{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T15:26:52Z","timestamp":1785857212122,"version":"3.56.0"},"reference-count":212,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,12,4]],"date-time":"2024-12-04T00:00:00Z","timestamp":1733270400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,12,4]],"date-time":"2024-12-04T00:00:00Z","timestamp":1733270400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The rapid progress of generative AI models has yielded substantial breakthroughs in AI, facilitating the generation of realistic synthetic data across various modalities. However, these advancements also introduce significant privacy risks, as the models may inadvertently expose sensitive information from their training data. Currently, there is no comprehensive survey work investigating privacy issues, e.g., attacking and defending privacy in generative AI models. We strive to identify existing attack techniques and mitigation strategies and to offer a summary of the current research landscape. Our survey encompasses a wide array of generative AI models, including language models, Generative Adversarial Networks, diffusion models, and their multi-modal counterparts. It indicates the critical need for continued research and development in privacy-preserving techniques for generative AI models. Furthermore, we offer insights into the challenges and discuss the open problems in the intersection of privacy and generative AI models.<\/jats:p>","DOI":"10.1007\/s10462-024-11024-6","type":"journal-article","created":{"date-parts":[[2024,12,4]],"date-time":"2024-12-04T03:31:09Z","timestamp":1733283069000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":47,"title":["Generative AI model privacy: a survey"],"prefix":"10.1007","volume":"58","author":[{"given":"Yihao","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinhe","family":"Huang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanjie","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dong","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bin","family":"Xiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,12,4]]},"reference":[{"key":"11024_CR1","doi-asserted-by":"crossref","unstructured":"Abadi M, Chu A, Goodfellow I, et al (2016) Deep learning with differential privacy. In: Proceedings of CCS, pp 308\u2013318","DOI":"10.1145\/2976749.2978318"},{"key":"11024_CR2","unstructured":"Achiam J, Adler S, Agarwal S, et al (2023) Gpt-4 technical report. arXiv preprint arXiv:2303.08774"},{"issue":"6","key":"11024_CR3","doi-asserted-by":"publisher","first-page":"1109","DOI":"10.1109\/TKDE.2018.2855136","volume":"31","author":"G Acs","year":"2018","unstructured":"Acs G, Melis L, Castelluccia C et al (2018) Differentially private mixture of generative neural networks. IEEE Trans Knowl Data Eng 31(6):1109\u20131121","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"11024_CR4","unstructured":"A\u00efvodji U, Gambs S, Ther T (2019) Gamin: An adversarial approach to black-box model inversion. arXiv preprint arXiv:1909.11835"},{"key":"11024_CR5","doi-asserted-by":"crossref","unstructured":"Anil R, Ghazi B, Gupta V, et al (2022) Large-scale differentially private bert. In: Proceedings of EMNLP, pp 6481\u20136491","DOI":"10.18653\/v1\/2022.findings-emnlp.484"},{"key":"11024_CR6","doi-asserted-by":"crossref","unstructured":"An S, Tao G, Xu Q, et al (2022) Mirror: Model inversion for deep learning network with high fidelity. In: Proc. of NDSS","DOI":"10.14722\/ndss.2022.24335"},{"key":"11024_CR7","unstructured":"Arjovsky M, Chintala S, Bottou L (2017a) Wasserstein gan. In: Proc. of ICML"},{"key":"11024_CR8","unstructured":"Arjovsky M, Chintala S, Bottou L (2017b) Wasserstein generative adversarial networks. In: Proc. of ICML, PMLR, pp 214\u2013223"},{"key":"11024_CR9","unstructured":"Arora S, Ge R, Liang Y, et al (2017) Generalization and equilibrium in generative adversarial nets (gans). In: International conference on machine learning, PMLR, pp 224\u2013232"},{"key":"11024_CR10","unstructured":"Augenstein S, McMahan HB, Ramage D, et al (2020) Generative models for effective ml on private, decentralized datasets. In: Proc. of ICLR"},{"key":"11024_CR11","first-page":"364","volume":"35","author":"M Augustin","year":"2022","unstructured":"Augustin M, Boreiko V, Croce F et al (2022) Diffusion visual counterfactual explanations. Adv Neural Inf Process Syst 35:364\u2013377","journal-title":"Adv Neural Inf Process Syst"},{"key":"11024_CR12","doi-asserted-by":"crossref","unstructured":"Avrahami O, Lischinski D, Fried O (2022) Blended diffusion for text-driven editing of natural images. In: Proc. of CVPR, pp 18,208\u201318,218","DOI":"10.1109\/CVPR52688.2022.01767"},{"key":"11024_CR13","unstructured":"Bae H, Jang J, Jung D, et al (2018) Security and privacy issues in deep learning. arXiv preprint arXiv:1807.11655"},{"key":"11024_CR14","unstructured":"Balunovic M, Dimitrov D, Jovanovi\u0107 N, et al (2022) Lamp: Extracting text from gradients with language model priors. In: Proc. of NeurIPS, pp 7641\u20137654"},{"key":"11024_CR15","unstructured":"Bertran M, Tang S, Roth A, et al (2023) Scalable membership inference attacks via quantile regression. In: Proc. of NeurIPS, pp 314\u2013330"},{"key":"11024_CR16","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1016\/j.neucom.2019.11.041","volume":"384","author":"A Boulemtafes","year":"2020","unstructured":"Boulemtafes A, Derhab A, Challal Y (2020) A review of privacy-preserving techniques for deep learning. Neurocomputing 384:21\u201345","journal-title":"Neurocomputing"},{"key":"11024_CR17","unstructured":"Brendel W, Rauber J, Bethge M (2018) Decision-based adversarial attacks: reliable attacks against black-box machine learning models. In: International conference on learning representations"},{"key":"11024_CR18","unstructured":"Brock A, Donahue J, Simonyan K (2018) Large scale gan training for high fidelity natural image synthesis. In: Proc. of ICLR"},{"key":"11024_CR19","doi-asserted-by":"crossref","unstructured":"Brown H, Lee K, Mireshghallah F, et al (2022) What does it mean for a language model to preserve privacy? In: FAccT \u201922, pp 2280\u20132292","DOI":"10.1145\/3531146.3534642"},{"key":"11024_CR20","unstructured":"Brown T, Mann B, Ryder N, et al (2020) Language models are few-shot learners. In: Proc. of NeurIPS, pp 1877\u20131901"},{"issue":"6","key":"11024_CR21","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3459992","volume":"54","author":"Z