{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T15:59:23Z","timestamp":1784995163127,"version":"3.55.0"},"reference-count":246,"publisher":"Association for Computing Machinery (ACM)","issue":"11s","license":[{"start":{"date-parts":[[2022,1,31]],"date-time":"2022-01-31T00:00:00Z","timestamp":1643587200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"ARC DECRA","award":["DE210101458"],"award-info":[{"award-number":["DE210101458"]}]},{"DOI":"10.13039\/100015539","name":"Australian Government","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100015539","id-type":"DOI","asserted-by":"crossref"}]},{"name":"NSF","award":["III-1763325, III-1909323, III-2106758, SaTC-1930941"],"award-info":[{"award-number":["III-1763325, III-1909323, III-2106758, SaTC-1930941"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2022,1,31]]},"abstract":"<jats:p>Machine learning (ML) models have been widely applied to various applications, including image classification, text generation, audio recognition, and graph data analysis. However, recent studies have shown that ML models are vulnerable to membership inference attacks (MIAs), which aim to infer whether a data record was used to train a target model or not. MIAs on ML models can directly lead to a privacy breach. For example, via identifying the fact that a clinical record that has been used to train a model associated with a certain disease, an attacker can infer that the owner of the clinical record has the disease with a high chance. In recent years, MIAs have been shown to be effective on various ML models, e.g., classification models and generative models. Meanwhile, many defense methods have been proposed to mitigate MIAs. Although MIAs on ML models form a newly emerging and rapidly growing research area, there has been no systematic survey on this topic yet. In this article, we conduct the first comprehensive survey on membership inference attacks and defenses. We provide the taxonomies for both attacks and defenses, based on their characterizations, and discuss their pros and cons. Based on the limitations and gaps identified in this survey, we point out several promising future research directions to inspire the researchers who wish to follow this area. This survey not only serves as a reference for the research community but also provides a clear description for researchers outside this research domain. To further help the researchers, we have created an online resource repository, which we will keep updated with future relevant work. Interested readers can find the repository at https:\/\/github.com\/HongshengHu\/membership-inference-machine-learning-literature.<\/jats:p>","DOI":"10.1145\/3523273","type":"journal-article","created":{"date-parts":[[2022,3,23]],"date-time":"2022-03-23T14:40:24Z","timestamp":1648046424000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":453,"title":["Membership Inference Attacks on Machine Learning: A Survey"],"prefix":"10.1145","volume":"54","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4455-4227","authenticated-orcid":false,"given":"Hongsheng","family":"Hu","sequence":"first","affiliation":[{"name":"The University of Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zoran","family":"Salcic","sequence":"additional","affiliation":[{"name":"The University of Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lichao","family":"Sun","sequence":"additional","affiliation":[{"name":"Lehigh University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Gillian","family":"Dobbie","sequence":"additional","affiliation":[{"name":"The University of Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Philip S.","family":"Yu","sequence":"additional","affiliation":[{"name":"University of Illinois at Chicago, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuyun","family":"Zhang","sequence":"additional","affiliation":[{"name":"Macquarie University, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,9,9]]},"reference":[{"key":"e_1_3_3_2_2","first-page":"308","volume-title":"CCS","author":"Abadi Martin","year":"2016","unstructured":"Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In CCS. ACM, 308\u2013318."},{"key":"e_1_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3450963"},{"key":"e_1_3_3_4_2","article-title":"Invariant risk minimization","author":"Arjovsky Martin","year":"2019","unstructured":"Martin Arjovsky, L\u00e9on Bottou, Ishaan Gulrajani, and David Lopez-Paz. 2019. Invariant risk minimization. arXiv preprint arXiv:1907.02893 (2019).","journal-title":"arXiv preprint arXiv:1907.02893"},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"e_1_3_3_6_2","first-page":"2654","volume-title":"NeurIPS","author":"Ba Lei Jimmy","year":"2014","unstructured":"Lei Jimmy Ba and Rich Caruana. 2014. Do deep nets really need to be deep? In NeurIPS. 2654\u20132662."},{"key":"e_1_3_3_7_2","first-page":"1943","volume-title":"CCS","author":"Backes Michael","year":"2017","unstructured":"Michael Backes, Mathias Humbert, Jun Pang, and Yang Zhang. 2017. walk2friends: Inferring social links from mobility profiles. In CCS. ACM, 1943\u20131957."},{"key":"e_1_3_3_8_2","volume-title":"ICML Workshop","author":"Bagmar Aadesh Mahavir","year":"2021","unstructured":"Aadesh Mahavir Bagmar, Shishira Maiya, Shruti Bidwalkar, and Amol Deshpande. 2021. Membership inference attacks on lottery ticket networks. In ICML Workshop. PMLR."},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1161\/CIRCOUTCOMES.118.005122"},{"key":"e_1_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3448250"},{"key":"e_1_3_3_11_2","article-title":"Quantifying membership inference vulnerability via generalization gap and other model metrics","author":"Bentley Jason W.","year":"2020","unstructured":"Jason W. Bentley, Daniel Gibney, Gary Hoppenworth, and Sumit Kumar Jha. 2020. Quantifying membership inference vulnerability via generalization gap and other model metrics. arXiv preprint arXiv:2009.05669 (2020).","journal-title":"arXiv preprint arXiv:2009.05669"},{"key":"e_1_3_3_12_2","first-page":"22","volume-title":"DBSec","author":"Bernau Daniel","year":"2021","unstructured":"Daniel Bernau, Jonas Robl, Philip W. Grassal, Steffen Schneider, and Florian Kerschbaum. 2021. Comparing local and central differential privacy using membership inference attacks. In DBSec. Springer, 22\u201342."},{"issue":"9","key":"e_1_3_3_13_2","article-title":"Pattern recognition","volume":"128","author":"Bishop Christopher M.","year":"2006","unstructured":"Christopher M. Bishop. 2006. Pattern recognition. Mach. Learn. 128, 9 (2006).","journal-title":"Mach. Learn."},{"key":"e_1_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-6401"},{"key":"e_1_3_3_15_2","first-page":"141","volume-title":"S&P","author":"Bourtoule Lucas","year":"2021","unstructured":"Lucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia, Adelin Travers, Baiwu Zhang, David Lie, and Nicolas Papernot. 2021. Machine unlearning. In S&P. IEEE, 141\u2013159."},{"key":"e_1_3_3_16_2","first-page":"635","volume-title":"TCC","author":"Bun Mark","year":"2016","unstructured":"Mark Bun and Thomas Steinke. 2016. Concentrated differential privacy: Simplifications, extensions, and lower bounds. In TCC. Springer, 635\u2013658."},{"key":"e_1_3_3_17_2","first-page":"267","volume-title":"USENIX Security","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Chang Liu, \u00dalfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The secret sharer: Evaluating and testing unintended memorization in neural networks. In USENIX Security. USENIX Association, 267\u2013284."},{"key":"e_1_3_3_18_2","article-title":"Extracting training data from large language models","author":"Carlini Nicholas","year":"2020","unstructured":"Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et\u00a0al. 2020. Extracting training data from large language models. arXiv preprint arXiv:2012.07805 (2020).","journal-title":"arXiv preprint arXiv:2012.07805"},{"key":"e_1_3_3_19_2","article-title":"Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer","author":"Chang Hongyan","year":"2019","unstructured":"Hongyan Chang, Virat Shejwalkar, Reza Shokri, and Amir Houmansadr. 2019. Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer. arXiv preprint arXiv:1912.11279 (2019).","journal-title":"arXiv preprint arXiv:1912.11279"},{"key":"e_1_3_3_20_2","volume-title":"EuroS&P","author":"Chang Hongyan","year":"2021","unstructured":"Hongyan Chang and Reza Shokri. 2021. On the privacy risks of algorithmic fairness. In EuroS&P. IEEE."