{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,2]],"date-time":"2026-08-02T11:58:36Z","timestamp":1785671916216,"version":"3.56.0"},"reference-count":55,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2020,8,6]],"date-time":"2020-08-06T00:00:00Z","timestamp":1596672000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,8,6]],"date-time":"2020-08-06T00:00:00Z","timestamp":1596672000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"name":"DoST - Ho Chi Minh city","award":["08\/2018\/H\u0110-QKHCN"],"award-info":[{"award-number":["08\/2018\/H\u0110-QKHCN"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"published-print":{"date-parts":[[2020,9]]},"DOI":"10.1007\/s42979-020-00254-4","type":"journal-article","created":{"date-parts":[[2020,8,6]],"date-time":"2020-08-06T16:03:46Z","timestamp":1596729826000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":45,"title":["Security and Privacy Issues in Deep Learning: A Brief Review"],"prefix":"10.1007","volume":"1","author":[{"given":"Trung","family":"Ha","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7282-3589","authenticated-orcid":false,"given":"Tran Khanh","family":"Dang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hieu","family":"Le","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tuan Anh","family":"Truong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,8,6]]},"reference":[{"issue":"4","key":"254_CR1","doi-asserted-by":"publisher","first-page":"454","DOI":"10.1108\/IJWIS-10-2018-0075","volume":"15","author":"TK Dang","year":"2019","unstructured":"Dang TK, Pham CDM, Ho DD. On verifying the authenticity of e-commercial crawling data by a semi-crosschecking method. Int J Web Inf Syst. 2019;15(4):454\u201373. https:\/\/doi.org\/10.1108\/IJWIS-10-2018-0075.","journal-title":"Int J Web Inf Syst"},{"key":"254_CR2","unstructured":"Tram\u00e8r F, Kurakin A, Papernot N, Goodfellow I, Boneh D, McDaniel P. Ensemble adversarial training: attacks and defenses. In: Proceedings of the 6th international conference on learning representations, Vancouver, BC, Canada, 30 Apr\u20133 May 2018."},{"issue":"9","key":"254_CR3","doi-asserted-by":"publisher","first-page":"2805","DOI":"10.1109\/TNNLS.2018.2886017","volume":"30","author":"X Yuan","year":"2019","unstructured":"Yuan X, Pan H, Qile Z, Xiaolin L. Adversarial examples: attacks and defenses for deep learning. IEEE Trans Neural Netw Learn Syst. 2019;30(9):2805\u201324.","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"254_CR4","unstructured":"Ji Z, Lipton ZC, Elkan C. Differential privacy and machine learning: a survey and review. arXiv preprint arXiv:1412.7584. 2014. https:\/\/arxiv.org\/abs\/1412.7584. Accessed 15 Apr 2020."},{"key":"254_CR5","unstructured":"Zhang D, Chen X, Wang D, Shi J. A survey on collaborative deep learning and privacy-preserving. In: Proceedings of the 3rd IEEE international conference on data science in cyberspace, Guangzhou, China, 18\u201321 June 2018. pp. 652\u2013658."},{"key":"254_CR6","doi-asserted-by":"crossref","unstructured":"Dwork C. Differential privacy: a survey of results. In: International conference on theory and applications of models of computation. Lecture notes in computer science, vol. 4978. Berlin: Springer; 2008. pp. 1\u201319.","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"254_CR7","doi-asserted-by":"crossref","unstructured":"Bun M, Steinke T. Concentrated differential privacy: simplifications, extensions, and lower bounds. In: Theory of cryptography conference. Lecture notes in computer science, vol 9985. Berlin: Springer; 2016. pp. 635\u2013658.","DOI":"10.1007\/978-3-662-53641-4_24"},{"key":"254_CR8","unstructured":"Szegedy C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R. Intriguing properties of neural networks. In: arXiv preprint arXiv:1312.6199. 