{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T16:04:09Z","timestamp":1774627449910,"version":"3.50.1"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102353"],"award-info":[{"award-number":["62102353"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62072398"],"award-info":[{"award-number":["62072398"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,5]]},"DOI":"10.1109\/tdsc.2024.3518698","type":"journal-article","created":{"date-parts":[[2024,12,23]],"date-time":"2024-12-23T19:43:23Z","timestamp":1734983003000},"page":"2687-2704","source":"Crossref","is-referenced-by-count":5,"title":["Defending Data Inference Attacks Against Machine Learning Models by Mitigating Prediction Distinguishability"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-4995-7085","authenticated-orcid":false,"given":"Ziqi","family":"Yang","sequence":"first","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"given":"Yiran","family":"Zhu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"given":"Jie","family":"Wan","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"given":"ChuXiao","family":"Xiang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"given":"Tong","family":"Tang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"given":"Yilin","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"given":"Ruite","family":"Xu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"given":"Lijin","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6087-8243","authenticated-orcid":false,"given":"Fan","family":"Zhang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2973-1889","authenticated-orcid":false,"given":"Jiarong","family":"Xu","sequence":"additional","affiliation":[{"name":"Department of Information Management and Business Intelligence, Fudan University, Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7872-6969","authenticated-orcid":false,"given":"Zhan","family":"Qin","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security, Zhejiang University, Hangzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3422337.3447836"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24293"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560675"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"ref13","article-title":"Overlearning reveals sensitive attributes","volume-title":"Proc. 8th Int. Conf. Learn. Representations","author":"Song"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00001"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref18","article-title":"Relaxloss: Defending membership inference attacks without losing utility","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Chen","year":"2022"},{"key":"ref19","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","volume-title":"Proc. 23rd USENIX Conf. Secur. Symp.","author":"Fredrikson"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-28954-6_7"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274696"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.32"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2017.00023"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1093\/bioinformatics\/btl242"},{"issue":"1","key":"ref30","first-page":"723","article-title":"A kernel two-sample test","volume":"13","author":"Gretton","year":"2012","journal-title":"J. Mach. Learn. Res."},{"key":"ref31","first-page":"1433","article-title":"Mitigating membership inference attacks by self-distillation through a novel ensemble architecture","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Tang"},{"key":"ref32","first-page":"1964","article-title":"Label-only membership inference attacks","volume-title":"Proc. 38th Int. Conf. Mach. Learn.","author":"Choquette-Choo"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.463"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"issue":"1","key":"ref37","first-page":"3221","article-title":"Accelerating t-SNE using tree-based algorithms","volume":"15","author":"Van Der Maaten","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref38","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry","year":"2017"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6930"},{"key":"ref40","first-page":"513","article-title":"AttriGuard: A practical defense against attribute inference attacks via adversarial machine learning","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Jia"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pgen.1000167"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978355"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23064"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23183"},{"key":"ref45","article-title":"Under the hood of membership inference attacks on aggregate location time-series","author":"Pyrgelis","journal-title":"arXiv:1902.07456"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref49","first-page":"201","article-title":"CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy","volume-title":"Proc. 33rd Int. Conf. Int. Conf. Mach. Learn.","author":"Dowlin"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref51","first-page":"1693","article-title":"Privacy-preserving prediction","volume-title":"Proc. 31st Conf. On Learn. Theory","author":"Dwork"},{"key":"ref52","first-page":"619","article-title":"Oblivious multi-party machine learning on trusted processors","volume-title":"Proc. 25th USENIX Secur. Symp.","author":"Ohrimenko"},{"key":"ref53","first-page":"1651","article-title":"Gazelle: A low latency framework for secure neural network inference","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Juvekar"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/10992672\/10812872.pdf?arnumber=10812872","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,15]],"date-time":"2025-05-15T19:37:11Z","timestamp":1747337831000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10812872\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5]]},"references-count":52,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2024.3518698","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5]]}}}