{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T02:09:07Z","timestamp":1776132547680,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":60,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,7,10]],"date-time":"2023-07-10T00:00:00Z","timestamp":1688947200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001456","name":"Land Transport Authority - Singapore","doi-asserted-by":"publisher","award":["UMGC-L011"],"award-info":[{"award-number":["UMGC-L011"]}],"id":[{"id":"10.13039\/501100001456","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001348","name":"Agency for Science, Technology and Research","doi-asserted-by":"publisher","award":["A19D6A0053"],"award-info":[{"award-number":["A19D6A0053"]}],"id":[{"id":"10.13039\/501100001348","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001381","name":"National Research Foundation Singapore","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,7,10]]},"DOI":"10.1145\/3592538.3594273","type":"proceedings-article","created":{"date-parts":[[2023,7,19]],"date-time":"2023-07-19T19:45:18Z","timestamp":1689795918000},"page":"3-13","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["PAID: Perturbed Image Attacks Analysis and Intrusion Detection Mechanism for Autonomous Driving Systems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-6120-8509","authenticated-orcid":false,"given":"Ko Zheng","family":"Teng","sequence":"first","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2603-1046","authenticated-orcid":false,"given":"Trupil","family":"Limbasiya","sequence":"additional","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5660-2447","authenticated-orcid":false,"given":"Federico","family":"Turrin","sequence":"additional","affiliation":[{"name":"University of Padua, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7640-2821","authenticated-orcid":false,"given":"Yan Lin","family":"Aung","sequence":"additional","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4843-5391","authenticated-orcid":false,"given":"Sudipta","family":"Chattopadhyay","sequence":"additional","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0594-0432","authenticated-orcid":false,"given":"Jianying","family":"Zhou","sequence":"additional","affiliation":[{"name":"Singapore University of Technology and Design, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3612-1934","authenticated-orcid":false,"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[{"name":"University of Padua, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,7,19]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"LiDAR Spoofing Attack Detection in Autonomous Vehicles. In 2022 IEEE International Conference on Consumer Electronics (ICCE). IEEE, 1\u20132.","author":"M\u00a0Ali Alheeti Khattab","year":"2022","unstructured":"Khattab M\u00a0Ali Alheeti , Abdulkareem Alzahrani , and Duaa Al\u00a0Dosary . 2022 . LiDAR Spoofing Attack Detection in Autonomous Vehicles. In 2022 IEEE International Conference on Consumer Electronics (ICCE). IEEE, 1\u20132. Khattab M\u00a0Ali Alheeti, Abdulkareem Alzahrani, and Duaa Al\u00a0Dosary. 2022. LiDAR Spoofing Attack Detection in Autonomous Vehicles. In 2022 IEEE International Conference on Consumer Electronics (ICCE). IEEE, 1\u20132."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3431233"},{"key":"e_1_3_2_1_3_1","volume-title":"Model evasion attack on intrusion detection systems using adversarial machine learning. In 2020 54th annual conference on information sciences and systems (CISS)","author":"Ayub Md\u00a0Ahsan","unstructured":"Md\u00a0Ahsan Ayub , William\u00a0 A Johnson , Douglas\u00a0 A Talbert , and Ambareen Siraj . 2020. Model evasion attack on intrusion detection systems using adversarial machine learning. In 2020 54th annual conference on information sciences and systems (CISS) . IEEE , 1\u20136. Md\u00a0Ahsan Ayub, William\u00a0A Johnson, Douglas\u00a0A Talbert, and Ambareen Siraj. 2020. Model evasion attack on intrusion detection systems using adversarial machine learning. In 2020 54th annual conference on information sciences and systems (CISS). IEEE, 1\u20136."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_1_5_1","volume-title":"Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio , Blaine Nelson , and Pavel Laskov . 