{"id":"https://openalex.org/W4410608964","doi":"https://doi.org/10.1109/satml64287.2025.00031","title":"SEA: Shareable and Explainable Attribution for Query-Based Black-Box Attacks","display_name":"SEA: Shareable and Explainable Attribution for Query-Based Black-Box Attacks","publication_year":2025,"publication_date":"2025-04-09","ids":{"openalex":"https://openalex.org/W4410608964","doi":"https://doi.org/10.1109/satml64287.2025.00031"},"language":"en","primary_location":{"id":"doi:10.1109/satml64287.2025.00031","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00031","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5001956754","display_name":"Yue Gao","orcid":"https://orcid.org/0000-0002-8901-9335"},"institutions":[{"id":"https://openalex.org/I135310074","display_name":"University of Wisconsin\u2013Madison","ror":"https://ror.org/01y2jtd41","country_code":"US","type":"education","lineage":["https://openalex.org/I135310074"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yue Gao","raw_affiliation_strings":["University of Wisconsin-Madison,Madison,USA"],"affiliations":[{"raw_affiliation_string":"University of Wisconsin-Madison,Madison,USA","institution_ids":["https://openalex.org/I135310074"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069844959","display_name":"Ilia Shumailov","orcid":"https://orcid.org/0000-0003-3100-0727"},"institutions":[{"id":"https://openalex.org/I40120149","display_name":"University of Oxford","ror":"https://ror.org/052gg0110","country_code":"GB","type":"education","lineage":["https://openalex.org/I40120149"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Ilia Shumailov","raw_affiliation_strings":["University of Oxford,Oxford,UK"],"affiliations":[{"raw_affiliation_string":"University of Oxford,Oxford,UK","institution_ids":["https://openalex.org/I40120149"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5042450214","display_name":"Kassem Fawaz","orcid":"https://orcid.org/0000-0002-4609-7691"},"institutions":[{"id":"https://openalex.org/I135310074","display_name":"University of Wisconsin\u2013Madison","ror":"https://ror.org/01y2jtd41","country_code":"US","type":"education","lineage":["https://openalex.org/I135310074"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kassem Fawaz","raw_affiliation_strings":["University of Wisconsin-Madison,Madison,USA"],"affiliations":[{"raw_affiliation_string":"University of Wisconsin-Madison,Madison,USA","institution_ids":["https://openalex.org/I135310074"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5001956754"],"corresponding_institution_ids":["https://openalex.org/I135310074"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.16864687,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"439","last_page":"458"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9952999949455261,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9952999949455261,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9923999905586243,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11614","display_name":"Cloud Data Security Solutions","score":0.9907000064849854,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.6837969422340393},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6588814854621887},{"id":"https://openalex.org/keywords/black-sea","display_name":"Black sea","score":0.6010302305221558},{"id":"https://openalex.org/keywords/attribution","display_name":"Attribution","score":0.5607572793960571},{"id":"https://openalex.org/keywords/information-retrieval","display_name":"Information retrieval","score":0.3705734610557556},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.2214282751083374},{"id":"https://openalex.org/keywords/oceanography","display_name":"Oceanography","score":0.09915000200271606},{"id":"https://openalex.org/keywords/geology","display_name":"Geology","score":0.09593126177787781}],"concepts":[{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.6837969422340393},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6588814854621887},{"id":"https://openalex.org/C2986842804","wikidata":"https://www.wikidata.org/wiki/Q166","display_name":"Black sea","level":2,"score":0.6010302305221558},{"id":"https://openalex.org/C143299363","wikidata":"https://www.wikidata.org/wiki/Q900584","display_name":"Attribution","level":2,"score":0.5607572793960571},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.3705734610557556},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2214282751083374},{"id":"https://openalex.org/C111368507","wikidata":"https://www.wikidata.org/wiki/Q43518","display_name":"Oceanography","level":1,"score":0.09915000200271606},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.09593126177787781},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/satml64287.2025.00031","is_oa":false,"landing_page_url":"https://doi.org/10.1109/satml64287.2025.00031","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Life below