{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,3]],"date-time":"2025-12-03T18:10:49Z","timestamp":1764785449641,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":35,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,12,6]],"date-time":"2023-12-06T00:00:00Z","timestamp":1701820800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2211302","2211888","2213636","2105494","1908536"],"award-info":[{"award-number":["2211302","2211888","2213636","2105494","1908536"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006754","name":"Army Research Laboratory","doi-asserted-by":"publisher","award":["W911NF-17-2-0196"],"award-info":[{"award-number":["W911NF-17-2-0196"]}],"id":[{"id":"10.13039\/100006754","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,12,6]]},"DOI":"10.1145\/3583740.3626617","type":"proceedings-article","created":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T18:35:50Z","timestamp":1723055750000},"page":"121-132","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["SODA: Protecting Proprietary Information in On-Device Machine Learning Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1318-7225","authenticated-orcid":false,"given":"Akanksha","family":"Atrey","sequence":"first","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, Massachusetts, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0344-1368","authenticated-orcid":false,"given":"Ritwik","family":"Sinha","sequence":"additional","affiliation":[{"name":"Adobe Research, San Jose, California, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4048-2142","authenticated-orcid":false,"given":"Saayan","family":"Mitra","sequence":"additional","affiliation":[{"name":"Adobe Research, San Jose, California, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5435-1901","authenticated-orcid":false,"given":"Prashant","family":"Shenoy","sequence":"additional","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, Massachusetts, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,8,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2017. Apple's 'Neural Engine' Infuses the iPhone With AI Smarts. www.wired.com\/story\/apples-neural-engine-infuses-the-iphone-with-ai-smarts\/."},{"key":"e_1_3_2_1_2_1","unstructured":"2019. Intel Vision Accelerator Design With Intel Movidius Vision Processing Unit (VPU). https:\/\/software.intel.com\/en-us\/iot\/hardware\/vision-accelerator-movidius-vpu#specifications."},{"key":"e_1_3_2_1_3_1","unstructured":"2019. The NVIDIA EGX Platform for Edge Computing. https:\/\/www.nvidia.com\/en-us\/data-center\/products\/egx-edge-computing\/."},{"key":"e_1_3_2_1_4_1","unstructured":"2019. Open Neural Network Exchange. https:\/\/onnx.ai\/. Accessed on 01\/18\/2022."},{"key":"e_1_3_2_1_5_1","volume-title":"Jorge Luis Reyes-Ortiz, et al","author":"Anguita Davide","year":"2013","unstructured":"Davide Anguita, Alessandro Ghio, Luca Oneto, Xavier Parra, Jorge Luis Reyes-Ortiz, et al. 2013. A public domain dataset for human activity recognition using smartphones.. In Esann."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2600428.2609627"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"e_1_3_2_1_8_1","volume-title":"Preserving Privacy in Personalized Models for Distributed Mobile Services. IEEE International Conference on Distributed Computing Systems","author":"Atrey Akanksha","year":"2021","unstructured":"Akanksha Atrey, Prashant Shenoy, and David Jensen. 2021. Preserving Privacy in Personalized Models for Distributed Mobile Services. IEEE International Conference on Distributed Computing Systems (2021)."},{"key":"e_1_3_2_1_9_1","volume-title":"International Joint Conference on Neural Networks (IJCNN). IEEE.","author":"Correia-Silva Jacson Rodrigues","year":"2018","unstructured":"Jacson Rodrigues Correia-Silva, Rodrigo F Berriel, Claudine Badue, Alberto F de Souza, and Thiago Oliveira-Santos. 2018. Copycat cnn: Stealing knowledge by persuading confession with random non-labeled data. In International Joint Conference on Neural Networks (IJCNN). IEEE."},{"key":"e_1_3_2_1_10_1","unstructured":"Google Developers. 2022. Why On-Device Machine Learning? https:\/\/developers.google.com\/learn\/topics\/on-device-ml\/learn-more."},{"key":"e_1_3_2_1_11_1","volume-title":"Consumers' privacy concerns and implications for a privacy preserving Smart Grid architecture---Results of an Austrian study. Energy Research & Social Science","author":"D\u00f6belt Susen","year":"2015","unstructured":"Susen D\u00f6belt, Markus Jung, Marc Busch, and Manfred Tscheligi. 2015. Consumers' privacy concerns and implications for a privacy preserving Smart Grid architecture---Results of an Austrian study. Energy Research & Social Science (2015)."},{"key":"e_1_3_2_1_12_1","volume-title":"ACM SIGSAC Conference on Computer and Communications Security.","author":"Fredrikson Matt","year":"2015","unstructured":"Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"e_1_3_2_1_14_1","volume-title":"On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280","author":"Grosse Kathrin","year":"2017","unstructured":"Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel. 2017. On the (statistical) detection of adversarial examples. arXiv preprint arXiv:1702.06280 (2017)."},{"key":"e_1_3_2_1_15_1","volume-title":"PRADA: Protecting Against DNN Model Stealing Attacks. In IEEE European Symposium on Security and Privacy (EuroS&P). IEEE.","author":"Juuti Mika","year":"2019","unstructured":"Mika Juuti, Sebastian Szyller, Samuel Marchal, and N Asokan. 2019. PRADA: Protecting Against DNN Model Stealing Attacks. In IEEE European Symposium on Security and Privacy (EuroS&P). IEEE."