{"id":"https://openalex.org/W4392903452","doi":"https://doi.org/10.1109/icassp48485.2024.10447875","title":"Interpreting Memorization in Deep Learning from Data Distribution","display_name":"Interpreting Memorization in Deep Learning from Data Distribution","publication_year":2024,"publication_date":"2024-03-18","ids":{"openalex":"https://openalex.org/W4392903452","doi":"https://doi.org/10.1109/icassp48485.2024.10447875"},"language":"en","primary_location":{"id":"doi:10.1109/icassp48485.2024.10447875","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1109/icassp48485.2024.10447875","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2024 - 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5055342873","display_name":"Likun Zhang","orcid":"https://orcid.org/0000-0003-3898-6533"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Likun Zhang","raw_affiliation_strings":["Institute of Information Engineering,CAS,Beijing,China","School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","CAS, Institute of Information Engineering, Beijing, China","Key Laboratory of Cyberspace Security Defense"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,CAS,Beijing,China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]},{"raw_affiliation_string":"CAS, Institute of Information Engineering, Beijing, China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"Key Laboratory of Cyberspace Security Defense","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103082251","display_name":"Jingwei Sun","orcid":"https://orcid.org/0000-0001-7058-5794"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jingwei Sun","raw_affiliation_strings":["Institute of Information Engineering,CAS,Beijing,China","CAS, Institute of Information Engineering, Beijing, China","Key Laboratory of Cyberspace Security Defense","School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,CAS,Beijing,China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"CAS, Institute of Information Engineering, Beijing, China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"Key Laboratory of Cyberspace Security Defense","institution_ids":[]},{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102631464","display_name":"Shoukun Guo","orcid":null},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shoukun Guo","raw_affiliation_strings":["Institute of Information Engineering,CAS,Beijing,China","CAS, Institute of Information Engineering, Beijing, China","Key Laboratory of Cyberspace Security Defense"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,CAS,Beijing,China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"CAS, Institute of Information Engineering, Beijing, China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"Key Laboratory of Cyberspace Security Defense","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100325254","display_name":"Fenghua Li","orcid":"https://orcid.org/0000-0002-3211-012X"},"institutions":[{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Fenghua Li","raw_affiliation_strings":["Institute of Information Engineering,CAS,Beijing,China","CAS, Institute of Information Engineering, Beijing, China","Key Laboratory of Cyberspace Security Defense","School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,CAS,Beijing,China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"CAS, Institute of Information Engineering, Beijing, China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"Key Laboratory of Cyberspace Security Defense","institution_ids":[]},{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101850333","display_name":"Jin Cao","orcid":"https://orcid.org/0000-0003-1372-7252"},"institutions":[{"id":"https://openalex.org/I149594827","display_name":"Xidian University","ror":"https://ror.org/05s92vm98","country_code":"CN","type":"education","lineage":["https://openalex.org/I149594827"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jin Cao","raw_affiliation_strings":["Xidian University,School of Cyber Engineering,Xi&#x2019;an,China"],"affiliations":[{"raw_affiliation_string":"Xidian University,School of Cyber Engineering,Xi&#x2019;an,China","institution_ids":["https://openalex.org/I149594827"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5024053576","display_name":"Ben Niu","orcid":"https://orcid.org/0000-0001-5822-8743"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ben Niu","raw_affiliation_strings":["Institute of Information Engineering,CAS,Beijing,China","Key Laboratory of Cyberspace Security Defense","CAS, Institute of Information Engineering, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering,CAS,Beijing,China","institution_ids":["https://openalex.org/I4210156404"]},{"raw_affiliation_string":"Key Laboratory of Cyberspace Security Defense","institution_ids":[]},{"raw_affiliation_string":"CAS, Institute of Information Engineering, Beijing, China","institution_ids":["https://openalex.org/I4210156404"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5055342873"],"corresponding_institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I4210165038"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.02603615,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"abs/1906.00389","issue":null,"first_page":"5565","last_page":"5569"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9976999759674072,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9193999767303467,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/outlier","display_name":"Outlier","score":0.7700920104980469},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6822412014007568},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.6220060586929321},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5708010196685791},{"id":"https://openalex.org/keywords/memorization","display_name":"Memorization","score":0.5612213611602783},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5287069082260132},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4711678922176361},{"id":"https://openalex.org/keywords/population","display_name":"Population","score":0.47103482484817505},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.46000438928604126},{"id":"https://openalex.org/keywords/distribution","display_name":"Distribution (mathematics)","score":0.44742634892463684},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4346914291381836},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.1396891474723816},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.1157800555229187}],"concepts":[{"id":"https://openalex.org/C79337645","wikidata":"https://www.wikidata.org/wiki/Q779824","display_name":"Outlier","level":2,"score":0.7700920104980469},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6822412014007568},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.6220060586929321},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5708010196685791},{"id":"https://openalex.org/C30038468","wikidata":"https://www.wikidata.org/wiki/Q4354775","display_name":"Memorization","level":2,"score":0.5612213611602783},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5287069082260132},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4711678922176361},{"id":"https://openalex.org/C2908647359","wikidata":"https://www.wikidata.org/wiki/Q2625603","display_name":"Population","level":2,"score":0.47103482484817505},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.46000438928604126},{"id":"https://openalex.org/C110121322","wikidata":"https://www.wikidata.org/wiki/Q865811","display_name":"Distribution (mathematics)","level":2,"score":0.44742634892463684},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4346914291381836},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.1396891474723816},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.1157800555229187},{"id":"https://openalex.org/C145420912","wikidata":"https://www.wikidata.org/wiki/Q853077","display_name":"Mathematics education","level":1,"score":0.0},{"id":"https://openalex.org/C149923435","wikidata":"https://www.wikidata.org/wiki/Q37732","display_name":"Demography","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C144024400","wikidata":"https://www.wikidata.org/wiki/Q21201","display_name":"Sociology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icassp48485.2024.10447875","is_oa":false,"landing_page_url":"http://dx.doi.org/10.1109/icassp48485.2024.10447875","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2024 - 2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":25,"referenced_works":["https://openalex.org/W2194775991","https://openalex.org/W2535690855","https://openalex.org/W2794511224","https://openalex.org/W2887995258","https://openalex.org/W2947018541","https://openalex.org/W2965527189","https://openalex.org/W2972112224","https://openalex.org/W3071470454","https://openalex.org/W3081595899","https://openalex.org/W3096738375","https://openalex.org/W3106873467","https://openalex.org/W3138758728","https://openalex.org/W3214437258","https://openalex.org/W4288057780","https://openalex.org/W4302012908","https://openalex.org/W4318144071","https://openalex.org/W6637373629","https://openalex.org/W6750342037","https://openalex.org/W6763463012","https://openalex.org/W6763736615","https://openalex.org/W6781511523","https://openalex.org/W6782331252","https://openalex.org/W6845733966","https://openalex.org/W6849050393","https://openalex.org/W6849141701"],"related_works":["https://openalex.org/W3093895509","https://openalex.org/W3163481960","https://openalex.org/W2323394100","https://openalex.org/W280704926","https://openalex.org/W2476068070","https://openalex.org/W4323971310","https://openalex.org/W2893372175","https://openalex.org/W1972827106","https://openalex.org/W4283526844","https://openalex.org/W2787003449"],"abstract_inverted_index":{"A":[0],"deep":[1,64],"learning":[2,65],"model":[3],"can":[4,134],"be":[5,71,135],"vulnerable":[6,76,138],"to":[7,17,39,55,70],"a":[8,20,82],"membership":[9],"inference":[10],"attack":[11,144],"(MIA)":[12],"which":[13,67],"allows":[14],"an":[15],"attacker":[16],"determine":[18],"if":[19,113],"specific":[21],"data":[22,48,62,77,94,110],"record":[23],"was":[24],"used":[25],"for":[26,63,85],"its":[27],"training.":[28],"In":[29],"this":[30],"paper,":[31],"we":[32],"investigate":[33],"the":[34,57,75,91,100,114,125,143,149],"unfairness":[35],"of":[36,46,59,93,116,132],"disparate":[37,97],"vulnerability":[38],"MIA":[40,86,117],"across":[41],"different":[42],"subgroups":[43],"in":[44,73],"terms":[45],"their":[47],"distributions.":[49],"We":[50,79],"propose":[51],"three":[52],"practical":[53],"methods":[54],"characterize":[56],"distribution":[58,95],"complex":[60],"training":[61],"models,":[66],"are":[68,103,129],"validated":[69],"effective":[72],"identifying":[74],"records.":[78,111],"then":[80],"provide":[81],"theoretical":[83],"definition":[84],"vulnerability.":[87],"Experimental":[88],"results":[89],"demonstrate":[90],"impact":[92],"on":[96,146,158],"vulnerability,":[98],"where":[99],"out-of-distribution":[101],"outliers":[102],"much":[104],"more":[105,137],"easily":[106],"attacked":[107],"than":[108,121,139,156],"normal":[109],"Even":[112],"accuracy":[115,145],"looks":[118],"no":[119],"better":[120],"random":[122],"guessing":[123],"over":[124],"whole":[126],"population,":[127],"there":[128],"certain":[130],"groups":[131],"\"outliers\"":[133],"significantly":[136],"others.":[140],"For":[141],"example,":[142],"examples":[147],"with":[148],"largest":[150],"10%":[151],"outlierness":[152],"is":[153],"15%":[154],"higher":[155],"that":[157],"in-distribution":[159],"examples.":[160]},"counts_by_year":[],"updated_date":"2025-12-21T01:58:51.020947","created_date":"2025-10-10T00:00:00"}