},{"key":"e_1_3_3_21_2","article-title":"A comprehensive analysis of information leakage in deep transfer learning","author":"Chen Cen","year":"2020","unstructured":"Cen Chen, Bingzhe Wu, Minghui Qiu, Li Wang, and Jun Zhou. 2020. A comprehensive analysis of information leakage in deep transfer learning. arXiv preprint arXiv:2009.01989 (2020).","journal-title":"arXiv preprint arXiv:2009.01989"},{"key":"e_1_3_3_22_2","doi-asserted-by":"crossref","first-page":"343","DOI":"10.1145\/3372297.3417238","volume-title":"CCS","author":"Chen Dingfan","year":"2020","unstructured":"Dingfan Chen, Ning Yu, Yang Zhang, and Mario Fritz. 2020. GAN-leaks: A taxonomy of membership inference attacks against generative models. In CCS. ACM, 343\u2013362."},{"key":"e_1_3_3_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3046648"},{"key":"e_1_3_3_24_2","doi-asserted-by":"crossref","first-page":"127","DOI":"10.1145\/3447548.3467445","volume-title":"KDD","author":"Chen Junjie","year":"2021","unstructured":"Junjie Chen, Wendy Hui Wang, Hongchang Gao, and Xinghua Shi. 2021. PAR-GAN: Improving the generalization of generative adversarial networks against membership inference attacks. In KDD. ACM, 127\u2013137."},{"key":"e_1_3_3_25_2","first-page":"26","volume-title":"Biocomputing","author":"Chen Junjie","year":"2020","unstructured":"Junjie Chen, Wendy Hui Wang, and Xinghua Shi. 2020. Differential privacy protection against membership inference attack on machine learning for genomic data. In Biocomputing. World Scientific, 26\u201337."},{"key":"e_1_3_3_26_2","first-page":"1","volume-title":"ICCCN","author":"Chen Jiale","year":"2020","unstructured":"Jiale Chen, Jiale Zhang, Yanchao Zhao, Hao Han, Kun Zhu, and Bing Chen. 2020. Beyond model-level membership privacy leakage: An adversarial approach in federated learning. In ICCCN. IEEE, 1\u20139."},{"key":"e_1_3_3_27_2","article-title":"When machine unlearning jeopardizes privacy","author":"Chen Min","year":"2020","unstructured":"Min Chen, Zhikun Zhang, Tianhao Wang, Michael Backes, Mathias Humbert, and Yang Zhang. 2020. When machine unlearning jeopardizes privacy. arXiv preprint arXiv:2005.02205 (2020).","journal-title":"arXiv preprint arXiv:2005.02205"},{"key":"e_1_3_3_28_2","article-title":"Differentially private data generative models","author":"Chen Qingrong","year":"2018","unstructured":"Qingrong Chen, Chong Xiang, Minhui Xue, Bo Li, Nikita Borisov, Dali Kaarfar, and Haojin Zhu. 2018. Differentially private data generative models. arXiv preprint arXiv:1812.02274 (2018).","journal-title":"arXiv preprint arXiv:1812.02274"},{"key":"e_1_3_3_29_2","article-title":"Improved baselines with momentum contrastive learning","author":"Chen Xinlei","year":"2020","unstructured":"Xinlei Chen, Haoqi Fan, Ross Girshick, and Kaiming He. 2020. Improved baselines with momentum contrastive learning. arXiv preprint arXiv:2003.04297 (2020).","journal-title":"arXiv preprint arXiv:2003.04297"},{"key":"e_1_3_3_30_2","first-page":"286","volume-title":"MLHC","author":"Choi Edward","year":"2017","unstructured":"Edward Choi, Siddharth Biswal, Bradley Malin, Jon Duke, Walter F. Stewart, and Jimeng Sun. 2017. Generating multi-label discrete patient records using generative adversarial networks. In MLHC. PMLR, 286\u2013305."},{"key":"e_1_3_3_31_2","first-page":"1964","volume-title":"ICML","author":"Choquette-Choo Christopher A.","year":"2021","unstructured":"Christopher A. Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In ICML. PMLR, 1964\u20131974."},{"key":"e_1_3_3_32_2","volume-title":"CVPR","author":"Cordts Marius","year":"2016","unstructured":"Marius Cordts, Mohamed Omran, Sebastian Ramos, Timo Rehfeld, Markus Enzweiler, Rodrigo Benenson, Uwe Franke, Stefan Roth, and Bernt Schiele. 2016. The Cityscapes dataset for semantic urban scene understanding. In CVPR. IEEE."},{"key":"e_1_3_3_33_2","first-page":"2893","volume-title":"NeurIPS","author":"Crowley Elliot J.","year":"2018","unstructured":"Elliot J. Crowley, Gavin Gray, and Amos Storkey. 2018. Moonshine: Distilling with cheap convolutions. In NeurIPS. Curran Associates Inc., 2893\u20132903."},{"key":"e_1_3_3_34_2","first-page":"896","volume-title":"WWW","author":"Dadoun Amine","year":"2019","unstructured":"Amine Dadoun, Rapha\u00ebl Troncy, Olivier Ratier, and Riccardo Petitti. 2019. Location embeddings for next trip recommendation. In WWW. ACM, 896\u2013903."},{"key":"e_1_3_3_35_2","first-page":"76","volume-title":"CMCL","author":"Danescu-Niculescu-Mizil Cristian","year":"2011","unstructured":"Cristian Danescu-Niculescu-Mizil and Lillian Lee. 2011. Chameleons in imagined conversations: A new approach to understanding coordination of linguistic style in dialogs. In CMCL. ACL, 76\u201387."},{"key":"e_1_3_3_36_2","article-title":"An overview of privacy in machine learning","author":"Cristofaro Emiliano De","year":"2020","unstructured":"Emiliano De Cristofaro. 2020. An overview of privacy in machine learning. arXiv preprint arXiv:2005.08679 (2020).","journal-title":"arXiv preprint arXiv:2005.08679"},{"key":"e_1_3_3_37_2","first-page":"248","volume-title":"CVPR","author":"Deng Jia","year":"2009","unstructured":"Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009. ImageNet: A large-scale hierarchical image database. In CVPR. IEEE, 248\u2013255."},{"key":"e_1_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0140-6736(20)30792-3"},{"key":"e_1_3_3_39_2","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin Jacob","year":"2018","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2018. BERT: Pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018).","journal-title":"arXiv preprint arXiv:1810.04805"},{"key":"e_1_3_3_40_2","volume-title":"ICLR","author":"Diao Enmao","year":"2020","unstructured":"Enmao Diao, Jie Ding, and Vahid Tarokh. 2020. HeteroFL: Computation and communication efficient federated learning for heterogeneous clients. In ICLR. Retrieved from OpenReview.net."},{"key":"e_1_3_3_41_2","unstructured":"Dheeru Dua and Casey Graff. 2017. UCI Machine Learning Repository. Retrieved from http:\/\/archive.ics.uci.edu\/ml."},{"key":"e_1_3_3_42_2","volume-title":"NuerIPS Workshop","author":"Duddu Vasisht","year":"2020","unstructured":"Vasisht Duddu, Antoine Boutet, and Virat Shejwalkar. 2020. GECKO: Reconciling privacy, accuracy and efficiency in embedded deep learning. In NuerIPS Workshop."},{"key":"e_1_3_3_43_2","first-page":"1","volume-title":"EAI MobiQuitous","author":"Duddu Vasisht","year":"2020","unstructured":"Vasisht Duddu, Antoine Boutet, and Virat Shejwalkar. 2020. Quantifying privacy leakage in graph embedding. In EAI MobiQuitous. 1\u201311."},{"key":"e_1_3_3_44_2","first-page":"1","volume-title":"TAMC","author":"Dwork Cynthia","year":"2008","unstructured":"Cynthia Dwork. 2008. Differential privacy: A survey of results. In TAMC. Springer, 1\u201319."},{"key":"e_1_3_3_45_2","first-page":"265","volume-title":"TCC","author":"Dwork Cynthia","year":"2006","unstructured":"Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006. Calibrating noise to sensitivity in private data analysis. In TCC. Springer, 265\u2013284."},{"key":"e_1_3_3_46_2","article-title":"Modelling and quantifying membership information leakage in machine learning","author":"Farokhi Farhad","year":"2020","unstructured":"Farhad Farokhi and Mohamed Ali Kaafar. 2020. Modelling and quantifying membership information leakage in machine learning. arXiv preprint arXiv:2001.10648 (2020).","journal-title":"arXiv preprint arXiv:2001.10648"},{"key":"e_1_3_3_47_2","first-page":"267","volume-title":"Annales scientifiques de l\u2019\u00c9cole Normale Sup\u00e9rieure","author":"Fortet Robert","year":"1953","unstructured":"Robert Fortet and Edith Mourier. 1953. Convergence de la r\u00e9partition empirique vers la r\u00e9partition th\u00e9orique. In Annales scientifiques de l\u2019\u00c9cole Normale Sup\u00e9rieure, Vol. 70. 267\u2013285."},{"key":"e_1_3_3_48_2","first-page":"1322","volume-title":"CCS","author":"Fredrikson Matt","year":"2015","unstructured":"Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In CCS. ACM, 1322\u20131333."},{"key":"e_1_3_3_49_2","volume-title":"USENIX Security","author":"Fredrikson Matthew","year":"2014","unstructured":"Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart. 2014. Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing. In USENIX Security. USENIX Association."},{"key":"e_1_3_3_50_2","first-page":"619","volume-title":"CCS","author":"Ganju Karan","year":"2018","unstructured":"Karan Ganju, Qi Wang, Wei Yang, Carl A. Gunter, and Nikita Borisov. 2018. Property inference attacks on fully connected neural networks using permutation invariant representations. In CCS. ACM, 619\u2013633."},{"key":"e_1_3_3_51_2","article-title":"Differentially private federated learning: A client level perspective","author":"Geyer Robin C.","year":"2017","unstructured":"Robin C. Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557 (2017).","journal-title":"arXiv preprint arXiv:1712.07557"},{"key":"e_1_3_3_52_2","doi-asserted-by":"publisher","DOI":"10.5555\/3086952"},{"key":"e_1_3_3_53_2","volume-title":"NeurIPS","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron C. Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In NeurIPS."},{"key":"e_1_3_3_54_2","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014).","journal-title":"arXiv preprint arXiv:1412.6572"},{"key":"e_1_3_3_55_2","first-page":"4696","volume-title":"ICPR","author":"Grosse Kathrin","year":"2021","unstructured":"Kathrin Grosse, Michael T. Smith, and Michael Backes. 2021. Killing four birds with one Gaussian process: The relation between different test-time attacks. In ICPR. IEEE, 4696\u20134703."},{"key":"e_1_3_3_56_2","doi-asserted-by":"crossref","first-page":"855","DOI":"10.1145\/2939672.2939754","volume-title":"KDD","author":"Grover Aditya","year":"2016","unstructured":"Aditya Grover and Jure Leskovec. 2016. node2vec: Scalable feature learning for networks. In KDD. ACM, 855\u2013864."},{"key":"e_1_3_3_57_2","first-page":"5769","volume-title":"NeurIPS","author":"Gulrajani Ishaan","year":"2017","unstructured":"Ishaan Gulrajani, Faruk Ahmed, Mart\u00edn Arjovsky, Vincent Dumoulin, and Aaron C. Courville. 2017. Improved training of Wasserstein GANs. In NeurIPS. 5769\u20135779."},{"key":"e_1_3_3_58_2","first-page":"228","volume-title":"MIDL","author":"Gupta Umang","year":"2021","unstructured":"Umang Gupta, Dimitris Stripelis, Pradeep K. Lam, Paul Thompson, Jose Luis Ambite, and Greg Ver Steeg. 2021. Membership inference attacks on deep regression models for neuroimaging. In MIDL, Vol. 143. PMLR, 228\u2013251."},{"key":"e_1_3_3_59_2","first-page":"3300","volume-title":"CVPR","author":"Hanzlik Lucjan","year":"2021","unstructured":"Lucjan Hanzlik, Yang Zhang, Kathrin Grosse, Ahmed Salem, Maximilian Augustin, Michael Backes, and Mario Fritz. 2021. MLcapsule: Guarded offline deployment of machine learning as a service. In CVPR. IEEE, 3300\u20133309."},{"key":"e_1_3_3_60_2","first-page":"1225","volume-title":"ICML","author":"Hardt Moritz","year":"2016","unstructured":"Moritz Hardt, Ben Recht, and Yoram Singer. 2016. Train faster, generalize better: Stability of stochastic gradient descent. In ICML. PMLR, 1225\u20131234."},{"key":"e_1_3_3_61_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0008"},{"key":"e_1_3_3_62_2","first-page":"9729","volume-title":"CVPR","author":"He Kaiming","year":"2020","unstructured":"Kaiming He, Haoqi Fan, Yuxin Wu, Saining Xie, and Ross Girshick. 2020. Momentum contrast for unsupervised visual representation learning. In CVPR. IEEE, 9729\u20139738."},{"key":"e_1_3_3_63_2","first-page":"770","volume-title":"CVPR","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep residual learning for image recognition. In CVPR. IEEE, 770\u2013778."},{"key":"e_1_3_3_64_2","first-page":"173","volume-title":"WWW","author":"He Xiangnan","year":"2017","unstructured":"Xiangnan He, Lizi Liao, Hanwang Zhang, Liqiang Nie, Xia Hu, and Tat-Seng Chua. 2017. Neural collaborative filtering. In WWW. ACM, 173\u2013182."},{"key":"e_1_3_3_65_2","article-title":"Node-level membership inference attacks against graph neural networks","author":"He Xinlei","year":"2021","unstructured":"Xinlei He, Rui Wen, Yixin Wu, Michael Backes, Yun Shen, and Yang Zhang. 2021. Node-level membership inference attacks against graph neural networks. arXiv preprint arXiv:2102.05429 (2021).","journal-title":"arXiv preprint arXiv:2102.05429"},{"key":"e_1_3_3_66_2","first-page":"519","volume-title":"ECCV","author":"He Yang","year":"2020","unstructured":"Yang He, Shadi Rahimian, Bernt Schiele, and Mario Fritz. 2020. Segmentations-leak: Membership inference attacks and defenses in semantic image segmentation. In ECCV. Springer, 519\u2013535."},{"key":"e_1_3_3_67_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0067"},{"key":"e_1_3_3_68_2","unstructured":"Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. Retrieved from https:\/\/arxiv.org\/abs\/1503.02531."},{"key":"e_1_3_3_69_2","doi-asserted-by":"publisher","DOI":"10.7551\/mitpress\/7011.001.0001"},{"key":"e_1_3_3_70_2","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00299"},{"key":"e_1_3_3_71_2","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pgen.1000167"},{"key":"e_1_3_3_72_2","article-title":"Meta-learning in neural networks: A survey","author":"Hospedales Timothy","year":"2020","unstructured":"Timothy Hospedales, Antreas Antoniou, Paul Micaelli, and Amos Storkey. 2020. Meta-learning in neural networks: A survey. arXiv preprint arXiv:2004.05439 (2020).","journal-title":"arXiv preprint arXiv:2004.05439"},{"key":"e_1_3_3_73_2","first-page":"1","volume-title":"IWQoS","author":"Hou Jiahui","year":"2019","unstructured":"Jiahui Hou, Jianwei Qian, Yu Wang, Xiang-Yang Li, Haohua Du, and Linlin Chen. 2019. ML defense: Against prediction API threats in cloud-based machine learning service. In IWQoS. ACM, 1\u201310."},{"key":"e_1_3_3_74_2","first-page":"1","volume-title":"IJCNN","author":"Hu Hongsheng","year":"2021","unstructured":"Hongsheng Hu, Zoran Salcic, Gillian Dobbie, Yi Chen, and Xuyun Zhang. 2021. EAR: An enhanced adversarial regularization approach against membership inference attacks. In IJCNN. IEEE, 1\u20138."},{"key":"e_1_3_3_75_2","article-title":"Source inference attacks in federated learning","author":"Hu Hongsheng","year":"2021","unstructured":"Hongsheng Hu, Zoran Salcic, Lichao Sun, Gillian Dobbie, and Xuyun Zhang. 2021. Source inference attacks in federated learning. arXiv preprint arXiv:2109.05659 (2021).","journal-title":"arXiv preprint arXiv:2109.05659"},{"key":"e_1_3_3_76_2","volume-title":"Workshop on Faces in \u201cReal-Life\u201d Images: Detection, Alignment, and Recognition","author":"Huang Gary B.","year":"2008","unstructured":"Gary B. Huang, Marwan Mattar, Tamara Berg, and Eric Learned-Miller. 2008. Labeled faces in the wild: A database for studying face recognition in unconstrained environments. In Workshop on Faces in \u201cReal-Life\u201d Images: Detection, Alignment, and Recognition."},{"key":"e_1_3_3_77_2","volume-title":"NDSS","author":"Hui Bo","year":"2021","unstructured":"Bo Hui, Yuchen Yang, Haolin Yuan, Philippe Burlina, Neil Zhenqiang Gong, and Yinzhi Cao. 2021. Practical blind membership inference attack via differential comparisons. In NDSS. Internet Society."},{"key":"e_1_3_3_78_2","article-title":"Differentially private learning does not bound membership inference","author":"Humphries Thomas","year":"2020","unstructured":"Thomas Humphries, Matthew Rafuse, Lindsey Tulloch, Simon Oya, Ian Goldberg, Urs Hengartner, and Florian Kerschbaum. 2020. Differentially private learning does not bound membership inference. arXiv preprint arXiv:2010.12112 (2020).","journal-title":"arXiv preprint arXiv:2010.12112"},{"key":"e_1_3_3_79_2","first-page":"1","volume-title":"CMI","author":"Irolla Paul","year":"2019","unstructured":"Paul Irolla and Gr\u00e9gory Ch\u00e2tel. 2019. Demystifying the membership inference attack. In CMI. IEEE, 1\u20137."},{"key":"e_1_3_3_80_2","article-title":"Membership inference attack susceptibility of clinical language models","author":"Jagannatha Abhyuday","year":"2021","unstructured":"Abhyuday Jagannatha, Bhanu Pratap Singh Rawat, and Hong Yu. 2021. Membership inference attack susceptibility of clinical language models. arXiv preprint arXiv:2104.08305 (2021).","journal-title":"arXiv preprint arXiv:2104.08305"},{"key":"e_1_3_3_81_2","first-page":"22205","volume-title":"NeurIPS","author":"Jagielski Matthew","year":"2020","unstructured":"Matthew Jagielski, Jonathan Ullman, and Alina Oprea. 2020. Auditing differentially private machine learning: How private is private SGD? In NeurIPS. 22205\u201322216."},{"key":"e_1_3_3_82_2","doi-asserted-by":"publisher","DOI":"10.4103\/2153-3539.186902"},{"key":"e_1_3_3_83_2","first-page":"1895","volume-title":"USENIX Security","author":"Jayaraman Bargav","year":"2019","unstructured":"Bargav Jayaraman and David Evans. 2019. Evaluating differentially private machine learning in practice. In USENIX Security. USENIX Association, 1895\u20131912."},{"key":"e_1_3_3_84_2","article-title":"Revisiting membership inference under realistic assumptions","author":"Jayaraman Bargav","year":"2020","unstructured":"Bargav Jayaraman, Lingxiao Wang, Katherine Knipmeyer, Quanquan Gu, and David Evans. 2020. Revisiting membership inference under realistic assumptions. arXiv preprint arXiv:2005.10881 (2020).","journal-title":"arXiv preprint arXiv:2005.10881"},{"key":"e_1_3_3_85_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2020.3039941"},{"key":"e_1_3_3_86_2","article-title":"An extension of Fano\u2019s inequality for characterizing model susceptibility to membership inference attacks","author":"Jha Sumit Kumar","year":"2020","unstructured":"Sumit Kumar Jha, Susmit Jha, Rickard Ewetz, Sunny Raj, Alvaro Velasquez, Laura L. Pullum, and Ananthram Swami. 