{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T02:02:12Z","timestamp":1780020132252,"version":"3.53.1"},"reference-count":68,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Knowledge-Based Systems"],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1016\/j.knosys.2026.116100","type":"journal-article","created":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T22:03:04Z","timestamp":1777932184000},"page":"116100","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Shortening the prefix! Members and non-members exhibit divergent behavior"],"prefix":"10.1016","volume":"346","author":[{"given":"Linyun","family":"Xie","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6451-1158","authenticated-orcid":false,"given":"Jiguo","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-8961-6046","authenticated-orcid":false,"given":"Hongliang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fenghua","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chunqiang","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"issue":"3","key":"10.1016\/j.knosys.2026.116100_b1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3641289","article-title":"A survey on evaluation of large language models","volume":"15","author":"Chang","year":"2024","journal-title":"ACM Trans. Intell. Syst. Technol."},{"key":"10.1016\/j.knosys.2026.116100_b2","doi-asserted-by":"crossref","DOI":"10.1016\/j.lindif.2023.102274","article-title":"ChatGPT for good? On opportunities and challenges of large language models for education","volume":"103","author":"Kasneci","year":"2023","journal-title":"Learn. Individ. Differ."},{"key":"10.1016\/j.knosys.2026.116100_b3","series-title":"Large language models for text classification: Case study and comprehensive review","author":"Kostina","year":"2025"},{"key":"10.1016\/j.knosys.2026.116100_b4","series-title":"International Conference on Machine Learning","first-page":"41092","article-title":"Prompting large language model for machine translation: A case study","author":"Zhang","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b5","doi-asserted-by":"crossref","unstructured":"P. Vaithilingam, T. Zhang, E.L. Glassman, Expectation vs. experience: Evaluating the usability of code generation tools powered by large language models, in: Chi Conference on Human Factors in Computing Systems Extended Abstracts, 2022, pp. 1\u20137.","DOI":"10.1145\/3491101.3519665"},{"issue":"2","key":"10.1016\/j.knosys.2026.116100_b6","doi-asserted-by":"crossref","DOI":"10.1145\/3605943","article-title":"Recent advances in natural language processing via large pre-trained language models: A survey","volume":"56","author":"Min","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.knosys.2026.116100_b7","series-title":"Proceedings of the Sixteenth ACM International Conference on Web Search and Data Mining","first-page":"1291","article-title":"Privacy in the time of language models","author":"Peris","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b8","article-title":"Advancing membership inference attacks: The present and the future","volume":"4","author":"Li","year":"2025","journal-title":"Secur. Saf."},{"key":"10.1016\/j.knosys.2026.116100_b9","doi-asserted-by":"crossref","unstructured":"N. Carlini, D. Ippolito, M. Jagielski, K. Lee, F. Tramer, C. Zhang, Quantifying Memorization Across Neural Language Models, in: The Eleventh International Conference on Learning Representations, 2023.","DOI":"10.52202\/075280-1708"},{"key":"10.1016\/j.knosys.2026.116100_b10","series-title":"Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers)","first-page":"3917","article-title":"Exploring memorization in fine-tuned language models","author":"Zeng","year":"2024"},{"key":"10.1016\/j.knosys.2026.116100_b11","unstructured":"N. Carlini, F. Tramer, E. Wallace, M. Jagielski, A. Herbert-Voss, K. Lee, A. Roberts, T. Brown, D. Song, U. Erlingsson, et al., Extracting training data from large language models, in: 30th USENIX Security Symposium, USENIX Security 21, 2021, pp. 2633\u20132650."},{"key":"10.1016\/j.knosys.2026.116100_b12","unstructured":"S. Keum, D. Shin, L. Marchyok, S. Hong, S. Son, Private Investigator: Extracting Personally Identifiable Information from Large Language Models Using Optimized Prompts, in: 34th USENIX Security Symposium, USENIX Security 25, 2025, pp. 8175\u20138194."