{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T18:47:07Z","timestamp":1782499627868,"version":"3.54.5"},"reference-count":42,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T00:00:00Z","timestamp":1782432000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T00:00:00Z","timestamp":1782432000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001858","name":"VINNOVA","doi-asserted-by":"publisher","award":["2025-02987"],"award-info":[{"award-number":["2025-02987"]}],"id":[{"id":"10.13039\/501100001858","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100018693","name":"HORIZON EUROPE Framework Programme","doi-asserted-by":"publisher","award":["101135576"],"award-info":[{"award-number":["101135576"]}],"id":[{"id":"10.13039\/100018693","id-type":"DOI","asserted-by":"publisher"}]},{"name":"SSF","award":["CCR25-0015"],"award-info":[{"award-number":["CCR25-0015"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Int. J. Inf. Secur."],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>IoT devices are widely deployed in critical infrastructure, often generating sensitive data that is processed by Machine Learning (ML) techniques. Among other applications, ML is leveraged in intrusion detection systems (IDSs) to detect cyberattacks. However, ML-based IDSs are vulnerable to adversarial attacks such as the Membership Inference Attack (MIA), in which an attacker attempts to infer whether a specific data point was present in the training dataset. This can be exploited by attackers to gain insights into the normal behavior of IoT devices and launch stealth attacks. While MIA has been widely demonstrated in image recognition, its effectiveness against ML-based IDS for IoT is poorly understood. In this work, we investigate the effectiveness of MIA against ML-based IDS. We propose a novel differential-private approach called PEDS, which leverages a sparse autoencoder and restricted Boltzmann machine to protect IDS training data against MIAs by synthesizing data points. We empirically evaluate the effectiveness of PEDS on real-world IoT datasets and show that it can substantially hinder the accuracy of MIAs while maintaining high IDS detection performance and enhancing privacy. We compare PEDS with six state-of-the-art synthesizers, including autoencoder-, kernel-, diffusion-model-, and GAN-based methods. The empirical results show that PEDS outperforms these state-of-the-art methods on five popular IoT\/IDS datasets, indicating its potential to enhance security and privacy in ML-based IDSs.<\/jats:p>","DOI":"10.1007\/s10207-026-01289-z","type":"journal-article","created":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T17:54:54Z","timestamp":1782496494000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["PEDS: Privately Encoded Deep Synthesis to Mitigate Membership Inference Attacks"],"prefix":"10.1007","volume":"25","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2772-4661","authenticated-orcid":false,"given":"Han","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-0064-852X","authenticated-orcid":false,"given":"Seonghyun","family":"Kim","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6116-164X","authenticated-orcid":false,"given":"Alfonso","family":"Iacovazzi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8192-0893","authenticated-orcid":false,"given":"Shahid","family":"Raza","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,26]]},"reference":[{"key":"1289_CR1","doi-asserted-by":"publisher","unstructured":"Abadi, M., Chu, A., Goodfellow, I., McMahan, H.B., Mironov, I., Talwar, K., Zhang, L.: Deep learning with differential privacy. Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (2016). https:\/\/doi.org\/10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"1289_CR2","unstructured":"Anderson, H.: The practical divide between adversarial ML research and security practice: A red team perspective. USENIX Association , (2021)"},{"key":"1289_CR3","doi-asserted-by":"crossref","unstructured":"Atashgahi, Z., Sokar, G., van\u00a0der Lee, T., Mocanu, E., Mocanu, D.C., Veldhuis, R., Pechenizkiy, M.: Quick and robust feature selection: the strength of energy-efficient sparse training for autoencoders (2021). arXiv:https:\/\/arxiv.org\/abs\/2012.00560","DOI":"10.1007\/s10994-021-06063-x"},{"key":"1289_CR4","unstructured":"Borisov, V., Sessler, K., Leemann, T., Pawelczyk, M., Kasneci, G.: Language models are realistic tabular data generators. In: The Eleventh International Conference on Learning Representations (2023). https:\/\/openreview.net\/forum?id=cEygmQNOeI"},{"key":"1289_CR5","doi-asserted-by":"publisher","unstructured":"Carlini, N., Chien, S., Nasr, M., Song, S., Terzis, A., Tram\u00e9r, F.: Membership inference attacks from first principles. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1897\u20131914 (2022). https:\/\/doi.org\/10.1109\/SP46214.2022.9833649","DOI":"10.1109\/SP46214.2022.9833649"},{"issue":"1","key":"1289_CR6","first-page":"321","volume":"16","author":"NV Chawla","year":"2002","unstructured":"Chawla, N.V., Bowyer, K.W., Hall, L.O., Kegelmeyer, W.P.: Smote: Synthetic minority over-sampling technique. J. Artif. Int. Res. 16(1), 321\u2013357 (2002)","journal-title":"J. Artif. Int. Res."},{"key":"1289_CR7","first-page":"26","volume":"26","author":"J Chen","year":"2021","unstructured":"Chen, J., Wang, W.H., Shi, X.: Differential privacy protection against membership inference attack on machine learning for genomic data. Pac. Symp. Biocomput. 26, 26\u201337 (2021)","journal-title":"Pac. Symp. Biocomput."},{"key":"1289_CR8","unstructured":"Chen, Q., Xiang, C., Xue, M., Li, B., Borisov, N., Kaafar, D., Zhu, H.: Differentially private data generative models, (2018). arXiv: abs\/1812.02274"},{"key":"1289_CR9","doi-asserted-by":"publisher","unstructured":"Creech, G., Hu, J.: Generation of a new ids test dataset: Time to retire the kdd collection. In: 2013 IEEE Wireless Communications and Networking Conference (WCNC), pp. 4487\u20134492 (2013). https:\/\/doi.org\/10.1109\/WCNC.2013.6555301","DOI":"10.1109\/WCNC.2013.6555301"},{"key":"1289_CR10","first-page":"1","volume-title":"Automata, Languages and Programming","author":"C Dwork","year":"2006","unstructured":"Dwork, C.: Differential privacy. In: Bugliesi, M., Preneel, B., Sassone, V., Wegener, I. (eds.) Automata, Languages and Programming, pp. 1\u201312. Springer, Berlin Heidelberg, Berlin, Heidelberg (2006)"},{"key":"1289_CR11","doi-asserted-by":"crossref","unstructured":"Dwork, C.: Differential privacy: A survey of results. In: International conference on theory and applications of models of computation, pp. 1\u201319. Springer (2008)","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"1289_CR12","doi-asserted-by":"publisher","first-page":"40281","DOI":"10.1109\/ACCESS.2022.3165809","volume":"10","author":"MA Ferrag","year":"2022","unstructured":"Ferrag, M.A., Friha, O., Hamouda, D., Maglaras, L., Janicke, H.: Edge-iiotset: A new comprehensive realistic cyber security dataset of iot and iiot applications for centralized and federated learning. IEEE Access 10, 40281\u201340306 (2022). https:\/\/doi.org\/10.1109\/ACCESS.2022.3165809","journal-title":"IEEE Access"},{"key":"1289_CR13","unstructured":"Harder, F., Adamczewski, K., Park, M.: Dp-merf: Differentially private mean embeddings with randomfeatures for practical privacy-preserving data generation. In: A.\u00a0Banerjee, K.