{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T23:54:03Z","timestamp":1781740443159,"version":"3.54.5"},"reference-count":60,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2021YFB3101100"],"award-info":[{"award-number":["2021YFB3101100"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018555","name":"Science and Technology Program of Guizhou Province","doi-asserted-by":"publisher","award":["[2020]5017"],"award-info":[{"award-number":["[2020]5017"]}],"id":[{"id":"10.13039\/501100018555","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018555","name":"Science and Technology Program of Guizhou Province","doi-asserted-by":"publisher","award":["[2022]065"],"award-info":[{"award-number":["[2022]065"]}],"id":[{"id":"10.13039\/501100018555","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272102"],"award-info":[{"award-number":["62272102"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272123"],"award-info":[{"award-number":["62272123"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.eswa.2026.132375","type":"journal-article","created":{"date-parts":[[2026,4,8]],"date-time":"2026-04-08T23:18:32Z","timestamp":1775690312000},"page":"132375","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Optimal adversarial perturbation guided membership inference: Gradient-sensitive white-box and hybrid zeroth-order black-box strategies"],"prefix":"10.1016","volume":"323","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8539-988X","authenticated-orcid":false,"given":"Zehua","family":"Ding","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5974-1570","authenticated-orcid":false,"given":"Youliang","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guorong","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9985-1953","authenticated-orcid":false,"given":"Jinbo","family":"Xiong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianfeng","family":"Ma","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.132375_bib0001","series-title":"Proceedings of the 2016\u202fACM SIGSAC conference on computer and communications security","first-page":"308","article-title":"Deep learning with differential privacy","author":"Abadi","year":"2016"},{"key":"10.1016\/j.eswa.2026.132375_bib0002","series-title":"Advances in neural information processing systems","first-page":"314","article-title":"Scalable membership inference attacks via quantile regression","volume":"vol. 36","author":"Bertran","year":"2023"},{"key":"10.1016\/j.eswa.2026.132375_bib0003","series-title":"2022\u202fIEEE symposium on security and privacy (SP)","first-page":"1897","article-title":"Membership inference attacks from first principles","author":"Carlini","year":"2022"},{"key":"10.1016\/j.eswa.2026.132375_bib0004","series-title":"International conference on learning representations","article-title":"Relaxloss: Defending membership inference attacks without losing utility","author":"Chen","year":"2022"},{"key":"10.1016\/j.eswa.2026.132375_bib0005","series-title":"2020\u202fIEEE symposium on security and privacy (SP)","first-page":"1277","article-title":"Hopskipjumpattack: A query-efficient decision-based attack","author":"Chen","year":"2020"},{"key":"10.1016\/j.eswa.2026.132375_bib0006","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103571","article-title":"Hp-mia: A novel membership inference attack scheme for high membership prediction precision","volume":"136","author":"Chen","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132375_bib0007","doi-asserted-by":"crossref","unstructured":"Chen, Z., & Pattabiraman, K. (2024a). A method to facilitate membership inference attacks in deep learning models.arXiv: 2407.01919\">.","DOI":"10.14722\/ndss.2025.230041"},{"key":"10.1016\/j.eswa.2026.132375_bib0008","series-title":"NDSS","article-title":"Overconfidence is a dangerous thing: Mitigating membership inference attacks by enforcing less confident prediction","author":"Chen","year":"2024"},{"key":"10.1016\/j.eswa.2026.132375_bib0009","series-title":"International conference on machine learning","first-page":"1964","article-title":"Label-only membership inference attacks","author":"Choquette-Choo","year":"2021"},{"key":"10.1016\/j.eswa.2026.132375_bib0010","series-title":"International conference on machine learning","first-page":"2196","article-title":"Minimally distorted adversarial examples with a fast adaptive boundary