2012. Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 ( 2012 ). Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389 (2012)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.14722\/autosec.2021.23002"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/IVS.2017.7995975"},{"key":"e_1_3_2_1_8_1","volume-title":"Inferring transportation modes from GPS trajectories using a convolutional neural network. Transportation research part C: emerging technologies 86","author":"Dabiri Sina","year":"2018","unstructured":"Sina Dabiri and Kevin Heaslip . 2018. Inferring transportation modes from GPS trajectories using a convolutional neural network. Transportation research part C: emerging technologies 86 ( 2018 ), 360\u2013371. Sina Dabiri and Kevin Heaslip. 2018. Inferring transportation modes from GPS trajectories using a convolutional neural network. Transportation research part C: emerging technologies 86 (2018), 360\u2013371."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/PerCom45495.2020.9127389"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIV.2020.3003524"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65610-2_4"},{"key":"e_1_3_2_1_12_1","volume-title":"Generative adversarial nets. Advances in neural information processing systems 27","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow , Jean Pouget-Abadie , Mehdi Mirza , Bing Xu , David Warde-Farley , Sherjil Ozair , Aaron Courville , and Yoshua Bengio . 2014. Generative adversarial nets. Advances in neural information processing systems 27 ( 2014 ). Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. Advances in neural information processing systems 27 (2014)."},{"key":"e_1_3_2_1_13_1","volume-title":"Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1412","author":"Goodfellow Ian","year":"2015","unstructured":"Ian Goodfellow , Jonathon Shlens , and Christian Szegedy . 2015 . Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1412 .6572 Ian Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_1_14_1","volume-title":"Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117","author":"Guo Chuan","year":"2017","unstructured":"Chuan Guo , Mayank Rana , Moustapha Cisse , and Laurens Van Der\u00a0Maaten . 2017. Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 ( 2017 ). Chuan Guo, Mayank Rana, Moustapha Cisse, and Laurens Van Der\u00a0Maaten. 2017. Countering adversarial images using input transformations. arXiv preprint arXiv:1711.00117 (2017)."},{"key":"e_1_3_2_1_15_1","volume-title":"Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA\/BDCloud\/SocialCom\/SustainCom)","author":"Han Xingshuo","unstructured":"Xingshuo Han , Kangjie Chen , Yuan Zhou , Meikang Qiu , Chun Fan , Yang Liu , and Tianwei Zhang . 2021. A Unified Anomaly Detection Methodology for Lane-Following of Autonomous Driving Systems. In 2021 IEEE Intl Conf on Parallel & Distributed Processing with Applications , Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA\/BDCloud\/SocialCom\/SustainCom) . IEEE , 836\u2013844. Xingshuo Han, Kangjie Chen, Yuan Zhou, Meikang Qiu, Chun Fan, Yang Liu, and Tianwei Zhang. 2021. A Unified Anomaly Detection Methodology for Lane-Following of Autonomous Driving Systems. In 2021 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA\/BDCloud\/SocialCom\/SustainCom). IEEE, 836\u2013844."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.imavis.2017.07.003"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2982544"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3301282","article-title":"How generative adversarial networks and their variants work: An overview","volume":"52","author":"Hong Yongjun","year":"2019","unstructured":"Yongjun Hong , Uiwon Hwang , Jaeyoon Yoo , and Sungroh Yoon . 2019 . How generative adversarial networks and their variants work: An overview . ACM Computing Surveys (CSUR) 52 , 1 (2019), 1 \u2013 43 . Yongjun Hong, Uiwon Hwang, Jaeyoon Yoo, and Sungroh Yoon. 2019. How generative adversarial networks and their variants work: An overview. ACM Computing Surveys (CSUR) 52, 1 (2019), 1\u201343.","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3212480.3212492"},{"key":"e_1_3_2_1_20_1","volume-title":"International Conference on Information and Communications Security. Springer, 124\u2013142","author":"Jiang Jingxuan","year":"2019","unstructured":"Jingxuan Jiang , Chundong Wang , Sudipta Chattopadhyay , and Wei Zhang . 