\u00a0Fukumizu (eds.) Proceedings of The 24th International Conference on Artificial Intelligence and Statistics, Proceedings of Machine Learning Research, vol. 130, pp. 1819\u20131827. PMLR (2021). https:\/\/proceedings.mlr.press\/v130\/harder21a.html"},{"key":"1289_CR14","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2021.103066","volume":"185","author":"S Ho","year":"2021","unstructured":"Ho, S., Qu, Y., Gu, B., Gao, L., Li, J., Xiang, Y.: Dp-gan: Differentially private consecutive data publishing using generative adversarial nets. J. Netw. Comput. Appl. 185, 103066 (2021). https:\/\/doi.org\/10.1016\/j.jnca.2021.103066. (https:\/\/www.sciencedirect.com\/science\/article\/pii\/S1084804521000904)","journal-title":"J. Netw. Comput. Appl."},{"key":"1289_CR15","doi-asserted-by":"publisher","unstructured":"Holubenko, V., Silva, P., Bento, C.: An intelligent mechanism for monitoring and detecting intrusions in iot devices. In: 2023 IEEE 20th Consumer Communications & Networking Conference (CCNC), pp. 959\u2013960 (2023). https:\/\/doi.org\/10.1109\/CCNC51644.2023.10060443","DOI":"10.1109\/CCNC51644.2023.10060443"},{"key":"1289_CR16","doi-asserted-by":"publisher","unstructured":"Huang, H.: Defense against membership inference attack applying domain adaptation with addictive noise 9, 92\u2013108 (2021). https:\/\/doi.org\/10.4236\/jcc.2021.95007","DOI":"10.4236\/jcc.2021.95007"},{"key":"1289_CR17","unstructured":"Jayaraman, B., Evans, D.: Evaluating differentially private machine learning in practice. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 1895\u20131912. USENIX Association, Santa Clara, CA (2019). https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/jayaraman"},{"key":"1289_CR18","doi-asserted-by":"publisher","unstructured":"Jia, J., Salem, A., Backes, M., Zhang, Y., Gong, N.Z.: Memguard: Defending against black-box membership inference attacks via adversarial examples. CCS \u201919, p. 259\u2013274. Association for Computing Machinery, New York, NY, USA (2019). https:\/\/doi.org\/10.1145\/3319535.3363201. https:\/\/doi.org\/10.1145\/3319535.3363201","DOI":"10.1145\/3319535.3363201"},{"key":"1289_CR19","doi-asserted-by":"publisher","first-page":"779","DOI":"10.1016\/j.future.2019.05.041","volume":"100","author":"N Koroniotis","year":"2019","unstructured":"Koroniotis, N., Moustafa, N., Sitnikova, E., Turnbull, B.: Towards the development of realistic botnet dataset in the internet of things for network forensic analytics: Bot-iot dataset. Futur. Gener. Comput. Syst. 100, 779\u2013796 (2019). https:\/\/doi.org\/10.1016\/j.future.2019.05.041. (https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167739X18327687)","journal-title":"Futur. Gener. Comput. Syst."},{"key":"1289_CR20","unstructured":"Kotelnikov, A., Baranchuk, D., Rubachev, I., Babenko, A.: TabDDPM: Modelling tabular data with diffusion models. In: A.\u00a0Krause, E.\u00a0Brunskill, K.\u00a0Cho, B.\u00a0Engelhardt, S.\u00a0Sabato, J.\u00a0Scarlett (eds.) Proceedings of the 40th International Conference on Machine Learning, Proceedings of Machine Learning Research, vol. 202, pp. 17,564\u201317,579. PMLR (2023). https:\/\/proceedings.mlr.press\/v202\/kotelnikov23a.html"},{"key":"1289_CR21","unstructured":"Lassila, M., \u00d6stman, J., Ngo, K.H., Graell\u00a0i Amat, A.: Practical bayes-optimal membership inference attacks. In: Advances in Neural Information Processing Systems (NeurIPS) (2025)"},{"key":"1289_CR22","doi-asserted-by":"publisher","first-page":"325","DOI":"10.1007\/978-3-642-24861-0_22","volume-title":"Information Security","author":"J Lee","year":"2011","unstructured":"Lee, J., Clifton, C.: How much is enough? choosing $$\\epsilon $$ for differential privacy. In: Lai, X., Zhou, J., Li, H. (eds.) Information Security, pp. 325\u2013340. Springer, Berlin Heidelberg, Berlin, Heidelberg (2011)"},{"key":"1289_CR23","unstructured":"Mckenna, R., Sheldon, D., Miklau, G.: Graphical-model based estimation and inference for differential privacy. In: K.\u00a0Chaudhuri, R.