{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T21:41:02Z","timestamp":1784238062220,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":108,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819712731","type":"print"},{"value":"9789819712748","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-981-97-1274-8_6","type":"book-chapter","created":{"date-parts":[[2024,3,12]],"date-time":"2024-03-12T19:20:02Z","timestamp":1710271202000},"page":"76-95","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":25,"title":["A Comprehensive Survey of Attack Techniques, Implementation, and Mitigation Strategies in Large Language Models"],"prefix":"10.1007","author":[{"given":"Aysan","family":"Esmradi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Daniel Wankit","family":"Yip","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chun Fai","family":"Chan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,3,13]]},"reference":[{"key":"6_CR1","unstructured":"OpenAI Homepage. https:\/\/openai.com\/"},{"key":"6_CR2","unstructured":"OpenAI. GPT-4 Technical Report. arXiv:2303.08774 (2023)"},{"key":"6_CR3","unstructured":"Radford, A., Wu, J., et al.: Language models are unsupervised multitask learners (2019)"},{"key":"6_CR4","unstructured":"Gozalo-Brizuela, R., Garrido-Merchan, E.C.: Chat-GPT is not all you need. A state of the art review of large generative AI MODELS. arXiv:2301.04655 (2023)"},{"key":"6_CR5","unstructured":"Cao, Y., Li, S., Liu, Y., et al.: A comprehensive survey of AI-generated content (AIGC): a history of generative AI from GAN to ChatGPT. arXiv:2303.04226 (2023)"},{"key":"6_CR6","unstructured":"Zhou, C., Li, Q., Li, C., et al.: A comprehensive survey on pretrained foundation models: a history from BERT to ChatGPT. arXiv:2302.09419 (2023)"},{"key":"6_CR7","doi-asserted-by":"crossref","unstructured":"Huang, X., Ruan, W., et al.: A survey of safety and trustworthiness of large language models through the lens of verification and validation. arXiv:2305.11391 (2023)","DOI":"10.1007\/s10462-024-10824-0"},{"key":"6_CR8","doi-asserted-by":"crossref","unstructured":"Yenduri, G., Ramalingam, M., Chemmalar Selvi, G., Supriya, Y., Srivastava, G., et al.: Generative pre-trained transformer: a comprehensive review on enabling technologies, potential applications, emerging challenges, and future directions. arXiv:2305.10435 (2023)","DOI":"10.1109\/ACCESS.2024.3389497"},{"key":"6_CR9","doi-asserted-by":"crossref","unstructured":"Wang, Y., Pan, Y., Yan, M., Su, Z., Luan, T.H.: A survey on ChatGPT: AI-generated contents, challenges, and solutions. arXiv:2305.18339 (2023)","DOI":"10.1109\/OJCS.2023.3300321"},{"key":"6_CR10","unstructured":"Liu, Y., Yao, Y., Ton, J., et al.: Trustworthy LLMs: a survey and guideline for evaluating large language models\u2019 alignment. arXiv:2308.05374 (2023)"},{"key":"6_CR11","unstructured":"Fan, M., Chen, C., Wang, C., Huang, J.: On the trustworthiness landscape of state-of-the-art generative models: a comprehensive survey. arXiv:2307.16680 (2023)"},{"key":"6_CR12","unstructured":"NSFOCUS Article. https:\/\/nsfocusglobal.com\/8-potential-security-hazards-of-chatgpt\/"},{"key":"6_CR13","unstructured":"Choi, E., Jo, Y., Jang, J., Seo, M.: Prompt injection: parameterization of fixed inputs. arXiv:2206.11349 (2022)"},{"key":"6_CR14","unstructured":"Simon Willison\u2019s Blog Post. https:\/\/simonwillison.net\/2022\/Sep\/12\/prompt-injection\/"},{"key":"6_CR15","unstructured":"Tweet by Goodside. https:\/\/twitter.com\/goodside\/status\/1569128808308957185"},{"key":"6_CR16","unstructured":"Greshake, K., Abdelnabi, S., Mishra, S., et al.: More than you\u2019ve asked for: a comprehensive analysis of novel prompt injection threats to application-integrated large language models. arXiv:2302.12173 (2023)"},{"key":"6_CR17","doi-asserted-by":"crossref","unstructured":"Greshake, K., Abdelnabi, S., Mishra, S., et