{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T06:03:12Z","timestamp":1780466592110,"version":"3.54.1"},"publisher-location":"Singapore","reference-count":36,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819557158","type":"print"},{"value":"9789819557165","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-5716-5_21","type":"book-chapter","created":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T13:07:36Z","timestamp":1769087256000},"page":"333-351","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Counterfactual Adversarial Examples for\u00a0Mitigating Privacy Risk in\u00a0Adversarially Robust Models"],"prefix":"10.1007","author":[{"given":"Aohan","family":"Sun","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanrong","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wencheng","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ji","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,1,23]]},"reference":[{"key":"21_CR1","doi-asserted-by":"publisher","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. In: International Conference on Learning Representations (2015). https:\/\/doi.org\/10.48550\/arXiv.1412.6572","DOI":"10.48550\/arXiv.1412.6572"},{"key":"21_CR2","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Frossard, P.: Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2574\u20132582 (2016)","DOI":"10.1109\/CVPR.2016.282"},{"key":"21_CR3","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE Symposium on Security and Privacy, pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"21_CR4","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. In: International Conference on Learning Representations. vol.\u00a06, pp. 4138\u20134160 (2018)"},{"key":"21_CR5","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1322\u20131333 (2015)","DOI":"10.1145\/2810103.2813677"},{"key":"21_CR6","doi-asserted-by":"crossref","unstructured":"Ganju, K., Wang, Q., Yang, W., Gunter, C.A., Borisov, N.: Property inference attacks on fully connected neural networks using permutation invariant representations. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, pp. 619\u2013633 (2018)","DOI":"10.1145\/3243734.3243834"},{"key":"21_CR7","unstructured":"Salem, A., Bhattacharya, A., Backes, M., Fritz, M., Zhang, Y.: Updates-leak: data set inference and reconstruction attacks in online learning. In: 29th USENIX Security Symposium, pp. 1291\u20131308 (2020)"},{"key":"21_CR8","doi-asserted-by":"crossref","unstructured":"Song, L., Shokri, R., Mittal, P.: Privacy risks of securing machine learning models against adversarial examples. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 241\u2013257. ACM, London United Kingdom (2019)","DOI":"10.1145\/3319535.3354211"},{"issue":"5","key":"21_CR9","doi-asserted-by":"publisher","first-page":"3183","DOI":"10.1109\/TDSC.2021.3088480","volume":"19","author":"H Huang","year":"2021","unstructured":"Huang, H., Luo, W., Zeng, G., Weng, J., Zhang, Y., Yang, A.: DAMIA: leveraging domain adaptation as a defense against membership inference attacks. IEEE Trans. Depend. Secure Comput. 19(5), 3183\u20133199 (2021)","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"21_CR10","doi-asserted-by":"crossref","unstructured":"Liu, Y., Zhao, Z., Backes, M., Zhang, Y.: Membership inference attacks by exploiting loss trajectory. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, pp. 2085\u20132098 (2022)","DOI":"10.1145\/3548606.3560684"},{"key":"21_CR11","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E., El\u00a0Ghaoui, L., Jordan, M.: Theoretically principled trade-off between robustness and accuracy. In: International Conference on Machine Learning, pp. 7472\u20137482. PMLR (2019)"},{"key":"21_CR12","doi-asserted-by":"crossref","unstructured":"Hopkins, S.B., Kamath, G., Majid, M., Narayanan, S.: Robustness implies privacy in statistical estimation. In: Proceedings of the 55th Annual ACM Symposium on Theory of Computing, pp. 497\u2013506 (2023)","DOI":"10.1145\/3564246.3585115"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., Jha, S.: Privacy risk in