{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,12]],"date-time":"2026-01-12T21:49:56Z","timestamp":1768254596847,"version":"3.49.0"},"reference-count":28,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2024,9,18]],"date-time":"2024-09-18T00:00:00Z","timestamp":1726617600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2024,9,18]],"date-time":"2024-09-18T00:00:00Z","timestamp":1726617600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"name":"Fundamental Research Program of Shanxi Province","award":["20210302123131 and 20210302124395"],"award-info":[{"award-number":["20210302123131 and 20210302124395"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Process Lett"],"DOI":"10.1007\/s11063-024-11682-1","type":"journal-article","created":{"date-parts":[[2024,9,18]],"date-time":"2024-09-18T19:01:43Z","timestamp":1726686103000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Label-Only Membership Inference Attack Based on Model Explanation"],"prefix":"10.1007","volume":"56","author":[{"given":"Yao","family":"Ma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xurong","family":"Zhai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuli","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xingyu","family":"Wei","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongle","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,9,18]]},"reference":[{"key":"11682_CR1","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V (2017) Membership Inference Attacks Against Machine Learning Models. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. CA, USA","DOI":"10.1109\/SP.2017.41"},{"key":"11682_CR2","doi-asserted-by":"publisher","first-page":"477","DOI":"10.1109\/TII.2020.3046648","volume":"18","author":"H Chen","year":"2022","unstructured":"Chen H, Li H, Dong G, Hao M, Xu G, Huang X, Liu Z (2022) Practical Membership Inference Attack against Collaborative Inference in Industrial IoT. IEEE Trans Industr Inf 18:477\u2013487. https:\/\/doi.org\/10.1109\/TII.2020.3046648","journal-title":"IEEE Trans Industr Inf"},{"key":"11682_CR3","doi-asserted-by":"publisher","first-page":"103201","DOI":"10.1016\/j.jisa.2022.103201","volume":"67","author":"Y Gu","year":"2022","unstructured":"Gu Y, Bai Y, Xu S (2022) CS-MIA: membership inference attack based on prediction confidence series in federated learning. J Inf Secur Appl 67:103201. https:\/\/doi.org\/10.1016\/j.jisa.2022.103201","journal-title":"J Inf Secur Appl"},{"key":"11682_CR4","first-page":"61","volume":"11","author":"MA Rahman","year":"2018","unstructured":"Rahman MA, Rahman T, Lagani\u00e8re R, Mohammed N (2018) Membership inference attack against differentially private deep learning model. Trans Data Priv 11:61\u201379","journal-title":"Trans Data Priv"},{"key":"11682_CR5","doi-asserted-by":"crossref","unstructured":"Rezaei S, Liu X (2021) On the Difficulty of Membership Inference Attacks. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 7892\u20137900, Vritual","DOI":"10.1109\/CVPR46437.2021.00780"},{"key":"11682_CR6","doi-asserted-by":"crossref","unstructured":"Salem A, Zhang Y, Humbert M, Fritz M, Backes M (2019) ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In Proceedings of the 26th Annual Network and Distributed System Security Symposium, pp. 24\u201327, CA, USA","DOI":"10.14722\/ndss.2019.23119"},{"key":"11682_CR7","doi-asserted-by":"crossref","unstructured":"Yeom S, Giacomelli I, Fredrikson M, Jha S (2018) Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting. In Proceedings of the 2018 IEEE 31st Computer Security Foundations Symposium (CSF), pp. 268\u2013282, OXF, UK","DOI":"10.1109\/CSF.2018.00027"},{"key":"11682_CR8","unstructured":"Choquette-Choo CA, Tramer F, Carlini N, Papernot N (2021) Label-Only Membership Inference Attacks. In Proceedings of the 38th International Conference on Machine Learning, pp. 1964\u20131974, Virtual"},{"key":"11682_CR9","doi-asserted-by":"crossref","unstructured":"Li Z, Zhang Y (2021) Membership Leakage in Label-Only Exposures. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 880\u2013895, Virtual","DOI":"10.1145\/3460120.3484575"},{"key":"11682_CR10","unstructured":"Rahimian S, Orekondy T, Fritz M (2020) Sampling attacks: amplification of membership inference attacks by Rep eated queries. CoRR abs\/2009.00395."},{"key":"11682_CR11","doi-asserted-by":"crossref","unstructured":"Long Y, Wang L, Bu D, Bindschaedler V, Wang X, Tang H, Gunter CA, Chen K (2020) A Pragmatic Approach to Membership Inferences on Machine Learning Models. In Proceedings of the 2020 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 521\u2013534","DOI":"10.1109\/EuroSP48549.2020.00040"},{"key":"11682_CR12","unstructured":"Watson L, Guo C, Cormode G, Sablayrolles A (2022) On the Importance of Difficulty Calibration in Membership Inference Attacks. In Proceedings of the Tenth International Conference on Learning Representations(ICLR), Virtual"},{"key":"11682_CR13","doi-asserted-by":"crossref","unstructured":"Conti M, Li J, Picek S, Xu J (2022) Label-Only Membership Inference Attack against Node-Level Graph Neural Networks. In Proceedings of the 15th {ACM} Workshop on Artificial Intelligence and Security, pp. 1\u201312, CA, USA","DOI":"10.1145\/3560830.3563734"},{"key":"11682_CR14","unstructured":"Leino K, Fredrikson M (2020) Stolen Memories: Leveraging Model Memorization for Calibrated White-Box Membership Inference. In Proceedings of the 29th USENIX