al.: Not what you\u2019ve signed up for: compromising real-world LLM-integrated applications with indirect prompt injection. arXiv:2302.12173 (2023)","DOI":"10.1145\/3605764.3623985"},{"key":"6_CR18","doi-asserted-by":"crossref","unstructured":"Kang, D., Li, X., Stoica, I., et al.: Exploiting programmatic behavior of LLMs: dual-use through standard security attacks. arXiv:2302.05733 (2023)","DOI":"10.1109\/SPW63631.2024.00018"},{"key":"6_CR19","unstructured":"Perez, F., Ribeiro, I.: Ignore previous prompt: attack techniques for language models. arXiv:2211.09527 (2022)"},{"key":"6_CR20","unstructured":"Liu, Y., Deng, G., Xu, Z., Li, Y., et al.: Jailbreaking ChatGPT via prompt engineering: an empirical study. arXiv:2305.13860 (2023)"},{"key":"6_CR21","doi-asserted-by":"crossref","unstructured":"Li, H., Guo, D., Fan, W., et al.: Multi-step jailbreaking privacy attacks on ChatGPT. arXiv:2304.05197 (2023)","DOI":"10.18653\/v1\/2023.findings-emnlp.272"},{"key":"6_CR22","unstructured":"Wei, A., Haghtalab, N., Steinhardt, J.: Jailbroken: how does LLM safety training fail? arXiv:2307.02483 (2023)"},{"key":"6_CR23","unstructured":"GitHub Repository. https:\/\/github.com\/0xk1h0\/ChatGPT_DAN"},{"key":"6_CR24","unstructured":"Medium Article. https:\/\/medium.com\/@neonforge\/upgraded-dan-version-for-chatgpt-is-here-new-shiny-and-more-unchained-63d82919d804"},{"key":"6_CR25","unstructured":"Kojima, T., Gu, S.S., Reid, M., Matsuo, Y., Iwasawa, Y.: Large language models are zero-shot reasoners. arXiv:2205.11916 (2023)"},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Shaikh, O., Zhang, H., Held, W., Bernstein, M., Yang, D.: On second thought, let\u2019s not think step by step! Bias and toxicity in zero-shot reasoning. arXiv:2212.08061 (2023)","DOI":"10.18653\/v1\/2023.acl-long.244"},{"key":"6_CR27","doi-asserted-by":"crossref","unstructured":"Jones, E., Jia, R., Raghunathan, A., Liang, P. Robust encodings: a framework for combating adversarial typos. arXiv preprint arXiv:2005.01229 (2020)","DOI":"10.18653\/v1\/2020.acl-main.245"},{"key":"6_CR28","unstructured":"WikiHow Article. https:\/\/www.wikihow.com\/Bypass-Chat-Gpt-Filter"},{"key":"6_CR29","unstructured":"Gigazine Article. https:\/\/gigazine.net\/news\/20221215-chatgpt-safeguard\/"},{"key":"6_CR30","unstructured":"GitHub Repository. https:\/\/github.com\/f\/awesome-chatgpt-prompts"},{"key":"6_CR31","unstructured":"Mashable Article. https:\/\/mashable.com\/article\/chatgpt-bard-giving-free-windows-11-keys"},{"key":"6_CR32","unstructured":"Reddit Post. https:\/\/www.reddit.com\/r\/ChatGPT\/comments\/zjfht5\/bypassing-restrictions\/"},{"key":"6_CR33","doi-asserted-by":"crossref","unstructured":"He, X., Lin, Z., Gong, Y., et al.: AnnoLLM: making large language models to be better crowdsourced annotators. arXiv:2303.16854 (2023)","DOI":"10.18653\/v1\/2024.naacl-industry.15"},{"key":"6_CR34","unstructured":"Wei, J., Wang, X., Schuurmans, D., et al.: Chain-of-thought prompting elicits reasoning in large language models. arXiv:2201.11903 (2023)"},{"key":"6_CR35","unstructured":"Microsoft Blog. https:\/\/blogs.microsoft.com\/blog\/2023\/02\/07\/reinventing-search-with-a-new-ai-powered-microsoft-bing-and-edge-your-copilot-for-the-web\/"},{"key":"6_CR36","unstructured":"OpenAI Blog. https:\/\/openai.com\/blog\/chatgpt-plugins"},{"key":"6_CR37","unstructured":"Post. https:\/\/embracethered.com\/blog\/posts\/2023\/chatgpt-plugin-vulns-chat-with-code\/"},{"key":"6_CR38","unstructured":"Embrace the Red Blog Post. https:\/\/embracethered.com\/blog\/posts\/2023\/chatgpt-chat-with-code-plugin-take-down\/"},{"key":"6_CR39","unstructured":"Render App. https:\/\/prompt-injection.onrender.com\/"},{"key":"6_CR40","unstructured":"Saha Roy, S., Naragam, K.V., Nilizadeh, S.: Generating phishing attacks using ChatGPT. arXiv:2305.05133 (2023)"},{"key":"6_CR41","unstructured":"Embrace