},{"key":"10.1016\/j.knosys.2026.116100_b13","series-title":"2017 IEEE Symposium on Security and Privacy","first-page":"3","article-title":"Membership inference attacks against machine learning models","author":"Shokri","year":"2017"},{"key":"10.1016\/j.knosys.2026.116100_b14","series-title":"ICLR 2025","article-title":"Scalable extraction of training data from (production) language models","author":"Nasr","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b15","series-title":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","first-page":"1724","article-title":"Membership inference attacks as privacy tools: Reliability, disparity and ensemble","author":"Wang","year":"2025"},{"key":"10.1016\/j.knosys.2026.116100_b16","doi-asserted-by":"crossref","unstructured":"S. Yeom, I. Giacomelli, M. Fredrikson, S. Jha, Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting, in: 2018 IEEE 31st Computer Security Foundations Symposium, CSF, 2018, pp. 268\u2013282.","DOI":"10.1109\/CSF.2018.00027"},{"key":"10.1016\/j.knosys.2026.116100_b17","series-title":"Proceedings of the 2022 Conference on Empirical Methods in Natural Language Processing","first-page":"8332","article-title":"Quantifying privacy risks of masked language models using membership inference attacks","author":"Mireshghallah","year":"2022"},{"key":"10.1016\/j.knosys.2026.116100_b18","series-title":"Membership inference attacks on large-scale models: A survey","author":"Wu","year":"2025"},{"issue":"04","key":"10.1016\/j.knosys.2026.116100_b19","article-title":"High-frequency CSI300 spot and futures price predictions via the neural network","volume":"18","author":"Jin","year":"2025","journal-title":"J. Uncertain Syst."},{"issue":"2","key":"10.1016\/j.knosys.2026.116100_b20","doi-asserted-by":"crossref","first-page":"1481","DOI":"10.1007\/s11135-025-02080-3","article-title":"Predictions of residential property price indices for China via machine learning models","volume":"59","author":"Jin","year":"2025","journal-title":"Qual. Quant.: Int. J. Methodol."},{"key":"10.1016\/j.knosys.2026.116100_b21","article-title":"Individual time series and composite forecasting of the Chinese stock index","volume":"5","author":"Xu","year":"2021","journal-title":"Mach. Learn. Appl."},{"key":"10.1016\/j.knosys.2026.116100_b22","doi-asserted-by":"crossref","first-page":"2264","DOI":"10.1016\/j.procs.2023.01.202","article-title":"An investigation of videos for abnormal behavior detection","volume":"218","author":"Patwal","year":"2023","journal-title":"Procedia Comput. Sci."},{"key":"10.1016\/j.knosys.2026.116100_b23","series-title":"Large language models: A survey","author":"Minaee","year":"2025"},{"key":"10.1016\/j.knosys.2026.116100_b24","series-title":"A Survey of Large Language Models","author":"Zhao","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b25","series-title":"SoK: Memorization in general-purpose large language models","author":"Hartmann","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b26","series-title":"Proceedings of the 17th International Natural Language Generation Conference","first-page":"584","article-title":"A comprehensive analysis of memorization in large language models","author":"Kiyomaru","year":"2024"},{"key":"10.1016\/j.knosys.2026.116100_b27","series-title":"Proceedings of the 40th International Conference on Machine Learning","first-page":"40306","article-title":"Bag of tricks for training data extraction from language models","volume":"vol. 202","author":"Yu","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b28","series-title":"Proceedings of the 2022 Conference on Empirical Methods in Natural Language Processing","first-page":"1816","article-title":"An empirical analysis of memorization in fine-tuned autoregressive language models","author":"Mireshghallah","year":"2022"},{"key":"10.1016\/j.knosys.2026.116100_b29","series-title":"Beyond memorization: Violating privacy via inference with large language models","author":"Staab","year":"2024"},{"key":"10.1016\/j.knosys.2026.116100_b30","series-title":"Pacific-Asia Conference on Knowledge Discovery and Data Mining","first-page":"326","article-title":"Privacy in fine-tuning large language models: Attacks, defenses, and future directions","author":"Du","year":"2025"},{"key":"10.1016\/j.knosys.2026.116100_b31","series-title":"PrivacyMind: Large language models can be contextual privacy protection learners","author":"Xiao","year":"2024"},{"issue":"7","key":"10.1016\/j.knosys.2026.116100_b32","doi-asserted-by":"crossref","first-page":"163","DOI":"10.1007\/s44443-025-00177-1","article-title":"A survey on privacy risks and protection in large language models","volume":"37","author":"Chen","year":"2025","journal-title":"J. King Saud Univ. Comput. Inf. Sci."},{"key":"10.1016\/j.knosys.2026.116100_b33","series-title":"Proceedings of the 36th International Conference on Machine Learning","first-page":"5558","article-title":"White-box vs black-box: Bayes optimal strategies for membership inference","volume":"vol. 97","author":"Sablayrolles","year":"2019"},{"key":"10.1016\/j.knosys.2026.116100_b34","doi-asserted-by":"crossref","first-page":"134981","DOI":"10.52202\/079017-4290","article-title":"Membership inference attacks against fine-tuned large language models via self-prompt calibration","volume":"37","author":"Fu","year":"2024","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.knosys.2026.116100_b35","series-title":"Findings of the Association for Computational Linguistics: ACL 2023","first-page":"11330","article-title":"Membership inference attacks against language models via neighbourhood comparison","author":"Mattern","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b36","unstructured":"W. Shi, A. Ajith, M. Xia, Y. Huang, D. Liu, T. Blevins, D. Chen, L. Zettlemoyer, Detecting Pretraining Data from Large Language Models, in: The Twelfth International Conference on Learning Representations, 2024."