{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,27]],"date-time":"2026-06-27T16:09:24Z","timestamp":1782576564696,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":57,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T00:00:00Z","timestamp":1763769600000},"content-version":"vor","delay-in-days":3,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science Foundation Graduate Research Fellowship Program","award":["CNS-2247484, CNS-2131910"],"award-info":[{"award-number":["CNS-2247484, CNS-2131910"]}]},{"name":"National Artificial Intelligence Research Resource","award":["NAIRR 240392"],"award-info":[{"award-number":["NAIRR 240392"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3744840","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:32:38Z","timestamp":1763854358000},"page":"1245-1259","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":4,"title":["Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented Generation"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-7423-6538","authenticated-orcid":false,"given":"Ali","family":"Naseh","sequence":"first","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-1551-0642","authenticated-orcid":false,"given":"Yuefeng","family":"Peng","sequence":"additional","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4846-0797","authenticated-orcid":false,"given":"Anshuman","family":"Suri","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-0430-2025","authenticated-orcid":false,"given":"Harsh","family":"Chaudhari","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4979-5292","authenticated-orcid":false,"given":"Alina","family":"Oprea","sequence":"additional","affiliation":[{"name":"Northeastern University, Boston, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7553-6657","authenticated-orcid":false,"given":"Amir","family":"Houmansadr","sequence":"additional","affiliation":[{"name":"University of Massachusetts Amherst, Amherst, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Marah Abdin Jyoti Aneja Harkirat Behl S\u00e9bastien Bubeck Ronen Eldan Suriya Gunasekar Michael Harrison Russell J Hewett Mojan Javaheripi Piero Kauffmann et al. 2024. Phi-4 technical report. arXiv preprint arXiv:2412.08905 (2024)."},{"key":"e_1_3_2_1_2_1","volume-title":"Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation. arXiv preprint arXiv:2405.20446","author":"Anderson Maya","year":"2024","unstructured":"Maya Anderson, Guy Amit, and Abigail Goldsteen. 2024. Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation. arXiv preprint arXiv:2405.20446 (2024)."},{"key":"e_1_3_2_1_3_1","unstructured":"Alina Beck. 2025. Raising the bar for RAG excellence: query rewriting and new semantic ranker. https:\/\/techcommunity.microsoft.com\/blog\/azure-ai-services-blog\/raising-the-bar-for-rag-excellence-query-rewriting-and-new-semantic-ranker\/4302729\/. Accessed: 2025-01-07."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"e_1_3_2_1_5_1","volume-title":"USENIX Security Symposium. 2633-2650","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al., 2021. Extracting training data from large language models. In USENIX Security Symposium. 2633-2650."},{"key":"e_1_3_2_1_6_1","volume-title":"Phantom: General Trigger Attacks on Retrieval Augmented Language Generation. arXiv preprint arXiv:2405.20485","author":"Chaudhari Harsh","year":"2024","unstructured":"Harsh Chaudhari, Giorgio Severi, John Abascal, Matthew Jagielski, Christopher A Choquette-Choo, Milad Nasr, Cristina Nita-Rotaru, and Alina Oprea. 2024. Phantom: General Trigger Attacks on Retrieval Augmented Language Generation. arXiv preprint arXiv:2405.20485 (2024)."},{"key":"e_1_3_2_1_7_1","volume-title":"Unleashing worms and extracting data: Escalating the outcome of attacks against rag-based inference in scale and severity using jailbreaking. arXiv preprint arXiv:2409.08045","author":"Cohen Stav","year":"2024","unstructured":"Stav Cohen, Ron Bitton, and Ben Nassi. 