{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,9]],"date-time":"2025-04-09T16:55:23Z","timestamp":1744217723689,"version":"3.40.3"},"publisher-location":"Cham","reference-count":36,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783031162091"},{"type":"electronic","value":"9783031162107"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-031-16210-7_54","type":"book-chapter","created":{"date-parts":[[2022,9,20]],"date-time":"2022-09-20T23:03:09Z","timestamp":1663714989000},"page":"661-673","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["How Differential Privacy Reinforces Privacy of Machine Learning Models?"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8840-7379","authenticated-orcid":false,"given":"Sana","family":"Ben Hamida","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1376-829X","authenticated-orcid":false,"given":"Hichem","family":"Mrabet","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4033-2969","authenticated-orcid":false,"given":"Abderrazak","family":"Jemai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,9,21]]},"reference":[{"key":"54_CR1","unstructured":"He, Y., Meng, G., Chen, K., Hu, X., He, J.: Towards security threats of deep learning systems: a survey. arXiv:1911.12562 [cs], October 2020"},{"key":"54_CR2","unstructured":"Papernot, N., Mcdaniel, P., Sinha, A., Wellman, M.: SoK: towards the Science of security and privacy in machine learning, p. 20 (2016)"},{"key":"54_CR3","doi-asserted-by":"publisher","unstructured":"Liu, Q., Li, P., Zhao, W., Cai, W., Yu, S., Leung, V.C.M.: A survey on security threats and defensive techniques of machine learning: a data driven view. IEEE Access 6, 12103\u201312117 (2018). https:\/\/doi.org\/10.1109\/ACCESS.2018.2805680","DOI":"10.1109\/ACCESS.2018.2805680"},{"key":"54_CR4","doi-asserted-by":"crossref","unstructured":"Hu, H., Salcic, Z., Sun, L., Dobbie, G., Yu, P.S., Zhang, X.: Membership inference attacks on machine learning: a survey. arXiv:2103.07853 [cs], November 2021","DOI":"10.1109\/ICDM51629.2021.00129"},{"key":"54_CR5","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. arXiv:1610.05820 [cs, stat], March 2017","DOI":"10.1109\/SP.2017.41"},{"key":"54_CR6","doi-asserted-by":"publisher","unstructured":"Yeom, S., Giacomelli, I., Menaged, A., Fredrikson, M., Jha, S.: Overfitting, robustness, and malicious algorithms: a study of potential causes of privacy risk in machine learning. JCS 28(1), 35\u201370 (2020). https:\/\/doi.org\/10.3233\/JCS-191362","DOI":"10.3233\/JCS-191362"},{"key":"54_CR7","doi-asserted-by":"crossref","unstructured":"Carlini, N., Chien, S., Nasr, M., Song, S., Terzis, A., Tramer, F.: Membership inference attacks from first principles. arXiv:2112.03570 [cs], December 2021","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"54_CR8","doi-asserted-by":"publisher","unstructured":"Nasr, M., Shokri, R., Houmansadr, A.: Machine learning with membership privacy using adversarial regularization. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, New York, NY, USA, pp. 634\u2013646, October 2018. https:\/\/doi.org\/10.1145\/3243734.3243855","DOI":"10.1145\/3243734.3243855"},{"key":"54_CR9","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., Berrang, P., Fritz, M., Backes, M.: ML-leaks: model and data independent membership inference attacks and defenses on machine learning models. arXiv:1806.01246 [cs], December 2018","DOI":"10.14722\/ndss.2019.23119"},{"key":"54_CR10","doi-asserted-by":"publisher","unstructured":"Song, L., Shokri, R., Mittal, P.: Privacy risks of securing machine learning models against adversarial examples. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 241\u2013257, November 2019. https:\/\/doi.org\/10.1145\/3319535.3354211","DOI":"10.1145\/3319535.3354211"},{"key":"54_CR11","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., Jha, S.: Privacy risk in machine learning: analyzing the connection to overfitting. arXiv:1709.01604 [cs, stat], May 2018","DOI":"10.1109\/CSF.2018.00027"},{"key":"54_CR12","doi-asserted-by":"publisher","unstructured":"Ying, X.: An overview of overfitting and its solutions. J. Phys. Conf. Ser. 1168, 022022, February 2019. https:\/\/doi.org\/10.1088\/1742-6596\/1168\/2\/022022","DOI":"10.1088\/1742-6596\/1168\/2\/022022"},{"key":"54_CR13","unstructured":"Truex, S., Liu, L., Gursoy, M.E., Yu, L., Wei, W.: Towards demystifying membership inference attacks. arXiv:1807.09173 [cs], February 2019"},{"key":"54_CR14","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11787006_1","volume-title":"Automata, Languages and Programming","author":"C Dwork","year":"2006","unstructured":"Dwork, C.: Differential privacy. In: Bugliesi, M., Preneel, B., Sassone, V., Wegener, I. (eds.) ICALP 2006. LNCS,  Part II, vol. 4052, pp. 1\u201312. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11787006_1"},{"key":"54_CR15","doi-asserted-by":"crossref","unstructured":"Chen, J., Wang, W.H., Shi, X.: Differential privacy protection against membership inference attack on machine learning for genomic data. In: Proceedings of the Pacific Symposium Biocomputing, vol. 26, pp. 26\u201337 (2021)","DOI":"10.1101\/2020.08.03.235416"},{"key":"54_CR16","doi-asserted-by":"publisher","unstructured":"Abadi, M., et al.: Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 308\u2013318, October 2016. https:\/\/doi.org\/10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"54_CR17","unstructured":"Du, J., Li, S., Feng, M., Chen, S.: Dynamic differential-privacy preserving SGD (2021)"},{"key":"54_CR18","unstructured":"Yann, L., Corinna, C., Christopher, J.C.B.: MNIST handwritten digit database, Yann LeCun, Corinna Cortes and Chris Burges. http:\/\/yann.lecun.com\/exdb\/mnist\/"},{"key":"54_CR19","unstructured":"TensorFlow Privacy. Tensorflow (2022). https:\/\/github.com\/tensorflow\/privacy. Accessed 8 Mar 2022"},{"key":"54_CR20","first-page":"1","volume":"31","author":"T Fawcett","year":"2004","unstructured":"Fawcett, T.: ROC graphs: notes and practical considerations for researchers. Mach. Learn. 31, 1\u201338 (2004)","journal-title":"Mach. Learn."},{"key":"54_CR21","doi-asserted-by":"publisher","unstructured":"Li, J., Li, N., Ribeiro, B.: Membership inference attacks and defenses in classification models. In: Proceedings of the Eleventh ACM Conference on Data and Application Security and Privacy, New York, NY, USA, pp. 5\u201316 (2021). https:\/\/doi.org\/10.1145\/3422337.3447836","DOI":"10.1145\/3422337.3447836"},{"key":"54_CR22","unstructured":"Choquette-Choo, C.A., Tramer, F., Carlini, N., Papernot, N.: Label-only membership inference attacks. In: Proceedings of the 38th International Conference on Machine Learning, pp. 1964\u20131974, July 2021"},{"key":"54_CR23","doi-asserted-by":"crossref","unstructured":"Jia, J., Salem, A., Backes, M., Zhang, Y., Gong, N.Z.: MemGuard: defending against black-box membership inference attacks via adversarial examples. arXiv:1909.10594 [cs], December 2019","DOI":"10.1145\/3319535.3363201"},{"key":"54_CR24","unstructured":"Yang, Z., Shao, B., Xuan, B., Chang, E.