{"id":"https://openalex.org/W4309346274","doi":"https://doi.org/10.1109/cns56114.2022.9947254","title":"Membership Inference Attack in Face of Data Transformations","display_name":"Membership Inference Attack in Face of Data Transformations","publication_year":2022,"publication_date":"2022-10-03","ids":{"openalex":"https://openalex.org/W4309346274","doi":"https://doi.org/10.1109/cns56114.2022.9947254"},"language":"en","primary_location":{"id":"doi:10.1109/cns56114.2022.9947254","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cns56114.2022.9947254","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Conference on Communications and Network Security (CNS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101936161","display_name":"Jiyu Chen","orcid":"https://orcid.org/0000-0002-0144-6376"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Jiyu Chen","raw_affiliation_strings":["University of California,Department of Computer Science,Davis","Department of Computer Science, University of California, Davis"],"affiliations":[{"raw_affiliation_string":"University of California,Department of Computer Science,Davis","institution_ids":["https://openalex.org/I84218800"]},{"raw_affiliation_string":"Department of Computer Science, University of California, Davis","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067005644","display_name":"Yiwen Guo","orcid":"https://orcid.org/0000-0002-0709-4877"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yiwen Guo","raw_affiliation_strings":["Independent Researcher"],"affiliations":[{"raw_affiliation_string":"Independent Researcher","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100353550","display_name":"Hao Chen","orcid":"https://orcid.org/0000-0002-4072-0710"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hao Chen","raw_affiliation_strings":["University of California,Department of Computer Science,Davis","Department of Computer Science, University of California, Davis"],"affiliations":[{"raw_affiliation_string":"University of California,Department of Computer Science,Davis","institution_ids":["https://openalex.org/I84218800"]},{"raw_affiliation_string":"Department of Computer Science, University of California, Davis","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5009102659","display_name":"Neil Zhenqiang Gong","orcid":"https://orcid.org/0000-0002-9900-9309"},"institutions":[{"id":"https://openalex.org/I170897317","display_name":"Duke University","ror":"https://ror.org/00py81415","country_code":"US","type":"education","lineage":["https://openalex.org/I170897317"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Neil Gong","raw_affiliation_strings":["Duke University,Department of Electrical and Computer Engineering","Department of Electrical and Computer Engineering, Duke University"],"affiliations":[{"raw_affiliation_string":"Duke University,Department of Electrical and Computer Engineering","institution_ids":["https://openalex.org/I170897317"]},{"raw_affiliation_string":"Department of Electrical and Computer Engineering, Duke University","institution_ids":["https://openalex.org/I170897317"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5101936161"],"corresponding_institution_ids":["https://openalex.org/I84218800"],"apc_list":null,"apc_paid":null,"fwci":0.1326,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.53978013,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"299","last_page":"307"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9753999710083008,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8177169561386108},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7728842496871948},{"id":"https://openalex.org/keywords/raw-data","display_name":"Raw data","score":0.5916421413421631},{"id":"https://openalex.org/keywords/face","display_name":"Face (sociological concept)","score":0.5670393705368042},{"id":"https://openalex.org/keywords/transformation","display_name":"Transformation (genetics)","score":0.5640578866004944},{"id":"https://openalex.org/keywords/data-transformation","display_name":"Data transformation","score":0.5194689631462097},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.5118512511253357},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.5086408853530884},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.4980185031890869},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.4405781030654907},{"id":"https://openalex.org/keywords/data-modeling","display_name":"Data modeling","score":0.4364132881164551},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.42539215087890625},{"id":"https://openalex.org/keywords/data-set","display_name":"Data set","score":0.4145072102546692},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.41407814621925354},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.412594199180603},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.10179239511489868}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8177169561386108},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7728842496871948},{"id":"https://openalex.org/C132964779","wikidata":"https://www.wikidata.org/wiki/Q2110223","display_name":"Raw data","level":2,"score":0.5916421413421631},{"id":"https://openalex.org/C2779304628","wikidata":"https://www.wikidata.org/wiki/Q3503480","display_name":"Face (sociological concept)","level":2,"score":0.5670393705368042},{"id":"https://openalex.org/C204241405","wikidata":"https://www.wikidata.org/wiki/Q461499","display_name":"Transformation (genetics)","level":3,"score":0.5640578866004944},{"id":"https://openalex.org/C150670458","wikidata":"https://www.wikidata.org/wiki/Q4272815","display_name":"Data transformation","level":3,"score":0.5194689631462097},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.5118512511253357},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.5086408853530884},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.4980185031890869},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.4405781030654907},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.4364132881164551},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.42539215087890625},{"id":"https://openalex.org/C58489278","wikidata":"https://www.wikidata.org/wiki/Q1172284","display_name":"Data