{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,5]],"date-time":"2026-05-05T02:50:02Z","timestamp":1777949402145,"version":"3.51.4"},"publisher-location":"Cham","reference-count":57,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032160881","type":"print"},{"value":"9783032160898","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-16089-8_2","type":"book-chapter","created":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T23:18:06Z","timestamp":1777850286000},"page":"16-31","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Lost in\u00a0the\u00a0Averages: Reassessing Record-Specific Privacy Risk Evaluation"],"prefix":"10.1007","author":[{"given":"Nata\u0161a","family":"Kr\u010do","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florent","family":"Gu\u00e9pin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Matthieu","family":"Meeus","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bogdan","family":"Kulynych","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yves-Alexandre","family":"de Montjoye","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"2_CR1","unstructured":"Alan Turing Institute. 2022. Reprosyn"},{"key":"2_CR2","unstructured":"Annamalai, M.S.M.S., Gadotti, A. and Rocher, L.: A linear reconstruction approach for attribute inference attacks against synthetic data. In: USENIX Security (2024)"},{"key":"2_CR3","unstructured":"Annamalai, M.S.M.S., Ganev, G., De Cristofaro, E.: \"What do you want from theory alone?\" experimenting with tight auditing of differentially private synthetic data generation. In: USENIX Security (2024)"},{"key":"2_CR4","doi-asserted-by":"crossref","unstructured":"Azadmanesh, M., Ghahfarokhi, B.S., Talouki, M.A.: A white-box generator membership inference attack against generative models. In: ISCISC (2021)","DOI":"10.1109\/ISCISC53448.2021.9720436"},{"key":"2_CR5","doi-asserted-by":"crossref","unstructured":"Balle, B., Cherubin, G., Hayes, J.: Reconstructing training data with informed adversaries. In: IEEE S&P (2022)","DOI":"10.1109\/SP46214.2022.9833677"},{"key":"2_CR6","unstructured":"Becker, B., Kohavi, R.: Adult. UCI Machine Learning Repository (1996)"},{"key":"2_CR7","unstructured":"Cao, Y., Chen, Z. and Quan, Z.[n.\u00a0d.].: Assessing Insurer\u2019s Litigation Risk: Claim Dispute Prediction with Actionable Interpretations Using Machine Learning Techniques. SSRN 5126964 ([n.\u00a0d.])"},{"key":"2_CR8","doi-asserted-by":"crossref","unstructured":"Carlini, N., Chien, S., Nasr, M., Song, S., Terzis, A., Tramer, F.: Membership Inference Attacks From First Principles. In: IEEE S&P (2022)","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"2_CR9","doi-asserted-by":"crossref","unstructured":"Carlini, N., Jagielski, M., Zhang, C., Papernot, N., Terzis, A., Tramer, F.: The privacy onion effect: Memorization is relative. In: NeurIPS (2022)","DOI":"10.52202\/068431-0964"},{"key":"2_CR10","doi-asserted-by":"crossref","unstructured":"Chhikara, H., Chhikara, S., Gupta, L.: Predictive analytics in finance: leveraging ai and machine learning for investment strategies. In: Utilizing AI and Machine Learning in Financial Analysis. IGI Global Scientific Publishing (2025)","DOI":"10.4018\/979-8-3693-8507-4.ch017"},{"key":"2_CR11","unstructured":"Choquette-Choo, C.A., Tramer, F., Carlini, N., Papernot, N.: Label-only membership inference attacks. In: ICML (2021)"},{"key":"2_CR12","doi-asserted-by":"crossref","unstructured":"D Cretu, A.M., Jones, D., de Montjoye, Y.A., Tople, S.: Investigating the effect of misalignment on membership privacy in the white-box setting. In: PoPETS (2024)","DOI":"10.56553\/popets-2024-0085"},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Dong, J., Roth, A., Su, W.J.: Gaussian differential privacy. J. Royal Stat. Society: Series B (Statistical Methodology) (2022)","DOI":"10.1111\/rssb.12454"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Dwork, C.: Differential Privacy. In: ICALP (Lecture Notes in Computer Science) (2006)","DOI":"10.1007\/11787006_1"},{"key":"2_CR15","doi-asserted-by":"crossref","unstructured":"Dwork, C., Roth, A., et\u00a0al.: The algorithmic foundations of differential privacy (2014)","DOI":"10.1561\/9781601988195"},{"key":"2_CR16","doi-asserted-by":"crossref","unstructured":"Feldman, V.: Does learning require memorization? a short tale about a long tail. In: ACM SIGACT Symposium on Theory of Computing 2020","DOI":"10.1145\/3357713.3384290"},{"key":"2_CR17","unstructured":"Georgi Ganev, Meenatchi Sundaram Muthu\u00a0Selva Annamalai, and Emiliano De\u00a0Cristofaro. 