2024. Unleashing worms and extracting data: Escalating the outcome of attacks against rag-based inference in scale and severity using jailbreaking. arXiv preprint arXiv:2409.08045 (2024)."},{"key":"e_1_3_2_1_8_1","volume-title":"The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=gmL46YMpu2J","author":"Dai Zhuyun","year":"2023","unstructured":"Zhuyun Dai, Vincent Y Zhao, Ji Ma, Yi Luan, Jianmo Ni, Jing Lu, Anton Bakalov, Kelvin Guu, Keith Hall, and Ming-Wei Chang. 2023. Promptagator: Few-shot Dense Retrieval From 8 Examples. In The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=gmL46YMpu2J"},{"key":"e_1_3_2_1_9_1","volume-title":"Blind baselines beat membership inference attacks for foundation models. arXiv preprint arXiv:2406.16201","author":"Das Debeshee","year":"2024","unstructured":"Debeshee Das, Jie Zhang, and Florian Tram\u00e8r. 2024. Blind baselines beat membership inference attacks for foundation models. arXiv preprint arXiv:2406.16201 (2024)."},{"key":"e_1_3_2_1_10_1","volume-title":"Building guardrails for large language models. arXiv preprint arXiv:2402.01822","author":"Dong Yi","year":"2024","unstructured":"Yi Dong, Ronghui Mu, Gaojie Jin, Yi Qi, Jinwei Hu, Xingyu Zhao, Jie Meng, Wenjie Ruan, and Xiaowei Huang. 2024. Building guardrails for large language models. arXiv preprint arXiv:2402.01822 (2024)."},{"key":"e_1_3_2_1_11_1","volume-title":"On the privacy risk of in-context learning. arXiv preprint arXiv:2411.10512","author":"Duan Haonan","year":"2024","unstructured":"Haonan Duan, Adam Dziedzic, Mohammad Yaghini, Nicolas Papernot, and Franziska Boenisch. 2024a. On the privacy risk of in-context learning. arXiv preprint arXiv:2411.10512 (2024)."},{"key":"e_1_3_2_1_12_1","volume-title":"International Conference on Machine Learning. PMLR, 8717-8730","author":"Duan Jinhao","year":"2023","unstructured":"Jinhao Duan, Fei Kong, Shiqi Wang, Xiaoshuang Shi, and Kaidi Xu. 2023. Are diffusion models vulnerable to membership inference attacks?. In International Conference on Machine Learning. PMLR, 8717-8730."},{"key":"e_1_3_2_1_13_1","volume-title":"Conference on Language Modeling (COLM).","author":"Duan Michael","year":"2024","unstructured":"Michael Duan, Anshuman Suri, Niloofar Mireshghallah, Sewon Min, Weijia Shi, Luke Zettlemoyer, Yulia Tsvetkov, Yejin Choi, David Evans, and Hannaneh Hajishirzi. 2024b. Do Membership Inference Attacks Work on Large Language Models?. In Conference on Language Modeling (COLM)."},{"key":"e_1_3_2_1_14_1","unstructured":"Abhimanyu Dubey Abhinav Jauhri Abhinav Pandey Abhishek Kadian Ahmad Al-Dahle Aiesha Letman Akhil Mathur Alan Schelten Amy Yang Angela Fan et al. 2024. The llama 3 herd of models. arXiv preprint arXiv:2407.21783 (2024)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P18-2006"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.52202\/079017-4290"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-28238-6_31"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670370"},{"key":"e_1_3_2_1_19_1","volume-title":"Baseline defenses for adversarial attacks against aligned language models. arXiv preprint arXiv:2309.00614","author":"Jain Neel","year":"2023","unstructured":"Neel Jain, Avi Schwarzschild, Yuxin Wen, Gowthami Somepalli, John Kirchenbauer, Ping-yeh Chiang, Micah Goldblum, Aniruddha Saha, Jonas Geiping, and Tom Goldstein. 2023. Baseline defenses for adversarial attacks against aligned language models. arXiv preprint arXiv:2309.00614 (2023)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3571730"},{"key":"e_1_3_2_1_21_1","volume-title":"RAG-Thief: Scalable Extraction of Private Data from Retrieval-Augmented Generation Applications with Agent-based Attacks. arXiv preprint arXiv:2411.14110","author":"Jiang Changyue","year":"2024","unstructured":"Changyue Jiang, Xudong Pan, Geng Hong, Chenfu Bao, and Min Yang. 2024. RAG-Thief: Scalable Extraction of Private Data from Retrieval-Augmented Generation Applications with Agent-based Attacks. arXiv preprint arXiv:2411.14110 (2024)."