},{"key":"10.1016\/j.knosys.2026.116100_b37","series-title":"2024 Annual Computer Security Applications Conference","first-page":"31","article-title":"Not all tokens are equal: Membership inference attacks against fine-tuned language models","author":"Song","year":"2024"},{"issue":"4","key":"10.1016\/j.knosys.2026.116100_b38","doi-asserted-by":"crossref","DOI":"10.1145\/3764113","article-title":"Unique security and privacy threats of large language models: A comprehensive survey","volume":"58","author":"Wang","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.knosys.2026.116100_b39","series-title":"Proceedings of the 16th Cyber Security Experimentation and Test Workshop","first-page":"10","article-title":"An attacker\u2019s dream? Exploring the capabilities of ChatGPT for developing malware","author":"Pa Pa","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b40","first-page":"581","article-title":"Kullback-leibler divergence","author":"Kullback","year":"1951","journal-title":"Encycl. Mach. Learn."},{"key":"10.1016\/j.knosys.2026.116100_b41","first-page":"707","article-title":"Binary codes capable of correcting deletions, insertions, and reversals","volume":"10","author":"Levenshtein","year":"1965","journal-title":"Sov. Phys. Dokl."},{"key":"10.1016\/j.knosys.2026.116100_b42","series-title":"Proceedings of the 29th International Conference on Neural Information Processing Systems - Volume 1","first-page":"649","article-title":"Character-level convolutional networks for text classification","author":"Zhang","year":"2015"},{"key":"10.1016\/j.knosys.2026.116100_b43","unstructured":"S. Merity, C. Xiong, J. Bradbury, R. Socher, Pointer Sentinel Mixture Models, in: International Conference on Learning Representations, 2017."},{"key":"10.1016\/j.knosys.2026.116100_b44","series-title":"Proceedings of the 2018 Conference on Empirical Methods in Natural Language Processing","first-page":"1797","article-title":"Don\u2019t give me the details, just the summary! topic-aware convolutional neural networks for extreme summarization","author":"Narayan","year":"2018"},{"issue":"8","key":"10.1016\/j.knosys.2026.116100_b45","first-page":"9","article-title":"Language models are unsupervised multitask learners","volume":"1","author":"Radford","year":"2019","journal-title":"OpenAI Blog"},{"key":"10.1016\/j.knosys.2026.116100_b46","series-title":"OPT: Open pre-trained transformer language models","author":"Zhang","year":"2022"},{"key":"10.1016\/j.knosys.2026.116100_b47","series-title":"Llama-3.1-8B-Instruct","author":"AI@Meta","year":"2024"},{"key":"10.1016\/j.knosys.2026.116100_b48","series-title":"Proceedings of the 40th International Conference on Machine Learning","first-page":"2397","article-title":"Pythia: A suite for analyzing large language models across training and scaling","volume":"vol. 202","author":"Biderman","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b49","series-title":"Falcon-40B: An open large language model with state-of-the-art performance","author":"Almazrouei","year":"2023"},{"key":"10.1016\/j.knosys.2026.116100_b50","series-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023"},{"issue":"7","key":"10.1016\/j.knosys.2026.116100_b51","doi-asserted-by":"crossref","first-page":"1145","DOI":"10.1016\/S0031-3203(96)00142-2","article-title":"The use of the area under the ROC curve in the evaluation of machine learning algorithms","volume":"30","author":"Bradley","year":"1997","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.knosys.2026.116100_b52","doi-asserted-by":"crossref","unstructured":"N. Carlini, S. Chien, M. Nasr, S. Song, A. Terzis, F. Tram\u00e8r, Membership Inference Attacks From First Principles, in: 2022 IEEE Symposium on Security and Privacy, SP, 2022, pp. 1897\u20131914.","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"10.1016\/j.knosys.2026.116100_b53","series-title":"The relationship between precision-recall and ROC curves","author":"Davis","year":"2006"},{"issue":"3","key":"10.1016\/j.knosys.2026.116100_b54","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1214\/ss\/1032280214","article-title":"Bootstrap confidence intervals","volume":"11","author":"DiCiccio","year":"1996","journal-title":"Statist. Sci."