Cai","year":"2021","unstructured":"Cai Z, Xiong Z, Xu H et al (2021) Generative adversarial networks: a survey toward private and secure applications. ACM Comput Surv 54(6):1\u201338","journal-title":"ACM Comput Surv"},{"key":"11024_CR22","first-page":"267","volume":"19","author":"N Carlini","year":"2019","unstructured":"Carlini N, Liu C, Erlingsson \u00da et al (2019) The secret sharer: evaluating and testing unintended memorization in neural networks. USENIX Secur 19:267\u2013284","journal-title":"USENIX Secur"},{"key":"11024_CR23","first-page":"2633","volume":"21","author":"N Carlini","year":"2021","unstructured":"Carlini N, Tramer F, Wallace E et al (2021) Extracting training data from large language models. USENIX Secur 21:2633\u20132650","journal-title":"USENIX Secur"},{"key":"11024_CR24","first-page":"5253","volume":"23","author":"N Carlini","year":"2023","unstructured":"Carlini N, Hayes J, Nasr M et al (2023) Extracting training data from diffusion models. USENIX Secur 23:5253\u20135270","journal-title":"USENIX Secur"},{"key":"11024_CR25","unstructured":"Carlini N, Ippolito D, Jagielski M, et al (2023b) Quantifying memorization across neural language models. In: Proc. of ICLR"},{"key":"11024_CR26","unstructured":"Cheng M, Le T, Chen PY, et al (2018) Query-efficient hard-label black-box attack: an optimization-based approach. arXiv preprint arXiv:1807.04457"},{"key":"11024_CR27","doi-asserted-by":"crossref","unstructured":"Chen J, Jordan MI, Wainwright MJ (2020c) Hopskipjumpattack: A query-efficient decision-based attack. In: 2020 ieee symposium on security and privacy (sp), IEEE, pp 1277\u20131294","DOI":"10.1109\/SP40000.2020.00045"},{"key":"11024_CR28","doi-asserted-by":"crossref","unstructured":"Chen S, Kahla M, Jia R, et al (2021) Knowledge-enriched distributional model inversion attacks. In: Proc. of ICCV, pp 16,178\u201316,187","DOI":"10.1109\/ICCV48922.2021.01587"},{"key":"11024_CR29","doi-asserted-by":"crossref","unstructured":"Chen Y, Liu Y, Dong L, et al (2022) Adaprompt: Adaptive model training for prompt-based nlp. In: Proc. of EMNLP, pp 6057\u20136068","DOI":"10.18653\/v1\/2022.findings-emnlp.448"},{"key":"11024_CR30","unstructured":"Chen D, Orekondy T, Fritz M (2020a) Gs-wgan: A gradient-sanitized approach for learning differentially private generators. In: Proc. of NeurIPS, pp 12,673\u201312,684"},{"key":"11024_CR31","doi-asserted-by":"crossref","unstructured":"Chen D, Yu N, Zhang Y, et al (2020b) Gan-leaks: A taxonomy of membership inference attacks against generative models. In: Proc. of CCS, pp 343\u2013362","DOI":"10.1145\/3372297.3417238"},{"key":"11024_CR32","doi-asserted-by":"crossref","unstructured":"Conneau A, Khandelwal K, Goyal N, et al (2020) Unsupervised cross-lingual representation learning at scale. In: Proc. of ACL, pp 8440\u20138451","DOI":"10.18653\/v1\/2020.acl-main.747"},{"key":"11024_CR33","unstructured":"Cristofaro ED (2020) An overview of privacy in machine learning"},{"key":"11024_CR34","doi-asserted-by":"crossref","unstructured":"Cummings R, Desfontaines D, Evans D, et al (2024) Advancing differential privacy: where we are now and future directions for real-world deployment. Harvard data science review","DOI":"10.1162\/99608f92.d3197524"},{"key":"11024_CR35","doi-asserted-by":"crossref","unstructured":"Deng G, Liu Y, Li Y, et al (2024) Masterkey: Automated jailbreaking of large language model chatbots. In: Proc. of NDSS, NDSS 2024","DOI":"10.14722\/ndss.2024.24188"},{"key":"11024_CR36","doi-asserted-by":"crossref","unstructured":"Deng J, Wang Y, Li J, et al (2021) Tag: Gradient attack on transformer-based language models. In: Proc. of EMNLP, pp 3600\u20133610","DOI":"10.18653\/v1\/2021.findings-emnlp.305"},{"key":"11024_CR37","unstructured":"Devlin J, Chang MW, Lee K, et al (2019) Bert: Pre-training of deep bidirectional transformers for language understanding. In: Proc. of NAACL"},{"key":"11024_CR38","unstructured":"Dhariwal P, Nichol A (2021) Diffusion models beat gans on image synthesis. In: Proc. of NeurIPS, pp 8780\u20138794"},{"key":"11024_CR39","unstructured":"Dhurandhar A, Chen PY, Luss R, et al (2018) Explanations based on the missing: Towards contrastive explanations with pertinent negatives. Advances in neural information processing systems 31"},{"key":"11024_CR40","unstructured":"Dinh L, Krueger D, Bengio Y (2014) Nice: Non-linear independent components estimation. arXiv preprint arXiv:1410.8516"},{"key":"11024_CR41","unstructured":"Dinh L, Sohl-Dickstein J, Bengio S (2016) Density estimation using real nvp. arXiv preprint arXiv:1605.08803"},{"key":"11024_CR42","unstructured":"Duan J, Kong F, Wang S, et al (2023) Are diffusion models vulnerable to membership inference attacks? In: Proc. of ICML"},{"key":"11024_CR43","doi-asserted-by":"crossref","unstructured":"Dwork C (2006) Differential privacy. In: Proc. of ICALP, pp 1\u201312","DOI":"10.1007\/11787006_1"},{"key":"11024_CR44","unstructured":"Fowl L, Geiping J, Reich S, et al (2022) Decepticons: Corrupted transformers breach privacy in federated learning for language models. In: Proc. of ICLR"},{"key":"11024_CR45","first-page":"17","volume":"14","author":"M Fredrikson","year":"2014","unstructured":"Fredrikson M, Lantz E, Jha S et al (2014) Privacy in pharmacogenetics: an $$\\{$$End-to-End$$\\}$$ case study of personalized warfarin dosing. USENIX Secur 14:17\u201332","journal-title":"USENIX Secur"},{"key":"11024_CR46","doi-asserted-by":"crossref","unstructured":"Fredrikson M, Jha S, Ristenpart T (2015) Model inversion attacks that exploit confidence information and basic countermeasures. In: Proc. of CCS, pp 1322\u20131333","DOI":"10.1145\/2810103.2813677"},{"key":"11024_CR47","doi-asserted-by":"crossref","unstructured":"Fu J, Ling X, Qian Y, et al (2024) Towards query-efficient decision-based adversarial attacks through frequency domain. In: 2024 IEEE International Conference on Multimedia and Expo (ICME), IEEE, pp 1\u20136","DOI":"10.1109\/ICME57554.2024.10687789"},{"key":"11024_CR48","unstructured":"Gal R, Alaluf Y, Atzmon Y, et al (2022) An image is worth one word: personalizing text-to-image generation using textual inversion. In: Proc. of ICLR"},{"key":"11024_CR49","doi-asserted-by":"crossref","unstructured":"Ganju K, Wang Q, Yang W, et al (2018) Property inference attacks on fully connected neural networks using permutation invariant representations. In: Proc. of CCS, pp 619\u2013633","DOI":"10.1145\/3243734.3243834"},{"key":"11024_CR50","doi-asserted-by":"crossref","unstructured":"Gao T, Fisch