{"id":"https://openalex.org/W4386072376","doi":"https://doi.org/10.1109/cvpr52729.2023.01571","title":"Can't Steal? Cont-Steal! Contrastive Stealing Attacks Against Image Encoders","display_name":"Can't Steal? Cont-Steal! Contrastive Stealing Attacks Against Image Encoders","publication_year":2023,"publication_date":"2023-06-01","ids":{"openalex":"https://openalex.org/W4386072376","doi":"https://doi.org/10.1109/cvpr52729.2023.01571"},"language":"en","primary_location":{"id":"doi:10.1109/cvpr52729.2023.01571","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52729.2023.01571","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://figshare.com/articles/conference_contribution/Can_t_Steal_Cont-Steal_Contrastive_Stealing_Attacks_Against_Image_Encoders/25436053","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5061607514","display_name":"Zeyang Sha","orcid":"https://orcid.org/0009-0006-5422-0342"},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":true,"raw_author_name":"Zeyang Sha","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security","institution_ids":["https://openalex.org/I4210128801"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074889369","display_name":"Xinlei He","orcid":"https://orcid.org/0000-0002-1526-6341"},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Xinlei He","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security","institution_ids":["https://openalex.org/I4210128801"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100752316","display_name":"Ning Yu","orcid":"https://orcid.org/0000-0002-3046-4338"},"institutions":[{"id":"https://openalex.org/I4210155268","display_name":"Salesforce (United States)","ror":"https://ror.org/057315g56","country_code":"US","type":"company","lineage":["https://openalex.org/I4210155268"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ning Yu","raw_affiliation_strings":["Salesforce Research"],"affiliations":[{"raw_affiliation_string":"Salesforce Research","institution_ids":["https://openalex.org/I4210155268"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004014878","display_name":"Michael Backes","orcid":"https://orcid.org/0000-0002-9326-6400"},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Backes","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security","institution_ids":["https://openalex.org/I4210128801"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100354683","display_name":"Yang Zhang","orcid":"https://orcid.org/0000-0002-4170-4798"},"institutions":[{"id":"https://openalex.org/I4210128801","display_name":"Helmholtz Center for Information Security","ror":"https://ror.org/02njgxr09","country_code":"DE","type":"facility","lineage":["https://openalex.org/I1305996414","https://openalex.org/I4210128801"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Yang Zhang","raw_affiliation_strings":["CISPA Helmholtz Center for Information Security"],"affiliations":[{"raw_affiliation_string":"CISPA Helmholtz Center for Information Security","institution_ids":["https://openalex.org/I4210128801"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5061607514"],"corresponding_institution_ids":["https://openalex.org/I4210128801"],"apc_list":null,"apc_paid":null,"fwci":3.6726,"has_fulltext":false,"cited_by_count":21,"citation_normalized_percentile":{"value":0.94450393,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"16373","last_page":"16383"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9789000153541565,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9138000011444092,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.7958893775939941},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.758832573890686},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.7246876358985901},{"id":"https://openalex.org/keywords/representation","display_name":"Representation (politics)","score":0.5490718483924866},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5357370376586914},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.5152671337127686},{"id":"https://openalex.org/keywords/feature-learning","display_name":"Feature