{"id":"https://openalex.org/W3109565608","doi":"https://doi.org/10.1109/ijcnn52387.2021.9534207","title":"TransMIA: Membership Inference Attacks Using Transfer Shadow Training","display_name":"TransMIA: Membership Inference Attacks Using Transfer Shadow Training","publication_year":2021,"publication_date":"2021-07-18","ids":{"openalex":"https://openalex.org/W3109565608","doi":"https://doi.org/10.1109/ijcnn52387.2021.9534207","mag":"3109565608"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn52387.2021.9534207","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9534207","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2011.14661","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5052844875","display_name":"Seira Hidano","orcid":"https://orcid.org/0009-0006-0571-7168"},"institutions":[{"id":"https://openalex.org/I4210164495","display_name":"KDDI Research (Japan)","ror":"https://ror.org/05qsqt662","country_code":"JP","type":"company","lineage":["https://openalex.org/I4210164495"]}],"countries":["JP"],"is_corresponding":true,"raw_author_name":"Seira Hidano","raw_affiliation_strings":["KDDI Research, Inc., Saitama, Japan","KDDI Research, Inc.,Saitama,Japan"],"affiliations":[{"raw_affiliation_string":"KDDI Research, Inc., Saitama, Japan","institution_ids":["https://openalex.org/I4210164495"]},{"raw_affiliation_string":"KDDI Research, Inc.,Saitama,Japan","institution_ids":["https://openalex.org/I4210164495"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085794030","display_name":"Takao Murakami","orcid":"https://orcid.org/0000-0002-5110-1261"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Takao Murakami","raw_affiliation_strings":["AIST, Tokyo, Japan","AIST,Tokyo,Japan"],"affiliations":[{"raw_affiliation_string":"AIST, Tokyo, Japan","institution_ids":[]},{"raw_affiliation_string":"AIST,Tokyo,Japan","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5049338284","display_name":"Yusuke Kawamoto","orcid":"https://orcid.org/0000-0002-2151-9560"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yusuke Kawamoto","raw_affiliation_strings":["AIST, Tokyo, Japan","AIST,Tokyo,Japan"],"affiliations":[{"raw_affiliation_string":"AIST, Tokyo, Japan","institution_ids":[]},{"raw_affiliation_string":"AIST,Tokyo,Japan","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5052844875"],"corresponding_institution_ids":["https://openalex.org/I4210164495"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.01060236,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"10"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9977999925613403,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.996399998664856,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12296","display_name":"Autopsy Techniques and Outcomes","score":0.9643999934196472,"subfield":{"id":"https://openalex.org/subfields/2741","display_name":"Radiology, Nuclear Medicine and Imaging"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.7844181060791016},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7703652381896973},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.761463463306427},{"id":"https://openalex.org/keywords/transfer-of-learning","display_name":"Transfer of learning","score":0.7211920619010925},{"id":"https://openalex.org/keywords/shadow","display_name":"Shadow (psychology)","score":0.7078239917755127},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6598999500274658},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6400116086006165},{"id":"https://openalex.org/keywords/popularity","display_name":"Popularity","score":0.5503973364830017},{"id":"https://openalex.org/keywords/transfer","display_name":"Transfer (computing)","score":0.44227609038352966},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.196982741355896}],"concepts":[{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.7844181060791016},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7703652381896973},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.761463463306427},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.7211920619010925},{"id":"https://openalex.org/C117797892","wikidata":"https://www.wikidata.org/wiki/Q286363","display_name":"Shadow (psychology)","level":2,"score":0.7078239917755127},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6598999500274658},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6400116086006165},{"id":"https://openalex.org/C2780586970","wikidata":"https://www.wikidata.org/wiki/Q1357284","display_name":"Popularity","level":2,"score":0.5503973364830017},{"id":"https://openalex.org/C2776175482","wikidata":"https://www.wikidata.org/wiki/Q1195816","display_name":"Transfer (computing)","level":2,"score":0.44227609038352966},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.196982741355896},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.0},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.0},{"id":"https://openalex.org/C173608175","wikidata":"https://www.wikidata.org/wiki/Q232661","display_name":"Parallel computing","level":1,"score":0.0},{"id":"https://openalex.org/C542102704","wikidata":"https://www.wikidata.org/wiki/Q183257","display_name":"Psychotherapist","level":1,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1109/ijcnn52387.2021.9534207","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9534207","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:2011.14661","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2011.14661","pdf_url":"https://arxiv.org/pdf/2011.14661","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"mag:3109565608","is_oa":true,"landing_page_url":"https://arxiv.org/pdf/2011.14661.