set","level":2,"score":0.4145072102546692},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.41407814621925354},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.412594199180603},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.10179239511489868},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C55493867","wikidata":"https://www.wikidata.org/wiki/Q7094","display_name":"Biochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0},{"id":"https://openalex.org/C135572916","wikidata":"https://www.wikidata.org/wiki/Q193351","display_name":"Data warehouse","level":2,"score":0.0},{"id":"https://openalex.org/C43617362","wikidata":"https://www.wikidata.org/wiki/Q170050","display_name":"Chromatography","level":1,"score":0.0},{"id":"https://openalex.org/C36289849","wikidata":"https://www.wikidata.org/wiki/Q34749","display_name":"Social science","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C104317684","wikidata":"https://www.wikidata.org/wiki/Q7187","display_name":"Gene","level":2,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/cns56114.2022.9947254","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cns56114.2022.9947254","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2022 IEEE Conference on Communications and Network Security (CNS)","raw_type":"proceedings-article"},{"id":"pmh:oai:hub.hku.hk:10722/346552","is_oa":false,"landing_page_url":"https://hub.hku.hk/handle/10722/346552","pdf_url":null,"source":{"id":"https://openalex.org/S4377196271","display_name":"The HKU Scholars Hub (University of Hong Kong)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I889458895","host_organization_name":"University of Hong Kong","host_organization_lineage":["https://openalex.org/I889458895"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Conference_Paper"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.5699999928474426,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G1236137737","display_name":null,"funder_award_id":"1801751,1956364,1937786","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":41,"referenced_works":["https://openalex.org/W1673923490","https://openalex.org/W1686810756","https://openalex.org/W2140196014","https://openalex.org/W2473418344","https://openalex.org/W2535690855","https://openalex.org/W2789226849","https://openalex.org/W2795435272","https://openalex.org/W2884943453","https://openalex.org/W2887995258","https://openalex.org/W2930926105","https://openalex.org/W2945237470","https://openalex.org/W2956128647","https://openalex.org/W2963378725","https://openalex.org/W2963456518","https://openalex.org/W2965527189","https://openalex.org/W2983140679","https://openalex.org/W3004170295","https://openalex.org/W3013068160","https://openalex.org/W3015625436","https://openalex.org/W3046102592","https://openalex.org/W3081595899","https://openalex.org/W3100213383","https://openalex.org/W3103245149","https://openalex.org/W3118608800","https://openalex.org/W3156534051","https://openalex.org/W3170901302","https://openalex.org/W3214437258","https://openalex.org/W4289143744","https://openalex.org/W4293846201","https://openalex.org/W6637162671","https://openalex.org/W6637373629","https://openalex.org/W6739868092","https://openalex.org/W6748503580","https://openalex.org/W6752346538","https://openalex.org/W6756573353","https://openalex.org/W6762844097","https://openalex.org/W6763077247","https://openalex.org/W6765055791","https://openalex.org/W6775482175","https://openalex.org/W6782331252","https://openalex.org/W6790161207"],"related_works":["https://openalex.org/W4394231753","https://openalex.org/W4385385304","https://openalex.org/W2786391746","https://openalex.org/W3086422166","https://openalex.org/W4393848201","https://openalex.org/W2053247611","https://openalex.org/W2151707824","https://openalex.org/W3024941504","https://openalex.org/W4313290070","https://openalex.org/W3094550016"],"abstract_inverted_index":{"Membership":[0],"inference":[1,127],"attacks":[2],"(MIAs)":[3],"on":[4,199],"machine":[5],"learning":[6],"models,":[7],"which":[8],"try":[9],"to":[10,71,152,158],"infer":[11],"whether":[12],"a":[13,21,74,86,107],"sample":[14,110],"is":[15,46,68,118],"in":[16,40,59,143],"the":[17,41,50,55,60,66,78,96,116,123,155,160,165,171],"training":[18,61,79,109],"dataset":[19],"of":[20,77,125,145,167,173,180],"target":[22],"model,":[23],"have":[24],"been":[25],"widely":[26],"studied":[27],"over":[28],"recent":[29],"years":[30],"as":[31,58],"data":[32,134,146,175,186],"privacy":[33,113],"attracts":[34],"increasing":[35],"attention.":[36],"One":[37],"unignorable":[38],"problem":[39],"current":[42,150],"MIA":[43],"threat":[44],"model":[45],"that":[47],"it":[48],"assumes":[49],"attacker":[51,67],"always":[52],"obtains":[53],"exactly":[54],"same":[56],"samples":[57],"set.":[62],"In":[63],"reality,":[64],"however,":[65],"more":[69,129],"likely":[70],"gather":[72],"only":[73],"transformed":[75,108],"version":[76],"samples.":[80],"For":[81],"instance,":[82],"portraits":[83],"downloadable":[84],"from":[85],"social":[87],"networking":[88],"website":[89,97],"usually":[90],"are":[91],"re-scaled":[92],"and":[93,154,170,188,201],"compressed,":[94],"while":[95],"owner":[98],"can":[99],"train":[100],"models":[101,203],"with":[102,183,191],"RAW":[103],"images.":[104],"We":[105,136,163],"believe":[106],"still":[111],"causes":[112],"leakage":[114],"if":[115],"transformation":[117],"semantic-preserving.":[119],"Therefore,":[120],"we":[121,196],"broaden":[122],"concept":[124],"membership":[126],"into":[128],"realistic":[130],"scenarios":[131],"by":[132,177,189,205],"considering":[133,174],"transformations.":[135],"introduce":[137],"two":[138],"strategies":[139,169],"for":[140],"designing":[141],"MIAs":[142,151],"face":[144],"transformations:":[147],"one":[148],"adapts":[149],"transformations,":[153],"other":[156],"tries":[157],"reverse":[159],"transformations":[161,176,187],"approximately.":[162],"demonstrated":[164],"effectiveness":[166],"our":[168],"significance":[172],"extensive":[178],"evaluations":[179,198],"multiple":[181],"datasets":[182],"several":[184],"common":[185],"comparisons":[190],"six":[192],"state-of-the-art":[193,207],"attacks.":[194],"Moreover,":[195],"conduct":[197],"data-augmented":[200],"privacy-preserving":[202],"protected":[204],"three":[206],"defenses.":[208]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