learning","score":0.5032872557640076},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.36893796920776367},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.36850666999816895},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.13456398248672485},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.07447093725204468}],"concepts":[{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.7958893775939941},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.758832573890686},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.7246876358985901},{"id":"https://openalex.org/C2776359362","wikidata":"https://www.wikidata.org/wiki/Q2145286","display_name":"Representation (politics)","level":3,"score":0.5490718483924866},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5357370376586914},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.5152671337127686},{"id":"https://openalex.org/C59404180","wikidata":"https://www.wikidata.org/wiki/Q17013334","display_name":"Feature learning","level":2,"score":0.5032872557640076},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.36893796920776367},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.36850666999816895},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.13456398248672485},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.07447093725204468},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C94625758","wikidata":"https://www.wikidata.org/wiki/Q7163","display_name":"Politics","level":2,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1109/cvpr52729.2023.01571","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52729.2023.01571","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},{"id":"pmh:oai:figshare.com:article/25436053","is_oa":true,"landing_page_url":"https://figshare.com/articles/conference_contribution/Can_t_Steal_Cont-Steal_Contrastive_Stealing_Attacks_Against_Image_Encoders/25436053","pdf_url":null,"source":{"id":"https://openalex.org/S4377196282","display_name":"Figshare","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210132348","host_organization_name":"Figshare (United Kingdom)","host_organization_lineage":["https://openalex.org/I4210132348"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Text"},{"id":"doi:10.60882/cispa.25436053.v1","is_oa":true,"landing_page_url":"https://doi.org/10.60882/cispa.25436053.v1","pdf_url":null,"source":{"id":"https://openalex.org/S7407050916","display_name":"CISPA Helmholtz Center","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:figshare.com:article/25436053","is_oa":true,"landing_page_url":"https://figshare.com/articles/conference_contribution/Can_t_Steal_Cont-Steal_Contrastive_Stealing_Attacks_Against_Image_Encoders/25436053","pdf_url":null,"source":{"id":"https://openalex.org/S4377196282","display_name":"Figshare","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210132348","host_organization_name":"Figshare (United Kingdom)","host_organization_lineage":["https://openalex.org/I4210132348"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Text"},"sustainable_development_goals":[{"score":0.7400000095367432,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":85,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1945616565","https://openalex.org/W2108598243","https://openalex.org/W2118858186","https://openalex.org/W2180612164","https://openalex.org/W2194775991","https://openalex.org/W2335728318","https://openalex.org/W2461943168","https://openalex.org/W2535690855","https://openalex.org/W2620038827","https://openalex.org/W2750384547","https://openalex.org/W2789304371","https://openalex.org/W2798991696","https://openalex.org/W2842511635","https://openalex.org/W2884943453","https://openalex.org/W2899546428","https://openalex.org/W2930926105","https://openalex.org/W2945237470","https://openalex.org/W2963303354","https://openalex.org/W2963378725","https://openalex.org/W2963460174","https://openalex.org/W2963744840","https://openalex.org/W2963844355","https://openalex.org/W2963857521","https://openalex.org/W2964318098","https://openalex.org/W2964583308","https://openalex.org/W2981828710","https://openalex.org/W3005680577","https://openalex.org/W3013068160","https://openalex.org/W3035060554","https://openalex.org/W3035524453","https://openalex.org/W3035682985","https://openalex.org/W3091910518","https://openalex.org/W3094502228","https://openalex.org/W3094559034","https://openalex.org/W3103245149","https://openalex.org/W3126787694","https://openalex.org/W3138758728","https://openalex.org/W3166396011","https://openalex.org/W3171007011","https://openalex.org/W3189812816","https://openalex.org/W3