2020. An extension of Fano\u2019s inequality for characterizing model susceptibility to membership inference attacks. arXiv preprint arXiv:2009.08097 (2020).","journal-title":"arXiv preprint arXiv:2009.08097"},{"key":"e_1_3_3_87_2","first-page":"259","volume-title":"CCS","author":"Jia Jinyuan","year":"2019","unstructured":"Jinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang, and Neil Zhenqiang Gong. 2019. MemGuard: Defending against black-box membership inference attacks via adversarial examples. In CCS. ACM, 259\u2013274."},{"key":"e_1_3_3_88_2","doi-asserted-by":"publisher","DOI":"10.1038\/sdata.2016.35"},{"key":"e_1_3_3_89_2","unstructured":"Kaggle. 2014. Acquire Valued Shoppers Challenge. Retrieved from https:\/\/www.kaggle.com\/c\/acquire-valued-shoppers-challenge\/data."},{"key":"e_1_3_3_90_2","unstructured":"Kaggle. 2015. Diabetic Retinopathy Detection. Retrieved from https:\/\/www.kaggle.com\/c\/diabetic-retinopathy-detection#references."},{"key":"e_1_3_3_91_2","volume-title":"KDD","author":"Kannan Anjuli","year":"2016","unstructured":"Anjuli Kannan, Karol Kurach, Sujith Ravi, Tobias Kaufmann, Andrew Tomkins, Balint Miklos, Greg Corrado, Laszlo Lukacs, Marina Ganea, Peter Young, et\u00a0al. 2016. Smart reply: Automated response suggestion for email. In KDD. ACM."},{"key":"e_1_3_3_92_2","article-title":"Progressive growing of GANs for improved quality, stability, and variation","author":"Karras Tero","year":"2017","unstructured":"Tero Karras, Timo Aila, Samuli Laine, and Jaakko Lehtinen. 2017. Progressive growing of GANs for improved quality, stability, and variation. arXiv preprint arXiv:1710.10196 (2017).","journal-title":"arXiv preprint arXiv:1710.10196"},{"key":"e_1_3_3_93_2","doi-asserted-by":"publisher","DOI":"10.1038\/srep27988"},{"key":"e_1_3_3_94_2","first-page":"5345","volume-title":"ICML","author":"Kaya Yigitcan","year":"2021","unstructured":"Yigitcan Kaya and Tudor Dumitras. 2021. When does data augmentation help with membership inference attacks? In ICML. PMLR, 5345\u20135355."},{"key":"e_1_3_3_95_2","article-title":"On the effectiveness of regularization against membership inference attacks","author":"Kaya Yigitcan","year":"2020","unstructured":"Yigitcan Kaya, Sanghyun Hong, and Tudor Dumitras. 2020. On the effectiveness of regularization against membership inference attacks. arXiv preprint arXiv:2006.05336 (2020).","journal-title":"arXiv preprint arXiv:2006.05336"},{"key":"e_1_3_3_96_2","article-title":"Auto-encoding variational Bayes","author":"Kingma Diederik P.","year":"2013","unstructured":"Diederik P. Kingma and Max Welling. 2013. Auto-encoding variational Bayes. arXiv preprint arXiv:1312.6114 (2013).","journal-title":"arXiv preprint arXiv:1312.6114"},{"key":"e_1_3_3_97_2","article-title":"Semi-supervised classification with graph convolutional networks","author":"Kipf Thomas N.","year":"2016","unstructured":"Thomas N. Kipf and Max Welling. 2016. Semi-supervised classification with graph convolutional networks. arXiv preprint arXiv:1609.02907 (2016).","journal-title":"arXiv preprint arXiv:1609.02907"},{"key":"e_1_3_3_98_2","first-page":"273","volume-title":"TSD","author":"Klakow Dietrich","year":"2020","unstructured":"Dietrich Klakow. 2020. Investigating the impact of pre-trained word embeddings on memorization in neural networks. In TSD. Springer, 273\u2013281."},{"key":"e_1_3_3_99_2","unstructured":"Alex Krizhevsky Geoffrey Hinton et\u00a0al. 2009. Learning multiple layers of features from tiny images. Citeseer 1."},{"key":"e_1_3_3_100_2","volume-title":"Information Theory and Statistics","author":"Kullback Solomon","year":"1997","unstructured":"Solomon Kullback. 1997. Information Theory and Statistics. Courier Corporation."},{"key":"e_1_3_3_101_2","article-title":"Adversarial machine learning at scale","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016).","journal-title":"arXiv preprint arXiv:1611.01236"},{"key":"e_1_3_3_102_2","doi-asserted-by":"publisher","DOI":"10.1016\/B978-1-55860-377-6.50048-7"},{"key":"e_1_3_3_103_2","first-page":"1558","volume-title":"ICML","author":"Larsen Anders Boesen Lindbo","year":"2016","unstructured":"Anders Boesen Lindbo Larsen, S\u00f8ren Kaae S\u00f8nderby, Hugo Larochelle, and Ole Winther. 2016. Autoencoding beyond pixels using a learned similarity metric. In ICML. PMLR, 1558\u20131566."},{"key":"e_1_3_3_104_2","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_3_105_2","first-page":"656","volume-title":"S&P","author":"Lecuyer Mathias","year":"2019","unstructured":"Mathias Lecuyer, Vaggelis Atlidakis, Roxana Geambasu, Daniel Hsu, and Suman Jana. 2019. Certified robustness to adversarial examples with differential privacy. In S&P. IEEE, 656\u2013672."},{"key":"e_1_3_3_106_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102378"},{"key":"e_1_3_3_107_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2005.92"},{"key":"e_1_3_3_108_2","first-page":"1605","volume-title":"USENIX Security","author":"Leino Klas","year":"2020","unstructured":"Klas Leino and Matt Fredrikson. 2020. Stolen memories: Leveraging model memorization for calibrated white-box membership inference. In USENIX Security. USENIX Association, 1605\u20131622."},{"key":"e_1_3_3_109_2","doi-asserted-by":"publisher","DOI":"10.5555\/1005332.1005345"},{"key":"e_1_3_3_110_2","article-title":"FedMD: Heterogenous federated learning via model distillation","author":"Li Daliang","year":"2019","unstructured":"Daliang Li and Junpu Wang. 2019. FedMD: Heterogenous federated learning via model distillation. arXiv preprint arXiv:1910.03581 (2019).","journal-title":"arXiv preprint arXiv:1910.03581"},{"key":"e_1_3_3_111_2","first-page":"5","volume-title":"CODASPY","author":"Li Jiacheng","year":"2021","unstructured":"Jiacheng Li, Ninghui Li, and Bruno Ribeiro. 2021. Membership inference attacks and defenses in classification models. In CODASPY. ACM, 5\u201316."},{"key":"e_1_3_3_112_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"e_1_3_3_113_2","volume-title":"CCS","author":"Li Zheng","year":"2021","unstructured":"Zheng Li and Yang Zhang. 2021. Membership leakage in label-only exposures. In CCS. ACM."},{"key":"e_1_3_3_114_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2017.07.005"},{"key":"e_1_3_3_115_2","doi-asserted-by":"publisher","DOI":"10.1145\/3436755"},{"key":"e_1_3_3_116_2","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2019.2916086"},{"key":"e_1_3_3_117_2","volume-title":"CCS","author":"Liu Hongbin","year":"2021","unstructured":"Hongbin Liu, Jinyuan Jia, Wenjie Qu, and Neil Zhenqiang Gong. 2021. EncoderMI: Membership inference against pre-trained encoders in contrastive learning. In CCS. ACM."},{"key":"e_1_3_3_118_2","article-title":"Trustworthy AI: A computational perspective","author":"Liu Haochen","year":"2021","unstructured":"Haochen Liu, Yiqi Wang, Wenqi Fan, Xiaorui Liu, Yaxin Li, Shaili Jain, Anil K. Jain, and Jiliang Tang. 2021. Trustworthy AI: A computational perspective. arXiv preprint arXiv:2107.06641 (2021).","journal-title":"arXiv preprint arXiv:2107.06641"},{"key":"e_1_3_3_119_2","first-page":"459","volume-title":"ICDM","author":"Liu Kin Sum","year":"2019","unstructured":"Kin Sum Liu, Chaowei Xiao, Bo Li, and Jie Gao. 2019. Performing co-membership attacks against deep generative models. In ICDM. IEEE, 459\u2013467."},{"key":"e_1_3_3_120_2","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.01.1900525"},{"key":"e_1_3_3_121_2","article-title":"ML-Doctor: Holistic risk assessment of inference attacks against machine learning models","author":"Liu Yugeng","year":"2021","unstructured":"Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2021. ML-Doctor: Holistic risk assessment of inference attacks against machine learning models. arXiv preprint arXiv:2102.02551 (2021).","journal-title":"arXiv preprint arXiv:2102.02551"},{"key":"e_1_3_3_122_2","first-page":"3730","volume-title":"ICCV","author":"Liu Ziwei","year":"2015","unstructured":"Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang. 2015. Deep learning face attributes in the wild. In ICCV. IEEE, 3730\u20133738."},{"key":"e_1_3_3_123_2","article-title":"Towards measuring membership privacy","author":"Long Yunhui","year":"2017","unstructured":"Yunhui Long, Vincent Bindschaedler, and Carl A. Gunter. 