{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T01:04:07Z","timestamp":1760058247212,"version":"build-2065373602"},"reference-count":56,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,3,20]],"date-time":"2025-03-20T00:00:00Z","timestamp":1742428800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]},{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]},{"name":"Major Key Project of PCL","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]},{"name":"Shenzhen Science and Technology Program","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]},{"name":"Project of Guangdong Power Grid Co., Ltd.","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]},{"name":"China Postdoctoral Science Foundation","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]},{"name":"National Natural Science Foundation of China","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]},{"name":"Shenzhen Colleges and Universities Stable Support Program","award":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"],"award-info":[{"award-number":["2023YFB3106504","2022B1212010005","PCL2023A09","PCL2024A04","ZDSYS20210623091809029","RCBS20221008093131089","037800KC23090005","GDKJXM20231042","2024M751555","62301190","GXWD20231129135251001"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>In this paper, we propose a method, namely Goalie, to defend against the correlated value and sign encoding attacks used to steal shared data from data trusts. Existing methods prevent these attacks by perturbing model parameters, gradients, or training data while significantly degrading model performance. To guarantee the performance of the benign models, Goalie detects the malicious models and stops their training. The key insight of detection is that encoding additional information in model parameters through regularization terms changes the parameter distributions. Our theoretical analysis suggests that the regularization terms lead to the differences in parameter distributions between benign and malicious models. According to the analysis, Goalie extracts features from the parameters in the early training epochs of the models and uses these features to detect malicious models. The experimental results show the high effectiveness and efficiency of Goalie. The accuracy of Goalie in detecting the models with one regularization term is more than 0.9, and Goalie has high performance in some extreme situations. Meanwhile, Goalie takes only 1.1 ms to detect a model using the features extracted from the first 30 training epochs.<\/jats:p>","DOI":"10.3390\/e27030323","type":"journal-article","created":{"date-parts":[[2025,3,20]],"date-time":"2025-03-20T07:59:54Z","timestamp":1742457594000},"page":"323","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Goalie: Defending Against Correlated Value and Sign Encoding Attacks"],"prefix":"10.3390","volume":"27","author":[{"given":"Rongfei","family":"Zhuang","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen 518055, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7058-2091","authenticated-orcid":false,"given":"Ximing","family":"Fu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen 518055, China"},{"name":"Peng Cheng Laboratory, Shenzhen 518055, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chuanyi","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen 518055, China"},{"name":"Peng Cheng Laboratory, Shenzhen 518055, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peiyi","family":"Han","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen 518055, China"},{"name":"Peng Cheng Laboratory, Shenzhen 518055, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shaoming","family":"Duan","sequence":"additional","affiliation":[{"name":"Peng Cheng Laboratory, Shenzhen 518055, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,3,20]]},"reference":[{"key":"ref_1","unstructured":"O\u2019hara, K. (2024, October 20). Data Trusts: Ethics, Architecture and Governance for Trustworthy Data Stewardship, Available online: https:\/\/eprints.soton.ac.uk\/428276\/1\/WSI_White_Paper_1.pdf."},{"key":"ref_2","unstructured":"Delacroix, S., and Montgomery, J. (2024, October 20). From Research Data Ethics Principles to Practice: Data Trusts as a Governance Tool, Available online: https:\/\/papers.ssrn.com\/sol3\/papers.cfm?abstract_id=3736090."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Song, C., Ristenpart, T., and Shmatikov, V. (November, January 30). Machine learning models that remember too much. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3134077"},{"key":"ref_4","unstructured":"Krizhevsky, A. (2009). Learning Multiple Layers of Features from Tiny Images. [Master\u2019s Thesis, University of Toronto]."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Abadi, M., Chu, A., Goodfellow, I., McMahan, H.B., Mironov, I., Talwar, K., and Zhang, L. (2016, January 24\u201328). Deep learning with differential privacy. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978318"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Golatkar, A., Achille, A., and Soatto, S. (2020, January 14\u201319). Eternal sunshine of the spotless net: Selective forgetting in deep networks. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00932"},{"key":"ref_7","unstructured":"Zhang, T., He, Z., and Lee, R.B. (2018). Privacy-preserving machine learning through data obfuscation. arXiv."},{"key":"ref_8","unstructured":"Jia, J., and Gong, N.Z. (2018, January 15\u201317). Attriguard: A practical defense against attribute inference attacks via adversarial machine learning. Proceedings of the USENIX Security Symposium, Baltimore, MD, USA."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1351","DOI":"10.1109\/TC.2015.2470255","article-title":"Privacy Preserving Deep Computation Model on Cloud for Big Data Feature Learning","volume":"65","author":"Zhang","year":"2016","journal-title":"IEEE Trans. Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"467","DOI":"10.1109\/TDSC.2013.51","article-title":"Privacy-preserving multi-class support vector machine for outsourcing the data classification in cloud","volume":"11","author":"Rahulamathavan","year":"2013","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"81","DOI":"10.1049\/iet-bmt.2017.0083","article-title":"Strengths and weaknesses of deep learning models for face recognition against image degradations","volume":"7","author":"Grm","year":"2017","journal-title":"IET Biom."},{"key":"ref_12","unstructured":"Dodge, S., and Karam, L. (August, January 31). A study and comparison of human and deep learning recognition performance under visual distortions. Proceedings of the International Conference on Computer Communication and Networks (ICCCN), Vancouver, BC, Canada."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"275","DOI":"10.1007\/s10462-010-9156-z","article-title":"A study of the effect of different types of noise on the precision of supervised learning techniques","volume":"33","author":"Nettleton","year":"2010","journal-title":"Artif. Intell. Rev."},{"key":"ref_14","unstructured":"Liu, J., Lu, Y.H., and Koh, C.K. (2010). Performance Analysis of Arithmetic Operations in Homomorphic Encryption, Purdue University. Technical Report."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition Workshops, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"405","DOI":"10.1146\/annurev-statistics-030718-104938","article-title":"Statistical Aspects of Wasserstein Distances","volume":"6","author":"Panaretos","year":"2019","journal-title":"Annu. Rev. Statist. Appl."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1016\/j.aiopen.2021.08.002","article-title":"Pre-trained models: Past, present and future","volume":"2","author":"Han","year":"2021","journal-title":"AI Open"},{"key":"ref_18","unstructured":"Kreyszig, E. (2011). Advanced Engineering Mathematics, Wiley."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Chernick, M.R. (2011). The Essentials of Biostatistics for Physicians, Nurses, and Clinicians, John Wiley & Sons.","DOI":"10.1002\/9781118071953"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1427","DOI":"10.1109\/TETCI.2022.3182415","article-title":"Taking Away Both Model and Data: Remember Training Data by Parameter Combinations","volume":"6","author":"Luo","year":"2022","journal-title":"IEEE Trans. Emerg. Top. Comput. Intell."},{"key":"ref_21","unstructured":"LeCun, Y. (2024, May 15). The MNIST Database of Handwritten Digits. Available online: https:\/\/www.kaggle.com\/datasets\/hojjatk\/mnist-dataset."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Liu, Z., Luo, P., Wang, X., and Tang, X. (2015, January 7\u201313). Deep learning face attributes in the wild. Proceedings of the IEEE International Conference on Computer Vision, Santiago, Chile.","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016). Identity mappings in deep residual networks. Lecture Notes in Computer Science, Springer.","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref_24","unstructured":"Simonyan, K., and Zisserman, A. (2015, January 7\u20139). Very Deep Convolutional Networks for Large-Scale Image Recognition. Proceedings of the 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA."},{"key":"ref_25","unstructured":"Xu, L., Skoularidou, M., Cuesta-Infante, A., and Veeramachaneni, K. (2019, January 8\u201314). Modeling tabular data using conditional GAN. Proceedings of the Neural Information Processing Systems, Vancouver, BC, Canada."},{"key":"ref_26","unstructured":"Huang, G.B., Ramesh, M., Berg, T., and Learned-Miller, E. (2007). Labeled Faces in the Wild: A Database for Studying Face Recognition in Unconstrained Environments, University of Massachusetts. Technical Report 07-49."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"1333","DOI":"10.1109\/TIFS.2017.2787987","article-title":"Privacy-Preserving Deep Learning via Additively Homomorphic Encryption","volume":"13","author":"Phong","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Chu, C., Jiang, L., and Chen, F. (2023, January 17\u201322). CryptoQFL: Quantum Federated Learning on Encrypted Data. Proceedings of the 2023 IEEE International Conference on Quantum Computing and Engineering (QCE), Bellevue, WA, USA.","DOI":"10.1109\/QCE57702.2023.00139"},{"key":"ref_29","unstructured":"Papernot, N., Abadi, M., Erlingsson, \u00da., Goodfellow, I.J., and Talwar, K. (2017, January 24\u201326). Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data. Proceedings of the 5th International Conference on Learning Representations, ICLR 2017, Toulon, France."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Jia, J., Salem, A., Backes, M., Zhang, Y., and Gong, N.Z. (2019, January 11\u201315). Memguard: Defending against black-box membership inference attacks via adversarial examples. Proceedings of the 2019 ACM Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3363201"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"497","DOI":"10.1007\/s10207-022-00646-y","article-title":"Defense against membership inference attack in graph neural networks through graph perturbation","volume":"22","author":"Wang","year":"2023","journal-title":"Int. J. Inf. Sec."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Cao, Y., and Yang, J. (2015, January 17\u201321). Towards making systems forget with machine unlearning. Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2015.35"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., Fritz, M., and Backes, M. (2019, January 24\u201327). ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. Proceedings of the Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2018, January 15\u201319). Machine learning with membership privacy using adversarial regularization. Proceedings of the ACM Conference on Computer and Communications Security, Toronto, ON, Canada.","DOI":"10.1145\/3243734.3243855"},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"111983","DOI":"10.1016\/j.knosys.2024.111983","article-title":"Defending against gradient inversion attacks in federated learning via statistical machine unlearning","volume":"299","author":"Gao","year":"2024","journal-title":"Knowl. Based Syst."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., and Ristenpart, T. (2015, January 12\u201316). Model inversion attacks that exploit confidence information and basic countermeasures. Proceedings of the ACM Conference on Computer and Communications Security, Denver, CO, USA.","DOI":"10.1145\/2810103.2813677"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Yang, Z., Zhang, J., Chang, E.C., and Liang, Z. (2019, January 11\u201315). Neural network inversion in adversarial setting via background knowledge alignment. Proceedings of the ACM Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3354261"},{"key":"ref_38","unstructured":"Salem, A., Bhattacharya, A., Backes, M., Fritz, M., and Zhang, Y. (2020, January 12\u201314). Updates-leak: Data set inference and reconstruction attacks in online learning. Proceedings of the USENIX Security Symposium, Boston, MA, USA."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Jia, R., Pei, H., Wang, W., Li, B., and Song, D. (2020, January 14\u201319). The secret revealer: Generative model-inversion attacks against deep neural networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Zhu, L., and Han, S. (2020). Deep leakage from gradients. Lecture Notes in Computer Science, Springer.","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"ref_41","unstructured":"Hitaj, B., Ateniese, G., and Perez-Cruz, F. (November, January 30). Deep models under the GAN: Information leakage from collaborative deep learning. Proceedings of the ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA."},{"key":"ref_42","unstructured":"Carlini, N., Tram\u00e8r, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., and Erlingsson, \u00da. (2021, January 11\u201313). Extracting Training Data from Large Language Models. Proceedings of the USENIX Security Symposium, Virtual."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Pan, X., Zhang, M., Ji, S., and Yang, M. (2020, January 18\u201321). Privacy risks of general-purpose language models. Proceedings of the IEEE Symposium on Security and Privacy, San Francisco, CA, USA.","DOI":"10.1109\/SP40000.2020.00095"},{"key":"ref_44","unstructured":"Carlini, N., Liu, C., Erlingsson, \u00da., Kos, J., and Song, D. (2019, January 14\u201316). The secret sharer: Evaluating and testing unintended memorization in neural networks. Proceedings of the USENIX Security Symposium, Santa Clara, CA, USA."},{"key":"ref_45","unstructured":"Kariyappa, S., Guo, C., Maeng, K., Xiong, W., Suh, G.E., Qureshi, M.K., and Lee, H.H.S. (2023, January 23\u201329). Cocktail party attack: Breaking aggregation-based privacy in federated learning using independent component analysis. Proceedings of the 40th International Conference on Machine Learning, ICML\u201923, Honolulu, HI, USA."},{"key":"ref_46","unstructured":"Goodfellow, I.J., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A.C., and Bengio, Y. (2014, January 8\u201313). Generative Adversarial Nets. Proceedings of the Advances in Neural Information Processing Systems, Montreal, QC, Canada."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., and Shmatikov, V. (2017, January 22\u201326). Membership inference attacks against machine learning models. Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA.","DOI":"10.1109\/SP.2017.41"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Song, L., Shokri, R., and Mittal, P. (2019, January 11\u201315). Privacy risks of securing machine learning models against adversarial examples. Proceedings of the ACM Conference on Computer and Communications Security, London, UK.","DOI":"10.1145\/3319535.3354211"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2019, January 19\u201323). Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. Proceedings of the Symposium on Security and Privacy, San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00065"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Melis, L., Song, C., De Cristofaro, E., and Shmatikov, V. (2019, January 19\u201323). Exploiting unintended feature leakage in collaborative learning. Proceedings of the Symposium on Security and Privacy, San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00029"},{"key":"ref_51","unstructured":"Leino, K., and Fredrikson, M. (2020, January 12\u201314). Stolen memories: Leveraging model memorization for calibrated white-box membership inference. Proceedings of the USENIX Security Symposium, Boston, MA, USA."},{"key":"ref_52","unstructured":"Sablayrolles, A., Douze, M., Schmid, C., Ollivier, Y., and J\u00e9gou, H. (2019, January 9\u201315). White-box vs black-box: Bayes optimal strategies for membership inference. Proceedings of the International Conference on Machine Learning, ICML, PMLR, Long Beach, CA, USA."},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"133","DOI":"10.2478\/popets-2019-0008","article-title":"LOGAN: Membership Inference Attacks Against Generative Models","volume":"2019","author":"Hayes","year":"2019","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Liu, K.S., Xiao, C., Li, B., and Gao, J. (2019, January 8\u201311). Performing co-membership attacks against deep generative models. Proceedings of the IEEE International Conference on Data Mining, Beijing, China.","DOI":"10.1109\/ICDM.2019.00056"},{"key":"ref_55","unstructured":"Kingma, D.P., and Welling, M. (2014, January 14\u201316). Auto-Encoding Variational Bayes. Proceedings of the 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Liu, Y., Zhao, Z., Backes, M., and Zhang, Y. (2022, January 7\u201311). Membership Inference Attacks by Exploiting Loss Trajectory. Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, CCS \u201922, New York, NY, USA.","DOI":"10.1145\/3548606.3560684"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/3\/323\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T16:57:13Z","timestamp":1760029033000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/3\/323"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,20]]},"references-count":56,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,3]]}},"alternative-id":["e27030323"],"URL":"https:\/\/doi.org\/10.3390\/e27030323","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2025,3,20]]}}}