},{"key":"e_1_3_2_1_22_1","volume-title":"The Thirteenth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=kVrwHLAb20","author":"Jovanovi\u0107 Nikola","year":"2025","unstructured":"Nikola Jovanovi\u0107, Robin Staab, Maximilian Baader, and Martin Vechev. 2025. Ward: Provable RAG Dataset Inference via LLM Watermarks. In The Thirteenth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=kVrwHLAb20"},{"key":"e_1_3_2_1_23_1","unstructured":"Patrick Lewis Ethan Perez Aleksandra Piktus Fabio Petroni Vladimir Karpukhin Naman Goyal Heinrich K\u00fcttler Mike Lewis Wen-tau Yih Tim Rockt\u00e4schel et al. 2020. Retrieval-augmented generation for knowledge-intensive nlp tasks. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_1_24_1","volume-title":"InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models. arXiv preprint arXiv:2410.22770","author":"Li Hao","year":"2024","unstructured":"Hao Li, Xiaogeng Liu, and Chaowei Xiao. 2024b. InjecGuard: Benchmarking and Mitigating Over-defense in Prompt Injection Guardrail Models. arXiv preprint arXiv:2410.22770 (2024)."},{"key":"e_1_3_2_1_25_1","volume-title":"Benchmarking Bias in Large Language Models during Role-Playing. arXiv preprint arXiv:2411.00585","author":"Li Xinyue","year":"2024","unstructured":"Xinyue Li, Zhenpeng Chen, Jie M Zhang, Yiling Lou, Tianlin Li, Weisong Sun, Yang Liu, and Xuanzhe Liu. 2024a. Benchmarking Bias in Large Language Models during Role-Playing. arXiv preprint arXiv:2411.00585 (2024)."},{"key":"e_1_3_2_1_26_1","volume-title":"Generating Is Believing: Membership Inference Attacks against Retrieval-Augmented Generation. arXiv preprint arXiv:2406.19234","author":"Li Yuying","year":"2024","unstructured":"Yuying Li, Gaoyang Liu, Chen Wang, and Yang Yang. 2024c. Generating Is Believing: Membership Inference Attacks against Retrieval-Augmented Generation. arXiv preprint arXiv:2406.19234 (2024)."},{"key":"e_1_3_2_1_27_1","volume-title":"Towards general text embeddings with multi-stage contrastive learning. arXiv preprint arXiv:2308.03281","author":"Li Zehan","year":"2023","unstructured":"Zehan Li, Xin Zhang, Yanzhao Zhang, Dingkun Long, Pengjun Xie, and Meishan Zhang. 2023. Towards general text embeddings with multi-stage contrastive learning. arXiv preprint arXiv:2308.03281 (2023)."},{"key":"e_1_3_2_1_28_1","volume-title":"Conversational question reformulation via sequence-to-sequence architectures and pretrained language models. arXiv preprint arXiv:2004.01909","author":"Lin Sheng-Chieh","year":"2020","unstructured":"Sheng-Chieh Lin, Jheng-Hong Yang, Rodrigo Nogueira, Ming-Feng Tsai, Chuan-Ju Wang, and Jimmy Lin. 2020. Conversational question reformulation via sequence-to-sequence architectures and pretrained language models. arXiv preprint arXiv:2004.01909 (2020)."},{"key":"e_1_3_2_1_29_1","volume-title":"Mask-based Membership Inference Attacks for Retrieval-Augmented Generation. arXiv preprint arXiv:2410.20142","author":"Liu Mingrui","year":"2024","unstructured":"Mingrui Liu, Sixiao Zhang, and Cheng Long. 2024b. Mask-based Membership Inference Attacks for Retrieval-Augmented Generation. arXiv preprint arXiv:2410.20142 (2024)."},{"key":"e_1_3_2_1_30_1","volume-title":"USENIX Security Symposium.","author":"Liu Yupei","year":"2024","unstructured":"Yupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia, and Neil Zhenqiang Gong. 2024a. Formalizing and benchmarking prompt injection attacks and defenses. In USENIX Security Symposium."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.emnlp-main.322"},{"key":"e_1_3_2_1_32_1","volume-title":"LLM Dataset Inference: Did you train on my dataset? arXiv preprint arXiv:2406.06443","author":"Maini Pratyush","year":"2024","unstructured":"Pratyush Maini, Hengrui Jia, Nicolas Papernot, and Adam Dziedzic. 2024. LLM Dataset Inference: Did you train on my dataset? arXiv preprint arXiv:2406.06443 (2024)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.findings-acl.719"},{"key":"e_1_3_2_1_34_1","volume-title":"SoK: Membership Inference Attacks on LLMs are Rushing Nowhere (and How to Fix It). arXiv preprint arXiv:2406.17975","author":"Meeus Matthieu","year":"2024","unstructured":"Matthieu Meeus, Igor Shilov, Shubham Jain, Manuel Faysse, Marek Rei, and Yves-Alexandre de Montjoye. 