{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T18:18:40Z","timestamp":1771611520884,"version":"3.50.1"},"reference-count":77,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2023,11,13]],"date-time":"2023-11-13T00:00:00Z","timestamp":1699833600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Knowl. Discov. Data"],"published-print":{"date-parts":[[2024,2,29]]},"abstract":"<jats:p>\n            Social media has drastically reshaped the world that allows billions of people to engage in such interactive environments to conveniently create and share content with the public. Among them, text data (e.g., tweets, blogs) maintains the basic yet important social activities and generates a rich source of user-oriented information. While those explicit sensitive user data like credentials have been significantly protected by all means, personal private attribute (e.g., age, gender, location) disclosure due to inference attacks is somehow challenging to avoid, especially when powerful natural language processing (NLP) techniques have been effectively deployed to automate attribute inferences from implicit text data. This puts users\u2019 attribute privacy at risk. To address this challenge, in this article, we leverage the inherent vulnerability of machine learning to adversarial attacks, and design a novel text-space\n            <jats:bold>Adv<\/jats:bold>\n            ersarial attack for\n            <jats:bold>S<\/jats:bold>\n            ocial\n            <jats:bold>G<\/jats:bold>\n            ood, called\n            <jats:italic>Adv4SG<\/jats:italic>\n            . In other words, we cast the problem of protecting personal attribute privacy as an adversarial attack formulation problem over the social media text data to defend against NLP-based attribute inference attacks. More specifically, Adv4SG proceeds with a sequence of word perturbations under given constraints such that the probed attribute cannot be identified correctly. Different from the prior works, we advance Adv4SG by considering social media property, and introducing cost-effective mechanisms to expedite attribute obfuscation over text data under the black-box setting. Extensive experiments on real-world social media datasets have demonstrated that our method can effectively degrade the inference accuracy with less computational cost over different attribute settings, which substantially helps mitigate the impacts of inference attacks and thus achieve high performance in user attribute privacy protection.\n          <\/jats:p>","DOI":"10.1145\/3614098","type":"journal-article","created":{"date-parts":[[2023,8,7]],"date-time":"2023-08-07T11:32:26Z","timestamp":1691407946000},"page":"1-24","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Adversary for Social Good: Leveraging Adversarial Attacks to Protect Personal Attribute Privacy"],"prefix":"10.1145","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1538-3644","authenticated-orcid":false,"given":"Xiaoting","family":"Li","sequence":"first","affiliation":[{"name":"Visa Research, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1550-6170","authenticated-orcid":false,"given":"Lingwei","family":"Chen","sequence":"additional","affiliation":[{"name":"Wright State University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0741-5511","authenticated-orcid":false,"given":"Dinghao","family":"Wu","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,13]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"crossref","unstructured":"Moustafa Alzantot Yash Sharma Ahmed Elgohary Bo-Jhang Ho Mani Srivastava and Kai-Wei Chang. 2018. Generating natural language adversarial examples. arXiv:1804.07998. Retrieved from https:\/\/arxiv.org\/abs\/1804.07998","DOI":"10.18653\/v1\/D18-1316"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3110025.3110046"},{"key":"e_1_3_2_4_2","first-page":"274","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In Proceedings of the International Conference on Machine Learning. PMLR, 274\u2013283."