attack","author":"Croce","year":"2020"},{"key":"10.1016\/j.eswa.2026.132375_bib0011","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"10399","article-title":"Leveraging adversarial examples to quantify membership information leakage","author":"Del Grosso","year":"2022"},{"key":"10.1016\/j.eswa.2026.132375_bib0012","series-title":"2024\u202fIEEE 23rd international conference on trust, security and privacy in computing and communications (trustcom)","first-page":"842","article-title":"Membership inference attacks via dynamic adversarial perturbations reduction","author":"Ding","year":"2024"},{"issue":"1","key":"10.1016\/j.eswa.2026.132375_bib0013","doi-asserted-by":"crossref","DOI":"10.1016\/j.ipm.2024.103947","article-title":"Membership inference attacks via spatial projection-based relative information loss in MLaas","volume":"62","author":"Ding","year":"2025","journal-title":"Information Processing & Management"},{"key":"10.1016\/j.eswa.2026.132375_bib0014","series-title":"The thirty-eighth annual conference on neural information processing systems ((neurIPS)","article-title":"Membership inference attacks against fine-tuned large language models via self-prompt calibration","author":"Fu","year":"2024"},{"key":"10.1016\/j.eswa.2026.132375_bib0015","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"14820","article-title":"Similarity distribution based membership inference attack on person re-identification","volume":"vol. 37","author":"Gao","year":"2023"},{"key":"10.1016\/j.eswa.2026.132375_bib0016","unstructured":"Goodfellow, I. J., Shlens, J., & Szegedy, C. (2014). Explaining and harnessing adversarial examples. arXiv: 1412.6572."},{"key":"10.1016\/j.eswa.2026.132375_bib0017","series-title":"International conference on machine learning","first-page":"1321","article-title":"On calibration of modern neural networks","author":"Guo","year":"2017"},{"key":"10.1016\/j.eswa.2026.132375_bib0018","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.eswa.2026.132375_bib0019","series-title":"Computer vision\u2013ECCV 2016: 14th European conference, Amsterdam, the Netherlands, October 11\u201314, 2016, proceedings, part IV 14","first-page":"630","article-title":"Identity mappings in deep residual networks","author":"He","year":"2016"},{"key":"10.1016\/j.eswa.2026.132375_bib0020","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"4700","article-title":"Densely connected convolutional networks","author":"Huang","year":"2017"},{"key":"10.1016\/j.eswa.2026.132375_bib0021","series-title":"Workshop on trustworthy and socially responsible machine learning, neurIPS","article-title":"Membership inference attacks via adversarial examples","author":"Jalalzai","year":"2022"},{"key":"10.1016\/j.eswa.2026.132375_bib0022","doi-asserted-by":"crossref","first-page":"348","DOI":"10.2478\/popets-2021-0031","article-title":"Revisiting membership inference under realistic assumptions","volume":"2","author":"Jayaraman","year":"2021","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"10.1016\/j.eswa.2026.132375_bib0023","series-title":"Proceedings of the 2019\u202fACM SIGSAC conference on computer and communications security","first-page":"259","article-title":"Memguard: Defending against black-box membership inference attacks via adversarial examples","author":"Jia","year":"2019"},{"key":"10.1016\/j.eswa.2026.132375_bib0024","series-title":"International conference on machine learning","first-page":"5345","article-title":"When does data augmentation help with membership inference attacks?","author":"Kaya","year":"2021"},{"key":"10.1016\/j.eswa.2026.132375_bib0025","unstructured":"Krizhevsky, A. and Hinton, G. (2009). Learning multiple layers of features from tiny images. Technical Report, University of Toronto, Toronto, ON, Canada."},{"key":"10.1016\/j.eswa.2026.132375_bib0026","series-title":"Imagenet classification with deep convolutional neural networks","first-page":"1097","volume":"25","author":"Krizhevsky","year":"2012"},{"issue":"7","key":"10.1016\/j.eswa.2026.132375_bib0027","first-page":"3","article-title":"Tiny imagenet visual recognition challenge","volume":"7","author":"Le","year":"2015","journal-title":"CS 231N"},{"key":"10.1016\/j.eswa.2026.132375_bib0028","series-title":"Advances in neural information processing systems","first-page":"73866","article-title":"Gaussian membership inference privacy","volume":"vol. 36","author":"Leemann","year":"2023"},{"key":"10.1016\/j.eswa.2026.132375_bib0029","series-title":"29th