{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T18:09:08Z","timestamp":1782929348955,"version":"3.54.5"},"reference-count":205,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,11,7]],"date-time":"2024-11-07T00:00:00Z","timestamp":1730937600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,11,7]],"date-time":"2024-11-07T00:00:00Z","timestamp":1730937600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Sci. China Inf. Sci."],"published-print":{"date-parts":[[2025,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>As the adoption of explainable AI (XAI) continues to expand, the urgency to address its privacy implications intensifies. Despite a growing corpus of research in AI privacy and explainability, there is little attention on privacy-preserving model explanations. This article presents the first thorough survey about privacy attacks on model explanations and their countermeasures. Our contribution to this field comprises a thorough analysis of research papers with a connected taxonomy that facilitates the categorization of privacy attacks and countermeasures based on the targeted explanations. This work also includes an initial investigation into the causes of privacy leaks. Finally, we discuss unresolved issues and prospective research directions uncovered in our analysis. This survey aims to be a valuable resource for the research community and offers clear insights for those new to this domain. To support ongoing research, we have established an online resource repository, which will be continuously updated with new and relevant findings.<\/jats:p>","DOI":"10.1007\/s11432-024-4123-4","type":"journal-article","created":{"date-parts":[[2024,11,11]],"date-time":"2024-11-11T03:38:29Z","timestamp":1731296309000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":26,"title":["Privacy-preserving explainable AI: a survey"],"prefix":"10.1007","volume":"68","author":[{"given":"Thanh Tam","family":"Nguyen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thanh Trung","family":"Huynh","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhao","family":"Ren","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Thanh Toan","family":"Nguyen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Phi Le","family":"Nguyen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongzhi","family":"Yin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Quoc Viet Hung","family":"Nguyen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,11,7]]},"reference":[{"key":"4123_CR1","first-page":"50","volume":"38","author":"B Goodman","year":"2017","unstructured":"Goodman B, Flaxman S. European Union regulations on algorithmic decision making and a \u201cright to explanation\u201d. AI Mag, 2017, 38: 50\u201357","journal-title":"AI Mag"},{"key":"4123_CR2","first-page":"292","volume-title":"Proceedings of IEEE European Symposium on Security and Privacy","author":"H Chang","year":"2021","unstructured":"Chang H, Shokri R. On the privacy risks of algorithmic fairness. In: Proceedings of IEEE European Symposium on Security and Privacy, 2021. 292\u2013303"},{"key":"4123_CR3","volume-title":"Proceedings of International Conference on Learning Representations","author":"M Ancona","year":"2018","unstructured":"Ancona M, Ceolini E, Oztireli C, et al. Towards better understanding of gradient-based attribution methods for deep neural networks. In: Proceedings of International Conference on Learning Representations, 2018"},{"key":"4123_CR4","doi-asserted-by":"publisher","first-page":"1135","DOI":"10.1145\/2939672.2939778","volume-title":"Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery & Data Mining","author":"M T Ribeiro","year":"2016","unstructured":"Ribeiro M T, Singh S, Guestrin C. \u201cWhy should I trust you?\u201d explaining the predictions of any classifier. In: Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, 2016. 1135\u20131144"},{"key":"4123_CR5","volume-title":"Proceedings of Conference on Neural Information Processing Systems","author":"S M Lundberg","year":"2017","unstructured":"Lundberg S M, Lee S-I. A unified approach to interpreting model predictions. In: Proceedings of Conference on Neural Information Processing Systems, 2017"},{"key":"4123_CR6","doi-asserted-by":"publisher","first-page":"2770","DOI":"10.1007\/s10618-022-00831-6","volume":"38","author":"R Guidotti","year":"2024","unstructured":"Guidotti R. Counterfactual explanations and how to find them: literature review and benchmarking. Data Min Knowl Disc, 2024, 38: 2770\u20132824","journal-title":"Data Min Knowl Disc"},{"key":"4123_CR7","doi-asserted-by":"publisher","first-page":"1719","DOI":"10.1007\/s10618-023-00933-9","volume":"37","author":"F Bodria","year":"2023","unstructured":"Bodria F, Giannotti F, Guidotti R, et al. Benchmarking and survey of explanation methods for black box models. Data Min Knowl Disc, 2023, 37: 1719\u20131778","journal-title":"Data Min Knowl Disc"},{"key":"4123_CR8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3236009","volume":"51","author":"R Guidotti","year":"2018","unstructured":"Guidotti R, Monreale A, Ruggieri S, et al. A survey of methods for explaining black box models. ACM Comput Surv, 2018, 51: 1\u201342","journal-title":"ACM Comput Surv"},{"key":"4123_CR9","first-page":"80","volume-title":"Proceedings of IEEE International Conference on Data Science and Advanced Analytics","author":"L H Gilpin","year":"2018","unstructured":"Gilpin L H, Bau D, Yuan B Z, et al. Explaining explanations: an overview of interpretability of machine learning. In: Proceedings of IEEE International Conference on Data Science and Advanced Analytics, 2018. 80\u201389"},{"key":"4123_CR10","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3608482","volume":"14","author":"S Goethals","year":"2023","unstructured":"Goethals S, S\u00f6rensen K, Martens D. The privacy issue of counterfactual explanations: explanation linkage attacks. ACM Trans Intell Syst Technol, 2023, 14: 1\u201324","journal-title":"ACM Trans Intell Syst Technol"},{"key":"4123_CR11","unstructured":"Ferry J, A\u00efvodji U, Gambs S, et al. SoK: taming the triangle\u2013on the interplays between fairness, interpretability and privacy in machine learning. 2023. ArXiv:2312.16191"},{"key":"4123_CR12","volume-title":"Proceedings of the AAAI Workshop on Artificial Intelligence Safety","author":"K Sokol","year":"2019","unstructured":"Sokol K, Flach P. Counterfactual explanations of machine learning predictions: opportunities and challenges for AI safety. In: Proceedings of the AAAI Workshop on Artificial Intelligence Safety, 2019"},{"key":"4123_CR13","first-page":"2233","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"X Luo","year":"2022","unstructured":"Luo X, Jiang Y, Xiao X. Feature inference attack on Shapley values. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2022. 2233\u20132247"},{"key":"4123_CR14","first-page":"13","volume-title":"Proceedings of IEEE International Conference on Cognitive Machine Intelligence","author":"F Naretto","year":"2022","unstructured":"Naretto F, Monreale A, Giannotti F. Evaluating the privacy exposure of interpretable global explainers. In: Proceedings of IEEE International Conference on Cognitive Machine Intelligence, 2022. 13\u201319"},{"key":"4123_CR15","first-page":"1","volume-title":"Proceedings of IEEE Symposium Series on Computational Intelligence","author":"A Artelt","year":"2021","unstructured":"Artelt A, Vaquet V, Velioglu R, et al. Evaluating robustness of counterfactual explanations. In: Proceedings of IEEE Symposium Series on Computational Intelligence, 2021. 1\u20139"},{"key":"4123_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3485133","volume":"55","author":"G R Machado","year":"2021","unstructured":"Machado G R, Silva E, Goldschmidt R R. Adversarial machine learning in image classification: a survey toward the defender\u2019s perspective. ACM Comput Surv, 2021, 55: 1\u201338","journal-title":"ACM Comput Surv"},{"key":"4123_CR17","first-page":"2154","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"B Biggio","year":"2018","unstructured":"Biggio B, Roli F. Wild patterns: ten years after the rise of adversarial machine learning. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2018. 