2019 . Road context-aware intrusion detection system for autonomous cars . In International Conference on Information and Communications Security. Springer, 124\u2013142 . Jingxuan Jiang, Chundong Wang, Sudipta Chattopadhyay, and Wei Zhang. 2019. Road context-aware intrusion detection system for autonomous cars. In International Conference on Information and Communications Security. Springer, 124\u2013142."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102150"},{"key":"e_1_3_2_1_22_1","volume-title":"EASI: Edge-Based Sender Identification on Resource-Constrained Platforms for Automotive Networks.. In NDSS.","author":"Kneib Marcel","year":"2020","unstructured":"Marcel Kneib , Oleg Schell , and Christopher Huth . 2020 . EASI: Edge-Based Sender Identification on Resource-Constrained Platforms for Automotive Networks.. In NDSS. Marcel Kneib, Oleg Schell, and Christopher Huth. 2020. EASI: Edge-Based Sender Identification on Resource-Constrained Platforms for Automotive Networks.. In NDSS."},{"key":"e_1_3_2_1_23_1","volume-title":"Sensors and sensor fusion in autonomous vehicles. In 2018 26th Telecommunications Forum (TELFOR)","author":"Koci\u0107 Jelena","unstructured":"Jelena Koci\u0107 , Nenad Jovi\u010di\u0107 , and Vujo Drndarevi\u0107 . 2018. Sensors and sensor fusion in autonomous vehicles. In 2018 26th Telecommunications Forum (TELFOR) . IEEE , 420\u2013425. Jelena Koci\u0107, Nenad Jovi\u010di\u0107, and Vujo Drndarevi\u0107. 2018. Sensors and sensor fusion in autonomous vehicles. In 2018 26th Telecommunications Forum (TELFOR). IEEE, 420\u2013425."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01426"},{"key":"e_1_3_2_1_25_1","volume-title":"Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin , Ian Goodfellow , and Samy Bengio . 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 ( 2016 ). Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016)."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00780"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00191"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2022.100515"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3173162.3173191"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3078111"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1186\/s13638-019-1484-3"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2020.1003021"},{"key":"e_1_3_2_1_33_1","volume-title":"On detecting adversarial perturbations. arXiv preprint arXiv:1702.04267","author":"Metzen Jan\u00a0Hendrik","year":"2017","unstructured":"Jan\u00a0Hendrik Metzen , Tim Genewein , Volker Fischer , and Bastian Bischoff . 2017. On detecting adversarial perturbations. arXiv preprint arXiv:1702.04267 ( 2017 ). Jan\u00a0Hendrik Metzen, Tim Genewein, Volker Fischer, and Bastian Bischoff. 2017. On detecting adversarial perturbations. arXiv preprint arXiv:1702.04267 (2017)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.vehcom.2019.100184"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423359"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00288"},{"key":"e_1_3_2_1_39_1","unstructured":"Singapore\u00a0Statutes Online. 2019. Speed and Stopping Distances Singapore. https:\/\/sso.agc.gov.sg\/SL\/RTA1961-R11?ProvIds=pr46- pr53- pr54- pr55- pr56- [Accessed 20-Apr-2022].  Singapore\u00a0Statutes Online. 2019. Speed and Stopping Distances Singapore. https:\/\/sso.agc.gov.sg\/SL\/RTA1961-R11?ProvIds=pr46- pr53- pr54- pr55- pr56- [Accessed 20-Apr-2022]."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2983285"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eng.2019.12.012"},{"key":"e_1_3_2_1_44_1","unstructured":"Udacity\u00a0Auro Robotics. 2018. Udacity Self-Driving Car Dataset 2-2. https:\/\/github.com\/udacity\/self-driving-car [Accessed 7-Sept-2022].  Udacity\u00a0Auro Robotics. 2018. Udacity Self-Driving Car Dataset 2-2. https:\/\/github.com\/udacity\/self-driving-car [Accessed 7-Sept-2022]."},{"key":"e_1_3_2_1_45_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Shen Junjie","year":"2020","unstructured":"Junjie Shen , Jun\u00a0Yeon Won , Zeyuan Chen , and Qi\u00a0Alfred Chen . 