2025. The Elusive Pursuit of Reproducing PATE-GAN: Benchmarking, Auditing, Debugging. TMLR (2025)"},{"key":"2_CR18","volume-title":"2024","author":"V Guan","year":"2024","unstructured":"Guan, V., Gu\u00e9pin, F., Cretu, A.-M., de Montjoye, Y.-A.: 2024. A zero auxiliary knowledge membership inference attack on aggregate location data, PoPETS (2024)"},{"key":"2_CR19","doi-asserted-by":"crossref","unstructured":"Gu\u00e9pin, F., Meeus, M., Cre\u0163u, A.-M., de Montjoye, Y.A..: Synthetic is all you need: removing the auxiliary data assumption for membership inference attacks against synthetic data. In: ESORICS (2023)","DOI":"10.1007\/978-3-031-54204-6_10"},{"key":"2_CR20","doi-asserted-by":"crossref","unstructured":"Hayes, J., Melis, L., Danezis, G., De Cristofaro, E.: LOGAN: membership inference attacks against generative models. In: PoPETS (2019)","DOI":"10.2478\/popets-2019-0008"},{"key":"2_CR21","doi-asserted-by":"crossref","unstructured":"He, Z., Zhang, T., Lee, R.B.: Model inversion attacks against collaborative inference. In: Computer Security Applications Conference (2019)","DOI":"10.1145\/3359789.3359824"},{"key":"2_CR22","unstructured":"Houssiau, F., et al.: Tapas: a toolbox for adversarial privacy auditing of synthetic data (2022)"},{"key":"2_CR23","unstructured":"Jagielski, M., Ullman, J., Oprea, A.: Auditing differentially private machine learning: how private is private SGD?. In: NeurIPS (2020)"},{"key":"2_CR24","doi-asserted-by":"crossref","unstructured":"Jayaraman, B., Wang, L., Knipmeyer, K., Gu, Q., Evans, D.: Revisiting membership inference under realistic assumptions. In: PoPETS 2021 (2021)","DOI":"10.2478\/popets-2021-0031"},{"key":"2_CR25","unstructured":"Kairouz, P., Oh, S., Viswanath, P.: The composition theorem for differential privacy. In: ICML (2015)"},{"key":"2_CR26","unstructured":"Kulynych, B., Gomez, J.F., Kaissis, G., Calmon, F., Troncoso, C.: Attack-aware noise calibration for differential privacy. In: NeurIPS (2024)"},{"key":"2_CR27","volume-title":"2022","author":"B Kulynych","year":"2022","unstructured":"Kulynych, B., Yaghini, M., Cherubin, G., Veale, M., Troncoso, C.: 2022. Disparate Vulnerability to Membership Inference Attacks, PoPETS (2022)"},{"key":"2_CR28","unstructured":"Kumar, S., Shokri, R.: ML Privacy Meter: Aiding regulatory compliance by quantifying the privacy risks of machine learning. In: Workshop on Hot Topics in Privacy Enhancing Technologies (HotPETs) (2020)"},{"key":"2_CR29","doi-asserted-by":"crossref","unstructured":"Lotan, E., et al.: Medical imaging and privacy in the era of artificial intelligence: myth, fallacy, and the future. J. Am. Coll. Radiol. (2020)","DOI":"10.1016\/j.jacr.2020.04.007"},{"key":"2_CR30","doi-asserted-by":"crossref","unstructured":"Matsumoto, T., Miura, T., Yanai, N.: Membership inference attacks against diffusion models. In: IEEE S&P Workshops (SPW) (2023)","DOI":"10.1109\/SPW59333.2023.00013"},{"key":"2_CR31","doi-asserted-by":"crossref","unstructured":"Meeus, M., Guepin, F., Cre\u0163u, A.M., de Montjoye, Y.A.: Achilles\u2019 heels: vulnerable record identification in synthetic data publishing. In: ESORICS (2023)","DOI":"10.1007\/978-3-031-51476-0_19"},{"key":"2_CR32","unstructured":"Meeus, M., Wutschitz, L., Zanella-B\u00e9guelin, S., Tople, S., Shokri, R.: The Canary\u2019s Echo: Auditing Privacy Risks of LLM-Generated Synthetic Text (2025)"},{"key":"2_CR33","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., Houmansadr, A.: Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In: IEEE S&P (2019)","DOI":"10.1109\/SP.2019.00065"},{"key":"2_CR34","doi-asserted-by":"crossref","unstructured":"Nasr, M., Song, S., Thakurta, A., Papernot, N., Carlini, N.: Lower Bounds for Differentially Private Machine Learning. In: IEEE S&P, Adversary Instantiation (2021)","DOI":"10.1109\/SP40001.2021.00069"},{"key":"2_CR35","doi-asserted-by":"crossref","unstructured":"Nowok, B., Raab, G.M., Dibben, C.: synthpop: Bespoke Creation of Synthetic Data in R. J. Stat. Softw. (2016)","DOI":"10.18637\/jss.v074.i11"},{"key":"2_CR36","unstructured":"Office for National Statistics. 