2154\u20132156"},{"key":"4123_CR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3624010","volume":"56","author":"M Rigaki","year":"2023","unstructured":"Rigaki M, Garcia S. A survey of privacy attacks in machine learning. ACM Comput Surv, 2023, 56: 1\u201334","journal-title":"ACM Comput Surv"},{"key":"4123_CR19","first-page":"1","volume":"54","author":"H Hu","year":"2022","unstructured":"Hu H, Salcic Z, Sun L, et al. Membership inference attacks on machine learning: a survey. ACM Comput Surv, 2022, 54: 1\u201337","journal-title":"ACM Comput Surv"},{"key":"4123_CR20","first-page":"1","volume":"54","author":"B Liu","year":"2022","unstructured":"Liu B, Ding M, Shaham S, et al. When machine learning meets privacy: a survey and outlook. ACM Comput Surv, 2022, 54: 1\u201336","journal-title":"ACM Comput Surv"},{"key":"4123_CR21","doi-asserted-by":"publisher","first-page":"102303","DOI":"10.1016\/j.inffus.2024.102303","volume":"107","author":"H Baniecki","year":"2024","unstructured":"Baniecki H, Biecek P. Adversarial attacks and defenses in explainable artificial intelligence: a survey. Inf Fusion, 2024, 107: 102303","journal-title":"Inf Fusion"},{"key":"4123_CR22","first-page":"506","volume-title":"Proceedings of the ACM on Asia Conference on Computer and Communications Security","author":"N Papernot","year":"2017","unstructured":"Papernot N, McDaniel P, Goodfellow I, et al. Practical black-box attacks against machine learning. In: Proceedings of the ACM on Asia Conference on Computer and Communications Security, 2017. 506\u2013519"},{"key":"4123_CR23","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3190835","volume-title":"IEEE Trans Big Data","author":"Z Liu","year":"2024","unstructured":"Liu Z, Guo J, Yang W, et al. Privacy-preserving aggregation in federated learning: a survey. IEEE Trans Big Data, 2024. doi: https:\/\/doi.org\/10.1109\/TBDATA.2022.3190835"},{"key":"4123_CR24","doi-asserted-by":"publisher","first-page":"52138","DOI":"10.1109\/ACCESS.2018.2870052","volume":"6","author":"A Adadi","year":"2018","unstructured":"Adadi A, Berrada M. Peeking inside the black-box: a survey on explainable artificial intelligence (XAI). IEEE Access, 2018, 6: 52138\u201352160","journal-title":"IEEE Access"},{"key":"4123_CR25","first-page":"210","volume-title":"Proceedings of International Convention on Information and Communication Technology, Electronics and Microelectronics","author":"F K Do\u0161ilovi\u0107","year":"2018","unstructured":"Do\u0161ilovi\u0107 F K, Br\u010di\u0107 M, Hlupi\u0107 N. Explainable artificial intelligence: a survey. In: Proceedings of International Convention on Information and Communication Technology, Electronics and Microelectronics, 2018. 210\u2013215"},{"key":"4123_CR26","series-title":"World Bank Institute Governance Working Paper","doi-asserted-by":"publisher","DOI":"10.1596\/23022","volume-title":"The right to information and privacy: balancing rights and managing conflicts","author":"D Banisar","year":"2011","unstructured":"Banisar D. The right to information and privacy: balancing rights and managing conflicts. World Bank Institute Governance Working Paper, 2011. https:\/\/documents.worldbank.org\/en\/publication\/documents-reports\/documentdetail\/847541468188048435\/the-right-to-information-and-privacy-balancing-rights-and-managing-conflicts-access-to-information-program"},{"key":"4123_CR27","first-page":"2211","volume-title":"Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery & Data Mining","author":"V Vo","year":"2023","unstructured":"Vo V, Le T, Nguyen V, et al. Feature-based learning for diverse and privacy-preserving counterfactual explanations. In: Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, 2023. 2211\u20132222"},{"key":"4123_CR28","volume-title":"Proceedings of ICML Workshops","author":"R Mochaourab","year":"2021","unstructured":"Mochaourab R, Sinha S, Greenstein S, et al. Robust counterfactual explanations for privacy-preserving SVM. In: Proceedings of ICML Workshops, 2021"},{"key":"4123_CR29","doi-asserted-by":"publisher","first-page":"4083","DOI":"10.1609\/aaai.v34i04.5827","volume":"34","author":"F Harder","year":"2020","unstructured":"Harder F, Bauer M, Park M. Interpretable and differentially private predictions. In: Proceedings of AAAI Conference on Artificial Intelligence, 2020. 34: 4083\u20134090","journal-title":"Proceedings of AAAI Conference on Artificial Intelligence"},{"key":"4123_CR30","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1145\/3461702.3462533","volume-title":"Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society","author":"R Shokri","year":"2021","unstructured":"Shokri R, Strobel M, Zick Y. On the privacy risks of model explanations. In: Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society, 2021. 231\u2013241"},{"key":"4123_CR31","volume-title":"Proceedings of the AAAI Workshop on Privacy-Preserving Artificial Intelligence","author":"R Shokri","year":"2020","unstructured":"Shokri R, Strobel M, Zick Y. Exploiting transparency measures for membership inference: a cautionary tale. In: Proceedings of the AAAI Workshop on Privacy-Preserving Artificial Intelligence, 2020"},{"key":"4123_CR32","unstructured":"Simonyan K, Vedaldi A, Zisserman A. Deep inside convolutional networks: visualising image classification models and saliency maps. 2013. ArXiv:1312.6034"},{"key":"4123_CR33","doi-asserted-by":"publisher","first-page":"e0130140","DOI":"10.1371\/journal.pone.0130140","volume":"10","author":"S Bach","year":"2015","unstructured":"Bach S, Binder A, Montavon G, et al. On pixel-wise explanations for non-linear classifier decisions by layer-wise relevance propagation. Plos One, 2015, 10: e0130140","journal-title":"Plos One"},{"key":"4123_CR34","first-page":"3145","volume-title":"Proceedings of International Conference on Machine Learning","author":"A Shrikumar","year":"2017","unstructured":"Shrikumar A, Greenside P, Kundaje A. Learning important features through propagating activation differences. In: Proceedings of International Conference on Machine Learning, 2017. 3145\u20133153"},{"key":"4123_CR35","doi-asserted-by":"publisher","first-page":"718","DOI":"10.1609\/aaai.v33i01.3301718","volume":"33","author":"J Sliwinski","year":"2019","unstructured":"Sliwinski J, Strobel M, Zick Y. Axiomatic characterization of data-driven influence measures for classification. In: Proceedings of AAAI Conference on Artificial Intelligence, 2019. 33: 718\u2013725","journal-title":"Proceedings of AAAI Conference on Artificial Intelligence"},{"key":"4123_CR36","unstructured":"Smilkov D, Thorat N, Kim B, et al. SmoothGrad: removing noise by adding noise. 2017. ArXiv:1706.03825"},{"key":"4123_CR37","first-page":"3319","volume-title":"Proceedings of International Conference on Machine Learning","author":"M Sundararajan","year":"2017","unstructured":"Sundararajan M, Taly A, Yan Q. Axiomatic attribution for deep networks. In: Proceedings of International Conference on Machine Learning, 2017. 3319\u20133328"},{"key":"4123_CR38","unstructured":"Miura T, Hasegawa S, Shibahara T. MEGEX: data-free model extraction attack against gradient-based explainable AI. 2021. ArXiv:2107.08909"},{"key":"4123_CR39","unstructured":"Springenberg J T, Dosovitskiy A, Brox T, et al. Striving for simplicity: the all convolutional net. 2014. ArXiv:1412.6806"},{"key":"4123_CR40","doi-asserted-by":"crossref","first-page":"277","DOI":"10.55207\/MGJU5571","volume":"7","author":"H Deng","year":"2019","unstructured":"Deng H. Interpreting tree ensembles with intrees. J Dialogue Studies, 2019, 7: 277\u2013287","journal-title":"J Dialogue Studies"},{"key":"4123_CR41","doi-asserted-by":"publisher","first-page":"180","DOI":"10.1145\/3375627.3375830","volume-title":"Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society","author":"D Slack","year":"2020","unstructured":"Slack D, Hilgard S, Jia E, et al. Fooling lime and shap: adversarial attacks on post hoc explanation methods. In: Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society, 2020. 180\u2013186"},{"key":"4123_CR42","volume-title":"XorSHAP: privacy-preserving explainable AI for decision tree models","author":"D Jetchev","year":"2023","unstructured":"Jetchev D, Vuille M. XorSHAP: privacy-preserving explainable AI for decision tree models. Cryptology ePrint Archive, 2023. https:\/\/eprint.iacr.org\/2023\/1859"},{"key":"4123_CR43","first-page":"598","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"A Datta","year":"2016","unstructured":"Datta A, Sen S, Zick Y. Algorithmic transparency via quantitative input influence: theory and experiments with learning systems. In: Proceedings of IEEE Symposium on Security and Privacy, 2016. 598\u2013617"},{"key":"4123_CR44","doi-asserted-by":"publisher","first-page":"647","DOI":"10.1007\/s10115-013-0679-x","volume":"41","author":"E \u0160trumbelj","year":"2014","unstructured":"\u0160trumbelj E, Kononenko I. Explaining prediction models and individual predictions with feature contributions. Knowl Inf Syst, 2014, 41: 647\u2013665","journal-title":"Knowl Inf Syst"},{"key":"4123_CR45","unstructured":"Maleki S, Tran-Thanh L, Hines G, et al. Bounding the estimation error of sampling-based Shapley value approximation. 