},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2746539.2746632"},{"key":"e_1_3_2_6_2","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1145\/3209542.3209552","volume-title":"Proceedings of the 29th on Hypertext and Social Media","author":"Beigi Ghazaleh","year":"2018","unstructured":"Ghazaleh Beigi, Kai Shu, Yanchao Zhang, and Huan Liu. 2018. Securing social media user data: An adversarial approach. In Proceedings of the 29th on Hypertext and Social Media. 165\u2013173."},{"key":"e_1_3_2_7_2","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1109\/SP.2017.49","volume-title":"Proceedings of the 2017 IEEE Symposium on Security and Privacy (sp)","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David Wagner. 2017. Towards evaluating the robustness of neural networks. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (sp). IEEE, 39\u201357."},{"key":"e_1_3_2_8_2","doi-asserted-by":"crossref","unstructured":"Ciprian Chelba Tomas Mikolov Mike Schuster Qi Ge Thorsten Brants Phillipp Koehn and Tony Robinson. 2013. One billion word benchmark for measuring progress in statistical language modeling. arXiv:1312.3005. Retrieved from https:\/\/arxiv.org\/abs\/1312.3005","DOI":"10.21437\/Interspeech.2014-564"},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","first-page":"99","DOI":"10.1109\/EISIC.2017.21","volume-title":"Proceedings of the 2017 European Intelligence and Security Informatics Conference (EISIC)","author":"Chen Lingwei","year":"2017","unstructured":"Lingwei Chen, Yanfang Ye, and Thirimachos Bourlai. 2017. Adversarial machine learning in malware detection: Arms race between evasion attack and defense. In Proceedings of the 2017 European Intelligence and Security Informatics Conference (EISIC). IEEE, 99\u2013106."},{"key":"e_1_3_2_10_2","doi-asserted-by":"crossref","unstructured":"Yong Cheng Lu Jiang and Wolfgang Macherey. 2019. Robust neural machine translation with doubly adversarial inputs. arXiv:1906.02443. Retrieved from https:\/\/arxiv.org\/abs\/1906.02443","DOI":"10.18653\/v1\/P19-1425"},{"key":"e_1_3_2_11_2","unstructured":"Junyoung Chung Caglar Gulcehre KyungHyun Cho and Yoshua Bengio. 2014. Empirical evaluation of gated recurrent neural networks on sequence modeling. arXiv:1412.3555. Retrieved from https:\/\/arxiv.org\/abs\/1412.3555"},{"key":"e_1_3_2_12_2","unstructured":"Nicholas Confessore. 2018. Cambridge analytica and Facebook: The scandal and the fallout so far. Retrieved fromhttps:\/\/www.nytimes.com\/2018\/04\/04\/us\/politics\/cambridge-analytica-scandal-fallout.html"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.5555\/1791834.1791836"},{"key":"e_1_3_2_14_2","doi-asserted-by":"crossref","unstructured":"Javid Ebrahimi Anyi Rao Daniel Lowd and Dejing Dou. 2017. Hotflip: White-box adversarial examples for text classification. arXiv:1712.06751. Retrieved from https:\/\/arxiv.org\/abs\/1712.06751","DOI":"10.18653\/v1\/P18-2006"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.5555\/1870658.1870782"},{"key":"e_1_3_2_16_2","first-page":"1054","volume-title":"Proceedings of the CCS","author":"Erlingsson \u00dalfar","year":"2014","unstructured":"\u00dalfar Erlingsson, Vasyl Pihur, and Aleksandra Korolova. 2014. Rappor: Randomized aggregatable privacy-preserving ordinal response. In Proceedings of the CCS. 1054\u20131067."},{"key":"e_1_3_2_17_2","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1109\/SPW.2018.00016","volume-title":"Proceedings of the 2018 IEEE Security and Privacy Workshops (SPW)","author":"Gao Ji","year":"2018","unstructured":"Ji Gao, Jack Lanchantin, Mary Lou Soffa, and Yanjun Qi. 2018. Black-box generation of adversarial text sequences to evade deep learning classifiers. In Proceedings of the 2018 IEEE Security and Privacy Workshops (SPW). IEEE, 50\u201356."},{"issue":"1","key":"e_1_3_2_18_2","first-page":"3","article-title":"Attribute inference attacks in online social networks","volume":"21","author":"Gong Neil Zhenqiang","year":"2018","unstructured":"Neil Zhenqiang Gong and Bin Liu. 2018. Attribute inference attacks in online social networks. TOPS 21, 1 (2018), 3.","journal-title":"TOPS"},{"key":"e_1_3_2_19_2","unstructured":"Zhitao Gong Wenlu Wang Bo Li Dawn Song and Wei-Shinn Ku. 2018. Adversarial texts with gradient methods. arXiv:1801.07175. Retrieved from https:\/\/arxiv.org\/abs\/1801.07175"},{"key":"e_1_3_2_20_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_2_21_2","unstructured":"Alex Graves. 