USENIX security symposium (USENIX security 20)","first-page":"1605","article-title":"Stolen memories: Leveraging model memorization for calibrated {White-Box} membership inference","author":"Leino","year":"2020"},{"key":"10.1016\/j.eswa.2026.132375_bib0030","series-title":"33rd USENIX security symposium (USENIX security 24)","first-page":"2387","article-title":"{MIST}: Defending against membership inference attacks through {Membership-Invariant} subspace training","author":"Li","year":"2024"},{"key":"10.1016\/j.eswa.2026.132375_bib0031","unstructured":"Li, Y., Liu, G., Wang, C., & Yang, Y. (2024b). Generating is believing: Membership inference attacks against retrieval-augmented generation. arXiv: 2406.19234."},{"key":"10.1016\/j.eswa.2026.132375_bib0032","series-title":"Proceedings of the 2021\u202fACM SIGSAC conference on computer and communications security","first-page":"880","article-title":"Membership leakage in label-only exposures","author":"Li","year":"2021"},{"key":"10.1016\/j.eswa.2026.132375_bib0033","doi-asserted-by":"crossref","first-page":"4996","DOI":"10.1109\/TIFS.2023.3303718","article-title":"Tear: Exploring temporal evolution of adversarial robustness for membership inference attacks against federated learning","volume":"18","author":"Liu","year":"2023","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.132375_bib0034","doi-asserted-by":"crossref","first-page":"427","DOI":"10.1109\/TIFS.2023.3324772","article-title":"Gradient-leaks: Enabling black-box membership inference attacks against machine learning models","volume":"19","author":"Liu","year":"2024","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.eswa.2026.132375_bib0035","series-title":"Proceedings of the 2022\u202fACM SIGSAC conference on computer and communications security","first-page":"2085","article-title":"Membership inference attacks by exploiting loss trajectory","author":"Liu","year":"2022"},{"key":"10.1016\/j.eswa.2026.132375_bib0036","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"11976","article-title":"A convnet for the 2020s","author":"Liu","year":"2022"},{"key":"10.1016\/j.eswa.2026.132375_bib0037","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., & Vladu, A. (2017). Towards deep learning models resistant to adversarial attacks. arXiv: 1706.06083."},{"key":"10.1016\/j.eswa.2026.132375_bib0038","series-title":"When does label smoothing help?","first-page":"4696","volume":"32","author":"M\u00fcller","year":"2019"},{"key":"10.1016\/j.eswa.2026.132375_bib0039","series-title":"Proceedings of the 2018\u202fACM SIGSAC conference on computer and communications security","first-page":"634","article-title":"Machine learning with membership privacy using adversarial regularization","author":"Nasr","year":"2018"},{"key":"10.1016\/j.eswa.2026.132375_bib0040","series-title":"2019\u202fIEEE symposium on security and privacy (SP)","first-page":"739","article-title":"Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning","author":"Nasr","year":"2019"},{"key":"10.1016\/j.eswa.2026.132375_bib0041","series-title":"Proceedings of the 2023\u202fACM southeast conference","first-page":"191","article-title":"Evaluation of query-based membership inference attack on the medical data","author":"Pedarla","year":"2023"},{"key":"10.1016\/j.eswa.2026.132375_bib0042","series-title":"The thirty-eighth annual conference on neural information processing systems","article-title":"OSLO: One-shot label-only membership inference attacks","author":"Peng","year":"2024"},{"key":"10.1016\/j.eswa.2026.132375_bib0043","series-title":"International conference on machine learning","first-page":"5558","article-title":"White-box vs black-box: Bayes optimal strategies for membership inference","author":"Sablayrolles","year":"2019"},{"key":"10.1016\/j.eswa.2026.132375_bib0044","series-title":"Proceedings of the 26th annual network and distributed system security symposium (NDSS)","article-title":"Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"Salem","year":"2019"},{"key":"10.1016\/j.eswa.2026.132375_bib0045","series-title":"NDSS","article-title":"Defending against membership inference attacks on iteratively pruned deep neural networks","author":"Shang","year":"2025"},{"key":"10.1016\/j.eswa.2026.132375_bib0046","series-title":"2017\u202fIEEE symposium on security and privacy (SP)","first-page":"3","article-title":"Membership inference attacks against machine learning