{"id":"https://openalex.org/W4416250879","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228207","title":"Membership Inference Attacks against Fine-Tuned Stable Diffusion Models Based on Semantic Loss Trajectory","display_name":"Membership Inference Attacks against Fine-Tuned Stable Diffusion Models Based on Semantic Loss Trajectory","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4416250879","doi":"https://doi.org/10.1109/ijcnn64981.2025.11228207"},"language":null,"primary_location":{"id":"doi:10.1109/ijcnn64981.2025.11228207","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228207","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102271777","display_name":"Jing Lai","orcid":"https://orcid.org/0009-0008-1465-0502"},"institutions":[{"id":"https://openalex.org/I3124059619","display_name":"China University of Geosciences","ror":"https://ror.org/04gcegc37","country_code":"CN","type":"education","lineage":["https://openalex.org/I3124059619"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jing Lai","raw_affiliation_strings":["China University of Geosciences,School of Computer Science,Wuhan,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"China University of Geosciences,School of Computer Science,Wuhan,China","institution_ids":["https://openalex.org/I3124059619"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101863339","display_name":"Yongfeng Qian","orcid":"https://orcid.org/0000-0003-1363-8030"},"institutions":[{"id":"https://openalex.org/I3124059619","display_name":"China University of Geosciences","ror":"https://ror.org/04gcegc37","country_code":"CN","type":"education","lineage":["https://openalex.org/I3124059619"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yongfeng Qian","raw_affiliation_strings":["China University of Geosciences,School of Computer Science,Wuhan,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"China University of Geosciences,School of Computer Science,Wuhan,China","institution_ids":["https://openalex.org/I3124059619"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5040872496","display_name":"Yixue Hao","orcid":"https://orcid.org/0000-0001-7296-2522"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yixue Hao","raw_affiliation_strings":["Huazhong University of Science and Technology,Guangdong HUST Industrial Technology Research Institute, School of Computer Science and Technology,Wuhan,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology,Guangdong HUST Industrial Technology Research Institute, School of Computer Science and Technology,Wuhan,China","institution_ids":["https://openalex.org/I47720641"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.16537674,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"9"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6236000061035156,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.6236000061035156,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.24879999458789825,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.012400000356137753,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7127000093460083},{"id":"https://openalex.org/keywords/matching","display_name":"Matching (statistics)","score":0.536899983882904},{"id":"https://openalex.org/keywords/semantic-similarity","display_name":"Semantic similarity","score":0.512499988079071},{"id":"https://openalex.org/keywords/trajectory","display_name":"Trajectory","score":0.5123999714851379},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.4932999908924103},{"id":"https://openalex.org/keywords/shadow","display_name":"Shadow (psychology)","score":0.4880000054836273},{"id":"https://openalex.org/keywords/semantic-matching","display_name":"Semantic matching","score":0.47589999437332153},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.42410001158714294},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.4075999855995178}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7849000096321106},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7127000093460083},{"id":"https://openalex.org/C165064840","wikidata":"https://www.wikidata.org/wiki/Q1321061","display_name":"Matching (statistics)","level":2,"score":0.536899983882904},{"id":"https://openalex.org/C130318100","wikidata":"https://www.wikidata.org/wiki/Q2268914","display_name":"Semantic similarity","level":2,"score":0.512499988079071},{"id":"https://openalex.org/C13662910","wikidata":"https://www.wikidata.org/wiki/Q193139","display_name":"Trajectory","level":2,"score":0.5123999714851379},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.4932999908924103},{"id":"https://openalex.org/C117797892","wikidata":"https://www.wikidata.org/wiki/Q286363","display_name":"Shadow (psychology)","level":2,"score":0.4880000054836273},{"id":"https://openalex.org/C2778493491","wikidata":"https://www.wikidata.org/wiki/Q7449072","display_name":"Semantic matching","level":3,"score":0.47589999437332153},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.47269999980926514},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.46549999713897705},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.42410001158714294},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.4075999855995178},{"id":"https://openalex.org/C176217482","wikidata":"https://www.wikidata.org/wiki/Q860554","display_name":"Metric (unit)","level":2,"score":0.400299996137619},{"id":"https://openalex.org/C2781122975","wikidata":"https://www.wikidata.org/wiki/Q16928266","display_name":"Semantic feature","level":2,"score":0.398499995470047},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3855000138282776},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.36649999022483826},{"id":"https://openalex.org/C204806902","wikidata":"https://www.wikidata.org/wiki/Q2333581","display_name":"Semantic security","level":5,"score":0.33149999380111694},{"id":"https://openalex.org/C126042441","wikidata":"https://www.wikidata.org/wiki/Q1324888","display_name":"Frame (networking)","level":2,"score":0.3203999996185303},{"id":"https://openalex.org/C75165309","wikidata":"https://www.wikidata.org/wiki/Q2258979","display_name":"Search engine indexing","level":2,"score":0.30059999227523804},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.2939000129699707},{"id":"https://openalex.org/C2780586970","wikidata":"https://www.wikidata.org/wiki/Q1357284","display_name":"Popularity","level":2,"score":0.29280000925064087},{"id":"https://openalex.org/C90312973","wikidata":"https://www.wikidata.org/wiki/Q7449052","display_name":"Semantic data model","level":2,"score":0.2784000039100647},{"id":"https://openalex.org/C160234255","wikidata":"https://www.wikidata.org/wiki/Q812535","display_name":"Bayesian inference","level":3,"score":0.26570001244544983},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.2621999979019165},{"id":"https://openalex.org/C2983787585","wikidata":"https://www.wikidata.org/wiki/Q93586","display_name":"Feature matching","level":3,"score":0.2531000077724457},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.25290000438690186}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn64981.2025.11228207","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11228207","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W1773149199","https://openalex.org/W1861492603","https://openalex.org/W2535690855","https://openalex.org/W3071470454","https://openalex.org/W4214622647","https://openalex.org/W4308410741","https://openalex.org/W4312933868","https://openalex.org/W4385269969","https://openalex.org/W4389195517","https://openalex.org/W4394625871","https://openalex.org/W4402351903","https://openalex.org/W4402643129","https://openalex.org/W4408155387","https://openalex.org/W4408216051","https://openalex.org/W4408750093"],"related_works":[],"abstract_inverted_index":{"With":[0],"the":[1,96,103,114,132],"increasing":[2],"popularity":[3],"of":[4,45,98,105],"text-to-image":[5],"generation":[6],"models,":[7,15],"numerous":[8],"researchers":[9],"have":[10],"recently":[11],"released":[12],"their":[13,69],"fine-tuned":[14],"accompanied":[16],"by":[17],"automatically":[18],"saved":[19],"and":[20,32,111,138],"publicly":[21],"available":[22],"checkpoints,":[23,75],"which":[24,49,94],"serve":[25],"as":[26,51],"essential":[27],"resources":[28],"for":[29,55],"model":[30,115],"replication":[31],"practical":[33],"applications":[34],"across":[35],"various":[36],"tasks.":[37],"However,":[38],"these":[39,74],"checkpoints":[40,97],"introduce":[41,141],"a":[42,52,85,142],"significant":[43],"risk":[44],"leaking":[46],"sensitive":[47],"information,":[48],"serves":[50],"primary":[53],"target":[54],"membership":[56,86,126,167],"inference":[57,87],"attacks":[58],"(MIAs).":[59],"Despite":[60],"this,":[61],"most":[62],"existing":[63,182],"MIAs":[64],"methods":[65],"remain":[66],"limited":[67],"in":[68,77],"ability":[70],"to":[71,101,124],"effectively":[72],"exploit":[73],"particularly":[76],"cross-modal":[78],"contexts.":[79],"In":[80],"this":[81],"paper,":[82],"we":[83,140],"propose":[84],"method":[88,146],"based":[89],"on":[90,153],"semantic":[91,106,133,143,155,161],"loss":[92,162],"trajectories,":[93],"analyzes":[95],"shadow":[99],"models":[100],"assess":[102],"degree":[104],"alignment":[107],"between":[108,135],"generated":[109,136],"images":[110,137],"text":[112],"during":[113],"training":[116],"process.":[117],"These":[118],"trajectory":[119],"changes":[120],"are":[121],"then":[122],"used":[123],"represent":[125],"information.":[127,156],"To":[128],"more":[129],"accurately":[130,165],"capture":[131],"matching":[134],"text,":[139],"similarity":[144],"calculation":[145],"that,":[147],"unlike":[148],"traditional":[149],"pixel-level":[150],"comparisons,":[151],"focuses":[152],"high-level":[154],"Experimental":[157],"results":[158],"demonstrate":[159],"that":[160],"trajectories":[163],"can":[164],"infer":[166],"with":[168],"high":[169],"confidence,":[170],"achieving":[171],"an":[172],"attack":[173],"success":[174],"rate":[175],"approaching":[176],"0.82,":[177],"approximately":[178],"30%":[179],"higher":[180],"than":[181],"methods,":[183],"while":[184],"maintaining":[185],"robust":[186],"performance":[187],"under":[188],"low":[189],"false":[190],"positive":[191],"rates.":[192]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-11-14T00:00:00"}
