{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T13:37:43Z","timestamp":1769002663546,"version":"3.49.0"},"reference-count":70,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22A2025"],"award-info":[{"award-number":["U22A2025"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62232007"],"award-info":[{"award-number":["62232007"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U23A20309"],"award-info":[{"award-number":["U23A20309"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3601844","type":"journal-article","created":{"date-parts":[[2025,9,4]],"date-time":"2025-09-04T18:24:24Z","timestamp":1757010264000},"page":"386-402","source":"Crossref","is-referenced-by-count":0,"title":["Untargeted Poisoning Membership Inference With Sample Selection and Enhancement"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-2559-9674","authenticated-orcid":false,"given":"Jian","family":"Li","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Northeastern University, Shenyang, Liaoning, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6184-4771","authenticated-orcid":false,"given":"Xiaochun","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Northeastern University, Shenyang, Liaoning, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6305-1740","authenticated-orcid":false,"given":"Wanlun","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2694-1023","authenticated-orcid":false,"given":"Bin","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Northeastern University, Shenyang, Liaoning, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0655-666X","authenticated-orcid":false,"given":"Sheng","family":"Wen","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5252-0831","authenticated-orcid":false,"given":"Yang","family":"Xiang","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2024.124971"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2024.124983"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3716628"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2025.125498"},{"key":"ref5","first-page":"1467","article-title":"Poisoning attacks against support vector machines","volume-title":"Proc. 29th Int. Conf. Mach. Learn.","author":"Biggio"},{"key":"ref6","first-page":"7614","article-title":"Transferable clean-label poisoning attacks on deep neural nets","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhu"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2024.3361451"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354211"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref11","article-title":"Amplifying membership exposure via data poisoning","volume-title":"Proc. Adv. Annu. Conf. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560554"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583542"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/532"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"ref16","first-page":"6106","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Shafahi"},{"key":"ref17","first-page":"1299","article-title":"When does machine learning fail? Generalized transferability for evasion and poisoning attacks","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Suciu"},{"key":"ref18","first-page":"4063","article-title":"Witches\u2019 brew: Industrial scale data poisoning via gradient matching","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Geiping"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179463"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref21","article-title":"Robust contrastive language-image pretraining against data poisoning and backdoor attacks","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Yang"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i12.17284"},{"key":"ref24","first-page":"5345","article-title":"When does data augmentation help with membership inference attacks?","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Kaya"},{"key":"ref25","first-page":"723","article-title":"A kernel two-sample test","volume-title":"J. Mach. Learn. Res.","volume":"13","author":"Gretton","year":"2012"},{"key":"ref26","first-page":"1633","article-title":"A new defense against adversarial images: Turning a weakness into a strength","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Hu"},{"key":"ref27","first-page":"1964","article-title":"Label-only membership inference attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Choquette-Choo"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3233190"},{"issue":"11","key":"ref30","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"Van der Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/554"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00443"},{"key":"ref33","first-page":"2530","article-title":"Not all samples are created equal: Deep learning with importance sampling","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Katharopoulos"},{"key":"ref34","first-page":"1768","article-title":"An empirical study of example forgetting during deep neural network learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Toneva"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3285015"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2024.121847"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i3.25442"},{"key":"ref38","first-page":"402","article-title":"Characterizing adversarial subspaces using local intrinsic dimensionality","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Ma"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref40","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"Proc. USENIX Secur. Symp.","author":"Song"},{"key":"ref41","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017"},{"key":"ref42","first-page":"215","article-title":"An analysis of single-layer networks in unsupervised feature learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Coates"},{"key":"ref43","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3222880"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3321565"},{"key":"ref46","first-page":"22738","article-title":"Poisoning and backdooring contrastive learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Carlini"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.32604\/cmc.2022.019709"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-023-17394-3"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-023-16126-x"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3346692"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-16210-7_54"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3581103"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2025.104513"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/tkde.2024.3419930"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2932228"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3376929"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-96-1093-8_12"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3704725"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3367737"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3305591"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3436755"},{"key":"ref64","article-title":"Scalable membership inference attacks via quantile regression","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Bertran"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref67","first-page":"1184","article-title":"On the importance of difficulty calibration in membership inference attacks","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Watson"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3606017"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3532957"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2023.100595"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11151295.pdf?arnumber=11151295","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T23:23:29Z","timestamp":1768951409000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11151295\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":70,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3601844","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}