{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T19:15:12Z","timestamp":1783192512385,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3485899","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"61-75","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":21,"title":["Morphence: Moving Target Defense Against Adversarial Examples"],"prefix":"10.1145","author":[{"given":"Abderrahmen","family":"Amich","sequence":"first","affiliation":[{"name":"University of Michigan, Dearborn"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Birhanu","family":"Eshete","sequence":"additional","affiliation":[{"name":"University of Michigan, Dearborn, United States of America"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63086-7_18"},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 35th International Conference on Machine Learning, ICML 2018(Proceedings of Machine Learning Research, Vol.\u00a080)","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David\u00a0A. Wagner. 2018. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In Proceedings of the 35th International Conference on Machine Learning, ICML 2018(Proceedings of Machine Learning Research, Vol.\u00a080). PMLR, 274\u2013283."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/CISS.2018.8362326"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_1_5_1","volume-title":"Thermometer Encoding: One Hot Way To Resist Adversarial Examples. In 6th International Conference on Learning Representations, ICLR","author":"Buckman Jacob","year":"2018","unstructured":"Jacob Buckman, Aurko Roy, Colin Raffel, and Ian\u00a0J. Goodfellow. 2018. Thermometer Encoding: One Hot Way To Resist Adversarial Examples. In 6th International Conference on Learning Representations, ICLR 2018. OpenReview.net."},{"key":"e_1_3_2_1_6_1","unstructured":"Nicholas Carlini Anish Athalye Nicolas Papernot Wieland Brendel Jonas Rauber Dimitris Tsipras Ian Goodfellow Aleksander Madry and Alexey Kurakin. 2019. On Evaluating Adversarial Robustness. arxiv:1902.06705\u00a0[cs.LG]"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_2_1_8_1","volume-title":"Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy, SP","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David\u00a0A. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy, SP 2017. 39\u201357."},{"key":"e_1_3_2_1_9_1","volume-title":"HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. In 2020 IEEE Symposium on Security and Privacy, SP","author":"Chen Jianbo","year":"2020","unstructured":"Jianbo Chen, Michael\u00a0I. Jordan, and Martin\u00a0J. Wainwright. 2020. HopSkipJumpAttack: A Query-Efficient Decision-Based Attack. In 2020 IEEE Symposium on Security and Privacy, SP 2020. IEEE, 1277\u20131294."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019(Proceedings of Machine Learning Research, Vol.\u00a097)","author":"Cohen M.","year":"2019","unstructured":"Jeremy\u00a0M. Cohen, Elan Rosenfeld, and J.\u00a0Zico Kolter. 2019. Certified Adversarial Robustness via Randomized Smoothing. In Proceedings of the 36th International Conference on Machine Learning, ICML 2019(Proceedings of Machine Learning Research, Vol.\u00a097). PMLR, 1310\u20131320."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/TASL.2011.2134090"},{"key":"e_1_3_2_1_13_1","unstructured":"Nilaksh Das Madhuri Shanbhogue Shang-Tse Chen Fred Hohman Li Chen Michael\u00a0E. Kounavis and Duen\u00a0Horng Chau. 2017. Keeping the Bad Guys Out: Protecting and Vaccinating Deep Learning with JPEG Compression. CoRR abs\/1705.02900(2017)."},{"key":"e_1_3_2_1_14_1","volume-title":"Explaining Transferability of Evasion and Poisoning Attacks. In 28th USENIX Security Symposium, USENIX Security","author":"Demontis Ambra","year":"2019","unstructured":"Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning Attacks. In 28th USENIX Security Symposium, USENIX Security 2019. USENIX Association, 321\u2013338."