2020 . Drift with Devil: Security of { Multi-Sensor} Fusion based Localization in { High-Level} Autonomous Driving under { GPS} Spoofing . In 29th USENIX Security Symposium (USENIX Security 20) . 931\u2013948. Junjie Shen, Jun\u00a0Yeon Won, Zeyuan Chen, and Qi\u00a0Alfred Chen. 2020. Drift with Devil: Security of { Multi-Sensor} Fusion based Localization in { High-Level} Autonomous Driving under { GPS} Spoofing. In 29th USENIX Security Symposium (USENIX Security 20). 931\u2013948."},{"key":"e_1_3_2_1_46_1","unstructured":"SullyChen. 2021. Chen driving datatets. https:\/\/github.com\/SullyChen\/driving-datasets [Accessed 7-Sept-2022].  SullyChen. 2021. Chen driving datatets. https:\/\/github.com\/SullyChen\/driving-datasets [Accessed 7-Sept-2022]."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3076287"},{"key":"e_1_3_2_1_48_1","volume-title":"International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1312","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2014 . Intriguing properties of neural networks . In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1312 .6199 Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In International Conference on Learning Representations. http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSAA.2016.20"},{"key":"e_1_3_2_1_50_1","unstructured":"Tesla Inc.2021. Transitioning to Tesla Vision. https:\/\/www.tesla.com\/support\/transitioning-tesla-vision [Accessed 20-Apr-2022].  Tesla Inc.2021. Transitioning to Tesla Vision. https:\/\/www.tesla.com\/support\/transitioning-tesla-vision [Accessed 20-Apr-2022]."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2018.2888904"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10489-021-02759-8"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484766"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2019.2908074"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00750"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.5555\/3304222.3304312"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2021.3061065"},{"key":"e_1_3_2_1_58_1","volume-title":"Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018","author":"Xu Weilin","year":"2018","unstructured":"Weilin Xu , David Evans , and Yanjun Qi . 2018 . Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018 , San Diego, California, USA , February 18-21, 2018. The Internet Society. http:\/\/wp.internetsociety.org\/ndss\/wp-content\/uploads\/sites\/25\/2018\/02\/ndss2018_03A-4_Xu_paper.pdf Weilin Xu, David Evans, and Yanjun Qi. 2018. Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks. In 25th Annual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18-21, 2018. The Internet Society. http:\/\/wp.internetsociety.org\/ndss\/wp-content\/uploads\/sites\/25\/2018\/02\/ndss2018_03A-4_Xu_paper.pdf"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3024643"},{"key":"e_1_3_2_1_60_1","volume-title":"Beware of What Get You There: Towards Understanding Model Extraction Attack. arXiv preprint arXiv:2104.05921","author":"Zhang Xinyi","year":"2021","unstructured":"Xinyi Zhang , Chengfang Fang , and Jie Shi . 2021. Thief , Beware of What Get You There: Towards Understanding Model Extraction Attack. arXiv preprint arXiv:2104.05921 ( 2021 ). Xinyi Zhang, Chengfang Fang, and Jie Shi. 2021. Thief, Beware of What Get You There: Towards Understanding Model Extraction Attack. arXiv preprint arXiv:2104.05921 (2021)."}],"event":{"name":"ASIA CCS '23: ACM Asia Conference on Computer and Communications Security","location":"Melbourne VIC Australia","acronym":"ASIA CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 9th ACM Cyber-Physical System Security Workshop"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3592538.3594273","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3592538.3594273","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:00Z","timestamp":1750182540000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3592538.3594273"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,10]]},"references-count":60,"alternative-id":["10.1145\/3592538.3594273","10.1145\/3592538"],"URL":"https:\/\/doi.org\/10.1145\/3592538.3594273","relation":{},"subject":[],"published":{"date-parts":[[2023,7,10]]},"assertion":[{"value":"2023-07-19","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}