machine learning: analyzing the connection to overfitting. In: 2018 IEEE 31st Computer Security Foundations Symposium, pp. 268\u2013282. IEEE (2018)","DOI":"10.1109\/CSF.2018.00027"},{"key":"21_CR14","doi-asserted-by":"publisher","unstructured":"Kim, B., Seo, J., Jeon, T.: Bridging adversarial robustness and gradient interpretability. In: ICLR Workshop on Safe Machine Learning: Specification, Robustness, and Assurance (2019). https:\/\/doi.org\/10.48550\/arXiv.1903.11626","DOI":"10.48550\/arXiv.1903.11626"},{"key":"21_CR15","unstructured":"Tsipras, D., Santurkar, S., Engstrom, L., Turner, A., Madry, A.: Robustness may be at odds with accuracy. In: International Conference on Learning Representations. vol.\u00a04, pp. 2394\u20132416 (2019)"},{"key":"21_CR16","doi-asserted-by":"crossref","unstructured":"Ren, Q., Chen, Y., Mo, Y., Wu, Q., Yan, J.: DICE: domain-attack invariant causal learning for improved data privacy protection and adversarial robustness. In: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 1483\u20131492. ACM, Washington DC USA (2022)","DOI":"10.1145\/3534678.3539242"},{"key":"21_CR17","unstructured":"Awasthi, P., Mao, A., Mohri, M., Zhong, Y.: Theoretically grounded loss functions and algorithms for adversarial robustness. In: International Conference on Artificial Intelligence and Statistics, pp. 10077\u201310094. PMLR (2023)"},{"issue":"5","key":"21_CR18","doi-asserted-by":"publisher","first-page":"2770","DOI":"10.1007\/s10618-022-00831-6","volume":"38","author":"R Guidotti","year":"2024","unstructured":"Guidotti, R.: Counterfactual explanations and how to find them: literature review and benchmarking. Data Min. Knowl. Disc. 38(5), 2770\u20132824 (2024)","journal-title":"Data Min. Knowl. Disc."},{"key":"21_CR19","doi-asserted-by":"crossref","unstructured":"Ribeiro, M.T., Singh, S., Guestrin, C.: \u201cWhy should i trust you?\u201d: explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1135\u20131144 (2016)","DOI":"10.1145\/2939672.2939778"},{"key":"21_CR20","unstructured":"Dhurandhar, A., Chen, P.Y., Luss, R., Tu, C.C., Ting, P., Shanmugam, K., Das, P.: Explanations based on the missing: towards contrastive explanations with pertinent negatives. In: Proceedings of the 32nd International Conference on Neural Information Processing Systems, pp. 590\u2013601 (2018)"},{"key":"21_CR21","doi-asserted-by":"crossref","unstructured":"Van\u00a0Looveren, A., Klaise, J.: Interpretable counterfactual explanations guided by prototypes. In: Joint European Conference on Machine Learning and Knowledge Discovery in Databases, pp. 650\u2013665 (2021)","DOI":"10.1007\/978-3-030-86520-7_40"},{"key":"21_CR22","unstructured":"Pawelczyk, M., Agarwal, C., Joshi, S., Upadhyay, S., Lakkaraju, H.: Exploring counterfactual explanations through the lens of adversarial examples: a theoretical and empirical analysis. In: International Conference on Artificial Intelligence and Statistics, pp. 4574\u20134594. PMLR (2022)"},{"key":"21_CR23","unstructured":"Boopathy, A., et al.: Proper network interpretability helps adversarial robustness in classification. In: International Conference on Machine Learning, pp. 1014\u20131023. PMLR (2020)"},{"key":"21_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.artint.2022.103840","volume":"316","author":"M Virgolin","year":"2023","unstructured":"Virgolin, M., Fracaros, S.: On the robustness of sparse counterfactual explanations to adverse perturbations. Artif. Intell. 316, 103840 (2023)","journal-title":"Artif. Intell."},{"key":"21_CR25","doi-asserted-by":"crossref","unstructured":"Jiang, J., Leofante, F., Rago, A., Toni, F.: Formalising the robustness of counterfactual explanations for neural networks. In: Proceedings of the AAAI Conference on Artificial Intelligence. vol.\u00a037, pp. 14901\u201314909 (2023)","DOI":"10.1609\/aaai.v37i12.26740"},{"key":"21_CR26","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy. pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"21_CR27","doi-asserted-by":"crossref","unstructured":"Hayes, J., Melis, L., Danezis, G., De\u00a0Cristofaro, E.: Logan: membership inference attacks against generative models. In: Proceedings on Privacy Enhancing Technologies. vol.