{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T16:24:01Z","timestamp":1759335841108,"version":"3.40.3"},"publisher-location":"Cham","reference-count":69,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031731150"},{"type":"electronic","value":"9783031731167"}],"license":[{"start":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:00:00Z","timestamp":1730332800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,10,31]],"date-time":"2024-10-31T00:00:00Z","timestamp":1730332800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-73116-7_13","type":"book-chapter","created":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T15:15:38Z","timestamp":1730301338000},"page":"214-232","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["SIMBA: Split Inference\u2014Mechanisms, Benchmarks and\u00a0Attacks"],"prefix":"10.1007","author":[{"given":"Abhishek","family":"Singh","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vivek","family":"Sharma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rohan","family":"Sukumaran","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John","family":"Mose","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jeffrey","family":"Chiu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Justin","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ramesh","family":"Raskar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,10,31]]},"reference":[{"unstructured":"US Census Bureau (2020). https:\/\/www.usa.gov\/statistics","key":"13_CR1"},{"issue":"4","key":"13_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3214303","volume":"51","author":"A Acar","year":"2018","unstructured":"Acar, A., Aksu, H., Uluagac, A.S., Conti, M.: A survey on homomorphic encryption schemes: theory and implementation. ACM Comput. Surv. (Csur) 51(4), 1\u201335 (2018)","journal-title":"ACM Comput. Surv. (Csur)"},{"unstructured":"Arora, S., Liang, Y., Ma, T.: Why are deep nets reversible: a simple theory, with implications for training. arXiv preprint arXiv:1511.05653 (2015)","key":"13_CR3"},{"unstructured":"Behrmann, J., Dittmer, S., Fernsel, P., Maa\u00df, P.: Analysis of invariance and robustness via invertibility of ReLU-Networks. arXiv preprint arXiv:1806.09730 (2018)","key":"13_CR4"},{"unstructured":"Bertran, M., et al.: Adversarially learned representations for information obfuscation and inference. In: International Conference on Machine Learning, pp. 614\u2013623. PMLR (2019)","key":"13_CR5"},{"unstructured":"Brown, T.B., et\u00a0al.: Language models are few-shot learners. arXiv preprint arXiv:2005.14165 (2020)","key":"13_CR6"},{"key":"13_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"82","DOI":"10.1007\/978-3-642-39077-7_5","volume-title":"Privacy Enhancing Technologies","author":"K Chatzikokolakis","year":"2013","unstructured":"Chatzikokolakis, K., Andr\u00e9s, M.E., Bordenabe, N.E., Palamidessi, C.: Broadening the scope of differential privacy using metrics. In: De Cristofaro, E., Wright, M. (eds.) PETS 2013. LNCS, vol. 7981, pp. 82\u2013102. Springer, Heidelberg (2013). https:\/\/doi.org\/10.1007\/978-3-642-39077-7_5"},{"unstructured":"Choquette-Choo, C.A., Tramer, F., Carlini, N., Papernot, N.: Label-only membership inference attacks. In: International Conference on Machine Learning, pp. 1964\u20131974. PMLR (2021)","key":"13_CR8"},{"key":"13_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-540-79228-4_1","volume-title":"Theory and Applications of Models of Computation","author":"C Dwork","year":"2008","unstructured":"Dwork, C.: Differential privacy: a survey of results. In: Agrawal, M., Du, D., Duan, Z., Li, A. (eds.) TAMC 2008. LNCS, vol. 4978, pp. 1\u201319. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-79228-4_1"},{"key":"13_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/11681878_14","volume-title":"Theory of Cryptography","author":"C Dwork","year":"2006","unstructured":"Dwork, C., McSherry, F., Nissim, K., Smith, A.: Calibrating noise to sensitivity in private data analysis. In: Halevi, S., Rabin, T. (eds.) TCC 2006. LNCS, vol. 3876, pp. 265\u2013284. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11681878_14"},{"doi-asserted-by":"publisher","unstructured":"Dwork, C., Roth, A.: The algorithmic foundations of differential privacy. foundations and trends\u00ae in theoretical computer science 9(3-4), 211\u2013407 (2014). https:\/\/doi.org\/10.1561\/0400000042","key":"13_CR11","DOI":"10.1561\/0400000042"},{"doi-asserted-by":"crossref","unstructured":"Gilbert, A.C., Zhang, Y., Lee, K., Zhang, Y., Lee, H.: Towards understanding the invertibility of convolutional neural networks. arXiv preprint arXiv:1705.08664 (2017)","key":"13_CR12","DOI":"10.24963\/ijcai.2017\/236"},{"issue":"1","key":"13_CR13","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3154793","volume":"21","author":"NZ Gong","year":"2018","unstructured":"Gong, N.Z., Liu, B.: Attribute inference attacks in online social networks. ACM Trans. Priv. Secur. (TOPS) 21(1), 1\u201330 (2018)","journal-title":"ACM Trans. Priv. Secur. (TOPS)"},{"unstructured":"Goodfellow, I.J., et al.: Generative adversarial networks. arXiv preprint arXiv:1406.2661 (2014)","key":"13_CR14"},{"unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)","key":"13_CR15"},{"unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. CoRR abs\/1512.03385 (2015). http:\/\/arxiv.org\/abs\/1512.03385","key":"13_CR16"},{"doi-asserted-by":"crossref","unstructured":"He, Z., Zhang, T., Lee, R.B.: Model inversion attacks against collaborative inference. In: Proceedings of the 35th Annual Computer Security Applications Conference, pp. 148\u2013162 (2019)","key":"13_CR17","DOI":"10.1145\/3359789.3359824"},{"issue":"12","key":"13_CR18","doi-asserted-by":"publisher","first-page":"9706","DOI":"10.1109\/JIOT.2020.3022358","volume":"8","author":"Z He","year":"2020","unstructured":"He, Z., Zhang, T., Lee, R.B.: Attacking and protecting data privacy in edge-cloud collaborative inference systems. IEEE Internet Things J. 8(12), 9706\u20139716 (2020)","journal-title":"IEEE Internet Things J."},{"issue":"10","key":"13_CR19","doi-asserted-by":"crossref","first-page":"1529","DOI":"10.1093\/jamia\/ocaa106","volume":"27","author":"S Henry","year":"2020","unstructured":"Henry, S., Wang, Y., Shen, F., Uzuner, O.: The 2019 national natural language processing (NLP) clinical challenges (N2C2)\/open health NLP (OHNLP) shared task on clinical concept normalization for clinical records. J. Am. Med. Inform. Assoc. 27(10), 1529\u20131537 (2020)","journal-title":"J. Am. Med. Inform. Assoc."},{"doi-asserted-by":"crossref","unstructured":"Howard, A., et\u00a0al.: Searching for MobileNetV3. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 1314\u20131324 (2019)","key":"13_CR20","DOI":"10.1109\/ICCV.2019.00140"},{"unstructured":"Huang, Y., Gupta, S., Song, Z., Li, K., Arora, S.: Evaluating gradient inversion attacks and defenses in federated learning. In: NeurIPS (2021)","key":"13_CR21"},{"unstructured":"Huang, Y., et al.: GPipe: efficient training of giant neural networks using pipeline parallelism. arxiv (2018)","key":"13_CR22"},{"unstructured":"Jia, J., Gong, N.Z.: Attriguard: a practical defense against attribute inference attacks via adversarial machine learning. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 18). pp. 513\u2013529 (2018)","key":"13_CR23"},{"doi-asserted-by":"crossref","unstructured":"Jia, J., Wang, B., Zhang, L., Gong, N.Z.: Attriinfer: inferring user attributes in online social networks using Markov random fields. In: Proceedings of the 26th International Conference on World Wide Web, pp. 1561\u20131569 (2017)","key":"13_CR24","DOI":"10.1145\/3038912.3052695"},{"issue":"1","key":"13_CR25","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1038\/sdata.2016.35","volume":"3","author":"AE Johnson","year":"2016","unstructured":"Johnson, A.E., et al.: MIMIC-III, a freely accessible critical care database. Sci. Data 3(1), 1\u20139 (2016)","journal-title":"Sci. Data"},{"unstructured":"Juvekar, C., Vaikuntanathan, V., Chandrakasan, A.: $$\\{$$GAZELLE$$\\}$$: A low latency framework for secure neural network inference. In: 27th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 18), pp. 1651\u20131669 (2018)","key":"13_CR26"},{"doi-asserted-by":"crossref","unstructured":"Kariyappa, S., Prakash, A., Qureshi, M.: Maze: Data-free model stealing attack using zeroth-order gradient estimation. arXiv preprint arXiv:2005.03161 (2020)","key":"13_CR27","DOI":"10.1109\/CVPR46437.2021.01360"},{"unstructured":"K\u00e4rkk\u00e4inen, K., Joo, J.: FairFace: face attribute dataset for balanced race, gender, and age. arXiv preprint arXiv:1908.04913 (2019)","key":"13_CR28"},{"issue":"1","key":"13_CR29","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2514689","volume":"39","author":"D Kifer","year":"2014","unstructured":"Kifer, D., Machanavajjhala, A.: Pufferfish: a framework for mathematical privacy definitions. ACM Trans. Database Syst. (TODS) 39(1), 1\u201336 (2014)","journal-title":"ACM Trans. Database Syst. (TODS)"},{"unstructured":"Krishna, K., Tomar, G.S., Parikh, A.P., Papernot, N., Iyyer, M.: Thieves on sesame street! model extraction of BERT-based APIs. arXiv preprint arXiv:1910.12366 (2019)","key":"13_CR30"},{"unstructured":"Krizhevsky, A., Hinton, G., et\u00a0al.: Learning multiple layers of features from tiny images (2009)","key":"13_CR31"},{"issue":"7553","key":"13_CR32","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y LeCun","year":"2015","unstructured":"LeCun, Y., Bengio, Y., Hinton, G.: Deep learning. Nature 521(7553), 436\u2013444 (2015)","journal-title":"Nature"},{"unstructured":"Lehmkuhl, R., Mishra, P., Srinivasan, A., Popa, R.A.: Muse: secure inference resilient to malicious clients. In: 30th USENIX Security Symposium (USENIX Security 21), pp. 2201\u20132218 (2021)","key":"13_CR33"},{"unstructured":"Li, A., Guo, J., Yang, H., Chen, Y.: DeepObfuscator: adversarial training framework for privacy-preserving image classification (2019)","key":"13_CR34"},{"doi-asserted-by":"crossref","unstructured":"Lindell, Y.: Secure multiparty computation (MPC). Cryptology ePrint Archive (2020)","key":"13_CR35","DOI":"10.1145\/3387108"},{"doi-asserted-by":"crossref","unstructured":"Liu, J., Juuti, M., Lu, Y., Asokan, N.: Oblivious neural network predictions via MiniONN transformations. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 619\u2013631 (2017)","key":"13_CR36","DOI":"10.1145\/3133956.3134056"},{"issue":"4","key":"13_CR37","first-page":"1","volume":"3","author":"S Liu","year":"2019","unstructured":"Liu, S., Du, J., Shrivastava, A., Zhong, L.: Privacy adversarial network: representation learning for mobile data privacy. Proc. ACM Interact. Mob. Wearable Ubiquitous Technol. 3(4), 1\u201318 (2019)","journal-title":"Proc. ACM Interact. Mob. Wearable Ubiquitous Technol."},{"key":"13_CR38","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1109\/TIFS.2021.3138611","volume":"17","author":"X Liu","year":"2021","unstructured":"Liu, X., Wu, B., Yuan, X., Yi, X.: Leia: a lightweight cryptographic neural network inference system at the edge. IEEE Trans. Inf. Forensics Secur. 17, 237\u2013252 (2021)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"13_CR39","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"578","DOI":"10.1007\/978-3-030-58621-8_34","volume-title":"Computer Vision \u2013 ECCV 2020","author":"Z Liu","year":"2020","unstructured":"Liu, Z., Wu, Z., Gan, C., Zhu, L., Han, S.: DataMix: efficient privacy-preserving edge-cloud inference. In: Vedaldi, A., Bischof, H., Brox, T., Frahm, J.-M. (eds.) ECCV 2020. LNCS, vol. 12356, pp. 578\u2013595. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58621-8_34"},{"unstructured":"Liu, Z., Luo, P., Wang, X., Tang, X.: Large-scale CelebFaces attributes (CelebA) dataset. Retrieved August 15(2018), 11 (2018)","key":"13_CR40"},{"doi-asserted-by":"crossref","unstructured":"Lowd, D., Meek, C.: Adversarial learning. In: Proceedings of the Eleventh ACM SIGKDD International Conference on Knowledge Discovery in Data Mining, pp. 641\u2013647 (2005)","key":"13_CR41","DOI":"10.1145\/1081870.1081950"},{"unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)","key":"13_CR42"},{"unstructured":"Mehnaz, S., Li, N., Bertino, E.: Black-box model inversion attribute inference attacks on classification models. arXiv preprint arXiv:2012.03404 (2020)","key":"13_CR43"},{"doi-asserted-by":"crossref","unstructured":"Mireshghallah, F., Taram, M., Jalali, A., Elthakeb, A.T., Tullsen, D., Esmaeilzadeh, H.: Not all features are equal: discovering essential features for preserving prediction privacy. arXiv preprint arXiv:2003.12154 (2020)","key":"13_CR44","DOI":"10.1145\/3442381.3449965"},{"unstructured":"Mireshghallah, F., Taram, M., Ramrakhyani, P., Tullsen, D.M., Esmaeilzadeh, H.: Shredder: learning noise to protect privacy with partial DNN inference on the edge. CoRR abs\/1905.11814 (2019). http:\/\/arxiv.org\/abs\/1905.11814","key":"13_CR45"},{"doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., Houmansadr, A.: Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 739\u2013753. IEEE (2019)","key":"13_CR46","DOI":"10.1109\/SP.2019.00065"},{"key":"13_CR47","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"19","DOI":"10.1007\/978-3-319-46487-9_2","volume-title":"Computer Vision \u2013 ECCV 2016","author":"SJ Oh","year":"2016","unstructured":"Oh, S.J., Benenson, R., Fritz, M., Schiele, B.: Faceless person recognition: privacy implications in social media. In: Leibe, B., Matas, J., Sebe, N., Welling, M. (eds.) ECCV 2016. LNCS, vol. 9907, pp. 19\u201335. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-46487-9_2"},{"issue":"5","key":"13_CR48","doi-asserted-by":"publisher","first-page":"4505","DOI":"10.1109\/JIOT.2020.2967734","volume":"7","author":"SA Osia","year":"2020","unstructured":"Osia, S.A., Shamsabadi, A.S., Sajadmanesh, S., Taheri, A., Katevas, K., Rabiee, H.R., Lane, N.D., Haddadi, H.: A hybrid deep learning architecture for privacy-preserving mobile analytics. IEEE Internet Things J. 7(5), 4505\u20134518 (2020)","journal-title":"IEEE Internet Things J."},{"key":"13_CR49","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1016\/j.neunet.2019.01.012","volume":"113","author":"GI Parisi","year":"2019","unstructured":"Parisi, G.I., Kemker, R., Part, J.L., Kanan, C., Wermter, S.: Continual lifelong learning with neural networks: a review. Neural Netw. 113, 54\u201371 (2019)","journal-title":"Neural Netw."},{"doi-asserted-by":"crossref","unstructured":"Pasquini, D., Ateniese, G., Bernaschi, M.: Unleashing the tiger: inference attacks on split learning. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 2113\u20132129 (2021)","key":"13_CR50","DOI":"10.1145\/3460120.3485259"},{"unstructured":"Reddi, V.J., et\u00a0al.: MLPerf inference benchmark. In: 2020 ACM\/IEEE 47th Annual International Symposium on Computer Architecture (ISCA), pp. 446\u2013459. IEEE (2020)","key":"13_CR51"},{"doi-asserted-by":"crossref","unstructured":"Ridgeway, D., Theofanos, M., Manley, T., Task, C.: Challenge design and lessons learned from the 2018 differential privacy challenges. https:\/\/doi.org\/10.6028\/NIST.TN.2151 (2021)","key":"13_CR52","DOI":"10.6028\/NIST.TN.2151"},{"doi-asserted-by":"crossref","unstructured":"Roy, P.C., Boddeti, V.N.: Mitigating information leakage in image representations: a maximum entropy approach (2019)","key":"13_CR53","DOI":"10.1109\/CVPR.2019.00269"},{"issue":"1\u20134","key":"13_CR54","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1016\/0167-2789(92)90242-F","volume":"60","author":"LI Rudin","year":"1992","unstructured":"Rudin, L.I., Osher, S., Fatemi, E.: Nonlinear total variation based noise removal algorithms. Physica D 60(1\u20134), 259\u2013268 (1992)","journal-title":"Physica D"},{"doi-asserted-by":"crossref","unstructured":"Sabt, M., Achemlal, M., Bouabdallah, A.: Trusted execution environment: what it is, and what it is not. In: 2015 IEEE Trustcom\/BigDataSE\/ISPA, vol.