{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T08:02:30Z","timestamp":1780473750209,"version":"3.54.1"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1936218"],"award-info":[{"award-number":["U1936218"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61802383"],"award-info":[{"award-number":["61802383"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102107"],"award-info":[{"award-number":["62102107"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072132"],"award-info":[{"award-number":["62072132"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62002074"],"award-info":[{"award-number":["62002074"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2023,5,1]]},"DOI":"10.1109\/tdsc.2022.3174569","type":"journal-article","created":{"date-parts":[[2022,5,12]],"date-time":"2022-05-12T19:33:48Z","timestamp":1652384028000},"page":"2144-2157","source":"Crossref","is-referenced-by-count":37,"title":["Defending Against Membership Inference Attacks With High Utility by GAN"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1453-0996","authenticated-orcid":false,"given":"Li","family":"Hu","sequence":"first","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0385-8793","authenticated-orcid":false,"given":"Jin","family":"Li","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7372-7345","authenticated-orcid":false,"given":"Guanbiao","family":"Lin","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shiyu","family":"Peng","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenxin","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yingying","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Artificial Intelligence and Blockchain, Guangzhou University, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8625-0275","authenticated-orcid":false,"given":"Changyu","family":"Dong","sequence":"additional","affiliation":[{"name":"School of Computing, Newcastle University, Newcastle upon Tyne, U.K."}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2014.220"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011190"},{"key":"ref12","doi-asserted-by":"crossref","first-page":"753","DOI":"10.1056\/NEJMoa0809329","article-title":"Estimation of the warfarin dose with clinical and pharmacogenetic data","volume":"360","author":"consortium","year":"2009","journal-title":"New England J Med"},{"key":"ref34","first-page":"422","article-title":"Sensitive data privacy protection method based on transfer learning","volume":"34","author":"fu","year":"2019","journal-title":"J Data Acquisition Process"},{"key":"ref15","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","author":"song","year":"2021","journal-title":"Proc 30th USENIX Secur Symp"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00813"},{"key":"ref14","article-title":"ML-Leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"salem","year":"2018"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref31","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1142\/9789811232701_0003"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.jbi.2012.07.011"},{"key":"ref33","first-page":"641","article-title":"Multi-source data privacy protection based on transfer learning","volume":"41","author":"yu-xiang","year":"2019","journal-title":"Comput Eng Sec"},{"key":"ref10","first-page":"601","article-title":"Stealing machine learning models via prediction APIs","author":"tram\u00e8r","year":"2016","journal-title":"Proc 25th USENIX Secur Symp"},{"key":"ref32","article-title":"Semi-supervised knowledge transfer for deep learning from private training data","author":"papernot","year":"2016"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SIBGRAPI.2018.00067"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2016.12.038"},{"key":"ref17","first-page":"1964","article-title":"Label-only membership inference attacks","author":"choquette-choo","year":"2021","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref39","article-title":"Modeling tabular data using conditional GAN","author":"xu","year":"2019"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref38","article-title":"Training generative adversarial networks with limited data","author":"karras","year":"2020"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref18","article-title":"Label-leaks: Membership inference attack with label","author":"li","year":"2020"},{"key":"ref24","article-title":"Membership privacy for machine learning models through knowledge transfer","author":"shejwalkar","year":"2019"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484749"},{"key":"ref45","first-page":"2893","article-title":"Moonshine: Distilling with cheap convolutions","author":"crowley","year":"2018","journal-title":"Proc 32nd Int Conf Neural Inf Process Syst"},{"key":"ref26","first-page":"1","article-title":"DAMIA: Leveraging domain adaptation as a defense against membership inference attacks","volume":"pp","author":"huang","year":"2021","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.082"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref42","article-title":"Improving neural networks by preventing co-adaptation of feature detectors","author":"hinton","year":"2012"},{"key":"ref41","first-page":"1605","article-title":"Stolen memories: Leveraging model memorization for calibrated white-box membership inference","author":"leino","year":"2020","journal-title":"Proc 29th USENIX Secur Symp"},{"key":"ref22","article-title":"On the effectiveness of regularization against membership inference attacks","author":"kaya","year":"2020"},{"key":"ref44","article-title":"Distilling the knowledge in a neural network","author":"hinton","year":"2015"},{"key":"ref21","article-title":"Use the spear as a shield: A novel adversarial example based privacy-preserving technique against membership inference attacks","author":"xue","year":"2020"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298664"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.4236\/jcc.2021.95007"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3474369.3486876"},{"key":"ref8","article-title":"The secret sharer: Measuring unintended neural network memorization & extracting secrets","author":"carlini","year":"2018"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/CCAA.2018.8777449"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3158369"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.jcmg.2018.01.020"},{"key":"ref40","article-title":"Learning multiple layers of features from tiny images","volume":"1","author":"krizhevsky","year":"2009","journal-title":"Handbook of Systemic Autoimmune Diseases"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10126099\/09773984.pdf?arnumber=9773984","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,19]],"date-time":"2023-06-19T18:29:27Z","timestamp":1687199367000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9773984\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5,1]]},"references-count":45,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2022.3174569","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,5,1]]}}}