{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T00:02:20Z","timestamp":1755993740505,"version":"3.44.0"},"reference-count":37,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T00:00:00Z","timestamp":1738368000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T00:00:00Z","timestamp":1738368000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,2,1]],"date-time":"2025-02-01T00:00:00Z","timestamp":1738368000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22A2036"],"award-info":[{"award-number":["U22A2036"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2021YFB3101102"],"award-info":[{"award-number":["2021YFB3101102"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Artif. Intell."],"published-print":{"date-parts":[[2025,2]]},"DOI":"10.1109\/tai.2024.3357791","type":"journal-article","created":{"date-parts":[[2024,1,26]],"date-time":"2024-01-26T14:08:42Z","timestamp":1706278122000},"page":"317-332","source":"Crossref","is-referenced-by-count":2,"title":["A Membership Inference and Adversarial Attack Defense Framework for Network Traffic Classifiers"],"prefix":"10.1109","volume":"6","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2890-3776","authenticated-orcid":false,"given":"Guangrui","family":"Liu","sequence":"first","affiliation":[{"name":"School of Cyberspace Science, Harbin Institute of Technology, Harbin, Heilongjiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4783-876X","authenticated-orcid":false,"given":"Weizhe","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science, Harbin Institute of Technology, Harbin, Heilongjiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-7325-6115","authenticated-orcid":false,"given":"Xurun","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science, Harbin Institute of Technology, Harbin, Heilongjiang, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-3261-9317","authenticated-orcid":false,"given":"Stephen","family":"King","sequence":"additional","affiliation":[{"name":"Leland High school, San Jose, CA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4485-6743","authenticated-orcid":false,"given":"Shui","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/s42979-021-00592-x"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2023.3314398"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3436755"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3137091"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3088084"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2022.3190816"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2021.3111139"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2020.3014246"},{"key":"ref9","first-page":"9583","article-title":"Bayesian differential privacy for machine learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Triastcyn","year":"2020"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484565"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-022-01581-0"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3052888"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39077-7_5"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"ref16","article-title":"Intriguing properties of neural networks","volume-title":"Proc. 2nd Int. Conf. Learn. Representations (ICLR)","author":"Szegedy","year":"2014"},{"article-title":"Explaining and harnessing adversarial examples","year":"2014","author":"Goodfellow","key":"ref17"},{"key":"ref18","first-page":"10380","article-title":"Adversarial risk and robustness: General definitions and implications for the uniform distribution","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"31","author":"Diochnos","year":"2018"},{"key":"ref19","first-page":"368","article-title":"A unified view on differential privacy and robustness to adversarial examples","volume-title":"Proc. Workshop Mach. Learn. CyberSecurity (ECMLPKDD)","author":"Pinot","year":"2019"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1146\/annurev.neuro.26.041002.131047"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.csda.2019.106839"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"ref24","first-page":"7683","article-title":"Scalable differential privacy with certified robustness in adversarial learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Phan","year":"2020"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.3233\/faia200256"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/ICOIN.2017.7899588"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3009843"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-021-3455-1"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.3390\/app9163414"},{"key":"ref30","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"Proc. 30th USENIX Secur. Symp.","volume":"1","author":"Song","year":"2021"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560675"},{"article-title":"Nesterov accelerated gradient and scale invariance for adversarial attacks","year":"2019","author":"Lin","key":"ref32"},{"key":"ref33","first-page":"2206","article-title":"Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Croce","year":"2020"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref36","first-page":"21945","article-title":"Denoised smoothing: A provable defense for pretrained classifiers","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Salman","year":"2020"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20545"}],"container-title":["IEEE Transactions on Artificial Intelligence"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9078688\/10908727\/10415302.pdf?arnumber=10415302","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T01:09:40Z","timestamp":1755911380000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10415302\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2]]},"references-count":37,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tai.2024.3357791","relation":{},"ISSN":["2691-4581"],"issn-type":[{"type":"electronic","value":"2691-4581"}],"subject":[],"published":{"date-parts":[[2025,2]]}}}