{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T21:06:26Z","timestamp":1772658386794,"version":"3.50.1"},"reference-count":43,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T00:00:00Z","timestamp":1762905600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,12]],"date-time":"2025-11-12T00:00:00Z","timestamp":1762905600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,11,12]]},"DOI":"10.1109\/tps-isa67132.2025.00061","type":"proceedings-article","created":{"date-parts":[[2026,3,3]],"date-time":"2026-03-03T20:50:15Z","timestamp":1772571015000},"page":"509-516","source":"Crossref","is-referenced-by-count":0,"title":["Exploring Membership Inference Vulnerabilities in Clinical Large Language Models"],"prefix":"10.1109","author":[{"given":"Alexander","family":"Nemecek","sequence":"first","affiliation":[{"name":"Case Western Reserve University,Cleveland,Ohio,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zebin","family":"Yun","sequence":"additional","affiliation":[{"name":"Tel Aviv University,Tel Aviv,Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zahra","family":"Rahmani","sequence":"additional","affiliation":[{"name":"Case Western Reserve University,Cleveland,Ohio,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yaniv","family":"Harel","sequence":"additional","affiliation":[{"name":"Tel Aviv University,Tel Aviv,Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vipin","family":"Chaudhary","sequence":"additional","affiliation":[{"name":"Case Western Reserve University,Cleveland,Ohio,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mahmood","family":"Sharif","sequence":"additional","affiliation":[{"name":"Tel Aviv University,Tel Aviv,Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Erman","family":"Ayday","sequence":"additional","affiliation":[{"name":"Case Western Reserve University,Cleveland,Ohio,USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3649506"},{"key":"ref2","article-title":"Finetuned language models are zero-shot learners","author":"Wei","year":"2021","journal-title":"arXiv preprint"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.caeai.2024.100298"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3643795.3648379"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.52202\/068431-1800"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.574"},{"key":"ref7","article-title":"On the opportunities and risks of foundation models","volume-title":"ArXiv","author":"Bommasani","year":"2021"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3604237.3626869"},{"key":"ref9","article-title":"Generative ai and large language models for cyber security: All insights you need","author":"Ferrag","year":"2024","journal-title":"Available at SSRN 4853709"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1002\/hcs2.61"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-023-02448-8"},{"key":"ref12","article-title":"Clinicalgpt: large language models finetuned with diverse medical data and comprehensive evaluation","author":"Wang","year":"2023","journal-title":"arXiv preprint"},{"key":"ref13","article-title":"Meditron-70b: Scaling medical pretraining for large language models","author":"Chen","year":"2023","journal-title":"arXiv preprint"},{"key":"ref14","article-title":"Instruction tuning large language models to understand electronic health records","volume-title":"The Thirty-eight Conference on Neural Information Processing Systems Datasets and Benchmarks Track","author":"Wu","year":"2024"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.7150\/ijms.111780"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.2196\/53008"},{"issue":"1","key":"ref17","first-page":"1","article-title":"Balancing innovation and privacy: ethical challenges in ai-driven healthcare","volume":"4","author":"Shoghli","year":"2024","journal-title":"Journal of Reviews in Medical Sciences"},{"key":"ref18","first-page":"8075","article-title":"Generated data with fake privacy: Hidden dangers of fine-tuning large language models on generated data","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Akkus","year":"2025"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref21","article-title":"Membership infer-ence attack susceptibility of clinical language models","author":"Jagannatha","year":"2021","journal-title":"arXiv preprint"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2019.2897554"},{"key":"ref23","article-title":"Towards label-only membership inference attack against pretrained large language models","author":"He","year":"2025","journal-title":"USENIX Security"},{"key":"ref24","article-title":"Noisy neighbors: Efficient membership inference attacks against 11 ms","author":"Galli","year":"2024","journal-title":"arXiv preprint"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.emnlp-main.570"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref27","article-title":"Do membership inference attacks work on large language models?","volume-title":"arXiv preprint","author":"Duan","year":"2024"},{"key":"ref28","article-title":"Practical membership inference attacks against fine-tuned large language models via self-prompt calibration","volume-title":"arXiv preprint","author":"Fu","year":"2023"},{"key":"ref29","article-title":"Min-k%++: Improved baseline for pre-training data detection from large language models","volume-title":"The Thirteenth International Conference on Learning Representations","author":"Zhang","year":"2025"},{"key":"ref30","article-title":"Membership inference attack susceptibility of clinical language models","volume-title":"arXiv preprint","author":"Jagannatha","year":"2021"},{"key":"ref31","doi-asserted-by":"crossref","DOI":"10.18653\/v1\/2024.eacl-long.143","article-title":"Spuq: Perturbationbased uncertainty quantification for large language models","volume-title":"arXiv preprint","author":"Gao","year":"2024"},{"key":"ref32","article-title":"Quantifying perturbation impacts for large language models","volume-title":"arXiv preprint","author":"Rauba","year":"2024"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1038\/s41597-022-01899-x"},{"key":"ref34","article-title":"Clinicalbert: Modeling clinical notes and predicting hospital readmission","author":"Huang","year":"2019","journal-title":"arXiv preprint"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML64287.2025.00028"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1038\/ng.436"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1037\/e516712004-001"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref40","first-page":"5558","article-title":"White-box vs black-box: Bayes optimal strategies for membership inference","volume-title":"International Conference on Machine Learning","author":"Sablayrolles","year":"2019"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref42","year":"2023","journal-title":"Chatgpt-3.5: Large language model"},{"key":"ref43","doi-asserted-by":"crossref","first-page":"2140","DOI":"10.18653\/v1\/2021.findings-acl.188","article-title":"MiniLMv2: Multi-head self-attention relation distillation for compressing pretrained transformers","volume-title":"Findings of the Association for Computational Linguistics: ACL-IJCNLP 2021","author":"Wang","year":"2021"}],"event":{"name":"2025 IEEE 7th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)","location":"Pittsburgh, PA, USA","start":{"date-parts":[[2025,11,12]]},"end":{"date-parts":[[2025,11,14]]}},"container-title":["2025 IEEE 7th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11410113\/11410157\/11410329.pdf?arnumber=11410329","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T20:47:27Z","timestamp":1772657247000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11410329\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,12]]},"references-count":43,"URL":"https:\/\/doi.org\/10.1109\/tps-isa67132.2025.00061","relation":{},"subject":[],"published":{"date-parts":[[2025,11,12]]}}}