{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2024,9,11]],"date-time":"2024-09-11T16:54:53Z","timestamp":1726073693866},"reference-count":23,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Fundamentals"],"published-print":{"date-parts":[[2021,1,1]]},"DOI":"10.1587\/transfun.2020cip0022","type":"journal-article","created":{"date-parts":[[2020,12,31]],"date-time":"2020-12-31T22:15:26Z","timestamp":1609452926000},"page":"143-151","source":"Crossref","is-referenced-by-count":2,"title":["Adversarial Black-Box Attacks with Timing Side-Channel Leakage"],"prefix":"10.1587","volume":"E104.A","author":[{"given":"Tsunato","family":"NAKAI","sequence":"first","affiliation":[{"name":"Mitsubishi Electric Corporation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daisuke","family":"SUZUKI","sequence":"additional","affiliation":[{"name":"Mitsubishi Electric Corporation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fumio","family":"OMATSU","sequence":"additional","affiliation":[{"name":"Mitsubishi Electric Corporation"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Takeshi","family":"FUJINO","sequence":"additional","affiliation":[{"name":"Ritsumeikan University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","doi-asserted-by":"crossref","unstructured":"[1] M. Jagielski, A. Oprea, B. Biggio, C. Liu, C. Nita-Rotaru, and B. Li, \u201cManipulating machine learning: Poisoning attacks and countermeasures for regression learning,\u201d 2018 IEEE Symposium on Security and Privacy (SP), pp.19-35, May 2018. 10.1109\/sp.2018.00057","DOI":"10.1109\/SP.2018.00057"},{"key":"2","unstructured":"[2] C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna Estrach, D. Erhan, I. Goodfellow, and R. Fergus, \u201cIntriguing properties of neural networks,\u201d 1 2014. 2nd International Conference on Learning Representations, ICLR 2014; Conference date: 14-04-2014 Through 16-04-2014."},{"key":"3","unstructured":"[3] F. Tram\u00e8r, F. Zhang, A. Juels, M.K. Reiter, and T. Ristenpart, \u201cStealing machine learning models via prediction apis,\u201d 25th USENIX Security Symposium (USENIX Security 16), pp.601-618, Austin, TX, 2016."},{"key":"4","doi-asserted-by":"crossref","unstructured":"[4] M. Fredrikson, S. Jha, and T. Ristenpart, \u201cModel inversion attacks that exploit confidence information and basic countermeasures,\u201d Proc. 22nd ACM SIGSAC Conference on Computer and Communications Security, CCS&apos;15, pp.1322-1333, New York, NY, USA, ACM, 2015. 10.1145\/2810103.2813677","DOI":"10.1145\/2810103.2813677"},{"key":"5","doi-asserted-by":"crossref","unstructured":"[5] K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, and D. Song, \u201cRobust physical-world attacks on deep learning visual classification,\u201d 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp.1625-1634, June 2018. 10.1109\/cvpr.2018.00175","DOI":"10.1109\/CVPR.2018.00175"},{"key":"6","doi-asserted-by":"crossref","unstructured":"[6] H. Yakura and J. Sakuma, \u201cRobust audio adversarial example for a physical attack,\u201d Proc. 28th International Joint Conference on Artificial Intelligence, IJCAI&apos;19, pp.5334-5341, AAAI Press, 2019. 10.24963\/ijcai.2019\/741","DOI":"10.24963\/ijcai.2019\/741"},{"key":"7","unstructured":"[7] I. Goodfellow, J. Shlens, and C. Szegedy, \u201cExplaining and harnessing adversarial examples,\u201d International Conference on Learning Representations, 2015."},{"key":"8","unstructured":"[8] N. Carlini and D.A. Wagner, \u201cTowards evaluating the robustness of neural networks,\u201d CoRR, vol.abs\/1608.04644, 2016."},{"key":"9","unstructured":"[9] N. Papernot, P.D. McDaniel, A. Sinha, and M.P. Wellman, \u201cTowards the science of security and privacy in machine learning,\u201d CoRR, vol.abs\/1611.03814, 2016."},{"key":"10","unstructured":"[10] N. Papernot, P.D. McDaniel, and I.J. Goodfellow, \u201cTransferability in machine learning: from phenomena to black-box attacks using adversarial samples,\u201d CoRR, vol.abs\/1605.07277, 2016."