{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,18]],"date-time":"2026-06-18T15:42:34Z","timestamp":1781797354360,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":81,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Key R\\&D Program of China","award":["2020AAA0107701"],"award-info":[{"award-number":["2020AAA0107701"]}]},{"name":"NSFC","award":["U20B2049 and U21B2018."],"award-info":[{"award-number":["U20B2049 and U21B2018."]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3670267","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"3838-3852","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Beowulf: Mitigating Model Extraction Attacks Via Reshaping Decision Regions"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2190-8117","authenticated-orcid":false,"given":"Xueluan","family":"Gong","sequence":"first","affiliation":[{"name":"School of Computer Science, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-7998-7273","authenticated-orcid":false,"given":"Rubin","family":"Wei","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1394-9587","authenticated-orcid":false,"given":"Ziyao","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-8528-4510","authenticated-orcid":false,"given":"Yuchen","family":"Sun","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-9110-8338","authenticated-orcid":false,"given":"Jiawen","family":"Peng","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1382-0679","authenticated-orcid":false,"given":"Yanjiao","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Electrical Engineering, Zhejiang University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8967-8525","authenticated-orcid":false,"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2019.04.021"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_1_3_1","volume-title":"FrugalGPT: How to use large language models while reducing cost and improving performance. arXiv preprint arXiv:2305.05176","author":"Chen Lingjiao","year":"2023","unstructured":"Lingjiao Chen, Matei Zaharia, and James Zou. 2023. FrugalGPT: How to use large language models while reducing cost and improving performance. arXiv preprint arXiv:2305.05176 (2023)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179406"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2017.7966217"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2018.8489592"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1060745.1060764"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00396"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/336"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2000196"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"e_1_3_2_1_14_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_15_1","volume-title":"Sparse dnns with improved adversarial robustness. Advances in Neural Information Processing Systems 31","author":"Guo Yiwen","year":"2018","unstructured":"Yiwen Guo, Chao Zhang, Changshui Zhang, and Yurong Chen. 2018. Sparse dnns with improved adversarial robustness. Advances in Neural Information Processing Systems 31 (2018)."},{"key":"e_1_3_2_1_16_1","volume-title":"FMix: Enhancing mixed sample data augmentation. arXiv preprint arXiv:2002.12047","author":"Harris Ethan","year":"2020","unstructured":"Ethan Harris, Antonia Marcu, Matthew Painter, Mahesan Niranjan, Adam Pr\u00fcgel-Bennett, and Jonathon Hare. 2020. FMix: Enhancing mixed sample data augmentation. arXiv preprint arXiv:2002.12047 (2020)."},{"key":"e_1_3_2_1_17_1","volume-title":"Model extraction and adversarial transferability, your BERT is vulnerable! arXiv preprint arXiv:2103.10013","author":"He Xuanli","year":"2021","unstructured":"Xuanli He, Lingjuan Lyu, Qiongkai Xu, and Lichao Sun. 2021. Model extraction and adversarial transferability, your BERT is vulnerable! arXiv preprint arXiv:2103.10013 (2021)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2007.366913"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2736277.2741141"},{"key":"e_1_3_2_1_20_1","volume-title":"Imagenette: A smaller subset of 10 easily classified classes from Imagenet.","author":"Howard Jeremy","year":"2019","unstructured":"Jeremy Howard. 2019. Imagenette: A smaller subset of 10 easily classified classes from Imagenet. (2019)."},{"key":"e_1_3_2_1_21_1","volume-title":"Model extraction attack against self-supervised speech models. arXiv preprint arXiv:2211.16044","author":"Hsu Tsu-Yuan","year":"2022","unstructured":"Tsu-Yuan Hsu, Chen-An Li, Tung-Yu Wu, and Hung-yi Lee. 2022. Model extraction attack against self-supervised speech models. arXiv preprint arXiv:2211.16044 (2022)."