2013. ArXiv:1306.4265"},{"key":"4123_CR46","unstructured":"Begley T, Schwedes T, Frye C, et al. Explainability for fair machine learning. 2020. ArXiv:2010.07389"},{"key":"4123_CR47","volume-title":"Proceedings of International Conference on Learning Representations","author":"U A\u00efvodji","year":"2022","unstructured":"A\u00efvodji U, Hara S, Marchand M, et al. Fooling shap with stealthily biased sampling. In: Proceedings of International Conference on Learning Representations, 2022"},{"key":"4123_CR48","doi-asserted-by":"publisher","first-page":"28333","DOI":"10.1109\/ACCESS.2022.3157589","volume":"10","author":"H Montenegro","year":"2022","unstructured":"Montenegro H, Silva W, Gaudio A, et al. Privacy-preserving case-based explanations: enabling visual interpretability by protecting privacy. IEEE Access, 2022, 10: 28333\u201328347","journal-title":"IEEE Access"},{"key":"4123_CR49","first-page":"1885","volume-title":"Proceedings of International Conference on Machine Learning","author":"P W Koh","year":"2017","unstructured":"Koh P W, Liang P. Understanding black-box predictions via influence functions. In: Proceedings of International Conference on Machine Learning, 2017. 1885\u20131894"},{"key":"4123_CR50","doi-asserted-by":"publisher","first-page":"103459","DOI":"10.1016\/j.artint.2021.103459","volume":"294","author":"E M Kenny","year":"2021","unstructured":"Kenny E M, Ford C, Quinn M, et al. Explaining black-box classifiers using post-hoc explanations-by-example: the effect of explanations and error-rates in XAI user studies. Artif Intell, 2021, 294: 103459","journal-title":"Artif Intell"},{"key":"4123_CR51","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1145\/3236386.3241340","volume":"16","author":"Z C Lipton","year":"2018","unstructured":"Lipton Z C. The mythos of model interpretability: in machine learning, the concept of interpretability is both important and slippery. Queue, 2018, 16: 31\u201357","journal-title":"Queue"},{"key":"4123_CR52","volume-title":"Proceedings of Conference on Neural Information Processing Systems","author":"B Kim","year":"2014","unstructured":"Kim B, Rudin C, Shah J A. The Bayesian case model: a generative approach for case-based reasoning and prototype classification. In: Proceedings of Conference on Neural Information Processing Systems, 2014"},{"key":"4123_CR53","doi-asserted-by":"publisher","first-page":"267","DOI":"10.1007\/s10844-008-0069-0","volume":"32","author":"C Nugent","year":"2009","unstructured":"Nugent C, Doyle D, Cunningham P. Gaining insight through case-based explanation. J Intell Inf Syst, 2009, 32: 267\u2013295","journal-title":"J Intell Inf Syst"},{"key":"4123_CR54","doi-asserted-by":"publisher","first-page":"185","DOI":"10.1016\/j.neunet.2020.07.010","volume":"130","author":"P Angelov","year":"2020","unstructured":"Angelov P, Soares E. Towards explainable deep neural networks (xDNN). Neural Netws, 2020, 130: 185\u2013194","journal-title":"Neural Netws"},{"key":"4123_CR55","first-page":"2092","volume-title":"Proceedings of IEEE International Conference on Systems, Man, and Cybernetics","author":"P Angelov","year":"2020","unstructured":"Angelov P, Soares E. Towards deep machine reasoning: a prototype-based deep neural network with decision tree inference. In: Proceedings of IEEE International Conference on Systems, Man, and Cybernetics, 2020. 2092\u20132099"},{"key":"4123_CR56","volume-title":"Proceedings of AAAI Conference on Artificial Intelligence","author":"O Li","year":"2018","unstructured":"Li O, Liu H, Chen C, et al. Deep learning for case-based reasoning through prototypes: a neural network that explains its predictions. In: Proceedings of AAAI Conference on Artificial Intelligence, 2018"},{"key":"4123_CR57","volume-title":"Proceedings of Conference on Neural Information Processing Systems","author":"C Chen","year":"2019","unstructured":"Chen C, Li O, Tao D, et al. This looks like that: deep learning for interpretable image recognition. In: Proceedings of Conference on Neural Information Processing Systems, 2019"},{"key":"4123_CR58","unstructured":"Papernot N, McDaniel P. Deep k-nearest neighbors: towards confident, interpretable and robust deep learning. 2018. ArXiv:1803.04765"},{"key":"4123_CR59","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1038\/s42256-020-00265-z","volume":"2","author":"Z Chen","year":"2020","unstructured":"Chen Z, Bei Y, Rudin C. Concept whitening for interpretable image recognition. Nat Mach Intell, 2020, 2: 772\u2013782","journal-title":"Nat Mach Intell"},{"key":"4123_CR60","first-page":"305","volume-title":"Proceedings of International Conference on Medical Image Computing and Computer Assisted Intervention","author":"W Silva","year":"2020","unstructured":"Silva W, Poellinger A, Cardoso J S, et al. Interpretability-guided content-based medical image retrieval. In: Proceedings of International Conference on Medical Image Computing and Computer Assisted Intervention, 2020. 305\u2013314"},{"key":"4123_CR61","doi-asserted-by":"publisher","first-page":"4612","DOI":"10.1109\/TPAMI.2024.3357717","volume":"46","author":"S Kim","year":"2024","unstructured":"Kim S, Chae D K. What does a model really look at?: extracting model-oriented concepts for explaining deep neural networks. IEEE Trans Pattern Anal Mach Intell, 2024, 46: 4612\u20134624","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"4123_CR62","first-page":"2708","volume-title":"Proceedings of International Joint Conferences on Artificial Intelligence","author":"E M Kenny","year":"2019","unstructured":"Kenny E M, Keane M T. Twin-systems to explain artificial neural networks using case-based reasoning: comparative tests of feature-weighting methods in ANN-CBR twins for XAI. In: Proceedings of International Joint Conferences on Artificial Intelligence, 2019. 2708\u20132715"},{"key":"4123_CR63","doi-asserted-by":"publisher","first-page":"4924","DOI":"10.1109\/TIFS.2021.3117075","volume":"16","author":"A Kuppa","year":"2021","unstructured":"Kuppa A, Le-Khac N A. Adversarial XAI methods in cybersecurity. IEEE Trans Inform Forensic Secur, 2021, 16: 4924\u20134938","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4123_CR64","first-page":"841","volume":"31","author":"S Wachter","year":"2017","unstructured":"Wachter S, Mittelstadt B, Russell C. Counterfactual explanations without opening the black box: automated decisions and the GDPR. Harv JL & Tech, 2017, 31: 841","journal-title":"Harv JL & Tech"},{"key":"4123_CR65","first-page":"275","volume-title":"Proceedings of the International Conference on Intelligent User Interfaces","author":"J Dodge","year":"2019","unstructured":"Dodge J, Liao Q V, Zhang Y, et al. Explaining models: an empirical study of how explanations impact fairness judgment. In: Proceedings of the International Conference on Intelligent User Interfaces, 2019. 275\u2013285"},{"key":"4123_CR66","first-page":"1","volume-title":"Proceedings of CHI Conference on Human Factors in Computing Systems","author":"R Binns","year":"2018","unstructured":"Binns R, van Kleek M, Veale M, et al. \u2018It\u2019s reducing a human being to a percentage\u2019 perceptions of justice in algorithmic decisions. In: Proceedings of CHI Conference on Human Factors in Computing Systems, 2018. 1\u201314"},{"key":"4123_CR67","doi-asserted-by":"publisher","first-page":"353","DOI":"10.1145\/3442188.3445899","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"A-H Karimi","year":"2021","unstructured":"Karimi A-H, Sch\u00f6lkopf B, Valera I. Algorithmic recourse: from counterfactual explanations to interventions. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2021. 353\u2013362"},{"key":"4123_CR68","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1145\/3287560.3287566","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"B Ustun","year":"2019","unstructured":"Ustun B, Spangher A, Liu Y. Actionable recourse in linear classification. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2019. 10\u201319"},{"key":"4123_CR69","unstructured":"Laugel T, Lesot M-J, Marsala C, et al. Inverse classification for comparison-based interpretability in machine learning. 2017. ArXiv:1712.08443"},{"key":"4123_CR70","volume-title":"Proceedings of Conference on Neural Information Processing Systems","author":"A Dhurandhar","year":"2018","unstructured":"Dhurandhar A, Chen P-Y, Luss R, et al. Explanations based on the missing: towards contrastive explanations with pertinent negatives. In: Proceedings of Conference on Neural Information Processing Systems, 2018"},{"key":"4123_CR71","first-page":"9680","volume-title":"Proceedings of International Conference on Artificial Intelligence and Statistics","author":"M Pawelczyk","year":"2023","unstructured":"Pawelczyk M, Lakkaraju H, Neel S. On the privacy risks of algorithmic recourse. In: Proceedings of International Conference on Artificial Intelligence and Statistics, 2023. 