},{"key":"11","unstructured":"[11] M. Juuti, S. Szyller, A. Dmitrenko, S. Marchal, and N. Asokan, \u201cPRADA: Protecting against DNN model stealing attacks,\u201d CoRR, vol.abs\/1805.02628, 2018."},{"key":"12","doi-asserted-by":"crossref","unstructured":"[12] N. Narodytska and S. Kasiviswanathan, \u201cSimple black-box adversarial attacks on deep neural networks,\u201d 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), pp.1310-1318, July 2017. 10.1109\/cvprw.2017.172","DOI":"10.1109\/CVPRW.2017.172"},{"key":"13","unstructured":"[13] C. Guo, J.R. Gardner, Y. You, A.G. Wilson, and K.Q. Weinberger, \u201cSimple black-box adversarial attacks,\u201d CoRR, vol.abs\/1905.07121, 2019."},{"key":"14","unstructured":"[14] M. Alzantot, Y. Sharma, S. Chakraborty, and M.B. Srivastava, \u201cGenattack: Practical black-box attacks with gradient-free optimization,\u201d CoRR, vol.abs\/1805.11090, 2018."},{"key":"15","doi-asserted-by":"crossref","unstructured":"[15] W. Hua, Z. Zhang, and G.E. Suh, \u201cReverse engineering convolutional neural networks through side-channel information leaks,\u201d Proc. 55th Annual Design Automation Conference, DAC&apos;18, pp.4:1-4:6, New York, NY, USA, ACM, 2018. 10.1109\/dac.2018.8465773","DOI":"10.1145\/3195970.3196105"},{"key":"16","unstructured":"[16] M. Yan, C.W. Fletcher, and J. Torrellas, \u201cCache telepathy: Leveraging shared resource attacks to learn DNN architectures,\u201d CoRR, vol.abs\/1808.04761, 2018."},{"key":"17","unstructured":"[17] S. Hong, M. Davinroy, Y. Kaya, S.N. Locke, I. Rackow, K. Kulda, D. Dachman-Soled, and T. Dumitras, \u201cSecurity analysis of deep neural networks operating in the presence of cache side-channel attacks,\u201d CoRR, vol.abs\/1810.03487, 2018."},{"key":"18","unstructured":"[18] M. Alam and D. Mukhopadhyay, \u201cHow secure are deep learning algorithms from side-channel based reverse engineering?,\u201d CoRR, vol.abs\/1811.05259, 2018."},{"key":"19","unstructured":"[19] L. Batina, S. Bhasin, D. Jap, and S. Picek, \u201cCSI NN: Reverse engineering of neural network architectures through electromagnetic side channel,\u201d 28th USENIX Security Symposium (USENIX Security 19), pp.515-532, Santa Clara, CA, 2019."},{"key":"20","doi-asserted-by":"crossref","unstructured":"[20] K. Yoshida, T. Kubota, M. Shiozaki, and T. Fujino, \u201cModel-extraction attack against FPGA-DNN accelerator utilizing correlation electromagnetic analysis,\u201d 2019 IEEE 27th Annual International Symposium on Field-Programmable Custom Computing Machines (FCCM), pp.318-318, April 2019. 10.1109\/fccm.2019.00059","DOI":"10.1109\/FCCM.2019.00059"},{"key":"21","unstructured":"[21] V. Duddu, D. Samanta, D.V. Rao, and V.E. Balas, \u201cStealing neural networks via timing side channels,\u201d CoRR, vol.abs\/1812.11720, 2018."},{"key":"22","unstructured":"[22] A. Dubey, R. Cammarota, and A. Aysu, \u201cMaskedNet: The first hardware inference engine aiming power side-channel protection,\u201d arXiv e-prints, p.arXiv:1910.13063, Oct. 2019."},{"key":"23","unstructured":"[23] Y. LeCun, C. Cortes, and C.J.C. Burges, \u201cThe MNIST database of handwritten digits,\u201d 1998. http:\/\/yann.lecun.com\/exdb\/mnist"}],"container-title":["IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E104.A\/1\/E104.A_2020CIP0022\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,1,2]],"date-time":"2021-01-02T03:37:39Z","timestamp":1609558659000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transfun\/E104.A\/1\/E104.A_2020CIP0022\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,1,1]]},"references-count":23,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021]]}},"URL":"https:\/\/doi.org\/10.1587\/transfun.2020cip0022","relation":{},"ISSN":["0916-8508","1745-1337"],"issn-type":[{"value":"0916-8508","type":"print"},{"value":"1745-1337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1,1]]}}}