{"id":"https://openalex.org/W4229449242","doi":"https://doi.org/10.24963/ijcai.2022/100","title":"Model Stealing Defense against Exploiting Information Leak through the Interpretation of Deep Neural Nets","display_name":"Model Stealing Defense against Exploiting Information Leak through the Interpretation of Deep Neural Nets","publication_year":2022,"publication_date":"2022-07-01","ids":{"openalex":"https://openalex.org/W4229449242","doi":"https://doi.org/10.24963/ijcai.2022/100"},"language":"en","primary_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/100","pdf_url":"https://www.ijcai.org/proceedings/2022/0100.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://www.ijcai.org/proceedings/2022/0100.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5082342996","display_name":"Jeonghyun Lee","orcid":"https://orcid.org/0000-0001-8460-7368"},"institutions":[{"id":"https://openalex.org/I197347611","display_name":"Korea University","ror":"https://ror.org/047dqcg40","country_code":"KR","type":"education","lineage":["https://openalex.org/I197347611"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Jeonghyun Lee","raw_affiliation_strings":["School of Cybersecurity, Korea University"],"affiliations":[{"raw_affiliation_string":"School of Cybersecurity, Korea University","institution_ids":["https://openalex.org/I197347611"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039187971","display_name":"Sungmin Han","orcid":"https://orcid.org/0000-0002-8227-9548"},"institutions":[{"id":"https://openalex.org/I197347611","display_name":"Korea University","ror":"https://ror.org/047dqcg40","country_code":"KR","type":"education","lineage":["https://openalex.org/I197347611"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Sungmin Han","raw_affiliation_strings":["School of Cybersecurity, Korea University"],"affiliations":[{"raw_affiliation_string":"School of Cybersecurity, Korea University","institution_ids":["https://openalex.org/I197347611"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5046513588","display_name":"Sangkyun Lee","orcid":"https://orcid.org/0000-0001-8415-6368"},"institutions":[{"id":"https://openalex.org/I197347611","display_name":"Korea University","ror":"https://ror.org/047dqcg40","country_code":"KR","type":"education","lineage":["https://openalex.org/I197347611"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Sangkyun Lee","raw_affiliation_strings":["School of Cybersecurity, Korea University"],"affiliations":[{"raw_affiliation_string":"School of Cybersecurity, Korea University","institution_ids":["https://openalex.org/I197347611"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.619,"has_fulltext":true,"fulltext_origin":"pdf","cited_by_count":4,"citation_normalized_percentile":{"value":0.53674,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":79,"max":82},"biblio":{"volume":null,"issue":null,"first_page":"710","last_page":"716"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.9949,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.976,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/interpretability","display_name":"Interpretability","score":0.90282166},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.41212344}],"concepts":[{"id":"https://openalex.org/C2781067378","wikidata":"https://www.wikidata.org/wiki/Q17027399","display_name":"Interpretability","level":2,"score":0.90282166},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.83714235},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.71603036},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.63305765},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.57272977},{"id":"https://openalex.org/C527412718","wikidata":"https://www.wikidata.org/wiki/Q855395","display_name":"Interpretation (philosophy)","level":2,"score":0.50191784},{"id":"https://openalex.org/C48103436","wikidata":"https://www.wikidata.org/wiki/Q599031","display_name":"State (computer science)","level":2,"score":0.44036186},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.42127094},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.41212344},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.39496213},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.1377497}],"mesh":[],"locations_count":1,"locations":[{"is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/100","pdf_url":"https://www.ijcai.org/proceedings/2022/0100.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://doi.org/10.24963/ijcai.2022/100","pdf_url":"https://www.ijcai.org/proceedings/2022/0100.pdf","source":{"id":"https://openalex.org/S4363608755","display_name":"Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true},"sustainable_development_goals":[{"display_name":"Reduced inequalities","score":0.59,"id":"https://metadata.un.org/sdg/10"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":26,"referenced_works":["https://openalex.org/W1787224781","https://openalex.org/W2295107390","https://openalex.org/W2603766943","https://openalex.org/W2605409611","https://openalex.org/W2657631929","https://openalex.org/W2765793020","https://openalex.org/W2777638777","https://openalex.org/W2903165775","https://openalex.org/W2962858109","https://openalex.org/W2962862931","https://openalex.org/W2963303354","https://openalex.org/W2963560987","https://openalex.org/W2964318098","https://openalex.org/W2969880113","https://openalex.org/W2996649838","https://openalex.org/W2997146418","https://openalex.org/W2997520586","https://openalex.org/W3035379805","https://openalex.org/W3109440167","https://openalex.org/W3130144427","https://openalex.org/W3172381285","https://openalex.org/W3174863366","https://openalex.org/W3177112732","https://openalex.org/W4249736682","https://openalex.org/W4300235091","https://openalex.org/W4403451191"],"related_works":["https://openalex.org/W4387589990","https://openalex.org/W4377704659","https://openalex.org/W4297660007","https://openalex.org/W4241566321","https://openalex.org/W3101055019","https://openalex.org/W2943982549","https://openalex.org/W2910028250","https://openalex.org/W2886918272","https://openalex.org/W2797441709","https://openalex.org/W2346578521"],"abstract_inverted_index":{"Model":[0],"stealing":[1,67,86,110,133,143],"techniques":[2],"allow":[3],"adversaries":[4],"to":[5,32,65,99],"create":[6],"attack":[7],"models":[8,62],"that":[9,54,79],"mimic":[10],"the":[11,75,101,105,117,121,141,155],"functionality":[12],"of":[13,36,104,123],"black-box":[14],"machine":[15],"learning":[16],"models,":[17,38],"querying":[18],"only":[19],"class":[20,90,118],"membership":[21],"or":[22,44],"probability":[23,119],"outcomes.":[24],"Recently,":[25],"interpretable":[26],"AI":[27,37,61,82],"is":[28,127],"getting":[29],"increasing":[30],"attention,":[31],"enhance":[33],"our":[34,146],"understanding":[35],"provide":[39],"additional":[40,57],"information":[41,58,103],"for":[42,130],"diagnoses,":[43],"satisfy":[45],"legal":[46],"requirements.":[47],"However,":[48],"it":[49,136],"has":[50],"been":[51],"recently":[52],"reported":[53],"providing":[55],"such":[56],"can":[59],"make":[60],"more":[63],"vulnerable":[64],"model":[66,83,85,98,107,109,132,142],"attacks.":[68],"In":[69,145],"this":[70],"paper,":[71],"we":[72],"propose":[73],"DeepDefense,":[74],"first":[76],"defense":[77,152],"mechanism":[78],"protects":[80],"an":[81],"against":[84,108],"attackers":[87],"exploiting":[88],"both":[89,116],"probabilities":[91],"and":[92,120,162],"interpretations.":[93],"DeepDefense":[94,126,148],"uses":[95],"a":[96],"misdirection":[97],"hide":[100],"critical":[102],"original":[106],"attacks,":[111],"with":[112],"minimal":[113,138],"degradation":[114],"on":[115,159],"interpretability":[122],"prediction":[124],"output.":[125],"highly":[128],"applicable":[129],"any":[131],"scenario":[134],"since":[135],"makes":[137],"assumptions":[139],"about":[140],"adversary.":[144],"experiments,":[147],"shows":[149],"significantly":[150],"higher":[151],"performance":[153],"than":[154],"existing":[156],"state-of-the-art":[157],"defenses":[158],"various":[160],"datasets":[161],"interpreters.":[163]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4229449242","counts_by_year":[{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":1}],"updated_date":"2025-01-22T03:52:07.810039","created_date":"2022-05-11"}