{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,26]],"date-time":"2025-03-26T19:02:25Z","timestamp":1743015745179,"version":"3.40.3"},"publisher-location":"Cham","reference-count":25,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030937324"},{"type":"electronic","value":"9783030937331"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-93733-1_3","type":"book-chapter","created":{"date-parts":[[2022,2,18]],"date-time":"2022-02-18T06:02:58Z","timestamp":1645164178000},"page":"39-54","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Practical Black Box Model Inversion Attacks Against Neural Nets"],"prefix":"10.1007","author":[{"given":"Thomas","family":"Bekman","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Masoumeh","family":"Abolfathi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haadi","family":"Jafarian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ashis","family":"Biswas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Farnoush","family":"Banaei-Kashani","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kuntal","family":"Das","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,2,18]]},"reference":[{"issue":"6","key":"3_CR1","doi-asserted-by":"publisher","first-page":"1164","DOI":"10.1016\/j.jbi.2012.07.011","volume":"45","author":"C-L Chi","year":"2012","unstructured":"Chi, C.-L., et al.: Individualized patient-centered lifestyle recommendations: an expert system for communicating patient specific cardiovascular risk information and prioritizing lifestyle options. J. Biomed. Inform. 45(6), 1164\u20131174 (2012)","journal-title":"J. Biomed. Inform."},{"doi-asserted-by":"crossref","unstructured":"International Warfarin Pharmacogenetics Consortium: Estimation of the warfarin dose with clinical and pharmacogenetic data. N. Engl. J. Med. 360(8), 753\u2013764 (2009)","key":"3_CR2","DOI":"10.1056\/NEJMoa0809329"},{"doi-asserted-by":"crossref","unstructured":"Taigman, Y., Yang, M., Ranzato, M.A., Wolf, L.: Deepface: closing the gap to human-level performance in face verification. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 1701\u20131708 (2014)","key":"3_CR3","DOI":"10.1109\/CVPR.2014.220"},{"unstructured":"AWS. https:\/\/aws.amazon.com\/rekognition\/","key":"3_CR4"},{"unstructured":"Google Cloud. https:\/\/cloud.google.com\/healthcare\/","key":"3_CR5"},{"unstructured":"Fredrikson, M., et al.: Privacy in pharmacogenetics: an end-to-end case study of personalized warfarin dosing. In: 23rd USENIX Security Symposium (USENIX Security 2014) (2014)","key":"3_CR6"},{"issue":"9","key":"3_CR7","doi-asserted-by":"publisher","first-page":"1536","DOI":"10.1109\/5.784232","volume":"87","author":"CA Jensen","year":"1999","unstructured":"Jensen, C.A., et al.: Inversion of feedforward neural networks: algorithms and applications. Proc. IEEE 87(9), 1536\u20131549 (1999)","journal-title":"Proc. IEEE"},{"issue":"3","key":"3_CR8","doi-asserted-by":"publisher","first-page":"409","DOI":"10.1109\/72.286912","volume":"5","author":"S Lee","year":"1994","unstructured":"Lee, S., Kil, R.M.: Inverse mapping of continuous functions using local and global information. IEEE Trans. Neural Netw. 5(3), 409\u2013423 (1994)","journal-title":"IEEE Trans. Neural Netw."},{"doi-asserted-by":"crossref","unstructured":"Mahendran, A., Vedaldi, A.: Understanding deep image representations by inverting them. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (2015)","key":"3_CR9","DOI":"10.1109\/CVPR.2015.7299155"},{"key":"3_CR10","doi-asserted-by":"publisher","first-page":"681","DOI":"10.1007\/978-3-642-03737-5_49","volume-title":"Towards Intelligent Engineering and Information Technology","author":"AR V\u00e1rkonyi-K\u00f3czy","year":"2009","unstructured":"V\u00e1rkonyi-K\u00f3czy, A.R.: Observer-based iterative fuzzy and neural network model inversion for measurement and control applications. In: Rudas, I.J., Fodor, J., Kacprzyk, J. (eds.) Towards Intelligent Engineering and Information Technology, pp. 681\u2013702. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-03737-5_49"},{"doi-asserted-by":"crossref","unstructured":"Hitaj, B., Ateniese, G., Perez-Cruz, F.: Deep models under the GAN: information leakage from collaborative deep learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (2017)","key":"3_CR11","DOI":"10.1145\/3133956.3134012"},{"doi-asserted-by":"crossref","unstructured":"Papernot, N., et al.: SoK: security and privacy in machine learning. In: 2018 IEEE European Symposium on Security and Privacy (EuroS&P). IEEE (2018)","key":"3_CR12","DOI":"10.1109\/EuroSP.2018.00035"},{"doi-asserted-by":"crossref","unstructured":"Shokri, R., et al.