{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,31]],"date-time":"2026-01-31T10:27:43Z","timestamp":1769855263498,"version":"3.49.0"},"publisher-location":"Singapore","reference-count":25,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819982950","type":"print"},{"value":"9789819982967","type":"electronic"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-981-99-8296-7_18","type":"book-chapter","created":{"date-parts":[[2023,11,17]],"date-time":"2023-11-17T00:04:14Z","timestamp":1700179454000},"page":"255-269","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Differential Privacy Under Membership Inference Attacks"],"prefix":"10.1007","author":[{"given":"Trung","family":"Ha","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Trang","family":"Vo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tran Khanh","family":"Dang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nguyen Thi Huyen","family":"Trang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,11,17]]},"reference":[{"issue":"309","key":"18_CR1","doi-asserted-by":"publisher","first-page":"63","DOI":"10.1080\/01621459.1965.10480775","volume":"60","author":"SL Warner","year":"1965","unstructured":"Warner, S.L.: Randomized response: a survey technique for eliminating evasive answer bias. J. Am. Stat. Assoc. 60(309), 63\u201369 (1965)","journal-title":"J. Am. Stat. Assoc."},{"key":"18_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"486","DOI":"10.1007\/11761679_29","volume-title":"Advances in Cryptology - EUROCRYPT 2006","author":"C Dwork","year":"2006","unstructured":"Dwork, C., Kenthapadi, K., McSherry, F., Mironov, I., Naor, M.: Our data, ourselves: Privacy via distributed noise generation. In: Vaudenay, S. (ed.) EUROCRYPT 2006. LNCS, vol. 4004, pp. 486\u2013503. Springer, Heidelberg (2006). https:\/\/doi.org\/10.1007\/11761679_29"},{"key":"18_CR3","unstructured":"Hill, K.: How target figured out a teen girl was pregnant before her father did. Forbes, Inc, vol. 7, pp.4\u20131 (2012)"},{"key":"18_CR4","doi-asserted-by":"crossref","unstructured":"Li, N., Qardaji, W., Su, D., Wu, Y., Yang, W.: Membership privacy: a unifying framework for privacy definitions. In: Proceedings of the 20th ACM SIGSAC Conference on Computer and Communications Security, pp. 889\u2013900 (2013)","DOI":"10.1145\/2508859.2516686"},{"key":"18_CR5","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1322\u20131333 (2015)","DOI":"10.1145\/2810103.2813677"},{"key":"18_CR6","doi-asserted-by":"crossref","unstructured":"Shokri, R., Shmatikov, V.: Privacy-preserving deep learning. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1310\u20131321 (2015)","DOI":"10.1145\/2810103.2813687"},{"key":"18_CR7","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction {APIs}. In: Proceedings of the 25th USENIX Security Symposium, pp. 601\u2013618 (2016)"},{"key":"18_CR8","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: Proceedings of the 38th IEEE Symposium on Security and Privacy, pp. 3\u201318 (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"18_CR9","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., Jha, S.: Privacy risk in machine learning: analyzing the connection to overfitting. In: Proceedings of the IEEE 31st Computer Security Foundations Symposium (CSF), pp. 268\u2013282 (2018)","DOI":"10.1109\/CSF.2018.00027"},{"issue":"1","key":"18_CR10","doi-asserted-by":"publisher","first-page":"133","DOI":"10.2478\/popets-2019-0008","volume":"2019","author":"J Hayes","year":"2019","unstructured":"Hayes, J., Melis, L., Danezis, G., De Cristofaro, E.: LOGAN: membership inference attacks against generative models. Proc. Priv. Enhancing Technol. (PoPETs) 2019(1), 133\u2013152 (2019)","journal-title":"Proc. Priv. Enhancing Technol. (PoPETs)"},{"issue":"4","key":"18_CR11","doi-asserted-by":"publisher","first-page":"232","DOI":"10.2478\/popets-2019-0067","volume":"2019","author":"B Hilprecht","year":"2019","unstructured":"Hilprecht, B., H\u00e4rterich, M., Bernau, D.: Monte Carlo and reconstruction membership inference attacks against generative models. Proc. Priv. Enhancing Technol. 2019(4), 232\u2013249 (2019)","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"18_CR12","unstructured":"Jayaraman, B., Evans, D.: Evaluating differentially private machine learning in practice. In: Proceedings of the 28th USENIX Security Symposium (USENIX Security 2019), pp. 1895\u20131912 (2019)"},{"key":"18_CR13","doi-asserted-by":"crossref","unstructured":"Liu, K.S., Xiao, C., Li, B., Gao, J.: Performing co-membership attacks against deep generative models. In: Proceedings of the 19th IEEE International Conference on Data Mining (ICDM), pp. 459\u2013467 (2019)","DOI":"10.1109\/ICDM.2019.00056"},{"key":"18_CR14","unstructured":"Nasr, M., Shokri, R., Houmansadr, A.: Comprehensive privacy analysis of deep learning. In: Proceedings of the 40th IEEE Symposium on Security and Privacy, pp. 1\u201315 (2019)"},{"key":"18_CR15","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., Houmansadr, A.: Comprehensive privacy analysis of deep learning: passive and active white-box inference attacks against centralized and federated learning. In: Proceedings of the 40th IEEE Symposium on Security and Privacy, pp. 739\u2013753 (2019)","DOI":"10.1109\/SP.2019.00065"},{"key":"18_CR16","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., Berrang, P., Fritz, M., Backes, M.: