{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T16:34:48Z","timestamp":1784046888764,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":46,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,8,14]],"date-time":"2022-08-14T00:00:00Z","timestamp":1660435200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,8,14]]},"DOI":"10.1145\/3534678.3539257","type":"proceedings-article","created":{"date-parts":[[2022,8,12]],"date-time":"2022-08-12T19:06:12Z","timestamp":1660331172000},"page":"1327-1336","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["MetaV"],"prefix":"10.1145","author":[{"given":"Xudong","family":"Pan","sequence":"first","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yifan","family":"Yan","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Min","family":"Yang","sequence":"additional","affiliation":[{"name":"Fudan University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,8,14]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"[n. d.]. PyTorch Hub. https:\/\/pytorch.org\/hub\/. Accessed: 2021-02-01."},{"key":"e_1_3_2_2_2_1","volume-title":"USENIX Security Symposium.","author":"Adi Y.","year":"2018","unstructured":"Y. Adi, Carsten Baum, et al. 2018. Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by Backdooring. In USENIX Security Symposium."},{"key":"e_1_3_2_2_3_1","unstructured":"Angela Aguinaldo Ping-Yeh Chiang et al. 2019. Compressing GANs using Knowledge Distillation. ArXiv abs\/1902.00159 (2019)."},{"key":"e_1_3_2_2_4_1","volume-title":"A Survey on Model Watermarking Neural Networks. ArXiv","author":"Boenisch Franziska","year":"2020","unstructured":"Franziska Boenisch. 2020. A Survey on Model Watermarking Neural Networks. ArXiv (2020)."},{"key":"e_1_3_2_2_5_1","unstructured":"Xiaoyu Cao J. Jia et al. 2021. IPGuard: Protecting the Intellectual Property of Deep Neural Networks via Fingerprinting the Classification Boundary. AsiaCCS (2021)."},{"key":"e_1_3_2_2_6_1","unstructured":"Yulong Cao Chaowei Xiao et al. 2019. Adversarial Sensor Attack on LiDARbased Perception in Autonomous Driving. CCS (2019)."},{"key":"e_1_3_2_2_7_1","volume-title":"Towards Evaluating the Robustness of Neural Networks. IEEE Symposium on Security and Privacy","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David A. Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. IEEE Symposium on Security and Privacy (2017)."},{"key":"e_1_3_2_2_8_1","unstructured":"A. Choroma'ska Mikael Henaff et al. 2015. The Loss Surfaces of Multilayer Networks. In AISTATS."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"crossref","unstructured":"Kevin Clark Minh-Thang Luong et al. 2019. BAM! Born-Again Multi-Task Networks for Natural Language Understanding. In ACL.","DOI":"10.18653\/v1\/P19-1595"},{"key":"e_1_3_2_2_10_1","volume-title":"BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In NAACL-HLT.","author":"Devlin J.","year":"2019","unstructured":"J. Devlin, Ming-Wei Chang, et al. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In NAACL-HLT."},{"key":"e_1_3_2_2_11_1","doi-asserted-by":"crossref","unstructured":"Andre Esteva B. Kuprel et al. 2017. Dermatologist-level classification of skin cancer with deep neural networks. Nature (2017).","DOI":"10.1038\/nature21056"},{"key":"e_1_3_2_2_12_1","volume-title":"Knowledge Distillation: A Survey. Int. J. Comput. Vis.","author":"Gou Jianping","year":"2021","unstructured":"Jianping Gou, B. Yu, et al. 2021. Knowledge Distillation: A Survey. Int. J. Comput. Vis. (2021)."},{"key":"e_1_3_2_2_13_1","unstructured":"Song Han Jeff Pool et al. 2015. Learning both Weights and Connections for Efficient Neural Network. ArXiv (2015)."},{"key":"e_1_3_2_2_14_1","unstructured":"Kaiming He X. Zhang et al. 2016. Deep Residual Learning for Image Recognition. CVPR (2016) 770--778."},{"key":"e_1_3_2_2_15_1","volume-title":"Econometric Modeling: Capital Markets - Portfolio Theory eJournal","author":"Heaton J. B.","year":"2016","unstructured":"J. B. Heaton, Nicholas G. Polson, et al. 2016. Deep Learning for Finance: Deep Portfolios. Econometric Modeling: Capital Markets - Portfolio Theory eJournal (2016)."