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP). IEEE (2017)","key":"3_CR13","DOI":"10.1109\/SP.2017.41"},{"doi-asserted-by":"crossref","unstructured":"Yang, Z., et al.: Neural network inversion in adversarial setting via background knowledge alignment. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (2019)","key":"3_CR14","DOI":"10.1145\/3319535.3354261"},{"unstructured":"Tram\u00e8r, F., et al.: Stealing machine learning models via prediction APIs. In: 25th USENIX Security Symposium (USENIX Security 2016) (2016)","key":"3_CR15"},{"doi-asserted-by":"crossref","unstructured":"Jia, J., et al.: Memguard: defending against black-box membership inference attacks via adversarial examples. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (2019)","key":"3_CR16","DOI":"10.1145\/3319535.3363201"},{"doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (2015)","key":"3_CR17","DOI":"10.1145\/2810103.2813677"},{"doi-asserted-by":"crossref","unstructured":"Papernot, N., et al.: Practical black-box attacks against machine learning. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security (2017)","key":"3_CR18","DOI":"10.1145\/3052973.3053009"},{"unstructured":"Papernot, N., McDaniel, P., Goodfellow, I.: Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277 (2016)","key":"3_CR19"},{"doi-asserted-by":"crossref","unstructured":"Ng, H.-W., Winkler, S.: A data-driven approach to cleaning large face datasets. In: 2014 IEEE International Conference on Image Processing (ICIP). IEEE (2014)","key":"3_CR20","DOI":"10.1109\/ICIP.2014.7025068"},{"issue":"1","key":"3_CR21","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1007\/s00146-014-0549-4","volume":"30","author":"B Batrinca","year":"2014","unstructured":"Batrinca, B., Treleaven, P.C.: Social media analytics: a survey of techniques, tools and platforms. AI Soc. 30(1), 89\u2013116 (2014). https:\/\/doi.org\/10.1007\/s00146-014-0549-4","journal-title":"AI Soc."},{"doi-asserted-by":"crossref","unstructured":"Salem, A., et al.: ML-leaks: model and data independent membership inference attacks and defenses on machine learning models. arXiv preprint arXiv:1806.01246 (2018)","key":"3_CR22","DOI":"10.14722\/ndss.2019.23119"},{"unstructured":"Hayes, J., et al.: Logan: membership inference attacks against generative models. arXiv preprint arXiv:1705.07663 (2017)","key":"3_CR23"},{"unstructured":"Laskov, P.: Practical evasion of a learning-based classifier: a case study. In: 2014 IEEE Symposium on Security and Privacy. IEEE (2014)","key":"3_CR24"},{"doi-asserted-by":"crossref","unstructured":"Zhang, Y., et al.: The secret revealer: generative model-inversion attacks against deep neural networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2020)","key":"3_CR25","DOI":"10.1109\/CVPR42600.2020.00033"}],"container-title":["Communications in Computer and Information Science","Machine Learning and Principles and Practice of Knowledge Discovery in Databases"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-93733-1_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,6]],"date-time":"2022-05-06T22:40:11Z","timestamp":1651876811000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-93733-1_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030937324","9783030937331"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-93733-1_3","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"18 February 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECML PKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Bilbao","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Spain","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13 September 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 September 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ecml2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2021.ecmlpkdd.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"869","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"210","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"24% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-9","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"The conference was held online due to the COVID-19 pandemic.","order":10,"name":"additional_info_on_review_process","label":"Additional Info on Review Process","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}