the Red Blog Post. https:\/\/embracethered.com\/blog\/posts\/2023\/chatgpt-plugin-youtube-indirect-prompt-injection\/"},{"key":"6_CR42","unstructured":"Kai Greshake\u2019s Blog Post. https:\/\/kai-greshake.de\/posts\/inject-my-pdf\/"},{"key":"6_CR43","unstructured":"Tom\u2019s Hardware Article. https:\/\/www.tomshardware.com\/news\/chatgpt-plugins-prompt-injection"},{"key":"6_CR44","unstructured":"OpenAI Website. https:\/\/openai.com\/gpt-4"},{"key":"6_CR45","unstructured":"Ouyang, L., Wu, J. Jiang, X., et al.: Training language models to follow instructions with human feedback. In: NeurIPS (2022)"},{"key":"6_CR46","unstructured":"Bloomberg Article. https:\/\/www.bloomberg.com\/news\/articles\/2023-05-02\/samsung-bans-chatgpt-and-other-generative-ai-use-by-staff-after-leak"},{"key":"6_CR47","unstructured":"OpenAI Blog. https:\/\/openai.com\/blog\/march-20-chatgpt-outage"},{"key":"6_CR48","unstructured":"Xie, S., Dai, W., Ghosh, E., Roy, S., Schwartz, D., Laine, K.: Does prompt-tuning language model ensure privacy? arXiv:2304.03472 (2023)"},{"key":"6_CR49","unstructured":"Brown, T., Mann, B., Ryder, N., et al.: Language models are few-shot learners. arXiv:2005.14165 (2020)"},{"key":"6_CR50","unstructured":"Zhang, Y., Ippolito, D.: Prompts should not be seen as secrets: systematically measuring prompt extraction attack success. arXiv:2307.06865 (2023)"},{"key":"6_CR51","unstructured":"OpenAI. https:\/\/openai.com\/policies\/privacy-policy"},{"key":"6_CR52","doi-asserted-by":"crossref","unstructured":"Shumailov, I., Zhao, Y., Bates, D., Papernot, N., Mullins, R., Anderson, R.: Sponge examples: energy-latency attacks on neural networks. In: Proceedings of IEEE European Symposium on Security and Privacy (EuroS&P), pp. 212\u2013231. IEEE (2021)","DOI":"10.1109\/EuroSP51992.2021.00024"},{"key":"6_CR53","unstructured":"Tramer, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction APIs. In: Proceedings of USENIX Security, vol. 16, pp. 601\u2013618 (2016)"},{"key":"6_CR54","doi-asserted-by":"crossref","unstructured":"Wang, B., Gong, N.Z.: Stealing hyperparameters in machine learning. In: Proceedings of IEEE SP, pp. 36\u201352 (2018)","DOI":"10.1109\/SP.2018.00038"},{"key":"6_CR55","unstructured":"Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., Papernot, N.: High accuracy and high fidelity extraction of neural networks. In: 29th USENIX Security Symposium (USENIX Security 2020), pp. 1345\u20131362 (2020)"},{"key":"6_CR56","unstructured":"Chandrasekaran, V., Chaudhuri, K., Giacomelli, I., Jha, S., Yan, S.: Exploring connections between active learning and model extraction. In: 29th USENIX Security Symposium (USENIX Security 2020), pp. 1309\u20131326 (2020)"},{"key":"6_CR57","doi-asserted-by":"crossref","unstructured":"Juuti, M., Szyller, S., Marchal, S., Asokan, N.: Prada: protecting against DNN model stealing attacks. In: 2019 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 512\u2013527. IEEE (2019)","DOI":"10.1109\/EuroSP.2019.00044"},{"key":"6_CR58","doi-asserted-by":"crossref","unstructured":"Kesarwani, M., Mukhoty, B., Arya, V., Mehta, S.: Model extraction warning in MLAAS paradigm. In: Proceedings of the 34th Annual Computer Security Applications Conference, pp. 371\u2013380 (2018)","DOI":"10.1145\/3274694.3274740"},{"key":"6_CR59","unstructured":"Pal, S., Gupta, Y., Kanade, A., Shevade, S.: Stateful detection of model extraction attacks. arXiv preprint arXiv:2107.05166 (2021)"},{"key":"6_CR60","doi-asserted-by":"crossref","unstructured":"Karchmer, A.: Theoretical limits of provable security against model extraction by efficient observational defenses. In: Cryptology ePrint Archive, Paper 2022\/1039 (2022)","DOI":"10.1109\/SaTML54575.2023.00046"},{"key":"6_CR61","unstructured":"Krishna, K., Tomar, G.S., Parikh, A.P., Papernot, N., Iyyer, M.: Thieves on sesame street! Model extraction of BERT-based