{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,15]],"date-time":"2025-11-15T10:33:04Z","timestamp":1763202784580,"version":"3.37.3"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"publisher","award":["62272038","U2241213","62172025"],"award-info":[{"award-number":["62272038","U2241213","62172025"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFB2702903"],"award-info":[{"award-number":["2022YFB2702903"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004826","name":"Beijing Natural Science Foundation","doi-asserted-by":"publisher","award":["M23018"],"award-info":[{"award-number":["M23018"]}],"id":[{"id":"10.13039\/501100004826","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tifs.2023.3318950","type":"journal-article","created":{"date-parts":[[2023,9,25]],"date-time":"2023-09-25T18:13:31Z","timestamp":1695665611000},"page":"5848-5859","source":"Crossref","is-referenced-by-count":9,"title":["Subject-Level Membership Inference Attack via Data Augmentation and Model Discrepancy"],"prefix":"10.1109","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1547-1177","authenticated-orcid":false,"given":"Yimin","family":"Liu","sequence":"first","affiliation":[{"name":"School of Cyberspace Science and Technology and the School of Computer Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5786-1512","authenticated-orcid":false,"given":"Peng","family":"Jiang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3277-3887","authenticated-orcid":false,"given":"Liehuang","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","article-title":"Subject membership inference attacks in federated learning","author":"suri","year":"2022","journal-title":"arXiv 2206 03317"},{"key":"ref35","article-title":"Inference attacks against collaborative learning","author":"melis","year":"2018","journal-title":"arXiv 1805 04049"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3529836.3529845"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3163241"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330885"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ISPCE-ASIA57917.2022.9971068"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0012"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2013.07.046"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2013.01.018"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-021-1067-4"},{"key":"ref33","first-page":"1","article-title":"Focusing on Pinocchio&#x2019;s nose: A gradients scrutinizer to thwart split-learning hijacking attacks using intrinsic attributes","author":"fu","year":"2023","journal-title":"Proc Symp Network and Distributed System Security"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0031"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24287"},{"key":"ref2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1561\/2200000083","article-title":"Advances and open problems in federated learning","volume":"14","author":"kairouz","year":"2019","journal-title":"Found Trends Mach Learn"},{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume":"54","author":"mcmahan","year":"2017","journal-title":"Proc 20th Int Conf Artif Intell Statist"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0121"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484756"},{"key":"ref38","article-title":"Membership inference on word embedding and beyond","author":"mahloujifar","year":"2021","journal-title":"arXiv 2106 11384"},{"key":"ref19","article-title":"Efficient passive membership inference attack in federated learning","author":"zari","year":"2021","journal-title":"arXiv 2111 00430"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref24","first-page":"2687","article-title":"Leakage of dataset properties in multi-party machine learning","author":"zhang","year":"2021","journal-title":"Proc 30th USENIX Secur Symp"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICC40277.2020.9148790"},{"key":"ref26","first-page":"1291","article-title":"Updates-leak: Data set inference and reconstruction attacks in online learning","author":"salem","year":"2020","journal-title":"Proc 29th USENIX Secur Symp"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417880"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-023-08593-y"},{"key":"ref22","article-title":"User-level membership inference attack against metric embedding learning","author":"li","year":"2022","journal-title":"arXiv 2203 02077"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3446776"},{"key":"ref8","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"dwork","year":"2014","journal-title":"Found Trends Theor Comput Sci"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.29012\/jpc.v7i3.405"},{"key":"ref9","article-title":"Enhanced membership inference attacks against machine learning models","author":"ye","year":"2021","journal-title":"arXiv 2111 09679"},{"key":"ref4","article-title":"Subject granular differential privacy in federated learning","author":"marathe","year":"2022","journal-title":"arXiv 2206 03617"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref6","article-title":"A field guide to federated optimization","author":"wang","year":"2021","journal-title":"arXiv 2107 06917"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-91431-8_38"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9970396\/10262058.pdf?arnumber=10262058","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,30]],"date-time":"2023-10-30T18:53:59Z","timestamp":1698692039000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10262058\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":38,"URL":"https:\/\/doi.org\/10.1109\/tifs.2023.3318950","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2023]]}}}