{"id":"https://openalex.org/W3102844060","doi":"https://doi.org/10.1145/3544746","title":"FENCE: Feasible Evasion Attacks on Neural Networks in Constrained Environments","display_name":"FENCE: Feasible Evasion Attacks on Neural Networks in Constrained Environments","publication_year":2022,"publication_date":"2022-06-21","ids":{"openalex":"https://openalex.org/W3102844060","doi":"https://doi.org/10.1145/3544746","mag":"3102844060"},"language":"en","primary_location":{"id":"doi:10.1145/3544746","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3544746","pdf_url":null,"source":{"id":"https://openalex.org/S4210174050","display_name":"ACM Transactions on Privacy and Security","issn_l":"2471-2566","issn":["2471-2566","2471-2574"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Privacy and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5058129809","display_name":"Alesia Chernikova","orcid":"https://orcid.org/0000-0001-7166-6051"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Alesia Chernikova","raw_affiliation_strings":["Northeastern University, Boston, MA, USA"],"raw_orcid":"https://orcid.org/0000-0001-7166-6051","affiliations":[{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5035574749","display_name":"Alina Oprea","orcid":"https://orcid.org/0000-0002-4979-5292"},"institutions":[{"id":"https://openalex.org/I12912129","display_name":"Northeastern University","ror":"https://ror.org/04t5xt781","country_code":"US","type":"education","lineage":["https://openalex.org/I12912129"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Alina Oprea","raw_affiliation_strings":["Northeastern University, Boston, MA, USA"],"raw_orcid":"https://orcid.org/0000-0002-4979-5292","affiliations":[{"raw_affiliation_string":"Northeastern University, Boston, MA, USA","institution_ids":["https://openalex.org/I12912129"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5058129809"],"corresponding_institution_ids":["https://openalex.org/I12912129"],"apc_list":null,"apc_paid":null,"fwci":4.7192,"has_fulltext":false,"cited_by_count":40,"citation_normalized_percentile":{"value":0.95340641,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":100},"biblio":{"volume":"25","issue":"4","first_page":"1","last_page":"34"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.977400004863739,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9731000065803528,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.790398120880127},{"id":"https://openalex.org/keywords/evasion","display_name":"Evasion (ethics)","score":0.7014946341514587},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5958269834518433},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.5791589021682739},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5764902830123901},{"id":"https://openalex.org/keywords/fence","display_name":"Fence (mathematics)","score":0.5500975847244263},{"id":"https://openalex.org/keywords/resilience","display_name":"Resilience (materials science)","score":0.5428547859191895},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5138126015663147},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.5039233565330505},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5015172958374023},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4534362554550171},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4483359456062317},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.4208815395832062},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.1465676724910736},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.09038245677947998}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.790398120880127},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.7014946341514587},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5958269834518433},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.5791589021682739},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5764902830123901},{"id":"https://openalex.org/C2779652578","wikidata":"https://www.wikidata.org/wiki/Q5442977","display_name":"Fence (mathematics)","level":2,"score":0.5500975847244263},{"id":"https://openalex.org/C2779585090","wikidata":"https://www.wikidata.org/wiki/Q3457762","display_name":"Resilience (materials