{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T07:34:24Z","timestamp":1773300864489,"version":"3.50.1"},"reference-count":30,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,10,3]],"date-time":"2022-10-03T00:00:00Z","timestamp":1664755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,10,3]],"date-time":"2022-10-03T00:00:00Z","timestamp":1664755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1801751,1956364,1937786"],"award-info":[{"award-number":["1801751,1956364,1937786"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,10,3]]},"DOI":"10.1109\/cns56114.2022.9947254","type":"proceedings-article","created":{"date-parts":[[2022,11,18]],"date-time":"2022-11-18T20:49:54Z","timestamp":1668804594000},"page":"299-307","source":"Crossref","is-referenced-by-count":1,"title":["Membership Inference Attack in Face of Data Transformations"],"prefix":"10.1109","author":[{"given":"Jiyu","family":"Chen","sequence":"first","affiliation":[{"name":"University of California,Department of Computer Science,Davis"}]},{"given":"Yiwen","family":"Guo","sequence":"additional","affiliation":[{"name":"Independent Researcher"}]},{"given":"Hao","family":"Chen","sequence":"additional","affiliation":[{"name":"University of California,Department of Computer Science,Davis"}]},{"given":"Neil","family":"Gong","sequence":"additional","affiliation":[{"name":"Duke University,Department of Electrical and Computer Engineering"}]}],"member":"263","reference":[{"key":"ref30","year":"2020","journal-title":"Opacus Train PyTorch models with Differential Privacy"},{"key":"ref10","article-title":"Label-only membership inference attacks","author":"choo","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref11","first-page":"1277","article-title":"Hop-skipjumpattack: A query-efficient decision-based attack","author":"chen","year":"0","journal-title":"2020 IEEE Symposium on Security and Privacy (SP)"},{"key":"ref12","article-title":"Membership leakage in label-only exposures","author":"li","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref13","article-title":"Sampling attacks: Amplification of membership inference attacks by repeated queries","author":"rahimian","year":"2020","journal-title":"ArXiv Preprint"},{"key":"ref14","first-page":"1605","article-title":"Stolen memories: Leveraging model memorization for calibrated white-box member-ship inference","author":"leino","year":"2020","journal-title":"29th USENIX Security Symposium USENIX Security 20"},{"key":"ref15","first-page":"5558","article-title":"White-box vs black-box: Bayes optimal strategies for membership inference","author":"sablayrolles","year":"2019","journal-title":"International Conference on Machine Learning"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0008"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0067"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2019.00056"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref28","article-title":"Very deep convolutional networks for large-scale image recognition","author":"simonyan","year":"2014","journal-title":"ArXiv Preprint"},{"key":"ref4","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"ArXiv Preprint"},{"key":"ref27","article-title":"pilgram: A python library for instagram filters","author":"kamakura","year":"2019","journal-title":"https \/\/github com\/akiomik\/pilgram"},{"key":"ref3","year":"2014","journal-title":"Kaggle Acquire valued shop-pers challenge"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref29","article-title":"Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"salem","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/30.125072"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref2","author":"krizhevsky","year":"2009","journal-title":"Learning multiple layers of features from tiny images"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref22","article-title":"Dif-ferentially private generative adversarial network","author":"xie","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref21","article-title":"Differentially private data generative models","author":"chen","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i12.17284"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-021-05951-6"},{"key":"ref26","article-title":"Towards deep learning models resistant to adversarial attacks","author":"madry","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref25","article-title":"Systematic evaluation of privacy risks of machine learning models","author":"song","year":"2021","journal-title":"30th USENIX Security Symposium ( USENIX Security 21)"}],"event":{"name":"2022 IEEE Conference on Communications and Network Security (CNS)","location":"Austin, TX, USA","start":{"date-parts":[[2022,10,3]]},"end":{"date-parts":[[2022,10,5]]}},"container-title":["2022 IEEE Conference on Communications and Network Security (CNS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9947203\/9947223\/09947254.pdf?arnumber=9947254","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,12]],"date-time":"2022-12-12T19:56:57Z","timestamp":1670875017000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9947254\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,3]]},"references-count":30,"URL":"https:\/\/doi.org\/10.1109\/cns56114.2022.9947254","relation":{},"subject":[],"published":{"date-parts":[[2022,10,3]]}}}