APIs. arXiv preprint arXiv:1910.12366 (2019)"},{"key":"6_CR62","unstructured":"Dziedzic, A., Ahmad Kaleem, M., Lu, Y.S., Papernot, N.: Increasing the cost of model extraction with calibrated proof of work. In: CoRR, abs\/2201.09243 (2022)"},{"key":"6_CR63","unstructured":"Zhu, L., Liu, Z., et al.: Deep leakage from gradients. In: Proceedings of NIPS, vol. 32 (2019)"},{"key":"6_CR64","unstructured":"Carlini, N., Tramer, F., Wallace, E., et al.: Extracting training data from large language models. arXiv:2012.07805 (2021)"},{"key":"6_CR65","doi-asserted-by":"crossref","unstructured":"Yue, X., Inan, H.A., Li, X., et al.: Synthetic text generation with differential privacy: a simple and practical recipe. arXiv:2210.14348 (2023)","DOI":"10.18653\/v1\/2023.acl-long.74"},{"key":"6_CR66","unstructured":"Nissenbaum, H.: Privacy as contextual integrity. In: Washington Law Review (2004)"},{"key":"6_CR67","unstructured":"Carlini, N., Ippolito, D., Jagielski, M., Lee, K., Tramer, F., Zhang, C.: Quantifying memorization across neural language models. arXiv:2202.07646 (2023)"},{"key":"6_CR68","doi-asserted-by":"crossref","unstructured":"Ishihara, S.: Training data extraction from pre-trained language models: a survey. arXiv:2305.16157 (2023)","DOI":"10.18653\/v1\/2023.trustnlp-1.23"},{"key":"6_CR69","doi-asserted-by":"crossref","unstructured":"Continella, A., Fratantonio, Y., Lindorfer, M., et al.: Obfuscation-resilient privacy leak detection for mobile apps through differential analysis. In: NDSS (2017)","DOI":"10.14722\/ndss.2017.23465"},{"key":"6_CR70","unstructured":"Ren, J., Rao, A., Lindorfer, M., Legout, A., Choffnes, D.: ReCon: revealing and controlling PII leaks in mobile network traffic. In: MobiSys (2016)"},{"key":"6_CR71","unstructured":"Vakili, T., Lamproudis, A., Henriksson, A., Dalianis, H.: Downstream task performance of BERT models pre-trained using automatically de-identified clinical data. In: Proceedings of the Thirteenth Language Resources and Evaluation Conference, Marseille, France, pp. 4245\u20134252 (2022)"},{"key":"6_CR72","unstructured":"Kandpal, N., Wallace, E., et al.: Deduplicating training data mitigates privacy risks in language models. In: Proceedings of the 39th International Conference on ML. Proceedings of Machine Learning Research, vol. 162, pp. 10697\u201310707. PMLR (2022)"},{"key":"6_CR73","doi-asserted-by":"crossref","unstructured":"Lee, K., Ippolito, D., Nystrom, A., et al.: Deduplicating training data makes language models better. In: Proceedings of the 60th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), Dublin, pp. 8424\u20138445 (2022)","DOI":"10.18653\/v1\/2022.acl-long.577"},{"key":"6_CR74","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/11681878_14","volume-title":"Theory of Cryptography","author":"C Dwork","year":"2006","unstructured":"Dwork, C., McSherry, F., Nissim, K., Smith, A.: Calibrating noise to sensitivity in private data analysis. In: Halevi, S., Rabin, T. (eds.) TCC 2006. LNCS, vol. 3876, pp. 265\u2013284. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11681878_14"},{"key":"6_CR75","unstructured":"Dwork, C.: Differential privacy: a survey of results. In: TAMC (2008)"},{"key":"6_CR76","doi-asserted-by":"crossref","unstructured":"Feldman, V.: Does learning require memorization? A short tale about a long tail. In: STOC (2020)","DOI":"10.1145\/3357713.3384290"},{"key":"6_CR77","unstructured":"Feldman, V., Zhang, C.: What neural networks memorize and why: discovering the long tail via influence estimation. In: NeurIPS (2020)"},{"key":"6_CR78","unstructured":"Ramaswamy, S., Thakkar, O., Mathews, R., et al.: Training production language models without memorizing user data. arXiv preprint arXiv:2009.10031 (2020)"},{"key":"6_CR79","doi-asserted-by":"crossref","unstructured":"Perez, E., Huang, S., Song, F., et al.: Red teaming language models with language