{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T10:52:56Z","timestamp":1781952776099,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":22,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6,22]]},"DOI":"10.1145\/3765611.3815137","type":"proceedings-article","created":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T09:39:33Z","timestamp":1781948373000},"page":"25-30","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["FlowGuard: Flow Matching for Identity-Independent Detection of Data-Free Model Stealing Attacks on Energy System Intrusion Detection Systems"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-2435-9395","authenticated-orcid":false,"given":"Maxime","family":"Schwarzer","sequence":"first","affiliation":[{"name":"Karlsruhe Institute of Technology, Thales Deutschland GmbH, Karlsruhe, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7638-098X","authenticated-orcid":false,"given":"Laurin","family":"Holz","sequence":"additional","affiliation":[{"name":"CortAIx Labs, Thales Deutschland, Ditzingen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2121-0810","authenticated-orcid":false,"given":"Tobias","family":"Huerten","sequence":"additional","affiliation":[{"name":"CortAIx Labs, Thales Deutschland, Ditzingen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8149-1600","authenticated-orcid":false,"given":"Johannes","family":"Loevenich","sequence":"additional","affiliation":[{"name":"CortAIx Labs, Thales Deutschland, Ditzingen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-7696-3786","authenticated-orcid":false,"given":"Thies","family":"Moehlenhof","sequence":"additional","affiliation":[{"name":"CortAIx Labs, Thales Deutschland, Ditzingen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0114-5610","authenticated-orcid":false,"given":"Roberto","family":"Rigolin","sequence":"additional","affiliation":[{"name":"CortAIx Labs, Thales Deutschland, Ditzingen, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3572-9083","authenticated-orcid":false,"given":"Veit","family":"Hagenmeyer","sequence":"additional","affiliation":[{"name":"Karlsruhe Institute of Technology, Karlsruhe, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"e_1_3_3_1_2_2","first-page":"1309","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Chandrasekaran Varun","year":"2020","unstructured":"Varun Chandrasekaran, Kamalika Chaudhuri, Irene Giacomelli, Somesh Jha, and Songbai Yan. 2020. Exploring connections between active learning and model extraction. In 29th USENIX Security Symposium (USENIX Security 20). 1309\u20131326."},{"key":"e_1_3_3_1_3_2","unstructured":"Elias Collaert Abel Rodr\u00edguez Sander Joos Lieven Desmet and Vera Rimmer. 2025. FlowPure: Continuous Normalizing Flows for Adversarial Purification. arxiv:https:\/\/arXiv.org\/abs\/2505.13280\u00a0[cs.LG] https:\/\/arxiv.org\/abs\/2505.13280"},{"key":"e_1_3_3_1_4_2","doi-asserted-by":"publisher","unstructured":"Benedikt Heidrich Matthias Hertel Oliver Neumann Veit Hagenmeyer and Ralf Mikut. 2024. Using conditional Invertible Neural Networks to perform mid-term peak load forecasting. IET Smart Grid 7 4 (2024) 460\u2013472. arXiv:https:\/\/ietresearch.onlinelibrary.wiley.com\/doi\/pdf\/10.1049\/stg2.1216910.1049\/stg2.12169","DOI":"10.1049\/stg2.12169"},{"key":"e_1_3_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"e_1_3_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01360"},{"key":"e_1_3_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00085"},{"key":"e_1_3_3_1_8_2","doi-asserted-by":"publisher","unstructured":"Noora\u00a0Zidan Khalaf Israa\u00a0Ibraheem Al\u00a0Barazanchi Israa\u00a0Ibraheem Al\u00a0Barazanchi A.\u00a0D. Radhi Sushma Parihar Pritesh Shah and Ravi Sekhar. 2025. Development of real-time threat detection systems with AI-driven cybersecurity in critical infrastructure. Mesopotamian Journal of CyberSecurity 5 2 (Jun. 2025) 501\u2013513. 10.58496\/MJCS\/2025\/031","DOI":"10.58496\/MJCS\/2025\/031"},{"key":"e_1_3_3_1_9_2","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky Alex","year":"2009","unstructured":"Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images. Technical Report. University of Toronto."