{"id":"https://openalex.org/W4206159279","doi":"https://doi.org/10.1109/milcom52596.2021.9652915","title":"Toward Effective Moving Target Defense Against Adversarial AI","display_name":"Toward Effective Moving Target Defense Against Adversarial AI","publication_year":2021,"publication_date":"2021-11-29","ids":{"openalex":"https://openalex.org/W4206159279","doi":"https://doi.org/10.1109/milcom52596.2021.9652915"},"language":"en","primary_location":{"id":"doi:10.1109/milcom52596.2021.9652915","is_oa":false,"landing_page_url":"https://doi.org/10.1109/milcom52596.2021.9652915","pdf_url":null,"source":{"id":"https://openalex.org/S4363608138","display_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5052289707","display_name":"Peter Martin","orcid":null},"institutions":[{"id":"https://openalex.org/I207766952","display_name":"CACI International (United States)","ror":"https://ror.org/00ghhyx51","country_code":"US","type":"company","lineage":["https://openalex.org/I207766952"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Peter Martin","raw_affiliation_strings":["CACI International, Sterling, Virginia, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"CACI International, Sterling, Virginia, USA","institution_ids":["https://openalex.org/I207766952"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113562773","display_name":"Jian Ying Fan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jian Fan","raw_affiliation_strings":["CACI International, Florham Park, New Jersey, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"CACI International, Florham Park, New Jersey, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069017416","display_name":"Taejin Kim","orcid":"https://orcid.org/0000-0003-2944-3692"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Taejin Kim","raw_affiliation_strings":["CACI International, Florham Park, New Jersey, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"CACI International, Florham Park, New Jersey, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5046227701","display_name":"Konrad Vesey","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Konrad Vesey","raw_affiliation_strings":["CACI International, Florham Park, New Jersey, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"CACI International, Florham Park, New Jersey, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5030851488","display_name":"Lloyd Greenwald","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lloyd Greenwald","raw_affiliation_strings":["CACI International, Florham Park, New Jersey, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"CACI International, Florham Park, New Jersey, USA","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5052289707"],"corresponding_institution_ids":["https://openalex.org/I207766952"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.19574861,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"993","last_page":"998"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.944599986076355,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9247999787330627,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8710411190986633},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.709234893321991},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.660292387008667},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5897232890129089},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.5574455857276917},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4583650529384613},{"id":"https://openalex.org/keywords/object","display_name":"Object (grammar)","score":0.42691296339035034},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.17882323265075684}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8710411190986633},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.709234893321991},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.660292387008667},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5897232890129089},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.5574455857276917},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4583650529384613},{"id":"https://openalex.org/C2781238097","wikidata":"https://www.wikidata.org/wiki/Q175026","display_name":"Object (grammar)","level":2,"score":0.42691296339035034},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.17882323265075684}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/milcom52596.2021.9652915","is_oa":false,"landing_page_url":"https://doi.org/10.1109/milcom52596.2021.9652915","pdf_url":null,"source":{"id":"https://openalex.org/S4363608138","display_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.5099999904632568,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":52,"referenced_works":["https://openalex.org/W1522301498","https://openalex.org/W1945616565","https://openalex.org/W2108598243","https://openalex.org/W2112796928","https://openalex.org/W2194775991","https://openalex.org/W2570685808","https://openalex.org/W2592962403","https://openalex.org/W2603766943","https://openalex.org/W2736899637","https://openalex.org/W2785557471","https://openalex.org/W2895097814","https://openalex.org/W2912070915","https://openalex.org/W2913318911","https://openalex.org/W2942810103","https://openalex.org/W2950782995","https://openalex.org/W2963001136","https://openalex.org/W2963070423","https://openalex.org/W2963299894","https://openalex.org/W2963857521","https://openalex.org/W2981030558","https://openalex.org/W2986517689","https://openalex.org/W2988796733","https://openalex.org/W3011975373","https://openalex.org/W3013219028","https://openalex.org/W3089683609","https://openalex.org/W3103340107","https://openalex.org/W3118608800","https://openalex.org/W3134756668","https://openalex.org/W4288346627","https://openalex.org/W4293350742","https://openalex.org/W4293846201","https://openalex.org/W4300725094","https://openalex.org/W6631190155","https://openalex.org/W6640425456","https://openalex.org/W6687483927","https://openalex.org/W6725195833","https://openalex.org/W6726114608","https://openalex.org/W6731927902","https://openalex.org/W6736092963","https://openalex.org/W6739868092","https://openalex.org/W6741036071","https://openalex.org/W6744890726","https://openalex.org/W6745272055","https://openalex.org/W6746608116","https://openalex.org/W6748111160","https://openalex.org/W6758779121","https://openalex.org/W6759580348","https://openalex.org/W6761472960","https://openalex.org/W6762749081","https://openalex.org/W6770290248","https://openalex.org/W6774549192","https://openalex.org/W6791539906"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W4320018150","https://openalex.org/W2040808657","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W2135200719","https://openalex.org/W3009622996","https://openalex.org/W3037859390"],"abstract_inverted_index":{"Deep":[0],"learning":[1],"(DL)":[2],"models":[3,24,108],"have":[4],"been":[5],"shown":[6],"to":[7,10,21,72],"be":[8],"vulnerable":[9],"adversarial":[11,17,53,139],"attacks.":[12,54],"DL":[13,64],"model":[14],"security":[15],"against":[16,50,89,122,137],"attacks":[18,140],"is":[19,87],"critical":[20],"using":[22,99],"DL-trained":[23],"in":[25],"forward":[26],"deployed":[27],"systems,":[28],"e.g.":[29],"facial":[30],"recognition,":[31],"document":[32],"characterization,":[33],"or":[34],"object":[35],"detection.":[36],"We":[37,79,103,116,131],"provide":[38],"results":[39],"and":[40,74],"lessons":[41],"learned":[42],"applying":[43,67],"a":[44,60,81,90,100,123],"moving":[45],"target":[46],"defense":[47],"(MTD)":[48],"strategy":[49,56,86,121,136],"iterative,":[51],"gradient-based":[52],"Our":[55],"involves":[57],"(1)":[58],"training":[59],"diverse":[61],"ensemble":[62,107,128],"of":[63,145],"models,":[65],"(2)":[66],"randomized":[68],"affine":[69],"input":[70],"transformations":[71],"inputs,":[73],"(3)":[75],"randomizing":[76],"output":[77,97],"decisions.":[78],"report":[80],"primary":[82],"lesson":[83],"that":[84,133],"this":[85],"ineffective":[88],"white-box":[91],"adversary,":[92],"which":[93],"could":[94],"completely":[95],"circumvent":[96],"randomization":[98],"deterministic":[101],"surrogate.":[102],"reveal":[104],"how":[105],"our":[106,119],"lacked":[109],"the":[110],"diversity":[111],"necessary":[112],"for":[113],"effective":[114],"MTD.":[115],"also":[117],"evaluate":[118],"MTD":[120,135],"black-box":[124,138],"adversary":[125],"employing":[126],"an":[127,134],"surrogate":[129],"model.":[130],"conclude":[132],"crucially":[141],"depends":[142],"on":[143],"lack":[144],"transferability":[146],"between":[147],"models.":[148]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":4}],"updated_date":"2026-05-07T13:39:58.223016","created_date":"2025-10-10T00:00:00"}
