{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T04:15:40Z","timestamp":1782360940815,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":73,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"Schweizerischer Nationalfonds zur F\u00f6rderung der Wissenschaftlichen Forschung","doi-asserted-by":"publisher","award":["214838"],"award-info":[{"award-number":["214838"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690194","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"1271-1284","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":16,"title":["Evaluations of Machine Learning Privacy Defenses are Misleading"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3276-2678","authenticated-orcid":false,"given":"Michael","family":"Aerni","sequence":"first","affiliation":[{"name":"ETH Zurich, Z\u00fcrich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-4670-9038","authenticated-orcid":false,"given":"Jie","family":"Zhang","sequence":"additional","affiliation":[{"name":"ETH Zurich, Z\u00fcrich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8703-8762","authenticated-orcid":false,"given":"Florian","family":"Tram\u00e8r","sequence":"additional","affiliation":[{"name":"ETH Zurich, Z\u00fcrich, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Deep Learning with Differential Privacy. In ACM SIGSAC Conference on Computer and Communications Security. ACM, 308--318","author":"Abadi Martin","year":"2016","unstructured":"Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep Learning with Differential Privacy. In ACM SIGSAC Conference on Computer and Communications Security. ACM, 308--318."},{"key":"e_1_3_2_1_2_1","volume-title":"International conference on machine learning. PMLR, 274--283","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning. PMLR, 274--283."},{"key":"e_1_3_2_1_3_1","unstructured":"Martin Bertran Shuai Tang Michael Kearns Jamie Morgenstern Aaron Roth and Zhiwei Steven Wu. 2023. Scalable Membership Inference Attacks via Quantile Regression. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"e_1_3_2_1_5_1","volume-title":"No Free Lunch in\" Privacy for Free: How does Dataset Condensation Help Privacy\". arXiv preprint arXiv:2209.14987","author":"Carlini Nicholas","year":"2022","unstructured":"Nicholas Carlini, Vitaly Feldman, and Milad Nasr. 2022. No Free Lunch in\" Privacy for Free: How does Dataset Condensation Help Privacy\". arXiv preprint arXiv:2209.14987 (2022)."},{"key":"e_1_3_2_1_6_1","unstructured":"Nicholas Carlini Matthew Jagielski Chiyuan Zhang Nicolas Papernot Andreas Terzis and Florian Tramer. 2022. The Privacy Onion Effect: Memorization Is Relative. In Advances in Neural Information Processing Systems. 13263--13276."},{"key":"e_1_3_2_1_7_1","volume-title":"USENIX Security Symposium. 267--284","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Chang Liu, \u00dalfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The secret sharer: Evaluating and testing unintended memorization in neural networks. In USENIX Security Symposium. 267--284."},{"key":"e_1_3_2_1_8_1","volume-title":"USENIX Security Symposium.","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al. 2021. Extracting training data from large language models. In USENIX Security Symposium."},{"key":"e_1_3_2_1_9_1","volume-title":"International Conference on Learning Representations.","author":"Chen Dingfan","year":"2022","unstructured":"Dingfan Chen, Ning Yu, and Mario Fritz. 2022. RelaxLoss: Defending Membership Inference Attacks without Losing Utility. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00361"},{"key":"e_1_3_2_1_11_1","volume-title":"International conference on machine learning. 1597--1607","author":"Chen Ting","year":"2020","unstructured":"Ting Chen, Simon Kornblith, Mohammad Norouzi, and Geoffrey Hinton. 2020. A simple framework for contrastive learning of visual representations. In International conference on machine learning. 1597--1607."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23014"},{"key":"e_1_3_2_1_13_1","volume-title":"International Conference on Machine Learning. PMLR","author":"Choquette-Choo Christopher A","year":"2021","unstructured":"Christopher A Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In International Conference on Machine Learning. PMLR, 1964--1974."},{"key":"e_1_3_2_1_14_1","volume-title":"Unlocking high-accuracy differentially private image classification through scale. arXiv preprint arXiv:2204.13650","author":"De Soham","year":"2022","unstructured":"Soham De, Leonard Berrada, Jamie Hayes, Samuel L Smith, and Borja Balle. 