},{"key":"e_1_3_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00020"},{"key":"e_1_3_3_1_11_2","unstructured":"Yaron Lipman Ricky T.\u00a0Q. Chen Heli Ben-Hamu Maximilian Nickel and Matt Le. 2023. Flow Matching for Generative Modeling."},{"key":"e_1_3_3_1_12_2","unstructured":"Yaron Lipman Marton Havasi Peter Holderrieth Neta Shaul Matt Le Brian Karrer Ricky T.\u00a0Q. Chen David Lopez-Paz Heli Ben-Hamu and Itai Gat. 2024. Flow Matching Guide and Code. arxiv:https:\/\/arXiv.org\/abs\/2412.06264\u00a0[cs.LG] https:\/\/arxiv.org\/abs\/2412.06264"},{"key":"e_1_3_3_1_13_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i1.32041"},{"key":"e_1_3_3_1_14_2","unstructured":"Eric Nalisnick Akihiro Matsukawa Yee\u00a0Whye Teh Dilan Gorur and Balaji Lakshminarayanan. 2019. Do deep generative models know what they don\u2019t know? (2019)."},{"key":"e_1_3_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_3_1_16_2","volume-title":"ICLR","author":"Orekondy Tribhuvanesh","year":"2020","unstructured":"Tribhuvanesh Orekondy, Bernt Schiele, and Mario Fritz. 2020. Prediction Poisoning: Towards Defenses Against DNN Model Stealing Attacks. In ICLR."},{"key":"e_1_3_3_1_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"e_1_3_3_1_18_2","doi-asserted-by":"publisher","unstructured":"Jonathan Rosenthal Eric Enouen Hung\u00a0Viet Pham and Lin Tan. 2023. DisGUIDE: Disagreement-Guided Data-Free Model Extraction. Proceedings of the AAAI Conference on Artificial Intelligence 37 8 (Jun. 2023) 9614\u20139622. 10.1609\/aaai.v37i8.26150","DOI":"10.1609\/aaai.v37i8.26150"},{"key":"e_1_3_3_1_19_2","first-page":"5305","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Tang Minxue","year":"2024","unstructured":"Minxue Tang, Anna Dai, Louis DiValentin, Aolin Ding, Amin Hass, Neil\u00a0Zhenqiang Gong, Yiran Chen, and Hai\u00a0\"Helen\" Li. 2024. ModelGuard: Information-Theoretic Defense Against Model Extraction Attacks. In 33rd USENIX Security Symposium (USENIX Security 24). USENIX Association, Philadelphia, PA, 5305\u20135322. https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/tang"},{"key":"e_1_3_3_1_20_2","first-page":"601","volume-title":"Proc. USENIX Security","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael\u00a0K Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction APIs. In Proc. USENIX Security. 601\u2013618."},{"key":"e_1_3_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/3538637.3538851"},{"key":"e_1_3_3_1_22_2","doi-asserted-by":"crossref","unstructured":"Zhenyi Wang Li Shen Tongliang Liu Tiehang Duan Yanjun Zhu Donglin Zhan David Doermann and Mingchen Gao. 2023. Defending against data-free model extraction by distributionally robust defensive training. Advances in Neural Information Processing Systems 36 (2023) 624\u2013637.","DOI":"10.52202\/075280-0029"},{"key":"e_1_3_3_1_23_2","doi-asserted-by":"publisher","unstructured":"Hongwei Yao Zheng Li Haiqin Weng Feng Xue Zhan Qin and Kui Ren. 2025. FDINet: Protecting Against DNN Model Extraction Using Feature Distortion Index. IEEE Transactions on Dependable and Secure Computing 22 04 (July 2025) 3179\u20133191. 10.1109\/TDSC.2024.3520599","DOI":"10.1109\/TDSC.2024.3520599"}],"event":{"name":"ACM Sustainability Week '26: ACM Sustainability Week 2026","location":"Banff , Alberta , Canada","acronym":"ACM Sustainability Week '26","sponsor":["SIGENERGY ACM Special Interest Group on Energy Systems and Informatics"]},"container-title":["Proceedings of the 2026 ACM Sustainability Week"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3765611.3815137","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T10:44:59Z","timestamp":1781952299000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3765611.3815137"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":22,"alternative-id":["10.1145\/3765611.3815137","10.1145\/3765611"],"URL":"https:\/\/doi.org\/10.1145\/3765611.3815137","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"2026-06-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}