{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,2]],"date-time":"2025-11-02T14:38:19Z","timestamp":1762094299266,"version":"build-2065373602"},"publisher-location":"New York, NY, USA","reference-count":58,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,15]],"date-time":"2023-11-15T00:00:00Z","timestamp":1700006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"NSF CNS","award":["1850725"],"award-info":[{"award-number":["1850725"]}]},{"name":"Indiana University Institute for Advanced Study (IAS)"},{"name":"Grant Thornton Institute"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3616653","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"756-770","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Stolen Risks of Models with Security Properties"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7857-2936","authenticated-orcid":false,"given":"Yue","family":"Qin","sequence":"first","affiliation":[{"name":"Indiana University Bloomington, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6265-0151","authenticated-orcid":false,"given":"Zhuoqun","family":"Fu","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-2481-0431","authenticated-orcid":false,"given":"Chuyun","family":"Deng","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7555-1673","authenticated-orcid":false,"given":"Xiaojing","family":"Liao","sequence":"additional","affiliation":[{"name":"Indiana University Bloomington, Bloomington, IN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7896-3382","authenticated-orcid":false,"given":"Jia","family":"Zhang","sequence":"additional","affiliation":[{"name":"Tsinghua University, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0083-733X","authenticated-orcid":false,"given":"Haixin","family":"Duan","sequence":"additional","affiliation":[{"name":"Tsinghua University &amp; Zhongguancun Laboratory, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2019. Medical Insurance Dataset. https:\/\/www.kaggle.com\/datasets\/ rajgupta2019\/medical-insurance-dataset."},{"key":"e_1_3_2_1_2_1","unstructured":"2022. Customer Churn Dataset. https:\/\/www.kaggle.com\/code\/yejiseoung\/ building-gradient-boosting-pipeline-0-99-roc-auc\/data."},{"key":"e_1_3_2_1_3_1","unstructured":"2023. Code dataset and full version paper. https:\/\/sites.google.com\/view\/ maskedthief\/home."},{"key":"e_1_3_2_1_4_1","volume-title":"Mixmatch: A holistic approach to semi-supervised learning. Advances in neural information processing systems","author":"Berthelot David","year":"2019","unstructured":"David Berthelot, Nicholas Carlini, Ian Goodfellow, Nicolas Papernot, Avital Oliver, and Colin A Raffel. 2019. Mixmatch: A holistic approach to semi-supervised learning. Advances in neural information processing systems, Vol. 32 (2019)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","unstructured":"Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In 2017 ieee symposium on security and privacy (sp). Ieee 39--57.","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_7_1","volume-title":"Property inference from poisoning. arXiv preprint arXiv:2101.11073","author":"Chase Melissa","year":"2021","unstructured":"Melissa Chase, Esha Ghosh, and Saeed Mahloujifar. 2021. Property inference from poisoning. arXiv preprint arXiv:2101.11073 (2021)."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_1_9_1","unstructured":"Tianqi Chen Tong He Michael Benesty Vadim Khotilovich Yuan Tang Hyunsu Cho Kailong Chen et al. 2015. Xgboost: extreme gradient boosting. R package version 0.4-2 Vol. 1 4 (2015) 1--4."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484776"},{"key":"e_1_3_2_1_11_1","volume-title":"International Conference on Machine Learning. PMLR","author":"Choquette-Choo Christopher A","year":"2021","unstructured":"Christopher A Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In International Conference on Machine Learning. PMLR, 1964--1974."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"e_1_3_2_1_13_1","volume-title":"International Conference on Machine Learning. PMLR","author":"Fischer Marc","year":"2019","unstructured":"Marc Fischer, Mislav Balunovic, Dana Drachsler-Cohen, Timon Gehr, Ce Zhang, and Martin Vechev. 2019. Dl2: Training and querying neural networks with logic. In International Conference on Machine Learning. PMLR, 1931--1941."},{"key":"e_1_3_2_1_14_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_15_1","volume-title":"Semi-Leak: Membership Inference Attacks Against Semi-supervised Learning. In European Conference on Computer Vision. Springer, 365--381","author":"He Xinlei","year":"2022","unstructured":"Xinlei He, Hongbin Liu, Neil Zhenqiang Gong, and Yang Zhang. 2022. Semi-Leak: Membership Inference Attacks Against Semi-supervised Learning. In European Conference on Computer Vision. Springer, 365--381."