{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T15:29:54Z","timestamp":1777390194730,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":25,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,12,4]],"date-time":"2023-12-04T00:00:00Z","timestamp":1701648000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"Deutscher Akademischer Austauschdienst","doi-asserted-by":"publisher","award":["IFI"],"award-info":[{"award-number":["IFI"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006374","name":"European Research Council","doi-asserted-by":"publisher","award":["101043410"],"award-info":[{"award-number":["101043410"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Bundesministerium f\u00fcr Bildung und Forschung","award":["BIFOLD23B"],"award-info":[{"award-number":["BIFOLD23B"]}]},{"DOI":"10.13039\/501100006374","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["390781972"],"award-info":[{"award-number":["390781972"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,12,4]]},"DOI":"10.1145\/3627106.3627134","type":"proceedings-article","created":{"date-parts":[[2023,12,2]],"date-time":"2023-12-02T18:13:22Z","timestamp":1701540802000},"page":"506-520","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["On the Detection of Image-Scaling Attacks in Machine Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-7170-1274","authenticated-orcid":false,"given":"Erwin","family":"Quiring","sequence":"first","affiliation":[{"name":"International Computer Science Institute (ICSI), USA and Ruhr University Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-1199-4477","authenticated-orcid":false,"given":"Andreas","family":"M\u00fcller","sequence":"additional","affiliation":[{"name":"Ruhr University Bochum, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5054-8758","authenticated-orcid":false,"given":"Konrad","family":"Rieck","sequence":"additional","affiliation":[{"name":"TU Berlin, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,12,4]]},"reference":[{"key":"e_1_3_2_1_1_1","first-page":"84","article-title":"Ten years after the rise of adversarial machine learning","author":"Biggio F.","year":"2018","unstructured":"[1] B.\u00a0Biggio and F.\u00a0Roli. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, 84, 2018.","journal-title":"Pattern Recognition"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2011.2106121"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2971601"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00025"},{"key":"e_1_3_2_1_6_1","volume-title":"Proc. of Int. Conference on Machine Learning (ICML)","author":"Gao I.","year":"2022","unstructured":"[6] Y.\u00a0Gao, I.\u00a0Shumailov, and K.\u00a0Fawaz. Rethinking image-scaling attacks: The interplay between vulnerabilities in machine learning systems. In Proc. of Int. Conference on Machine Learning (ICML), 2022."},{"key":"e_1_3_2_1_7_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv: 1708.06733","author":"Gu B.","year":"2017","unstructured":"[7] T.\u00a0Gu, B.\u00a0Dolan-Gavitt, and S.\u00a0Garg. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv: 1708.06733, 2017."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR.2010.579"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN48987.2021.00023"},{"issue":"4","key":"e_1_3_2_1_11_1","article-title":"Hiding traces of resampling in digital images","volume":"3","author":"Kirchner R.","year":"2008","unstructured":"[11] M.\u00a0Kirchner and R.\u00a0B\u00f6hme. Hiding traces of resampling in digital images. IEEE Transactions on Information Forensics and Security (TIFS), 3(4), 2008.","journal-title":"IEEE Transactions on Information Forensics and Security (TIFS)"},{"key":"e_1_3_2_1_12_1","volume-title":"Learning multiple layers of features from tiny images. Technical report","author":"Krizhevsky G.","year":"2009","unstructured":"[12] A.\u00a0Krizhevsky and G.\u00a0Hinton. Learning multiple layers of features from tiny images. Technical report, 2009."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW50608.2020.00024"},{"key":"e_1_3_2_1_16_1","volume-title":"Proc. of USENIX Security Symposium","author":"Quiring A.","year":"2019","unstructured":"[16] E.\u00a0Quiring, A.\u00a0Maier, and K.\u00a0Rieck. Misleading authorship attribution of source code using adversarial learning. In Proc. of USENIX Security Symposium, 2019."},{"key":"e_1_3_2_1_17_1","volume-title":"Proc. of USENIX Security Symposium","author":"Quiring D.","year":"2020","unstructured":"[17] E.\u00a0Quiring, D.\u00a0Klein, D.\u00a0Arp, M.\u00a0Johns, and K.\u00a0Rieck. Adversarial preprocessing: Understanding and preventing image-scaling attacks in machine learning. In Proc. of USENIX Security Symposium, 2020."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00049"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4614-0757-7"},{"key":"e_1_3_2_1_21_1","volume-title":"Advances in Neural Information Proccessing Systems (NIPS)","author":"Shafahi W.","year":"2018","unstructured":"[21] A.\u00a0Shafahi, W.\u00a0R. Huang, M.\u00a0Najibi, O.\u00a0Suciu, C.\u00a0Studer, T.\u00a0Dumitras, and T.\u00a0Goldstein. Poison frogs! Targeted clean-label poisoning attacks on neural networks. In Advances in Neural Information Proccessing Systems (NIPS), 2018."},{"key":"e_1_3_2_1_22_1","volume-title":"Very deep convolutional networks for large-scale image recognition. arXiv:1409.1556","author":"Simonyan A.","year":"2014","unstructured":"[22] K.\u00a0Simonyan and A.\u00a0Zisserman. Very deep convolutional networks for large-scale image recognition. arXiv:1409.1556, 2014."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/281875"},{"key":"e_1_3_2_1_24_1","volume-title":"Proc. of USENIX Security Symposium","author":"Xiao Y.","year":"2019","unstructured":"[24] Q.\u00a0Xiao, Y.\u00a0Chen, C.\u00a0Shen, Y.\u00a0Chen, and K.\u00a0Li. Seeing is not believing: Camouflage attacks on image scaling algorithms. In Proc. of USENIX Security Symposium, 2019."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"}],"event":{"name":"ACSAC '23: Annual Computer Security Applications Conference","location":"Austin TX USA","acronym":"ACSAC '23"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627134","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627106.3627134","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T17:39:29Z","timestamp":1755884369000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627106.3627134"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,12,4]]},"references-count":25,"alternative-id":["10.1145\/3627106.3627134","10.1145\/3627106"],"URL":"https:\/\/doi.org\/10.1145\/3627106.3627134","relation":{},"subject":[],"published":{"date-parts":[[2023,12,4]]},"assertion":[{"value":"2023-12-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}