{"id":"https://openalex.org/W4416798821","doi":"https://doi.org/10.1109/apsipaasc65261.2025.11249122","title":"Model Extraction Attack and Its Countermeasure for Denoising Diffusion Implicit Models","display_name":"Model Extraction Attack and Its Countermeasure for Denoising Diffusion Implicit Models","publication_year":2025,"publication_date":"2025-10-22","ids":{"openalex":"https://openalex.org/W4416798821","doi":"https://doi.org/10.1109/apsipaasc65261.2025.11249122"},"language":null,"primary_location":{"id":"doi:10.1109/apsipaasc65261.2025.11249122","is_oa":false,"landing_page_url":"https://doi.org/10.1109/apsipaasc65261.2025.11249122","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5111526309","display_name":"H. Shoji","orcid":null},"institutions":[{"id":"https://openalex.org/I161296585","display_name":"Tokyo University of Science","ror":"https://ror.org/05sj3n476","country_code":"JP","type":"education","lineage":["https://openalex.org/I161296585"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Hayato Shoji","raw_affiliation_strings":["Tokyo University of Science,Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tokyo University of Science,Japan","institution_ids":["https://openalex.org/I161296585"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5058191809","display_name":"Kazuaki Nakamura","orcid":"https://orcid.org/0000-0002-4859-4624"},"institutions":[{"id":"https://openalex.org/I161296585","display_name":"Tokyo University of Science","ror":"https://ror.org/05sj3n476","country_code":"JP","type":"education","lineage":["https://openalex.org/I161296585"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Kazuaki Nakamura","raw_affiliation_strings":["Tokyo University of Science,Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tokyo University of Science,Japan","institution_ids":["https://openalex.org/I161296585"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.17635128,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"2181","last_page":"2186"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.929099977016449,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.929099977016449,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.016899999231100082,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.004800000227987766,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/property","display_name":"Property (philosophy)","score":0.6949999928474426},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.6098999977111816},{"id":"https://openalex.org/keywords/countermeasure","display_name":"Countermeasure","score":0.6026999950408936},{"id":"https://openalex.org/keywords/clone","display_name":"clone (Java method)","score":0.5788999795913696},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.4081999957561493}],"concepts":[{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.6949999928474426},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6743999719619751},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6236000061035156},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.6098999977111816},{"id":"https://openalex.org/C21593369","wikidata":"https://www.wikidata.org/wiki/Q1032176","display_name":"Countermeasure","level":2,"score":0.6026999950408936},{"id":"https://openalex.org/C81089528","wikidata":"https://www.wikidata.org/wiki/Q5134986","display_name":"clone (Java method)","level":3,"score":0.5788999795913696},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.4431999921798706},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.42719998955726624},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.42570000886917114},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.4081999957561493},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.36230000853538513},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.3621000051498413},{"id":"https://openalex.org/C163294075","wikidata":"https://www.wikidata.org/wiki/Q581861","display_name":"Noise reduction","level":2,"score":0.34769999980926514},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.3012999892234802}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/apsipaasc65261.2025.11249122","is_oa":false,"landing_page_url":"https://doi.org/10.1109/apsipaasc65261.2025.11249122","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 Asia Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":6,"referenced_works":["https://openalex.org/W2623427976","https://openalex.org/W2768064608","https://openalex.org/W2963844355","https://openalex.org/W4200025412","https://openalex.org/W4211179786","https://openalex.org/W4387967949"],"related_works":[],"abstract_inverted_index":{"Recently,":[0],"the":[1,22,36,40,60,70,91,99,122,139,150,158,171,183,196,209],"threat":[2],"of":[3,24,62,76,93,98,119,130,142,152,185,211],"cyber":[4],"attacks":[5],"against":[6],"machine":[7],"learning":[8],"models":[9,118,205],"has":[10,34,42],"been":[11],"increasing.":[12],"Typical":[13],"examples":[14],"include":[15],"Model":[16],"Extraction":[17],"Attack":[18],"(MEA),":[19],"which":[20],"steals":[21],"functionality":[23],"a":[25,108,112,127,143,165,177],"victim":[26,144,159,212],"model":[27,32],"by":[28,82,170],"creating":[29],"its":[30,46],"clone":[31,117,172,204],"that":[33,115],"almost":[35],"same":[37],"functionality.":[38],"Thus,":[39],"literature":[41],"studied":[43],"MEA":[44,63,94],"and":[45,73,167,192],"defense":[47,113,198],"methods,":[48],"mainly":[49],"focusing":[50],"on":[51,64,95,189],"image":[52,66,77,103,194],"recognition":[53],"models.":[54,84,105,214],"However,":[55],"no":[56],"existing":[57],"studies":[58],"evaluate":[59],"risk":[61],"diffusion-based":[65,102],"generation":[67,78,104],"models,":[68,173],"despite":[69],"recent":[71],"advances":[72],"widespread":[74],"use":[75],"AI":[79],"services":[80],"powered":[81],"diffusion":[83],"In":[85,121,182],"this":[86],"paper,":[87],"we":[88,110,125],"first":[89],"demonstrate":[90],"feasibility":[92],"DDIM,":[96],"one":[97],"most":[100],"common":[101],"Then,":[106],"as":[107,135,164,176],"countermeasure,":[109],"propose":[111],"method":[114,199],"detects":[116],"DDIM.":[120],"proposed":[123,197],"method,":[124],"add":[126],"small":[128],"number":[129],"out-of-distribution":[131],"images,":[132],"referred":[133],"to":[134,138],"\u201cmarking":[136],"images\u201d,":[137],"training":[140],"dataset":[141],"DDIM":[145,213],"model.":[146,160],"This":[147,161],"technique":[148],"provides":[149],"property":[151,162],"occasionally":[153],"generating":[154],"marking":[155],"images":[156],"for":[157,179],"works":[163],"watermark":[166],"is":[168],"inherited":[169],"being":[174],"used":[175],"clue":[178],"detecting":[180],"them.":[181],"results":[184],"our":[186],"experiments":[187],"conducted":[188],"face,":[190],"fruit,":[191],"church":[193],"datasets,":[195],"can":[200],"correctly":[201],"detect":[202],"all":[203],"without":[206],"seriously":[207],"degrading":[208],"usability":[210]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-11-28T00:00:00"}