},{"key":"e_1_3_2_1_15_1","volume-title":"Boosting Adversarial Attacks With Momentum. In 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018","author":"Dong Yinpeng","year":"2018","unstructured":"Yinpeng Dong, Fangzhou Liao, Tianyu Pang, Hang Su, Jun Zhu, Xiaolin Hu, and Jianguo Li. 2018. Boosting Adversarial Attacks With Momentum. In 2018 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2018, Salt Lake City, UT, USA, June 18-22, 2018. 9185\u20139193."},{"key":"e_1_3_2_1_16_1","unstructured":"Ivan Evtimov Kevin Eykholt Earlence Fernandes Tadayoshi Kohno Bo Li Atul Prakash Amir Rahmati and Dawn Song. 2017. Robust Physical-World Attacks on Machine Learning Models. CoRR abs\/1707.08945(2017)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3297858.3304037"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1038\/s41389-019-0157-8"},{"key":"e_1_3_2_1_19_1","unstructured":"Ian Goodfellow. 2019. A Research Agenda: Dynamic Models to Defend Against Correlated Attacks. arxiv:1903.06293\u00a0[cs.LG]"},{"key":"e_1_3_2_1_20_1","volume-title":"Explaining and Harnessing Adversarial Examples. In 3rd International Conference on Learning Representations, ICLR.","author":"Goodfellow J.","year":"2015","unstructured":"Ian\u00a0J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In 3rd International Conference on Learning Representations, ICLR."},{"key":"e_1_3_2_1_21_1","volume-title":"3rd International Conference on Learning Representations, ICLR","author":"Gu Shixiang","year":"2015","unstructured":"Shixiang Gu and Luca Rigazio. 2015. Towards Deep Neural Network Architectures Robust to Adversarial Examples. In 3rd International Conference on Learning Representations, ICLR 2015."},{"key":"e_1_3_2_1_22_1","volume-title":"6th International Conference on Learning Representations, ICLR","author":"Guo Chuan","year":"2018","unstructured":"Chuan Guo, Mayank Rana, Moustapha Ciss\u00e9, and Laurens van\u00a0der Maaten. 2018. Countering Adversarial Images using Input Transformations. In 6th International Conference on Learning Representations, ICLR 2018. OpenReview.net."},{"key":"e_1_3_2_1_23_1","volume-title":"11th USENIX Workshop on Offensive Technologies, WOOT 2017","author":"He Warren","year":"2017","unstructured":"Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song. 2017. Adversarial Example Defense: Ensembles of Weak Defenses are not Strong. In 11th USENIX Workshop on Offensive Technologies, WOOT 2017, Vancouver, BC, Canada, August 14-15, 2017. USENIX Association."},{"key":"e_1_3_2_1_24_1","unstructured":"Weiwei Hu and Ying Tan. 2017. Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN. CoRR abs\/1702.05983(2017)."},{"key":"e_1_3_2_1_25_1","unstructured":"Ruitong Huang Bing Xu Dale Schuurmans and Csaba Szepesv\u00e1ri. 2015. Learning with a Strong Adversary. CoRR abs\/1511.03034(2015)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"crossref","unstructured":"Sushil Jajodia Anup\u00a0K. Ghosh Vipin Swarup Cliff Wang and Xiaoyang\u00a0Sean Wang (Eds.). 2011. Moving Target Defense - Creating Asymmetric Uncertainty for Cyber Threats. Advances in Information Security Vol.\u00a054. Springer.","DOI":"10.1007\/978-1-4614-0977-9"},{"key":"e_1_3_2_1_27_1","volume-title":"Adversarial Malware Binaries: Evading Deep Learning for Malware Detection in Executables. In 26th European Signal Processing Conference, EUSIPCO. 533\u2013537","author":"Kolosnjaji Bojan","year":"2018","unstructured":"Bojan Kolosnjaji, Ambra Demontis, Battista Biggio, Davide Maiorca, Giorgio Giacinto, Claudia Eckert, and Fabio Roli. 2018. Adversarial Malware Binaries: Evading Deep Learning for Malware Detection in Executables. In 26th European Signal Processing Conference, EUSIPCO. 533\u2013537."},{"key":"e_1_3_2_1_28_1","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n.d.]. CIFAR-10 (Canadian Institute for Advanced Research). ([n. d.]). http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"e_1_3_2_1_30_1","unstructured":"Alexey Kurakin Ian Goodfellow and Samy Bengio. 