Fetching the paper…
Reading the bibliography…
Recent work has introduced attacks that extract the architecture information of deep neural networks (DNN), as this knowledge enhances an adversary's capability to conduct black-box attacks against the model.
The mnist database of handwritten digits
Yann LeCun · 1998
Earlier work this paper cites.
Architecting against software cache-based side-channel attacks
Jingfei Kong, Onur Aciicmez, Jean-Pierre Seifert, and Huiyang Zhou · 2013
Earlier work this paper cites.
Drebin: Effective and explainable detection of android malware in your pocket
Daniel Arp, Michael Spreitzenbarth, Malte Hubner, Hugo Gascon, Konrad Rieck, and CERT Siemens · 2014
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2014
Earlier work this paper cites.
Flush+ reload: A high resolution, low noise, l3 cache side-channel attack
Yuval Yarom and Katrina Falkner · 2014
Earlier work this paper cites.
Cross-tenant side-channel attacks in paas clouds
Yinqian Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart · 2014
Earlier work this paper cites.
Deepdriving: Learning affordance for direct perception in autonomous driving
Chenyi Chen, Ari Seff, Alain Kornhauser, and Jianxiong Xiao · 2015
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart · 2015
Earlier work this paper cites.
Last-level cache side-channel attacks are practical
Fangfei Liu, Yuval Yarom, Qian Ge, Gernot Heiser, and Ruby B Lee · 2015
Earlier work this paper cites.
Deep face recognition
Omkar M Parkhi, Andrea Vedaldi, Andrew Zisserman, et al · 2015
Earlier work this paper cites.
Going deeper with convolutions
Christian Szegedy, Wei Liu, Yangqing Jia, Pierre Sermanet, Scott Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich · 2015
Earlier work this paper cites.
Tensorflow: a system for large-scale machine learning
Martín Abadi, Paul Barham, Jianmin Chen, Zhifeng Chen, Andy Davis, Jeffrey Dean, Matthieu Devin, Sanjay Ghemawat, Geoffrey Irving, Michael Isard, et al · 2016
Earlier work this paper cites.
Deep speech 2: End-to-end speech recognition in english and mandarin
Dario Amodei, Sundaram Ananthanarayanan, Rishita Anubhai, Jingliang Bai, Eric Battenberg, Carl Case, Jared Casper, Bryan Catanzaro, Qiang Cheng, Guoliang Chen, et al · 2016
Cited alongside, same era.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Cited alongside, same era.
Adversarial machine learning at scale
Alexey Kurakin, Ian Goodfellow, and Samy Bengio · 2016
Cited alongside, same era.
Resnet in resnet: generalizing residual architectures
Sasha Targ, Diogo Almeida, and Kevin Lyman · 2016
Cited alongside, same era.
Stealing machine learning models via prediction apis
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart · 2016
Cited alongside, same era.
Nikolai Smolyanskiy, Alexey Kamenev, Jeffrey Smith, and Stan Birchfield · 2017
Later among the works it cites.
The space of transferable adversarial examples
Florian Tramèr, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel · 2017
Later among the works it cites.
Reverse engineering convolutional neural networks through side-channel information leaks
Weizhe Hua, Zhiru Zhang, and G Edward Suh · 2018
Closest in time.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Closest in time.
Understanding membership inferences on well-generalized learning models
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Mastik: A micro-architectural side-channel toolkit
Yuval Yarom · 2016
Cited alongside, same era.
A software approach to defeating side channels in last-level caches
Ziqiao Zhou, Michael K Reiter, and Yinqian Zhang · 2016
Cited alongside, same era.
Xception: Deep learning with depthwise separable convolutions
François Chollet · 2017
Cited alongside, same era.
Mobilenets: Efficient convolutional neural networks for mobile vision applications
Andrew G Howard, Menglong Zhu, Bo Chen, Dmitry Kalenichenko, Weijun Wang, Tobias Weyand, Marco Andreetto, and Hartwig Adam · 2017
Cited alongside, same era.
Densely connected convolutional networks
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Cited alongside, same era.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Cited alongside, same era.
Yunhui Long, Vincent Bindschaedler, Lei Wang, Diyue Bu, Xiaofeng Wang, Haixu Tang, Carl A Gunter, and Kai Chen · 2018
Closest in time.
Towards reverse-engineering black-box neural networks
Seong Joon Oh, Max Augustin, Bernt Schiele, and Mario Fritz · 2018
Closest in time.
When does machine learning fail? generalized transferability for evasion and poisoning attacks
Octavian Suciu, Radu Mărginean, Yiğitcan Kaya, Hal Daumé III, and Tudor Dumitraş · 2018
Closest in time.
Stealing hyperparameters in machine learning
Binghui Wang and Neil Zhenqiang Gong · 2018
Closest in time.
With great training comes great vulnerability: Practical attacks against transfer learning
Bolun Wang, Yuanshun Yao, Bimal Viswanath, Haitao Zheng, and Ben Y. Zhao · 2018
Closest in time.
I know what you see: Power side-channel attack on convolutional neural network accelerators
Lingxiao Wei, Yannan Liu, Bo Luo, Yu Li, and Qiang Xu · 2018
Closest in time.
Cache telepathy: Leveraging shared resource attacks to learn dnn architectures
Mengjia Yan, Christopher Fletcher, and Josep Torrellas · 2018
Closest in time.