},{"key":"e_1_3_2_1_22_1","volume-title":"Densenet: Implementing efficient convnet descriptor pyramids. arXiv preprint arXiv:1404.1869","author":"Iandola Forrest","year":"2014","unstructured":"Forrest Iandola, Matt Moskewicz, Sergey Karayev, Ross Girshick, Trevor Darrell, and Kurt Keutzer. 2014. Densenet: Implementing efficient convnet descriptor pyramids. arXiv preprint arXiv:1404.1869 (2014)."},{"key":"e_1_3_2_1_23_1","volume-title":"USENIX Security Symposium. 1937--1954","author":"Jia Hengrui","year":"2021","unstructured":"Hengrui Jia, Christopher A Choquette-Choo, Varun Chandrasekaran, and Nicolas Papernot. 2021. Entangled watermarks as a defense against model extraction. In USENIX Security Symposium. 1937--1954."},{"key":"e_1_3_2_1_24_1","volume-title":"A comprehensive defense framework against model extraction attacks","author":"Jiang Wenbo","year":"2023","unstructured":"Wenbo Jiang, Hongwei Li, Guowen Xu, Tianwei Zhang, and Rongxing Lu. 2023. A comprehensive defense framework against model extraction attacks. IEEE Transactions on Dependable and Secure Computing (2023)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"e_1_3_2_1_26_1","volume-title":"International Conference on Learning Representations.","author":"Kariyappa Sanjay","year":"2020","unstructured":"Sanjay Kariyappa, Atul Prakash, and Moinuddin K Qureshi. 2020. Protecting DNNs from theft using an ensemble of diverse models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"e_1_3_2_1_29_1","volume-title":"Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer.","author":"Krishna Kalpesh","year":"2019","unstructured":"Kalpesh Krishna, Gaurav Singh Tomar, Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer. 2019. Thieves on sesame street! model extraction of bert-based apis. arXiv preprint arXiv:1910.12366 (2019)."},{"key":"e_1_3_2_1_30_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_31_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Kurakin Alexey","year":"2017","unstructured":"Alexey Kurakin, Ian J Goodfellow, and Samy Bengio. 2017. Adversarial examples in the physical world. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_32_1","unstructured":"Yann LeCun Corinna Cortes and Chris Burges. 2010. MNIST handwritten digit database. (2010)."},{"key":"e_1_3_2_1_33_1","volume-title":"IEEE Security and Privacy Workshops.","author":"Lee Taesung","year":"2019","unstructured":"Taesung Lee, Benjamin Edwards, Ian Molloy, and Dong Su. 2019. Defending against machine learning model stealing attacks using deceptive perturbations. In IEEE Security and Privacy Workshops."},{"key":"e_1_3_2_1_34_1","volume-title":"OpenAI's GPT-3 language model: A technical overview. Blog Post","author":"Chuan Li.","year":"2020","unstructured":"Chuan Li. 2020. OpenAI's GPT-3 language model: A technical overview. Blog Post (2020)."},{"key":"e_1_3_2_1_35_1","volume-title":"Advances in Neural Information Processing Systems","volume":"31","author":"Li Hao","year":"2018","unstructured":"Hao Li, Zheng Xu, Gavin Taylor, Christoph Studer, and Tom Goldstein. 2018. Visualizing the loss landscape of neural nets. In Advances in Neural Information Processing Systems, Vol. 31."},{"key":"e_1_3_2_1_36_1","volume-title":"MEAOD: Model extraction attack against object detectors. arXiv preprint arXiv:2312.14677","author":"Li Zeyu","year":"2023","unstructured":"Zeyu Li, Chenghui Shi, Yuwen Pu, Xuhong Zhang, Yu Li, Jinbao Li, and Shouling Ji. 2023. MEAOD: Model extraction attack against object detectors. arXiv preprint arXiv:2312.14677 (2023)."},{"key":"e_1_3_2_1_37_1","volume-title":"On the feasibility of specialized ability stealing for large language code models. arXiv preprint arXiv:2303.03012","author":"Li Zongjie","year":"2023","unstructured":"Zongjie Li, Chaozheng Wang, Pingchuan Ma, Chaowei Liu, Shuai Wang, Daoyuan Wu, and Cuiyun Gao. 2023. On the feasibility of specialized ability stealing for large language code models. arXiv preprint arXiv:2303.03012 (2023)."},{"key":"e_1_3_2_1_38_1","first-page":"21464","article-title":"Energy-based out-of-distribution detection","volume":"33","author":"Liu Weitang","year":"2020","unstructured":"Weitang Liu, Xiaoyun Wang, John Owens, and Yixuan Li. 2020. Energy-based out-of-distribution detection. Advances in Neural Information Processing Systems 33 (2020), 21464--21475.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475290"},{"key":"e_1_3_2_1_40_1","volume-title":"International Conference on Learning Representations.