2017. Adversarial Machine Learning at Scale. arxiv:1611.01236\u00a0[cs.CV]"},{"key":"e_1_3_2_1_31_1","unstructured":"Alexey Kurakin Ian\u00a0J. Goodfellow and Samy Bengio. 2016. Adversarial Machine Learning at Scale. CoRR abs\/1611.01236(2016)."},{"key":"e_1_3_2_1_32_1","unstructured":"Yan LeCun Corinna Cortes and Christopher\u00a0J.C. Burges. 2020. The MNIST Database of Handwritten Digits. http:\/\/yann.lecun.com\/exdb\/mnist\/."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"crossref","unstructured":"Mathias Lecuyer Vaggelis Atlidakis Roxana Geambasu Daniel Hsu and Suman Jana. 2019. Certified Robustness to Adversarial Examples with Differential Privacy. arxiv:1802.03471\u00a0[stat.ML]","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"crossref","unstructured":"Cheng Lei Hongqi Zhang Jing-Lei Tan Yu-Chen Zhang and Xiao-Hu Liu. [n.d.]. Moving Target Defense Techniques: A Survey. Secur. Commun. Networks 2018 ([n. d.]).","DOI":"10.1155\/2018\/3759626"},{"key":"e_1_3_2_1_35_1","volume-title":"Certified Adversarial Robustness with Additive Noise. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019","author":"Li Bai","year":"2019","unstructured":"Bai Li, Changyou Chen, Wenlin Wang, and Lawrence Carin. 2019. Certified Adversarial Robustness with Additive Noise. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019. 9459\u20139469."},{"key":"e_1_3_2_1_36_1","unstructured":"Yan Luo Xavier Boix Gemma Roig Tomaso\u00a0A. Poggio and Qi Zhao. 2015. Foveation-based Mechanisms Alleviate Adversarial Examples. CoRR abs\/1511.06292(2015)."},{"key":"e_1_3_2_1_37_1","unstructured":"Aleksander Madry Aleksandar Makelov Ludwig Schmidt Dimitris Tsipras and Adrian Vladu. 2017. Towards Deep Learning Models Resistant to Adversarial Attacks. CoRR abs\/1706.06083(2017)."},{"key":"e_1_3_2_1_38_1","volume-title":"Knockoff Nets: Stealing Functionality of Black-Box Models. arxiv:1812.02766\u00a0[cs.CV]","author":"Orekondy Tribhuvanesh","year":"2018","unstructured":"Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2018. Knockoff Nets: Stealing Functionality of Black-Box Models. arxiv:1812.02766\u00a0[cs.CV]"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","unstructured":"Nicolas Papernot Patrick McDaniel Xi Wu Somesh Jha and Ananthram Swami. 2016. Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks. 582\u2013597. https:\/\/doi.org\/10.1109\/SP.2016.41","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_40_1","unstructured":"Nicolas Papernot Patrick\u00a0D. McDaniel and Ian\u00a0J. Goodfellow. 2016. Transferability in Machine Learning: from Phenomena to Black-Box Attacks using Adversarial Samples. CoRR abs\/1605.07277(2016)."},{"key":"e_1_3_2_1_41_1","unstructured":"Nicolas Papernot Patrick\u00a0D. McDaniel Ian\u00a0J. Goodfellow Somesh Jha Z.\u00a0Berkay Celik and Ananthram Swami. 2016. Practical Black-Box Attacks against Deep Learning Systems using Adversarial Examples. CoRR abs\/1602.02697(2016)."},{"key":"e_1_3_2_1_42_1","unstructured":"Yaguan Qian Qiqi Shao Jiamin Wang Xiang Lin Yankai Guo Zhaoquan Gu Bin Wang and Chunming Wu. 2020. EI-MTD: Moving Target Defense for Edge Intelligence against Adversarial Attacks. CoRR abs\/2009.10537(2020)."},{"key":"e_1_3_2_1_43_1","volume-title":"The Workshops of the The Thirty-Second AAAI Conference on Artificial Intelligence. 268\u2013276","author":"Raff Edward","year":"2018","unstructured":"Edward Raff, Jon Barker, Jared Sylvester, Robert Brandon, Bryan Catanzaro, and Charles\u00a0K. Nicholas. 2018. Malware Detection by Eating a Whole EXE. In The Workshops of the The Thirty-Second AAAI Conference on Artificial Intelligence. 268\u2013276."},{"key":"e_1_3_2_1_44_1","unstructured":"Aditi Raghunathan Jacob Steinhardt and Percy Liang. 2020. Certified Defenses against Adversarial Examples. arxiv:1801.09344\u00a0[cs.LG]"},{"key":"e_1_3_2_1_45_1","unstructured":"Ahmad\u00a0El Sallab Mohammed Abdou Etienne Perot and Senthil\u00a0Kumar Yogamani. 