9680\u20139696"},{"key":"4123_CR72","first-page":"607","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"R K Mothilal","year":"2020","unstructured":"Mothilal R K, Sharma A, Tan C. Explaining machine learning classifiers through diverse counterfactual explanations. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2020. 607\u2013617"},{"key":"4123_CR73","first-page":"1487","volume-title":"Proceedings of USENIX","author":"G Severi","year":"2021","unstructured":"Severi G, Meyer J, Coull S, et al. Explanation-guided backdoor poisoning attacks against malware classifiers. In: Proceedings of USENIX, 2021. 1487\u20131504"},{"key":"4123_CR74","first-page":"1","volume-title":"Proceedings of International Joint Conference on Neural Networks","author":"A Kuppa","year":"2020","unstructured":"Kuppa A, Le-Khac N-A. Black box attacks on explainable artificial intelligence (XAI) methods in cyber security. In: Proceedings of International Joint Conference on Neural Networks, 2020. 1\u20138"},{"key":"4123_CR75","first-page":"257","volume-title":"Proceedings of the International Conference on Machine Learning for Cyber Security","author":"M Liu","year":"2022","unstructured":"Liu M, Liu X, Yan A, et al. Explanation-guided minimum adversarial attack. In: Proceedings of the International Conference on Machine Learning for Cyber Security, 2022. 257\u2013270"},{"key":"4123_CR76","first-page":"873","volume-title":"Proceedings of AAAI Conference on Artificial Intelligence","author":"T Nguyen","year":"2023","unstructured":"Nguyen T, Lai P, Phan H, et al. XRand: differentially private defense against explanation-guided attacks. In: Proceedings of AAAI Conference on Artificial Intelligence, 2023. 873\u2013881"},{"key":"4123_CR77","doi-asserted-by":"publisher","first-page":"3963","DOI":"10.1109\/TDSC.2023.3341090","volume":"21","author":"E Abdukhamidov","year":"2024","unstructured":"Abdukhamidov E, Abuhamad M, Woo S S, et al. Hardening interpretable deep learning systems: investigating adversarial threats and defenses. IEEE Trans Dependable Secure Comput, 2024, 21: 3963\u20133976","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"4123_CR78","unstructured":"Garcia W, Choi J I, Adari S K, et al. Explainable black-box attacks against model-based authentication. 2018. ArXiv:1810.00024"},{"key":"4123_CR79","volume-title":"Proceedings of USENIX","author":"X Zhang","year":"2020","unstructured":"Zhang X, Wang N, Shen H, et al. Interpretable deep learning under fire. In: Proceedings of USENIX, 2020"},{"key":"4123_CR80","doi-asserted-by":"publisher","first-page":"20180083","DOI":"10.1098\/rsta.2018.0083","volume":"376","author":"M Veale","year":"2018","unstructured":"Veale M, Binns R, Edwards L. Algorithms that remember: model inversion attacks and data protection law. Philos Trans R Soc A, 2018, 376: 20180083","journal-title":"Philos Trans R Soc A"},{"key":"4123_CR81","unstructured":"Shokri R, Strobel M, Zick Y. Privacy risks of explaining machine learning models. 2019. ArXiv:1907.00164"},{"key":"4123_CR82","first-page":"268","volume-title":"Proceedings of IEEE Computer Security Foundations Symposium","author":"S Yeom","year":"2018","unstructured":"Yeom S, Giacomelli I, Fredrikson M, et al. Privacy risk in machine learning: analyzing the connection to overfitting. In: Proceedings of IEEE Computer Security Foundations Symposium, 2018. 268\u2013282"},{"key":"4123_CR83","first-page":"5558","volume-title":"Proceedings of International Conference on Machine Learning","author":"A Sablayrolles","year":"2019","unstructured":"Sablayrolles A, Douze M, Schmid C, et al. White-box vs black-box: Bayes optimal strategies for membership inference. In: Proceedings of International Conference on Machine Learning, 2019. 5558\u20135567"},{"key":"4123_CR84","first-page":"1897","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"N Carlini","year":"2022","unstructured":"Carlini N, Chien S, Nasr M, et al. Membership inference attacks from first principles. In: Proceedings of IEEE Symposium on Security and Privacy, 2022. 1897\u20131914"},{"key":"4123_CR85","first-page":"2085","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Y Liu","year":"2022","unstructured":"Liu Y, Zhao Z, Backes M, et al. Membership inference attacks by exploiting loss trajectory. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2022. 2085\u20132098"},{"key":"4123_CR86","first-page":"1917","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Z Li","year":"2022","unstructured":"Li Z, Liu Y, He X, et al. Auditing membership leakages of multi-exit networks. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2022. 1917\u20131931"},{"key":"4123_CR87","first-page":"3093","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"J Ye","year":"2022","unstructured":"Ye J, Maddi A, Murakonda S K, et al. Enhanced membership inference attacks against machine learning models. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2022. 3093\u20133106"},{"key":"4123_CR88","unstructured":"Quan P, Chakraborty S, Jeyakumar J V, et al. On the amplification of security and privacy risks by post-hoc explanations in machine learning models. 2022. ArXiv:2206.14004"},{"key":"4123_CR89","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"H Liu","year":"2024","unstructured":"Liu H, Wu Y, Yu Z, et al. Please tell me more: privacy impact of explainability through the lens of membership inference attack. In: Proceedings of IEEE Symposium on Security and Privacy, 2024"},{"key":"4123_CR90","first-page":"1","volume-title":"Proceedings of Encyclopedia of Cryptography, Security and Privacy","author":"F A Petitcolas","year":"2023","unstructured":"Petitcolas F A. Kerckhoffs\u2019 principle. In: Proceedings of Encyclopedia of Cryptography, Security and Privacy, 2023. 1\u20132"},{"key":"4123_CR91","first-page":"37","volume-title":"Proceedings of Machine Learning Proceedings","author":"M W Craven","year":"1994","unstructured":"Craven M W, Shavlik J W. Using sampling and queries to extract rules from trained neural networks. In: Proceedings of Machine Learning Proceedings, 1994. 37\u201345"},{"key":"4123_CR92","first-page":"3126","volume-title":"Proceedings of the Web Conference","author":"M Pawelczyk","year":"2020","unstructured":"Pawelczyk M, Broelemann K, Kasneci G. Learning model-agnostic counterfactual explanations for tabular data. In: Proceedings of the Web Conference, 2020. 3126\u20133132"},{"key":"4123_CR93","unstructured":"Huang C, Swoopes C, Xiao C, et al. Accurate, explainable, and private models: providing recourse while minimizing training data leakage. 2023. ArXiv:2308.04341"},{"key":"4123_CR94","first-page":"1","volume":"671","author":"L Sweeney","year":"2000","unstructured":"Sweeney L. Simple demographics often identify people uniquely. Health, 2000, 671: 1\u201334","journal-title":"Health"},{"key":"4123_CR95","doi-asserted-by":"publisher","first-page":"2665","DOI":"10.1007\/s10618-023-00930-y","volume":"38","author":"D Brughmans","year":"2024","unstructured":"Brughmans D, Leyman P, Martens D. NICE: an algorithm for nearest instance counterfactual explanations. Data Min Knowl Disc, 2024, 38: 2665\u20132703","journal-title":"Data Min Knowl Disc"},{"key":"4123_CR96","first-page":"163","volume-title":"Proceedings of Case-Based Reasoning Research and Development. Cham: Springer","author":"M T Keane","year":"2020","unstructured":"Keane M T, Smyth B. Good counterfactuals and where to find them: a case-based technique for generating counterfactuals for explainable AI (XAI). In: Proceedings of Case-Based Reasoning Research and Development. Cham: Springer, 2020. 163\u2013178"},{"key":"4123_CR97","first-page":"809","volume-title":"Proceedings of the Conference on Uncertainty in Artificial Intelligence","author":"M Pawelczyk","year":"2020","unstructured":"Pawelczyk M, Broelemann K, Kasneci G. On counterfactual explanations under predictive multiplicity. In: Proceedings of the Conference on Uncertainty in Artificial Intelligence, 2020. 809\u2013818"},{"key":"4123_CR98","unstructured":"A\u00efvodji U, Bolot A, Gambs S. Model extraction from counterfactual explanations. 2020. ArXiv:2009.01884"},{"key":"4123_CR99","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1146\/annurev-statistics-060116-054123","volume":"4","author":"C Dwork","year":"2017","unstructured":"Dwork C, Smith A, Steinke T, et al. Exposed! A survey of attacks on private data. Annu Rev Stat Appl, 2017, 4: 61\u201384","journal-title":"Annu Rev Stat Appl"},{"key":"4123_CR100","unstructured":"Ferry J, A\u00efvodji U, Gambs S, et al. Probabilistic dataset reconstruction from interpretable models. 