{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T04:11:38Z","timestamp":1751343098859,"version":"3.41.0"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62371070"],"award-info":[{"award-number":["62371070"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["2021XD-A01-1"],"award-info":[{"award-number":["2021XD-A01-1"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Beijing Natural Science Foundation","award":["L222043"],"award-info":[{"award-number":["L222043"]}]},{"name":"BUPT Excellent Ph.D. Students Foundation","award":["CX2023150"],"award-info":[{"award-number":["CX2023150"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62371070"],"award-info":[{"award-number":["62371070"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["2021XD-A01-1"],"award-info":[{"award-number":["2021XD-A01-1"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Beijing Natural Science Foundation","award":["L222043"],"award-info":[{"award-number":["L222043"]}]},{"name":"European Union\u2019s Horizon Europe Project CENTRIC","award":["101096379"],"award-info":[{"award-number":["101096379"]}]},{"name":"Open Fellowships of EPSRC","award":["EP\/W024101\/1"],"award-info":[{"award-number":["EP\/W024101\/1"]}]},{"name":"EPSRC Project","award":["EP\/X011852\/1"],"award-info":[{"award-number":["EP\/X011852\/1"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3578931","type":"journal-article","created":{"date-parts":[[2025,6,11]],"date-time":"2025-06-11T17:42:34Z","timestamp":1749663754000},"page":"6292-6307","source":"Crossref","is-referenced-by-count":0,"title":["On the Impact of Uncertainty and Calibration on Likelihood-Ratio Membership Inference Attacks"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9695-6880","authenticated-orcid":false,"given":"Meiyi","family":"Zhu","sequence":"first","affiliation":[{"name":"Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8892-4520","authenticated-orcid":false,"given":"Caili","family":"Guo","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4277-6857","authenticated-orcid":false,"given":"Chunyan","family":"Feng","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9898-3209","authenticated-orcid":false,"given":"Osvaldo","family":"Simeone","sequence":"additional","affiliation":[{"name":"Department of Engineering, King&#x2019;s Communications, Learning and Information Processing (KCLIP) Laboratory, King&#x2019;s College London, London, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref4","first-page":"1895","article-title":"Evaluating differentially private machine learning in practice","volume-title":"Proc. 28th USENIX Secur. Symp. (USENIX Secur.)","author":"Jayaraman"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23014"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-021-05946-3"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.2514\/1.28707"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref10","article-title":"Efficient membership inference attacks by Bayesian neural network","author":"Liu","year":"2025","journal-title":"arXiv:2312.03262"},{"key":"ref11","article-title":"ML-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"Salem","year":"2018","journal-title":"arXiv:1806.01246"},{"issue":"2","key":"ref12","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"Proc. USENIX Secur. Symp.","volume":"1","author":"Song"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0031"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560684"},{"key":"ref15","first-page":"20863","article-title":"Scalable membership inference attacks via quantile regression","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Bertran"},{"key":"ref16","article-title":"Membership inference attacks on DNNs using adversarial perturbations","author":"Ali","year":"2023","journal-title":"arXiv:2307.05193"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560675"},{"key":"ref18","article-title":"Low-cost high-power membership inference attacks","author":"Zarifzadeh","year":"2024","journal-title":"arXiv:2312.03262"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484575"},{"key":"ref20","first-page":"1964","article-title":"Label-only membership inference attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Choquette-Choo"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/b106715"},{"key":"ref22","article-title":"A gentle introduction to conformal prediction and distribution-free uncertainty quantification","author":"Angelopoulos","year":"2021","journal-title":"arXiv:2107.07511"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TMLCN.2023.3319282"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2019.2897554"},{"key":"ref25","article-title":"Data and model dependencies of membership inference attack","author":"Tonni","year":"2020","journal-title":"arXiv:2002.06856"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2023.02.058"},{"key":"ref27","article-title":"Fundamental limits of membership inference attacks on machine learning models","author":"Aubinais","year":"2023","journal-title":"arXiv:2310.13786"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0023"},{"key":"ref29","article-title":"Understanding membership inferences on well-generalized learning models","author":"Long","year":"2018","journal-title":"arXiv:1802.04889"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00038"},{"volume-title":"Information Theory From Coding to Learning","year":"2025","author":"Polyanskiy","key":"ref32"},{"key":"ref33","article-title":"Federated learning with nonvacuous generalisation bounds","author":"Jobic","year":"2023","journal-title":"arXiv:2310.11203"},{"key":"ref34","first-page":"1321","article-title":"On calibration of modern neural networks","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","author":"Guo"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1002\/0471722065"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.2307\/2335470"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-45528-0"},{"volume-title":"Deep Learning","year":"2016","author":"Goodfellow","key":"ref38"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00157"},{"key":"ref40","article-title":"Evaluating machine unlearning via epistemic uncertainty","author":"Becker","year":"2022","journal-title":"arXiv:2208.10836"},{"key":"ref41","article-title":"Randomized quantization is all you need for differential privacy in federated learning","author":"Youn","year":"2023","journal-title":"arXiv:2306.11913"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3036948"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17123"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT57864.2024.10619313"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1137\/0916069"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1002\/9781119995784.ch2"},{"volume-title":"Comparisons of Stochastic Matrices With Applications in Information Theory, Statistics, Economics and Population","year":"1998","author":"Cohen","key":"ref47"},{"key":"ref48","article-title":"Information-theoretic generalization bounds for deep neural networks","author":"He","year":"2024","journal-title":"arXiv:2404.03176"},{"key":"ref49","article-title":"On the effectiveness of regularization against membership inference attacks","author":"Kaya","year":"2020","journal-title":"arXiv:2006.05336"},{"key":"ref50","article-title":"Against membership inference attack: Pruning is all you need","author":"Wang","year":"2020","journal-title":"arXiv:2008.13578"},{"key":"ref51","article-title":"Automatic calibration for membership inference attack on large language models","author":"Zare Zade","year":"2025","journal-title":"arXiv:2505.03392"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2019.2930526"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i9.26289"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3174569"},{"key":"ref55","article-title":"Set-valued classification\u2014Overview via a unified framework","author":"Chzhen","year":"2021","journal-title":"arXiv:2102.12318"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-16239-8_8"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11030733.pdf?arnumber=11030733","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T17:37:30Z","timestamp":1751305050000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11030733\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3578931","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"type":"print","value":"1556-6013"},{"type":"electronic","value":"1556-6021"}],"subject":[],"published":{"date-parts":[[2025]]}}}