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},{"id":"doi:10.48550/arxiv.2011.14661","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2011.14661","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article-journal"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2011.14661","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2011.14661","pdf_url":"https://arxiv.org/pdf/2011.14661","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1776693683","display_name":null,"funder_award_id":"JP19H04113","funder_id":"https://openalex.org/F4320320212","funder_display_name":"Japan Society for the Promotion of Science London"},{"id":"https://openalex.org/G5913768863","display_name":null,"funder_award_id":"JPMJER1603","funder_id":"https://openalex.org/F4320338112","funder_display_name":"Exploratory Research for Advanced Technology"}],"funders":[{"id":"https://openalex.org/F4320320212","display_name":"Japan Society for the Promotion of Science London","ror":"https://ror.org/02m7axw05"},{"id":"https://openalex.org/F4320320907","display_name":"Japan Science and Technology Corporation","ror":"https://ror.org/00097mb19"},{"id":"https://openalex.org/F4320338112","display_name":"Exploratory Research for Advanced Technology","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":59,"referenced_works":["https://openalex.org/W2053637704","https://openalex.org/W2053801139","https://openalex.org/W2097272254","https://openalex.org/W2102605133","https://openalex.org/W2117539524","https://openalex.org/W2137844145","https://openalex.org/W2160921898","https://openalex.org/W2165698076","https://openalex.org/W2168939893","https://openalex.org/W2194775991","https://openalex.org/W2395579298","https://openalex.org/W2473418344","https://openalex.org/W2532781556","https://openalex.org/W2535690855","https://openalex.org/W2616180702","https://openalex.org/W2617174679","https://openalex.org/W2798657499","https://openalex.org/W2884943453","https://openalex.org/W2887280559","https://openalex.org/W2887995258","https://openalex.org/W2913413968","https://openalex.org/W2927692314","https://openalex.org/W2930926105","https://openalex.org/W2946363484","https://openalex.org/W2963378725","https://openalex.org/W2963839617","https://openalex.org/W2964020641","https://openalex.org/W2964151798","https://openalex.org/W2964829966","https://openalex.org/W2965527189","https://openalex.org/W2983140679","https://openalex.org/W3007720613","https://openalex.org/W3008580825","https://openalex.org/W3023716276","https://openalex.org/W3024386862","https://openalex.org/W3028302264","https://openalex.org/W3084357355","https://openalex.org/W3102360395","https://openalex.org/W3104224589","https://openalex.org/W3106968132","https://openalex.org/W3118608800","https://openalex.org/W3164762628","https://openalex.org/W3202500832","https://openalex.org/W6651608069","https://openalex.org/W6663928093","https://openalex.org/W6680211044","https://openalex.org/W6684956099","https://openalex.org/W6687483927","https://openalex.org/W6697274609","https://openalex.org/W6728897251","https://openalex.org/W6750182894","https://openalex.org/W6756399779","https://openalex.org/W6774484160","https://openalex.org/W6775482175","https://openalex.org/W6776993083","https://openalex.org/W6777717587","https://openalex.org/W6778091624","https://openalex.org/W6782733353","https://openalex.org/W6786745724"],"related_works":["https://openalex.org/W3202860343","https://openalex.org/W3190768044","https://openalex.org/W3125679694","https://openalex.org/W2902027132","https://openalex.org/W3098309759","https://openalex.org/W3028816787","https://openalex.org/W3092633571","https://openalex.org/W3131914967","https://openalex.org/W3123519610","https://openalex.org/W3015424723","https://openalex.org/W2787710446","https://openalex.org/W2988677439","https://openalex.org/W3010489274","https://openalex.org/W3196119265","https://openalex.org/W2897830718","https://openalex.org/W3008635596","https://openalex.org/W3046734944","https://openalex.org/W3047535539","https://openalex.org/W3093235747","https://openalex.org/W3158675315"],"abstract_inverted_index":{"Transfer":[0],"learning":[1,16,35,42,58],"has":[2,30],"been":[3],"widely":[4],"studied":[5],"and":[6,133,159,188],"gained":[7],"increasing":[8],"popularity":[9],"to":[10,59,73,100,104,122],"improve":[11,106],"the":[12,65,69,75,78,94,97,107,123,139,156,160,175,183],"accuracy":[13],"of":[14,77,96,109,116,155,164,177,185],"machine":[15,41],"models":[17],"by":[18],"transferring":[19],"some":[20],"knowledge":[21],"acquired":[22],"in":[23],"different":[24],"training.":[25],"However,":[26],"no":[27],"prior":[28],"work":[29],"pointed":[31],"out":[32],"that":[33,135,141],"transfer":[34,57,86,146,168],"can":[36],"strengthen":[37],"privacy":[38],"attacks":[39,63,128,137],"on":[40,64,182],"models.":[43],"In":[44,81],"this":[45],"paper,":[46],"we":[47,83,173],"propose":[48,84],"TransMIA":[49],"(Transfer":[50],"learning-based":[51],"Membership":[52],"Inference":[53],"Attacks),":[54],"which":[55,165],"use":[56,144],"perform":[60],"membership":[61,110],"inference":[62,111],"source":[66],"model":[67,99],"when":[68,112],"adversary":[70,92],"is":[71,120],"able":[72],"access":[74],"parameters":[76,95],"transferred":[79,98],"model.":[80],"particular,":[82],"a":[85,113],"shadow":[87,102,117,147,169],"training":[88,118,148,170],"technique,":[89],"where":[90],"an":[91],"employs":[93],"construct":[101],"models,":[103],"significantly":[105],"performance":[108,176],"limited":[114],"amount":[115],"data":[119],"available":[121],"adversary.":[124],"We":[125,150],"evaluate":[126],"our":[127,136,145,167,193],"using":[129],"two":[130],"real":[131],"datasets,":[132],"show":[134],"outperform":[138],"state-of-the-art":[140],"does":[142],"not":[143],"technique.":[149,171],"also":[151],"compare":[152],"four":[153,179],"combinations":[154],"learning-based/entropy-based":[157],"approach":[158],"fine-tuning/freezing":[161],"approach,":[162],"all":[163],"employ":[166],"Then":[172],"examine":[174],"these":[178],"approaches":[180],"based":[181],"distributions":[184],"confidence":[186],"values,":[187],"discuss":[189],"possible":[190],"countermeasures":[191],"against":[192],"attacks.":[194]},"counts_by_year":[],"updated_date":"2026-04-09T08:11:56.329763","created_date":"2025-10-10T00:00:00"}