2023. ArXiv:2308.15099"},{"key":"4123_CR101","series-title":"Dissertation for Ph.D. Degree","volume-title":"Addresing interpretability fairness & privacy in machine learning through combinatorial optimization methods","author":"J Ferry","year":"2023","unstructured":"Ferry J. Addresing interpretability fairness & privacy in machine learning through combinatorial optimization methods. Dissertation for Ph.D. Degree. Toulouse: Universit\u00e9 Paul Sabatier-Toulouse III, 2023"},{"key":"4123_CR102","doi-asserted-by":"publisher","first-page":"46","DOI":"10.1145\/3287287","volume":"62","author":"S Garfinkel","year":"2019","unstructured":"Garfinkel S, Abowd J M, Martindale C. Understanding database reconstruction attacks on public data. Commun ACM, 2019, 62: 46\u201353","journal-title":"Commun ACM"},{"key":"4123_CR103","first-page":"587","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"C Song","year":"2017","unstructured":"Song C, Ristenpart T, Shmatikov V. Machine learning models that remember too much. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2017. 587\u2013601"},{"key":"4123_CR104","first-page":"267","volume-title":"Proceedings of USENIX","author":"N Carlini","year":"2019","unstructured":"Carlini N, Liu C, Erlingsson \u00da, et al. The secret sharer: evaluating and testing unintended memorization in neural networks. In: Proceedings of USENIX, 2019. 267\u2013284"},{"key":"4123_CR105","first-page":"1291","volume-title":"Proceedings of USENIX","author":"A Salem","year":"2020","unstructured":"Salem A, Bhattacharya A, Backes M, et al. Updates-leak: data set inference and reconstruction attacks in online learning. In: Proceedings of USENIX, 2020. 1291\u20131308"},{"key":"4123_CR106","doi-asserted-by":"publisher","first-page":"274","DOI":"10.1007\/978-3-642-31540-4_21","volume-title":"Proceedings of Data and Applications Security and Privacy XXVI","author":"S Gambs","year":"2012","unstructured":"Gambs S, Gmati A, Hurfin M. Reconstruction attack through classifier analysis. In: Proceedings of Data and Applications Security and Privacy XXVI, 2012. 274\u2013281"},{"key":"4123_CR107","first-page":"1","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"S Milli","year":"2019","unstructured":"Milli S, Schmidt L, Dragan A D, et al. Model reconstruction from model explanations. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2019. 1\u20139"},{"key":"4123_CR108","first-page":"1322","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"M Fredrikson","year":"2015","unstructured":"Fredrikson M, Jha S, Ristenpart T. Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2015. 1322\u20131333"},{"key":"4123_CR109","first-page":"225","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Z Yang","year":"2019","unstructured":"Yang Z, Zhang J, Chang E-C, et al. Neural network inversion in adversarial setting via background knowledge alignment. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2019. 225\u2013240"},{"key":"4123_CR110","first-page":"253","volume-title":"Proceedings of Conference on Computer Vision and Pattern Recognition","author":"Y Zhang","year":"2020","unstructured":"Zhang Y, Jia R, Pei H, et al. The secret revealer: generative model-inversion attacks against deep neural networks. In: Proceedings of Conference on Computer Vision and Pattern Recognition, 2020. 253\u2013261"},{"key":"4123_CR111","first-page":"4829","volume-title":"Proceedings of Conference on Computer Vision and Pattern Recognition","author":"A Dosovitskiy","year":"2016","unstructured":"Dosovitskiy A, Brox T. Inverting visual representations with convolutional networks. In: Proceedings of Conference on Computer Vision and Pattern Recognition, 2016. 4829\u20134837"},{"key":"4123_CR112","doi-asserted-by":"publisher","first-page":"148","DOI":"10.1145\/3359789.3359824","volume-title":"Proceedings of the Annual Computer Security Applications Conference","author":"Z He","year":"2019","unstructured":"He Z, Zhang T, Lee R B. Model inversion attacks against collaborative inference. In: Proceedings of the Annual Computer Security Applications Conference, 2019. 148\u2013162"},{"key":"4123_CR113","first-page":"682","volume-title":"Proceedings of International Conference on Computer Vision","author":"X Zhao","year":"2021","unstructured":"Zhao X, Zhang W, Xiao X, et al. Exploiting explanations for model inversion attacks. In: Proceedings of International Conference on Computer Vision, 2021. 682\u2013692"},{"key":"4123_CR114","unstructured":"Dumoulin V, Visin F. A guide to convolution arithmetic for deep learning. 2016. ArXiv:1603.07285"},{"key":"4123_CR115","first-page":"618","volume-title":"Proceedings of International Conference on Computer Vision","author":"R R Selvaraju","year":"2017","unstructured":"Selvaraju R R, Cogswell M, Das A, et al. Grad-CAM: visual explanations from deep networks via gradient-based localization. In: Proceedings of International Conference on Computer Vision, 2017. 618\u2013626"},{"key":"4123_CR116","first-page":"723","volume-title":"Proceedings of European Conference on Computer Vision Workshops","author":"A Rehman","year":"2019","unstructured":"Rehman A, Rahim R, Nadeem S, et al. End-to-end trained CNN encoder-decoder networks for image steganography. In: Proceedings of European Conference on Computer Vision Workshops, 2019. 723\u2013729"},{"key":"4123_CR117","first-page":"2472","volume-title":"Proceedings of Conference on Computer Vision and Pattern Recognition","author":"Y Zhang","year":"2018","unstructured":"Zhang Y, Tian Y, Kong Y, et al. Residual dense network for image super-resolution. In: Proceedings of Conference on Computer Vision and Pattern Recognition, 2018. 2472\u20132481"},{"key":"4123_CR118","first-page":"2921","volume-title":"Proceedings of Conference on Computer Vision and Pattern Recognition","author":"B Zhou","year":"2016","unstructured":"Zhou B, Khosla A, Lapedriza A, et al. Learning deep features for discriminative localization. In: Proceedings of Conference on Computer Vision and Pattern Recognition, 2016. 2921\u20132929"},{"key":"4123_CR119","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.artint.2018.07.007","volume":"267","author":"T Miller","year":"2019","unstructured":"Miller T. Explanation in artificial intelligence: insights from the social sciences. Artif Intelligence, 2019, 267: 1\u201338","journal-title":"Artif Intelligence"},{"key":"4123_CR120","volume-title":"Proceedings of International Conference on Learning Representations","author":"C Song","year":"2020","unstructured":"Song C, Shmatikov V. Overlearning reveals sensitive attributes. In: Proceedings of International Conference on Learning Representations, 2020"},{"key":"4123_CR121","first-page":"619","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"K Ganju","year":"2018","unstructured":"Ganju K, Wang Q, Yang W, et al. Property inference attacks on fully connected neural networks using permutation invariant representations. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2018. 619\u2013633"},{"key":"4123_CR122","first-page":"691","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"L Melis","year":"2019","unstructured":"Melis L, Song C, de Cristofaro E, et al. Exploiting unintended feature leakage in collaborative learning. In: Proceedings of IEEE Symposium on Security and Privacy, 2019. 691\u2013706"},{"key":"4123_CR123","first-page":"2687","volume-title":"Proceedings of USENIX","author":"W Zhang","year":"2021","unstructured":"Zhang W, Tople S, Ohrimenko O. Leakage of dataset properties in multi-party machine learning. In: Proceedings of USENIX, 2021. 2687\u20132704"},{"key":"4123_CR124","first-page":"416","volume-title":"Proceedings of ACM International Conference on Information and Knowledge Management","author":"V Duddu","year":"2022","unstructured":"Duddu V, Boutet A. Inferring sensitive attributes from model explanations. In: Proceedings of ACM International Conference on Information and Knowledge Management, 2022. 416\u2013425"},{"key":"4123_CR125","first-page":"883","volume-title":"Proceedings of International Conference on Machine Learning","author":"J Chen","year":"2018","unstructured":"Chen J, Song L, Wainwright M, et al. Learning to explain: an information-theoretic perspective on model interpretation. In: Proceedings of International Conference on Machine Learning, 2018. 883\u2013892"},{"key":"4123_CR126","doi-asserted-by":"crossref","unstructured":"Salem A, Zhang Y, Humbert M, et al. ML-leaks: model and data independent membership inference attacks and defenses on machine learning models. 