Security Symposium, pp. 1605\u20131622, CA, USA"},{"key":"11682_CR15","doi-asserted-by":"crossref","unstructured":"Miao Y, Chen C, Pan L, Liu S, Camtepe S, Zhang J, Xiang Y (2022) No-Label User-Level Membership Inference for ASR Model Auditing. In Proceedings of the Computer Security \u2013 ESORICS 2022-27th European Symposium on Research in Computer Security, pp. 610\u2013628, CPH, DK","DOI":"10.1007\/978-3-031-17146-8_30"},{"key":"11682_CR16","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Goodfellow I, Jha S, Celik ZB, Swami A (2017) Practical Black-Box Attacks against Machine Learning. In Proceedings of the Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, pp. 506\u2013519, Abu Dhabi, AE","DOI":"10.1145\/3052973.3053009"},{"key":"11682_CR17","unstructured":"Song L, Mittal P (2021) Systematic Evaluation of Privacy Risks of Machine Learning Models. In Proceedings of the 30th USENIX Security Symposium (USENIX Security 21), pp. 2615\u20132632, Virtual"},{"key":"11682_CR18","doi-asserted-by":"crossref","unstructured":"Carlini N, Chien S, Nasr M, Song S, Terzis A, Tram\u00e8r F (2022) Membership Inference Attacks From First Principles. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), pp. 1897\u20131914, CA, USA","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"11682_CR19","doi-asserted-by":"crossref","unstructured":"Liu Y, Zhao Z, Backes M, Zhang Y (2022) Membership Inference Attacks by Exploiting Loss Trajectory. In Proceedings of the 2022 {ACM} {SIGSAC} Conference on Computer and Communications Security(CCS), pp. 2085\u20132098, LA, CA, USA","DOI":"10.1145\/3548606.3560684"},{"key":"11682_CR20","unstructured":"Simonyan K, Vedaldi A, Zisserman A (2014) Deep Inside Convolutional Networks: Visualising Image Classification Models and Saliency Maps. In Proceedings of the 2nd International Conference on Learning Representations, AB, CA"},{"key":"11682_CR21","unstructured":"Sundararajan M, Taly A, Yan Q (2017) Axiomatic Attribution for Deep Networks. In Proceedings of the 34th International Conference on Machine Learning, pp. 3319\u20133328, NSW, AU"},{"key":"11682_CR22","doi-asserted-by":"publisher","first-page":"336","DOI":"10.1007\/s11263-019-01228-7","volume":"128","author":"RR Selvaraju","year":"2020","unstructured":"Selvaraju RR, Cogswell M, Das A, Vedantam R, Parikh D, Batra D (2020) Grad-CAM: visual explanations from deep networks via gradient-based localization. Int J Comput Vis 128:336\u2013359. https:\/\/doi.org\/10.1007\/s11263-019-01228-7","journal-title":"Int J Comput Vis"},{"key":"11682_CR23","doi-asserted-by":"crossref","unstructured":"Ribeiro MT, Singh S, Guestrin C (2016) Why Should I Trust You? Explaining the Predictions of Any Classifier. In Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1135\u20131144, CA, USA","DOI":"10.1145\/2939672.2939778"},{"key":"11682_CR24","unstructured":"Lundberg SM, Lee S-I (2017) A Unified Approach to Interpreting Model Predictions. In Proceedings of the International Conference on Neural Information Processing Systems, pp. 4768\u20134777, CA, USA"},{"key":"11682_CR25","doi-asserted-by":"publisher","first-page":"55459","DOI":"10.1109\/ACCESS.2022.3175824","volume":"10","author":"Y Zhang","year":"2022","unstructured":"Zhang Y, Zhou H, Wang P, Yang G (2022) Black-box based limited query membership inference attack. IEEE Access 10:55459\u201355468. https:\/\/doi.org\/10.1109\/ACCESS.2022.3175824","journal-title":"IEEE Access"},{"key":"11682_CR26","unstructured":"Toneva M, Sordoni A, Combes RT, Trischler A, Bengio Y, Gordon GJ (2019) An Empirical Study of Example Forgetting during Deep Neural Network Learning. In Proceedings of the 7th International Conference on Learning Representations, LA, USA. https:\/\/www.tensorflow.org\/api_docs\/python\/tf\/keras\/datasets"},{"key":"11682_CR27","doi-asserted-by":"crossref","unstructured":"Rahimian S, Orekondy T, Fritz M (2021), November Differential privacy defenses and sampling attacks for membership inference. In Proceedings of the 14th ACM workshop on artificial intelligence and security (pp. 193\u2013202)","DOI":"10.1145\/3474369.3486876"},{"key":"11682_CR28","doi-asserted-by":"crossref","unstructured":"Jia J, Salem A, Backes M, Zhang Y, Gong NZ (2019), November Memguard: Defending against black-box membership inference attacks via adversarial examples. In Proceedings of the 2019 ACM SIGSAC conference on computer and communications security (pp. 259\u2013274)","DOI":"10.1145\/3319535.3363201"}],"container-title":["Neural Processing Letters"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11063-024-11682-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11063-024-11682-1\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11063-024-11682-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T15:58:26Z","timestamp":1730303906000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11063-024-11682-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,18]]},"references-count":28,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2024,10]]}},"alternative-id":["11682"],"URL":"https:\/\/doi.org\/10.1007\/s11063-024-11682-1","relation":{},"ISSN":["1573-773X"],"issn-type":[{"value":"1573-773X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9,18]]},"assertion":[{"value":"15 August 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 September 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing Interests"}}],"article-number":"236"}}