{"id":"https://openalex.org/W2808195004","doi":"https://doi.org/10.1109/ijcnn.2018.8489592","title":"Copycat CNN: Stealing Knowledge by Persuading Confession with Random Non-Labeled Data","display_name":"Copycat CNN: Stealing Knowledge by Persuading Confession with Random Non-Labeled Data","publication_year":2018,"publication_date":"2018-07-01","ids":{"openalex":"https://openalex.org/W2808195004","doi":"https://doi.org/10.1109/ijcnn.2018.8489592","mag":"2808195004"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn.2018.8489592","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn.2018.8489592","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/1806.05476","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5004524457","display_name":"Jacson Rodrigues Correia-Silva","orcid":null},"institutions":[{"id":"https://openalex.org/I51235708","display_name":"Universidade Federal do Esp\u00edrito Santo","ror":"https://ror.org/05sxf4h28","country_code":"BR","type":"education","lineage":["https://openalex.org/I51235708"]}],"countries":["BR"],"is_corresponding":true,"raw_author_name":"Jacson Rodrigues Correia-Silva","raw_affiliation_strings":["Universidade Federal do Esp\u00edrito Santo, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Esp\u00edrito Santo, Brazil","institution_ids":["https://openalex.org/I51235708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5084789423","display_name":"Rodrigo F. Berriel","orcid":"https://orcid.org/0000-0002-6701-893X"},"institutions":[{"id":"https://openalex.org/I51235708","display_name":"Universidade Federal do Esp\u00edrito Santo","ror":"https://ror.org/05sxf4h28","country_code":"BR","type":"education","lineage":["https://openalex.org/I51235708"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Rodrigo F. Berriel","raw_affiliation_strings":["Universidade Federal do Esp\u00edrito Santo, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Esp\u00edrito Santo, Brazil","institution_ids":["https://openalex.org/I51235708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056260430","display_name":"Claudine Badu\u00e9","orcid":"https://orcid.org/0000-0003-1810-8581"},"institutions":[{"id":"https://openalex.org/I51235708","display_name":"Universidade Federal do Esp\u00edrito Santo","ror":"https://ror.org/05sxf4h28","country_code":"BR","type":"education","lineage":["https://openalex.org/I51235708"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Claudine Badue","raw_affiliation_strings":["Universidade Federal do Esp\u00edrito Santo, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Esp\u00edrito Santo, Brazil","institution_ids":["https://openalex.org/I51235708"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005735333","display_name":"Alberto F. De Souza","orcid":"https://orcid.org/0000-0003-1561-8447"},"institutions":[{"id":"https://openalex.org/I51235708","display_name":"Universidade Federal do Esp\u00edrito Santo","ror":"https://ror.org/05sxf4h28","country_code":"BR","type":"education","lineage":["https://openalex.org/I51235708"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Alberto F. de Souza","raw_affiliation_strings":["Universidade Federal do Esp\u00edrito Santo, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Esp\u00edrito Santo, Brazil","institution_ids":["https://openalex.org/I51235708"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5037893575","display_name":"Thiago Oliveira-Santos","orcid":"https://orcid.org/0000-0001-7607-635X"},"institutions":[{"id":"https://openalex.org/I51235708","display_name":"Universidade Federal do Esp\u00edrito Santo","ror":"https://ror.org/05sxf4h28","country_code":"BR","type":"education","lineage":["https://openalex.org/I51235708"]}],"countries":["BR"],"is_corresponding":false,"raw_author_name":"Thiago Oliveira-Santos","raw_affiliation_strings":["Universidade Federal do Esp\u00edrito Santo, Brazil"],"affiliations":[{"raw_affiliation_string":"Universidade Federal do Esp\u00edrito