2013. Generating sequences with recurrent neural networks. arXiv:1308.0850. Retrieved from https:\/\/arxiv.org\/abs\/1308.0850"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2013.06.020"},{"key":"e_1_3_2_23_2","first-page":"513","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security 18)","author":"Jia Jinyuan","year":"2018","unstructured":"Jinyuan Jia and Neil Zhenqiang Gong. 2018. Attriguard: A practical defense against attribute inference attacks via adversarial machine learning. In Proceedings of the 27th USENIX Security Symposium (USENIX Security 18). 513\u2013529."},{"key":"e_1_3_2_24_2","first-page":"259","volume-title":"Proceedings of the CCS","author":"Jia Jinyuan","year":"2019","unstructured":"Jinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang, and Neil Zhenqiang Gong. 2019. MemGuard: Defending against black-box membership inference attacks via adversarial examples. In Proceedings of the CCS. 259\u2013274."},{"key":"e_1_3_2_25_2","first-page":"1561","volume-title":"Proceedings of the WWW","author":"Jia Jinyuan","year":"2017","unstructured":"Jinyuan Jia, Binghui Wang, Le Zhang, and Neil Zhenqiang Gong. 2017. AttriInfer: Inferring user attributes in online social networks using markov random fields. In Proceedings of the WWW. 1561\u20131569."},{"key":"e_1_3_2_26_2","doi-asserted-by":"crossref","unstructured":"Robin Jia and Percy Liang. 2017. Adversarial examples for evaluating reading comprehension systems. arXiv:1707.07328. Retrieved from https:\/\/arxiv.org\/abs\/1707.07328","DOI":"10.18653\/v1\/D17-1215"},{"key":"e_1_3_2_27_2","first-page":"173","volume-title":"Proceedings of the International Conference of the Cross-Language Evaluation Forum for European Languages","author":"Karadzhov Georgi","year":"2017","unstructured":"Georgi Karadzhov, Tsvetomila Mihaylova, Yasen Kiprov, Georgi Georgiev, Ivan Koychev, and Preslav Nakov. 2017. The case for being average: A mediocrity approach to style masking and author obfuscation. In Proceedings of the International Conference of the Cross-Language Evaluation Forum for European Languages. Springer, 173\u2013185."},{"key":"e_1_3_2_28_2","first-page":"890","volume-title":"Proceedings of the CLEF (Working Notes)","author":"Keswani Yashwant","year":"2016","unstructured":"Yashwant Keswani, Harsh Trivedi, Parth Mehta, and Prasenjit Majumder. 2016. Author masking through translation.. In Proceedings of the CLEF (Working Notes). 890\u2013894."},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1080\/15427951.2012.625257"},{"key":"e_1_3_2_30_2","first-page":"533","volume-title":"Proceedings of the European Signal Processing Conference (EUSIPCO)","author":"Kolosnjaji Bojan","year":"2018","unstructured":"Bojan Kolosnjaji, Ambra Demontis, Battista Biggio, Davide Maiorca, Giorgio Giacinto, Claudia Eckert, and Fabio Roli. 2018. Adversarial malware binaries: Evading deep learning for malware detection in executables. In Proceedings of the European Signal Processing Conference (EUSIPCO). IEEE, 533\u2013537."},{"key":"e_1_3_2_31_2","first-page":"11304","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","author":"Kumar Chetan","year":"2020","unstructured":"Chetan Kumar, Riazat Ryan, and Ming Shao. 2020. Adversary for social good: Protecting familial privacy through joint adversarial attacks. In Proceedings of the AAAI Conference on Artificial Intelligence. 11304\u201311311."},{"key":"e_1_3_2_32_2","unstructured":"Jinfeng Li Shouling Ji Tianyu Du Bo Li and Ting Wang. 2018. Textbugger: Generating adversarial text against real-world applications. arXiv:1812.05271. Retrieved from https:\/\/arxiv.org\/abs\/1812.05271"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2007.367856"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3543873.3587313"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1145\/3477495.3531968"},{"key":"e_1_3_2_36_2","first-page":"208","volume-title":"Proceedings of the 2021 SIAM International Conference on Data Mining (SDM)","author":"Li Xiaoting","year":"2021","unstructured":"Xiaoting Li, Lingwei Chen, and Dinghao Wu. 2021. Turning attacks into protection: Social media privacy protection using adversarial attacks. In Proceedings of the 2021 SIAM International Conference on Data Mining (SDM). SIAM, 208\u2013216."