A, Chen D (2021) Making pre-trained language models better few-shot learners. In: Proc. of ACL\/IJCNLP, pp 3816\u20133830","DOI":"10.18653\/v1\/2021.acl-long.295"},{"key":"11024_CR51","doi-asserted-by":"crossref","unstructured":"Golda A, Mekonen K, Pandey A, et al (2024) Privacy and security concerns in generative ai: a comprehensive survey. IEEE Access","DOI":"10.1109\/ACCESS.2024.3381611"},{"key":"11024_CR52","unstructured":"Gomez AN, Ren M, Urtasun R, et al (2017) The reversible residual network: backpropagation without storing activations. In: Proc. of NeurIPS"},{"key":"11024_CR53","unstructured":"Goodfellow I, Pouget-Abadie J, Mirza M, et al (2014) Generative adversarial nets. In: Proc. of NeurIPS"},{"key":"11024_CR54","doi-asserted-by":"crossref","unstructured":"Gu Y, Han X, Liu Z, et al (2022) Ppt: Pre-trained prompt tuning for few-shot learning. In: Proc. of ACL, pp 8410\u20138423","DOI":"10.18653\/v1\/2022.acl-long.576"},{"key":"11024_CR55","unstructured":"Gulrajani I, Ahmed F, Arjovsky M, et al (2017) Improved training of wasserstein gans. In: Proc. of NeurIPS"},{"key":"11024_CR56","doi-asserted-by":"crossref","unstructured":"Guo D, Rush AM, Kim Y (2021) Parameter-efficient transfer learning with diff pruning. In: Proc. of ACL\/IJCNLP, pp 4884\u20134896","DOI":"10.18653\/v1\/2021.acl-long.378"},{"key":"11024_CR57","unstructured":"Gupta S, Huang Y, Zhong Z, et al (2022) Recovering private text in federated learning of language models"},{"key":"11024_CR58","doi-asserted-by":"crossref","unstructured":"Han G, Choi J, Lee H, et al (2023) Reinforcement learning-based black-box model inversion attacks. In: Proc. of CVPR, pp 20,504\u201320,513","DOI":"10.1109\/CVPR52729.2023.01964"},{"key":"11024_CR59","doi-asserted-by":"publisher","first-page":"133","DOI":"10.2478\/popets-2019-0008","volume":"1","author":"J Hayes","year":"2019","unstructured":"Hayes J, Melis L, Danezis G et al (2019) Logan: Membership inference attacks against generative models. PoPETs 1:133\u2013152","journal-title":"PoPETs"},{"key":"11024_CR60","doi-asserted-by":"publisher","first-page":"232","DOI":"10.2478\/popets-2019-0067","volume":"4","author":"B Hilprecht","year":"2019","unstructured":"Hilprecht B, H\u00e4rterich M, Bernau D (2019) Monte Carlo and reconstruction membership inference attacks against generative models. PoPETs 4:232\u2013249","journal-title":"PoPETs"},{"key":"11024_CR61","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1162\/tacl_a_00299","volume":"8","author":"S Hisamoto","year":"2020","unstructured":"Hisamoto S, Post M, Duh K (2020) Membership inference attacks on sequence-to-sequence models: Is my data in your machine translation system? Trans Assoc Comput Linguist 8:49\u201363","journal-title":"Trans Assoc Comput Linguist"},{"key":"11024_CR62","doi-asserted-by":"crossref","unstructured":"Hitaj B, Ateniese G, Perez-Cruz F (2017) Deep models under the gan: Information leakage from collaborative deep learning. In: Proc. of CCS, p 603-618","DOI":"10.1145\/3133956.3134012"},{"issue":"8","key":"11024_CR63","doi-asserted-by":"publisher","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","volume":"9","author":"S Hochreiter","year":"1997","unstructured":"Hochreiter S, Schmidhuber J (1997) Long short-term memory. Neural Comput 9(8):1735\u20131780","journal-title":"Neural Comput"},{"key":"11024_CR64","unstructured":"Ho J, Jain A, Abbeel P (2020) Denoising diffusion probabilistic models. In: Proc. of NeurIPS, pp 6840\u20136851"},{"key":"11024_CR65","doi-asserted-by":"crossref","unstructured":"Hoory S, Feder A, Tendler A, et al (2021) Learning and evaluating a differentially private pre-trained language model. In: Proc. of EMNLP, pp 1178\u20131189","DOI":"10.18653\/v1\/2021.findings-emnlp.102"},{"key":"11024_CR66","unstructured":"Ho J, Salimans T (2021) Classifier-free diffusion guidance. In: NeurIPS 2021 workshop on deep generative models and downstream applications"},{"key":"11024_CR67","unstructured":"Houlsby N, Giurgiu A, Jastrzebski S, et al (2019) Parameter-efficient transfer learning for nlp. In: Proc. of ICML, pp 2790\u20132799"},{"key":"11024_CR68","doi-asserted-by":"crossref","unstructured":"Howard J, Ruder S (2018) Universal language model fine-tuning for text classification. In: Proc. of ACL, pp 328\u2013339","DOI":"10.18653\/v1\/P18-1031"},{"key":"11024_CR69","unstructured":"Hu EJ, Shen Y, Wallis P, et al (2022a) Lora: Low-rank adaptation of large language models. In: Proc. of ICLR"},{"key":"11024_CR70","unstructured":"Hu EJ, Wallis P, Allen-Zhu Z, et al (2021) Lora: Low-rank adaptation of large language models. In: Proc. of ICLR"},{"issue":"11s","key":"11024_CR71","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3523273","volume":"54","author":"H Hu","year":"2022","unstructured":"Hu H, Salcic Z, Sun L et al (2022) Membership inference attacks on machine learning: a survey. ACM Comput Surv 54(11s):1\u201337","journal-title":"ACM Comput Surv"},{"issue":"8","key":"11024_CR72","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10462-024-10846-8","volume":"57","author":"K Hu","year":"2024","unstructured":"Hu K, Gong S, Zhang Q et al (2024) An overview of implementing security and privacy in federated learning. Artif Intell Rev 57(8):1\u201366","journal-title":"Artif Intell Rev"},{"issue":"7","key":"11024_CR73","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1007\/s10462-024-10824-0","volume":"57","author":"X Huang","year":"2024","unstructured":"Huang X, Ruan W, Huang W et al (2024) A survey of safety and trustworthiness of large language models through the lens of verification and validation. Artif Intell Rev 57(7):175","journal-title":"Artif Intell Rev"},{"key":"11024_CR74","doi-asserted-by":"crossref","unstructured":"Huang J, Shao H, Chang KCC (2022) Are large pre-trained language models leaking your personal information? In: Proc. of EMNLP, pp 2038\u20132047","DOI":"10.18653\/v1\/2022.findings-emnlp.148"},{"key":"11024_CR75","unstructured":"Hu P, Wang Z, Sun R, et al (2022c) $${\\text{M}}^4$$i: Multi-modal models membership inference. In: Proc. of NeurIPS"},{"key":"11024_CR76","doi-asserted-by":"crossref","unstructured":"Jacob P, Zablocki \u00c9, Ben-Younes H, et al (2022) Steex: steering counterfactual explanations with semantics. In: European Conference on Computer Vision, Springer, pp 387\u2013403","DOI":"10.1007\/978-3-031-19775-8_23"},{"key":"11024_CR77","unstructured":"Jagannatha A, Rawat BPS, Yu H (2021) Membership inference attack susceptibility of clinical language models. arXiv preprint arXiv:2104.08305"},{"key":"11024_CR78","unstructured":"Jagielski M, Nasr M, Lee K, et al (2024) Students parrot their teachers: membership inference on model distillation. In: Proc. of NeurIPS"},{"key":"11024_CR79","doi-asserted-by":"crossref","unstructured":"Jeanneret G, Simon L, Jurie F (2022) Diffusion models for counterfactual explanations. In: Proceedings of the Asian Conference on Computer Vision, pp 858\u2013876","DOI":"10.1007\/978-3-031-26293-7_14"},{"key":"11024_CR80","doi-asserted-by":"crossref","unstructured":"Jeanneret G, Simon L, Jurie F (2023) Adversarial counterfactual visual explanations. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 16,425\u201316,435","DOI":"10.1109\/CVPR52729.2023.01576"},{"key":"11024_CR81","doi-asserted-by":"crossref","unstructured":"Jeanneret G, Simon L, Jurie F (2024) Text-to-image models for counterfactual explanations: a black-box approach. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pp 4757\u20134767","DOI":"10.1109\/WACV57701.2024.00469"},{"issue":"Suppl 2","key":"11024_CR82","doi-asserted-by":"publisher","first-page":"1919","DOI":"10.1007\/s10462-023-10567-4","volume":"56","author":"H Jia","year":"2023","unstructured":"Jia H, Rao H, Wen C et al (2023) Crayfish optimization algorithm. Artif Intell Rev 56(Suppl 2):1919\u20131979","journal-title":"Artif Intell Rev"},{"issue":"2","key":"11024_CR83","doi-asserted-by":"publisher","first-page":"344","DOI":"10.1016\/j.ijrobp.2017.04.021","volume":"99","author":"A Jochems","year":"2017","unstructured":"Jochems A, Deist TM, El Naqa I et al (2017) Developing and validating a survival prediction model for nsclc patients through distributed learning across 3 countries. Int J Radiat Oncol Biol Phys 99(2):344\u2013352","journal-title":"Int J Radiat Oncol Biol Phys"},{"key":"11024_CR84","unstructured":"Jordon J, Yoon J, Van Der Schaar M (2018) Pate-gan: Generating synthetic data with differential privacy guarantees. In: Proc. of ICLR"},{"key":"11024_CR85","doi-asserted-by":"crossref","unstructured":"Kahla M, Chen S, Just HA, et al (2022) Label-only model inversion attacks via boundary repulsion. In: Proc. of CVPR, pp 15,045\u201315,053","DOI":"10.1109\/CVPR52688.2022.01462"},{"key":"11024_CR86","doi-asserted-by":"crossref","unstructured":"Kansy M, Ra\u00ebl A, Mignone G, et al (2023) Controllable inversion of black-box face recognition models via diffusion. In: Proc. of ICCV, pp 3167\u20133177","DOI":"10.1109\/ICCVW60793.2023.00341"},{"key":"11024_CR87","unstructured":"Karimi Mahabadi R, Henderson J, Ruder S (2021) Compacter: Efficient low-rank hypercomplex adapter layers. In: Proc. of NeurIPS, pp 1022\u20131035"},{"key":"11024_CR88","unstructured":"Karras T, Aila T, Laine S, et al (2018) Progressive growing of gans for improved quality, stability, and variation. In: Proc. of ICLR"},{"key":"11024_CR89","doi-asserted-by":"crossref","unstructured":"Karras T, Laine S, Aila T (2019) A style-based generator architecture for generative adversarial networks. In: Proc. of CVPR, pp 4401\u20134410","DOI":"10.1109\/CVPR.2019.00453"},{"key":"11024_CR90","doi-asserted-by":"crossref","unstructured":"Karras T, Laine S, Aittala M, et al (2020) Analyzing and improving the image quality of stylegan. In: Proc. of CVPR, pp 8110\u20138119","DOI":"10.1109\/CVPR42600.2020.00813"},{"issue":"11","key":"11024_CR91","doi-asserted-by":"publisher","first-page":"4997","DOI":"10.1109\/TNNLS.2020.3026572","volume":"32","author":"A Khajenezhad","year":"2020","unstructured":"Khajenezhad A, Madani H, Beigy H (2020) Masked autoencoder for distribution estimation on small structured data sets. IEEE Trans Neural Netw Learn Syst 32(11):4997\u20135007","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"issue":"Suppl 3","key":"11024_CR92","doi-asserted-by":"publisher","first-page":"2917","DOI":"10.1007\/s10462-023-10595-0","volume":"56","author":"A Khan","year":"2023","unstructured":"Khan A, Rauf Z, Sohail A et al (2023) A survey of the vision transformers and their cnn-transformer based variants. Artif Intell Rev 56(Suppl 3):2917\u20132970","journal-title":"Artif Intell Rev"},{"key":"11024_CR93","doi-asserted-by":"crossref","unstructured":"Kim G, Kwon T, Ye JC (2022) Diffusionclip: Text-guided diffusion models for robust image manipulation. In: Proc. of CVPR, pp 2426\u20132435","DOI":"10.1109\/CVPR52688.2022.00246"},{"key":"11024_CR94","unstructured":"Kingma DP, Ba J (2015) Adam: A method for stochastic optimization. In: Proc. of ICLR"},{"key":"11024_CR95","unstructured":"Kingma DP, Dhariwal P (2018) Glow: Generative flow with invertible 1x1 convolutions. In: Proc. of NeurIPS"},{"key":"11024_CR96","unstructured":"Kingma DP, Welling M (2013) Auto-encoding variational bayes. arXiv preprint arXiv:1312.6114"},{"key":"11024_CR97","doi-asserted-by":"crossref","unstructured":"Ko M, Jin M, Wang C, et al (2023) Practical membership inference attacks against large-scale multi-modal models: a pilot study. In: Proc of ICCV pp 4848\u20134858","DOI":"10.1109\/ICCV51070.2023.00449"},{"key":"11024_CR98","unstructured":"Kong F, Duan J, Ma R, et al (2024) An efficient membership inference attack for the diffusion model by proximal initialization. In: Proc. of ICLR"},{"key":"11024_CR99","unstructured":"Krizhevsky A, Hinton G, et al (2009) Learning multiple layers of features from tiny images"},{"key":"11024_CR100","doi-asserted-by":"publisher","first-page":"4924","DOI":"10.1109\/TIFS.2021.3117075","volume":"16","author":"A Kuppa","year":"2021","unstructured":"Kuppa A, Le-Khac NA (2021) Adversarial xai methods in cybersecurity. IEEE Trans Inf Forensics Secur 16:4924\u20134938","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"11024_CR101","unstructured":"Lan Z, Chen M, Goodman S, et al (2020) Albert: A lite bert for self-supervised learning of language representations. In: Proc. of ICLR"},{"key":"11024_CR102","doi-asserted-by":"crossref","unstructured":"Lang O, Gandelsman Y, Yarom M, et al (2021) Explaining in style: training a gan to explain a classifier in stylespace. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 693\u2013702","DOI":"10.1109\/ICCV48922.2021.00073"},{"issue":"11","key":"11024_CR103","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun Y, Bottou L, Bengio Y et al (1998) Gradient-based learning applied to document recognition. Proc IEEE 86(11):2278\u20132324","journal-title":"Proc IEEE"},{"key":"11024_CR104","doi-asserted-by":"crossref","unstructured":"Lester B, Al-Rfou R, Constant N (2021) The power of scale for parameter-efficient prompt tuning. In: Proc. of EMNLP, pp 3045\u20133059","DOI":"10.18653\/v1\/2021.emnlp-main.243"},{"key":"11024_CR105","doi-asserted-by":"crossref","unstructured":"Lewis M, Liu Y, Goyal N, et al (2020) Bart: Denoising sequence-to-sequence pre-training for natural language generation, translation, and comprehension. In: Proc. of ACL","DOI":"10.18653\/v1\/2020.acl-main.703"},{"key":"11024_CR106","unstructured":"Li XL, Liang P (2021) Prefix-tuning: optimizing continuous prompts for generation. In: Proc. of ACL\/IJCNLP, pp 4582\u20134597"},{"key":"11024_CR107","doi-asserted-by":"crossref","unstructured":"Li H, Guo D, Fan W, et al (2023) Multi-step jailbreaking privacy attacks on chatgpt. In: Proc. of EMNLP","DOI":"10.18653\/v1\/2023.findings-emnlp.272"},{"key":"11024_CR108","doi-asserted-by":"crossref","unstructured":"Li S, Liu H, Dong T, et al (2021) Hidden backdoors in human-centric language models. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp 3123\u20133140","DOI":"10.1145\/3460120.3484576"},{"key":"11024_CR109","unstructured":"Li X, Tramer F, Liang P, et al (2022) Large language models can be strong differentially private learners. In: Proc. of ICLR"},{"key":"11024_CR110","doi-asserted-by":"crossref","unstructured":"Liu KS, Xiao C, Li B, et al (2019a) Performing co-membership attacks against deep generative models. In: IEEE ICDM, pp 459\u2013467","DOI":"10.1109\/ICDM.2019.00056"},{"key":"11024_CR111","doi-asserted-by":"publisher","first-page":"4566","DOI":"10.1109\/ACCESS.2020.3045078","volume":"9","author":"X Liu","year":"2020","unstructured":"Liu X, Xie L, Wang Y et al (2020) Privacy and security issues in deep learning: a survey. IEEE Access 9:4566\u20134593","journal-title":"IEEE Access"},{"issue":"2","key":"11024_CR112","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3436755","volume":"54","author":"B Liu","year":"2021","unstructured":"Liu B, Ding M, Shaham S et al (2021) When machine learning meets privacy: a survey and outlook. ACM Comput Surv 54(2):1\u201336","journal-title":"ACM Comput Surv"},{"issue":"8","key":"11024_CR113","doi-asserted-by":"publisher","first-page":"199","DOI":"10.1007\/s10462-024-10841-z","volume":"57","author":"J Liu","year":"2024","unstructured":"Liu J, Li Y, Guo Y et al (2024) Generation and countermeasures of adversarial examples on vision: a survey. Artif Intell Rev 57(8):199","journal-title":"Artif Intell Rev"},{"key":"11024_CR114","doi-asserted-by":"crossref","unstructured":"Liu Z, Luo P, Wang X, et al (2015) Deep learning face attributes in the wild. In: Proceedings of the IEEE international conference on computer vision, pp 3730\u20133738","DOI":"10.1109\/ICCV.2015.425"},{"key":"11024_CR115","unstructured":"Liu Y, Ott M, Goyal N, et al (2019b) Roberta: A robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692"},{"key":"11024_CR116","doi-asserted-by":"crossref","unstructured":"Liu X, Park DH, Azadi S, et al (2023a) More control for free! image synthesis with semantic diffusion guidance. In: Proc. of WACV, pp 289\u2013299","DOI":"10.1109\/WACV56688.2023.00037"},{"key":"11024_CR117","doi-asserted-by":"crossref","unstructured":"Liu Y, Peng J, James J, et al (2019c) Ppgan: Privacy-preserving generative adversarial network. In: IEEE (ICPADS), pp 985\u2013989","DOI":"10.1109\/ICPADS47876.2019.00150"},{"key":"11024_CR118","unstructured":"Liu H, Tam D, Muqeeth M, et al (2022) Few-shot parameter-efficient fine-tuning is better and cheaper than in-context learning. In: Proc. of NeurIPS, pp 1950\u20131965"},{"key":"11024_CR119","doi-asserted-by":"crossref","unstructured":"Liu R, Wang D, Ren Y, et al (2024b) Unstoppable attack: label-only model inversion via conditional diffusion model. In: IEEE TransInf Forensics Security","DOI":"10.1109\/TIFS.2024.3372815"},{"key":"11024_CR120","doi-asserted-by":"crossref","unstructured":"Liu X, Zheng Y, Du Z, et al (2023b) Gpt understands, too. AI Open","DOI":"10.1016\/j.aiopen.2023.08.012"},{"key":"11024_CR121","doi-asserted-by":"crossref","unstructured":"Lu J, Zhang XS, Zhao T, et al (2022) April: Finding the achilles\u2019 heel on privacy for vision transformers. In: Proc. of CVPR, pp 10,051\u201310,060","DOI":"10.1109\/CVPR52688.2022.00981"},{"key":"11024_CR122","doi-asserted-by":"crossref","unstructured":"Maho T, Furon T, Le Merrer E (2021) Surfree: a fast surrogate-free black-box attack. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 10,430\u201310,439","DOI":"10.1109\/CVPR46437.2021.01029"},{"key":"11024_CR123","doi-asserted-by":"crossref","unstructured":"Makadia A, Pavlovic V, Kumar S (2008) A new baseline for image annotation. In: Computer vision\u2013ECCV 2008: 10th European conference on computer vision, Marseille, France, October 12-18, 2008, Proceedings, Part III 10, Springer, pp 316\u2013329","DOI":"10.1007\/978-3-540-88690-7_24"},{"key":"11024_CR124","doi-asserted-by":"crossref","unstructured":"Matsumoto T, Miura T, Yanai N (2023) Membership inference attacks against diffusion models. In: IEEE(SPW), pp 77\u201383","DOI":"10.1109\/SPW59333.2023.00013"},{"key":"11024_CR125","doi-asserted-by":"crossref","unstructured":"Mattern J, Mireshghallah F, Jin Z, et al (2023) Membership inference attacks against language models via neighbourhood comparison. In: Proc. of ACL, pp 11,330\u201311,343","DOI":"10.18653\/v1\/2023.findings-acl.719"},{"key":"11024_CR126","unstructured":"Mireshghallah F, Backurs A, Inan HA, et al (2022a) Differentially private model compression. In: Proc. of NeurIPS, pp 29,468\u201329,483"},{"key":"11024_CR127","doi-asserted-by":"crossref","unstructured":"Mireshghallah F, Goyal K, Uniyal A, et al (2022b) Quantifying privacy risks of masked language models using membership inference attacks. In: Proc. of EMNLP, pp 8332\u20138347","DOI":"10.18653\/v1\/2022.emnlp-main.570"},{"key":"11024_CR128","unstructured":"Mireshghallah F, Taram M, Vepakomma P, et al (2020) Privacy in deep learning: a survey. arXiv preprint arXiv:2004.12254"},{"key":"11024_CR129","unstructured":"Mirza M, Osindero S (2014) Conditional generative adversarial nets. arXiv preprint arXiv:1411.1784"},{"key":"11024_CR130","unstructured":"Miyato T, Kataoka T, Koyama M, et al (2018) Spectral normalization for generative adversarial networks. In: Proc. of ICLR"},{"key":"11024_CR131","unstructured":"Nasr M, Carlini N, Hayase J, et al (2023) Scalable extraction of training data from (production) language models"},{"key":"11024_CR132","unstructured":"Nguyen BN, Chandrasegaran K, Abdollahzadeh M, et al (2024) Label-only model inversion attacks via knowledge transfer. In: Proc. of NeurIPS"},{"key":"11024_CR133","doi-asserted-by":"crossref","unstructured":"Nguyen NB, Chandrasegaran K, Abdollahzadeh M, et al (2023) Re-thinking model inversion attacks against deep neural networks. In: Proc. of CVPR, pp 384\u2013393","DOI":"10.1109\/CVPR52729.2023.01572"},{"key":"11024_CR134","doi-asserted-by":"crossref","unstructured":"Nguyen A, Clune J, Bengio Y, et al (2017) Plug & play generative networks: conditional iterative generation of images in latent space. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 4467\u20134477","DOI":"10.1109\/CVPR.2017.374"},{"key":"11024_CR135","unstructured":"Nichol AQ, Dhariwal P, Ramesh A, et al (2022) Glide: Towards photorealistic image generation and editing with text-guided diffusion models. In: Proc. of ICML, PMLR, pp 16,784\u201316,804"},{"key":"11024_CR136","unstructured":"Odena A, Olah C, Shlens J (2017) Conditional image synthesis with auxiliary classifier gans. In: Proc. of ICML, PMLR, pp 2642\u20132651"},{"issue":"14s","key":"11024_CR137","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3595292","volume":"55","author":"D Oliynyk","year":"2023","unstructured":"Oliynyk D, Mayer R, Rauber A (2023) I know what you trained last summer: a survey on stealing machine learning models and defences. ACM Comput Surv 55(14s):1\u201341","journal-title":"ACM Comput Surv"},{"key":"11024_CR138","doi-asserted-by":"crossref","unstructured":"Pennington J, Socher R, Manning C (2014) GloVe: Global vectors for word representation. In: Proceedings of the 2014 conference on empirical methods in natural language processing (EMNLP), pp 1532\u20131543","DOI":"10.3115\/v1\/D14-1162"},{"key":"11024_CR139","doi-asserted-by":"crossref","unstructured":"Peters ME, Neumann M, Zettlemoyer L, et al (2018) Dissecting contextual word embeddings: architecture and representation. In: Proc. of EMNLP, pp 1499\u20131509","DOI":"10.18653\/v1\/D18-1179"},{"key":"11024_CR140","doi-asserted-by":"crossref","unstructured":"Qi G, Chen Y, Mao X, et al (2023) Model inversion attack via dynamic memory learning. In: Proc. of MM \u201923, pp 5614\u20135622","DOI":"10.1145\/3581783.3612072"},{"key":"11024_CR141","doi-asserted-by":"crossref","unstructured":"Qin G, Eisner J (2021) Learning how to ask: querying lms with mixtures of soft prompts. In: Proc. of NAACL, pp 5203\u20135212","DOI":"10.18653\/v1\/2021.naacl-main.410"},{"issue":"8","key":"11024_CR142","first-page":"9","volume":"1","author":"A Radford","year":"2019","unstructured":"Radford A, Wu J, Child R et al (2019) Language models are unsupervised multitask learners. OpenAI blog 1(8):9","journal-title":"OpenAI blog"},{"key":"11024_CR143","unstructured":"Radford A, Kim JW, Hallacy C, et al (2021) Learning transferable visual models from natural language supervision. In: Proc. of ICML, pp 8748\u20138763"},{"key":"11024_CR144","unstructured":"Radford A, Metz L, Chintala S (2015) Unsupervised representation learning with deep convolutional generative adversarial networks. arXiv preprint arXiv:1511.06434"},{"key":"11024_CR145","unstructured":"Radford A, Narasimhan K, Salimans T, et al (2018) Improving language understanding by generative pre-training. arXiv:2001.08361"},{"key":"11024_CR146","unstructured":"Rae JW, Borgeaud S, Cai T, et al (2021) Scaling language models: methods, analysis & insights from training gopher. arXiv preprint arXiv:2112.11446"},{"issue":"1","key":"11024_CR147","first-page":"5485","volume":"21","author":"C Raffel","year":"2020","unstructured":"Raffel C, Shazeer N, Roberts A et al (2020) Exploring the limits of transfer learning with a unified text-to-text transformer. J Mach Learn Res 21(1):5485\u20135551","journal-title":"J Mach Learn Res"},{"key":"11024_CR148","unstructured":"Ramesh A, Dhariwal P, Nichol A, et al (2022) Hierarchical text-conditional image generation with clip latents. arXiv preprint arXiv:2204.06125"},{"issue":"4","key":"11024_CR149","first-page":"1","volume":"13","author":"H Ren","year":"2022","unstructured":"Ren H, Deng J, Xie X (2022) Grnn: Generative regression neural network-a data leakage attack for federated learning. Acm T Intel Syst Tec 13(4):1\u201324","journal-title":"Acm T Intel Syst Tec"},{"issue":"4","key":"11024_CR150","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3624010","volume":"56","author":"M Rigaki","year":"2023","unstructured":"Rigaki M, Garcia S (2023) A survey of privacy attacks in machine learning. ACM Comput Surv 56(4):1\u201334","journal-title":"ACM Comput Surv"},{"key":"11024_CR151","doi-asserted-by":"crossref","unstructured":"Rombach R, Blattmann A, Lorenz D, et al (2022) High-resolution image synthesis with latent diffusion models. In: Proc. of CVPR, pp 10,684\u201310,695","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"11024_CR152","doi-asserted-by":"crossref","unstructured":"Ruiz N, Li Y, Jampani V, et al (2023) Dreambooth: Fine tuning text-to-image diffusion models for subject-driven generation. In: Proc. of CVPR, pp 22,500\u201322,510","DOI":"10.1109\/CVPR52729.2023.02155"},{"key":"11024_CR153","unstructured":"Rust P, S\u00f8gaard A (2023) Differential privacy, linguistic fairness, and training data influence: impossibility and possibility theorems for multilingual language models. In: Proc. of ICML, pp 29,354\u201329,387"},{"issue":"7","key":"11024_CR154","doi-asserted-by":"publisher","first-page":"184","DOI":"10.1007\/s10462-024-10766-7","volume":"57","author":"S Saha","year":"2024","unstructured":"Saha S, Hota A, Chattopadhyay AK et al (2024) A multifaceted survey on privacy preservation of federated learning: progress, challenges, and opportunities. Artif Intell Rev 57(7):184","journal-title":"Artif Intell Rev"},{"key":"11024_CR155","unstructured":"Saharia C, Chan W, Saxena S, et al (2022) Photorealistic text-to-image diffusion models with deep language understanding. In: Proc. of NeurIPS, pp 36,479\u201336,494"},{"key":"11024_CR156","unstructured":"Sanh V, Webson A, Raffel C, et al (2022) Multitask prompted training enables zero-shot task generalization. In: Proc. of ICLR"},{"key":"11024_CR157","doi-asserted-by":"crossref","unstructured":"Schick T, Sch\u00fctze H (2021) Exploiting cloze questions for few shot text classification and natural language inference. In: Proc. of EACL, pp 255\u2013269","DOI":"10.18653\/v1\/2021.eacl-main.20"},{"key":"11024_CR158","unstructured":"Schuhmann C, Vencu R, Beaumont R, et al (2021) Laion-400m: Open