\u00a0Salakhutdinov (eds.) Proceedings of the 36th International Conference on Machine Learning, Proceedings of Machine Learning Research, vol.\u00a097, pp. 4435\u20134444. PMLR (2019). https:\/\/proceedings.mlr.press\/v97\/mckenna19a.html"},{"issue":"3","key":"1289_CR24","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","volume":"17","author":"Y Meidan","year":"2018","unstructured":"Meidan, Y., Bohadana, M., Mathov, Y., Mirsky, Y., Shabtai, A., Breitenbacher, D., Elovici, Y.: N-baiot-network-based detection of iot botnet attacks using deep autoencoders. IEEE Pervasive Comput. 17(3), 12\u201322 (2018)","journal-title":"IEEE Pervasive Comput."},{"key":"1289_CR25","unstructured":"Min, M.R., Ning, X., Cheng, C., Gerstein, M.: Interpretable Sparse High-Order Boltzmann Machines. In: S.\u00a0Kaski, J.\u00a0Corander (eds.) Proceedings of the Seventeenth International Conference on Artificial Intelligence and Statistics, Proceedings of Machine Learning Research, vol.\u00a033, pp. 614\u2013622. PMLR, Reykjavik, Iceland (2014). https:\/\/proceedings.mlr.press\/v33\/min14.html"},{"key":"1289_CR26","doi-asserted-by":"publisher","unstructured":"Nasr, M., Shokri, R., Houmansadr, A.: Machine learning with membership privacy using adversarial regularization. CCS \u201918, p. 634\u2013646. Association for Computing Machinery, New York, NY, USA (2018). https:\/\/doi.org\/10.1145\/3243734.3243855","DOI":"10.1145\/3243734.3243855"},{"key":"1289_CR27","unstructured":"Ng, A.: CS294 Lecture notes in Sparse Autoencoder (2011). https:\/\/web.stanford.edu\/class\/cs294a\/sparseAutoencoder_2011new.pdf"},{"key":"1289_CR28","first-page":"61","volume":"11","author":"M Rahman","year":"2018","unstructured":"Rahman, M., Rahman, T., Lagani\u00e8re, R., Mohammed, N.: Membership inference attack against differentially private deep learning model. Trans. Data Priv. 11, 61\u201379 (2018)","journal-title":"Trans. Data Priv."},{"key":"1289_CR29","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., Berrang, P., Fritz, M., Backes, M.: Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models. In: Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS), (2019)","DOI":"10.14722\/ndss.2019.23119"},{"key":"1289_CR30","doi-asserted-by":"publisher","unstructured":"Shi, Y., Davaslioglu, K., Sagduyu, Y.E.: Over-the-air membership inference attacks as privacy threats for deep learning-based wireless signal classifiers. In: Proceedings of the 2nd ACM Workshop on Wireless Security and Machine Learning, WiseML \u201920, p. 61\u201366. Association for Computing Machinery, New York, NY, USA (2020). https:\/\/doi.org\/10.1145\/3395352.3404070","DOI":"10.1145\/3395352.3404070"},{"key":"1289_CR31","doi-asserted-by":"publisher","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318 (2017). https:\/\/doi.org\/10.1109\/SP.2017.41","DOI":"10.1109\/SP.2017.41"},{"key":"1289_CR32","doi-asserted-by":"publisher","unstructured":"Stolfo, S., Fan, W., Lee, W., Prodromidis, A., Chan, P.: Cost-based modeling for fraud and intrusion detection: results from the jam project. In: Proceedings DARPA Information Survivability Conference and Exposition. DISCEX\u201900, vol.\u00a02, pp. 130\u2013144 vol.2 (2000). https:\/\/doi.org\/10.1109\/DISCEX.2000.821515","DOI":"10.1109\/DISCEX.2000.821515"},{"key":"1289_CR33","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.8269-draft","author":"E Tabassi","year":"2019","unstructured":"Tabassi, E., Burns, K., Hadjimichael, M., Molina-Markham, A., Sexton, J.: A taxonomy and terminology of adversarial machine learning (2019). https:\/\/doi.org\/10.6028\/NIST.IR.8269-draft","journal-title":"A taxonomy and terminology of adversarial machine learning"},{"key":"1289_CR34","doi-asserted-by":"crossref","unstructured":"Tantipongpipat, U.T., Waites, C., Boob, D., Siva, A.A., Cummings, R.: Differentially private synthetic mixed-type data generation for unsupervised learning. 