},{"key":"e_1_3_2_37_2","first-page":"710","volume-title":"Proceedings of the International Conference on Security and Privacy in Communication Systems","author":"Li Xiaoting","year":"2022","unstructured":"Xiaoting Li, Lingwei Chen, and Dinghao Wu. 2022. Adversary for social good: Leveraging attribute-obfuscating attack to protect user privacy on social networks. In Proceedings of the International Conference on Security and Privacy in Communication Systems. Springer, 710\u2013728."},{"key":"e_1_3_2_38_2","doi-asserted-by":"crossref","unstructured":"Bin Liang Hongcheng Li Miaoqiang Su Pan Bian Xirong Li and Wenchang Shi. 2017. Deep text classification can be fooled. arXiv:1704.08006. Retrieved from https:\/\/arxiv.org\/abs\/1704.08006","DOI":"10.24963\/ijcai.2018\/585"},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/1376616.1376629"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/1217299.1217302"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13278-014-0193-5"},{"key":"e_1_3_2_42_2","unstructured":"Takeru Miyato Andrew M. Dai and Ian Goodfellow. 2016. Adversarial training methods for semi-supervised text classification. arXiv:1605.07725. Retrieved from https:\/\/arxiv.org\/abs\/1605.07725"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"issue":"8","key":"e_1_3_2_44_2","article-title":"Predicting age groups of twitter users based on language and metadata features","volume":"12","author":"Morgan-Lopez Antonio A.","year":"2017","unstructured":"Antonio A. Morgan-Lopez, Annice E. Kim, Robert F. Chew, and Paul Ruddle. 2017. Predicting age groups of twitter users based on language and metadata features. PloS One 12, 8 (2017).","journal-title":"PloS One"},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","unstructured":"Nikola Mrk\u0161i\u0107 Diarmuid O. S\u00e9aghdha Blaise Thomson Milica Ga\u0161i\u0107 Lina Rojas-Barahona Pei-Hao Su David Vandyke Tsung-Hsien Wen and Steve Young. 2016. Counter-fitting word vectors to linguistic constraints. arXiv:1603.00892. Retrieved from https:\/\/arxiv.org\/abs\/1603.00892","DOI":"10.18653\/v1\/N16-1018"},{"key":"e_1_3_2_46_2","first-page":"1491","volume-title":"Proceedings of the ICCV","author":"Oh Seong Joon","year":"2017","unstructured":"Seong Joon Oh, Mario Fritz, and Bernt Schiele. 2017. Adversarial image perturbation for privacy protection a game theory perspective. In Proceedings of the ICCV. 1491\u20131500."},{"key":"e_1_3_2_47_2","unstructured":"Nicolas Papernot Patrick McDaniel and Ian Goodfellow. 2016. Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv:1605.07277. Retrieved from https:\/\/arxiv.org\/abs\/1605.07277"},{"key":"e_1_3_2_48_2","first-page":"506","volume-title":"Proceedings of the AsiaCCS","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z. Berkay Celik, and Ananthram Swami. 2017. Practical black-box attacks against machine learning. In Proceedings of the AsiaCCS. 506\u2013519."},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MILCOM.2016.7795300","volume-title":"Proceedings of the MILCOM 2016-2016 IEEE Military Communications Conference","author":"Papernot Nicolas","year":"2016","unstructured":"Nicolas Papernot, Patrick McDaniel, Ananthram Swami, and Richard Harang. 2016. Crafting adversarial input sequences for recurrent neural networks. In Proceedings of the MILCOM 2016-2016 IEEE Military Communications Conference. IEEE, 49\u201354."},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_2_51_2","doi-asserted-by":"crossref","unstructured":"Fabio Pierazzi Feargus Pendlebury Jacopo Cortellazzi and Lorenzo Cavallaro. 