{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T05:50:37Z","timestamp":1780638637623,"version":"3.54.1"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFB3106400"],"award-info":[{"award-number":["2023YFB3106400"]}]},{"name":"National Key Research and Development Program of China","award":["2023QY1202"],"award-info":[{"award-number":["2023QY1202"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2336203"],"award-info":[{"award-number":["U2336203"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U1836210"],"award-info":[{"award-number":["U1836210"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772406"],"award-info":[{"award-number":["61772406"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key Research and Development Science and Technology of Hainan Province","award":["GHYF2022010"],"award-info":[{"award-number":["GHYF2022010"]}]},{"name":"Beijing Natural Science Foundation","award":["L242015"],"award-info":[{"award-number":["L242015"]}]},{"name":"Beijing Natural Science Foundation","award":["4242031"],"award-info":[{"award-number":["4242031"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3550070","type":"journal-article","created":{"date-parts":[[2025,3,11]],"date-time":"2025-03-11T17:33:04Z","timestamp":1741714384000},"page":"6592-6606","source":"Crossref","is-referenced-by-count":5,"title":["Comparing Different Membership Inference Attacks With a Comprehensive Benchmark"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7622-4690","authenticated-orcid":false,"given":"Jun","family":"Niu","sequence":"first","affiliation":[{"name":"School of Cyber Engineering and the School of Computer Science and Technology, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3741-9158","authenticated-orcid":false,"given":"Xiaoyan","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Telecommunications Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-7669-1350","authenticated-orcid":false,"given":"Moxuan","family":"Zeng","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Hainan University, Haikou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ge","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingyang","family":"Zhao","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5214-3176","authenticated-orcid":false,"given":"Chunhui","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Hainan University, Haikou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yangming","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Hainan University, Haikou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Suyu","family":"An","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Hainan University, Haikou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yangzhong","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Hainan University, Haikou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinghui","family":"Yue","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Yanshan University, Qinhuangdao, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhipeng","family":"He","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-4377-7076","authenticated-orcid":false,"given":"Weihao","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Cyberspace Security, Hainan University, Haikou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-0013-5894","authenticated-orcid":false,"given":"Kuo","family":"Shen","sequence":"additional","affiliation":[{"name":"Hangzhou Institute of Technology, Xidian University, Hangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5091-8464","authenticated-orcid":false,"given":"Peng","family":"Liu","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, State College, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3964-8034","authenticated-orcid":false,"given":"Lan","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Informatics, Computing and Cyber Systems, Northern Arizona University, Flagstaff, AZ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4251-1143","authenticated-orcid":false,"given":"Jianfeng","family":"Ma","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8306-7195","authenticated-orcid":false,"given":"Yuqing","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Engineering and the School of Computer Science and Technology, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref2","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018","journal-title":"arXiv:1810.04805"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2020.3039941"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref6","first-page":"2633","article-title":"Extracting training data from large language models","volume-title":"Proc. USENIX Secur.","author":"Carlini"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24293"},{"key":"ref12","first-page":"4525","article-title":"ML-doctor: Holistic risk assessment of inference attacks against machine learning models","volume-title":"Proc. USENIX Secur.","author":"Liu"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484756"},{"key":"ref14","first-page":"519","article-title":"Segmentations-leak: Membership inference attacks and defenses in semantic image segmentation","volume-title":"Proc. ECCV","author":"Yang"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3497772"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103201"},{"key":"ref17","article-title":"User-level membership inference attack against metric embedding learning","author":"Li","year":"2022","journal-title":"arXiv:2203.02077"},{"key":"ref18","first-page":"4543","article-title":"Inference attacks against graph neural networks","volume-title":"Proc. USENIX Secur.","author":"Zhang"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00028"},{"key":"ref20","first-page":"1964","article-title":"Label-only membership inference attacks","volume-title":"Proc. ICML","author":"Choquette-Choo"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxac080"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01015"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3501279"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484571"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1037\/e516712004-001"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00780"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0031"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00040"},{"issue":"2","key":"ref30","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"Proc. USENIX Secur. Symp.","volume":"1","author":"Song"},{"key":"ref31","article-title":"Enhanced membership inference attacks against machine learning models","author":"Ye","year":"2021","journal-title":"arXiv:2111.09679"},{"key":"ref32","article-title":"SHAPr: An efficient and versatile membership privacy risk metric for machine learning","author":"Duddu","year":"2021","journal-title":"arXiv:2112.02230"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref34","article-title":"On the importance of difficulty calibration in membership inference attacks","author":"Watson","year":"2021","journal-title":"arXiv:2111.08440"},{"key":"ref35","first-page":"723","article-title":"A kernel two-sample test","volume":"13","author":"Gretton","year":"2012","journal-title":"J. Mach. Learn. Res."},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/WACV57701.2024.00477"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2025.3550070"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3422337.3447836"},{"key":"ref39","first-page":"1","article-title":"Effective passive membership inference attacks in federated learning against overparameterized models","volume-title":"Proc. 11th Int. Conf. Learn. Represent.","author":"Li"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.jiixd.2024.02.001"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10919167.pdf?arnumber=10919167","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,4]],"date-time":"2025-07-04T04:46:44Z","timestamp":1751604404000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10919167\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":40,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3550070","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}