{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,15]],"date-time":"2025-08-15T02:33:47Z","timestamp":1755225227344,"version":"3.43.0"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","funder":[{"name":"The Institute of Information & Communications Technology Planning & Evaluation (IITP) grant funded by the Korea government (MSIT)","award":["No. 2020-0-00153"],"award-info":[{"award-number":["No. 2020-0-00153"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3710840","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:30:56Z","timestamp":1755066656000},"page":"591-604","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Evaluating Robustness of Reference-based Phishing Detectors"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-9451-1044","authenticated-orcid":false,"given":"Eunjin","family":"Roh","sequence":"first","affiliation":[{"name":"Oregon State University, Corvallis, OR, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-3352-1504","authenticated-orcid":false,"given":"Sungwoo","family":"Jeon","sequence":"additional","affiliation":[{"name":"KAIST, Daejeon, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0904-2875","authenticated-orcid":false,"given":"Sooel","family":"Son","sequence":"additional","affiliation":[{"name":"KAIST, Daejeon, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4154-7611","authenticated-orcid":false,"given":"Sanghyun","family":"Hong","sequence":"additional","affiliation":[{"name":"Oregon State University, Corvallis, OR, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417233"},{"key":"e_1_3_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSC.2011.52"},{"key":"e_1_3_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML54575.2023.00031"},{"key":"e_1_3_3_1_5_2","first-page":"274","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In Proceedings of the International Conference on Machine Learning. 274\u2013283."},{"key":"e_1_3_3_1_6_2","first-page":"2613","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Bastani Osbert","year":"2016","unstructured":"Osbert Bastani, Yani Ioannou, Leonidas Lampropoulos, Dimitrios Vytiniotis, Aditya Nori, and Antonio Criminisi. 2016. Measuring neural net robustness with constraints. In Proceedings of the Advances in Neural Information Processing Systems. 2613\u20132621."},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3373017.3373020"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179461"},{"key":"e_1_3_3_1_9_2","doi-asserted-by":"crossref","unstructured":"A.S. Bozkir and M. Aydos. 2020. LogoSENSE: A Companion HOG based Logo Detection Scheme for Phishing Web Page and E-mail Brand Recognition. Computers & Security (2020).","DOI":"10.1016\/j.cose.2020.101855"},{"key":"e_1_3_3_1_10_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Carlini Nicholas","year":"2023","unstructured":"Nicholas Carlini, Florian Tramer, Krishnamurthy\u00a0Dj Dvijotham, Leslie Rice, Mingjie Sun, and J\u00a0Zico Kolter. 2023. (Certified!!) Adversarial Robustness for Free!. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_3_1_12_2","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Cheng Shuyu","year":"2019","unstructured":"Shuyu Cheng, Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu. 2019. Improving Black-box Adversarial Attacks with a Transfer-based Prior. In Proceedings of the Advances in Neural Information Processing Systems."},{"key":"e_1_3_3_1_13_2","first-page":"1310","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. In Proceedings of the International Conference on Machine Learning. 1310\u20131320."},{"key":"e_1_3_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00175"},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"crossref","unstructured":"Anthony\u00a0Y. Fu Liu Wenyin and Xiaotie Deng. 2006. Detecting Phishing Web Pages with Visual Similarity Assessment Based on Earth Mover\u2019s Distance (EMD). IEEE Transactions on Dependable and Secure Computing 3 4 (2006) 301\u2013311.","DOI":"10.1109\/TDSC.2006.50"},{"key":"e_1_3_3_1_16_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Goodfellow Ian\u00a0J.","year":"2015","unstructured":"Ian\u00a0J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and Harnessing Adversarial Examples. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_1_17_2","volume-title":"Safe Browsing - Google Safe Browsing","author":"LLC Google","year":"1999","unstructured":"Google LLC. 1999. Safe Browsing - Google Safe Browsing. https:\/\/safebrowsing.google.com\/"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"crossref","unstructured":"Anandbabu Gopatoti Kiran\u00a0Kumar Gopathoti Sai\u00a0Prasanna Shanganthi and Chappali Nirmala. 2018. Image Denoising using spatial filters and Image Transforms: A Review. International Journal for Research in Applied Science and Engineering Technology 6 (2018) 3447\u20133452. https:\/\/api.semanticscholar.org\/CorpusID:57598681","DOI":"10.22214\/ijraset.2018.4571"},{"key":"e_1_3_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"e_1_3_3_1_20_2","unstructured":"Dan Hendrycks and Thomas Dietterich. 2019. Benchmarking Neural Network Robustness to Common Corruptions and Perturbations. Proceedings of the International Conference on Learning Representations (2019)."},{"key":"e_1_3_3_1_21_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Logan Engstrom, and Aleksander Madry. 2019. Prior Convictions: Black-box Adversarial Attacks with Bandits and Priors. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58558-7_29"},{"key":"e_1_3_3_1_23_2","unstructured":"Alexey Kurakin Ian\u00a0J. Goodfellow and Samy Bengio. 2016. Adversarial examples in the physical world. ArXiv abs\/1607.02533 (2016). https:\/\/api.semanticscholar.org\/CorpusID:1257772"},{"key":"e_1_3_3_1_24_2","series-title":"Proceedings of Machine Learning Research","first-page":"2965","volume-title":"Proceedings of the 35th International Conference on Machine Learning","volume":"80","author":"Lehtinen Jaakko","year":"2018","unstructured":"Jaakko Lehtinen, Jacob Munkberg, Jon Hasselgren, Samuli Laine, Tero Karras, Miika Aittala, and Timo Aila. 2018. Noise2Noise: Learning Image Restoration without Clean Data. In Proceedings of the 35th International Conference on Machine Learning(Proceedings of Machine Learning Research, Vol.\u00a080), Jennifer Dy and Andreas Krause (Eds.). PMLR, 2965\u20132974. https:\/\/proceedings.mlr.press\/v80\/lehtinen18a.html"},{"key":"e_1_3_3_1_25_2","first-page":"3793","volume-title":"Proceedings of the USENIX Security Symposium","author":"Lin Yun","year":"2021","unstructured":"Yun Lin, Ruofan Liu, Dinil\u00a0Mon Divakaran, Jun\u00a0Yang Ng, Qing\u00a0Zhou Chan, Yiwen Lu, Yuxuan Si, Fan Zhang, and Jin\u00a0Song Dong. 2021. Phishpedia: A Hybrid Deep Learning Based Approach to Visually Identify Phishing Webpages. In Proceedings of the USENIX Security Symposium. 3793\u20133810."},{"key":"e_1_3_3_1_26_2","first-page":"1633","volume-title":"Proceedings of the USENIX Security Symposium","author":"Liu Ruofan","year":"2022","unstructured":"Ruofan Liu, Yun Lin, Xianglin Yang, Siang\u00a0Hwee Ng, Dinil\u00a0Mon Divakaran, and Jin\u00a0Song Dong. 2022. Inferring Phishing Intention via Webpage Appearance and Dynamics: A Deep Vision Based Approach. In Proceedings of the USENIX Security Symposium. 1633\u20131650."},{"key":"e_1_3_3_1_27_2","first-page":"4139","volume-title":"Proceedings of the USENIX Security Symposium","author":"Liu Ruofan","year":"2023","unstructured":"Ruofan Liu, Yun Lin, Yifan Zhang, Penn\u00a0Han Lee, and Jin\u00a0Song Dong. 2023. Knowledge Expansion and Counterfactual Interaction for Reference-Based Phishing Detection. In Proceedings of the USENIX Security Symposium. 4139\u20134156."