\u00a01, pp. 57\u201364. IEEE (2015)","key":"13_CR55","DOI":"10.1109\/Trustcom.2015.357"},{"doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","key":"13_CR56","DOI":"10.1109\/SP.2017.41"},{"doi-asserted-by":"crossref","unstructured":"Singh, A., et al.: DISCO: dynamic and invariant sensitive channel obfuscation for deep neural networks. arXiv preprint arXiv:2012.11025 (2020)","key":"13_CR57","DOI":"10.1109\/CVPR46437.2021.01195"},{"unstructured":"Tao, Y., McKenna, R., Hay, M., Machanavajjhala, A., Miklau, G.: Benchmarking differentially private synthetic data generation algorithms. arXiv preprint arXiv:2112.09238 (2021)","key":"13_CR58"},{"unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction APIs. In: 25th $$\\{$$USENIX$$\\}$$ Security Symposium ($$\\{$$USENIX$$\\}$$ Security 16), pp. 601\u2013618 (2016)","key":"13_CR59"},{"unstructured":"Ulyanov, D., Vedaldi, A., Lempitsky, V.S.: Deep image prior. CoRR abs\/1711.10925 (2017). http:\/\/arxiv.org\/abs\/1711.10925","key":"13_CR60"},{"doi-asserted-by":"crossref","unstructured":"Vepakomma, P., Singh, A., Gupta, O., Raskar, R.: NoPeek: information leakage reduction to share activations in distributed deep learning. arXiv preprint arXiv:2008.09161 (2020)","key":"13_CR61","DOI":"10.1109\/ICDMW51313.2020.00134"},{"doi-asserted-by":"crossref","unstructured":"Wagh, S., Tople, S., Benhamouda, F., Kushilevitz, E., Mittal, P., Rabin, T.: FALCON: honest-majority maliciously secure framework for private deep learning. arXiv preprint arXiv:2004.02229 (2020)","key":"13_CR62","DOI":"10.2478\/popets-2021-0011"},{"unstructured":"Wang, K.C., Fu, Y., Li, K., Khisti, A., Zemel, R., Makhzani, A.: Variational model inversion attacks. In: Advances in Neural Information Processing Systems, vol. 34 (2021)","key":"13_CR63"},{"issue":"4","key":"13_CR64","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang, Z., Bovik, A.C., Sheikh, H.R., Simoncelli, E.P.: Image quality assessment: from error visibility to structural similarity. IEEE Trans. Image Process. 13(4), 600\u2013612 (2004)","journal-title":"IEEE Trans. Image Process."},{"unstructured":"Xiang, L., Ma, H., Zhang, H., Zhang, Y., Ren, J., Zhang, Q.: Interpretable complex-valued neural networks for privacy protection. arXiv preprint arXiv:1901.09546 (2019)","key":"13_CR65"},{"doi-asserted-by":"crossref","unstructured":"Zhang, R., Isola, P., Efros, A.A., Shechtman, E., Wang, O.: The unreasonable effectiveness of deep features as a perceptual metric. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 586\u2013595 (2018)","key":"13_CR66","DOI":"10.1109\/CVPR.2018.00068"},{"doi-asserted-by":"crossref","unstructured":"Zhang, Y., Jia, R., Pei, H., Wang, W., Li, B., Song, D.: The secret revealer: generative model-inversion attacks against deep neural networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 253\u2013261 (2020)","key":"13_CR67","DOI":"10.1109\/CVPR42600.2020.00033"},{"doi-asserted-by":"crossref","unstructured":"Zhang, Z., Song, Y., Qi, H.: Age progression\/regression by conditional adversarial autoencoder. In: IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE (2017)","key":"13_CR68","DOI":"10.1109\/CVPR.2017.463"},{"doi-asserted-by":"crossref","unstructured":"Zhao, B.Z.H., et al.: On the (in) feasibility of attribute inference attacks on machine learning models. In: 2021 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 232\u2013251. IEEE (2021)","key":"13_CR69","DOI":"10.1109\/EuroSP51992.2021.00025"}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-73116-7_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T15:21:56Z","timestamp":1730301716000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-73116-7_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,31]]},"ISBN":["9783031731150","9783031731167"],"references-count":69,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-73116-7_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2024,10,31]]},"assertion":[{"value":"31 October 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}