{"id":"https://openalex.org/W3208646583","doi":"https://doi.org/10.1145/3474369.3486863","title":"SEAT","display_name":"SEAT","publication_year":2021,"publication_date":"2021-10-28","ids":{"openalex":"https://openalex.org/W3208646583","doi":"https://doi.org/10.1145/3474369.3486863","mag":"3208646583"},"language":"en","primary_location":{"id":"doi:10.1145/3474369.3486863","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3474369.3486863","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486863","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486863","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5046266368","display_name":"Zhanyuan Zhang","orcid":"https://orcid.org/0000-0002-5689-9145"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Zhanyuan Zhang","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101433146","display_name":"Yizheng Chen","orcid":"https://orcid.org/0000-0001-8799-2580"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yizheng Chen","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5062174672","display_name":"David Wagner","orcid":"https://orcid.org/0000-0001-7728-4273"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"David Wagner","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5046266368"],"corresponding_institution_ids":["https://openalex.org/I95457486"],"apc_list":null,"apc_paid":null,"fwci":2.7194,"has_fulltext":true,"cited_by_count":33,"citation_normalized_percentile":{"value":0.91897273,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"37","last_page":"48"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9901000261306763,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9851999878883362,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8226355314254761},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.5468650460243225},{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.5239135026931763},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.5211724638938904},{"id":"https://openalex.org/keywords/detector","display_name":"Detector","score":0.5135310292243958},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4629074037075043},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.4421624541282654},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.42206817865371704},{"id":"https://openalex.org/keywords/real-time-computing","display_name":"Real-time computing","score":0.3784988224506378},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.32776665687561035},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.14220371842384338},{"id":"https://openalex.org/keywords/telecommunications","display_name":"Telecommunications","score":0.06961840391159058}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8226355314254761},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.5468650460243225},{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.5239135026931763},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.5211724638938904},{"id":"https://openalex.org/C94915269","wikidata":"https://www.wikidata.org/wiki/Q1834857","display_name":"Detector","level":2,"score":0.5135310292243958},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4629074037075043},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.4421624541282654},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.42206817865371704},{"id":"https://openalex.org/C79403827","wikidata":"https://www.wikidata.org/wiki/Q3988","display_name":"Real-time computing","level":1,"score":0.3784988224506378},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.32776665687561035},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.14220371842384338},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.06961840391159058},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3474369.3486863","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3474369.3486863","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486863","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3474369.3486863","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3474369.3486863","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3474369.3486863","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320315389","display_name":"Open Philanthropy Project","ror":"https://ror.org/004d1k391"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3208646583.pdf","grobid_xml":"https://content.openalex.org/works/W3208646583.grobid-xml"},"referenced_works_count":37,"referenced_works":["https://openalex.org/W1520914943","https://openalex.org/W1576445103","https://openalex.org/W1686810756","https://openalex.org/W1782590233","https://openalex.org/W2002427601","https://openalex.org/W2092277251","https://openalex.org/W2099001231","https://openalex.org/W2108598243","https://openalex.org/W2138621090","https://openalex.org/W2152161678","https://openalex.org/W2168326969","https://openalex.org/W2194775991","https://openalex.org/W2296452361","https://openalex.org/W2335728318","https://openalex.org/W2461943168","https://openalex.org/W2603766943","https://openalex.org/W2612112834","https://openalex.org/W2640329709","https://openalex.org/W2735607295","https://openalex.org/W2808195004","https://openalex.org/W2899771611","https://openalex.org/W2905209730","https://openalex.org/W2946814535","https://openalex.org/W2949117887","https://openalex.org/W2963062382","https://openalex.org/W2963070423","https://openalex.org/W2963857521","https://openalex.org/W2997146418","https://openalex.org/W3007318395","https://openalex.org/W3018424040","https://openalex.org/W3035379805","https://openalex.org/W3049152512","https://openalex.org/W3088909400","https://openalex.org/W3103932910","https://openalex.org/W3118608800","https://openalex.org/W3168455774","https://openalex.org/W4285719527"],"related_works":["https://openalex.org/W4244478748","https://openalex.org/W4223488648","https://openalex.org/W2134969820","https://openalex.org/W2251605416","https://openalex.org/W1997222214","https://openalex.org/W2560439919","https://openalex.org/W4389340727","https://openalex.org/W3150465815","https://openalex.org/W2802581102","https://openalex.org/W4205786897"],"abstract_inverted_index":{"Given":[0],"black-box":[1,30],"access":[2],"to":[3,110],"the":[4,12,18,25,36,52,101],"prediction":[5],"API,":[6],"model":[7,31,64,79,104],"extraction":[8,32,65,80,105],"attacks":[9,33,81,86,106],"can":[10,38],"steal":[11],"functionality":[13],"of":[14,103],"models":[15],"deployed":[16],"in":[17,67,88],"cloud.":[19],"In":[20],"this":[21,89],"paper,":[22],"we":[23],"introduce":[24],"SEAT":[26,42,55,99],"detector,":[27],"which":[28],"detects":[29,56],"so":[34],"that":[35,58,61,94],"defender":[37],"terminate":[39],"malicious":[40],"accounts.":[41,72],"has":[43],"a":[44,63],"similarity":[45,53],"encoder":[46],"trained":[47],"by":[48,107],"adversarial":[49],"training.":[50],"Using":[51],"encoder,":[54],"accounts":[57],"make":[59],"queries":[60],"indicate":[62],"attack":[66],"progress":[68],"and":[69,82],"cancels":[70],"these":[71],"We":[73],"evaluate":[74],"our":[75],"defense":[76],"against":[77,83,96],"existing":[78],"new":[84],"adaptive":[85,97],"introduced":[87],"paper.":[90],"Our":[91],"results":[92],"show":[93],"even":[95],"attackers,":[98],"increases":[100],"cost":[102],"3.8":[108],"times":[109],"16":[111],"times.":[112]},"counts_by_year":[{"year":2025,"cited_by_count":13},{"year":2024,"cited_by_count":7},{"year":2023,"cited_by_count":9},{"year":2022,"cited_by_count":4}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2021-11-08T00:00:00"}