2017. Towards measuring membership privacy. arXiv preprint arXiv:1712.09136 (2017).","journal-title":"arXiv preprint arXiv:1712.09136"},{"key":"e_1_3_3_124_2","article-title":"Understanding membership inferences on well-generalized learning models","author":"Long Yunhui","year":"2018","unstructured":"Yunhui Long, Vincent Bindschaedler, Lei Wang, Diyue Bu, Xiaofeng Wang, Haixu Tang, Carl A. Gunter, and Kai Chen. 2018. Understanding membership inferences on well-generalized learning models. arXiv preprint arXiv:1802.04889 (2018).","journal-title":"arXiv preprint arXiv:1802.04889"},{"key":"e_1_3_3_125_2","first-page":"521","volume-title":"EuroS&P","author":"Long Yunhui","year":"2020","unstructured":"Yunhui Long, Lei Wang, Diyue Bu, Vincent Bindschaedler, Xiaofeng Wang, Haixu Tang, Carl A. Gunter, and Kai Chen. 2020. A pragmatic approach to membership inferences on machine learning models. In EuroS&P. IEEE, 521\u2013534."},{"key":"e_1_3_3_126_2","article-title":"Threats to federated learning: A survey","author":"Lyu Lingjuan","year":"2020","unstructured":"Lingjuan Lyu, Han Yu, and Qiang Yang. 2020. Threats to federated learning: A survey. arXiv preprint arXiv:2003.02133 (2020).","journal-title":"arXiv preprint arXiv:2003.02133"},{"key":"e_1_3_3_127_2","article-title":"Towards deep learning models resistant to adversarial attacks","author":"Madry Aleksander","year":"2017","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2017. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017).","journal-title":"arXiv preprint arXiv:1706.06083"},{"key":"e_1_3_3_128_2","article-title":"Membership inference on word embedding and beyond","author":"Mahloujifar Saeed","year":"2021","unstructured":"Saeed Mahloujifar, Huseyin A. Inan, Melissa Chase, Esha Ghosh, and Marcello Hasegawa. 2021. Membership inference on word embedding and beyond. arXiv preprint arXiv:2106.11384 (2021).","journal-title":"arXiv preprint arXiv:2106.11384"},{"key":"e_1_3_3_129_2","unstructured":"Matt Mahoney. 2011. Large text compression benchmark. Retrieved from https:\/\/cs.fit.edu\/mmahoney\/compression\/text.html. (2011)."},{"key":"e_1_3_3_130_2","first-page":"165","volume-title":"RecSys","author":"McAuley Julian","year":"2013","unstructured":"Julian McAuley and Jure Leskovec. 2013. Hidden factors and hidden topics: Understanding rating dimensions with review text. In RecSys. ACM, 165\u2013172."},{"key":"e_1_3_3_131_2","first-page":"1273","volume-title":"AISTATS","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In AISTATS. PMLR, 1273\u20131282."},{"key":"e_1_3_3_132_2","volume-title":"ICLR","author":"McMahan Brendan","year":"2018","unstructured":"Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning differentially private recurrent language models. In ICLR. Retrieved from OpenReview.net."},{"key":"e_1_3_3_133_2","article-title":"Learning differentially private recurrent language models","author":"McMahan H. Brendan","year":"2017","unstructured":"H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2017. Learning differentially private recurrent language models. arXiv preprint arXiv:1710.06963 (2017).","journal-title":"arXiv preprint arXiv:1710.06963"},{"key":"e_1_3_3_134_2","first-page":"691","volume-title":"S&P","author":"Melis Luca","year":"2019","unstructured":"Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting unintended feature leakage in collaborative learning. In S&P. IEEE, 691\u2013706."},{"key":"e_1_3_3_135_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0012"},{"key":"e_1_3_3_136_2","article-title":"Extreme adaptation for personalized neural machine translation","author":"Michel Paul","year":"2018","unstructured":"Paul Michel and Graham Neubig. 2018. Extreme adaptation for personalized neural machine translation. arXiv preprint arXiv:1805.01817 (2018).","journal-title":"arXiv preprint arXiv:1805.01817"},{"key":"e_1_3_3_137_2","doi-asserted-by":"publisher","DOI":"10.1093\/bib\/bbx044"},{"key":"e_1_3_3_138_2","article-title":"Privacy in deep learning: A survey","author":"Mireshghallah Fatemehsadat","year":"2020","unstructured":"Fatemehsadat Mireshghallah, Mohammadkazem Taram, Praneeth Vepakomma, Abhishek Singh, Ramesh Raskar, and Hadi Esmaeilzadeh. 2020. Privacy in deep learning: A survey. arXiv preprint arXiv:2004.12254 (2020).","journal-title":"arXiv preprint arXiv:2004.12254"},{"key":"e_1_3_3_139_2","first-page":"263","volume-title":"CSF","author":"Mironov Ilya","year":"2017","unstructured":"Ilya Mironov. 2017. R\u00e9nyi differential privacy. In CSF. IEEE, 263\u2013275."},{"issue":"37","key":"e_1_3_3_140_2","first-page":"870","article-title":"Machine learning.","volume":"45","author":"Mitchell Tom M.","year":"1997","unstructured":"Tom M. Mitchell, et\u00a0al. 1997. Machine learning. Burr Ridge, IL: McGraw Hill 45, 37 (1997), 870\u2013877.","journal-title":"Burr Ridge, IL: McGraw Hill"},{"key":"e_1_3_3_141_2","volume-title":"WASSA","author":"Mohmmad Saif M.","year":"2017","unstructured":"Saif M. Mohmmad and Felipe Bravo-Marquez. 2017. WASSA-2017 shared task on emotion intensity. In WASSA. ACL."},{"key":"e_1_3_3_142_2","doi-asserted-by":"publisher","DOI":"10.5555\/3360093"},{"key":"e_1_3_3_143_2","volume-title":"SIGSPATIAL","author":"Moosavi Sobhan","year":"2019","unstructured":"Sobhan Moosavi, Mohammad Hossein Samavatian, Srinivasan Parthasarathy, Radu Teodorescu, and Rajiv Ramnath. 2019. Accident risk prediction based on heterogeneous sparse data: New dataset and insights. In SIGSPATIAL. ACM."},{"key":"e_1_3_3_144_2","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2021-0041"},{"key":"e_1_3_3_145_2","article-title":"ML privacy meter: Aiding regulatory compliance by quantifying the privacy risks of machine learning","author":"Murakonda Sasi Kumar","year":"2020","unstructured":"Sasi Kumar Murakonda and Reza Shokri. 2020. ML privacy meter: Aiding regulatory compliance by quantifying the privacy risks of machine learning. arXiv preprint arXiv:2007.09339 (2020).","journal-title":"arXiv preprint arXiv:2007.09339"},{"key":"e_1_3_3_146_2","article-title":"Toward robustness and privacy in federated learning: Experimenting with local and central differential privacy","author":"Naseri Mohammad","year":"2020","unstructured":"Mohammad Naseri, Jamie Hayes, and Emiliano De Cristofaro. 2020. Toward robustness and privacy in federated learning: Experimenting with local and central differential privacy. arXiv preprint arXiv:2009.03561 (2020).","journal-title":"arXiv preprint arXiv:2009.03561"},{"key":"e_1_3_3_147_2","first-page":"634","volume-title":"CCS","author":"Nasr Milad","year":"2018","unstructured":"Milad Nasr, Reza Shokri, and Amir Houmansadr. 2018. Machine learning with membership privacy using adversarial regularization. In CCS. ACM, 634\u2013646."},{"key":"e_1_3_3_148_2","first-page":"739","volume-title":"S&P","author":"Nasr Milad","year":"2019","unstructured":"Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In S&P. IEEE, 739\u2013753."},{"key":"e_1_3_3_149_2","volume-title":"S&P","author":"Nasr Milad","year":"2021","unstructured":"Milad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot, and Nicholas Carlini. 2021. Adversary instantiation: Lower bounds for differentially private machine learning. In S&P. IEEE."},{"key":"e_1_3_3_150_2","volume-title":"NuerIPS Workshop","author":"Netzer Yuval","year":"2011","unstructured":"Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, and Andrew Y. Ng. 2011. Reading digits in natural images with unsupervised feature learning. In NuerIPS Workshop."},{"key":"e_1_3_3_151_2","first-page":"4990","volume-title":"ICCV","author":"Neuhold Gerhard","year":"2017","unstructured":"Gerhard Neuhold, Tobias Ollmann, Samuel Rota Bulo, and Peter Kontschieder. 2017. The Mapillary Vistas dataset for semantic understanding of street scenes. In ICCV. IEEE, 4990\u20134999."},{"key":"e_1_3_3_152_2","first-page":"343","volume-title":"ICIP","author":"Ng Hong-Wei","year":"2014","unstructured":"Hong-Wei Ng and Stefan Winkler. 2014. A data-driven approach to cleaning large face datasets. In ICIP. IEEE, 343\u2013347."},{"key":"e_1_3_3_153_2","unstructured":"Texas Department of State Health Services. 2006. Texas Hospital Inpatient Discharge Public Use Data File. Retrieved from https:\/\/www.dshs.texas.gov\/thcic\/hospitals\/Inpatientpudf.shtm."},{"key":"e_1_3_3_154_2","article-title":"Membership inference attack on graph neural networks","author":"Olatunji Iyiola E.","year":"2021","unstructured":"Iyiola E. Olatunji, Wolfgang Nejdl, and Megha Khosla. 2021. Membership inference attack on graph neural networks. arXiv preprint arXiv:2101.06570 (2021).","journal-title":"arXiv preprint arXiv:2101.06570"},{"key":"e_1_3_3_155_2","volume-title":"ICLR","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot, Mart\u00edn Abadi, Ulfar Erlingsson, Ian Goodfellow, and Kunal Talwar. 2017. Semi-supervised knowledge transfer for deep learning from private training data. In ICLR. Retrieved from OpenReview.net."},{"key":"e_1_3_3_156_2","article-title":"Towards the science of security and privacy in machine learning","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick McDaniel, Arunesh Sinha, and Michael Wellman. 