2013. https:\/\/arxiv.org\/abs\/1312.6199. Accessed 15 Apr 2020."},{"key":"254_CR9","doi-asserted-by":"crossref","unstructured":"Tabacof P, Valle E. Exploring the space of adversarial images. In: International joint conference on neural networks, Vancouver, BC, Canada, 24\u201329 July 2016. pp. 426\u2013433.","DOI":"10.1109\/IJCNN.2016.7727230"},{"key":"254_CR10","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Wu X, Jha S, Swami A. Distillation as a defense to adversarial perturbations against deep neural networks. In: Proceedings of the 37th IEEE symposium on security and privacy, San Jose, CA, USA, 22\u201326 May 2016. pp. 582\u2013597.","DOI":"10.1109\/SP.2016.41"},{"key":"254_CR11","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A. The limitations of deep learning in adversarial settings. In: IEEE European symposium on security and privacy (EuroS&P), Saarbr\u00fccken, Germany, 21\u201324 Mar 2016. pp. 372\u2013387.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"254_CR12","unstructured":"Carlini N, Wagner D. Towards evaluating the robustness of neural networks. In: Proceedings of the 38th IEEE symposium on security and privacy, San Jose, CA, USA, 22\u201326 May 2017. pp. 39\u201357."},{"key":"254_CR13","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli SM, Fawzi A, Frossard P. Deepfool: a simple and accurate method to fool deep neural networks. In: Proceedings of the IEEE conference on computer vision and pattern recognition, Las Vegas, NV, USA, 27\u201330 June 2016. pp. 2574\u20132582.","DOI":"10.1109\/CVPR.2016.282"},{"key":"254_CR14","doi-asserted-by":"crossref","unstructured":"Moosavi-Dezfooli SM, Fawzi A, Fawzi O, Frossard P. Universal adversarial perturbations. In: Proceedings of the IEEE conference on computer vision and pattern recognition, Honolulu, HI, USA, 21\u201326 July 2017. pp. 86\u201394.","DOI":"10.1109\/CVPR.2017.17"},{"key":"254_CR15","unstructured":"Goodfellow IJ, Shlens J, Szegedy C. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572. 2014. https:\/\/arxiv.org\/abs\/1412.6572. Accessed 15 Apr 2020."},{"key":"254_CR16","unstructured":"Kurakin A, Goodfellow I, Bengio S. Adversarial machine learning at scale. In: Proceedings of the 5th international conference on learning representations, Toulon, France, 24\u201326 Apr 2017."},{"key":"254_CR17","doi-asserted-by":"crossref","unstructured":"Dong Y, Liao F, Pang T, Su H, Zhu J, Hu X, Li J. Boosting adversarial attacks with momentum. In: Proceedings of the IEEE conference on computer vision and pattern recognition, Salt Lake City, UT, USA, 18\u201322 June 2018. pp. 9185\u20139193.","DOI":"10.1109\/CVPR.2018.00957"},{"key":"254_CR18","unstructured":"Kurakin A, Goodfellow I, Bengio S. Adversarial examples in the physical world. In: Proceedings of the 5th international conference on learning representations, Toulon, France, 24\u201326 Apr 2017."},{"key":"254_CR19","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Goodfellow I, Jha S, Celik ZB, Swami A. Practical black-box attacks against machine learning. In: Proceedings of the ACM on Asia conference on computer and communications security, Abu Dhabi, United Arab Emirates, 2\u20136 Apr 2017. pp. 506\u2013519.","DOI":"10.1145\/3052973.3053009"},{"key":"254_CR20","unstructured":"Metzen JH, Genewein T, Fischer V, Bischoff B. On detecting adversarial perturbations. In: Proceedings of the 5th international conference on learning representations, Toulon, France, 24\u201326 Apr 2017."},{"key":"254_CR21","doi-asserted-by":"crossref","unstructured":"Lu J, Issaranon T, Forsyth D. Safetynet: detecting and rejecting adversarial examples robustly. In: Proceedings of the IEEE international conference on computer vision, Venice, Italy, 22\u201329 Oct 2017. pp. 446\u2013454.","DOI":"10.1109\/ICCV.2017.56"},{"key":"254_CR22","unstructured":"Hendrycks D, Gimpel K. Early methods for detecting adversarial images. In: Proceedings of the 5th international conference on learning representations, Toulon, France, 24\u201326 Apr 2017."