dataset of clip-filtered 400 million image-text pairs. arXiv preprint arXiv:2111.02114"},{"key":"11024_CR159","doi-asserted-by":"crossref","unstructured":"Shafran A, Peleg S, Hoshen Y (2021) Membership inference attacks are easier on difficult problems. In: Proc. of ICCV, pp 14,820\u201314,829","DOI":"10.1109\/ICCV48922.2021.01455"},{"key":"11024_CR160","unstructured":"Shi Z, Lipani A (2024) Don\u2019t stop pretraining? make prompt-based fine-tuning powerful learner. In: Proc. of NeurIPS"},{"key":"11024_CR161","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, et al (2017) Membership inference attacks against machine learning models. In: IEEE (SP), pp 3\u201318","DOI":"10.1109\/SP.2017.41"},{"key":"11024_CR162","doi-asserted-by":"crossref","unstructured":"Socher R, Perelygin A, Wu J, et al (2013) Recursive deep models for semantic compositionality over a sentiment treebank. In: Proceedings of the 2013 conference on empirical methods in natural language processing, pp 1631\u20131642","DOI":"10.18653\/v1\/D13-1170"},{"issue":"10","key":"11024_CR163","doi-asserted-by":"publisher","first-page":"2430","DOI":"10.1109\/JSAC.2020.3000372","volume":"38","author":"M Song","year":"2020","unstructured":"Song M, Wang Z, Zhang Z et al (2020) Analyzing user-level privacy attack against federated learning. IEEE J Sel Areas Commun 38(10):2430\u20132444","journal-title":"IEEE J Sel Areas Commun"},{"key":"11024_CR164","unstructured":"Song Y, Ermon S (2019) Generative modeling by estimating gradients of the data distribution. In: Proc. of NeurIPS"},{"key":"11024_CR165","doi-asserted-by":"crossref","unstructured":"Song C, Raghunathan A (2020) Information leakage in embedding models. In: Proc. of CCS, pp 377\u2013390","DOI":"10.1145\/3372297.3417270"},{"key":"11024_CR166","doi-asserted-by":"crossref","unstructured":"Song C, Shmatikov V (2019) Auditing data provenance in text-generation models. In: Proc. of SIGKDD, pp 196\u2013206","DOI":"10.1145\/3292500.3330885"},{"key":"11024_CR167","unstructured":"Song Y, Shu R, Kushman N, et al (2018) Constructing unrestricted adversarial examples with generative models. Adv Neural Inform Process Syst 31"},{"key":"11024_CR168","unstructured":"Song Y, Sohl-Dickstein J, Kingma DP, et al (2020b) Score-based generative modeling through stochastic differential equations. In: Proc. of ICLR"},{"issue":"2","key":"11024_CR169","doi-asserted-by":"publisher","first-page":"1427","DOI":"10.1007\/s10462-022-10204-6","volume":"56","author":"S Sousa","year":"2023","unstructured":"Sousa S, Kern R (2023) How to keep text private? A systematic review of deep learning methods for privacy-preserving natural language processing. Artif Intell Rev 56(2):1427\u20131492","journal-title":"Artif Intell Rev"},{"key":"11024_CR170","unstructured":"Struppek L, Hintersdorf D, Correira ADA, et al (2022) Plug & play attacks: towards robust and flexible model inversion attacks. In: Proc. of ICML, pp 20,522\u201320,545"},{"key":"11024_CR171","unstructured":"Sung YL, Cho J, Bansal M (2022) Lst: Ladder side-tuning for parameter and memory efficient transfer learning. In: Proc. of NeurIPS, pp 12,991\u201313,005"},{"key":"11024_CR172","unstructured":"Sung YL, Nair V, Raffel CA (2021) Training neural networks with fixed sparse masks. In: Proc. of NeurIPS, pp 24,193\u201324,205"},{"key":"11024_CR173","unstructured":"Su Y, Wang X, Qin Y, et al (2021) On transferability of prompt tuning for natural language processing. In: Proc. of NAACL, pp 3949\u20133969"},{"key":"11024_CR174","unstructured":"Szegedy C, Zaremba W, Sutskever I, et al (2013) Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199"},{"key":"11024_CR175","doi-asserted-by":"crossref","unstructured":"Thomas A, Adelani DI, Davody A, et al (2020) Investigating the impact of pre-trained word embeddings on memorization in neural networks. In: Proc. of TSD, pp 273\u2013281","DOI":"10.1007\/978-3-030-58323-1_30"},{"key":"11024_CR176","doi-asserted-by":"crossref","unstructured":"Tian Z, Cui L, Zhang C, et al (2023) The role of class information in model inversion attacks against image deep learning classifiers. IEEE Trans Dependable Secure Comput","DOI":"10.1109\/TDSC.2023.3306748"},{"key":"11024_CR177","doi-asserted-by":"crossref","unstructured":"Torkzadehmahani R, Kairouz P, Paten B (2019) Dp-cgan: Differentially private synthetic data and label generation. In: CVPR workshop","DOI":"10.1109\/CVPRW.2019.00018"},{"key":"11024_CR178","doi-asserted-by":"crossref","unstructured":"Triastcyn A, Faltings B (2019) Federated generative privacy. In: Proc. of IJCAIW","DOI":"10.1109\/MIS.2020.2993966"},{"key":"11024_CR179","unstructured":"Vahdat A, Kautz J (2020) Nvae: A deep hierarchical variational autoencoder. In: Proc. of NeurIPS, pp 19,667\u201319,679"},{"key":"11024_CR180","unstructured":"Van Den Oord A, Vinyals O, et al (2017) Neural discrete representation learning. In: Proc. of NeurIPS"},{"key":"11024_CR181","first-page":"27916","volume":"34","author":"G van den Burg","year":"2021","unstructured":"van den Burg G, Williams C (2021) On memorization in probabilistic deep generative models. Adv Neural Inform Process Syst 34:27916\u201327928","journal-title":"Adv Neural Inform Process Syst"},{"key":"11024_CR182","unstructured":"Van den Oord A, Kalchbrenner N, Espeholt L, et al (2016) Conditional image generation with pixelcnn decoders. In: Proc. of NeurIPS"},{"key":"11024_CR183","unstructured":"Vaswani A, Shazeer N, Parmar N, et al (2017) Attention is all you need. In: Proc. of NeurIPS"},{"key":"11024_CR184","doi-asserted-by":"crossref","unstructured":"Vu T, Lester B, Constant N, et al (2022) SPoT: Better frozen model adaptation through soft prompt transfer. In: Proc. of ACL, pp 5039\u20135059","DOI":"10.18653\/v1\/2022.acl-long.346"},{"key":"11024_CR185","first-page":"841","volume":"31","author":"S Wachter","year":"2017","unstructured":"Wachter S, Mittelstadt B, Russell C (2017) Counterfactual explanations without opening the black box: automated decisions and the gdpr. Harv JL Tech 31:841","journal-title":"Harv JL Tech"},{"key":"11024_CR186","unstructured":"Wang KC, Fu Y, Li K, et al (2021) Variational model inversion attacks. In: Proc. of NeurIPS, pp 9706\u20139719"},{"key":"11024_CR187","doi-asserted-by":"crossref","unstructured":"Wang D, Liu Y, Tang W, et al (2019) signadam++: Learning confidences for deep neural networks. In: Proc. of ICDMW, pp 186\u2013195","DOI":"10.1109\/ICDMW.2019.00037"},{"key":"11024_CR188","doi-asserted-by":"crossref","unstructured":"Wang D, Xu T, Zhang H, et al (2022) Pwprop: A progressive weighted adaptive method for training deep neural networks. In: 2022 IEEE 34th International Conference on Tools with Artificial Intelligence (ICTAI), pp 508\u2013515","DOI":"10.1109\/ICTAI56018.2022.00081"},{"key":"11024_CR189","unstructured":"Wen Y, Marchyok L, Hong S, et al (2024) Privacy backdoors: Enhancing membership inference through poisoning pre-trained models. arXiv preprint arXiv:2404.01231"},{"key":"11024_CR190","unstructured":"Wu Y, Yu N, Li Z, et al (2022) Membership inference attacks against text-to-image generation models. arXiv preprint arXiv:2210.00968"},{"key":"11024_CR191","unstructured":"Xie L, Lin K, Wang S, et al (2018) Differentially private generative adversarial network. arXiv preprint arXiv:1802.06739"},{"issue":"9","key":"11024_CR192","doi-asserted-by":"publisher","first-page":"2358","DOI":"10.1109\/TIFS.2019.2897874","volume":"14","author":"C Xu","year":"2019","unstructured":"Xu C, Ren J, Zhang D et al (2019) Ganobfuscator: Mitigating information leakage under gan via differential privacy. IEEE Trans Inf Forensics Secur 14(9):2358\u20132371","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"11024_CR193","unstructured":"Yang AX, Robeyns M, Wang X, et al (2024) Bayesian low-rank adaptation for large language models. In: Proc. of ICLR"},{"key":"11024_CR194","unstructured":"Yang Z, Chang EC, Liang Z (2019) Adversarial neural network inversion via auxiliary knowledge alignment. arXiv preprint arXiv:1902.08552"},{"key":"11024_CR195","doi-asserted-by":"crossref","unstructured":"Ye Z, Luo W, Naseem ML, et al (2023) C2fmi: Corse-to-fine black-box model inversion attack. IEEE Trans Dependable Secure Comput","DOI":"10.1109\/TDSC.2023.3285071"},{"key":"11024_CR196","doi-asserted-by":"crossref","unstructured":"Yuan X, Chen K, Zhang J, et al (2023) Pseudo label-guided model inversion attack via conditional generative adversarial network. In: Proc. of AAAI, pp 3349\u20133357","DOI":"10.1609\/aaai.v37i3.25442"},{"key":"11024_CR197","doi-asserted-by":"crossref","unstructured":"Yuan Z, Wu F, Long Y, et al (2022) Secretgen: Privacy recovery on pre-trained models via distribution discrimination. In: Proc. of ECCV, pp 139\u2013155","DOI":"10.1007\/978-3-031-20065-6_9"},{"key":"11024_CR198","unstructured":"Yu D, Naik S, Backurs A, et al (2022) Differentially private fine-tuning of language models. In: Proc. of ICLR"},{"key":"11024_CR199","unstructured":"Yu D, Zhang H, Chen W, et al (2021) Large scale private learning via low-rank reparametrization. In: Proc. of ICML, pp 12,208\u201312,218"},{"key":"11024_CR200","doi-asserted-by":"crossref","unstructured":"Zaken EB, Ravfogel S, Goldberg Y (2022) Bitfit: Simple parameter-efficient fine-tuning for transformer-based masked language-models. In: Proc. of ACL, pp 1\u20139","DOI":"10.18653\/v1\/2022.acl-short.1"},{"issue":"6","key":"11024_CR201","doi-asserted-by":"publisher","first-page":"4347","DOI":"10.1007\/s10462-021-10123-y","volume":"55","author":"G Zhang","year":"2022","unstructured":"Zhang G, Liu B, Zhu T et al (2022) Visual privacy attacks and defenses in deep learning: a survey. Artif Intell Rev 55(6):4347\u20134401","journal-title":"Artif Intell Rev"},{"key":"11024_CR202","unstructured":"Zhang H, Goodfellow I, Metaxas D, et al (2019) Self-attention generative adversarial networks. In: Proc. of ICML, PMLR, pp 7354\u20137363"},{"key":"11024_CR203","doi-asserted-by":"crossref","unstructured":"Zhang Y, Jia R, Pei H, et al (2020) The secret revealer: Generative model-inversion attacks against deep neural networks. In: Proc. of CVPR, pp 253\u2013261","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"11024_CR204","unstructured":"Zhang X, Ji S, Wang T (2018) Differentially private releasing via deep generative model (technical report). arXiv preprint arXiv:1801.01594"},{"key":"11024_CR205","unstructured":"Zhang N, Li L, Chen X, et al (2022b) Differentiable prompt makes pre-trained language models better few-shot learners. In: Proc. of ICLR"},{"key":"11024_CR206","unstructured":"Zhang G, Liu B, Tian H, et al (2024) How does a deep learning model architecture impact its privacy? a comprehensive study of privacy attacks on cnns and transformers. In: USENIX Security 24"},{"key":"11024_CR207","doi-asserted-by":"crossref","unstructured":"Zhang L, Rao A, Agrawala M (2023) Adding conditional control to text-to-image diffusion models. In: Proc. of CVPR, pp 3836\u20133847","DOI":"10.1109\/ICCV51070.2023.00355"},{"issue":"4","key":"11024_CR208","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1007\/s10462-024-10721-6","volume":"57","author":"X Zhao","year":"2024","unstructured":"Zhao X, Wang L, Zhang Y et al (2024) A review of convolutional neural networks in computer vision. Artif Intell Rev 57(4):99","journal-title":"Artif Intell Rev"},{"key":"11024_CR209","unstructured":"Zhao Z, Dua D, Singh S (2018) Generating natural adversarial examples. In: International conference on learning representations"},{"key":"11024_CR210","unstructured":"Zhao B, Mopuri KR, Bilen H (2020) idlg: Improved deep leakage from gradients. arXiv preprint arXiv:2001.02610"},{"key":"11024_CR211","doi-asserted-by":"crossref","unstructured":"Zhou J, Chen Y, Shen C, et al (2022) Property inference attacks against gans. In: Proc. of NDSS","DOI":"10.14722\/ndss.2022.23019"},{"key":"11024_CR212","doi-asserted-by":"crossref","unstructured":"Zhu L, Liu Z, Han S (2019) Deep leakage from gradients. In: Proc. of NeurIPS","DOI":"10.1007\/978-3-030-63076-8_2"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-024-11024-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-024-11024-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-024-11024-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,11]],"date-time":"2025-01-11T05:18:03Z","timestamp":1736572683000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-024-11024-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,4]]},"references-count":212,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,1]]}},"alternative-id":["11024"],"URL":"https:\/\/doi.org\/10.1007\/s10462-024-11024-6","relation":{},"ISSN":["1573-7462"],"issn-type":[{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,4]]},"assertion":[{"value":"6 November 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 December 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no relevant financial or non-financial interests to disclose.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"33"}}