2016. Towards the science of security and privacy in machine learning. arXiv preprint arXiv:1611.03814 (2016).","journal-title":"arXiv preprint arXiv:1611.03814"},{"key":"e_1_3_3_157_2","volume-title":"MICCAI","author":"Paul William","year":"2021","unstructured":"William Paul, Yinzhi Cao, Miaomiao Zhang, and Phil Burlina. 2021. Defending medical image diagnostics against privacy attacks using generative methods. In MICCAI. Springer."},{"key":"e_1_3_3_158_2","volume-title":"NDSS","author":"Pyrgelis Apostolos","year":"2018","unstructured":"Apostolos Pyrgelis, Carmela Troncoso, and Emiliano De Cristofaro. 2018. Knock knock, who\u2019s there? Membership inference on aggregate location data. In NDSS. The Internet Society."},{"key":"e_1_3_3_159_2","doi-asserted-by":"publisher","DOI":"10.1145\/3392154"},{"key":"e_1_3_3_160_2","article-title":"Unsupervised representation learning with deep convolutional generative adversarial networks","author":"Radford Alec","year":"2015","unstructured":"Alec Radford, Luke Metz, and Soumith Chintala. 2015. Unsupervised representation learning with deep convolutional generative adversarial networks. arXiv preprint arXiv:1511.06434 (2015).","journal-title":"arXiv preprint arXiv:1511.06434"},{"key":"e_1_3_3_161_2","first-page":"1","article-title":"Exploring the limits of transfer learning with a unified text-to-text transformer","volume":"21","author":"Raffel Colin","year":"2020","unstructured":"Colin Raffel, Noam Shazeer, Adam Roberts, Katherine Lee, Sharan Narang, Michael Matena, Yanqi Zhou, Wei Li, and Peter J. Liu. 2020. Exploring the limits of transfer learning with a unified text-to-text transformer. J. Mach. Learn. Res. 21 (2020), 1\u201367.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_3_162_2","volume-title":"NuerIPS Workshop","author":"Rahimian Shadi","year":"2020","unstructured":"Shadi Rahimian, Tribhuvanesh Orekondy, and Mario Fritz. 2020. Sampling attacks: Amplification of membership inference attacks by repeated queries. In NuerIPS Workshop."},{"issue":"1","key":"e_1_3_3_163_2","first-page":"61","article-title":"Membership inference attack against differentially private deep learning model","volume":"11","author":"Rahman Md Atiqur","year":"2018","unstructured":"Md Atiqur Rahman, Tanzila Rahman, Robert Lagani\u00e8re, Noman Mohammed, and Yang Wang. 2018. Membership inference attack against differentially private deep learning model. Trans. Data Priv. 11, 1 (2018), 61\u201379.","journal-title":"Trans. Data Priv."},{"key":"e_1_3_3_164_2","unstructured":"Reddit. 2017. Reddit comments dataset. Retrieved from https:\/\/bigquery.cloud.google.com\/dataset\/fh-bigquery:redditcomments."},{"key":"e_1_3_3_165_2","first-page":"7892","volume-title":"CVPR","author":"Rezaei Shahbaz","year":"2021","unstructured":"Shahbaz Rezaei and Xin Liu. 2021. On the difficulty of membership inference attacks. In CVPR. IEEE, 7892\u20137900."},{"key":"e_1_3_3_166_2","article-title":"Accuracy-privacy trade-off in deep ensemble","author":"Rezaei Shahbaz","year":"2021","unstructured":"Shahbaz Rezaei, Zubair Shafiq, and Xin Liu. 2021. Accuracy-privacy trade-off in deep ensemble. arXiv preprint arXiv:2105.05381 (2021).","journal-title":"arXiv preprint arXiv:2105.05381"},{"key":"e_1_3_3_167_2","article-title":"A survey of privacy attacks in machine learning","author":"Rigaki Maria","year":"2020","unstructured":"Maria Rigaki and Sebastian Garcia. 2020. A survey of privacy attacks in machine learning. arXiv preprint arXiv:2007.07646 (2020).","journal-title":"arXiv preprint arXiv:2007.07646"},{"key":"e_1_3_3_168_2","volume-title":"Monte Carlo Statistical Methods","author":"Robert Christian","year":"2013","unstructured":"Christian Robert and George Casella. 2013. Monte Carlo Statistical Methods. Springer Science & Business Media."},{"key":"e_1_3_3_169_2","doi-asserted-by":"publisher","DOI":"10.1145\/3453158"},{"key":"e_1_3_3_170_2","doi-asserted-by":"crossref","first-page":"1325","DOI":"10.1145\/3340531.3411866","volume-title":"CIKM","author":"Rozemberczki Benedek","year":"2020","unstructured":"Benedek Rozemberczki and Rik Sarkar. 2020. Characteristic functions on graphs: Birds of a feather, from statistical descriptors to parametric models. In CIKM. ACM, 1325\u20131334."},{"key":"e_1_3_3_171_2","unstructured":"Stuart Russell and Peter Norvig. 2002. Artificial intelligence: A modern approach. Pearson Education Inc."},{"key":"e_1_3_3_172_2","first-page":"6","article-title":"Online algorithms and stochastic approximations","volume":"5","author":"Saad David","year":"1998","unstructured":"David Saad. 1998. Online algorithms and stochastic approximations. Online Learn. 5 (1998), 6\u20133.","journal-title":"Online Learn."},{"key":"e_1_3_3_173_2","first-page":"5558","volume-title":"ICML","author":"Sablayrolles Alexandre","year":"2019","unstructured":"Alexandre Sablayrolles, Matthijs Douze, Cordelia Schmid, Yann Ollivier, and Herv\u00e9 J\u00e9gou. 2019. White-box vs. black-box: Bayes optimal strategies for membership inference. In ICML. PMLR, 5558\u20135567."},{"key":"e_1_3_3_174_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3073804"},{"key":"e_1_3_3_175_2","volume-title":"NDSS","author":"Salem Ahmed","year":"2019","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Mario Fritz, and Michael Backes. 2019. ML-Leaks: Model and data independent membership inference attacks and defenses on machine learning models. In NDSS. Internet Society."},{"key":"e_1_3_3_176_2","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v29i3.2157"},{"key":"e_1_3_3_177_2","doi-asserted-by":"publisher","DOI":"10.1145\/3398394"},{"key":"e_1_3_3_178_2","volume-title":"ICCV","author":"Shafran Avital","year":"2021","unstructured":"Avital Shafran, Shmuel Peleg, and Yedid Hoshen. 2021. Reconstruction-based membership inference attacks are easier on difficult problems. In ICCV. IEEE."},{"key":"e_1_3_3_179_2","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2021-1188"},{"key":"e_1_3_3_180_2","first-page":"9549","volume-title":"AAAI","author":"Shejwalkar Virat","year":"2021","unstructured":"Virat Shejwalkar and Amir Houmansadr. 2021. Membership privacy for machine learning models through knowledge transfer. In AAAI. AAAI Press, 9549\u20139557."},{"key":"e_1_3_3_181_2","volume-title":"AIES","author":"Shokri Reza","year":"2021","unstructured":"Reza Shokri, Martin Strobel, and Yair Zick. 2021. On the privacy risks of model explanations. In AIES. ACM."},{"key":"e_1_3_3_182_2","first-page":"3","volume-title":"S&P","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In S&P. IEEE, 3\u201318."},{"key":"e_1_3_3_183_2","doi-asserted-by":"crossref","first-page":"377","DOI":"10.1145\/3372297.3417270","volume-title":"CCS","author":"Song Congzheng","year":"2020","unstructured":"Congzheng Song and Ananth Raghunathan. 2020. Information leakage in embedding models. In CCS. ACM, 377\u2013390."},{"key":"e_1_3_3_184_2","first-page":"587","volume-title":"CCS","author":"Song Congzheng","year":"2017","unstructured":"Congzheng Song, Thomas Ristenpart, and Vitaly Shmatikov. 2017. Machine learning models that remember too much. In CCS. ACM, 587\u2013601."},{"key":"e_1_3_3_185_2","volume-title":"KDD","author":"Song Congzheng","year":"2019","unstructured":"Congzheng Song and Vitaly Shmatikov. 2019. Auditing data provenance in text-generation models. In KDD. ACM."},{"key":"e_1_3_3_186_2","first-page":"2615","volume-title":"USENIX Security","author":"Song Liwei","year":"2021","unstructured":"Liwei Song and Prateek Mittal. 2021. Systematic evaluation of privacy risks of machine learning models. In USENIX Security. USENIX Association, 2615\u20132632."},{"key":"e_1_3_3_187_2","first-page":"50","volume-title":"S&P Workshops","author":"Song Liwei","year":"2019","unstructured":"Liwei Song, Reza Shokri, and Prateek Mittal. 2019. Membership inference attacks against adversarially robust deep learning models. In S&P Workshops. IEEE, 50\u201356."},{"key":"e_1_3_3_188_2","first-page":"241","volume-title":"CCS","author":"Song Liwei","year":"2019","unstructured":"Liwei Song, Reza Shokri, and Prateek Mittal. 2019. Privacy risks of securing machine learning models against adversarial examples. In CCS. ACM, 241\u2013257."},{"key":"e_1_3_3_189_2","doi-asserted-by":"publisher","DOI":"10.5555\/2627435.2670313"},{"key":"e_1_3_3_190_2","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/781670"},{"key":"e_1_3_3_191_2","article-title":"Adversarial attack and defense on graph data: A survey","author":"Sun Lichao","year":"2018","unstructured":"Lichao Sun, Yingtong Dou, Carl Yang, Ji Wang, Philip S. Yu, Lifang He, and Bo Li. 2018. Adversarial attack and defense on graph data: A survey. arXiv preprint arXiv:1812.10528 (2018).","journal-title":"arXiv preprint arXiv:1812.10528"},{"key":"e_1_3_3_192_2","first-page":"2818","volume-title":"CVPR","author":"Szegedy Christian","year":"2016","unstructured":"Christian Szegedy, Vincent Vanhoucke, Sergey Ioffe, Jon Shlens, and Zbigniew Wojna. 