{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T00:29:49Z","timestamp":1766449789653,"version":"3.28.0"},"reference-count":53,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179463","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"364-381","source":"Crossref","is-referenced-by-count":7,"title":["Accuracy-Privacy Trade-off in Deep Ensemble: A Membership Inference Perspective"],"prefix":"10.1109","author":[{"given":"Shahbaz","family":"Rezaei","sequence":"first","affiliation":[{"name":"University of California,Davis,CA,USA"}]},{"given":"Zubair","family":"Shafiq","sequence":"additional","affiliation":[{"name":"University of California,Davis,CA,USA"}]},{"given":"Xin","family":"Liu","sequence":"additional","affiliation":[{"name":"University of California,Davis,CA,USA"}]}],"member":"263","reference":[{"key":"ref1","article-title":"When ensembling smaller models is more efficient than single large models","author":"Kondratyuk","year":"2020","journal-title":"arXiv preprint arXiv:2005.00570"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1023\/A:1022859003006"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1002\/widm.1249"},{"key":"ref4","article-title":"On power laws in deep ensembles","author":"Lobacheva","year":"2020","journal-title":"arXiv preprint arXiv:2007.08483"},{"key":"ref5","article-title":"Why m heads are better than one: Training a diverse ensemble of deep networks","author":"Lee","year":"2015","journal-title":"arXiv preprint arXiv:1511.06314"},{"key":"ref6","article-title":"Multiple networks are more efficient than one: Fast and accurate models via ensembles and cascades","author":"Wang","year":"2020","journal-title":"arXiv preprint arXiv:2012.01988"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.4324\/9781410605337-29"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref10","article-title":"Damia: Leveraging domain adaptation as a defense against membership inference attacks","author":"Huang","year":"2020","journal-title":"arXiv preprint arXiv:2005.08016"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3422337.3447836"},{"key":"ref12","article-title":"Sampling attacks: Amplification of membership inference attacks by repeated queries","author":"Rahimian","year":"2020","journal-title":"arXiv preprint arXiv:2009.00395"},{"key":"ref13","article-title":"Defending model inversion and membership inference attacks via prediction purification","author":"Yang","year":"2020","journal-title":"arXiv preprint arXiv:2005.03915"},{"key":"ref14","article-title":"Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"Salem","year":"2018","journal-title":"arXiv preprint arXiv:1806.01246"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2019.2897554"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref18","article-title":"Label-only membership inference attacks","author":"Choo","year":"2020","journal-title":"arXiv preprint arXiv:2007.14321"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3357713.3384290"},{"key":"ref20","article-title":"Snapshot ensembles: Train 1, get m for free","author":"Huang","year":"2017","journal-title":"arXiv preprint arXiv:1704.00109"},{"key":"ref21","article-title":"The diversified ensemble neural network","volume":"33","author":"Zhang","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref22","article-title":"Deep ensembles: A loss landscape perspective","author":"Fort","year":"2019","journal-title":"arXiv preprint arXiv:1912.02757"},{"key":"ref23","first-page":"6405","article-title":"Simple and scalable predictive uncertainty estimation using deep ensembles","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems","author":"Lakshminarayanan"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00780"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2019.2916086"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354211"},{"key":"ref27","article-title":"Towards measuring membership privacy","author":"Long","year":"2017","journal-title":"arXiv preprint arXiv:1712.09136"},{"key":"ref28","article-title":"Understanding membership inferences on well-generalized learning models","author":"Long","year":"2018","journal-title":"arXiv preprint arXiv:1802.04889"},{"key":"ref29","article-title":"Privacy analysis of deep learning in the wild: Membership inference attacks against transfer learning","author":"Zou","year":"2020","journal-title":"arXiv preprint arXiv:2009.04872"},{"key":"ref30","article-title":"Label-leaks: Membership inference attack with label","author":"Li","year":"2020","journal-title":"arXiv preprint arXiv:2007.15528"},{"key":"ref31","article-title":"On the importance of difficulty calibration in membership inference attacks","author":"Watson","year":"2021","journal-title":"arXiv preprint arXiv:2111.08440"},{"key":"ref32","first-page":"5558","article-title":"White-box vs black-box: Bayes optimal strategies for membership inference","volume-title":"International Conference on Machine Learning","author":"Sablayrolles"},{"key":"ref33","article-title":"An efficient subpopulation-based membership inference attack","author":"Rezaei","year":"2022","journal-title":"arXiv preprint arXiv:2203.02080"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref38","first-page":"1605","article-title":"Stolen memories: Leveraging model memorization for calibrated white-box membership inference","volume-title":"29th {USENIX} Security Symposium ({USENIX} Security 20)","author":"Leino"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"article-title":"Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms","year":"2017","author":"Xiao","key":"ref40"},{"article-title":"Reading digits in natural images with unsupervised feature learning","volume-title":"NIPS Workshop","author":"Netzer","key":"ref41"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref42"},{"key":"ref43","article-title":"On the certified robustness for ensemble models and beyond","author":"Yang","year":"2021","journal-title":"arXiv preprint arXiv:2107.10873"},{"key":"ref44","article-title":"Towards robust deep learning with ensemble networks and noisy layers","author":"Liang","year":"2020","journal-title":"arXiv preprint arXiv:2007.01507"},{"key":"ref45","article-title":"Differentially private learning needs better features (or much more data)","author":"Tramer","year":"2020","journal-title":"arXiv preprint arXiv:2011.11660"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/sp46214.2022.9833649"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359824"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"ref52","first-page":"1964","article-title":"Label-only membership inference attacks","volume-title":"International conference on machine learning","author":"Choquette-Choo"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","start":{"date-parts":[[2023,5,21]]},"location":"San Francisco, CA, USA","end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179463.pdf?arnumber=10179463","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,21]],"date-time":"2024-07-21T04:20:18Z","timestamp":1721535618000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179463\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":53,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179463","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}