2017. Deep Reinforcement Learning framework for Autonomous Driving. CoRR abs\/1704.02532(2017)."},{"key":"e_1_3_2_1_46_1","unstructured":"Krzystof\u00a0Podgorski Samuel\u00a0Kotz Tomasz\u00a0Kozubowski. 2012. The Laplace Distribution and Generalizations: A Revisit with Applications to Communications Economics Engineering and Finance."},{"key":"e_1_3_2_1_47_1","volume-title":"Decision and Game Theory for Security - 10th International Conference, GameSec 2019(Lecture Notes in Computer Science, Vol.\u00a011836)","author":"Sengupta Sailik","unstructured":"Sailik Sengupta, Tathagata Chakraborti, and Subbarao Kambhampati. 2019. MTDeep: Boosting the Security of Deep Neural Nets Against Adversarial Attacks with Moving Target Defense. In Decision and Game Theory for Security - 10th International Conference, GameSec 2019(Lecture Notes in Computer Science, Vol.\u00a011836). Springer, 479\u2013491."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3356250.3360025"},{"key":"e_1_3_2_1_49_1","volume-title":"6th International Conference on Learning Representations, ICLR","author":"Song Yang","year":"2018","unstructured":"Yang Song, Taesup Kim, Sebastian Nowozin, Stefano Ermon, and Nate Kushman. 2018. PixelDefend: Leveraging Generative Models to Understand and Defend against Adversarial Examples. In 6th International Conference on Learning Representations, ICLR 2018."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"crossref","unstructured":"Shixin Tian Guolei Yang and Y. Cai. 2018. Detecting Adversarial Examples Through Image Transformation. In AAAI.","DOI":"10.1609\/aaai.v32i1.11828"},{"key":"e_1_3_2_1_51_1","volume-title":"Ensemble Adversarial Training: Attacks and Defenses. In 6th International Conference on Learning Representations, ICLR","author":"Tram\u00e8r Florian","year":"2018","unstructured":"Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian\u00a0J. Goodfellow, Dan Boneh, and Patrick\u00a0D. McDaniel. 2018. Ensemble Adversarial Training: Attacks and Defenses. In 6th International Conference on Learning Representations, ICLR 2018."},{"key":"e_1_3_2_1_52_1","volume-title":"25th USENIX Security Symposium (USENIX Security 16)","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael\u00a0K. Reiter, and Thomas Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs. In 25th USENIX Security Symposium (USENIX Security 16). Austin, TX, 601\u2013618."},{"key":"e_1_3_2_1_53_1","volume-title":"Aaron van\u00a0den Oord, and Pushmeet Kohli","author":"Uesato Jonathan","year":"2018","unstructured":"Jonathan Uesato, Brendan O\u2019Donoghue, Aaron van\u00a0den Oord, and Pushmeet Kohli. 2018. Adversarial Risk and the Dangers of Evaluating Against Weak Attacks. arxiv:1802.05666\u00a0[cs.LG]"},{"key":"e_1_3_2_1_54_1","unstructured":"Eric Wong and J.\u00a0Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. arxiv:1711.00851\u00a0[cs.LG]"},{"key":"e_1_3_2_1_55_1","volume-title":"Adversarial Examples for Semantic Segmentation and Object Detection. In IEEE International Conference on Computer Vision, ICCV","author":"Xie Cihang","year":"2017","unstructured":"Cihang Xie, Jianyu Wang, Zhishuai Zhang, Yuyin Zhou, Lingxi Xie, and Alan\u00a0L. Yuille. 2017. Adversarial Examples for Semantic Segmentation and Object Detection. In IEEE International Conference on Computer Vision, ICCV 2017. IEEE Computer Society, 1378\u20131387."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140449"}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485899","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3485899","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:19:28Z","timestamp":1755890368000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3485899"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":56,"alternative-id":["10.1145\/3485832.3485899","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3485899","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}