2016. Rethinking the inception architecture for computer vision. In CVPR. IEEE, 2818\u20132826."},{"key":"e_1_3_3_193_2","article-title":"Intriguing properties of neural networks","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013).","journal-title":"arXiv preprint arXiv:1312.6199"},{"key":"e_1_3_3_194_2","first-page":"1","article-title":"A taxonomy and terminology of adversarial machine learning","author":"Tabassi Elham","year":"2019","unstructured":"Elham Tabassi, Kevin Burns, Michael Hadjimichael, Andres Molina-Markham, and Julian Sexton. 2019. A taxonomy and terminology of adversarial machine learning. J. Res. Natl. Inst. Stand. Technol (2019), 1\u201329.","journal-title":"J. Res. Natl. Inst. Stand. Technol"},{"key":"e_1_3_3_195_2","article-title":"Mitigating membership inference attacks by self-distillation through a novel ensemble architecture","author":"Tang Xinyu","year":"2021","unstructured":"Xinyu Tang, Saeed Mahloujifar, Liwei Song, Virat Shejwalkar, Milad Nasr, Amir Houmansadr, and Prateek Mittal. 2021. Mitigating membership inference attacks by self-distillation through a novel ensemble architecture. arXiv preprint arXiv:2110.08324 (2021).","journal-title":"arXiv preprint arXiv:2110.08324"},{"key":"e_1_3_3_196_2","article-title":"Data and model dependencies of membership inference attack","author":"Tonni Shakila Mahjabin","year":"2020","unstructured":"Shakila Mahjabin Tonni, Dinusha Vatsalan, Farhad Farokhi, Dali Kaafar, Zhigang Lu, and Gioacchino Tangari. 2020. Data and model dependencies of membership inference attack. arXiv preprint arXiv:2002.06856 (2020).","journal-title":"arXiv preprint arXiv:2002.06856"},{"key":"e_1_3_3_197_2","volume-title":"ICML","author":"Tople Shruti","year":"2020","unstructured":"Shruti Tople, Amit Sharma, and Aditya Nori. 2020. Alleviating privacy attacks via causal learning. In ICML. PMLR."},{"key":"e_1_3_3_198_2","first-page":"601","volume-title":"USENIX Security","author":"Tram\u00e8r Florian","year":"2016","unstructured":"Florian Tram\u00e8r, Fan Zhang, Ari Juels, Michael K. Reiter, and Thomas Ristenpart. 2016. Stealing machine learning models via prediction APIs. In USENIX Security. USENIX Association, 601\u2013618."},{"key":"e_1_3_3_199_2","first-page":"33","volume-title":"AAAI-SSS","author":"Triastcyn Aleksei","year":"2019","unstructured":"Aleksei Triastcyn and Boi Faltings. 2019. Generating artificial data for private deep learning. In AAAI-SSS. CEUR Workshop Proceedings, 33\u201340."},{"key":"e_1_3_3_200_2","first-page":"82","volume-title":"TPS-ISA","author":"Truex Stacey","year":"2019","unstructured":"Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Wenqi Wei, and Lei Yu. 2019. Effects of differential privacy and data skewness on membership inference vulnerability. In TPS-ISA. IEEE, 82\u201391."},{"issue":"01","key":"e_1_3_3_201_2","first-page":"1","article-title":"Demystifying membership inference attacks in machine learning as a service","author":"Truex Stacey","year":"2019","unstructured":"Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Lei Yu, and Wenqi Wei. 2019. Demystifying membership inference attacks in machine learning as a service. IEEE Trans. Serv. Comput.01 (2019), 1\u20131.","journal-title":"IEEE Trans. Serv. Comput."},{"key":"e_1_3_3_202_2","first-page":"831","volume-title":"NeurIPS","author":"Vapnik Vladimir","year":"1992","unstructured":"Vladimir Vapnik. 1992. Principles of risk minimization for learning theory. In NeurIPS. 831\u2013838."},{"key":"e_1_3_3_203_2","doi-asserted-by":"publisher","DOI":"10.1098\/rsta.2018.0083"},{"key":"e_1_3_3_204_2","first-page":"3081","volume-title":"LREC","author":"Verhoeven Ben","year":"2014","unstructured":"Ben Verhoeven and Walter Daelemans. 2014. CLiPS stylometry investigation (CSI) corpus: A Dutch corpus for the detection of age, gender, personality, sentiment and deception in text. In LREC. 3081\u20133085."},{"key":"e_1_3_3_205_2","article-title":"GLUE: A multi-task benchmark and analysis platform for natural language understanding","author":"Wang Alex","year":"2018","unstructured":"Alex Wang, Amanpreet Singh, Julian Michael, Felix Hill, Omer Levy, and Samuel R. Bowman. 2018. GLUE: A multi-task benchmark and analysis platform for natural language understanding. arXiv preprint arXiv:1804.07461 (2018).","journal-title":"arXiv preprint arXiv:1804.07461"},{"key":"e_1_3_3_206_2","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.2000246"},{"key":"e_1_3_3_207_2","first-page":"2097","volume-title":"CVPR","author":"Wang Xiaosong","year":"2017","unstructured":"Xiaosong Wang, Yifan Peng, Le Lu, Zhiyong Lu, Mohammadhadi Bagheri, and Ronald M. Summers. 2017. ChestX-Ray8: Hospital-scale chest X-ray database and benchmarks on weakly-supervised classification and localization of common thorax diseases. In CVPR. IEEE, 2097\u20132106."},{"key":"e_1_3_3_208_2","article-title":"Membership inference attacks on knowledge graphs","author":"Wang Yu","year":"2021","unstructured":"Yu Wang and Lichao Sun. 2021. Membership inference attacks on knowledge graphs. arXiv preprint arXiv:2104.08273 (2021).","journal-title":"arXiv preprint arXiv:2104.08273"},{"key":"e_1_3_3_209_2","volume-title":"IJCAI","author":"Wang Yijue","year":"2021","unstructured":"Yijue Wang, Chenghong Wang, Zigeng Wang, Shanglin Zhou, Hang Liu, Jinbo Bi, Caiwen Ding, and Sanguthevar Rajasekaran. 2021. Against membership inference attack: Pruning is all you need. In IJCAI. Retrieved from ijcai.org."},{"key":"e_1_3_3_210_2","first-page":"263","volume-title":"ICPR","author":"Webster Ryan","year":"2021","unstructured":"Ryan Webster, Julien Rabin, Lo\u00efc Simon, and Fr\u00e9d\u00e9ric Jurie. 2021. Generating private data surrogates for vision related tasks. In ICPR. IEEE, 263\u2013269."},{"key":"e_1_3_3_211_2","article-title":"This person (probably) exists. Identity membership attacks against GAN generated faces","author":"Webster Ryan","year":"2021","unstructured":"Ryan Webster, Julien Rabin, Loic Simon, and Frederic Jurie. 2021. This person (probably) exists. Identity membership attacks against GAN generated faces. arXiv preprint arXiv:2107.06018 (2021).","journal-title":"arXiv preprint arXiv:2107.06018"},{"key":"e_1_3_3_212_2","article-title":"California Institute of Technology","author":"Welinder Peter","year":"2010","unstructured":"Peter Welinder, Steve Branson, Takeshi Mita, Catherine Wah, Florian Schroff, Serge Belongie, and Pietro Perona. 2010. California Institute of Technology. CNS-TR-2010-001. 2010.","journal-title":"CNS-TR-2010-001"},{"key":"e_1_3_3_213_2","unstructured":"Wikipedia. 2021. Confusion Matrix. Retrieved from https:\/\/bit.ly\/2wHUpcf."},{"key":"e_1_3_3_214_2","unstructured":"Wikipedia. 2021. General Data Protection Regulation. Retrieved from https:\/\/en.wikipedia.org\/wiki\/General_Data_Protection_Regulation."},{"key":"e_1_3_3_215_2","unstructured":"Wikipedia. 2021. ROC. Retrieved from https:\/\/bit.ly\/341yHfa."},{"key":"e_1_3_3_216_2","volume-title":"AAAI","author":"Wu Bingzhe","year":"2020","unstructured":"Bingzhe Wu, Chaochao Chen, Shiwan Zhao, Cen Chen, Yuan Yao, Guangyu Sun, Li Wang, Xiaolu Zhang, and Jun Zhou. 2020. Characterizing membership privacy in stochastic gradient Langevin dynamics. In AAAI. AAAI Press."},{"key":"e_1_3_3_217_2","article-title":"Adapting membership inference attacks to GNN for graph classification: Approaches and implications","author":"Wu Bang","year":"2021","unstructured":"Bang Wu, Xiangwen Yang, Shirui Pan, and Xingliang Yuan. 2021. Adapting membership inference attacks to GNN for graph classification: Approaches and implications. arXiv preprint arXiv:2110.08760 (2021).","journal-title":"arXiv preprint arXiv:2110.08760"},{"key":"e_1_3_3_218_2","first-page":"307","volume-title":"NeurIPS","author":"Wu Bingzhe","year":"2019","unstructured":"Bingzhe Wu, Shiwan Zhao, ChaoChao Chen, Haoyang Xu, Li Wang, Xiaolu Zhang, Guangyu Sun, and Jun Zhou. 2019. Generalization in generative adversarial networks: A novel perspective from privacy protection. In NeurIPS. 307\u2013317."},{"key":"e_1_3_3_219_2","article-title":"On the privacy-utility trade-off in differentially private hierarchical text classification","author":"Wunderlich Dominik","year":"2021","unstructured":"Dominik Wunderlich, Daniel Bernau, Francesco Ald\u00e0, Javier Parra-Arnau, and Thorsten Strufe. 