2024. SoK: Membership Inference Attacks on LLMs are Rushing Nowhere (and How to Fix It). arXiv preprint arXiv:2406.17975 (2024)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.274"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_1_37_1","volume-title":"Document expansion by query prediction. arXiv preprint arXiv:1904.08375","author":"Nogueira Rodrigo","year":"2019","unstructured":"Rodrigo Nogueira, Wei Yang, Jimmy Lin, and Kyunghyun Cho. 2019. Document expansion by query prediction. arXiv preprint arXiv:1904.08375 (2019)."},{"key":"e_1_3_2_1_38_1","volume-title":"International Conference on Learning Representations.","author":"Oren Yonatan","year":"2023","unstructured":"Yonatan Oren, Nicole Meister, Niladri Chatterji, Faisal Ladhak, and Tatsunori B Hashimoto. 2023. Proving test set contamination in black box language models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_39_1","volume-title":"Data Extraction Attacks in Retrieval-Augmented Generation via Backdoors. arXiv preprint arXiv:2411.01705","author":"Peng Yuefeng","year":"2024","unstructured":"Yuefeng Peng, Junda Wang, Hong Yu, and Amir Houmansadr. 2024. Data Extraction Attacks in Retrieval-Augmented Generation via Backdoors. arXiv preprint arXiv:2411.01705 (2024)."},{"key":"e_1_3_2_1_40_1","volume-title":"Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527","author":"Perez F\u00e1bio","year":"2022","unstructured":"F\u00e1bio Perez and Ian Ribeiro. 2022. Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527 (2022)."},{"key":"e_1_3_2_1_41_1","volume-title":"Scaling Up Membership Inference: When and How Attacks Succeed on Large Language Models. arXiv preprint arXiv:2411.00154","author":"Puerto Haritz","year":"2024","unstructured":"Haritz Puerto, Martin Gubri, Sangdoo Yun, and Seong Joon Oh. 2024. Scaling Up Membership Inference: When and How Attacks Succeed on Large Language Models. arXiv preprint arXiv:2411.00154 (2024)."},{"key":"e_1_3_2_1_42_1","volume-title":"Follow My Instruction and Spill the Beans: Scalable Data Extraction from Retrieval-Augmented Generation Systems. arXiv preprint arXiv:2402.17840","author":"Qi Zhenting","year":"2024","unstructured":"Zhenting Qi, Hanlin Zhang, Eric Xing, Sham Kakade, and Himabindu Lakkaraju. 2024. Follow My Instruction and Spill the Beans: Scalable Data Extraction from Retrieval-Augmented Generation Systems. arXiv preprint arXiv:2402.17840 (2024)."},{"key":"e_1_3_2_1_43_1","unstructured":"Lianhui Qin Sean Welleck Daniel Khashabi and Yejin Choi. 2022. Cold decoding: Energy-based constrained text generation with langevin dynamics. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_1_44_1","volume-title":"International Conference on Machine Learning. PMLR, 5558-5567","author":"Sablayrolles Alexandre","year":"2019","unstructured":"Alexandre Sablayrolles, Matthijs Douze, Cordelia Schmid, Yann Ollivier, and Herv\u00e9 J\u00e9gou. 2019. White-box vs black-box: Bayes optimal strategies for membership inference. In International Conference on Machine Learning. PMLR, 5558-5567."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-main.346"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_47_1","volume-title":"Do Parameters Reveal More than Loss for Membership Inference? Transactions on Machine Learning Research (TMLR)","author":"Suri Anshuman","year":"2024","unstructured":"Anshuman Suri, Xiao Zhang, and David Evans. 2024. Do Parameters Reveal More than Loss for Membership Inference? Transactions on Machine Learning Research (TMLR) (2024). https:\/\/arxiv.org\/abs\/2406.11544"},{"key":"e_1_3_2_1_48_1","volume-title":"Cassidy Hardin, Surya Bhupatiraju, L\u00e9onard Hussenot, Thomas Mesnard, Bobak Shahriari, Alexandre Ram\u00e9, et al.","author":"Team Gemma","year":"2024","unstructured":"Gemma Team, Morgane Riviere, Shreya Pathak, Pier Giuseppe Sessa, Cassidy Hardin, Surya Bhupatiraju, L\u00e9onard Hussenot, Thomas Mesnard, Bobak Shahriari, Alexandre Ram\u00e9, et al., 2024. Gemma 2: Improving open language models at a practical size. arXiv preprint arXiv:2408.00118 (2024)."