},{"key":"e_1_3_2_2_16_1","volume-title":"Hinton et al","author":"Geoffrey","year":"2015","unstructured":"Geoffrey E. Hinton et al. 2015. Distilling the Knowledge in a Neural Network. ArXiv (2015)."},{"key":"e_1_3_2_2_17_1","volume-title":"Densely Connected Convolutional Networks. 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR)","author":"Huang Gao","year":"2017","unstructured":"Gao Huang, Zhuang Liu, and Kilian Q. Weinberger. 2017. Densely Connected Convolutional Networks. 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2017), 2261--2269."},{"key":"e_1_3_2_2_18_1","unstructured":"Forrest N. Iandola M. Moskewicz Khalid Ashraf Song Han W. Dally and K. Keutzer. 2016. SqueezeNet: AlexNet-level accuracy with 50x fewer parameters and 1MB model size. ArXiv abs\/1602.07360 (2016)."},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"crossref","unstructured":"Hoyong Jeong Dohyun Ryu et al. 2021. Neural Network Stealing via Meltdown. ICOIN (2021) 36--38.","DOI":"10.1109\/ICOIN50884.2021.9333926"},{"key":"e_1_3_2_2_20_1","volume-title":"PRADA: Protecting Against DNN Model Stealing Attacks. EuroS&P","author":"Juuti Mika","year":"2019","unstructured":"Mika Juuti, Sebastian Szyller, et al. 2019. PRADA: Protecting Against DNN Model Stealing Attacks. EuroS&P (2019)."},{"key":"e_1_3_2_2_21_1","volume-title":"Kingma and Jimmy Ba","author":"Diederik","year":"2015","unstructured":"Diederik P. Kingma and Jimmy Ba. 2015. Adam: A Method for Stochastic Optimization. CoRR abs\/1412.6980 (2015)."},{"key":"e_1_3_2_2_22_1","volume-title":"One weird trick for parallelizing convolutional neural networks. ArXiv abs\/1404.5997","author":"Krizhevsky A.","year":"2014","unstructured":"A. Krizhevsky. 2014. One weird trick for parallelizing convolutional neural networks. ArXiv abs\/1404.5997 (2014)."},{"key":"e_1_3_2_2_23_1","unstructured":"Hao Li Asim Kadav et al. 2017. Pruning Filters for Efficient ConvNets. ArXiv (2017)."},{"key":"e_1_3_2_2_24_1","unstructured":"Yuanchun Li Ziqi Zhang et al. 2021. ModelDiff: testing-based DNN similarity comparison for model reuse detection. ISSTA (2021)."},{"key":"e_1_3_2_2_25_1","unstructured":"Nils Lukas Yuxuan Zhang et al. 2021. Deep Neural Network Fingerprinting by Conferrable Adversarial Examples. ICLR (2021)."},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"crossref","unstructured":"Seyed-Mohsen Moosavi-Dezfooli Alhussein Fawzi et al. 2016. DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks. CVPR (2016).","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_2_27_1","unstructured":"Adam Paszke S. Gross et al. 2019. PyTorch: An Imperative Style HighPerformance Deep Learning Library. In NeurIPS."},{"key":"e_1_3_2_2_28_1","volume-title":"Unsupervised Representation Learning with Deep Convolutional Generative Adversarial Networks. CoRR abs\/1511.06434","author":"Radford Alec","year":"2016","unstructured":"Alec Radford, Luke Metz, and Soumith Chintala. 2016. Unsupervised Representation Learning with Deep Convolutional Generative Adversarial Networks. CoRR abs\/1511.06434 (2016)."},{"key":"e_1_3_2_2_29_1","doi-asserted-by":"crossref","unstructured":"Esteban Real A. Aggarwal et al. 2019. Regularized Evolution for Image Classifier Architecture Search. In AAAI.","DOI":"10.1609\/aaai.v33i01.33014780"},{"key":"e_1_3_2_2_30_1","doi-asserted-by":"crossref","unstructured":"F. Regazzoni P. Palmieri et al. 2021. Protecting artificial intelligence IPs: a survey of watermarking and fingerprinting for machine learning. CAAI Transactions on Intelligence Technology (2021).","DOI":"10.1049\/cit2.12029"},{"key":"e_1_3_2_2_31_1","unstructured":"B. Rouhani Huili Chen et al. 2018. DeepSigns: A Generic Watermarking Framework for IP Protection of Deep Learning Models. ArXiv (2018)."},{"key":"e_1_3_2_2_32_1","volume-title":"Very Deep Convolutional Networks for Large-Scale Image Recognition. ArXiv","author":"Simonyan K.","year":"2015","unstructured":"K. Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. ArXiv (2015)."},{"key":"e_1_3_2_2_33_1","unstructured":"Christian Szegedy W. Zaremba Ilya Sutskever Joan Bruna et al. 2014. Intriguing properties of neural networks. ArXiv (2014)."},{"key":"e_1_3_2_2_34_1","unstructured":"Florian Tram\u00e8r F. Zhang et al. 2016. Stealing Machine Learning Models via Prediction APIs. In USENIX Security."},{"key":"e_1_3_2_2_35_1","unstructured":"G. Truda and P. Marais. 2019. Warfarin dose estimation on multiple datasets with automated hyperparameter optimisation and a novel software framework. ArXiv (2019)."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"crossref","unstructured":"Y. Uchida Yuki Nagai et al. 2017. Embedding Watermarks into Deep Neural Networks. ICMR (2017).","DOI":"10.1145\/3078971.3078974"},{"key":"e_1_3_2_2_37_1","volume-title":"Fingerprinting Deep Neural Networks - a DeepFool Approach. ISCAS","author":"Wang Si","year":"2021","unstructured":"Si Wang and Chip-Hong Chang. 2021. Fingerprinting Deep Neural Networks - a DeepFool Approach. ISCAS (2021)."},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"crossref","unstructured":"M. Whirl-Carrillo E. McDonagh et al. 2012. Pharmacogenomics Knowledge for Personalized Medicine. Clinical Pharmacology & Therapeutics (2012).","DOI":"10.1038\/clpt.2012.96"},{"key":"e_1_3_2_2_39_1","unstructured":"H. Xiao K. Rasul et al. 2017. Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms. ArXiv (2017)."},{"key":"e_1_3_2_2_40_1","unstructured":"Xiangrui Xu Y. Li et al. 2020. \"Identity Bracelets\" for Deep Neural Networks. IEEE Access (2020)."},{"key":"e_1_3_2_2_41_1","volume":"202","author":"Yan Mengjia","unstructured":"Mengjia Yan, Christopher W. Fletcher, and J. Torrellas. 2020. Cache Telepathy: Leveraging Shared Resource Attacks to Learn DNN Architectures. USENIX Security (2020).","journal-title":"J. Torrellas."},{"key":"e_1_3_2_2_42_1","unstructured":"Jiancheng Yang R. Shi et al. 2020. MedMNIST Classification Decathlon: A Lightweight AutoML Benchmark for Medical Image Analysis. ArXiv (2020)."},{"key":"e_1_3_2_2_43_1","unstructured":"Honggang Yu Kaichen Yang et al. 2020. CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples. In NDSS."},{"key":"e_1_3_2_2_44_1","doi-asserted-by":"crossref","unstructured":"Jialong Zhang Zhongshu Gu et al. 2018. Protecting intellectual property of deep neural networks with watermarking. AsiaCCS (2018).","DOI":"10.1145\/3196494.3196550"},{"key":"e_1_3_2_2_45_1","volume-title":"AFA: Adversarial fingerprinting authentication for deep neural networks. Comput. Commun.","author":"Zhao Jingjing","year":"2020","unstructured":"Jingjing Zhao, Qingyue Hu, et al. 2020. AFA: Adversarial fingerprinting authentication for deep neural networks. Comput. Commun. (2020)."},{"key":"e_1_3_2_2_46_1","volume-title":"Informer: Beyond Efficient Transformer for Long Sequence Time-Series Forecasting. In AAAI.","author":"Zhou Haoyi","year":"2021","unstructured":"Haoyi Zhou, Shanghang Zhang, et al. 2021. Informer: Beyond Efficient Transformer for Long Sequence Time-Series Forecasting. In AAAI."}],"event":{"name":"KDD '22: The 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Washington DC USA","acronym":"KDD '22","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3534678.3539257","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3534678.3539257","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:59:58Z","timestamp":1750186798000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3534678.3539257"}},"subtitle":["A Meta-Verifier Approach to Task-Agnostic Model Fingerprinting"],"short-title":[],"issued":{"date-parts":[[2022,8,14]]},"references-count":46,"alternative-id":["10.1145\/3534678.3539257","10.1145\/3534678"],"URL":"https:\/\/doi.org\/10.1145\/3534678.3539257","relation":{},"subject":[],"published":{"date-parts":[[2022,8,14]]},"assertion":[{"value":"2022-08-14","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}