},{"key":"e_1_3_3_1_28_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00049"},{"key":"e_1_3_3_1_31_2","first-page":"361","volume-title":"Proceedings of the USENIX Security Symposium","author":"Oest Adam","year":"2020","unstructured":"Adam Oest, Penghui Zhang, Brad Wardman, Eric Nunes, Jakub Burgis, Ali Zand, Kurt Thomas, Adam Doup\u00e9, and Gail-Joon Ahn. 2020. Sunrise to Sunset: Analyzing the End-to-end Life Cycle and Effectiveness of Phishing Attacks at Scale. In Proceedings of the USENIX Security Symposium. 361\u2013377."},{"key":"e_1_3_3_1_32_2","doi-asserted-by":"crossref","unstructured":"Aaditya\u00a0(Adi) Prakash Nick Moran Solomon Garber Antonella DiLillo and James\u00a0A. Storer. 2018. Deflecting Adversarial Attacks with Pixel Deflection. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2018) 8571\u20138580. https:\/\/api.semanticscholar.org\/CorpusID:4528012","DOI":"10.1109\/CVPR.2018.00894"},{"key":"e_1_3_3_1_33_2","first-page":"91","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Ren Shaoqing","year":"2015","unstructured":"Shaoqing Ren, Kaiming He, Ross\u00a0B. Girshick, and Jian Sun. 2015. Faster R-CNN: Towards Real-Time Object Detection with Region Proposal Networks. In Proceedings of the Advances in Neural Information Processing Systems. 91\u201399."},{"key":"e_1_3_3_1_34_2","doi-asserted-by":"publisher","unstructured":"Baoguang Shi Mingkun Yang Xinggang Wang Pengyuan Lyu Cong Yao and Xiang Bai. 2019. ASTER: An Attentional Scene Text Recognizer with Flexible Rectification. IEEE Transactions on Pattern Analysis and Machine Intelligence 41 9 (2019) 2035\u20132048. 10.1109\/TPAMI.2018.2848939","DOI":"10.1109\/TPAMI.2018.2848939"},{"key":"e_1_3_3_1_35_2","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Sitawarin Chawin","year":"2023","unstructured":"Chawin Sitawarin, Florian Tram\u00e8r, and Nicholas Carlini. 2023. Preprocessors Matter! Realistic Decision-Based Attacks on Machine Learning Systems. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_3_1_36_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian\u00a0J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-98785-5_1"},{"key":"e_1_3_3_1_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"e_1_3_3_1_39_2","volume-title":"Thirty-seventh Conference on Neural Information Processing Systems","author":"Xie Yutong","year":"2023","unstructured":"Yutong Xie, Mingze Yuan, Bin Dong, and Quanzheng Li. 2023. Unsupervised Image Denoising with Score Function. In Thirty-seventh Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=d6LShzSTOP"},{"key":"e_1_3_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"e_1_3_3_1_41_2","doi-asserted-by":"publisher","unstructured":"Kai Zhang Wangmeng Zuo Yunjin Chen Deyu Meng and Lei Zhang. 2017. Beyond a Gaussian Denoiser: Residual Learning of Deep CNN for Image Denoising. IEEE Transactions on Image Processing 26 7 (2017) 3142\u20133155. 10.1109\/TIP.2017.2662206","DOI":"10.1109\/TIP.2017.2662206"},{"key":"e_1_3_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00021"},{"key":"e_1_3_3_1_43_2","first-page":"3165","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security","author":"Zhang Penghui","year":"2022","unstructured":"Penghui Zhang, Zhibo Sun, Sukwha Kyung, Hans\u00a0Walter Behrens, Zion\u00a0Leonahenahe Basque, Haehyun Cho, Adam Oest, Ruoyu Wang, Tiffany Bao, Yan Shoshitaishvili, Gail-Joon Ahn, and Adam Doup\u00e9. 2022. I\u2019m SPARTACUS, No, I\u2019m SPARTACUS: Proactively Protecting Users from Phishing by Intentionally Triggering Cloaking Behavior. In Proceedings of the ACM Conference on Computer and Communications Security. 3165\u20133179."}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3710840","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:28:08Z","timestamp":1755070088000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3710840"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":42,"alternative-id":["10.1145\/3708821.3710840","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3710840","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}