},{"key":"e_1_3_2_1_49_1","volume-title":"Beir: A heterogenous benchmark for zero-shot evaluation of information retrieval models. arXiv preprint arXiv:2104.08663","author":"Thakur Nandan","year":"2021","unstructured":"Nandan Thakur, Nils Reimers, Andreas R\u00fcckl\u00e9, Abhishek Srivastava, and Iryna Gurevych. 2021. Beir: A heterogenous benchmark for zero-shot evaluation of information retrieval models. arXiv preprint arXiv:2104.08663 (2021)."},{"key":"e_1_3_2_1_50_1","volume-title":"MaFeRw: Query Rewriting with Multi-Aspect Feedbacks for Retrieval-Augmented Large Language Models. arXiv preprint arXiv:2408.17072","author":"Wang Yujing","year":"2024","unstructured":"Yujing Wang, Hainan Zhang, Liang Pang, Hongwei Zheng, and Zhiming Zheng. 2024b. MaFeRw: Query Rewriting with Multi-Aspect Feedbacks for Retrieval-Augmented Large Language Models. arXiv preprint arXiv:2408.17072 (2024)."},{"key":"e_1_3_2_1_51_1","volume-title":"Membership Inference Attack against Long-Context Large Language Models. arXiv preprint arXiv:2411.11424","author":"Wang Zixiong","year":"2024","unstructured":"Zixiong Wang, Gaoyang Liu, Yang Yang, and Chen Wang. 2024a. Membership Inference Attack against Long-Context Large Language Models. arXiv preprint arXiv:2411.11424 (2024)."},{"key":"e_1_3_2_1_52_1","volume-title":"On the Importance of Difficulty Calibration in Membership Inference Attacks. In International Conference on Learning Representations.","author":"Watson Lauren","year":"2022","unstructured":"Lauren Watson, Chuan Guo, Graham Cormode, and Alexandre Sablayrolles. 2022. On the Importance of Difficulty Calibration in Membership Inference Attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_53_1","volume-title":"Jailbroken: How does llm safety training fail?. In Advances in Neural Information Processing Systems.","author":"Wei Alexander","year":"2024","unstructured":"Alexander Wei, Nika Haghtalab, and Jacob Steinhardt. 2024. Jailbroken: How does llm safety training fail?. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_1_54_1","unstructured":"An Yang Baosong Yang Beichen Zhang Binyuan Hui Bo Zheng Bowen Yu Chengyuan Li Dayiheng Liu Fei Huang Haoran Wei et al. 2024. Qwen2. 5 Technical Report. arXiv preprint arXiv:2412.15115 (2024)."},{"key":"e_1_3_2_1_55_1","volume-title":"Low-Cost High-Power Membership Inference Attacks. In International Conference on Machine Learning.","author":"Zarifzadeh Sajjad","year":"2024","unstructured":"Sajjad Zarifzadeh, Philippe Liu, and Reza Shokri. 2024. Low-Cost High-Power Membership Inference Attacks. In International Conference on Machine Learning."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"crossref","unstructured":"Shenglai Zeng Jiankun Zhang Pengfei He Yue Xing Yiding Liu Han Xu Jie Ren Shuaiqiang Wang Dawei Yin Yi Chang et al. 2024. The good and the bad: Exploring privacy issues in retrieval-augmented generation (rag). arXiv preprint arXiv:2402.16893 (2024).","DOI":"10.18653\/v1\/2024.findings-acl.267"},{"key":"e_1_3_2_1_57_1","volume-title":"Retrieve anything to augment large language models. arXiv preprint arXiv:2310.07554","author":"Zhang Peitian","year":"2023","unstructured":"Peitian Zhang, Shitao Xiao, Zheng Liu, Zhicheng Dou, and Jian-Yun Nie. 2023. Retrieve anything to augment large language models. arXiv preprint arXiv:2310.07554 (2023)."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744840","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744840","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:08:51Z","timestamp":1766441331000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3744840"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":57,"alternative-id":["10.1145\/3719027.3744840","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3744840","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}