{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:36:24Z","timestamp":1777656984570,"version":"3.51.4"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2018YFB2100403"],"award-info":[{"award-number":["2018YFB2100403"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tifs.2023.3295942","type":"journal-article","created":{"date-parts":[[2023,7,17]],"date-time":"2023-07-17T17:37:45Z","timestamp":1689615465000},"page":"4449-4462","source":"Crossref","is-referenced-by-count":7,"title":["Analysis and Utilization of Hidden Information in Model Inversion Attacks"],"prefix":"10.1109","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4275-5722","authenticated-orcid":false,"given":"Zeping","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2354-4791","authenticated-orcid":false,"given":"Xiaowen","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4900-5115","authenticated-orcid":false,"given":"Jie","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5977-7477","authenticated-orcid":false,"given":"Shuaishuai","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM42002.2020.9322508"},{"key":"ref35","first-page":"1","article-title":"PyTorch: An imperative style, high-performance deep learning library","author":"paszke","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.32"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2014.7025068"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"ref37","first-page":"3221","article-title":"Accelerating t-SNE using tree-based algorithms","volume":"15","author":"van der maaten","year":"2014","journal-title":"J Mach Learn Res"},{"key":"ref14","first-page":"11666","article-title":"Improving robustness to model inversion attacks via mutual information regularization","author":"wang","year":"2020","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"ref36","article-title":"Unsupervised representation learning with deep convolutional generative adversarial networks","author":"radford","year":"2016","journal-title":"arXiv 1511 06434"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref30","first-page":"1291","article-title":"Updates-leak: Data set inference and reconstruction attacks in online learning","author":"salem","year":"2020","journal-title":"Proc 29th Secur Symp (USENIX Security)"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref33","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"xiao","year":"2017","journal-title":"ArXiv 1708 07747"},{"key":"ref10","first-page":"17","article-title":"Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing","author":"fredrikson","year":"2014","journal-title":"Proc 23rd Secur Symp (USENIX Security)"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"ref2","year":"2021","journal-title":"Azure Machine Learning as a Service"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1038\/nature14539"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref16","article-title":"Diversity-sensitive conditional generative adversarial networks","author":"yang","year":"2019","journal-title":"arXiv 1901 09024"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3233190"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01587"},{"key":"ref18","first-page":"2672","article-title":"Generative adversarial nets","author":"goodfellow","year":"2014","journal-title":"Proc 27th Int Conf Neural Inf Process Syst"},{"key":"ref24","year":"2016","journal-title":"Statistical inference considered harmful"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220099"},{"key":"ref26","first-page":"818","article-title":"Visualizing and understanding convolutional networks","author":"zeiler","year":"2014","journal-title":"Computer Vision (ECCV)"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7299155"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref21","author":"gonzalez","year":"2006","journal-title":"Digital Image Processing"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/5.784232"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/72.286912"},{"key":"ref29","author":"goodfellow","year":"2016","journal-title":"Deep Learning"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3019508"},{"key":"ref7","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2014","journal-title":"arXiv 1312 6199"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/PST.2017.00023"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2018.07.023"},{"key":"ref3","year":"2021","journal-title":"Machine Learning Image and Video Analysis&#x2014;Amazon Rekognition&#x2014;Amazon Web Services"},{"key":"ref6","article-title":"A taxonomy and terminology of adversarial machine learning","author":"tabassi","year":"8269"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9970396\/10184490.pdf?arnumber=10184490","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T17:48:46Z","timestamp":1692640126000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10184490\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/tifs.2023.3295942","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}