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. International Conference on Learning Representations."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3616652"},{"key":"e_1_3_2_1_42_1","first-page":"39","article-title":"Evaluation of classification models in machine learning","volume":"7","author":"Novakovic Jasmina Dj","year":"2017","unstructured":"Jasmina Dj Novakovic, Alempije Veljovic, Sinisa S Ilic, Zeljko Papic, and Milica Tomovic. 2017. Evaluation of classification models in machine learning. Theory and Applications of Mathematics & Computer Science 7, 1 (2017), 39.","journal-title":"Theory and Applications of Mathematics & Computer Science"},{"key":"e_1_3_2_1_43_1","first-page":"75","article-title":"Deep learning models based on image classification: A review","volume":"4","author":"Obaid Kavi B","year":"2020","unstructured":"Kavi B Obaid, Subhi Zeebaree, Omar M Ahmed, et al . 2020. Deep learning models based on image classification: A review. International Journal of Science and Business 4, 11 (2020), 75--81.","journal-title":"International Journal of Science and Business"},{"key":"e_1_3_2_1_44_1","volume-title":"I know what you trained last summer: A survey on stealing machine learning models and defences. Comput. Surveys","author":"Oliynyk Daryna","year":"2023","unstructured":"Daryna Oliynyk, Rudolf Mayer, and Andreas Rauber. 2023. I know what you trained last summer: A survey on stealing machine learning models and defences. Comput. Surveys (2023)."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_2_1_46_1","volume-title":"International Conference on Learning Representations.","author":"Orekondy Tribhuvanesh","year":"2020","unstructured":"Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2020. Prediction poisoning: Towards defenses against DNN model stealing attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i01.5432"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_2_1_49_1","volume-title":"Fencebox: A platform for defeating adversarial examples with data augmentation techniques. arXiv preprint arXiv:2012.01701","author":"Qiu Han","year":"2020","unstructured":"Han Qiu, Yi Zeng, Tianwei Zhang, Yong Jiang, and Meikang Qiu. 2020. Fencebox: A platform for defeating adversarial examples with data augmentation techniques. arXiv preprint arXiv:2012.01701 (2020)."},{"key":"e_1_3_2_1_50_1","volume-title":"International Conference on Smart Systems and Inventive Technology. IEEE, 729--735","author":"Ganapathi Raju VN","year":"2020","unstructured":"VN Ganapathi Raju, K Prasanna Lakshmi, Vinod Mahesh Jain, Archana Kalidindi, and V Padma. 2020. Study the influence of normalization\/transformation process on the accuracy of supervised classification. In International Conference on Smart Systems and Inventive Technology. IEEE, 729--735."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2015.152"},{"key":"e_1_3_2_1_52_1","volume-title":"International Conference on Learning Representations.","author":"Sabour Sara","year":"2016","unstructured":"Sara Sabour, Yanshuai Cao, Fartash Faghri, and David J Fleet. 2016. Adversarial manipulation of deep representations. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCIS.2007.4456849"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01485"},{"key":"e_1_3_2_1_55_1","volume-title":"AAAI Spring Symposium: Computational Approaches to Analyzing Weblogs","volume":"6","author":"Schler Jonathan","year":"2006","unstructured":"Jonathan Schler, Moshe Koppel, Shlomo Argamon, and James W Pennebaker. 2006. Effects of age and gender on blogging.. In AAAI Spring Symposium: Computational Approaches to Analyzing Weblogs, Vol. 6. 199--205."},{"key":"e_1_3_2_1_56_1","volume-title":"International Conference on Learning Representations. OpenReview.net.","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. In International Conference on Learning Representations. OpenReview.net."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01333"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"e_1_3_2_1_59_1","volume-title":"et al","author":"Sutton Richard S","year":"1998","unstructured":"Richard S Sutton, Andrew G Barto, et al . 1998. Introduction to reinforcement learning. Vol. 135. MIT press Cambridge."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475591"},{"key":"e_1_3_2_1_61_1","volume-title":"USENIX Security Symposium.","author":"Tang Minxue","year":"2024","unstructured":"Minxue Tang, Anna Dai, Louis DiValentin, Aolin Ding, Amin Hass, Neil Zhenqiang Gong, and Yiran Chen. 2024. MODELGUARD: Information-theoretic defense against model extraction attacks. In USENIX Security Symposium."