{"id":"https://openalex.org/W4386243278","doi":"https://doi.org/10.1109/infocom53939.2023.10229036","title":"Mixup Training for Generative Models to Defend Membership Inference Attacks","display_name":"Mixup Training for Generative Models to Defend Membership Inference Attacks","publication_year":2023,"publication_date":"2023-05-17","ids":{"openalex":"https://openalex.org/W4386243278","doi":"https://doi.org/10.1109/infocom53939.2023.10229036"},"language":"en","primary_location":{"id":"doi:10.1109/infocom53939.2023.10229036","is_oa":false,"landing_page_url":"https://doi.org/10.1109/infocom53939.2023.10229036","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE INFOCOM 2023 - IEEE Conference on Computer Communications","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5065414494","display_name":"Zhe Ji","orcid":"https://orcid.org/0009-0005-8803-1737"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Zhe Ji","raw_affiliation_strings":["Shanghai Jiao Tong University"],"affiliations":[{"raw_affiliation_string":"Shanghai Jiao Tong University","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102549902","display_name":"Qiansiqi Hu","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qiansiqi Hu","raw_affiliation_strings":["Shanghai Jiao Tong University"],"affiliations":[{"raw_affiliation_string":"Shanghai Jiao Tong University","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5018175815","display_name":"Liyao Xiang","orcid":"https://orcid.org/0000-0003-0165-4930"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Liyao Xiang","raw_affiliation_strings":["Shanghai Jiao Tong University","John Hopcroft Center, Shanghai Jiao Tong University, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Jiao Tong University","institution_ids":["https://openalex.org/I183067930"]},{"raw_affiliation_string":"John Hopcroft Center, Shanghai Jiao Tong University, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5023919188","display_name":"Chenghu Zhou","orcid":"https://orcid.org/0000-0003-3331-2302"},"institutions":[{"id":"https://openalex.org/I4210160793","display_name":"Institute of Geographic Sciences and Natural Resources Research","ror":"https://ror.org/04t1cdb72","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210160793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chenghu Zhou","raw_affiliation_strings":["CAS,Institute of Geographic Sciences and Natural Resources Research","Institute of Geographic Sciences and Natural Resources Research, CAS"],"affiliations":[{"raw_affiliation_string":"CAS,Institute of Geographic Sciences and Natural Resources Research","institution_ids":["https://openalex.org/I4210160793"]},{"raw_affiliation_string":"Institute of Geographic Sciences and Natural Resources Research, CAS","institution_ids":["https://openalex.org/I4210160793"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5065414494"],"corresponding_institution_ids":["https://openalex.org/I183067930"],"apc_list":null,"apc_paid":null,"fwci":0.5254,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.71418834,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"10"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9908999800682068,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12357","display_name":"Digital Media Forensic Detection","score":0.9266999959945679,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/overfitting","display_name":"Overfitting","score":0.9023247957229614},{"id":"https://openalex.org/keywords/discriminative-model","display_name":"Discriminative model","score":0.7836416959762573},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7744086384773254},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7299448251724243},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.7086248397827148},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6625649333000183},{"id":"https://openalex.org/keywords/training","display_name":"Training (meteorology)","score":0.5891816020011902},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5850763916969299},{"id":"https://openalex.org/keywords/generative-model","display_name":"Generative model","score":0.583713948726654},{"id":"https://openalex.org/keywords/perspective","display_name":"Perspective (graphical)","score":0.5772603154182434},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.5118972063064575},{"id":"https://openalex.org/keywords/popularity","display_name":"Popularity","score":0.44251251220703125},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.42799875140190125},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.4116976857185364},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.18980616331100464},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.09625735878944397}],"concepts":[{"id":"https://openalex.org/C22019652","wikidata":"https://www.wikidata.org/wiki/Q331309","display_name":"Overfitting","level":3,"score":0.9023247957229614},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.7836416959762573},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7744086384773254},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7299448251724243},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.7086248397827148},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6625649333000183},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.5891816020011902},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5850763916969299},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.583713948726654},{"id":"https://openalex.org/C12713177","wikidata":"https://www.wikidata.org/wiki/Q1900281","display_name":"Perspective (graphical)","level":2,"score":0.5772603154182434},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.5118972063064575},{"id":"https://openalex.org/C2780586970","wikidata":"https://www.wikidata.org/wiki/Q1357284","display_name":"Popularity","level":2,"score":0.44251251220703125},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.42799875140190125},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.4116976857185364},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.18980616331100464},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.09625735878944397},{"id":"https://openalex.org/C185592680","wikidata":"https://www.wikidata.org/wiki/Q2329","display_name":"Chemistry","level":0,"score":0.0},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C43617362","wikidata":"https://www.wikidata.org/wiki/Q170050","display_name":"Chromatography","level":1,"score":0.0},{"id":"https://openalex.org/C153294291","wikidata":"https://www.wikidata.org/wiki/Q25261","display_name":"Meteorology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/infocom53939.2023.10229036","is_oa":false,"landing_page_url":"https://doi.org/10.1109/infocom53939.2023.10229036","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE INFOCOM 2023 - IEEE Conference on Computer Communications","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6899999976158142,"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":39,"referenced_works":["https://openalex.org/W1834627138","https://openalex.org/W2171766961","https://openalex.org/W2194775991","https://openalex.org/W2396881363","https://openalex.org/W2535690855","https://openalex.org/W2604918751","https://openalex.org/W2621140322","https://openalex.org/W2765407302","https://openalex.org/W2887995258","https://openalex.org/W2962785568","https://openalex.org/W2963373786","https://openalex.org/W2965527189","https://openalex.org/W2993330478","https://openalex.org/W3003257820","https://openalex.org/W3004170295","https://openalex.org/W3013068160","https://openalex.org/W3071470454","https://openalex.org/W3106873467","https://openalex.org/W3118608800","https://openalex.org/W3159069780","https://openalex.org/W3173029858","https://openalex.org/W3192357745","https://openalex.org/W3205994208","https://openalex.org/W3213204049","https://openalex.org/W4285483870","https://openalex.org/W4287553002","https://openalex.org/W4288057780","https://openalex.org/W4295521014","https://openalex.org/W6639056083","https://openalex.org/W6718379498","https://openalex.org/W6735913928","https://openalex.org/W6735926176","https://openalex.org/W6745136726","https://openalex.org/W6771101288","https://openalex.org/W6775482175","https://openalex.org/W6787335730","https://openalex.org/W6787972765","https://openalex.org/W6802769956","https://openalex.org/W6840437216"],"related_works":["https://openalex.org/W3040691452","https://openalex.org/W3048732067","https://openalex.org/W4383468834","https://openalex.org/W4384648009","https://openalex.org/W4303645823","https://openalex.org/W4285263558","https://openalex.org/W2093104230","https://openalex.org/W2900159906","https://openalex.org/W4287828318","https://openalex.org/W2406556600"],"abstract_inverted_index":{"With":[0],"the":[1,13,17,21,31,41,44,87,102,112,123,126,139],"popularity":[2],"of":[3,20,30,43,125],"machine":[4],"learning,":[5],"it":[6,60],"has":[7,49],"been":[8,50],"a":[9,36,72,82],"growing":[10],"concern":[11],"on":[12],"trained":[14],"model":[15,147],"revealing":[16],"private":[18],"information":[19],"training":[22,42,74,89,136,153],"data.":[23,104],"Membership":[24],"inference":[25],"attack":[26],"(MIA)":[27],"poses":[28],"one":[29],"threats":[32],"by":[33],"inferring":[34],"whether":[35],"given":[37],"sample":[38],"participates":[39],"in":[40,161],"target":[45],"model.":[46],"Although":[47],"MIA":[48],"widely":[51],"studied":[52],"for":[53,56,76,142],"discriminative":[54],"models,":[55,58,144],"generative":[57,77,143],"neither":[59],"nor":[61],"its":[62],"defense":[63,83],"is":[64,91,108],"extensively":[65],"investigated.":[66],"In":[67],"this":[68],"work,":[69],"we":[70],"propose":[71],"mixup":[73,135],"method":[75,120],"adversarial":[78],"networks":[79],"(GANs)":[80],"as":[81],"against":[84],"MIAs.":[85],"Specifically,":[86],"original":[88,103],"data":[90],"replaced":[92],"with":[93],"their":[94],"interpolations":[95],"so":[96],"that":[97,134],"GANs":[98],"would":[99],"never":[100],"overfit":[101],"The":[105],"intriguing":[106],"part":[107],"an":[109],"analysis":[110],"from":[111],"hypothesis":[113],"test":[114],"perspective":[115],"to":[116,158],"theoretically":[117],"prove":[118],"our":[119],"could":[121],"mitigate":[122],"AUC":[124],"strongest":[127],"likelihood":[128],"ratio":[129],"attack.":[130],"Experimental":[131],"results":[132],"support":[133],"successfully":[137],"defends":[138],"state-of-the-art":[140],"MIAs":[141],"yet":[145],"without":[146],"performance":[148],"degradation":[149],"or":[150],"any":[151],"additional":[152],"efforts,":[154],"showing":[155],"great":[156],"promise":[157],"be":[159],"deployed":[160],"practice.":[162]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