2022. Unlocking high-accuracy differentially private image classification through scale. arXiv preprint arXiv:2204.13650 (2022)."},{"key":"e_1_3_2_1_15_1","unstructured":"Damien Desfontaines. 2021. A list of real-world uses of differential privacy. https:\/\/desfontain.es\/privacy\/real-world-differential-privacy.html. Ted is writing things (personal blog)."},{"key":"e_1_3_2_1_16_1","volume-title":"International Conference on Machine Learning. PMLR, 5378--5396","author":"Dong Tian","year":"2022","unstructured":"Tian Dong, Bo Zhao, and Lingjuan Lyu. 2022. Privacy for free: How does dataset condensation help privacy?. In International Conference on Machine Learning. PMLR, 5378--5396."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i6.20613"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357713.3384290"},{"key":"e_1_3_2_1_20_1","volume-title":"Privacy Backdoors: Stealing Data with Corrupted Pretrained Models. arXiv preprint arXiv:2404.00473","author":"Feng Shanglun","year":"2024","unstructured":"Shanglun Feng and Florian Tram\u00e8r. 2024. Privacy Backdoors: Stealing Data with Corrupted Pretrained Models. arXiv preprint arXiv:2404.00473 (2024)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475329"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"e_1_3_2_1_24_1","volume-title":"Deep Residual Learning for Image Recognition. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484571"},{"key":"e_1_3_2_1_26_1","volume-title":"Measuring Forgetting of Memorized Training Examples. In The Eleventh International Conference on Learning Representations.","author":"Jagielski Matthew","year":"2022","unstructured":"Matthew Jagielski, Om Thakkar, Florian Tramer, Daphne Ippolito, Katherine Lee, Nicholas Carlini, Eric Wallace, Shuang Song, Abhradeep Guha Thakurta, Nicolas Papernot, and Chiyuan Zhang. 2022. Measuring Forgetting of Memorized Training Examples. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_27_1","first-page":"22205","article-title":"Auditing differentially private machine learning: How private is private sgd","volume":"33","author":"Jagielski Matthew","year":"2020","unstructured":"Matthew Jagielski, Jonathan Ullman, and Alina Oprea. 2020. Auditing differentially private machine learning: How private is private sgd? Advances in Neural Information Processing Systems, Vol. 33 (2020), 22205--22216.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"e_1_3_2_1_29_1","volume-title":"International conference on machine learning. PMLR, 1376--1385","author":"Kairouz Peter","year":"2015","unstructured":"Peter Kairouz, Sewoong Oh, and Pramod Viswanath. 2015. The composition theorem for differential privacy. In International conference on machine learning. PMLR, 1376--1385."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2024-0031"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00449"},{"key":"e_1_3_2_1_32_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3381477"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484749"},{"key":"e_1_3_2_1_35_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Liu Yugeng","year":"2022","unstructured":"Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2022. ML-Doctor: Holistic risk assessment of inference attacks against machine learning models. In 31st USENIX Security Symposium (USENIX Security 22). 4525--4542."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00040"},{"key":"e_1_3_2_1_37_1","volume-title":"Data-free knowledge distillation for deep neural networks. arXiv preprint arXiv:1710.07535","author":"Lopes Raphael Gontijo","year":"2017","unstructured":"Raphael Gontijo Lopes, Stefano Fenu, and Thad Starner. 2017. Data-free knowledge distillation for deep neural networks. arXiv preprint arXiv:1710.07535 (2017)."},{"key":"e_1_3_2_1_38_1","volume-title":"International Conference on Learning Representations.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_39_1","volume-title":"Identifying Mislabeled Instances in Classification Datasets. In 2019 International Joint Conference on Neural Networks (IJCNN). 1--8.","author":"Nicolas","unstructured":"Nicolas M. M\u00fcller and Karla Markert. 2019. Identifying Mislabeled Instances in Classification Datasets. In 2019 International Joint Conference on Neural Networks (IJCNN). 1--8."},{"key":"e_1_3_2_1_40_1","volume-title":"Tight Auditing of Differentially Private Machine Learning. In USENIX Security Symposium. 1631--1648","author":"Nasr Milad","year":"2023","unstructured":"Milad Nasr, Jamie Hayes, Thomas Steinke, Borja Balle, Florian Tram\u00e8r, Matthew Jagielski, Nicholas Carlini, and Andreas Terzis. 