water","id":"https://metadata.un.org/sdg/14","score":0.6800000071525574}],"awards":[{"id":"https://openalex.org/G5683485010","display_name":null,"funder_award_id":"CNS-1942014,CNS-2247381","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":68,"referenced_works":["https://openalex.org/W1834627138","https://openalex.org/W2016828421","https://openalex.org/W2117539524","https://openalex.org/W2125838338","https://openalex.org/W2142384583","https://openalex.org/W2148685281","https://openalex.org/W2151135920","https://openalex.org/W2251939518","https://openalex.org/W2603766943","https://openalex.org/W2746600820","https://openalex.org/W2905526464","https://openalex.org/W2949128310","https://openalex.org/W2954978443","https://openalex.org/W2962818281","https://openalex.org/W2962847335","https://openalex.org/W2963857521","https://openalex.org/W2969542116","https://openalex.org/W2969695741","https://openalex.org/W2970078867","https://openalex.org/W2988194011","https://openalex.org/W2996851481","https://openalex.org/W2997999392","https://openalex.org/W3007305010","https://openalex.org/W3010896178","https://openalex.org/W3015625436","https://openalex.org/W3034619610","https://openalex.org/W3034892461","https://openalex.org/W3035172095","https://openalex.org/W3080260826","https://openalex.org/W3080297477","https://openalex.org/W3103836116","https://openalex.org/W3107235539","https://openalex.org/W3185067909","https://openalex.org/W3198300623","https://openalex.org/W3204342889","https://openalex.org/W3213831029","https://openalex.org/W4245671428","https://openalex.org/W4293846201","https://openalex.org/W4313120717","https://openalex.org/W6637162671","https://openalex.org/W6745272055","https://openalex.org/W6746402973","https://openalex.org/W6746608116","https://openalex.org/W6748475379","https://openalex.org/W6750404860","https://openalex.org/W6752654261","https://openalex.org/W6752985256","https://openalex.org/W6759580348","https://openalex.org/W6762681652","https://openalex.org/W6765723815","https://openalex.org/W6766673545","https://openalex.org/W6767666165","https://openalex.org/W6773713311","https://openalex.org/W6784493056","https://openalex.org/W6788680506","https://openalex.org/W6794740203","https://openalex.org/W6802755634","https://openalex.org/W6802839878","https://openalex.org/W6838602400","https://openalex.org/W6838695150","https://openalex.org/W6839326927","https://openalex.org/W6839453425","https://openalex.org/W6840571915","https://openalex.org/W6841173982","https://openalex.org/W6849189713","https://openalex.org/W6849756054","https://openalex.org/W6850316284","https://openalex.org/W6853123908"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2035546108","https://openalex.org/W2376361520","https://openalex.org/W2133328864","https://openalex.org/W2093949997","https://openalex.org/W2570200690","https://openalex.org/W2389726244","https://openalex.org/W3030478661"],"abstract_inverted_index":{"Machine":[0],"Learning":[1],"(ML)":[2],"systems":[3,25,91],"are":[4,26],"vulnerable":[5],"to":[6,18,35,61,65,85,96,106,112,148,152,165,226],"adversarial":[7,128],"examples,":[8],"particularly":[9],"those":[10],"from":[11,48],"query-based":[12],"black-box":[13,87],"attacks.":[14,114],"Despite":[15],"various":[16],"efforts":[17],"detect":[19],"and":[20,41,53,69,95,145,182,202,216],"prevent":[21],"such":[22],"attacks,":[23],"ML":[24,57,82,90],"still":[27],"at":[28,137],"risk,":[29],"demanding":[30],"a":[31,63,80,198],"more":[32,212],"comprehensive":[33],"approach":[34],"security":[36,46,58,83],"that":[37,133,179,204],"includes":[38],"logging,":[39],"analyzing,":[40],"sharing":[42],"evidence.":[43],"While":[44],"traditional":[45],"benefits":[47],"well-established":[49],"practices":[50],"of":[51,158,200],"forensics":[52],"threat":[54],"intelligence":[55,99],"sharing,":[56],"has":[59],"yet":[60],"find":[62],"way":[64],"profile":[66],"its":[67],"attackers":[68],"share":[70],"information":[71],"about":[72],"them.":[73],"In":[74],"response,":[75],"this":[76],"paper":[77],"introduces":[78],"SEA,":[79],"novel":[81],"system":[84],"characterize":[86],"attacks":[88,184],"on":[89,125,141,197],"for":[92],"forensic":[93,154],"purposes":[94],"facilitate":[97],"human-explainable":[98],"sharing.":[100],"SEA":[101,134,196,224],"leverages":[102],"Hidden":[103],"Markov":[104],"Models":[105],"attribute":[107],"the":[108,118,126,142,159,180,208],"observed":[109],"query":[110],"sequence":[111],"known":[113],"It":[115],"thus":[116],"understands":[117],"attack's":[119,160],"progression":[120],"rather":[121],"than":[122,213],"focusing":[123],"solely":[124],"final":[127],"examples.":[129],"Our":[130],"evaluations":[131],"reveal":[132],"is":[135,146],"effective":[136],"attack":[138,173,210],"attribution,":[139],"even":[140,164],"second":[143],"incident,":[144],"robust":[147],"adaptive":[149],"strategies":[150],"designed":[151],"evade":[153],"analysis.":[155],"SEA's":[156],"explanations":[157],"behavior":[161],"allow":[162],"us":[163],"fingerprint":[166],"specific":[167],"minor":[168],"bugs":[169],"in":[170,185],"widely":[171],"used":[172],"libraries.":[174],"For":[175],"example,":[176],"we":[177,221],"discover":[178],"SignOPT":[181],"Square":[183],"ART":[186],"v1.14":[187],"send":[188],"over":[189],"50%":[190],"duplicated":[191],"queries.":[192],"We":[193],"thoroughly":[194],"evaluate":[195],"variety":[199],"settings":[201],"demonstrate":[203,222],"it":[205],"can":[206],"recognize":[207],"same":[209],"with":[211],"90%":[214],"Top-1":[215],"95%":[217],"Top-3":[218],"accuracy.":[219],"Finally,":[220],"how":[223],"generalizes":[225],"other":[227],"domains":[228],"like":[229],"text":[230],"classification.":[231]},"counts_by_year":[],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
