yao, and Li Fei-Fei. 2011. Novel Dataset for Fine-Grained Image Categorization. In First Workshop on Fine-Grained Visual Categorization, IEEE Conference on Computer Vision and Pattern Recognition. Colorado Springs, CO."},{"key":"e_1_3_2_1_36_1","unstructured":"Simon Kornblith Mohammad Norouzi Honglak Lee and Geoffrey Hinton. 2019. Similarity of neural network representations revisited. arXiv preprint arXiv:1905.00414.  Simon Kornblith Mohammad Norouzi Honglak Lee and Geoffrey Hinton. 2019. Similarity of neural network representations revisited. arXiv preprint arXiv:1905.00414."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/WCRE.2001.957835"},{"key":"e_1_3_2_1_38_1","unstructured":"Chuan Li. 2020. OpenAI\u2019s GPT-3 Language Model: A Technical Overview. https:\/\/lambdalabs.com\/blog\/demystifying-gpt-3\/  Chuan Li. 2020. OpenAI\u2019s GPT-3 Language Model: A Technical Overview. https:\/\/lambdalabs.com\/blog\/demystifying-gpt-3\/"},{"key":"e_1_3_2_1_39_1","unstructured":"Hao Li Asim Kadav Igor Durdanovic Hanan Samet and Hans Peter Graf. 2016. Pruning filters for efficient ConvNets. arXiv preprint arXiv:1608.08710.  Hao Li Asim Kadav Igor Durdanovic Hanan Samet and Hans Peter Graf. 2016. Pruning filters for efficient ConvNets. arXiv preprint arXiv:1608.08710."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00035"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-C.2017.8"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2006.28"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238199"},{"key":"e_1_3_2_1_44_1","volume-title":"Trojaning Attack on Neural Networks. In 25th Annual Network and Distributed System Security Symposium (NDSS). 18\u2013221","author":"Liu Yingqi","year":"2018","unstructured":"Yingqi Liu , Shiqing Ma , Yousra Aafer , Wen-Chuan Lee , Juan Zhai , Weihang Wang , and Xiangyu Zhang . 2018 . Trojaning Attack on Neural Networks. In 25th Annual Network and Distributed System Security Symposium (NDSS). 18\u2013221 . Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang. 2018. Trojaning Attack on Neural Networks. In 25th Annual Network and Distributed System Security Symposium (NDSS). 18\u2013221."},{"key":"e_1_3_2_1_45_1","unstructured":"Nils Lukas Yuxuan Zhang and Florian Kerschbaum. 2019. Deep Neural Network Fingerprinting by Conferrable Adversarial Examples. arXiv preprint arXiv:1912.00888.  Nils Lukas Yuxuan Zhang and Florian Kerschbaum. 2019. Deep Neural Network Fingerprinting by Conferrable Adversarial Examples. arXiv preprint arXiv:1912.00888."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238202"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3236082"},{"key":"e_1_3_2_1_48_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083.  Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227178"},{"key":"e_1_3_2_1_50_1","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Ming Jiang","year":"2017","unstructured":"Jiang Ming , Dongpeng Xu , Yufei Jiang , and Dinghao Wu . 2017 . Binsim: Trace-based semantic binary diffing via system call sliced segment equivalence checking . In 26th USENIX Security Symposium (USENIX Security 17) . 253\u2013270. Jiang Ming, Dongpeng Xu, Yufei Jiang, and Dinghao Wu. 2017. Binsim: Trace-based semantic binary diffing via system call sliced segment equivalence checking. In 26th USENIX Security Symposium (USENIX Security 17). 253\u2013270."},{"key":"e_1_3_2_1_51_1","unstructured":"Ari Morcos Maithra Raghu and Samy Bengio. 2018. Insights on representational similarity in neural networks with canonical correlation. In Advances in Neural Information Processing Systems. 5727\u20135736.  Ari Morcos Maithra Raghu and Samy Bengio. 2018. Insights on representational similarity in neural networks with canonical correlation. In Advances in Neural Information Processing Systems. 5727\u20135736."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICVGIP.2008.47"},{"key":"e_1_3_2_1_53_1","volume-title":"International Conference on Machine Learning. 4901\u20134911","author":"Odena Augustus","year":"2019","unstructured":"Augustus Odena , Catherine Olsson , David Andersen , and Ian Goodfellow . 2019 . Tensorfuzz: Debugging neural networks with coverage-guided fuzzing . In International Conference on Machine Learning. 4901\u20134911 . Augustus Odena, Catherine Olsson, David Andersen, and Ian Goodfellow. 2019. Tensorfuzz: Debugging neural networks with coverage-guided fuzzing. In International Conference on Machine Learning. 4901\u20134911."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/382222.382462"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2009.191"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132747.3132785"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.49"},{"key":"e_1_3_2_1_59_1","volume-title":"Svcca: Singular vector canonical correlation analysis for deep learning dynamics and interpretability. In Advances in Neural Information Processing Systems. 6076\u20136085.","author":"Raghu Maithra","year":"2017","unstructured":"Maithra Raghu , Justin Gilmer , Jason Yosinski , and Jascha Sohl-Dickstein . 2017 . Svcca: Singular vector canonical correlation analysis for deep learning dynamics and interpretability. In Advances in Neural Information Processing Systems. 6076\u20136085. Maithra Raghu, Justin Gilmer, Jason Yosinski, and Jascha Sohl-Dickstein. 