2023. Tight Auditing of Differentially Private Machine Learning. In USENIX Security Symposium. 1631--1648."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243855"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00069"},{"key":"e_1_3_2_1_44_1","unstructured":"Curtis G. Northcutt Anish Athalye and Jonas Mueller. 2021. Pervasive Label Errors in Test Sets Destabilize Machine Learning Benchmarks. In Neural Information Processing Systems Datasets and Benchmarks Track."},{"key":"e_1_3_2_1_45_1","volume-title":"International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=HkwoSDPgg","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot, Mart\u00edn Abadi, \u00dalfar Erlingsson, Ian Goodfellow, and Kunal Talwar. 2017. Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=HkwoSDPgg"},{"key":"e_1_3_2_1_46_1","unstructured":"Krishna Pillutla Galen Andrew Peter Kairouz H. Brendan McMahan Alina Oprea and Sewoong Oh. 2023. Unleashing the Power of Randomization in Auditing Differentially Private ML. In Advances in Neural Information Processing Systems. 66201--66238."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML59370.2024.00014"},{"key":"e_1_3_2_1_48_1","volume-title":"International Conference on Machine Learning. PMLR, 5558--5567","author":"Sablayrolles Alexandre","year":"2019","unstructured":"Alexandre Sablayrolles, Matthijs Douze, Cordelia Schmid, Yann Ollivier, and Herv\u00e9 J\u00e9gou. 2019. White-box vs black-box: Bayes optimal strategies for membership inference. In International Conference on Machine Learning. PMLR, 5558--5567."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.60882\/cispa.24612846.v1"},{"key":"e_1_3_2_1_50_1","volume-title":"Proceedings of the International Conference on Machine Learning","volume":"202","author":"Sander Tom","year":"2023","unstructured":"Tom Sander, Pierre Stock, and Alexandre Sablayrolles. 2023. TAN without a Burn: Scaling Laws of DP-SGD. In Proceedings of the International Conference on Machine Learning, Vol. 202. 29937--29949."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_52_1","unstructured":"Adam D. Smith. 2020. Lectures 9 and 10. https:\/\/drive.google.com\/file\/d\/1M_GfjspEV2oaAuANKn2NJPYTDm1Mek0q\/view."},{"key":"e_1_3_2_1_53_1","unstructured":"Thomas Steinke Milad Nasr and Matthew Jagielski. 2023. Privacy Auditing with One (1) Training Run. In Advances in Neural Information Processing Systems. 49268--49280."},{"key":"e_1_3_2_1_54_1","unstructured":"Thomas Steinke and Jonathan Ullman. 2020. The Pitfalls of Average-Case Differential Privacy. DifferentialPrivacy.org. https:\/\/differentialprivacy.org\/average-case-dp\/."},{"key":"e_1_3_2_1_55_1","volume-title":"USENIX Security Symposium. 1433--1450","author":"Tang Xinyu","year":"2022","unstructured":"Xinyu Tang, Saeed Mahloujifar, Liwei Song, Virat Shejwalkar, Milad Nasr, Amir Houmansadr, and Prateek Mittal. 2022. Mitigating Membership Inference Attacks by Self-Distillation Through a Novel Ensemble Architecture. In USENIX Security Symposium. 1433--1450."},{"key":"e_1_3_2_1_56_1","volume-title":"International Conference on Learning Representations.","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer and Dan Boneh. 2020. Differentially Private Learning Needs Better Features (or Much More Data). In International Conference on Learning Representations."},{"key":"e_1_3_2_1_57_1","volume-title":"On adaptive attacks to adversarial example defenses. Advances in neural information processing systems","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. Advances in neural information processing systems, Vol. 33 (2020), 1633--1645."},{"key":"e_1_3_2_1_58_1","volume-title":"Ensemble Adversarial Training: Attacks and Defenses. In International Conference on Learning Representations.","author":"Tram\u00e8r Florian","year":"2018","unstructured":"Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2018. Ensemble Adversarial Training: Attacks and Defenses. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560554"},{"key":"e_1_3_2_1_60_1","volume-title":"Debugging differential privacy: A case study for privacy auditing. arXiv preprint arXiv:2202.12219","author":"Tramer Florian","year":"2022","unstructured":"Florian Tramer, Andreas Terzis, Thomas Steinke, Shuang Song, Matthew Jagielski, and Nicholas Carlini. 2022. Debugging differential privacy: A case study for privacy auditing. arXiv preprint arXiv:2202.12219 (2022)."