},{"volume-title":"The collected works of Wassily Hoeffding","author":"Hoeffding Wassily","key":"e_1_3_2_1_16_1","unstructured":"Wassily Hoeffding. 1994. Probability inequalities for sums of bounded random variables. In The collected works of Wassily Hoeffding. Springer, 409--426."},{"volume-title":"29th USENIX security symposium (USENIX Security 20). 1345--1362.","author":"Jagielski Matthew","key":"e_1_3_2_1_17_1","unstructured":"Matthew Jagielski, Nicholas Carlini, David Berthelot, Alex Kurakin, and Nicolas Papernot. 2020. High accuracy and high fidelity extraction of neural networks. In 29th USENIX security symposium (USENIX Security 20). 1345--1362."},{"key":"e_1_3_2_1_18_1","volume-title":"Entangled watermarks as a defense against model extraction. arXiv preprint arXiv:2002.12200","author":"Jia Hengrui","year":"2020","unstructured":"Hengrui Jia, Christopher A Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot. 2020a. Entangled watermarks as a defense against model extraction. arXiv preprint arXiv:2002.12200 (2020)."},{"key":"e_1_3_2_1_19_1","volume-title":"Almost tight L0-norm certified robustness of top-k predictions against adversarial perturbations. arXiv preprint arXiv:2011.07633","author":"Jia Jinyuan","year":"2020","unstructured":"Jinyuan Jia, Binghui Wang, Xiaoyu Cao, Hongbin Liu, and Neil Zhenqiang Gong. 2020b. Almost tight L0-norm certified robustness of top-k predictions against adversarial perturbations. arXiv preprint arXiv:2011.07633 (2020)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274740"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313665"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57529-2_18"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1177\/0278364904045481"},{"volume-title":"Calculus with applications","author":"Lax Peter D","key":"e_1_3_2_1_26_1","unstructured":"Peter D Lax and Maria Shea Terrell. 2014. Calculus with applications. Springer."},{"key":"e_1_3_2_1_27_1","volume-title":"A long-term study of content polluters on twitter. ICWSM, seven months with the devils","author":"Lee K","year":"2011","unstructured":"K Lee, BD Eoff, and J Caverlee. 2011. A long-term study of content polluters on twitter. ICWSM, seven months with the devils (2011)."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00020"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"e_1_3_2_1_30_1","volume-title":"ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. In 31st USENIX Security Symposium, USENIX Security 2022","author":"Liu Yugeng","year":"2022","unstructured":"Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2022. ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022, Kevin R. B. Butler and Kurt Thomas (Eds.). USENIX Association, 4525--4542. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/liu-yugeng"},{"key":"e_1_3_2_1_31_1","volume-title":"Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)."},{"key":"e_1_3_2_1_32_1","volume-title":"Black-box model inversion attribute inference attacks on classification models. arXiv preprint arXiv:2012.03404","author":"Mehnaz Shagufta","year":"2020","unstructured":"Shagufta Mehnaz, Ninghui Li, and Elisa Bertino. 2020. Black-box model inversion attribute inference attacks on classification models. arXiv preprint arXiv:2012.03404 (2020)."},{"key":"e_1_3_2_1_33_1","volume-title":"International Conference on Machine Learning. PMLR, 3578--3586","author":"Mirman Matthew","year":"2018","unstructured":"Matthew Mirman, Timon Gehr, and Martin Vechev. 2018. Differentiable abstract interpretation for provably robust neural networks. In International Conference on Machine Learning. PMLR, 3578--3586."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/0925-2312(91)90023-5"},{"key":"e_1_3_2_1_35_1","volume-title":"I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences. arXiv preprint arXiv:2206.08451","author":"Oliynyk Daryna","year":"2022","unstructured":"Daryna Oliynyk, Rudolf Mayer, and Andreas Rauber. 2022. I Know What You Trained Last Summer: A Survey on Stealing Machine Learning Models and Defences. arXiv preprint arXiv:2206.08451 (2022)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_1_37_1","volume-title":"Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks. In 8th International Conference on Learning Representations, ICLR 2020","author":"Orekondy Tribhuvanesh","year":"2020","unstructured":"Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2020. Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks. In 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26-30, 2020. OpenReview.net. https:\/\/openreview.net\/forum?id=SyevYxHtDB"},{"key":"e_1_3_2_1_38_1","volume-title":"Stateful Detection of Model Extraction Attacks. arXiv preprint arXiv:2107.05166","author":"Pal Soham","year":"2021","unstructured":"Soham Pal, Yash Gupta, Aditya Kanade, and Shirish Shevade. 