2017. Svcca: Singular vector canonical correlation analysis for deep learning dynamics and interpretability. In Advances in Neural Information Processing Systems. 6076\u20136085."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-017-9564-7"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2013.01.008"},{"key":"e_1_3_2_1_62_1","volume-title":"A Target-Agnostic Attack on Deep Models: Exploiting Security Vulnerabilities of Transfer Learning. CoRR, abs\/1904.04334","author":"Rezaei Shahbaz","year":"2019","unstructured":"Shahbaz Rezaei and Xin Liu . 2019. A Target-Agnostic Attack on Deep Models: Exploiting Security Vulnerabilities of Transfer Learning. CoRR, abs\/1904.04334 ( 2019 ). Shahbaz Rezaei and Xin Liu. 2019. A Target-Agnostic Attack on Deep Models: Exploiting Security Vulnerabilities of Transfer Learning. CoRR, abs\/1904.04334 (2019)."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC.2008.41"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/872757.872770"},{"key":"e_1_3_2_1_66_1","unstructured":"Masoumeh Shafieinejad Jiaqi Wang Nils Lukas Xinda Li and Florian Kerschbaum. 2019. On the robustness of the backdoor-based watermarking in deep neural networks. arXiv preprint arXiv:1906.07745.  Masoumeh Shafieinejad Jiaqi Wang Nils Lukas Xinda Li and Florian Kerschbaum. 2019. On the robustness of the backdoor-based watermarking in deep neural networks. arXiv preprint arXiv:1906.07745."},{"key":"e_1_3_2_1_67_1","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199.  Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199."},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3180155.3180220"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"crossref","unstructured":"Yuchi Tian Ziyuan Zhong Vicente Ordonez Gail Kaiser and Baishakhi Ray. 2019. Testing DNN Image Classifiers for Confusion & Bias Errors. arXiv preprint arXiv:1905.07831.  Yuchi Tian Ziyuan Zhong Vicente Ordonez Gail Kaiser and Baishakhi Ray. 2019. Testing DNN Image Classifiers for Confusion & Bias Errors. arXiv preprint arXiv:1905.07831.","DOI":"10.1145\/3377811.3380400"},{"key":"e_1_3_2_1_70_1","volume-title":"Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR).","author":"Tramer Florian","year":"2018","unstructured":"Florian Tramer and Dan Boneh . 2018 . Slalom: Fast , Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR). Florian Tramer and Dan Boneh. 2018. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_71_1","first-page":"32","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r , Fan Zhang , Ari Juels , Michael K. Reiter , and Thomas Ristenpart . 2016 . Stealing Machine Learning Models via Prediction APIs . In 25th USENIX Security Symposium (USENIX Security 16) . USENIX Association, Austin, TX. 601\u2013618. isbn:978-1-93 1971- 32 - 34 Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. In 25th USENIX Security Symposium (USENIX Security 16). USENIX Association, Austin, TX. 601\u2013618. isbn:978-1-931971-32-4"},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3078971.3078974"},{"key":"e_1_3_2_1_73_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Wang Bolun","year":"2018","unstructured":"Bolun Wang , Yuanshun Yao , Bimal Viswanath , Haitao Zheng , and Ben Y Zhao . 2018 . With great training comes great vulnerability: Practical attacks against transfer learning . In 27th USENIX Security Symposium (USENIX Security 18) . 1281\u20131297. Bolun Wang, Yuanshun Yao, Bimal Viswanath, Haitao Zheng, and Ben Y Zhao. 2018. With great training comes great vulnerability: Practical attacks against transfer learning. In 27th USENIX Security Symposium (USENIX Security 18). 1281\u20131297."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3293882.3330579"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134018"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2962027"},{"key":"e_1_3_2_1_78_1","volume-title":"Jin Song Dong, and Dai Ting","author":"Zhang Peixin","year":"2020","unstructured":"Peixin Zhang , Jingyi Wang , Jun Sun , Guoliang Dong , Xinyu Wang , Xingen Wang , Jin Song Dong, and Dai Ting . 2020 . White-box fairness testing through adversarial sampling. Peixin Zhang, Jingyi Wang, Jun Sun, Guoliang Dong, Xinyu Wang, Xingen Wang, Jin Song Dong, and Dai Ting. 2020. White-box fairness testing through adversarial sampling."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1145\/3368089.3409676"}],"event":{"name":"ISSTA '21: 30th ACM SIGSOFT International Symposium on Software Testing and Analysis","location":"Virtual Denmark","acronym":"ISSTA '21","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 30th ACM SIGSOFT International Symposium on Software Testing and Analysis"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460319.3464816","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460319.3464816","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:31Z","timestamp":1750193311000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460319.3464816"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,7,11]]},"references-count":79,"alternative-id":["10.1145\/3460319.3464816","10.1145\/3460319"],"URL":"https:\/\/doi.org\/10.1145\/3460319.3464816","relation":{},"subject":[],"published":{"date-parts":[[2021,7,11]]},"assertion":[{"value":"2021-07-11","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}