2018. ArXiv:1806.01246","DOI":"10.14722\/ndss.2019.23119"},{"key":"4123_CR127","first-page":"601","volume-title":"Proceedings of USENIX","author":"F Tram\u00e8r","year":"2016","unstructured":"Tram\u00e8r F, Zhang F, Juels A, et al. Stealing machine learning models via prediction APIs. In: Proceedings of USENIX, 2016. 601\u2013618"},{"key":"4123_CR128","first-page":"1345","volume-title":"Proceedings of USENIX","author":"M Jagielski","year":"2020","unstructured":"Jagielski M, Carlini N, Berthelot D, et al. High accuracy and high fidelity extraction of neural networks. In: Proceedings of USENIX, 2020. 1345\u20131362"},{"key":"4123_CR129","first-page":"1318","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"Y Wang","year":"2022","unstructured":"Wang Y, Qian H, Miao C. DualCF: efficient model extraction attack from counterfactual explanations. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2022. 1318\u20131329"},{"key":"4123_CR130","first-page":"4679","volume-title":"Proceedings of International Conference on Artificial Intelligence and Statistics","author":"D Nguyen","year":"2023","unstructured":"Nguyen D, Bui N, Nguyen V A. Feasible recourse plan via diverse interpolation. In: Proceedings of International Conference on Artificial Intelligence and Statistics, 2023. 4679\u20134698"},{"key":"4123_CR131","first-page":"353","volume-title":"Proceedings of Artificial Neural Networks and Machine Learning","author":"A Artelt","year":"2020","unstructured":"Artelt A, Hammer B. Convex density constraints for computing plausible counterfactual explanations. In: Proceedings of Artificial Neural Networks and Machine Learning, 2020. 353\u2013365"},{"key":"4123_CR132","doi-asserted-by":"crossref","unstructured":"Kumari K, Jadliwala M, Jha S K, et al. Towards a game-theoretic understanding of explanation-based membership inference attacks. 2024. ArXiv:2404.07139","DOI":"10.1007\/978-3-031-74835-6_13"},{"key":"4123_CR133","first-page":"181","volume-title":"Proceedings of IEEE International Conference on Data Engineering","author":"X Luo","year":"2021","unstructured":"Luo X, Wu Y, Xiao X, et al. Feature inference attack on model predictions in vertical federated learning. In: Proceedings of IEEE International Conference on Data Engineering, 2021. 181\u2013192"},{"key":"4123_CR134","first-page":"80","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"S Barocas","year":"2020","unstructured":"Barocas S, Selbst A D, Raghavan M. The hidden assumptions behind counterfactual explanations and principal reasons. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2020. 80\u201389"},{"key":"4123_CR135","doi-asserted-by":"publisher","first-page":"228","DOI":"10.1145\/3442188.3445886","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"A Kasirzadeh","year":"2021","unstructured":"Kasirzadeh A, Smart A. The use and misuse of counterfactuals in ethical machine learning. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2021. 228\u2013236"},{"key":"4123_CR136","unstructured":"Hashemi M, Fathi A. PermuteAttack: counterfactual explanation of machine learning credit scorecards. 2020. ArXiv:2008.10138"},{"key":"4123_CR137","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1561\/0400000042","volume":"9","author":"C Dwork","year":"2014","unstructured":"Dwork C, Roth A. The algorithmic foundations of differential privacy. FNT Theor Comput Sci, 2014, 9: 211\u2013407","journal-title":"FNT Theor Comput Sci"},{"key":"4123_CR138","first-page":"1895","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"N Patel","year":"2022","unstructured":"Patel N, Shokri R, Zick Y. Model explanations with differential privacy. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2022. 1895\u20131904"},{"key":"4123_CR139","unstructured":"Yang F, Feng Q, Zhou K, et al. Differentially private counterfactuals via functional mechanism. 2022. ArXiv:2208.02878"},{"key":"4123_CR140","unstructured":"Hamer J, Valladares J, Viswanathan V, et al. Simple steps to success: axiomatics of distance-based algorithmic recourse. 2023. ArXiv:2306.15557"},{"key":"4123_CR141","unstructured":"Pentyala S, Sharma S, Kariyappa S, et al. Privacy-preserving algorithmic recourse. 2023. ArXiv:2311.14137"},{"key":"4123_CR142","unstructured":"Holohan N, Braghin S, Aonghusa P M, et al. Diffprivlib: the IBM differential privacy library. 2019. ArXiv:1907.02444"},{"key":"4123_CR143","first-page":"1069","volume":"12","author":"K Chaudhuri","year":"2011","unstructured":"Chaudhuri K, Monteleoni C, Sarwate A D. Differentially private empirical risk minimization. J Mach Learn Res, 2011, 12: 1069\u20131109","journal-title":"J Mach Learn Res"},{"key":"4123_CR144","volume-title":"Proceedings of Conference on Neural Information Processing Systems","author":"D Wang","year":"2017","unstructured":"Wang D, Ye M, Xu J. Differentially private empirical risk minimization revisited: faster and more general. In: Proceedings of Conference on Neural Information Processing Systems, 2017"},{"key":"4123_CR145","volume-title":"Proceedings of ACM International Conference on Information and Knowledge Management","author":"D Joshi","year":"2022","unstructured":"Joshi D, Thakkar J. k-means subclustering: a differentially private algorithm with improved clustering quality. In: Proceedings of ACM International Conference on Information and Knowledge Management, 2022"},{"key":"4123_CR146","first-page":"1541","volume":"18","author":"Z Lu","year":"2020","unstructured":"Lu Z, Shen H. Differentially private k-means clustering with convergence guarantee. IEEE Trans Dependable Secure Comput, 2020, 18: 1541\u20131552","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"4123_CR147","first-page":"308","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"M Abadi","year":"2016","unstructured":"Abadi M, Chu A, Goodfellow I, et al. Deep learning with differential privacy. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2016. 308\u2013318"},{"key":"4123_CR148","first-page":"339","volume-title":"Proceedings of International Conference on Machine Learning","author":"T Wagner","year":"2023","unstructured":"Wagner T, Naamad Y, Mishra N. Fast private kernel density estimation via locality sensitive quantization. In: Proceedings of International Conference on Machine Learning, 2023. 339\u2013367"},{"key":"4123_CR149","unstructured":"Wang G. Interpret federated learning with Shapley values. 2019. ArXiv:1905.04519"},{"key":"4123_CR150","unstructured":"Watson L, Andreeva R, Yang H-T, et al. Differentially private Shapley values for data evaluation. 2022. ArXiv:2206.00511"},{"key":"4123_CR151","unstructured":"Naidu R, Priyanshu A, Kumar A, et al. When differential privacy meets interpretability: a case study. 2021. ArXiv:2106.13203"},{"key":"4123_CR152","first-page":"3192","volume-title":"Proceedings of International Conference on Machine Learning","author":"Z Bu","year":"2023","unstructured":"Bu Z, Wang Y-X, Zha S, et al. Differentially private optimization on large model at small cost. In: Proceedings of International Conference on Machine Learning, 2023. 3192\u20133218"},{"key":"4123_CR153","volume-title":"Proceedings of Conference on Neural Information Processing Systems","author":"S Hooker","year":"2019","unstructured":"Hooker S, Erhan D, Kindermans P-J, et al. A benchmark for interpretability methods in deep neural networks. In: Proceedings of Conference on Neural Information Processing Systems, 2019"},{"key":"4123_CR154","volume-title":"Security, Cryptology, and Machine Learning","author":"T Veugen","year":"2022","unstructured":"Veugen T, Kamphorst B, Marcus M. Privacy-preserving contrastive explanations with local foil trees. In: Cyber Security, Cryptology, and Machine Learning. Cham: Springer, 2022"},{"key":"4123_CR155","unstructured":"van der Waa J, Robeer M, van Diggelen J, et al. Contrastive explanations with local foil trees. 2018. ArXiv:1806.07470"},{"key":"4123_CR156","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1145\/3387108","volume":"64","author":"Y Lindell","year":"2021","unstructured":"Lindell Y. Secure multiparty computation. Commun ACM, 2021, 64: 86\u201396","journal-title":"Commun ACM"},{"key":"4123_CR157","first-page":"259","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"J Jia","year":"2019","unstructured":"Jia J, Salem A, Backes M, et al. MemGuard: defending against black-box membership inference attacks via adversarial examples. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2019. 