},{"key":"10.1016\/j.knosys.2026.116100_b55","doi-asserted-by":"crossref","first-page":"348","DOI":"10.2478\/popets-2021-0031","article-title":"Revisiting membership inference under realistic assumptions","volume":"2021","author":"Jayaraman","year":"2021","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"10.1016\/j.knosys.2026.116100_b56","series-title":"Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics","first-page":"2006","article-title":"Model extraction and adversarial transferability, your BERT is vulnerable!","author":"He","year":"2021"},{"key":"10.1016\/j.knosys.2026.116100_b57","doi-asserted-by":"crossref","unstructured":"J. Jia, A. Salem, M. Backes, Y. Zhang, N.Z. Gong, MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples, in: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, 2019.","DOI":"10.1145\/3319535.3363201"},{"key":"10.1016\/j.knosys.2026.116100_b58","series-title":"Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies","first-page":"3799","article-title":"Privacy regularization: Joint privacy-utility optimization in LanguageModels","author":"Mireshghallah","year":"2021"},{"key":"10.1016\/j.knosys.2026.116100_b59","series-title":"Theory of Cryptography Conference","first-page":"265","article-title":"Calibrating noise to sensitivity in private data analysis","author":"Dwork","year":"2006"},{"key":"10.1016\/j.knosys.2026.116100_b60","doi-asserted-by":"crossref","unstructured":"M. Abadi, A. Chu, I.J. Goodfellow, H.B. McMahan, I. Mironov, K. Talwar, L. Zhang, Deep Learning with Differential Privacy, in: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 2016.","DOI":"10.1145\/2976749.2978318"},{"key":"10.1016\/j.knosys.2026.116100_b61","unstructured":"X. Li, F. Tramer, P. Liang, T. Hashimoto, Large Language Models Can Be Strong Differentially Private Learners, in: International Conference on Learning Representations, 2022."},{"issue":"1","key":"10.1016\/j.knosys.2026.116100_b62","first-page":"343","article-title":"DF-MIA: A distribution-free membership inference attack on fine-tuned large language models","volume":"39","author":"Huang","year":"2025","journal-title":"Proc. AAAI Conf. Artif. Intell."},{"key":"10.1016\/j.knosys.2026.116100_b63","series-title":"Proceedings of the 39th International Conference on Machine Learning","first-page":"10697","article-title":"Deduplicating training data mitigates privacy risks in language models","volume":"vol. 162","author":"Kandpal","year":"2022"},{"key":"10.1016\/j.knosys.2026.116100_b64","series-title":"Neural Networks: Tricks of the Trade","first-page":"55","article-title":"Early stopping-but when?","author":"Prechelt","year":"2002"},{"issue":"5","key":"10.1016\/j.knosys.2026.116100_b65","first-page":"4754","article-title":"Dynamic prototype network based on sample adaptation for few-shot malware detection","volume":"35","author":"Chai","year":"2023","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"10.1016\/j.knosys.2026.116100_b66","doi-asserted-by":"crossref","DOI":"10.1145\/3735645","article-title":"AEKG4APT: An AI-enhanced knowledge graph for advanced persistent threats with large language model analysis","author":"Zhou","year":"2025","journal-title":"ACM Trans. Intell. Syst. Technol."},{"issue":"1","key":"10.1016\/j.knosys.2026.116100_b67","doi-asserted-by":"crossref","first-page":"507","DOI":"10.1109\/TDSC.2025.3607846","article-title":"H44: A software-defined deception defense system in safeguard defense mode","volume":"23","author":"Wang","year":"2026","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.knosys.2026.116100_b68","doi-asserted-by":"crossref","DOI":"10.1016\/j.dajour.2023.100267","article-title":"A Gaussian process regression machine learning model for forecasting retail property prices with Bayesian optimizations and cross-validation","author":"Xu","year":"2023","journal-title":"Decis. Anal. J."}],"container-title":["Knowledge-Based Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126008269?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126008269?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,29]],"date-time":"2026-05-29T01:08:20Z","timestamp":1780016900000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0950705126008269"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":68,"alternative-id":["S0950705126008269"],"URL":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116100","relation":{},"ISSN":["0950-7051"],"issn-type":[{"value":"0950-7051","type":"print"}],"subject":[],"published":{"date-parts":[[2026,7]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Shortening the prefix! Members and non-members exhibit divergent behavior","name":"articletitle","label":"Article Title"},{"value":"Knowledge-Based Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116100","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier B.V. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"116100"}}