2021. Stateful Detection of Model Extraction Attacks. arXiv preprint arXiv:2107.05166 (2021)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_41_1","volume-title":"CLN2INV: learning loop invariants with continuous logic networks. arXiv preprint arXiv:1909.11542","author":"Ryan Gabriel","year":"2019","unstructured":"Gabriel Ryan, Justin Wong, Jianan Yao, Ronghui Gu, and Suman Jana. 2019. CLN2INV: learning loop invariants with continuous logic networks. arXiv preprint arXiv:1909.11542 (2019)."},{"key":"e_1_3_2_1_42_1","volume-title":"Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models. arXiv preprint arXiv:1806.01246","author":"Salem Ahmed","year":"2018","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2018. Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models. arXiv preprint arXiv:1806.01246 (2018)."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_44_1","volume-title":"Certifying some distributional robustness with principled adversarial training. arXiv preprint arXiv:1710.10571","author":"Sinha Aman","year":"2017","unstructured":"Aman Sinha, Hongseok Namkoong, Riccardo Volpi, and John Duchi. 2017. Certifying some distributional robustness with principled adversarial training. arXiv preprint arXiv:1710.10571 (2017)."},{"key":"e_1_3_2_1_45_1","volume-title":"Improving the generalization of adversarial training with domain adaptation. arXiv preprint arXiv:1810.00740","author":"Song Chuanbiao","year":"2018","unstructured":"Chuanbiao Song, Kun He, Liwei Wang, and John E Hopcroft. 2018. Improving the generalization of adversarial training with domain adaptation. arXiv preprint arXiv:1810.00740 (2018)."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354211"},{"key":"e_1_3_2_1_47_1","volume-title":"Dropout: a simple way to prevent neural networks from overfitting. The journal of machine learning research","author":"Srivastava Nitish","year":"2014","unstructured":"Nitish Srivastava, Geoffrey Hinton, Alex Krizhevsky, Ilya Sutskever, and Ruslan Salakhutdinov. 2014. Dropout: a simple way to prevent neural networks from overfitting. The journal of machine learning research, Vol. 15, 1 (2014), 1929--1958."},{"key":"e_1_3_2_1_48_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"volume-title":"25th USENIX security symposium (USENIX Security 16). 601--618.","author":"Tram\u00e8r Florian","key":"e_1_3_2_1_49_1","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction {APIs}. In 25th USENIX security symposium (USENIX Security 16). 601--618."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"e_1_3_2_1_51_1","volume-title":"International Conference on Machine Learning. PMLR, 5286--5295","author":"Wong Eric","year":"2018","unstructured":"Eric Wong and Zico Kolter. 2018. Provable defenses against adversarial examples via the convex outer adversarial polytope. In International Conference on Machine Learning. PMLR, 5286--5295."},{"key":"e_1_3_2_1_52_1","volume-title":"LOT: Layer-wise Orthogonal Training on Improving l2 Certified Robustness. NeurIPS","author":"Xu Xiaojun","year":"2022","unstructured":"Xiaojun Xu, Linyi Li, and Bo Li. 2022. LOT: Layer-wise Orthogonal Training on Improving l2 Certified Robustness. NeurIPS (2022)."},{"key":"e_1_3_2_1_53_1","volume-title":"Improving Certified Robustness via Statistical Learning with Logical Reasoning. NeurIPS","author":"Yang Zhuolin","year":"2022","unstructured":"Zhuolin Yang, Zhikuan Zhao, Boxin Wang, Jiawei Zhang, Linyi Li, Hengzhi Pei, Bojan Karla?, Ji Liu, Heng Guo, Ce Zhang, and Bo Li. 2022. Improving Certified Robustness via Statistical Learning with Logical Reasoning. NeurIPS (2022)."},{"key":"e_1_3_2_1_54_1","unstructured":"Honggang Yu Kaichen Yang Teng Zhang Yun-Yun Tsai Tsung-Yi Ho and Yier Jin. 2020. CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples.. In NDSS."},{"key":"e_1_3_2_1_55_1","volume-title":"mixup: Beyond empirical risk minimization. arXiv preprint arXiv:1710.09412","author":"Zhang Hongyi","year":"2017","unstructured":"Hongyi Zhang, Moustapha Cisse, Yann N Dauphin, and David Lopez-Paz. 2017. mixup: Beyond empirical risk minimization. arXiv preprint arXiv:1710.09412 (2017)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196550"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486863"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_4"}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Copenhagen Denmark","acronym":"CCS '23"},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616653","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3616653","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:46:34Z","timestamp":1755740794000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3616653"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":58,"alternative-id":["10.1145\/3576915.3616653","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3616653","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}