{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T22:42:26Z","timestamp":1780612946720,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":22,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,6,23]],"date-time":"2024-06-23T00:00:00Z","timestamp":1719100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272459"],"award-info":[{"award-number":["62272459"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,6,23]]},"DOI":"10.1145\/3649329.3654810","type":"proceedings-article","created":{"date-parts":[[2024,11,7]],"date-time":"2024-11-07T19:27:22Z","timestamp":1731007642000},"page":"1-6","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Garrison: A High-Performance GPU-Accelerated Inference System for Adversarial Ensemble Defense"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-2485-0899","authenticated-orcid":false,"given":"Yan","family":"Wang","sequence":"first","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences; School of Cyber Security, University of Chinese Academy of Sciences, Beijing, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1432-6429","authenticated-orcid":false,"given":"Xingbin","family":"Wang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-8733-6907","authenticated-orcid":false,"given":"Zechao","family":"Lin","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering,Chinese Academy of Sciences, Beijing, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7539-7132","authenticated-orcid":false,"given":"Yulan","family":"Su","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, Beijing, China"},{"name":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3746-8083","authenticated-orcid":false,"given":"Sisi","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9215-7632","authenticated-orcid":false,"given":"Rui","family":"Hou","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-9868-5353","authenticated-orcid":false,"given":"Dan","family":"Meng","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"ICASSP","year":"2023","unstructured":"Fan M, et al. Enhance transferability of adversarial examples with model architecture. ICASSP, 2023."},{"key":"e_1_3_2_1_2_1","volume-title":"Adversarial Robustness for Face Recognition: How to Introduce Ensemble Diversity among Feature Extractors? SafeAI@ AAAI","year":"2021","unstructured":"Amada T, et al. Adversarial Robustness for Face Recognition: How to Introduce Ensemble Diversity among Feature Extractors? SafeAI@ AAAI. 2021."},{"key":"e_1_3_2_1_3_1","volume-title":"NeurPS","author":"Yang Zhuolin","year":"2021","unstructured":"Yang, Zhuolin, et al. Trs: Transferability reduced ensemble via promoting gradient diversity and model smoothness. NeurPS, 2021."},{"key":"e_1_3_2_1_4_1","volume-title":"TOSN","year":"2021","unstructured":"Song Q, et al. DeepMTD: Moving Target Defense for Deep Visual Sensing against Adversarial Examples. TOSN, 2021."},{"key":"e_1_3_2_1_5_1","volume-title":"A research agenda: Dynamic models to defend against correlated attacks. arXiv preprint arXiv:1903.06293","author":"Goodfellow Ian","year":"2019","unstructured":"Goodfellow, Ian. A research agenda: Dynamic models to defend against correlated attacks. arXiv preprint arXiv:1903.06293 (2019)."},{"key":"e_1_3_2_1_6_1","volume-title":"NSDI","author":"Gunasekaran Cocktail","year":"2022","unstructured":"Gunasekaran, et al. Cocktail: A multidimensional optimization for model serving in cloud. NSDI, 2022."},{"key":"e_1_3_2_1_7_1","volume-title":"ICLR","author":"Liu Yanpei","year":"2017","unstructured":"Liu, Yanpei, et al. Delving into transferable adversarial examples and black-box attacks. ICLR, 2017."},{"key":"e_1_3_2_1_8_1","volume-title":"NeurIPS","author":"Heredia","year":"2023","unstructured":"Heredia, et al. On the Role of Randomization in Adversarially Robust Classification. NeurIPS, 2023."},{"key":"e_1_3_2_1_9_1","volume-title":"ICML","year":"2023","unstructured":"Pinot R, et al. On the robustness of randomized classifiers to adversarial examples. ICML, 2023."},{"key":"e_1_3_2_1_10_1","volume-title":"ICML","author":"Pinot","year":"2020","unstructured":"R. Pinot, et al. Randomization matters how to defend against strong adversarial attacks. ICML, 2020"},{"key":"e_1_3_2_1_11_1","volume-title":"ICML","author":"Dbouk","year":"2023","unstructured":"Dbouk, et al. On the robustness of randomized ensembles to adversarial perturbations. ICML, 2023."},{"key":"e_1_3_2_1_12_1","volume-title":"NeurIPS","author":"Peng Qi","year":"2022","unstructured":"Peng, Qi, et al. Dynamic Stochastic Ensemble with Adversarial Robust Lottery Ticket Subnetworks. NeurIPS, 2022."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16955"},{"key":"e_1_3_2_1_14_1","volume-title":"NSDI","author":"Crankshaw Clipper","year":"2017","unstructured":"Crankshaw, et al. Clipper: A Low-Latency online prediction serving system. NSDI, 2017."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419111.3421284"},{"key":"e_1_3_2_1_16_1","volume-title":"PMLR","author":"Ilyas","year":"2018","unstructured":"Ilyas, et al. Black-box adversarial attacks with limited queries and information. PMLR, 2018."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20053-3_19"},{"key":"e_1_3_2_1_18_1","volume-title":"NeurIPS","author":"Cui Sen","year":"2022","unstructured":"Cui, Sen, et al. Synergy-of-Experts: Collaborate to Improve Adversarial Robustness. NeurIPS, 2022."},{"key":"e_1_3_2_1_19_1","volume-title":"Morphence-2.0: Evasion-Resilient Moving Target Defense Powered by Out-of-Distribution Detection. arXiv preprint arXiv:2206.07321","author":"Amich","year":"2022","unstructured":"Amich, et al. Morphence-2.0: Evasion-Resilient Moving Target Defense Powered by Out-of-Distribution Detection. arXiv preprint arXiv:2206.07321 (2022)."},{"key":"e_1_3_2_1_20_1","volume-title":"OSDI 20","author":"Gujarati Arpan","year":"2020","unstructured":"Gujarati, Arpan, et al. Serving DNNs like clockwork: Performance predictability from the bottom up. OSDI 20, 2020."},{"key":"e_1_3_2_1_21_1","volume-title":"NeurIPS","author":"Yang Dverge","year":"2020","unstructured":"H. Yang, et al. Dverge: diversifying vulnerabilities for enhanced robust generation of ensembles. NeurIPS, 2020."},{"key":"e_1_3_2_1_22_1","volume-title":"DeepRecSys: A system for optimizing end-to-end at-scale neural recommendation inference. ISCA","author":"Gupta Udit","year":"2020","unstructured":"Gupta, Udit, et al. DeepRecSys: A system for optimizing end-to-end at-scale neural recommendation inference. ISCA, IEEE, 2020."}],"event":{"name":"DAC '24: 61st ACM\/IEEE Design Automation Conference","location":"San Francisco CA USA","acronym":"DAC '24","sponsor":["SIGDA ACM Special Interest Group on Design Automation","IEEE-CEDA","SIGBED ACM Special Interest Group on Embedded Systems"]},"container-title":["Proceedings of the 61st ACM\/IEEE Design Automation Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3649329.3654810","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3649329.3654810","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:17:48Z","timestamp":1750295868000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3649329.3654810"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,23]]},"references-count":22,"alternative-id":["10.1145\/3649329.3654810","10.1145\/3649329"],"URL":"https:\/\/doi.org\/10.1145\/3649329.3654810","relation":{},"subject":[],"published":{"date-parts":[[2024,6,23]]},"assertion":[{"value":"2024-11-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}