},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition.","author":"Kariyappa Sanjay","year":"2021","unstructured":"Sanjay Kariyappa, Atul Prakash, and Moinuddin K Qureshi. 2021. Maze: Data-free model stealing attack using zeroth-order gradient estimation. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition."},{"key":"e_1_3_2_1_17_1","volume-title":"International Conference on Learning Representations.","author":"Kariyappa Sanjay","year":"2021","unstructured":"Sanjay Kariyappa, Atul Prakash, and Moinuddin K Qureshi. 2021. Protecting dnns from theft using an ensemble of diverse models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition.","author":"Kariyappa Sanjay","year":"2020","unstructured":"Sanjay Kariyappa and Moinuddin K Qureshi. 2020. Defending against model stealing attacks with adaptive misinformation. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274740"},{"key":"e_1_3_2_1_20_1","unstructured":"Yann LeCun and Corinna Cortes. 2010. The MNIST Database of Handwritten Digits. http:\/\/yann.lecun.com\/exdb\/mnist\/."},{"key":"e_1_3_2_1_21_1","volume-title":"IEEE Security and Privacy Workshops (SPW). IEEE.","author":"Lee Taesung","year":"2019","unstructured":"Taesung Lee, Benjamin Edwards, Ian Molloy, and Dong Su. 2019. Defending against neural network model stealing attacks using deceptive perturbations. In IEEE Security and Privacy Workshops (SPW). IEEE."},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security.","author":"Liu Jian","year":"2017","unstructured":"Jian Liu, Mika Juuti, Yao Lu, and Nadarajah Asokan. 2017. Oblivious neural network predictions via minionn transformations. In Proceedings of the ACM SIGSAC Conference on Computer and Communications Security."},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the ACM SIGSAC conference on computer and communications security.","author":"Meng Dongyu","year":"2017","unstructured":"Dongyu Meng and Hao Chen. 2017. Magnet: a two-pronged defense against adversarial examples. In Proceedings of the ACM SIGSAC conference on computer and communications security."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3373376.3378522"},{"key":"e_1_3_2_1_25_1","volume-title":"Proceedings of the International Conference on Learning Representations.","author":"Oh Seong Joon","year":"2018","unstructured":"Seong Joon Oh, Bernt Schiele, and Mario Fritz. 2018. Towards reverse-engineering black-box neural networks. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_1_27_1","volume-title":"Prediction poisoning: Towards defenses against DNN model stealing attacks. arXiv preprint arXiv:1906.10908","author":"Orekondy Tribhuvanesh","year":"2019","unstructured":"Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2019. Prediction poisoning: Towards defenses against DNN model stealing attacks. arXiv preprint arXiv:1906.10908 (2019)."},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot, Mart\u00edn Abadi, Ulfar Erlingsson, Ian Goodfellow, and Kunal Talwar. 2017. Semi-supervised knowledge transfer for deep learning from private training data. Proceedings of the International Conference on Learning Representations (2017)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_30_1","volume-title":"IEEE Symposium on Security and Privacy (S&P). IEEE.","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2016. Distillation as a defense to adversarial perturbations against deep neural networks. In IEEE Symposium on Security and Privacy (S&P). IEEE."},{"key":"e_1_3_2_1_31_1","volume-title":"IEEE European symposium on security and privacy (EuroS&P). IEEE.","author":"Quiring Erwin","year":"2018","unstructured":"Erwin Quiring, Daniel Arp, and Konrad Rieck. 2018. Forgotten siblings: Unifying attacks on machine learning and digital watermarking. In IEEE European symposium on security and privacy (EuroS&P). IEEE."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of the USENIX Security Symposium.","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction apis. In Proceedings of the USENIX Security Symposium."},{"key":"e_1_3_2_1_34_1","volume-title":"AAAI Workshop on Crowdsourcing, Deep Learning, and Artificial Intelligence Agents","author":"Yoon Seunghyun","year":"2017","unstructured":"Seunghyun Yoon, Hyeongu Yun, Yuna Kim, Gyu-tae Park, and Kyomin Jung. 2017. Efficient transfer learning schemes for personalized language modeling using recurrent neural network. AAAI Workshop on Crowdsourcing, Deep Learning, and Artificial Intelligence Agents (2017)."},{"key":"e_1_3_2_1_35_1","volume-title":"Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining.","author":"Zhou Chong","year":"2017","unstructured":"Chong Zhou and Randy C Paffenroth. 2017. Anomaly detection with robust deep autoencoders. In Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining."}],"event":{"name":"SEC '23: Eighth ACM\/IEEE Symposium on Edge Computing","sponsor":["SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing","IEEE Computer Society"],"location":"Wilmington DE USA","acronym":"SEC '23"},"container-title":["Proceedings of the Eighth ACM\/IEEE Symposium on Edge Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3583740.3626617","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3583740.3626617","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:46:28Z","timestamp":1750178788000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3583740.3626617"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,6]]},"references-count":35,"alternative-id":["10.1145\/3583740.3626617","10.1145\/3583740"],"URL":"https:\/\/doi.org\/10.1145\/3583740.3626617","relation":{},"subject":[],"published":{"date-parts":[[2023,12,6]]},"assertion":[{"value":"2024-08-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}