2021 12th International Conference on Information, Intelligence, Systems & Applications (IISA) pp. 1\u20139 (2021)","DOI":"10.1109\/IISA52424.2021.9555521"},{"key":"1289_CR35","doi-asserted-by":"crossref","unstructured":"Torkzadehmahani, R., Kairouz, P., Paten, B.: Dp-cgan: Differentially private synthetic data and label generation pp. 0\u20130 (2019)","DOI":"10.1109\/CVPRW.2019.00018"},{"key":"1289_CR36","unstructured":"Yang, Z., Shao, B., Xuan, B., Chang, E.C., Zhang, F.: Defending model inversion and membership inference attacks via prediction purification, (2020)"},{"key":"1289_CR37","unstructured":"Yeom, S., Fredrikson, M., Jha, S.: The unintended consequences of overfitting: Training data inference attacks. CoRR abs\/1709.01604 (2017). arXiv: http:\/\/arxiv.org\/abs\/1709.01604"},{"key":"1289_CR38","unstructured":"Zarifzadeh, S., Liu, P., Shokri, R.: Low-cost high-power membership inference attacks. In: Proceedings of the 41st International Conference on Machine Learning, ICML\u201924. JMLR.org, (2024)"},{"key":"1289_CR39","doi-asserted-by":"publisher","first-page":"2269","DOI":"10.1109\/ACCESS.2021.3137201","volume":"10","author":"M Zeeshan","year":"2022","unstructured":"Zeeshan, M., Riaz, Q., Bilal, M.A., Shahzad, M.K., Jabeen, H., Haider, S.A., Rahim, A.: Protocol-based deep intrusion detection for dos and ddos attacks using unsw-nb15 and bot-iot data-sets. IEEE Access 10, 2269\u20132283 (2022). https:\/\/doi.org\/10.1109\/ACCESS.2021.3137201","journal-title":"IEEE Access"},{"issue":"4","key":"1289_CR40","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3134428","volume":"42","author":"J Zhang","year":"2017","unstructured":"Zhang, J., Cormode, G., Procopiuc, C.M., Srivastava, D., Xiao, X.: Privbayes: Private data release via bayesian networks. ACM Trans. Database Syst. 42(4), 1\u201341 (2017). https:\/\/doi.org\/10.1145\/3134428","journal-title":"ACM Trans. Database Syst."},{"key":"1289_CR41","unstructured":"Zhang, Z., Wang, T., Li, N., Honorio, J., Backes, M., He, S., Chen, J., Zhang, Y.: PrivSyn: Differentially private data synthesis. In: 30th USENIX Security Symposium (USENIX Security 21), pp. 929\u2013946. USENIX Association (2021). https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/zhang-zhikun"},{"key":"1289_CR42","doi-asserted-by":"publisher","unstructured":"Zhao, Z., Birke, R., Chen, L.Y.: Tabula: Harnessing language models for tabular data synthesis. In: Advances in Knowledge Discovery and Data Mining?: 29th Pacific-Asia Conference on Knowledge Discovery and Data Mining, PAKDD 2025, Sydney, NSW, Australia, June 10\u201313, 2025, Proceedings, Part V, p. 247\u2013259. Springer-Verlag, Berlin, Heidelberg (2025). https:\/\/doi.org\/10.1007\/978-981-96-8186-0_20","DOI":"10.1007\/978-981-96-8186-0_20"}],"container-title":["International Journal of Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01289-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10207-026-01289-z","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10207-026-01289-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,26]],"date-time":"2026-06-26T17:55:12Z","timestamp":1782496512000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10207-026-01289-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,26]]},"references-count":42,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2026,8]]}},"alternative-id":["1289"],"URL":"https:\/\/doi.org\/10.1007\/s10207-026-01289-z","relation":{},"ISSN":["1615-5270"],"issn-type":[{"value":"1615-5270","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,26]]},"assertion":[{"value":"1 August 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 June 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"114"}}