{"id":"https://openalex.org/W3090625831","doi":"https://doi.org/10.1109/icip40778.2020.9191063","title":"Substitute Model Generation for Black-Box Adversarial Attack Based on Knowledge Distillation","display_name":"Substitute Model Generation for Black-Box Adversarial Attack Based on Knowledge Distillation","publication_year":2020,"publication_date":"2020-09-30","ids":{"openalex":"https://openalex.org/W3090625831","doi":"https://doi.org/10.1109/icip40778.2020.9191063","mag":"3090625831"},"language":"en","primary_location":{"id":"doi:10.1109/icip40778.2020.9191063","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icip40778.2020.9191063","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE International Conference on Image Processing (ICIP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5037775888","display_name":"Weiyu Cui","orcid":null},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Weiyu Cui","raw_affiliation_strings":["School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"affiliations":[{"raw_affiliation_string":"School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101556023","display_name":"Xiaorui Li","orcid":"https://orcid.org/0000-0002-0627-3101"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaorui Li","raw_affiliation_strings":["School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"affiliations":[{"raw_affiliation_string":"School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100601287","display_name":"Jiawei Huang","orcid":"https://orcid.org/0000-0003-4839-1971"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiawei Huang","raw_affiliation_strings":["School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"affiliations":[{"raw_affiliation_string":"School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100354895","display_name":"Wenyi Wang","orcid":"https://orcid.org/0000-0003-1619-0294"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenyi Wang","raw_affiliation_strings":["School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"affiliations":[{"raw_affiliation_string":"School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100328312","display_name":"Shuai Wang","orcid":"https://orcid.org/0000-0002-7897-2024"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shuai Wang","raw_affiliation_strings":["School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"affiliations":[{"raw_affiliation_string":"School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100689468","display_name":"Jianwen Chen","orcid":"https://orcid.org/0000-0002-6436-6568"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jianwen Chen","raw_affiliation_strings":["School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China"],"affiliations":[{"raw_affiliation_string":"School of Information and Communication Engineering, University of Electronic Science and Technology of China, Chengdu, China","institution_ids":["https://openalex.org/I150229711"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5037775888"],"corresponding_institution_ids":["https://openalex.org/I150229711"],"apc_list":null,"apc_paid":null,"fwci":1.4582,"has_fulltext":false,"cited_by_count":18,"citation_normalized_percentile":{"value":0.8603426,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":93,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"648","last_page":"652"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9456999897956848,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8158297538757324},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7414245009422302},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.7405133843421936},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.720287024974823},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5907533764839172},{"id":"https://openalex.org/keywords/distillation","display_name":"Distillation","score":0.586801290512085},{"id":"https://openalex.org/keywords/white-box","display_name":"White box","score":0.5716575384140015},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5482041835784912},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5261445045471191},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4520058035850525}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8158297538757324},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7414245009422302},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.7405133843421936},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.720287024974823},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5907533764839172},{"id":"https://openalex.org/C204030448","wikidata":"https://www.wikidata.org/wiki/Q101017","display_name":"Distillation","level":2,"score":0.586801290512085},{"id":"https://openalex.org/C180932941","wikidata":"https://www.wikidata.org/wiki/Q997233","display_name":"White box","level":2,"score":0.5716575384140015},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5482041835784912},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5261445045471191},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4520058035850525},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C178790620","wikidata":"https://www.wikidata.org/wiki/Q11351","display_name":"Organic chemistry","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icip40778.2020.9191063","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icip40778.2020.9191063","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2020 IEEE International Conference on Image Processing (ICIP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":37,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1821462560","https://openalex.org/W1945616565","https://openalex.org/W2097117768","https://openalex.org/W2180612164","https://openalex.org/W2183341477","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2570685808","https://openalex.org/W2603766943","https://openalex.org/W2746600820","https://openalex.org/W2747909401","https://openalex.org/W2769312802","https://openalex.org/W2774644650","https://openalex.org/W2910426746","https://openalex.org/W2962835968","https://openalex.org/W2963207607","https://openalex.org/W2963397674","https://openalex.org/W2963446712","https://openalex.org/W2963542245","https://openalex.org/W2963723401","https://openalex.org/W2963744840","https://openalex.org/W2963857521","https://openalex.org/W2964014389","https://openalex.org/W2964016283","https://openalex.org/W2964153729","https://openalex.org/W3106412272","https://openalex.org/W3118608800","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6638523607","https://openalex.org/W6640425456","https://openalex.org/W6719080892","https://openalex.org/W6731927902","https://openalex.org/W6738693630","https://openalex.org/W6745722055"],"related_works":["https://openalex.org/W2047881532","https://openalex.org/W1984273188","https://openalex.org/W2727407240","https://openalex.org/W154189287","https://openalex.org/W3033197410","https://openalex.org/W3009622996","https://openalex.org/W2777690624","https://openalex.org/W3037859390","https://openalex.org/W2601181618","https://openalex.org/W1855700431"],"abstract_inverted_index":{"Although":[0],"deep":[1],"convolutional":[2],"neural":[3],"network":[4],"(CNN)":[5],"performs":[6],"well":[7],"in":[8],"many":[9],"computer":[10],"vision":[11],"tasks,":[12],"its":[13],"classification":[14],"mechanism":[15],"is":[16,21],"very":[17],"vulnerable":[18],"when":[19],"it":[20],"exposed":[22],"to":[23,37,58,71,93],"the":[24,39,64,103,112],"perturbation":[25],"of":[26,42,66],"adversarial":[27,76],"attacks.":[28],"In":[29],"this":[30,83],"paper,":[31],"we":[32],"proposed":[33,51],"a":[34,59],"new":[35],"algorithm":[36,52,101],"generate":[38],"substitute":[40,84,113],"model":[41,62,85,114],"black-box":[43,68,75],"CNN":[44,55,69],"models":[45,57,70],"by":[46,86,108,110],"using":[47,87],"knowledge":[48,117],"distillation.":[49,118],"The":[50,74],"distills":[53],"multiple":[54],"teacher":[56],"compact":[60],"student":[61],"as":[63],"substitution":[65],"other":[67],"be":[72,79],"attacked.":[73],"samples":[77],"can":[78],"consequently":[80],"generated":[81],"on":[82,96,116],"various":[88],"white-box":[89],"attacking":[90,104],"methods.":[91],"According":[92],"our":[94,100],"experiments":[95],"ResNet18":[97],"and":[98],"DenseNet121,":[99],"boosts":[102],"success":[105],"rate":[106],"(ASR)":[107],"20%":[109],"training":[111],"based":[115]},"counts_by_year":[{"year":2025,"cited_by_count":4},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":5},{"year":2022,"cited_by_count":4},{"year":2021,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
