{"id":"https://openalex.org/W4402592004","doi":"https://doi.org/10.1007/s11063-024-11682-1","title":"Label-Only Membership Inference Attack Based on Model Explanation","display_name":"Label-Only Membership Inference Attack Based on Model Explanation","publication_year":2024,"publication_date":"2024-09-18","ids":{"openalex":"https://openalex.org/W4402592004","doi":"https://doi.org/10.1007/s11063-024-11682-1"},"language":"en","primary_location":{"id":"doi:10.1007/s11063-024-11682-1","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s11063-024-11682-1","pdf_url":"https://link.springer.com/content/pdf/10.1007/s11063-024-11682-1.pdf","source":{"id":"https://openalex.org/S140962798","display_name":"Neural Processing Letters","issn_l":"1370-4621","issn":["1370-4621","1573-773X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Neural Processing Letters","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/s11063-024-11682-1.pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5045930787","display_name":"Yao Ma","orcid":"https://orcid.org/0000-0001-5932-4868"},"institutions":[{"id":"https://openalex.org/I9086337","display_name":"Taiyuan University of Technology","ror":"https://ror.org/03kv08d37","country_code":"CN","type":"education","lineage":["https://openalex.org/I9086337"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yao Ma","raw_affiliation_strings":["College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China","institution_ids":["https://openalex.org/I9086337"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111330035","display_name":"Xurong Zhai","orcid":null},"institutions":[{"id":"https://openalex.org/I9086337","display_name":"Taiyuan University of Technology","ror":"https://ror.org/03kv08d37","country_code":"CN","type":"education","lineage":["https://openalex.org/I9086337"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xurong Zhai","raw_affiliation_strings":["College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China","institution_ids":["https://openalex.org/I9086337"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107954022","display_name":"Dan Yu","orcid":null},"institutions":[{"id":"https://openalex.org/I9086337","display_name":"Taiyuan University of Technology","ror":"https://ror.org/03kv08d37","country_code":"CN","type":"education","lineage":["https://openalex.org/I9086337"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dan Yu","raw_affiliation_strings":["College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China","institution_ids":["https://openalex.org/I9086337"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100329749","display_name":"Yuli Yang","orcid":"https://orcid.org/0000-0002-6634-5349"},"institutions":[{"id":"https://openalex.org/I9086337","display_name":"Taiyuan University of Technology","ror":"https://ror.org/03kv08d37","country_code":"CN","type":"education","lineage":["https://openalex.org/I9086337"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuli Yang","raw_affiliation_strings":["College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China","institution_ids":["https://openalex.org/I9086337"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035520800","display_name":"Xingyu Wei","orcid":null},"institutions":[{"id":"https://openalex.org/I4210105136","display_name":"Yangtze River Delta Physics Research Center (China)","ror":"https://ror.org/01g53qc72","country_code":"CN","type":"company","lineage":["https://openalex.org/I4210105136"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xingyu Wei","raw_affiliation_strings":["Research Center for Identification and Resolution System, Jiashan in Novation Center, Yangtze Delta Region Institute of Tsinghua University, Zhejiang, 314100, China"],"affiliations":[{"raw_affiliation_string":"Research Center for Identification and Resolution System, Jiashan in Novation Center, Yangtze Delta Region Institute of Tsinghua University, Zhejiang, 314100, China","institution_ids":["https://openalex.org/I4210105136"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5077607914","display_name":"Yongle Chen","orcid":"https://orcid.org/0000-0002-1000-1109"},"institutions":[{"id":"https://openalex.org/I9086337","display_name":"Taiyuan University of Technology","ror":"https://ror.org/03kv08d37","country_code":"CN","type":"education","lineage":["https://openalex.org/I9086337"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yongle Chen","raw_affiliation_strings":["College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Taiyuan University of Technology, Jinzhong, 030600, China","institution_ids":["https://openalex.org/I9086337"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5045930787"],"corresponding_institution_ids":["https://openalex.org/I9086337"],"apc_list":{"value":2390,"currency":"EUR","value_usd":2990},"apc_paid":{"value":2390,"currency":"EUR","value_usd":2990},"fwci":0.7268,"has_fulltext":true,"cited_by_count":2,"citation_normalized_percentile":{"value":0.76319229,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":95,"max":96},"biblio":{"volume":"56","issue":"5","first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9912999868392944,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computational-intelligence","display_name":"Computational