{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T14:15:45Z","timestamp":1785420945008,"version":"3.56.0"},"reference-count":46,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179334","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"400-417","source":"Crossref","is-referenced-by-count":16,"title":["SNAP: Efficient Extraction of Private Properties with Poisoning"],"prefix":"10.1109","author":[{"given":"Harsh","family":"Chaudhari","sequence":"first","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"John","family":"Abascal","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alina","family":"Oprea","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Matthew","family":"Jagielski","sequence":"additional","affiliation":[{"name":"Google Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Florian","family":"Tram\u00e8r","sequence":"additional","affiliation":[{"name":"ETH Zurich"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jonathan","family":"Ullman","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"ref2","first-page":"2687","article-title":"Leakage of dataset properties in Multi-Party machine learning","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Zhang"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833623"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1504\/ijsn.2015.071829"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0121"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref7","article-title":"UCI machine learning repository","author":"Dua","year":"2017"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/773153.773173"},{"key":"ref10","article-title":"The secret sharer: Evaluating and testing unintended memorization in neural networks","volume-title":"28th USENIX Security Symposium (USENIX Security 19)","author":"Carlini"},{"key":"ref11","article-title":"Extracting training data from large language models","volume-title":"30th USENIX Security Symposium (USENIX Security 2021)","author":"Carlini"},{"key":"ref12","article-title":"Reconstructing training data with informed adversaries","volume-title":"CoRR","volume":"abs\/2201.04845","author":"Balle","year":"2022"},{"key":"ref13","first-page":"5959","article-title":"Gradient disaggregation: Breaking privacy in federated learning by reconstructing the user participant matrix","volume-title":"Proceedings of the 38th International Conference on Machine Learning","volume":"139","author":"Lam"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp57164.2023.00020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pgen.1000167"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref17","article-title":"White-box vs black-box: Bayes optimal strategies for membership inference","volume-title":"International Conference on Machine Learning","author":"Sablayrolles"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00040"},{"key":"ref19","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"30th USENIX Security Symposium","author":"Song"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0031"},{"key":"ref21","article-title":"Label-only membership inference attacks","volume-title":"Proceedings of the 38th International Conference on Machine Learning","author":"Choquette-Choo"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560675"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref24","article-title":"Poisoning attacks against support vector machines","volume-title":"Proceedings of the 29th International Conference on International Conference on Machine Learning","author":"Biggio"},{"key":"ref25","first-page":"1689","article-title":"Is feature selection secure against training data poisoning?","volume-title":"International Conference on Machine Learning","author":"Xiao"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/11856214_5"},{"key":"ref28","first-page":"1885","article-title":"Understanding black-box predictions via influence functions","volume-title":"Proceedings of the 34th International Conference on Machine Learning-Volume 70","author":"Koh"},{"key":"ref29","first-page":"1299","article-title":"When does machine learning {FAIL}? generalized transferability for evasion and poisoning attacks","volume-title":"27th USENIX Security Symposium","author":"Suciu"},{"key":"ref30","article-title":"Witches\u2019 brew: Industrial scale data poisoning via gradient matching","volume-title":"International Conference on Learning Representations","author":"Geiping"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref32","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485368"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/657"},{"key":"ref35","first-page":"22205","article-title":"Auditing differentially private machine learning: How private is private SGD?","volume":"33","author":"Jagielski","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00069"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560554"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/sp.2019.00029"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23019"},{"key":"ref40","article-title":"Inference attacks against graph neural networks","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Zhang"},{"key":"ref41","first-page":"97","article-title":"Support vector machines under adversarial label noise","volume-title":"Proceedings of the Asian Conference on Machine Learning","volume":"20","author":"Biggio"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref43","article-title":"Certified defenses for data poisoning attacks","volume-title":"Advances in Neural Information Processing Systems","volume":"30","author":"Steinhardt","year":"2017"},{"key":"ref44","first-page":"22769","article-title":"Improved certified defenses against data poisoning with (Deterministic Finite Aggregation","volume-title":"Proceedings of the 39th International Conference on Machine Learning","volume":"162","author":"Wang"},{"key":"ref45","article-title":"Opacus: User-friendly differential privacy library in PyTorch","author":"Yousefpour","year":"2021"},{"key":"ref46","article-title":"Adam: A method for stochastic optimization","volume-title":"3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings","author":"Kingma"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179334.pdf?arnumber=10179334","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:18:35Z","timestamp":1721452715000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179334\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":46,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179334","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}