259\u2013274"},{"key":"4123_CR158","doi-asserted-by":"publisher","first-page":"59","DOI":"10.56553\/popets-2023-0041","volume":"2023","author":"I E Olatunji","year":"2023","unstructured":"Olatunji I E, Rathee M, Funke T, et al. Private graph extraction via feature explanations. PoPETs, 2023, 2023: 59\u201378","journal-title":"PoPETs"},{"key":"4123_CR159","doi-asserted-by":"publisher","first-page":"148037","DOI":"10.1109\/ACCESS.2021.3124844","volume":"9","author":"H Montenegro","year":"2021","unstructured":"Montenegro H, Silva W, Cardoso J S. Privacy-preserving generative adversarial network for case-based explainability in medical image analysis. IEEE Access, 2021, 9: 148037\u2013148047","journal-title":"IEEE Access"},{"key":"4123_CR160","first-page":"1570","volume-title":"Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops","author":"J Chen","year":"2018","unstructured":"Chen J, Konrad J, Ishwar P. VGAN-based image representation learning for privacy-preserving facial expression recognition. In: Proceedings of IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops, 2018. 1570\u20131579"},{"key":"4123_CR161","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1016\/j.patcog.2016.11.008","volume":"65","author":"G Montavon","year":"2017","unstructured":"Montavon G, Lapuschkin S, Binder A, et al. Explaining nonlinear classification decisions with deep Taylor decomposition. Pattern Recogn, 2017, 65: 211\u2013222","journal-title":"Pattern Recogn"},{"key":"4123_CR162","doi-asserted-by":"publisher","first-page":"3203","DOI":"10.1145\/3292500.3332281","volume-title":"Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery & Data Mining","author":"K Gade","year":"2019","unstructured":"Gade K, Geyik S C, Kenthapadi K, et al. Explainable AI in industry. In: Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, 2019. 3203\u20133204"},{"key":"4123_CR163","first-page":"1","volume-title":"Proceedings of CHI Conference on Human Factors in Computing Systems","author":"H Kaur","year":"2020","unstructured":"Kaur H, Nori H, Jenkins S, et al. Interpreting interpretability: understanding data scientists\u2019 use of interpretability tools for machine learning. In: Proceedings of CHI Conference on Human Factors in Computing Systems, 2020. 1\u201314"},{"key":"4123_CR164","first-page":"14","volume-title":"Proceedings of Conference on Computer Vision and Pattern Recognition","author":"S Hu","year":"2022","unstructured":"Hu S, Liu X, Zhang Y, et al. Protecting facial privacy: generating adversarial identity masks via style-robust makeup transfer. In: Proceedings of Conference on Computer Vision and Pattern Recognition, 2022. 14\u201323"},{"key":"4123_CR165","doi-asserted-by":"publisher","first-page":"103720","DOI":"10.1016\/j.ipm.2024.103720","volume":"61","author":"H Liu","year":"2024","unstructured":"Liu H, Wang Y, Zhang Z, et al. Matrix factorization recommender based on adaptive Gaussian differential privacy for implicit feedback. Inf Process Manage, 2024, 61: 103720","journal-title":"Inf Process Manage"},{"key":"4123_CR166","unstructured":"Liu Z, Jiang Y, Jiang W, et al. Guaranteeing data privacy in federated unlearning with dynamic user participation. 2024. ArXiv:2406.00966"},{"key":"4123_CR167","first-page":"902","volume-title":"Proceedings of AAAI Conference on Artificial Intelligence","author":"D Mi","year":"2024","unstructured":"Mi D, Zhang Y, Zhang L Y, et al. Towards model extraction attacks in GAN-based image translation via domain shift mitigation. In: Proceedings of AAAI Conference on Artificial Intelligence, 2024. 902\u2013910"},{"key":"4123_CR168","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"Y Zhang","year":"2024","unstructured":"Zhang Y, Hu S, Zhang L Y, et al. Why does little robustness help? A further step towards understanding adversarial transferability. In: Proceedings of IEEE Symposium on Security and Privacy, 2024"},{"key":"4123_CR169","unstructured":"Nguyen T T, Huynh T T, Ren Z, et al. A survey of machine unlearning. 2022. ArXiv:2209.02299"},{"key":"4123_CR170","volume-title":"Proceedings of European Conference on Machine Learning and Knowledge Discovery in Databases","author":"T T Huynh","year":"2024","unstructured":"Huynh T T, Nguyen T B, Nguyen P L, et al. Fast-FedUL: a training-free federated unlearning with provable skew resilience. In: Proceedings of European Conference on Machine Learning and Knowledge Discovery in Databases, 2024"},{"key":"4123_CR171","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3355458","volume-title":"IEEE Trans Dependable Secure Comput","author":"Z Liu","year":"2024","unstructured":"Liu Z, Guo J, Yang W, et al. Dynamic user clustering for efficient and privacy-preserving federated learning. IEEE Trans Dependable Secure Comput, 2024. doi: https:\/\/doi.org\/10.1109\/TDSC.2024.3355458"},{"key":"4123_CR172","unstructured":"Li Z, Chen H, Ni Z, et al. Balancing privacy protection and interpretability in federated learning. 2023. ArXiv:2302.08044"},{"key":"4123_CR173","volume-title":"Proceedings of AAAI Conference on Artificial Intelligence","author":"J Zhang","year":"2018","unstructured":"Zhang J, Bareinboim E. Fairness in decision-making\u2014the causal explanation formula. In: Proceedings of AAAI Conference on Artificial Intelligence, 2018"},{"key":"4123_CR174","volume-title":"Proceedings of International Conference on Learning Representations","author":"C Frye","year":"2021","unstructured":"Frye C, de Mijolla D, Begley T, et al. Shapley explainability on the data manifold. In: Proceedings of International Conference on Learning Representations, 2021"},{"key":"4123_CR175","doi-asserted-by":"publisher","first-page":"279","DOI":"10.1145\/3287560.3287574","volume-title":"Proceedings of ACM Conference on Fairness, Accountability, and Transparency","author":"B Mittelstadt","year":"2019","unstructured":"Mittelstadt B, Russell C, Wachter S. Explaining explanations in AI. In: Proceedings of ACM Conference on Fairness, Accountability, and Transparency, 2019. 279\u2013288"},{"key":"4123_CR176","first-page":"3713","volume-title":"Proceedings of International Conference on Machine Learning","author":"J Gillenwater","year":"2021","unstructured":"Gillenwater J, Joseph M, Kulesza A. Differentially private quantiles. In: Proceedings of International Conference on Machine Learning, 2021. 3713\u20133722"},{"key":"4123_CR177","doi-asserted-by":"publisher","first-page":"307","DOI":"10.1145\/3514094.3534157","volume-title":"Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society","author":"A Ghosh","year":"2022","unstructured":"Ghosh A, Shanbhag A, Wilson C. FairCanary: rapid continuous explainable fairness. In: Proceedings of the AAAI\/ACM Conference on AI, Ethics, and Society, 2022. 307\u2013316"},{"key":"4123_CR178","doi-asserted-by":"publisher","first-page":"2517","DOI":"10.1007\/s10618-023-00967-z","volume":"37","author":"Z Li","year":"2023","unstructured":"Li Z, van Leeuwen M. Explainable contextual anomaly detection using quantile regression forests. Data Min Knowl Disc, 2023, 37: 2517\u20132563","journal-title":"Data Min Knowl Disc"},{"key":"4123_CR179","doi-asserted-by":"publisher","first-page":"1335","DOI":"10.1007\/s10618-022-00841-4","volume":"36","author":"M Merz","year":"2022","unstructured":"Merz M, Richman R, Tsanakas A, et al. Interpreting deep learning models with marginal attribution by conditioning on quantiles. Data Min Knowl Disc, 2022, 36: 1335\u20131370","journal-title":"Data Min Knowl Disc"},{"key":"4123_CR180","volume-title":"Proceedings of Conference on Neural Information Processing Systems","author":"D Alvarez-Melis","year":"2018","unstructured":"Alvarez-Melis D, Jaakkola T. Towards robust interpretability with self-explaining neural networks. In: Proceedings of Conference on Neural Information Processing Systems, 2018"},{"key":"4123_CR181","first-page":"9127","volume-title":"Proceedings of AAAI Conference on Artificial Intelligence","author":"Z Zhang","year":"2022","unstructured":"Zhang Z, Liu Q, Wang H, et al. ProtGNN: towards self-explaining graph neural networks. In: Proceedings of AAAI Conference on Artificial Intelligence, 2022. 9127\u20139135"},{"key":"4123_CR182","unstructured":"Khosla M. Privacy and transparency in graph machine learning: a unified perspective. 