-C., Zhang, F.: Defending model inversion and membership inference attacks via prediction purification. arXiv:2005.03915 [cs], August 2020"},{"key":"54_CR25","doi-asserted-by":"crossref","unstructured":"Hanzlik, L., et al.: MLCapsule: guarded offline deployment of machine learning as a service, pp. 3300\u20133309 (2021)","DOI":"10.1109\/CVPRW53098.2021.00368"},{"key":"54_CR26","doi-asserted-by":"crossref","unstructured":"Ben Hamida, S., Mrabet, H., Belguith, S., Alhomoud, A., Jemai, A.: Towards securing machine learning models against membership inference attacks. Comput. Mater. Continua (2021)","DOI":"10.32604\/cmc.2022.019709"},{"key":"54_CR27","unstructured":"Kaya, Y., Dumitras, T.: When does data augmentation help with membership inference attacks?. In: Proceedings of the 38th International Conference on Machine Learning, pp. 5345\u20135355, July 2021"},{"key":"54_CR28","doi-asserted-by":"crossref","unstructured":"Yu, D., Zhang, H., Chen, W., Yin, J., Liu, T.-Y.: How does data augmentation affect privacy in machine learning? (2021)","DOI":"10.1609\/aaai.v35i12.17284"},{"key":"54_CR29","doi-asserted-by":"publisher","unstructured":"Hayes, J., Melis, L., Danezis, G., De Cristofaro, E.: LOGAN: membership inference attacks against generative models. In: Proceedings on Privacy Enhancing Technologies, vol. 2019, no 1, pp. 133\u2013152, January 2019. https:\/\/doi.org\/10.2478\/popets-2019-0008","DOI":"10.2478\/popets-2019-0008"},{"key":"54_CR30","unstructured":"Leino, K., Fredrikson, M.: Stolen memories: leveraging model memorization for calibrated {white-box} membership inference, pp. 1605\u20131622 (2020)"},{"key":"54_CR31","doi-asserted-by":"publisher","unstructured":"Saeidian, S., Cervia, G., Oechtering, T.J., Skoglund, M.: Quantifying membership privacy via information leakage. IEEE Trans. Inf. Forensics Secur. 16, 3096\u20133108 (2021). https:\/\/doi.org\/10.1109\/TIFS.2021.3073804","DOI":"10.1109\/TIFS.2021.3073804"},{"key":"54_CR32","doi-asserted-by":"crossref","unstructured":"Shejwalkar, V., Houmansadr, A.: Membership privacy for machine learning models through knowledge transfer | researchain. In: AAAI Conference on Artificial Intelligence, pp. 9549\u20139557 (2021)","DOI":"10.1609\/aaai.v35i11.17150"},{"key":"54_CR33","doi-asserted-by":"publisher","unstructured":"Bernau, D., Robl, J., Grassal, P.W., Schneider, S., Kerschbaum, F.: Comparing local and central differential privacy using membership inference attacks. In: Barker, K., Ghazinour, K. (eds.) DBSec 2021. LNCS, vol. 12840, pp. 22\u201342. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-81242-3_2. https:\/\/www.springerprofessional.de\/en\/comparing-local-and-central-differential-privacy-using-membershi\/19361800","DOI":"10.1007\/978-3-030-81242-3_2"},{"key":"54_CR34","unstructured":"Tang, X., et al.: Mitigating membership inference attacks by self-distillation through a novel ensemble architecture. arXiv:2110.08324 [cs], October 2021. http:\/\/arxiv.org\/abs\/2110.08324. Consult\u00e9 le: 12 mars 2022. [En ligne]. Disponible sur"},{"key":"54_CR35","doi-asserted-by":"publisher","unstructured":"Zheng, J., Cao, Y., Wang, H.: Resisting membership inference attacks through knowledge distillation. Neurocomputing 452, 114\u2013126 (2021). https:\/\/doi.org\/10.1016\/j.neucom.2021.04.082","DOI":"10.1016\/j.neucom.2021.04.082"},{"key":"54_CR36","doi-asserted-by":"crossref","unstructured":"Jarin, I., Eshete, B.: DP-UTIL: comprehensive utility analysis of differential privacy in machine learning. arXiv:2112.12998 [cs], December 2021","DOI":"10.1145\/3508398.3511513"}],"container-title":["Communications in Computer and Information Science","Advances in Computational Collective Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-16210-7_54","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,3,9]],"date-time":"2023-03-09T12:23:44Z","timestamp":1678364624000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-16210-7_54"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783031162091","9783031162107"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-16210-7_54","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"21 September 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}