2019. Intriguing properties of adversarial ML attacks in the problem space. arXiv:1911.02142. Retrieved from https:\/\/arxiv.org\/abs\/1911.02142","DOI":"10.1109\/SP40000.2020.00073"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2015.01.004"},{"key":"e_1_3_2_53_2","first-page":"479","volume-title":"Proceedings of the USENIX Security","author":"Quiring Erwin","year":"2019","unstructured":"Erwin Quiring, Alwin Maier, and Konrad Rieck. 2019. Misleading authorship attribution of source code using adversarial learning. In Proceedings of the USENIX Security. 479\u2013496."},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/MAES.2007.327521"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2010.2054471"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1103"},{"key":"e_1_3_2_57_2","unstructured":"Sebastian Ruder Parsa Ghaffari and John G. Breslin. 2016. Character-level and multi-channel convolutional neural networks for large-scale authorship attribution. arXiv:1609.06686. Retrieved from https:\/\/arxiv.org\/abs\/1609.06686"},{"key":"e_1_3_2_58_2","unstructured":"Suranjana Samanta and Sameep Mehta. 2017. Towards crafting text adversarial samples. arXiv:1707.02812. Retrieved from https:\/\/arxiv.org\/abs\/1707.02812"},{"key":"e_1_3_2_59_2","first-page":"744","volume-title":"Proceedings of the European Conference on Information Retrieval","author":"Samanta Suranjana","year":"2018","unstructured":"Suranjana Samanta and Sameep Mehta. 2018. Generating adversarial text samples. In Proceedings of the European Conference on Information Retrieval. Springer, 744\u2013749."},{"key":"e_1_3_2_60_2","doi-asserted-by":"crossref","unstructured":"Motoki Sato Jun Suzuki Hiroyuki Shindo and Yuji Matsumoto. 2018. Interpretable adversarial perturbation in input embedding space for text. arXiv:1805.02917. Retrieved from https:\/\/arxiv.org\/abs\/1805.02917","DOI":"10.24963\/ijcai.2018\/601"},{"key":"e_1_3_2_61_2","first-page":"199","volume-title":"Proceedings of the AAAI Spring Symposium: Computational Approaches to Analyzing Weblogs","author":"Schler Jonathan","year":"2006","unstructured":"Jonathan Schler, Moshe Koppel, Shlomo Argamon, and James W. Pennebaker. 2006. Effects of age and gender on blogging. In Proceedings of the AAAI Spring Symposium: Computational Approaches to Analyzing Weblogs. 199\u2013205."},{"key":"e_1_3_2_62_2","first-page":"1633","volume-title":"Proceedings of the 27th USENIX Security Symposium (USENIX Security 18)","author":"Shetty Rakshith","year":"2018","unstructured":"Rakshith Shetty, Bernt Schiele, and Mario Fritz. 2018. A4NT: Author attribute anonymity by adversarial training of neural machine translation. In Proceedings of the 27th USENIX Security Symposium (USENIX Security 18). 1633\u20131650."},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2015-0024"},{"issue":"4","key":"e_1_3_2_64_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3009908","article-title":"Privacy games along location traces: A game-theoretic framework for optimizing location privacy","volume":"19","author":"Shokri Reza","year":"2016","unstructured":"Reza Shokri, George Theodorakopoulos, and Carmela Troncoso. 2016. Privacy games along location traces: A game-theoretic framework for optimizing location privacy. ACM Transactions on Privacy and Security 19, 4 (2016), 1\u201331.","journal-title":"ACM Transactions on Privacy and Security"},{"key":"e_1_3_2_65_2","first-page":"617","volume-title":"Proceedings of the ACM Conference on Computer and Communications Security (CCS)","author":"Shokri Reza","year":"2012","unstructured":"Reza Shokri, George Theodorakopoulos, Carmela Troncoso, Jean-Pierre Hubaux, and Jean-Yves Le Boudec. 2012. Protecting location privacy: Optimal strategy against localization attacks. In Proceedings of the ACM Conference on Computer and Communications Security (CCS). 617\u2013627."},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219909"},{"key":"e_1_3_2_67_2","unstructured":"Christian Szegedy Wojciech Zaremba Ilya Sutskever Joan Bruna Dumitru Erhan Ian Goodfellow and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv:1312.6199. Retrieved from https:\/\/arxiv.org\/abs\/1312.6199"},{"key":"e_1_3_2_68_2","first-page":"729","volume-title":"Proceedings of the USENIX Security","author":"Wang Tianhao","year":"2017","unstructured":"Tianhao Wang, Jeremiah Blocki, Ninghui Li, and Somesh Jha. 2017. Locally differentially private protocols for frequency estimation. In Proceedings of the USENIX Security. 