2022. ArXiv:2207.10896"},{"key":"4123_CR183","doi-asserted-by":"publisher","first-page":"103627","DOI":"10.1016\/j.artint.2021.103627","volume":"302","author":"I Tiddi","year":"2022","unstructured":"Tiddi I, Schlobach S. Knowledge graphs as tools for explainable machine learning: a survey. Artif Intell, 2022, 302: 103627","journal-title":"Artif Intell"},{"key":"4123_CR184","doi-asserted-by":"publisher","first-page":"1019","DOI":"10.1177\/01655515221112844","volume":"50","author":"E Rajabi","year":"2024","unstructured":"Rajabi E, Etminani K. Knowledge-graph-based explainable AI: a systematic review. J Inf Sci, 2024, 50: 1019\u20131029","journal-title":"J Inf Sci"},{"key":"4123_CR185","doi-asserted-by":"publisher","first-page":"679","DOI":"10.1109\/TDSC.2017.2697854","volume":"16","author":"J Qian","year":"2019","unstructured":"Qian J, Li X Y, Zhang C, et al. Social network de-anonymization and privacy inference with knowledge graph model. IEEE Trans Dependable Secure Comput, 2019, 16: 679\u2013692","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"4123_CR186","unstructured":"Wang Y, Huang L, Yu P S, et al. Membership inference attacks on knowledge graphs. 2021. ArXiv:2104.08273"},{"key":"4123_CR187","first-page":"501","volume-title":"Proceedings of WWW Companion","author":"J Domingo-Ferrer","year":"2019","unstructured":"Domingo-Ferrer J, P\u00e9rez-Sol\u00e0 C, Blanco-Justicia A. Collaborative explanation of deep models with limited interaction for trade secret and privacy preservation. In: Proceedings of WWW Companion, 2019. 501\u2013507"},{"key":"4123_CR188","doi-asserted-by":"publisher","first-page":"e1495","DOI":"10.1002\/widm.1495","volume":"13","author":"A Gaudio","year":"2023","unstructured":"Gaudio A, Smailagic A, Faloutsos C, et al. DeepFixCX: explainable privacy-preserving image compression for medical image analysis. WIREs Data Min Knowl, 2023, 13: e1495","journal-title":"WIREs Data Min Knowl"},{"key":"4123_CR189","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1109\/TNNLS.2020.2978386","volume":"32","author":"Z Wu","year":"2021","unstructured":"Wu Z, Pan S, Chen F, et al. A comprehensive survey on graph neural networks. IEEE Trans Neural Netw Learn Syst, 2021, 32: 4\u201324","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"4123_CR190","doi-asserted-by":"publisher","first-page":"47615","DOI":"10.1109\/ACCESS.2019.2909924","volume":"7","author":"Z Liu","year":"2019","unstructured":"Liu Z, Luong N C, Wang W, et al. A survey on blockchain: a game theoretical perspective. IEEE Access, 2019, 7: 47615\u201347643","journal-title":"IEEE Access"},{"key":"4123_CR191","first-page":"5782","volume":"45","author":"H Yuan","year":"2022","unstructured":"Yuan H, Yu H, Gui S, et al. Explainability in graph neural networks: a taxonomic survey. IEEE Trans Pattern Anal Mach Intell, 2022, 45: 5782\u20135799","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"4123_CR192","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3618105","volume":"56","author":"M A Prado-Romero","year":"2024","unstructured":"Prado-Romero M A, Prenkaj B, Stilo G, et al. A survey on graph counterfactual explanations: definitions, methods, evaluation, and research challenges. ACM Comput Surv, 2024, 56: 1\u201337","journal-title":"ACM Comput Surv"},{"key":"4123_CR193","unstructured":"Dai E, Zhao T, Zhu H, et al. A comprehensive survey on trustworthy graph neural networks: privacy, robustness, fairness, and explainability. 2022. ArXiv:2204.08570"},{"key":"4123_CR194","volume-title":"Proceedings of ACM Multimedia Workshop","author":"Z Ren","year":"2023","unstructured":"Ren Z, Qian K, Schultz T, et al. An overview of the ICASSP special session on AI security and privacy in speech and audio processing. In: Proceedings of ACM Multimedia Workshop, 2023"},{"key":"4123_CR195","first-page":"1884","volume-title":"Proceedings of the ACM SIGSAC Conference on Computer and Communications Security","author":"Z Li","year":"2021","unstructured":"Li Z, Shi C, Zhang T, et al. Robust detection of machine-induced audio attacks in intelligent audio systems with microphone array. In: Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, 2021. 1884\u20131899"},{"key":"4123_CR196","first-page":"1","volume-title":"Proceedings of IEEE Security and Privacy Workshops","author":"N Carlini","year":"2018","unstructured":"Carlini N, Wagner D. Audio adversarial examples: targeted attacks on speech-to-text. In: Proceedings of IEEE Security and Privacy Workshops, 2018. 1\u20137"},{"key":"4123_CR197","first-page":"730","volume-title":"Proceedings of IEEE Symposium on Security and Privacy","author":"H Abdullah","year":"2021","unstructured":"Abdullah H, Warren K, Bindschaedler V, et al. SoK: the faults in our ASRs: an overview of attacks against automatic speech recognition and speaker identification systems. In: Proceedings of IEEE Symposium on Security and Privacy, 2021. 730\u2013747"},{"key":"4123_CR198","first-page":"100322","volume":"9","author":"Z Ren","year":"2022","unstructured":"Ren Z, Qian K, Dong F, et al. Deep attention-based neural networks for explainable heart sound classification. Machine Learn Appl, 2022, 9: 100322","journal-title":"Machine Learn Appl"},{"key":"4123_CR199","first-page":"7184","volume-title":"Proceedings of IEEE International Conference on Acoustics, Speech and Signal Processing","author":"Z Ren","year":"2020","unstructured":"Ren Z, Baird A, Han J, et al. Generating and protecting against adversarial attacks for deep speech-based emotion recognition models. In: Proceedings of IEEE International Conference on Acoustics, Speech and Signal Processing, 2020. 7184\u20137188"},{"key":"4123_CR200","first-page":"1","volume-title":"Proceedings of Interspeech","author":"Y Chang","year":"2022","unstructured":"Chang Y, Ren Z, Nguyen T T, et al. Example-based explanations with adversarial attacks for respiratory sound analysis. In: Proceedings of Interspeech, 2022. 1\u20135"},{"key":"4123_CR201","first-page":"1","volume-title":"Proceedings of Secure and Trustworthy Deep Learning Systems Workshop","author":"Z Liu","year":"2023","unstructured":"Liu Z, Guo J, Yang M, et al. Privacy-enhanced knowledge transfer with collaborative split learning over teacher ensembles. In: Proceedings of Secure and Trustworthy Deep Learning Systems Workshop, 2023. 1\u201313"},{"key":"4123_CR202","doi-asserted-by":"publisher","first-page":"2398","DOI":"10.1109\/TIFS.2023.3266919","volume":"18","author":"Z Liu","year":"2023","unstructured":"Liu Z, Lin H Y, Liu Y. Long-term privacy-preserving aggregation with user-dynamics for federated learning. IEEE Trans Inform Forensic Secur, 2023, 18: 2398\u20132412","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4123_CR203","doi-asserted-by":"publisher","first-page":"1839","DOI":"10.1109\/TIFS.2022.3163592","volume":"18","author":"Z Liu","year":"2023","unstructured":"Liu Z, Guo J, Lam K Y, et al. Efficient dropout-resilient aggregation for privacy-preserving machine learning. IEEE Trans Inform Forensic Secur, 2023, 18: 1839\u20131854","journal-title":"IEEE Trans Inform Forensic Secur"},{"key":"4123_CR204","first-page":"1","volume-title":"Proceedings of International Conference on Privacy, Security and Trust","author":"N Belhadj-Cheikh","year":"2021","unstructured":"Belhadj-Cheikh N, Imine A, Rusinowitch M. FOX: fooling with explanations: privacy protection with adversarial reactions in social media. In: Proceedings of International Conference on Privacy, Security and Trust, 2021. 1\u201310"},{"key":"4123_CR205","first-page":"1167","volume-title":"Proceedings of International Conference on Artificial Intelligence and Statistics","author":"R Jia","year":"2019","unstructured":"Jia R, Dao D, Wang B, et al. Towards efficient data valuation based on the Shapley value. In: Proceedings of International Conference on Artificial Intelligence and Statistics, 2019. 1167\u20131176"}],"container-title":["Science China Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-024-4123-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11432-024-4123-4","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11432-024-4123-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T22:02:44Z","timestamp":1771538564000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11432-024-4123-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,7]]},"references-count":205,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["4123"],"URL":"https:\/\/doi.org\/10.1007\/s11432-024-4123-4","relation":{},"ISSN":["1674-733X","1869-1919"],"issn-type":[{"value":"1674-733X","type":"print"},{"value":"1869-1919","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,7]]},"assertion":[{"value":"4 April 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 June 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 August 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 November 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 July 2025","order":6,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Update","order":7,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"In this article the missing funding note has been added.","order":8,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"111101"}}