{"id":"https://openalex.org/W4367164336","doi":"https://doi.org/10.1109/access.2023.3270860","title":"Membership Inference Attacks Against Temporally Correlated Data in Deep Reinforcement Learning","display_name":"Membership Inference Attacks Against Temporally Correlated Data in Deep Reinforcement Learning","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4367164336","doi":"https://doi.org/10.1109/access.2023.3270860"},"language":"en","primary_location":{"id":"doi:10.1109/access.2023.3270860","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2023.3270860","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10108924.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10108924.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5020639820","display_name":"Maziar Gomrokchi","orcid":"https://orcid.org/0009-0004-0303-3593"},"institutions":[{"id":"https://openalex.org/I5023651","display_name":"McGill University","ror":"https://ror.org/01pxwe438","country_code":"CA","type":"education","lineage":["https://openalex.org/I5023651"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Maziar Gomrokchi","raw_affiliation_strings":["Department of Computer Science, McGill University, Montr&#x00E9;al, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, McGill University, Montr&#x00E9;al, Canada","institution_ids":["https://openalex.org/I5023651"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103171852","display_name":"Susan Amin","orcid":"https://orcid.org/0000-0002-8968-5928"},"institutions":[{"id":"https://openalex.org/I4210164802","display_name":"Mila - Quebec Artificial Intelligence Institute","ror":"https://ror.org/05c22rx21","country_code":"CA","type":"facility","lineage":["https://openalex.org/I4210164802"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Susan Amin","raw_affiliation_strings":["Mila-Qu&#x00E9;bec AI Institute, Montr&#x00E9;al, Canada"],"affiliations":[{"raw_affiliation_string":"Mila-Qu&#x00E9;bec AI Institute, Montr&#x00E9;al, Canada","institution_ids":["https://openalex.org/I4210164802"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076661689","display_name":"Hossein Aboutalebi","orcid":"https://orcid.org/0000-0003-4396-3993"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Hossein Aboutalebi","raw_affiliation_strings":["VIP Laboratory, Cheriton School of Computer Science, University of Waterloo, Waterloo, Canada"],"affiliations":[{"raw_affiliation_string":"VIP Laboratory, Cheriton School of Computer Science, University of Waterloo, Waterloo, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102920751","display_name":"Alexander Wong","orcid":"https://orcid.org/0000-0001-5729-5899"},"institutions":[{"id":"https://openalex.org/I151746483","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68","country_code":"CA","type":"education","lineage":["https://openalex.org/I151746483"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Alexander Wong","raw_affiliation_strings":["DarwinAI Corporation, Waterloo, Canada","Cheriton School of Computer Science, VIP Lab, University of Waterloo, Waterloo, ON, Canada"],"affiliations":[{"raw_affiliation_string":"DarwinAI Corporation, Waterloo, Canada","institution_ids":[]},{"raw_affiliation_string":"Cheriton School of Computer Science, VIP Lab, University of Waterloo, Waterloo, ON, Canada","institution_ids":["https://openalex.org/I151746483"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060420363","display_name":"Doina Precup","orcid":"https://orcid.org/0000-0003-4718-9851"},"institutions":[{"id":"https://openalex.org/I5023651","display_name":"McGill University","ror":"https://ror.org/01pxwe438","country_code":"CA","type":"education","lineage":["https://openalex.org/I5023651"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Doina Precup","raw_affiliation_strings":["Department of Computer Science, McGill University, Montr&#x00E9;al, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, McGill University, Montr&#x00E9;al, Canada","institution_ids":["https://openalex.org/I5023651"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5020639820"],"corresponding_institution_ids":["https://openalex.org/I5023651"],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.8641,"has_fulltext":true,"cited_by_count":5,"citation_normalized_percentile":{"value":0.78004157,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":96},"biblio":{"volume":"11","issue":null,"first_page":"42796","last_page":"42808"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9861999750137329,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.9412999749183655,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.8877689242362976},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7280235886573792},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.7107630372047424},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6814881563186646},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5918022394180298},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5639213919639587},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5534159541130066},{"id":"https://openalex.org/keywords/reinforcement","display_name":"Reinforcement","score":0.5206714868545532},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.44516345858573914},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.18863746523857117},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.08460569381713867}],"concepts":[{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.8877689242362976},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7280235886573792},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.7107630372047424},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6814881563186646},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5918022394180298},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5639213919639587},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5534159541130066},{"id":"https://openalex.org/C67203356","wikidata":"https://www.wikidata.org/wiki/Q1321905","display_name":"Reinforcement","level":2,"score":0.5206714868545532},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.44516345858573914},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.18863746523857117},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.08460569381713867},{"id":"https://openalex.org/C66938386","wikidata":"https://www.wikidata.org/wiki/Q633538","display_name":"Structural engineering","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2023.3270860","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2023.3270860","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10108924.