models","author":"Shokri","year":"2017"},{"key":"10.1016\/j.eswa.2026.132375_bib0047","series-title":"30th USENIX security symposium (USENIX security 21)","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","author":"Song","year":"2021"},{"key":"10.1016\/j.eswa.2026.132375_bib0048","series-title":"2019\u202fIEEE security and privacy workshops (SPW)","first-page":"50","article-title":"Membership inference attacks against adversarially robust deep learning models","author":"Song","year":"2019"},{"key":"10.1016\/j.eswa.2026.132375_bib0049","series-title":"Proceedings of the 2019\u202fACM SIGSAC conference on computer and communications security","first-page":"241","article-title":"Privacy risks of securing machine learning models against adversarial examples","author":"Song","year":"2019"},{"key":"10.1016\/j.eswa.2026.132375_bib0050","series-title":"High-dimensional learning dynamics 2024: The emergence of structure and reasoning","article-title":"Do parameters reveal more than loss for membership inference?","author":"Suri","year":"2024"},{"key":"10.1016\/j.eswa.2026.132375_bib0051","series-title":"Proceedings of the 41st international conference on machine learning","first-page":"47819","article-title":"Membership inference attacks on diffusion models via quantile regression","author":"Tang","year":"2024"},{"key":"10.1016\/j.eswa.2026.132375_bib0052","doi-asserted-by":"crossref","DOI":"10.1016\/j.ins.2023.120068","article-title":"Graddiff: Gradient-based membership inference attacks against federated distillation with differential comparison","volume":"658","author":"Wang","year":"2024","journal-title":"Information Sciences"},{"key":"10.1016\/j.eswa.2026.132375_bib0053","unstructured":"Watson, L., Guo, C., Cormode, G., & Sablayrolles, A. (2021). On the importance of difficulty calibration in membership inference attacks. arXiv: 2111.08440."},{"key":"10.1016\/j.eswa.2026.132375_bib0054","series-title":"The eleventh international conference on learning representations","article-title":"Canary in a coalmine: Better membership inference with ensembled adversarial queries","author":"Wen","year":"2023"},{"key":"10.1016\/j.eswa.2026.132375_bib0055","series-title":"The twelfth international conference on learning representations","article-title":"You only query once: An efficient label-only membership inference attack","author":"Wu","year":"2024"},{"key":"10.1016\/j.eswa.2026.132375_bib0056","series-title":"Proceedings of the 2022\u202fACM SIGSAC conference on computer and communications security","first-page":"3093","article-title":"Enhanced membership inference attacks against machine learning models","author":"Ye","year":"2022"},{"key":"10.1016\/j.eswa.2026.132375_bib0057","series-title":"2018\u202fIEEE 31st computer security foundations symposium (CSF)","first-page":"268","article-title":"Privacy risk in machine learning: Analyzing the connection to overfitting","author":"Yeom","year":"2018"},{"key":"10.1016\/j.eswa.2026.132375_bib0058","series-title":"British machine vision conference 2016","article-title":"Wide residual networks","author":"Zagoruyko","year":"2016"},{"key":"10.1016\/j.eswa.2026.132375_bib0059","series-title":"Proceedings of the 41st international conference on machine learning","first-page":"58244","article-title":"Low-cost high-power membership inference attacks","author":"Zarifzadeh","year":"2024"},{"issue":"11","key":"10.1016\/j.eswa.2026.132375_bib0060","doi-asserted-by":"crossref","first-page":"2969","DOI":"10.1093\/comjnl\/bxac080","article-title":"Evaluating membership inference through adversarial robustness","volume":"65","author":"Zhang","year":"2022","journal-title":"The Computer Journal"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426012881?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426012881?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T23:22:18Z","timestamp":1781738538000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426012881"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":60,"alternative-id":["S0957417426012881"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132375","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Optimal adversarial perturbation guided membership inference: Gradient-sensitive white-box and hybrid zeroth-order black-box strategies","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132375","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"132375"}}