\u00a02019, pp. 133\u2013152. De Gruyter (2019)","DOI":"10.2478\/popets-2019-0008"},{"key":"21_CR28","doi-asserted-by":"crossref","unstructured":"Chen, J., Wang, W.H., Shi, X.: Differential privacy protection against membership inference attack on machine learning for genomic data. In: BIOCOMPUTING 2021: Proceedings of the Pacific Symposium, pp. 26\u201337. World Scientific (2020)","DOI":"10.1142\/9789811232701_0003"},{"issue":"11","key":"21_CR29","doi-asserted-by":"publisher","first-page":"2969","DOI":"10.1093\/comjnl\/bxac080","volume":"65","author":"Z Zhang","year":"2022","unstructured":"Zhang, Z., Zhang, L.Y., Zheng, X., Abbasi, B.H., Hu, S.: Evaluating membership inference through adversarial robustness. Comput. J. 65(11), 2969\u20132978 (2022)","journal-title":"Comput. J."},{"key":"21_CR30","doi-asserted-by":"crossref","unstructured":"Jia, J., Salem, A., Backes, M., Zhang, Y., Gong, N.Z.: Memguard: defending against black-box membership inference attacks via adversarial examples. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 259\u2013274 (2019)","DOI":"10.1145\/3319535.3363201"},{"issue":"2","key":"21_CR31","doi-asserted-by":"publisher","first-page":"717","DOI":"10.1214\/23-AOS2267","volume":"51","author":"M Li","year":"2023","unstructured":"Li, M., Berrett, T.B., Yu, Y.: On robustness and local differential privacy. Ann. Stat. 51(2), 717\u2013737 (2023)","journal-title":"Ann. Stat."},{"key":"21_CR32","doi-asserted-by":"crossref","unstructured":"Song, C., Ristenpart, T., Shmatikov, V.: Machine learning models that remember too much. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 587\u2013601 (2017)","DOI":"10.1145\/3133956.3134077"},{"key":"21_CR33","doi-asserted-by":"crossref","unstructured":"Hajihassani, O., Ardakanian, O., Khazaei, H.: Latent representation learning and manipulation for privacy-preserving sensor data analytics. In: 2020 IEEE Second Workshop on Machine Learning on Edge in Sensor Systems, pp. 7\u201312. IEEE (2020)","DOI":"10.1109\/SenSysML50931.2020.00009"},{"issue":"1","key":"21_CR34","first-page":"152","volume":"4","author":"V Raja","year":"2024","unstructured":"Raja, V.: Fostering privacy in collaborative data sharing via auto-encoder latent space embedding. J. Artif. Intell. General Sci. 4(1), 152\u2013162 (2024)","journal-title":"J. Artif. Intell. General Sci."},{"key":"21_CR35","doi-asserted-by":"crossref","unstructured":"Xiao, C., Li, B., Zhu, J., He, W., Liu, M., Song, D.: Generating adversarial examples with adversarial networks. In: Proceedings of the 27th International Joint Conference on Artificial Intelligence, pp. 3905\u20133911 (2018)","DOI":"10.24963\/ijcai.2018\/543"},{"issue":"11","key":"21_CR36","first-page":"2579","volume":"9","author":"L Van der Maaten","year":"2008","unstructured":"Van der Maaten, L., Hinton, G.: Visualizing data using t-SNE. J. Mach. Learn. Res. 9(11), 2579\u20132605 (2008)","journal-title":"J. Mach. Learn. Res."}],"container-title":["Lecture Notes in Computer Science","Web and Big Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-5716-5_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,22]],"date-time":"2026-01-22T13:07:49Z","timestamp":1769087269000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-5716-5_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819557158","9789819557165"],"references-count":36,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-5716-5_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"23 January 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"APWeb-WAIM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Asia-Pacific Web (APWeb) and Web-Age Information Management (WAIM) Joint International Conference on Web and Big Data","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Shenyang","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"apwebwaim2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/apweb2025.sau.edu.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}