science)","level":2,"score":0.5428547859191895},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5138126015663147},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.5039233565330505},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5015172958374023},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4534362554550171},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4483359456062317},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.4208815395832062},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.1465676724910736},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.09038245677947998},{"id":"https://openalex.org/C97355855","wikidata":"https://www.wikidata.org/wiki/Q11473","display_name":"Thermodynamics","level":1,"score":0.0},{"id":"https://openalex.org/C8891405","wikidata":"https://www.wikidata.org/wiki/Q1059","display_name":"Immune system","level":2,"score":0.0},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.0},{"id":"https://openalex.org/C66938386","wikidata":"https://www.wikidata.org/wiki/Q633538","display_name":"Structural engineering","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C203014093","wikidata":"https://www.wikidata.org/wiki/Q101929","display_name":"Immunology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3544746","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3544746","pdf_url":null,"source":{"id":"https://openalex.org/S4210174050","display_name":"ACM Transactions on Privacy and Security","issn_l":"2471-2566","issn":["2471-2566","2471-2574"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Privacy and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":107,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1945616565","https://openalex.org/W1954903228","https://openalex.org/W2038296020","https://openalex.org/W2051267297","https://openalex.org/W2077488147","https://openalex.org/W2095577883","https://openalex.org/W2146729596","https://openalex.org/W2167421362","https://openalex.org/W2180612164","https://openalex.org/W2408141691","https://openalex.org/W2432142698","https://openalex.org/W2529444969","https://openalex.org/W2535873859","https://openalex.org/W2570685808","https://openalex.org/W2574797807","https://openalex.org/W2590523583","https://openalex.org/W2603766943","https://openalex.org/W2609368435","https://openalex.org/W2612637113","https://openalex.org/W2640329709","https://openalex.org/W2738841453","https://openalex.org/W2747678151","https://openalex.org/W2749572357","https://openalex.org/W2767951891","https://openalex.org/W2780061022","https://openalex.org/W2783113218","https://openalex.org/W2784452215","https://openalex.org/W2787708942","https://openalex.org/W2787957674","https://openalex.org/W2798302089","https://openalex.org/W2798966449","https://openalex.org/W2799194071","https://openalex.org/W2799420851","https://openalex.org/W2853623529","https://openalex.org/W2885407017","https://openalex.org/W2889836475","https://openalex.org/W2892852825","https://openalex.org/W2896732478","https://openalex.org/W2898268570","https://openalex.org/W2898435086","https://openalex.org/W2902314211","https://openalex.org/W2903094299","https://openalex.org/W2908403421","https://openalex.org/W2914897181","https://openalex.org/W2917814433","https://openalex.org/W2923292931","https://openalex.org/W2923778952","https://openalex.org/W2932026309","https://openalex.org/W2948348660","https://openalex.org/W2949506549","https://openalex.org/W2950106672","https://openalex.org/W2958343096","https://openalex.org/W2959169310","https://openalex.org/W2962718684","https://openalex.org/W2962818281","https://openalex.org/W2962917037","https://openalex.org/W2963143631","https://openalex.org/W2963165251","https://openalex.org/W2963207607","https://openalex.org/W2963745020","https://openalex.org/W2963834268","https://openalex.org/W2963857521","https://openalex.org/W2964153729","https://openalex.org/W2965657710","https://openalex.org/W2967540978","https://openalex.org/W2971180473","https://openalex.org/W2972094710","https://openalex.org/W2980829995","https://openalex.org/W2989093880","https://openalex.org/W2994715219","https://openalex.org/W2994725226","https://openalex.org/W2997681437","https://openalex.org/W3007712033","https://openalex.org/W3017825983","https://openalex.org/W3024548636","https://openalex.org/W3103340107","https://openalex.org/W3103836116","https://openalex.org/W3104158743","https://openalex.org/W3104227430","https://openalex.org/W3113651845","https://openalex.org/W3116908162","https://openalex.org/W3125713917","https://openalex.org/W3155427574","https://openalex.org/W3165205057","https://openalex.org/W4238819983","https://openalex.org/W4287812648","https://openalex.org/W4288028426","https://openalex.org/W4289376977","https://openalex.org/W4289685488","https://openalex.org/W4293580221","https://openalex.org/W4293846201","https://openalex.org/W4297573953","https://openalex.org/W4297814571","https://openalex.org/W4300434632","https://openalex.org/W4300511536","https://openalex.org/W4300824008","https://openalex.org/W4301332587","https://openalex.org/W4302016602","https://openalex.org/W4302369416","https://openalex.org/W6637162671","https://openalex.org/W6719080892","https://openalex.org/W6733645847","https://openalex.org/W6737220129","https://openalex.org/W6743222990","https://openalex.org/W6749656578","https://openalex.org/W6774549192"],"related_works":["https://openalex.org/W2950183588","https://openalex.org/W3080754722","https://openalex.org/W4383221314","https://openalex.org/W3093978547","https://openalex.org/W2953536436","https://openalex.org/W3203790781","https://openalex.org/W2997056298","https://openalex.org/W2738001131","https://openalex.org/W4285785480","https://openalex.org/W3127875750"],"abstract_inverted_index":{"As":[0],"advances":[1],"in":[2,12,35,38,52,63,71,214],"Deep":[3,33],"Neural":[4,104],"Networks":[5,105],"(DNNs)":[6],"demonstrate":[7,207],"unprecedented":[8],"levels":[9],"of":[10,60,93,133,210],"performance":[11,132],"many":[13],"critical":[14],"applications,":[15],"their":[16,137],"vulnerability":[17],"to":[18,44,120,182,201,217],"attacks":[19,28,86],"is":[20],"still":[21],"an":[22,171],"open":[23],"question.":[24],"We":[25,74,99,125,159,188],"consider":[26],"evasion":[27,85,224],"at":[29],"testing":[30],"time":[31],"against":[32,102,222],"Learning":[34],"constrained":[36,94,215],"environments,":[37],"which":[39],"dependencies":[40],"between":[41],"features":[42],"need":[43],"be":[45,57],"satisfied.":[46],"These":[47],"situations":[48],"may":[49,56],"arise":[50],"naturally":[51],"tabular":[53],"data":[54,157],"or":[55],"the":[58,91,128,147,152,156,175,179,186,208,219],"result":[59],"feature":[61],"engineering":[62],"specific":[64],"application":[65,97],"domains,":[66],"such":[67],"as":[68],"threat":[69],"detection":[70],"cyber":[72,109],"security.":[73],"propose":[75],"a":[76],"general":[77],"iterative":[78],"gradient-based":[79],"framework":[80],"called":[81],"FENCE":[82,203],"for":[83,107],"crafting":[84],"that":[87,145,161,190],"take":[88],"into":[89],"consideration":[90],"specifics":[92],"domains":[95,216],"and":[96,116,131,142,155,184],"requirements.":[98],"apply":[100],"it":[101],"Feed-Forward":[103],"trained":[106,192],"two":[108],"security":[110],"applications:":[111],"network":[112,169],"traffic":[113],"botnet":[114],"classification":[115],"malicious":[117],"domain":[118],"classification,":[119],"generate":[121],"feasible":[122],"adversarial":[123,212],"examples.":[124],"extensively":[126],"evaluate":[127],"success":[129,149],"rate":[130],"our":[134,202],"attacks,":[135],"compare":[136],"improvement":[138],"over":[139],"several":[140],"baselines,":[141],"analyze":[143],"factors":[144],"impact":[146],"attack":[148],"rate,":[150],"including":[151],"optimization":[153],"objective":[154],"imbalance.":[158],"show":[160,189],"with":[162,195],"minimal":[163],"effort":[164],"(e.g.,":[165],"generating":[166],"12":[167],"additional":[168],"connections),":[170],"attacker":[172],"can":[173],"change":[174],"model\u2019s":[176],"prediction":[177],"from":[178],"Malicious":[180],"class":[181],"Benign":[183],"evade":[185],"classifier.":[187],"models":[191],"on":[193],"datasets":[194],"higher":[196],"imbalance":[197],"are":[198],"more":[199],"vulnerable":[200],"attacks.":[204,225],"Finally,":[205],"we":[206],"potential":[209],"performing":[211],"training":[213],"increase":[218],"model":[220],"resilience":[221],"these":[223]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":15},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":1}],"updated_date":"2026-05-13T08:25:38.343686","created_date":"2025-10-10T00:00:00"}