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833688"},{"key":"e_1_3_2_1_63_1","volume-title":"USENIX Security Symposium. 601--618","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction APIs. In USENIX Security Symposium. 601--618."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00474"},{"key":"e_1_3_2_1_65_1","volume-title":"International Conference on Learning Representations.","author":"Uddin AFM","year":"2021","unstructured":"AFM Uddin, Mst Monira, Wheemyung Shin, TaeChoong Chung, Sung-Ho Bae, et al. 2021. Saliencymix: A saliency guided data augmentation strategy for better regularization. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_66_1","unstructured":"Jonathan Vanian. 2023. ChatGPT and generative AI are booming but the costs can be extraordinary. (2023)."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2015.2426703"},{"key":"e_1_3_2_1_68_1","volume-title":"USENIX Symposium on Networked Systems Design and Implementation. 945--960","author":"Weng Qizhen","year":"2022","unstructured":"Qizhen Weng, Wencong Xiao, Yinghao Yu, Wei Wang, Cheng Wang, Jian He, Yong Li, Liping Zhang, Wei Lin, and Yu Ding. 2022. MLaaS in the wild: Workload analysis and scheduling in large-scale heterogeneous GPU clusters. In USENIX Symposium on Networked Systems Design and Implementation. 945--960."},{"key":"e_1_3_2_1_69_1","volume-title":"USENIX Security Symposium.","author":"Xiang Chong","year":"2021","unstructured":"Chong Xiang, Arjun Nitin Bhagoji, Vikash Sehwag, and Prateek Mittal. 2021. Patchguard: A provably robust defense against adversarial patches via small receptive fields and masking. In USENIX Security Symposium."},{"key":"e_1_3_2_1_70_1","volume-title":"Monitoring-based differential privacy mechanism against query flooding-based model extraction attack","author":"Yan Haonan","year":"2021","unstructured":"Haonan Yan, Xiaoguang Li, Hui Li, Jiamin Li, Wenhai Sun, and Fenghua Li. 2021. Monitoring-based differential privacy mechanism against query flooding-based model extraction attack. IEEE Transactions on Dependable and Secure Computing (2021)."},{"key":"e_1_3_2_1_71_1","unstructured":"Yaoqing Yang Rajiv Khanna Yaodong Yu Amir Gholami Kurt Keutzer Joseph E Gonzalez Kannan Ramchandran and Michael W Mahoney. 2020. Boundary thickness and robustness in learning models. In Advances in Neural Information Processing Systems. 6223--6234."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24178"},{"key":"e_1_3_2_1_73_1","volume-title":"International Conference on Machine Learning. 856--863","author":"Yu Lei","year":"2003","unstructured":"Lei Yu and Huan Liu. 2003. Feature selection for high-dimensional data: A fast correlation-based filter solution. In International Conference on Machine Learning. 856--863."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00612"},{"key":"e_1_3_2_1_75_1","volume-title":"Wide residual networks. arXiv preprint arXiv:1605.07146","author":"Zagoruyko Sergey","year":"2016","unstructured":"Sergey Zagoruyko and Nikos Komodakis. 2016. Wide residual networks. arXiv preprint arXiv:1605.07146 (2016)."},{"key":"e_1_3_2_1_76_1","volume-title":"International Conference on Learning Representations. 1--13","author":"Zhang H","year":"2018","unstructured":"H Zhang, M Cisse, Y Dauphin, and D Lopez-Paz. 2018. mixup: Beyond empirical risk management. In International Conference on Learning Representations. 1--13."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3246766"},{"key":"e_1_3_2_1_78_1","volume-title":"Character-level convolutional networks for text classification. Advances in Neural Information Processing Systems 28","author":"Zhang Xiang","year":"2015","unstructured":"Xiang Zhang, Junbo Zhao, and Yann LeCun. 2015. Character-level convolutional networks for text classification. Advances in Neural Information Processing Systems 28 (2015)."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-29959-0_4"},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59013-0_8"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01228-1_9"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670267","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3670267","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:12:00Z","timestamp":1755843120000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3670267"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":81,"alternative-id":["10.1145\/3658644.3670267","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3670267","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}