2021. On the privacy-utility trade-off in differentially private hierarchical text classification. arXiv preprint arXiv:2103.02895 (2021).","journal-title":"arXiv preprint arXiv:2103.02895"},{"key":"e_1_3_3_220_2","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao Han","year":"2017","unstructured":"Han Xiao, Kashif Rasul, and Roland Vollgraf. 2017. Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747 (2017).","journal-title":"arXiv preprint arXiv:1708.07747"},{"key":"e_1_3_3_221_2","article-title":"Differentially private generative adversarial network","author":"Xie Liyang","year":"2018","unstructured":"Liyang Xie, Kaixiang Lin, Shu Wang, Fei Wang, and Jiayu Zhou. 2018. Differentially private generative adversarial network. arXiv preprint arXiv:1802.06739 (2018).","journal-title":"arXiv preprint arXiv:1802.06739"},{"key":"e_1_3_3_222_2","doi-asserted-by":"publisher","DOI":"10.1126\/science.1254806"},{"key":"e_1_3_3_223_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2897874"},{"key":"e_1_3_3_224_2","article-title":"Disparate vulnerability: On the unfairness of privacy attacks against machine learning","author":"Yaghini Mohammad","year":"2019","unstructured":"Mohammad Yaghini, Bogdan Kulynych, Giovanni Cherubin, and Carmela Troncoso. 2019. Disparate vulnerability: On the unfairness of privacy attacks against machine learning. arXiv preprint arXiv:1906.00389 (2019).","journal-title":"arXiv preprint arXiv:1906.00389"},{"key":"e_1_3_3_225_2","doi-asserted-by":"publisher","DOI":"10.1145\/2814575"},{"key":"e_1_3_3_226_2","doi-asserted-by":"publisher","DOI":"10.2200\/S00960ED2V01Y201910AIM043"},{"key":"e_1_3_3_227_2","article-title":"Defending model inversion and membership inference attacks via prediction purification","author":"Yang Ziqi","year":"2020","unstructured":"Ziqi Yang, Bin Shao, Bohan Xuan, Ee-Chien Chang, and Fan Zhang. 2020. Defending model inversion and membership inference attacks via prediction purification. arXiv preprint arXiv:2005.03915 (2020).","journal-title":"arXiv preprint arXiv:2005.03915"},{"key":"e_1_3_3_228_2","first-page":"268","volume-title":"CSF","author":"Yeom Samuel","year":"2018","unstructured":"Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018. Privacy risk in machine learning: Analyzing the connection to overfitting. In CSF. IEEE, 268\u2013282."},{"key":"e_1_3_3_229_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460427"},{"key":"e_1_3_3_230_2","doi-asserted-by":"crossref","first-page":"2026","DOI":"10.1145\/3447548.3467444","volume-title":"KDD","author":"Yin Yu","year":"2021","unstructured":"Yu Yin, Ke Chen, Lidan Shou, and Gang Chen. 2021. Defending privacy against more knowledgeable membership inference attackers. In KDD. ACM, 2026\u20132036."},{"key":"e_1_3_3_231_2","first-page":"61","volume-title":"PPMLP","author":"Ying Zuobin","year":"2020","unstructured":"Zuobin Ying, Yun Zhang, and Ximeng Liu. 2020. Privacy-preserving in defending against membership inference attacks. In PPMLP. ACM, 61\u201363."},{"key":"e_1_3_3_232_2","first-page":"10746","volume-title":"AAAI","author":"Yu Da","year":"2021","unstructured":"Da Yu, Huishuai Zhang, Wei Chen, Jian Yin, and Tie-Yan Liu. 2021. How does data augmentation affect privacy in machine learning? In AAAI, Vol. 35. AAAI Press, 10746\u201310753."},{"key":"e_1_3_3_233_2","article-title":"BDD100K: A diverse driving video database with scalable annotation tooling","author":"Yu Fisher","year":"2018","unstructured":"Fisher Yu, Wenqi Xian, Yingying Chen, Fangchen Liu, Mike Liao, Vashisht Madhavan, and Trevor Darrell. 2018. BDD100K: A diverse driving video database with scalable annotation tooling. arXiv preprint arXiv:1805.04687 (2018).","journal-title":"arXiv preprint arXiv:1805.04687"},{"key":"e_1_3_3_234_2","article-title":"Privacy for all: Demystify vulnerability disparity of differential privacy against membership inference attack","author":"Zhang Bo","year":"2020","unstructured":"Bo Zhang, Ruotong Yu, Haipei Sun, Yanying Li, Jun Xu, and Hui Wang. 2020. Privacy for all: Demystify vulnerability disparity of differential privacy against membership inference attack. arXiv preprint arXiv:2001.08855 (2020).","journal-title":"arXiv preprint arXiv:2001.08855"},{"key":"e_1_3_3_235_2","doi-asserted-by":"publisher","DOI":"10.1145\/3446776"},{"key":"e_1_3_3_236_2","article-title":"Weibo content corpus","author":"Zhang Huaping","year":"2017","unstructured":"Huaping Zhang. 2017. Weibo content corpus. In Proceedings of the http:\/\/www.nlpir.org\/wordpress\/download\/weibo_content_corpus.rar.","journal-title":"http:\/\/www.nlpir.org\/wordpress\/download\/weibo_content_corpus.rar"},{"key":"e_1_3_3_237_2","volume-title":"ICLR","author":"Zhang Hongyi","year":"2018","unstructured":"Hongyi Zhang, Moustapha Cisse, Yann N. Dauphin, and David Lopez-Paz. 2018. mixup: Beyond empirical risk minimization. In ICLR. Retrieved from OpenReview.net."},{"key":"e_1_3_3_238_2","first-page":"1","volume-title":"ICC","author":"Zhang Jingwen","year":"2020","unstructured":"Jingwen Zhang, Jiale Zhang, Junjun Chen, and Shui Yu. 2020. GAN enhanced membership inference: A passive local attack in federated learning. In ICC. IEEE, 1\u20136."},{"key":"e_1_3_3_239_2","article-title":"Membership inference attacks against recommender systems","author":"Zhang Minxing","year":"2021","unstructured":"Minxing Zhang, Zhaochun Ren, Zihan Wang, Pengjie Ren, Zhumin Chen, Pengfei Hu, and Yang Zhang. 2021. Membership inference attacks against recommender systems. arXiv preprint arXiv:2109.08045 (2021).","journal-title":"arXiv preprint arXiv:2109.08045"},{"key":"e_1_3_3_240_2","article-title":"Privacy-preserving machine learning through data obfuscation","author":"Zhang Tianwei","year":"2018","unstructured":"Tianwei Zhang, Zecheng He, and Ruby B. Lee. 2018. Privacy-preserving machine learning through data obfuscation. arXiv preprint arXiv:1807.01860 (2018).","journal-title":"arXiv preprint arXiv:1807.01860"},{"key":"e_1_3_3_241_2","article-title":"Differentially private releasing via deep generative model","author":"Zhang Xinyang","year":"2018","unstructured":"Xinyang Zhang, Shouling Ji, and Ting Wang. 2018. Differentially private releasing via deep generative model. arXiv preprint arXiv:1801.01594 (2018).","journal-title":"arXiv preprint arXiv:1801.01594"},{"key":"e_1_3_3_242_2","first-page":"5810","volume-title":"CVPR","author":"Zhang Zhifei","year":"2017","unstructured":"Zhifei Zhang, Yang Song, and Hairong Qi. 2017. Age progression\/regression by conditional adversarial autoencoder. In CVPR. IEEE, 5810\u20135818."},{"key":"e_1_3_3_243_2","volume-title":"EuroS&P","author":"Zhao Benjamin Zi Hao","year":"2021","unstructured":"Benjamin Zi Hao Zhao, Aviral Agrawal, Catisha Coburn, Hassan Jameel Asghar, Raghav Bhaskar, Mohamed Ali Kaafar, Darren Webb, and Peter Dickinson. 2021. On the (In) feasibility of attribute inference attacks on machine learning models. In EuroS&P. IEEE."},{"key":"e_1_3_3_244_2","volume-title":"CCS Workshop","author":"Zhao Benjamin Zi Hao","year":"2019","unstructured":"Benjamin Zi Hao Zhao, Hassan Jameel Asghar, Raghav Bhaskar, and Mohamed Ali Kaafar. 2019. On inferring training data attributes in machine learning models. In CCS Workshop. ACM."},{"key":"e_1_3_3_245_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.04.082"},{"key":"e_1_3_3_246_2","first-page":"19","volume-title":"ICCV","author":"Zhu Yukun","year":"2015","unstructured":"Yukun Zhu, Ryan Kiros, Rich Zemel, Ruslan Salakhutdinov, Raquel Urtasun, Antonio Torralba, and Sanja Fidler. 2015. Aligning books and movies: Towards story-like visual explanations by watching movies and reading books. In ICCV. IEEE, 19\u201327."},{"key":"e_1_3_3_247_2","article-title":"Privacy analysis of deep learning in the wild: Membership inference attacks against transfer learning","author":"Zou Yang","year":"2020","unstructured":"Yang Zou, Zhikun Zhang, Michael Backes, and Yang Zhang. 2020. Privacy analysis of deep learning in the wild: Membership inference attacks against transfer learning. arXiv preprint arXiv:2009.04872 (2020).","journal-title":"arXiv preprint arXiv:2009.04872"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3523273","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3523273","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3523273","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:30Z","timestamp":1750183770000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3523273"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,1,31]]},"references-count":246,"journal-issue":{"issue":"11s","published-print":{"date-parts":[[2022,1,31]]}},"alternative-id":["10.1145\/3523273"],"URL":"https:\/\/doi.org\/10.1145\/3523273","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,1,31]]},"assertion":[{"value":"2021-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-09-09","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}