{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T11:09:07Z","timestamp":1777892947899,"version":"3.51.4"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2021,11,1]],"date-time":"2021-11-01T00:00:00Z","timestamp":1635724800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,11,1]],"date-time":"2021-11-01T00:00:00Z","timestamp":1635724800000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,11,1]],"date-time":"2021-11-01T00:00:00Z","timestamp":1635724800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,11,1]],"date-time":"2021-11-01T00:00:00Z","timestamp":1635724800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1564097"],"award-info":[{"award-number":["1564097"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1547102"],"award-info":[{"award-number":["1547102"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Georgia Tech IISP"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Serv. Comput."],"published-print":{"date-parts":[[2021,11,1]]},"DOI":"10.1109\/tsc.2019.2897554","type":"journal-article","created":{"date-parts":[[2019,2,5]],"date-time":"2019-02-05T19:34:51Z","timestamp":1549395291000},"page":"2073-2089","source":"Crossref","is-referenced-by-count":188,"title":["Demystifying Membership Inference Attacks in Machine Learning as a Service"],"prefix":"10.1109","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8274-645X","authenticated-orcid":false,"given":"Stacey","family":"Truex","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4138-3082","authenticated-orcid":false,"given":"Ling","family":"Liu","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7676-0167","authenticated-orcid":false,"given":"Mehmet Emre","family":"Gursoy","sequence":"additional","affiliation":[]},{"given":"Lei","family":"Yu","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9177-114X","authenticated-orcid":false,"given":"Wenqi","family":"Wei","sequence":"additional","affiliation":[]}],"member":"263","reference":[{"key":"ref39","article-title":"Adversarial examples in the physical world","author":"kurakin","year":"2016","journal-title":"arXiv preprint arXiv 1607 02533"},{"key":"ref38","article-title":"Efficient estimation of word representations in vector space","author":"mikolov","year":"2013"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2016.0045"},{"key":"ref32","article-title":"Transferability in machine learning: From phenomena to black-box attacks using adversarial samples","author":"papernot","year":"2016","journal-title":"arXiv preprint arXiv 1605 07761"},{"key":"ref31","article-title":"Practical black-box attacks against deep learning systems using adversarial examples","author":"papernot","year":"2016"},{"key":"ref30","article-title":"Intriguing properties of neural networks","author":"szegedy","year":"2013","journal-title":"arXiv preprint arXiv 1312 6199"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2205597"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6639344"},{"key":"ref35","first-page":"142","article-title":"Deep learning for autonomous vehicles","author":"kisa?anin","year":"2017","journal-title":"Proc IEEE 47th Int Symp Multiple-Valued Logic"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref28","article-title":"MNIST handwritten digit database","author":"lecun","year":"2010"},{"key":"ref27","article-title":"UCI machine learning repository","author":"dheeru","year":"2017"},{"key":"ref29","article-title":"Learning multiple layers of features from tiny images","author":"krizhevsky","year":"2009"},{"key":"ref2","author":"copeland","year":"2015","journal-title":"Microsoft Azure planning deploying and managing your data center in the cloud"},{"key":"ref1","article-title":"Amazon Machine Learning: Developer Guide","year":"2018"},{"key":"ref20","first-page":"2825","article-title":"Scikit-learn: Machine learning in Python","volume":"12","author":"pedregosa","year":"2011","journal-title":"J Mach Learn Res"},{"key":"ref22","first-page":"1","article-title":"Ensemble methods in machine learning","author":"dietterich","year":"2000","journal-title":"Proc Int Workshop Multiple Classifier Syst"},{"key":"ref21","year":"2010","journal-title":"Version 7 10 0 (R2010a)"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1023\/A:1010933404324"},{"key":"ref23","first-page":"882","article-title":"Improving committee diagnosis with resampling techniques","author":"parmanto","year":"1996","journal-title":"Proc Int Conf Neural Inf Process"},{"key":"ref26","year":"2017","journal-title":"Python A Dynamic Open Source Programming Language"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-59119-2_166"},{"key":"ref50","article-title":"The unintended consequences of overfitting: Training data inference attacks","author":"yeom","year":"2017","journal-title":"arXiv preprint arXiv 1709 01922"},{"key":"ref10","article-title":"The secret sharer: Measuring unintended neural network memorization & extracting secrets","author":"carlini","year":"2018","journal-title":"arXiv preprint arXiv 1802 08232"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1065167.1065184"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2013.43"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-79228-4_1"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2016-0043"},{"key":"ref15","article-title":"Efficient and private scoring of decision trees, support vector machines and logistic regression models based on pre-computation","author":"de cock","year":"2017","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1017\/CBO9781107337756"},{"key":"ref17","article-title":"Volume shadow copy service","author":"sankaran","year":"2004","journal-title":"Power Solutions"},{"key":"ref18","article-title":"Semi-supervised learning literature survey","author":"zhu","year":"2005"},{"key":"ref19","article-title":"Online active learning methods for fast label-efficient spam filtering","author":"sculley","year":"2007","journal-title":"Proc 4th Conf Email Anti-Spam"},{"key":"ref4","article-title":"Cloud Machine Learning Engine Documentation","year":"2018"},{"key":"ref3","article-title":"IBM Data Science and Machine Learning","year":"2018"},{"key":"ref6","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"dwork","year":"2014","journal-title":"Foundations and Trends\ufffd in Theoretical Computer Science"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4471-5601-7_1"},{"key":"ref8","article-title":"Understanding membership inferences on well-generalized learning models","author":"long","year":"2018","journal-title":"arXiv preprint arXiv 1802 04102"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref49","article-title":"Adversarial examples: Attacks and defenses for deep learning","author":"yuan","year":"2017","journal-title":"arXiv preprint arXiv 1712 07107"},{"key":"ref9","article-title":"LOGAN: Evaluating privacy leakage of generative models using generative adversarial networks","author":"hayes","year":"2017","journal-title":"arXiv preprint arXiv 1705 07663"},{"key":"ref46","article-title":"Knock knock, who&#x2019;s there? Membership inference on aggregate location data","author":"pyrgelis","year":"2017","journal-title":"arXiv preprint arXiv 1708 04782"},{"key":"ref45","first-page":"61","article-title":"Membership inference attack against differentially private deep learning model","volume":"11","author":"rahman","year":"2018","journal-title":"Trans Data Privacy"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1002\/9781118960608.gbm00570"},{"key":"ref42","article-title":"Towards measuring membership privacy","author":"long","year":"2017","journal-title":"arXiv preprint arXiv 1712 09136"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.23876\/j.krcp.2017.36.1.3"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"ref43","first-page":"33","article-title":"Differential privacy under fire","author":"haeberlen","year":"2011","journal-title":"Proc Usenix Secur Symp"}],"container-title":["IEEE Transactions on Services Computing"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/4629386\/9642441\/8634878-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/4629386\/9642441\/08634878.pdf?arnumber=8634878","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,5,10]],"date-time":"2022-05-10T14:52:50Z","timestamp":1652194370000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8634878\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,1]]},"references-count":50,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tsc.2019.2897554","relation":{},"ISSN":["1939-1374","2372-0204"],"issn-type":[{"value":"1939-1374","type":"electronic"},{"value":"2372-0204","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,1]]}}}