},{"key":"254_CR23","unstructured":"Song Y, Kim T, Nowozin S, Ermon S, Kushman N. Pixeldefend: leveraging generative models to understand and defend against adversarial examples. In: Proceedings of the 6th international conference on learning representations, Vancouver, BC, Canada, 30 Apr\u20133 May 2018."},{"key":"254_CR24","doi-asserted-by":"crossref","unstructured":"Nasr M, Shokri R, Houmansadr A. Comprehensive privacy analysis of deep learning: passive and active white-box inference attacks against centralized and federated learning. In: Proceedings of the 40th IEEE symposium on security and privacy, San Francisco, CA, USA, 19\u201323 May 2019. pp. 739\u2013753.","DOI":"10.1109\/SP.2019.00065"},{"key":"254_CR25","unstructured":"Fredrikson M, Lantz E, Jha S, Lin S, Page D, Ristenpart T. Privacy in pharmacogenetics: an end-to-end case study of personalized warfarin dosing. In: 23rd USENIX security symposium, San Diego, CA, USA, 20\u201322 Aug 2014. pp. 17\u201332."},{"key":"254_CR26","doi-asserted-by":"crossref","unstructured":"Fredrikson M, Jha S, Ristenpart T. Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, Denver, CO, USA, 12\u201316 Oct 2015. pp. 1322\u20131333.","DOI":"10.1145\/2810103.2813677"},{"key":"254_CR27","unstructured":"Tram\u00e8r F, Zhang F, Juels A, Reiter MK, Ristenpart T. Stealing machine learning models via prediction apis. In: 25th USENIX security symposium, Austin, TX, USA, 10\u201312 Aug 2016. pp. 601\u2013618."},{"key":"254_CR28","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V. Membership inference attacks against machine learning models. In: Proceedings of the 38th IEEE symposium on security and privacy, San Jose, CA, USA, 22\u201326 May 2017. pp. 3\u201318.","DOI":"10.1109\/SP.2017.41"},{"issue":"7","key":"254_CR29","doi-asserted-by":"publisher","first-page":"e0130140","DOI":"10.1371\/journal.pone.0130140","volume":"10","author":"S Bach","year":"2015","unstructured":"Bach S, Binder A, Montavon G, Klauschen F, M\u00fcller KR, Samek W. On pixel-wise explanations for non-linear classifier decisions by layer-wise relevance propagation. PLoS ONE. 2015;10(7):e0130140.","journal-title":"PLoS ONE"},{"key":"254_CR30","unstructured":"Chaudhuri K, Monteleoni C. Privacy-preserving logistic regression. In: Advances in neural information processing systems. 2009. pp. 289\u2013296."},{"key":"254_CR31","doi-asserted-by":"crossref","unstructured":"Hitaj B, Ateniese G, Perez-Cruz F. Deep models under the GAN: information leakage from collaborative deep learning. In: Proceedings of the 24th ACM SIGSAC conference on computer and communications security, Dallas, TX, USA, 30 Oct\u201303 Nov 2017. pp. 603\u2013618.","DOI":"10.1145\/3133956.3134012"},{"key":"254_CR32","doi-asserted-by":"crossref","unstructured":"Shokri R, Shmatikov V. Privacy-preserving deep learning. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security, Denver, CO, USA, 12\u201316 Oct 2015. pp. 1310\u20131321.","DOI":"10.1145\/2810103.2813687"},{"key":"254_CR33","doi-asserted-by":"crossref","unstructured":"Abadi M, Chu A, Goodfellow I, McMahan HB, Mironov I, Talwar K, Zhang L. Deep learning with differential privacy. In: Proceedings of the 23rd ACM SIGSAC conference on computer and communications security, Vienna, Austria, 24\u201328 Oct 2016. pp. 308\u2013318.","DOI":"10.1145\/2976749.2978318"},{"key":"254_CR34","unstructured":"McMahan HB, Ramage D, Talwar K, Zhang L. Learning differentially private recurrent language models. In: Proceedings of the 6th international conference on learning representations, Vancouver, BC, Canada, 30 Apr\u20133 May 2018."