729\u2013745."},{"key":"e_1_3_2_69_2","doi-asserted-by":"crossref","unstructured":"Yicheng Wang and Mohit Bansal. 2018. Robust machine comprehension models via adversarial training. arXiv:1804.06473. Retrieved from https:\/\/arxiv.org\/abs\/1804.06473","DOI":"10.18653\/v1\/N18-2091"},{"key":"e_1_3_2_70_2","unstructured":"Yanfang Ye Shifu Hou Yujie Fan Yiyue Qian Yiming Zhang Shiyu Sun Qian Peng and Kenneth Laparo. 2020.  \\(\\alpha\\) -Satellite: An AI-driven system and benchmark datasets for hierarchical community-level risk assessment to help combat COVID-19. arXiv:2003.12232. Retrieved from https:\/\/arxiv.org\/abs\/2003.12232"},{"key":"e_1_3_2_71_2","first-page":"211","volume-title":"Proceedings of the AAMAS","author":"Yu Sixie","year":"2018","unstructured":"Sixie Yu, Yevgeniy Vorobeychik, and Scott Alfeld. 2018. Adversarial classification on social networks. In Proceedings of the AAMAS. 211\u2013219."},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.14778\/1921071.1921080"},{"key":"e_1_3_2_73_2","doi-asserted-by":"crossref","unstructured":"Yuan Zang Fanchao Qi Chenghao Yang Zhiyuan Liu Meng Zhang Qun Liu and Maosong Sun. 2019. Word-level textual adversarial attacking as combinatorial optimization. arXiv:1910.12196. Retrieved from https:\/\/arxiv.org\/abs\/1910.12196","DOI":"10.18653\/v1\/2020.acl-main.540"},{"key":"e_1_3_2_74_2","doi-asserted-by":"crossref","unstructured":"Huangzhao Zhang Hao Zhou Ning Miao and Lei Li. 2020. Generating fluent adversarial examples for natural languages. arXiv:2007.06174. Retrieved from https:\/\/arxiv.org\/abs\/2007.06174","DOI":"10.18653\/v1\/P19-1559"},{"issue":"3","key":"e_1_3_2_75_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3374217","article-title":"Adversarial attacks on deep-learning models in natural language processing: A survey","volume":"11","author":"Zhang Wei Emma","year":"2020","unstructured":"Wei Emma Zhang, Quan Z. Sheng, Ahoud Alhazmi, and Chenliang Li. 2020. Adversarial attacks on deep-learning models in natural language processing: A survey. ACM Transactions on Intelligent Systems and Technology 11, 3 (2020), 1\u201341.","journal-title":"ACM Transactions on Intelligent Systems and Technology"},{"key":"e_1_3_2_76_2","first-page":"649","volume-title":"Proceedings of the Advances in Neural Information Processing Systems","author":"Zhang Xiang","year":"2015","unstructured":"Xiang Zhang, Junbo Zhao, and Yann LeCun. 2015. Character-level convolutional networks for text classification. In Proceedings of the Advances in Neural Information Processing Systems. 649\u2013657."},{"key":"e_1_3_2_77_2","first-page":"287","volume-title":"Proceedings of the 2018 World Wide Web Conference","author":"Zhang Yang","year":"2018","unstructured":"Yang Zhang, Mathias Humbert, Tahleen Rahman, Cheng-Te Li, Jun Pang, and Michael Backes. 2018. Tagvisor: A privacy advisor for sharing hashtags. In Proceedings of the 2018 World Wide Web Conference. 287\u2013296."},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE.2008.4497459"}],"container-title":["ACM Transactions on Knowledge Discovery from Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3614098","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3614098","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:37:27Z","timestamp":1750178247000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3614098"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,13]]},"references-count":77,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2024,2,29]]}},"alternative-id":["10.1145\/3614098"],"URL":"https:\/\/doi.org\/10.1145\/3614098","relation":{},"ISSN":["1556-4681","1556-472X"],"issn-type":[{"value":"1556-4681","type":"print"},{"value":"1556-472X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,13]]},"assertion":[{"value":"2022-01-02","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-07-26","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-11-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}