ML-leaks: model and data independent membership inference attacks and defenses on machine learning models. In: Proceedings of the 26th Network and Distributed Systems Security Symposium (2019)","DOI":"10.14722\/ndss.2019.23119"},{"key":"18_CR17","doi-asserted-by":"crossref","unstructured":"Chen, D., Yu, N., Zhang, Y., Fritz, M.: GAN-leaks: a taxonomy of membership inference attacks against generative models. In: Proceedings of the 27th ACM SIGSAC Conference on Computer and Communications Security, pp. 343\u2013362 (2020)","DOI":"10.1145\/3372297.3417238"},{"issue":"5","key":"18_CR18","doi-asserted-by":"publisher","first-page":"253","DOI":"10.1007\/s42979-020-00254-4","volume":"1","author":"T Ha","year":"2020","unstructured":"Ha, T., Dang, T.K., Le, H., Truong, T.A.: Security and privacy issues in deep learning: a brief review. SN Comput. Sci. 1(5), 253 (2020)","journal-title":"SN Comput. Sci."},{"key":"18_CR19","unstructured":"Leino, K., Fredrikson, M.: Stolen memories: leveraging model memorization for calibrated {White-Box} membership inference. In: Proceedings of the 29th USENIX Security Symposium (USENIX Security 20), pp. 1605\u20131622 (2020)"},{"key":"18_CR20","doi-asserted-by":"publisher","unstructured":"Long, Y., et al.: A pragmatic approach to membership inferences on machine learning models. In: Proceedings of the 5th IEEE European Symposium on Security and Privacy, pp. 521\u2013534 (2020). https:\/\/doi.org\/10.1109\/EuroSP48549.2020.00040","DOI":"10.1109\/EuroSP48549.2020.00040"},{"key":"18_CR21","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1007\/978-3-030-91387-8_21","volume-title":"Future Data and Security Engineering","author":"T Ha","year":"2021","unstructured":"Ha, T., Dang, T.K., Nguyen-Tan, N.: Comprehensive analysis of privacy in black-box and white-box inference attacks against generative adversarial network. In: Dang, T.K., K\u00fcng, J., Chung, T.M., Takizawa, M. (eds.) FDSE 2021. LNCS, vol. 13076, pp. 323\u2013337. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-91387-8_21"},{"issue":"2","key":"18_CR22","doi-asserted-by":"publisher","first-page":"348","DOI":"10.2478\/popets-2021-0031","volume":"2021","author":"B Jayaraman","year":"2021","unstructured":"Jayaraman, B., Wang, L., Knipmeyer, K., Gu, Q., Evans, D.: Revisiting membership inference under realistic assumptions. Proc. Priv. Enhancing Technol. 2021(2), 348\u2013368 (2021). https:\/\/doi.org\/10.2478\/popets-2021-0031","journal-title":"Proc. Priv. Enhancing Technol."},{"issue":"2\/3","key":"18_CR23","doi-asserted-by":"publisher","first-page":"117","DOI":"10.1108\/IJWIS-04-2022-0078","volume":"18","author":"T Ha","year":"2022","unstructured":"Ha, T., Dang, T.K.: Inference attacks based on GAN in federated learning. Int. J. Web Inf. Syst. 18(2\/3), 117\u2013136 (2022)","journal-title":"Int. J. Web Inf. Syst."},{"issue":"11s","key":"18_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3523273","volume":"54","author":"H Hu","year":"2022","unstructured":"Hu, H., Salcic, Z., Sun, L., Dobbie, G., Yu, P.S., Zhang, X.: Membership inference attacks on machine learning: a survey. ACM Comput. Surv. 54(11s), 1\u201337 (2022)","journal-title":"ACM Comput. Surv."},{"issue":"3","key":"18_CR25","doi-asserted-by":"publisher","first-page":"2341","DOI":"10.1109\/TDSC.2022.3180828","volume":"20","author":"L Liu","year":"2022","unstructured":"Liu, L., Wang, Y., Liu, G., Peng, K., Wang, C.: Membership inference attacks against machine learning models via prediction sensitivity. IEEE Trans. Dependable Secure Comput. 20(3), 2341\u20132347 (2022). https:\/\/doi.org\/10.1109\/TDSC.2022.3180828","journal-title":"IEEE Trans. Dependable Secure Comput."}],"container-title":["Communications in Computer and Information Science","Future Data and Security Engineering. Big Data, Security and Privacy, Smart City and Industry 4.0 Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-99-8296-7_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,11,17]],"date-time":"2023-11-17T00:09:57Z","timestamp":1700179797000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-99-8296-7_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9789819982950","9789819982967"],"references-count":25,"URL":"https:\/\/doi.org\/10.1007\/978-981-99-8296-7_18","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"value":"1865-0929","type":"print"},{"value":"1865-0937","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"17 November 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"FDSE","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Future Data and Security Engineering","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Da Nang","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Vietnam","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 November 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 November 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"fdse2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/thefdse.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EquinOCS","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"135","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"38","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"8","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"6","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}