Santo, Brazil","institution_ids":["https://openalex.org/I51235708"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5004524457"],"corresponding_institution_ids":["https://openalex.org/I51235708"],"apc_list":null,"apc_paid":null,"fwci":9.1381,"has_fulltext":false,"cited_by_count":152,"citation_normalized_percentile":{"value":0.98209398,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9925000071525574,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9896000027656555,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/schema-crosswalk","display_name":"Schema crosswalk","score":0.9082836508750916},{"id":"https://openalex.org/keywords/copycat","display_name":"Copycat","score":0.8739991188049316},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8399314284324646},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.6800163984298706},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.5646281242370605},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5139569640159607},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.44268709421157837},{"id":"https://openalex.org/keywords/domain-knowledge","display_name":"Domain knowledge","score":0.42485934495925903},{"id":"https://openalex.org/keywords/object","display_name":"Object (grammar)","score":0.420841783285141},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4142954349517822},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.351179838180542},{"id":"https://openalex.org/keywords/pedestrian","display_name":"Pedestrian","score":0.08529043197631836}],"concepts":[{"id":"https://openalex.org/C121193887","wikidata":"https://www.wikidata.org/wiki/Q7431117","display_name":"Schema crosswalk","level":3,"score":0.9082836508750916},{"id":"https://openalex.org/C130191384","wikidata":"https://www.wikidata.org/wiki/Q2996887","display_name":"Copycat","level":2,"score":0.8739991188049316},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8399314284324646},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.6800163984298706},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.5646281242370605},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5139569640159607},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.44268709421157837},{"id":"https://openalex.org/C207685749","wikidata":"https://www.wikidata.org/wiki/Q2088941","display_name":"Domain knowledge","level":2,"score":0.42485934495925903},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.420841783285141},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4142954349517822},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.351179838180542},{"id":"https://openalex.org/C2777113093","wikidata":"https://www.wikidata.org/wiki/Q221488","display_name":"Pedestrian","level":2,"score":0.08529043197631836},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C22212356","wikidata":"https://www.wikidata.org/wiki/Q775325","display_name":"Transport engineering","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/ijcnn.2018.8489592","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn.2018.8489592","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:1806.05476","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1806.05476","pdf_url":"https://arxiv.org/pdf/1806.05476","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:1806.05476","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1806.05476","pdf_url":"https://arxiv.org/pdf/1806.05476","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.6899999976158142}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W1533861849","https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W1932198206","https://openalex.org/W1945616565","https://openalex.org/W2003238582","https://openalex.org/W2103943262","https://openalex.org/W2106115875","https://openalex.org/W2117539524","https://openalex.org/W2118858186","https://openalex.org/W2137306662","https://openalex.org/W2150283722","https://openalex.org/W2155893237","https://openalex.org/W2161634108","https://openalex.org/W2408141691","https://openalex.org/W2603766943","https://openalex.org/W2623427976","https://openalex.org/W2727957049","https://openalex.org/W2767405849","https://openalex.org/W2774018344","https://openalex.org/W2963389226","https://openalex.org/W2963626858","https://openalex.org/W2964082701","https://openalex.org/W2964318098","https://openalex.org/W3118608800","https://openalex.org/W4299518610","https://openalex.org/W6631943919","https://openalex.org/W6635552349","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6640425456","https://openalex.org/W6677919164","https://openalex.org/W6680591342","https://openalex.org/W6682132143","https://openalex.org/W6700903540","https://openalex.org/W6714069269","https://openalex.org/W6718639682","https://openalex.org/W6729756640","https://openalex.org/W6746621119","https://openalex.org/W6787972765"],"related_works":["https://openalex.org/W2613429440","https://openalex.org/W2991511628","https://openalex.org/W4226493464","https://openalex.org/W4312417841","https://openalex.org/W3193565141","https://openalex.org/W3133861977","https://openalex.org/W2951211570","https://openalex.org/W3167935049","https://openalex.org/W3103566983","https://openalex.org/W3029198973"],"abstract_inverted_index":{"In":[0,202],"the":[1,77,96,136,155,158,168,180,203,223,226,241,244,253,256],"past":[2],"few":[3],"years,":[4],"Convolutional":[5],"Neural":[6],"Networks":[7],"(CNNs)":[8],"have":[9],"been":[10],"achieving":[11],"state-of-the-art":[12],"performance":[13,178,224,254],"on":[14],"a":[15,113,151,162,199,270,276],"variety":[16],"of":[17,95,157,222,225,252,255],"problems.":[18],"Many":[19],"companies":[20],"employ":[21],"resources":[22],"and":[23,29,65,144,160,171,194,197,211,233],"money":[24],"to":[25,42,46,61,74,90,100,123,149,175,268],"generate":[26],"these":[27,105],"models":[28,228],"provide":[30],"them":[31],"as":[32,179,279],"an":[33],"API,":[34],"therefore":[35],"it":[36,122,265],"is":[37,133,139,165,266],"in":[38,76,98,102,107,188],"their":[39],"best":[40],"interest":[41],"protect":[43],"them,":[44],"i.e.,":[45],"avoid":[47],"that":[48,56,69,84,264],"someone":[49],"else":[50],"copy":[51,132,204],"them.":[52],"Recent":[53],"studies":[54],"revealed":[55],"stateof-the-art":[57],"CNNs":[58,70],"are":[59,147],"vulnerable":[60],"adversarial":[62],"examples":[63,94],"attacks,":[64,205],"this":[66,108],"weakness":[67],"indicates":[68],"do":[71,87],"not":[72,88],"need":[73,89],"operate":[75,101],"problem":[78],"domain":[79,210,231],"(PD).":[80],"Therefore,":[81],"we":[82,110],"hypothesize":[83],"they":[85],"also":[86],"be":[91,118,173],"trained":[92,166],"with":[93,141,154,167,229,281],"PD":[97,212],"order":[99],"it.":[103],"Given":[104],"facts,":[106],"paper,":[109],"investigate":[111],"if":[112],"target":[114,137,181,277],"blackbox":[115],"CNN":[116,246,272],"can":[117],"copied":[119,248],"by":[120,273],"persuading":[121],"confess":[124],"its":[125,145],"knowledge":[126,156],"through":[127],"random":[128,142,282],"non-labeled":[129,283],"data.":[130,284],"The":[131],"two-fold:":[134],"i)":[135],"network":[138,164,278],"queried":[140],"data":[143,239],"predictions":[146],"used":[148],"create":[150,269],"fake":[152,169],"dataset":[153,170],"network;":[159],"ii)":[161],"copycat":[163,216,245,271],"should":[172],"able":[174],"achieve":[176],"similar":[177],"network.":[182],"This":[183],"hypothesis":[184],"was":[185],"evaluated":[186],"locally":[187],"three":[189],"problems":[190],"(facial":[191],"expression,":[192],"object,":[193],"crosswalk":[195],"classification)":[196],"against":[198],"cloud-based":[200],"API.":[201,260],"images":[206],"from":[207,240],"both":[208],"nonproblem":[209],"were":[213],"used.":[214],"All":[215],"networks":[217],"achieved":[218],"at":[219,234,249],"least":[220,235,250],"93.7%":[221],"original":[227],"non-problem":[230],"data,":[232],"98.6%":[236],"using":[237],"additional":[238],"PD.":[242],"Additionally,":[243],"successfully":[247],"97.3%":[251],"Microsoft":[257],"Azure":[258],"Emotion":[259],"Our":[261],"results":[262],"show":[263],"possible":[267],"simply":[274],"querying":[275],"black-box":[280]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":16},{"year":2024,"cited_by_count":31},{"year":2023,"cited_by_count":28},{"year":2022,"cited_by_count":21},{"year":2021,"cited_by_count":24},{"year":2020,"cited_by_count":16},{"year":2019,"cited_by_count":13},{"year":2018,"cited_by_count":1}],"updated_date":"2026-03-27T14:29:43.386196","created_date":"2025-10-10T00:00:00"}
