{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T18:57:58Z","timestamp":1773773878119,"version":"3.50.1"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"NSFC-FDCT"},{"name":"Joint Scientific Research Project Fund","award":["0051\/2022\/AFJ"],"award-info":[{"award-number":["0051\/2022\/AFJ"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,7]]},"DOI":"10.1109\/tdsc.2025.3548119","type":"journal-article","created":{"date-parts":[[2025,3,5]],"date-time":"2025-03-05T14:03:07Z","timestamp":1741183387000},"page":"4472-4487","source":"Crossref","is-referenced-by-count":3,"title":["Model Inversion Attack Against Transfer Learning: Inverting a Model Without Querying It"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7561-0992","authenticated-orcid":false,"given":"Dayong","family":"Ye","sequence":"first","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Sydney, NSW, Australia"}]},{"given":"Huiqiang","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Data Science, City University of Macau, Macau, China"}]},{"given":"Shuai","family":"Zhou","sequence":"additional","affiliation":[{"name":"Faculty of Data Science, City University of Macau, Macau, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3411-7947","authenticated-orcid":false,"given":"Tianqing","family":"Zhu","sequence":"additional","affiliation":[{"name":"Institute of Data Science, City University of Macau, Macau, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1680-2521","authenticated-orcid":false,"given":"Wanlei","family":"Zhou","sequence":"additional","affiliation":[{"name":"Institute of Data Science, City University of Macau, Macau, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4268-372X","authenticated-orcid":false,"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.3004555"},{"key":"ref2","first-page":"1281","article-title":"With great training comes great vulnerability: Practical attacks against transfer learning","volume-title":"Proc. USENIX Symp. Secur.","author":"Wang"},{"key":"ref3","article-title":"Privacy analysis of deep learning in the wild: Membership inference attacks against transfer learning","author":"Zou","year":"2020"},{"key":"ref4","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","volume-title":"Proc. USENIX Secur. Symp.","author":"Fredrikson"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref8","first-page":"16937","article-title":"Inverting gradients - how easy is it to break privacy in federated learning?","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Geiping"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00072"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2017.2771779"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-021-03488-z"},{"key":"ref13","article-title":"Training language models to follow instructions with human feedback","author":"Ouyang","year":"2023"},{"key":"ref14","first-page":"1877","article-title":"Language models are few-shot learners","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Brown"},{"key":"ref15","first-page":"3593","article-title":"Teacher model fingerprinting attacks against transfer learning","volume-title":"Proc. USENIX Secur. Symp.","author":"Chen"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.371"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1201\/9781351251389-8"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243757"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33013379"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00612"},{"key":"ref21","first-page":"1","article-title":"Negative data augmentation","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Sinha"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1142\/p616"},{"issue":"15","key":"ref23","first-page":"3743","article-title":"What regularized auto-encoders learn from the data-generating distribution","author":"Alain","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-019-0197-0"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00760"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2019.2910052"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00975"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.2992393"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/tkde.2021.3090866"},{"key":"ref30","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Simonyan"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"},{"key":"ref32","first-page":"2507","article-title":"Lipschitz continuous autoencoders in application to anomaly detection","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Kim"},{"key":"ref33","first-page":"3663","article-title":"Certifiably robust variational autoencoders","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Barrett"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-020-05929-w"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2014.7025068"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref37","article-title":"The mnist database of handwritten digits","author":"LeCun","year":"1998"},{"key":"ref38","article-title":"An MNIST-like dataset of 70,000 28x28 labeled fashion images","year":"2017"},{"key":"ref39","first-page":"1291","article-title":"Updates-leak: Data set inference and reconstruction attacks in online learning","volume-title":"Proc. USENIX Secur. Symp.","author":"Salem"},{"key":"ref40","first-page":"2633","article-title":"Extracting training data from large language models","volume-title":"Proc. USENIX Secur. Symp.","author":"Carlini"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00232"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2019.00020"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/cvprw50498.2020.00359"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3163591"},{"key":"ref47","first-page":"1","article-title":"A target-agnostic attack on deep models: Exploiting security vulnerabilities of transfer learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Rezaei"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN52387.2021.9534207"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/tsc.2020.3000900"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/tr.2021.3105697"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01462"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3233190"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11077775\/10910223.pdf?arnumber=10910223","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,11]],"date-time":"2025-07-11T22:48:41Z","timestamp":1752274121000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10910223\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7]]},"references-count":53,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3548119","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7]]}}}