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:d58af4099b024a45a16da109243a9b68","is_oa":true,"landing_page_url":"https://doaj.org/article/d58af4099b024a45a16da109243a9b68","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 11, Pp 42796-42808 (2023)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2023.3270860","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2023.3270860","pdf_url":"https://ieeexplore.ieee.org/ielx7/6287639/6514899/10108924.pdf","source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.5799999833106995,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G2165548363","display_name":null,"funder_award_id":"Canada","funder_id":"https://openalex.org/F4320334593","funder_display_name":"Natural Sciences and Engineering Research Council of Canada"},{"id":"https://openalex.org/G8284766523","display_name":null,"funder_award_id":"(NSERC)","funder_id":"https://openalex.org/F4320334593","funder_display_name":"Natural Sciences and Engineering Research Council of Canada"}],"funders":[{"id":"https://openalex.org/F4320314000","display_name":"Compute Canada","ror":"https://ror.org/03ty8yr27"},{"id":"https://openalex.org/F4320322676","display_name":"University of Waterloo","ror":"https://ror.org/01aff2v68"},{"id":"https://openalex.org/F4320334593","display_name":"Natural Sciences and Engineering Research Council of Canada","ror":"https://ror.org/01h531d29"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4367164336.pdf","grobid_xml":"https://content.openalex.org/works/W4367164336.grobid-xml"},"referenced_works_count":71,"referenced_works":["https://openalex.org/W1569296262","https://openalex.org/W1686810756","https://openalex.org/W1903029394","https://openalex.org/W2064126294","https://openalex.org/W2109553965","https://openalex.org/W2145339207","https://openalex.org/W2158782408","https://openalex.org/W2170505850","https://openalex.org/W2194775991","https://openalex.org/W2520881573","https://openalex.org/W2535690855","https://openalex.org/W2593493160","https://openalex.org/W2754517384","https://openalex.org/W2766447205","https://openalex.org/W2772721022","https://openalex.org/W2781726626","https://openalex.org/W2787938642","https://openalex.org/W2792764867","https://openalex.org/W2795435272","https://openalex.org/W2884367402","https://openalex.org/W2887995258","https://openalex.org/W2904453761","https://openalex.org/W2921693358","https://openalex.org/W2950222626","https://openalex.org/W2952604841","https://openalex.org/W2963079702","https://openalex.org/W2963378725","https://openalex.org/W2963446712","https://openalex.org/W2963864421","https://openalex.org/W2965527189","https://openalex.org/W2996343955","https://openalex.org/W3011159643","https://openalex.org/W3013068160","https://openalex.org/W3034824210","https://openalex.org/W3034971196","https://openalex.org/W3046102592","https://openalex.org/W3071470454","https://openalex.org/W3096692244","https://openalex.org/W3106051020","https://openalex.org/W3106873467","https://openalex.org/W3123212791","https://openalex.org/W3126232929","https://openalex.org/W3132455321","https://openalex.org/W3138815606","https://openalex.org/W3154201502","https://openalex.org/W3158694080","https://openalex.org/W3170901302","https://openalex.org/W3177828909","https://openalex.org/W4210870706","https://openalex.org/W4214717370","https://openalex.org/W4287665106","https://openalex.org/W4298201312","https://openalex.org/W4299401133","https://openalex.org/W4308410483","https://openalex.org/W6637373629","https://openalex.org/W6684921986","https://openalex.org/W6746809867","https://openalex.org/W6747473740","https://openalex.org/W6748839928","https://openalex.org/W6749825310","https://openalex.org/W6757469721","https://openalex.org/W6760535535","https://openalex.org/W6762427411","https://openalex.org/W6764132201","https://openalex.org/W6775482175","https://openalex.org/W6780404908","https://openalex.org/W6780559895","https://openalex.org/W6780983157","https://openalex.org/W6781089347","https://openalex.org/W6792723844","https://openalex.org/W6794139601"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W4320018150","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W2135200719"],"abstract_inverted_index":{"While":[0],"significant":[1],"research":[2],"advances":[3],"have":[4,15],"been":[5,16,59],"made":[6],"in":[7,22,106,158,162,165,177],"the":[8,27,42,45,53,74,98,112,120,133,142,184,188,193],"field":[9],"of":[10,29,47,76,94,100,114,122,187,195],"deep":[11,30,54,79,134],"reinforcement":[12,31,55,80,107,135,189],"learning,":[13],"there":[14],"no":[17],"concrete":[18],"adversarial":[19,68,144],"attack":[20,69,145],"strategies":[21],"literature":[23],"tailored":[24],"for":[25,72],"studying":[26],"vulnerability":[28,75],"learning":[32,56,81,108,136,185,190],"algorithms":[33],"to":[34,83,96],"membership":[35,85,130],"inference":[36,86],"attacks.":[37],"In":[38,88],"such":[39],"attacking":[40],"systems,":[41],"adversary":[43],"targets":[44],"set":[46],"collected":[48],"input":[49],"data":[50,152],"on":[51,111],"which":[52,103,172],"algorithm":[57,82,191],"has":[58],"trained.":[60],"To":[61],"address":[62],"this":[63,178],"gap,":[64],"we":[65,90,118,181],"propose":[66],"an":[67,154],"framework":[70,146],"designed":[71],"testing":[73],"a":[77,84,92],"state-of-the-art":[78],"attack.":[87],"particular,":[89],"design":[91],"series":[93],"experiments":[95],"investigate":[97],"impact":[99],"temporal":[101],"correlation,":[102],"naturally":[104],"exists":[105],"training":[109],"data,":[110],"probability":[113],"information":[115],"leakage.":[116],"Moreover,":[117],"compare":[119],"performance":[121],"<italic":[123,127],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[124,128],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">collective</i>":[125],"and":[126,160],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">individual</i>":[129],"attacks":[131],"against":[132],"algorithm.":[137],"Experimental":[138],"results":[139],"show":[140,182],"that":[141,183],"proposed":[143],"is":[147],"surprisingly":[148],"effective":[149],"at":[150],"inferring":[151],"with":[153],"accuracy":[155],"exceeding":[156],"84%":[157],"individual":[159],"97%":[161],"collective":[163],"modes":[164],"three":[166],"different":[167],"continuous":[168],"control":[169],"Mujoco":[170],"tasks,":[171],"raises":[173],"serious":[174],"privacy":[175,196],"concerns":[176],"regard.":[179],"Finally,":[180],"state":[186],"influences":[192],"level":[194],"breaches":[197],"significantly.":[198]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":1}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