},{"key":"e_1_3_2_1_61_1","volume-title":"Memorization in Self-Supervised Learning Improves Downstream Generalization. In The Twelfth International Conference on Learning Representations.","author":"Wang Wenhao","year":"2024","unstructured":"Wenhao Wang, Muhammad Ahmad Kaleem, Adam Dziedzic, Michael Backes, Nicolas Papernot, and Franziska Boenisch. 2024. Memorization in Self-Supervised Learning Improves Downstream Generalization. In The Twelfth International Conference on Learning Representations."},{"key":"e_1_3_2_1_62_1","volume-title":"On the Importance of Difficulty Calibration in Membership Inference Attacks. In International Conference on Learning Representations.","author":"Watson Lauren","year":"2021","unstructured":"Lauren Watson, Chuan Guo, Graham Cormode, and Alexandre Sablayrolles. 2021. On the Importance of Difficulty Calibration in Membership Inference Attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_63_1","volume-title":"The Eleventh International Conference on Learning Representations.","author":"Wen Yuxin","year":"2022","unstructured":"Yuxin Wen, Arpit Bansal, Hamid Kazemi, Eitan Borgnia, Micah Goldblum, Jonas Geiping, and Tom Goldstein. 2022. Canary in a Coalmine: Better Membership Inference with Ensembled Adversarial Queries. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_64_1","volume-title":"Defending Model Inversion and Membership Inference Attacks via Prediction Purification. arxiv","author":"Yang Ziqi","year":"2005","unstructured":"Ziqi Yang, Bin Shao, Bohan Xuan, Ee-Chien Chang, and Fan Zhang. 2020. Defending Model Inversion and Membership Inference Attacks via Prediction Purification. arxiv: 2005.03915 [cs.CR]"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560675"},{"key":"e_1_3_2_1_66_1","volume-title":"Privacy risk in machine learning: Analyzing the connection to overfitting. In 2018 IEEE 31st computer security foundations symposium (CSF)","author":"Yeom Samuel","unstructured":"Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018. Privacy risk in machine learning: Analyzing the connection to overfitting. In 2018 IEEE 31st computer security foundations symposium (CSF). IEEE, 268--282."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"e_1_3_2_1_68_1","volume-title":"Opacus: User-Friendly Differential Privacy Library in PyTorch. arXiv preprint arXiv:2109.12298","author":"Yousefpour Ashkan","year":"2021","unstructured":"Ashkan Yousefpour, Igor Shilov, Alexandre Sablayrolles, Davide Testuggine, Karthik Prasad, Mani Malek, John Nguyen, Sayan Ghosh, Akash Bharadwaj, Jessica Zhao, Graham Cormode, and Ilya Mironov. 2021. Opacus: User-Friendly Differential Privacy Library in PyTorch. arXiv preprint arXiv:2109.12298 (2021)."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"crossref","unstructured":"Sergey Zagoruyko and Nikos Komodakis. 2016. Wide Residual Networks. In BMVC.","DOI":"10.5244\/C.30.87"},{"key":"e_1_3_2_1_70_1","unstructured":"Sajjad Zarifzadeh Philippe Liu and Reza Shokri. 2024. Low-Cost High-Power Membership Inference Attacks. arxiv: 2312.03262 [cs stat]"},{"key":"e_1_3_2_1_71_1","first-page":"21414","article-title":"Dense: Data-free one-shot federated learning","volume":"35","author":"Zhang Jie","year":"2022","unstructured":"Jie Zhang, Chen Chen, Bo Li, Lingjuan Lyu, Shuang Wu, Shouhong Ding, Chunhua Shen, and Chao Wu. 2022. Dense: Data-free one-shot federated learning. Advances in Neural Information Processing Systems, Vol. 35 (2022), 21414--21428.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_72_1","volume-title":"The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=ConT6H7MWL","author":"Zhang Jie","year":"2023","unstructured":"Jie Zhang, Chen Chen, and Lingjuan Lyu. 2023. IDEAL: Query-Efficient Data-Free Learning from Black-Box Models. In The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=ConT6H7MWL"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"crossref","unstructured":"Xinbin Zhang. 2017. An Improved Method of Identifying Mislabeled Data and the Mislabeled Data in MNIST and CIFAR-10.","DOI":"10.2139\/ssrn.3080736"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690194","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690194","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T05:53:32Z","timestamp":1755842012000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690194"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":73,"alternative-id":["10.1145\/3658644.3690194","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690194","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}