models. arXiv preprint:2202.03286 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.225"},{"key":"6_CR80","unstructured":"Zhang, C., Li, S., Xia, J., Wang, W., Yan, F., Liu, Y.: Efficient homomorphic encryption for cross-silo federated learning. In: 2020 USENIX Annual Technical Conference (USENIX ATC 2020), pp. 493\u2013506 (2020)"},{"key":"6_CR81","unstructured":"Yue, K., Jin, R., Wong, C., Baron, D., Dai, H.: Gradient obfuscation gives a false sense of security in federated learning. arXiv:2206.04055 (2022)"},{"key":"6_CR82","unstructured":"Jagielski, M., et al.: Measuring forgetting of memorized training examples. arXiv:2207.00099 (2023)"},{"key":"6_CR83","unstructured":"The Verge. https:\/\/www.theverge.com\/23599441\/microsoft-bing-ai-sydney-secret-rules"},{"key":"6_CR84","unstructured":"Ars Technica. https:\/\/arstechnica.com\/information-technology\/2023\/02\/ai-powered-bing-chat-spills-its-secrets-via-prompt-injection-attack\/"},{"issue":"8","key":"6_CR85","first-page":"1","volume":"55","author":"Z Tian","year":"2022","unstructured":"Tian, Z., Cui, L., Liang, J., et al.: A comprehensive survey on poisoning attacks and countermeasures in machine learning. ACM Comput. Surv.Comput. Surv. 55(8), 1\u201335 (2022)","journal-title":"ACM Comput. Surv.Comput. Surv."},{"key":"6_CR86","unstructured":"Ramirez, M.A., Kim, S.K., Al Hamadi, H., et al.: Poisoning attacks and defenses on artificial intelligence: a survey. arXiv:2202.10276 (2022)"},{"key":"6_CR87","doi-asserted-by":"crossref","unstructured":"Chen, J., Zhang, L., Zheng, H., Wang, X., Ming, Z.: DeepPoison: feature transfer based stealthy poisoning attack. arXiv:2101.02562 (2021)","DOI":"10.1109\/TCSII.2021.3060896"},{"key":"6_CR88","doi-asserted-by":"crossref","unstructured":"Xu, J., Ma, M.D., Wang, F., Xiao, C., Chen, M.: Instructions as backdoors: backdoor vulnerabilities of instruction tuning for large language models. arXiv:2305.14710 (2023)","DOI":"10.18653\/v1\/2024.naacl-long.171"},{"key":"6_CR89","doi-asserted-by":"crossref","unstructured":"Wallace, E., Zhao, T., Feng, S., Singh, S.: Concealed data poisoning attacks on NLP models. In: Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, pp. 139\u2013150 (2021)","DOI":"10.18653\/v1\/2021.naacl-main.13"},{"key":"6_CR90","unstructured":"Microsoft Blog. https:\/\/blogs.microsoft.com\/blog\/2016\/03\/25\/learning-tays-introduction\/"},{"key":"6_CR91","unstructured":"Liu, T.Y., Yang, Y., Mirzasoleiman, B.: Friendly noise against adversarial noise: a powerful defense against data poisoning attacks. arXiv:2208.10224 (2023)"},{"key":"6_CR92","unstructured":"Yang, Y., Liu, T.Y., Mirzasoleiman, B.: Not all poisons are created equal: robust training against data poisoning. arXiv:2210.09671 (2022)"},{"key":"6_CR93","unstructured":"Li, Y., Lyu, X., Koren, N., Lyu, L., Li, B., Ma, X.: Anti-backdoor learning: training clean models on poisoned data. In: Neural Information Processing Systems, vol. 34 (2021)"},{"key":"6_CR94","unstructured":"Hong, S., Chandrasekaran, V., Kaya, Y., et al.: On the effectiveness of mitigating data poisoning attacks with gradient shaping. arXiv preprint arXiv:2002.11497 (2020)"},{"key":"6_CR95","doi-asserted-by":"crossref","unstructured":"Qi, F., Chen, Y., Li, M., Yao, Y., Liu, Z., Sun, M.: ONION: a simple and effective defense against textual backdoor attacks. arXiv:2011.10369 (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.752"},{"key":"6_CR96","doi-asserted-by":"crossref","unstructured":"Salem, A., Backes, M., Zhang, Y.: Get a model! Model hijacking attack against machine learning models. arXiv:2111.04394 (2021)","DOI":"10.14722\/ndss.2022.23064"},{"key":"6_CR97","unstructured":"Si, W., Backes, M., Zhang, Y., Salem, A.: Two-in-one: a model hijacking attack against text generation models. arXiv:2305.07406 (2023)"},{"key":"6_CR98","unstructured":"He, X., Li, Z., Xu, W., et al.: Membership-doctor: comprehensive assessment of membership inference against machine learning models. arXiv:2208.10445 (2022)"},{"key":"6_CR99","doi-asserted-by":"crossref","unstructured":"Carlini, N., Chien, S., Nasr, M., et al.: Membership inference attacks from first principles. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1897\u20131914. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"6_CR100","doi-asserted-by":"crossref","unstructured":"Mireshghallah, F., Goyal, K., Uniyal, A., et al.: Quantifying privacy risks of masked language models using membership inference attacks. arXiv:2203.03929 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.570"},{"key":"6_CR101","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., et al.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"6_CR102","doi-asserted-by":"crossref","unstructured":"Hisamoto, S., Post, M., Duh, K.: Membership inference attacks on sequence-to-sequence models: is my data in your machine translation system?. In: Transactions of the Association for Computational Linguistics, pp. 49\u201363 (2020)","DOI":"10.1162\/tacl_a_00299"},{"key":"6_CR103","doi-asserted-by":"crossref","unstructured":"Lee, K., et al.: Deduplicating training data makes language models better. arXiv:2107.06499 (2021)","DOI":"10.18653\/v1\/2022.acl-long.577"},{"key":"6_CR104","unstructured":"Leino, K., Fredrikson, M.: Stolen memories: leveraging model memorization for calibrated white-box membership inference. In: Proceedings of the 29th USENIX Security Symposium (USENIX Security), pp. 1605\u20131622 (2020)"},{"key":"6_CR105","doi-asserted-by":"crossref","unstructured":"Bourtoule, L., Chandrasekaran, V., Choquette-Choo, C.A., et al.: Machine unlearning. In: Proceedings of the IEEE Symposium on Security Privacy (SP), pp. 141\u2013159 (2021)","DOI":"10.1109\/SP40001.2021.00019"},{"key":"6_CR106","unstructured":"Sekhari, A., Acharya, J., et al.: Remember what you want to forget: algorithms for machine unlearning. In: Proceedings of the Neural Information Processing Systems, vol. 34, pp. 18075\u201318086 (2021)"},{"key":"6_CR107","unstructured":"Duan, H., Dziedzic, A., Yaghini, M., Papernot, N., Boenisch, F.: On the privacy risk of in-context learning. In: trustnlpworkshop (2021)"},{"key":"6_CR108","doi-asserted-by":"crossref","unstructured":"Mattern, J., Mireshghallah, F., Jin, Z., et al.: Membership inference attacks against language models via neighbourhood comparison. arXiv:2305.18462 (2023)","DOI":"10.18653\/v1\/2023.findings-acl.719"}],"container-title":["Communications in Computer and Information Science","Ubiquitous Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-97-1274-8_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,14]],"date-time":"2024-11-14T05:22:01Z","timestamp":1731561721000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-97-1274-8_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9789819712731","9789819712748"],"references-count":108,"URL":"https:\/\/doi.org\/10.1007\/978-981-97-1274-8_6","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"13 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"UbiSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Ubiquitous Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Exeter","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Kingdom","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 November 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"3 November 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ubisec2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/hpcn.exeter.ac.uk\/ubisec2023\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"MyReview","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"91","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"29","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"32% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}