intelligence","score":0.7772002816200256},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6019809246063232},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.47773927450180054},{"id":"https://openalex.org/keywords/complex-system","display_name":"Complex system","score":0.4723309874534607},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.40451571345329285}],"concepts":[{"id":"https://openalex.org/C139502532","wikidata":"https://www.wikidata.org/wiki/Q1122090","display_name":"Computational intelligence","level":2,"score":0.7772002816200256},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6019809246063232},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.47773927450180054},{"id":"https://openalex.org/C47822265","wikidata":"https://www.wikidata.org/wiki/Q854457","display_name":"Complex system","level":2,"score":0.4723309874534607},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.40451571345329285}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1007/s11063-024-11682-1","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s11063-024-11682-1","pdf_url":"https://link.springer.com/content/pdf/10.1007/s11063-024-11682-1.pdf","source":{"id":"https://openalex.org/S140962798","display_name":"Neural Processing Letters","issn_l":"1370-4621","issn":["1370-4621","1573-773X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Neural Processing Letters","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1007/s11063-024-11682-1","is_oa":true,"landing_page_url":"https://doi.org/10.1007/s11063-024-11682-1","pdf_url":"https://link.springer.com/content/pdf/10.1007/s11063-024-11682-1.pdf","source":{"id":"https://openalex.org/S140962798","display_name":"Neural Processing Letters","issn_l":"1370-4621","issn":["1370-4621","1573-773X"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Neural Processing Letters","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4402592004.pdf","grobid_xml":"https://content.openalex.org/works/W4402592004.grobid-xml"},"referenced_works_count":19,"referenced_works":["https://openalex.org/W2282821441","https://openalex.org/W2535690855","https://openalex.org/W2603766943","https://openalex.org/W2616247523","https://openalex.org/W2795435272","https://openalex.org/W2963378725","https://openalex.org/W2983140679","https://openalex.org/W3096692244","https://openalex.org/W3102564565","https://openalex.org/W3115278118","https://openalex.org/W3170237968","https://openalex.org/W3208464986","https://openalex.org/W3214437258","https://openalex.org/W4280575929","https://openalex.org/W4285226583","https://openalex.org/W4288057780","https://openalex.org/W4296960577","https://openalex.org/W4307964254","https://openalex.org/W4308410741"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052","https://openalex.org/W2382290278","https://openalex.org/W4395014643"],"abstract_inverted_index":{"It":[0,78,122],"is":[1,35,138],"well":[2],"known":[3],"that":[4,149],"machine":[5],"learning":[6],"models":[7],"(e.g.,":[8],"image":[9],"recognition)":[10],"can":[11,79,152],"unintentionally":[12],"leak":[13],"information":[14],"about":[15],"the":[16,33,50,108,165],"training":[17],"set.":[18],"Conventional":[19],"membership":[20,40,71,87,97,150],"inference":[21,41,58,72,88,98],"relies":[22],"on":[23,75,140],"posterior":[24,34],"vectors,":[25],"and":[26,55,94,117,143],"this":[27],"task":[28],"becomes":[29],"extremely":[30],"difficult":[31],"when":[32],"masked.":[36],"However,":[37],"current":[38],"label-only":[39,70,82],"attacks":[42],"require":[43],"a":[44,60,69,81,85,119,157],"large":[45,61],"number":[46,62],"of":[47,52,63],"queries":[48],"during":[49],"generation":[51],"adversarial":[53],"samples,":[54],"thus":[56],"incorrect":[57],"generates":[59],"invalid":[64],"queries.":[65],"Therefore,":[66],"we":[67],"introduce":[68],"attack":[73,83,89],"based":[74],"model":[76,166],"explanations.":[77],"transform":[80],"into":[84],"traditional":[86],"by":[90,129],"observing":[91],"neighborhood":[92,110],"consistency":[93],"perform":[95],"fine-grained":[96],"for":[99],"vulnerable":[100,134,162],"samples.":[101,135],"We":[102],"use":[103],"feature":[104],"attribution":[105],"to":[106,167],"simplify":[107],"high-dimensional":[109],"sampling":[111,159],"process,":[112],"quickly":[113],"identify":[114],"decision":[115],"boundaries":[116],"recover":[118],"posteriori":[120],"vectors.":[121],"also":[123],"compares":[124],"different":[125,130],"privacy":[126,169],"risks":[127],"faced":[128],"samples":[131,163],"through":[132],"finding":[133],"The":[136,146],"method":[137],"validated":[139],"CIFAR-10,":[141],"CIFAR-100":[142],"MNIST":[144],"datasets.":[145],"results":[147],"show":[148],"attributes":[151],"be":[153],"identified":[154],"even":[155],"using":[156],"simple":[158],"method.":[160],"Furthermore,":[161],"expose":[164],"greater":[168],"risks.":[170]},"counts_by_year":[{"year":2025,"cited_by_count":2}],"updated_date":"2026-03-09T07:00:12.390032","created_date":"2025-10-10T00:00:00"}