2011. Census Microdata Teaching Files"},{"key":"2_CR37","doi-asserted-by":"crossref","unstructured":"Osuala, R., Lang, D.M., Riess, A.: Enhancing the utility of privacy-preserving cancer classification using synthetic data. In: Artificial Intelligence and Imaging for Diagnostic and Treatment Challenges in Breast Care. Springer Nature Switzerland (2025)","DOI":"10.1007\/978-3-031-77789-9_6"},{"key":"2_CR38","doi-asserted-by":"crossref","unstructured":"Pang, Y., Wang, T., Kang, X., Huai, M., Zhang, Y.: White-box Membership Inference Attacks against Diffusion Models (2025)","DOI":"10.14722\/ndss.2025.230324"},{"key":"2_CR39","doi-asserted-by":"crossref","unstructured":"Ping, H., Stoyanovich, J., Howe, B.: DataSynthesizer: Privacy-Preserving Synthetic Datasets (SSDBM). In: ACM (2017)","DOI":"10.1145\/3085504.3091117"},{"key":"2_CR40","unstructured":"Pollock, J., Shilov, I., Dodd, E., de Montjoye, Y.A.: Free Record-Level Privacy Risk Evaluation Through Artifact-Based Methods. arXiv preprint arXiv:2411.05743 (2024)"},{"key":"2_CR41","doi-asserted-by":"crossref","unstructured":"Pyrgelis, A., Troncoso, C., De\u00a0Cristofaro, E.: Knock Knock, Who\u2019s There? Membership Inference on Aggregate Location Data. (2018)","DOI":"10.14722\/ndss.2018.23183"},{"key":"2_CR42","unstructured":"Sablayrolles, A., Douze, M., Schmid, C., Ollivier, Y., Herv\u00e9 J\u00e9gou.: White-box vs black-box, Bayes optimal strategies for membership inference (2019). In: ICML (2019)"},{"key":"2_CR43","doi-asserted-by":"crossref","unstructured":"Salem, A.: SoK: Let the privacy games begin! A unified treatment of data inference privacy in machine learning. In: IEEE S&P (2023)","DOI":"10.1109\/SP46215.2023.10179281"},{"key":"2_CR44","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: IEEE S&P (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"2_CR45","unstructured":"Song, L., Mittal, P.: Systematic evaluation of privacy risks of machine learning models. In: USENIX Security (2021)"},{"key":"2_CR46","unstructured":"Stadler, T., Oprisanu, B., Troncoso, C.: Synthetic data\u2013anonymisation groundhog day. In: USENIX Security (2022)"},{"key":"2_CR47","unstructured":"Synthetic Data Expert Group, Financial Conduct Authority. 2024. Report: Using Synthetic Data in Financial Services (2024)"},{"key":"2_CR48","unstructured":"Tramer, F., Terzis, A., Steinke, T., Song, S., Jagielski, M., Carlini, N.: Debugging Differential Privacy, A Case Study for Privacy Auditing (2022)"},{"key":"2_CR49","doi-asserted-by":"crossref","unstructured":"Wang, Z., Song, M., Zhang, Z., Song, Y., Wang, Q., Qi, H.: Beyond inferring class representatives: User-level privacy leakage from federated learning. In: IEEE INFOCOM 2019-IEEE Conference on Computer Communications (2019)","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"2_CR50","doi-asserted-by":"crossref","unstructured":"Wasserman, L., Zhou, S.: A statistical framework for differential privacy. J. Amer, Statist, Assoc (2010)","DOI":"10.1198\/jasa.2009.tm08651"},{"key":"2_CR51","unstructured":"Watson, L., Guo, C., Cormode, G., Sablayrolles, A.: On the importance of difficulty calibration in membership inference attacks. In: International Conference on Learning Representations"},{"key":"2_CR52","unstructured":"Lei, X., Skoularidou, M., Cuesta-Infante, A., Veeramachaneni, K.: Modeling tabular data using conditional gan, In: NeurIPS (2019)"},{"key":"2_CR53","unstructured":"Yang, Z., Zhang, J., Chang, E.C., Liang, Z.: Neural network inversion in adversarial setting via background knowledge alignment. In: ACM CCS"},{"key":"2_CR54","doi-asserted-by":"crossref","unstructured":"Ye, J., Maddi, A., Murakonda, S.K., Bindschaedler, V., Shokri, R.: Enhanced membership inference attacks against machine learning models. In: ACM CCS (2022)","DOI":"10.1145\/3548606.3560675"},{"key":"2_CR55","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., Jha, S.: Privacy risk in machine learning: analyzing the connection to overfitting. In: IEEE Computer Security Foundations Symposium (2018)","DOI":"10.1109\/CSF.2018.00027"},{"key":"2_CR56","unstructured":"Zarifzadeh, S., Liu, P., Shokri, R.: Low-cost high-power membership inference attacks. In: ICML (2024)"},{"key":"2_CR57","unstructured":"Zhang, J., Cormode, G., Procopiuc, C.M., Srivastava, D., Xiao, X.: Private Data Release via Bayesian Networks, PrivBayes (2017)"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2025 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-16089-8_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T23:18:10Z","timestamp":1777850290000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-16089-8_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032160881","9783032160898"],"references-count":57,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-16089-8_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}