{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T04:06:45Z","timestamp":1778904405497,"version":"3.51.4"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1109\/tdsc.2026.3658692","type":"journal-article","created":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T21:01:44Z","timestamp":1769634104000},"page":"5734-5748","source":"Crossref","is-referenced-by-count":0,"title":["Rethinking Query Choices for Differential Privacy Auditing"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-5469-0762","authenticated-orcid":false,"given":"Zehang","family":"Deng","sequence":"first","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongqiao","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-4108-5588","authenticated-orcid":false,"given":"Shan","family":"Jiang","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6305-1740","authenticated-orcid":false,"given":"Wanlun","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0655-666X","authenticated-orcid":false,"given":"Sheng","family":"Wen","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3411-7947","authenticated-orcid":false,"given":"Tianqing","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Data Science, City University of Macau, Macau, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5252-0831","authenticated-orcid":false,"given":"Yang","family":"Xiang","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2014.56"},{"key":"ref3","article-title":"Influence functions in deep learning are fragile","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Basu","year":"2021"},{"key":"ref4","article-title":"Quantifying membership inference vulnerability via generalization gap and other model metrics","author":"Bentley","year":"2020"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/979-8-8688-1414-3_3"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330723"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICMCSI61536.2024.00029"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.2307\/2331986"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1914598117"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3183713.3197390"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4020-6949-9"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2023.02.058"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3716628"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2025.125498"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3581103"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2025.3532957"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243818"},{"key":"ref19","article-title":"SHAPr: An efficient and versatile membership privacy risk metric for machine learning","author":"Duddu","year":"2021"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1038\/nature21056"},{"key":"ref22","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref23","first-page":"22205","article-title":"Auditing differentially private machine learning: How private is private SGD?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Jagielski","year":"2020"},{"key":"ref24","first-page":"1895","article-title":"Evaluating differentially private machine learning in practice","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Jayaraman","year":"2019"},{"key":"ref25","first-page":"4165","article-title":"A general framework for auditing differentially private machine learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Lu","year":"2022"},{"key":"ref26","first-page":"1","article-title":"Unveiling m-sharpness through the structure of stochastic gradient noise","volume-title":"Proc. 29th Annu. Conf. Neural Inf. Process. Syst.","author":"Luo","year":"2025"},{"key":"ref27","first-page":"4424","article-title":"Explicit eigenvalue regularization improves sharpness-aware minimization","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Luo","year":"2024"},{"key":"ref28","article-title":"CANIFE: Crafting canaries for empirical privacy measurement in federated learning","volume-title":"Proc. Int. Conf. Learn. Representations (ICLR)","author":"Maddock","year":"2023"},{"key":"ref29","first-page":"131482","article-title":"Nearly tight black-box auditing of differentially private machine learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Muthu","year":"2024"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00069"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1201\/9780429186196"},{"key":"ref32","first-page":"8026","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Paszke","year":"2019"},{"key":"ref33","first-page":"1","article-title":"Unleashing the power of randomization in auditing differentially private ML","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Pillutla","year":"2024"},{"key":"ref34","first-page":"19920","article-title":"Estimating training data influence by tracing gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Pruthi","year":"2020"},{"key":"ref35","article-title":"Poisoning attacks and defenses on artificial intelligence: A survey","author":"Ramirez","year":"2022"},{"key":"ref36","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Song","year":"2021"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/GlobalSIP.2013.6736861"},{"key":"ref38","first-page":"49268","article-title":"Privacy auditing with one (1) training run","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Steinke","year":"2024"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3551636"},{"key":"ref40","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2023.103827"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref43","article-title":"Opacus: User-friendly differential privacy library in PyTorch","volume-title":"Proc. NeurIPS Workshop Privacy Mach. Learn.","author":"Yousefpour","year":"2021"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/JAS.2024.124983"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/tkde.2020.3014246"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11517592\/11367291.pdf?arnumber=11367291","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T03:09:45Z","timestamp":1778900985000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11367291\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":45,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2026.3658692","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5]]}}}