},{"issue":"6","key":"254_CR35","doi-asserted-by":"publisher","first-page":"1109","DOI":"10.1109\/TKDE.2018.2855136","volume":"31","author":"G Acs","year":"2018","unstructured":"Acs G, Melis L, Castelluccia C, De Cristofaro E. Differentially private mixture of generative neural networks. IEEE Trans Knowl Data Eng. 2018;31(6):1109\u201321.","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"254_CR36","doi-asserted-by":"crossref","unstructured":"Blum A, Dwork C, McSherry F, Nissim K. Practical privacy: the SuLQ framework. In: Proceedings of the twenty-fourth ACM SIGMOD-SIGACT-SIGART symposium on principles of database systems. 2005. pp. 128\u2013138.","DOI":"10.1145\/1065167.1065184"},{"key":"254_CR37","doi-asserted-by":"crossref","unstructured":"Chitta R, Jin R, Jain AK. Efficient kernel clustering using random fourier features. In: IEEE 12th international conference on data mining, Brussels, Belgium, 10\u201313 Dec 2012. pp. 161\u2013170.","DOI":"10.1109\/ICDM.2012.61"},{"key":"254_CR38","unstructured":"Kingma DP, Welling M. Auto-encoding variational bayes. In: 2nd International conference on learning representations, Banff, AB, Canada, 14\u201316 Apr 2014"},{"key":"254_CR39","volume-title":"Deep learning","author":"I Goodfellow","year":"2016","unstructured":"Goodfellow I, Bengio Y, Courville A, Bengio Y. Deep learning. 1st ed. Cambridge: MIT press; 2016.","edition":"1"},{"key":"254_CR40","unstructured":"Xie L, Lin K, Wang S, Wang F, Zhou J. Diffeentially private generative adversarial network. arXiv preprint arXiv:1802.06739. 2018. https:\/\/arxiv.org\/abs\/1802.06739. Accessed 15 Apr 2020."},{"key":"254_CR41","doi-asserted-by":"crossref","unstructured":"Yu L, Liu L, Pu C, Gursoy ME, Truex S. Differentially private model publishing for deep learning. In: Proceedings of the 40th IEEE symposium on security and privacy, San Francisco, CA, USA, 19\u201323 May 2019. pp. 332\u2013349.","DOI":"10.1109\/SP.2019.00019"},{"key":"254_CR42","doi-asserted-by":"crossref","unstructured":"Lee H, Grosse R, Ranganath R, Ng AY. Convolutional deep belief networks for scalable unsupervised learning of hierarchical representations. In: Proceedings of the 26th annual international conference on machine learning. 2009. pp. 609\u2013616.","DOI":"10.1145\/1553374.1553453"},{"issue":"9\u201310","key":"254_CR43","doi-asserted-by":"publisher","first-page":"1681","DOI":"10.1007\/s10994-017-5656-2","volume":"106","author":"N Phan","year":"2017","unstructured":"Phan N, Wu X, Dou D. Preserving differential privacy in convolutional deep belief networks. J Mach Learn. 2017;106(9\u201310):1681\u2013704.","journal-title":"J Mach Learn"},{"key":"254_CR44","doi-asserted-by":"crossref","unstructured":"Phan N, Wu X, Hu H, Dou D. Adaptive laplace mechanism: differential privacy preservation in deep learning. In: Proceedings of the 17th IEEE international conference on data mining (ICDM), New Orleans, LA, USA, 18\u201321 Nov 2017. pp. 385\u2013394.","DOI":"10.1109\/ICDM.2017.48"},{"key":"254_CR45","unstructured":"Papernot N, Abadi M, Erlingsson U, Goodfellow I, Talwar K. Semi-supervised knowledge transfer for deep learning from private training data. In: Proceedings of the 5th international conference on learning representations, Toulon, France, 24\u201326 Apr 2017."},{"key":"254_CR46","unstructured":"Papernot N, Song S, Mironov I, Raghunathan A, Talwar K, Erlingsson \u00da. Scalable private learning with pate. In: Proceedings of the 6th international conference on learning representations, Vancouver, BC, Canada, 30 Apr\u20133 May 2018."},{"key":"254_CR47","unstructured":"Triastcyn A, Faltings B. Generating differentially private datasets using gans. arXiv preprint arXiv:1803.03148. 