204619801","https://openalex.org/W3211574353","https://openalex.org/W3212600502","https://openalex.org/W4221155126","https://openalex.org/W4221163002","https://openalex.org/W4280654419","https://openalex.org/W4287812705","https://openalex.org/W4288117700","https://openalex.org/W4293846201","https://openalex.org/W4294506858","https://openalex.org/W4296564842","https://openalex.org/W4297808394","https://openalex.org/W4300511536","https://openalex.org/W4308391439","https://openalex.org/W4312048073","https://openalex.org/W4313156423","https://openalex.org/W4323927040","https://openalex.org/W6600428322","https://openalex.org/W6640425456","https://openalex.org/W6677919164","https://openalex.org/W6703116779","https://openalex.org/W6719080892","https://openalex.org/W6739868092","https://openalex.org/W6743688258","https://openalex.org/W6747838042","https://openalex.org/W6755965039","https://openalex.org/W6763077247","https://openalex.org/W6770088130","https://openalex.org/W6774314701","https://openalex.org/W6775078712","https://openalex.org/W6775482175","https://openalex.org/W6776700526","https://openalex.org/W6779326418","https://openalex.org/W6783931880","https://openalex.org/W6784333009","https://openalex.org/W6784847890","https://openalex.org/W6789917881","https://openalex.org/W6791353385","https://openalex.org/W6803870738","https://openalex.org/W6809775742","https://openalex.org/W6839417280","https://openalex.org/W6842301077","https://openalex.org/W6848065295","https://openalex.org/W6850805448"],"related_works":["https://openalex.org/W4390516098","https://openalex.org/W2181948922","https://openalex.org/W2384362569","https://openalex.org/W4205302943","https://openalex.org/W2119949815","https://openalex.org/W2561132942","https://openalex.org/W2142795561","https://openalex.org/W3155418658","https://openalex.org/W2379948177","https://openalex.org/W2107949441"],"abstract_inverted_index":{"Self-supervised":[0],"representation":[1,30,118,153],"learning":[2,154],"techniques":[3],"have":[4],"been":[5],"developing":[6],"rapidly":[7],"to":[8,24,48,60,143,147,157],"make":[9],"full":[10],"use":[11],"of":[12,42,51,88,119,152],"unlabeled":[13],"images.":[14],"They":[15],"encode":[16],"images":[17],"into":[18],"rich":[19,117],"features":[20],"that":[21],"are":[22],"oblivious":[23],"downstream":[25,111],"tasks.":[26],"Behind":[27],"their":[28,79,106],"revolutionary":[29],"power,":[31],"the":[32,49,62,68,86,98,116,148,158],"requirements":[33],"for":[34],"dedicated":[35],"model":[36,53],"designs":[37],"and":[38,104,128],"a":[39,57,125,139],"massive":[40],"amount":[41],"computation":[43],"resources":[44],"expose":[45],"image":[46],"encoders":[47,90,103],"risks":[50],"potential":[52],"stealing":[54,100,132,162],"attacks":[55,73,101,163],"-":[56],"cheap":[58],"way":[59],"mimic":[61],"well-trained":[63],"encoder":[64,161],"performance":[65],"while":[66],"circumventing":[67],"demanding":[69],"requirements.":[70],"Yet":[71],"conventional":[72,99],"only":[74],"target":[75],"supervised":[76],"classifiers":[77],"given":[78],"predicted":[80],"labels":[81],"and/or":[82],"posteriors,":[83],"which":[84],"leaves":[85],"vulnerability":[87,108],"unsupervised":[89],"unexplored.":[91],"In":[92],"this":[93],"paper,":[94],"we":[95,121,141],"first":[96],"instantiate":[97],"against":[102,160],"demonstrate":[105],"severer":[107],"compared":[109],"with":[110],"classifiers.":[112],"To":[113],"better":[114],"leverage":[115],"encoders,":[120],"further":[122],"propose":[123],"Cont-Steal,":[124],"contrastive-learning-based":[126],"attack,":[127],"validate":[129],"its":[130],"improved":[131],"effectiveness":[133],"in":[134,175],"various":[135],"experiment":[136],"settings.":[137],"As":[138],"takeaway,":[140],"appeal":[142],"our":[144,173],"community's":[145],"attention":[146],"intellectual":[149],"property":[150],"protection":[151],"techniques,":[155],"especially":[156],"defenses":[159],"like":[164],"ours.":[165],"<sup":[166,169],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[167,170],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</sup>":[168,171],"See":[172],"code":[174],"https://github.com/zeyangsha/Cont-Steal.":[176]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":8},{"year":2024,"cited_by_count":9},{"year":2023,"cited_by_count":3}],"updated_date":"2026-03-25T14:56:36.534964","created_date":"2025-10-10T00:00:00"}