2018. https:\/\/128.84.21.199\/abs\/1803.03148v1. Accessed 15 Apr 2020."},{"issue":"1","key":"254_CR48","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1049\/iet-bmt.2018.5101","volume":"8","author":"TAT Nguyen","year":"2019","unstructured":"Nguyen TAT, Dang TK. Privacy preserving biometric-based remote authentication with secure processing unit on untrusted server. J IET Biom. 2019;8(1):79\u201391.","journal-title":"J IET Biom"},{"key":"254_CR49","first-page":"52","volume":"36","author":"QNT Thi","year":"2017","unstructured":"Thi QNT, Dang TK. Towards a fine-grained privacy-enabled attribute-based access control mechanism. Trans Large Scale Data Knowl Cent Syst. 2017;36:52\u201372.","journal-title":"Trans Large Scale Data Knowl Cent Syst"},{"key":"254_CR50","doi-asserted-by":"publisher","DOI":"10.1016\/j.scs.2020.102097","author":"TK Dang","year":"2020","unstructured":"Dang TK, Pham CDM, Nguyen TLP. A pragmatic elliptic curve cryptography-based extension for energy-efficient device-to-device communications in smart cities. Sustain Cities Soc. 2020. https:\/\/doi.org\/10.1016\/j.scs.2020.102097.","journal-title":"Sustain Cities Soc"},{"key":"254_CR51","doi-asserted-by":"crossref","unstructured":"Dang TK, Tran KTK. The meeting of acquaintances: a cost-efficient authentication scheme for light-weight objects with transient trust level and plurality approach. In: Security and Communication Networks, Hindawi, vol. 2019. 2019.","DOI":"10.1155\/2019\/8123259"},{"key":"254_CR52","doi-asserted-by":"crossref","unstructured":"Bengio Y. Learning deep architectures for AI. In: Foundations and trends\u00ae in machine learning. 2009. vol. 2, no. 1, pp. 1\u2013127.","DOI":"10.1561\/2200000006"},{"key":"254_CR53","unstructured":"Long Y, Bindschaedler V, Wang L, Bu D, Wang X, Tang H, Chen K. Understanding membership inferences on well-generalized learning models. arXiv preprint arXiv:1802.04889. 2018. https:\/\/arxiv.org\/abs\/1802.04889. Accessed 15 Apr 2020."},{"key":"254_CR54","doi-asserted-by":"crossref","unstructured":"Yeom S, Giacomelli I, Fredrikson M, Jha S. Privacy risk in machine learning: Analyzing the connection to overfitting. In: Proceedings of the 31st IEEE computer security foundations symposium, Oxford, United Kingdom, 9\u201312 July 2018. pp. 268\u2013282.","DOI":"10.1109\/CSF.2018.00027"},{"key":"254_CR55","doi-asserted-by":"crossref","unstructured":"Phan N, Wang Y, Wu X, Dou D. Differential privacy preservation for deep auto-encoders: an application of human behavior prediction. In: Proceedings of the 30th AAAI conference on artificial intelligence, Phoenix, Arizona, USA, 12\u201317 Feb 2016.","DOI":"10.1609\/aaai.v30i1.10165"}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-020-00254-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-020-00254-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-020-00254-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,11,6]],"date-time":"2022-11-06T00:47:59Z","timestamp":1667695679000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-020-00254-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,6]]},"references-count":55,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2020,9]]}},"alternative-id":["254"],"URL":"https:\/\/doi.org\/10.1007\/s42979-020-00254-4","relation":{},"ISSN":["2662-995X","2661-8907"],"issn-type":[{"value":"2662-995X","type":"print"},{"value":"2661-8907","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,8,6]]},"assertion":[{"value":"30 April 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"15 July 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 August 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with Ethical Standards"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of Interest"}}],"article-number":"253"}}