{"id":"https://openalex.org/W4214817174","doi":"https://doi.org/10.1109/iscisc53448.2021.9720436","title":"A White-Box Generator Membership Inference Attack Against Generative Models","display_name":"A White-Box Generator Membership Inference Attack Against Generative Models","publication_year":2021,"publication_date":"2021-09-01","ids":{"openalex":"https://openalex.org/W4214817174","doi":"https://doi.org/10.1109/iscisc53448.2021.9720436"},"language":"en","primary_location":{"id":"doi:10.1109/iscisc53448.2021.9720436","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iscisc53448.2021.9720436","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 18th International ISC Conference on Information Security and Cryptology (ISCISC)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5051306267","display_name":"Maryam Azadmanesh","orcid":"https://orcid.org/0000-0003-2932-7149"},"institutions":[{"id":"https://openalex.org/I39268498","display_name":"University of Isfahan","ror":"https://ror.org/05h9t7759","country_code":"IR","type":"education","lineage":["https://openalex.org/I39268498"]}],"countries":["IR"],"is_corresponding":true,"raw_author_name":"Maryam Azadmanesh","raw_affiliation_strings":["University of Isfahan,Departement of Computer Engineering,Isfahan,Iran"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Isfahan,Departement of Computer Engineering,Isfahan,Iran","institution_ids":["https://openalex.org/I39268498"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041422232","display_name":"Behrouz Shahgholi Ghahfarokhi","orcid":"https://orcid.org/0000-0001-9768-8793"},"institutions":[{"id":"https://openalex.org/I39268498","display_name":"University of Isfahan","ror":"https://ror.org/05h9t7759","country_code":"IR","type":"education","lineage":["https://openalex.org/I39268498"]}],"countries":["IR"],"is_corresponding":false,"raw_author_name":"Behrouz Shahgholi Ghahfarokhi","raw_affiliation_strings":["University of Isfahan,Departement of Computer Engineering,Isfahan,Iran"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Isfahan,Departement of Computer Engineering,Isfahan,Iran","institution_ids":["https://openalex.org/I39268498"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5074326922","display_name":"Maede Ashouri Talouki","orcid":null},"institutions":[{"id":"https://openalex.org/I39268498","display_name":"University of Isfahan","ror":"https://ror.org/05h9t7759","country_code":"IR","type":"education","lineage":["https://openalex.org/I39268498"]}],"countries":["IR"],"is_corresponding":false,"raw_author_name":"Maede Ashouri Talouki","raw_affiliation_strings":["University of Isfahan,Departement of Computer Engineering,Isfahan,Iran"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Isfahan,Departement of Computer Engineering,Isfahan,Iran","institution_ids":["https://openalex.org/I39268498"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5051306267"],"corresponding_institution_ids":["https://openalex.org/I39268498"],"apc_list":null,"apc_paid":null,"fwci":0.2798,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.66529394,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"13","last_page":"17"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9959999918937683,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8187907338142395},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7506027221679688},{"id":"https://openalex.org/keywords/generator","display_name":"Generator (circuit theory)","score":0.7318863272666931},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.6021024584770203},{"id":"https://openalex.org/keywords/white-box","display_name":"White box","score":0.5676195025444031},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.5661192536354065},{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.514309287071228},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.48231077194213867},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.47652944922447205},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.45660120248794556},{"id":"https://openalex.org/keywords/generative-adversarial-network","display_name":"Generative adversarial network","score":0.4421161413192749},{"id":"https://openalex.org/keywords/data-modeling","display_name":"Data modeling","score":0.42144834995269775},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.40558531880378723},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2620231807231903},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.17905399203300476},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.16549310088157654}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8187907338142395},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7506027221679688},{"id":"https://openalex.org/C2780992000","wikidata":"https://www.wikidata.org/wiki/Q17016113","display_name":"Generator (circuit theory)","level":3,"score":0.7318863272666931},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.6021024584770203},{"id":"https://openalex.org/C180932941","wikidata":"https://www.wikidata.org/wiki/Q997233","display_name":"White box","level":2,"score":0.5676195025444031},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.5661192536354065},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.514309287071228},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.48231077194213867},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.47652944922447205},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.45660120248794556},{"id":"https://openalex.org/C2988773926","wikidata":"https://www.wikidata.org/wiki/Q25104379","display_name":"Generative adversarial network","level":3,"score":0.4421161413192749},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.42144834995269775},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.40558531880378723},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2620231807231903},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.17905399203300476},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.16549310088157654},{"id":"https://openalex.org/C163258240","wikidata":"https://www.wikidata.org/wiki/Q25342","display_name":"Power (physics)","level":2,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C120665830","wikidata":"https://www.wikidata.org/wiki/Q14620","display_name":"Optics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/iscisc53448.2021.9720436","is_oa":false,"landing_page_url":"https://doi.org/10.1109/iscisc53448.2021.9720436","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 18th International ISC Conference on Information Security and Cryptology (ISCISC)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6899999976158142,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W2535690855","https://openalex.org/W2593414223","https://openalex.org/W2739748921","https://openalex.org/W2795435272","https://openalex.org/W2887995258","https://openalex.org/W2903389359","https://openalex.org/W2945237470","https://openalex.org/W2963378725","https://openalex.org/W2963684088","https://openalex.org/W2965527189","https://openalex.org/W3042943646","https://openalex.org/W3071470454","https://openalex.org/W3106873467","https://openalex.org/W3201409833","https://openalex.org/W4295521014","https://openalex.org/W4299412574","https://openalex.org/W4320013936","https://openalex.org/W6685352114","https://openalex.org/W6735913928","https://openalex.org/W6741832134","https://openalex.org/W6746775625","https://openalex.org/W6756699189","https://openalex.org/W6763077247","https://openalex.org/W6765779288"],"related_works":["https://openalex.org/W4297846880","https://openalex.org/W4307079546","https://openalex.org/W4283317927","https://openalex.org/W2950942529","https://openalex.org/W4324108765","https://openalex.org/W4307929675","https://openalex.org/W4285052570","https://openalex.org/W3102631191","https://openalex.org/W4365152419","https://openalex.org/W4214817174"],"abstract_inverted_index":{"Using":[0],"generative":[1,59],"models":[2,19,43],"to":[3,81,93,110],"generate":[4],"unlimited":[5],"number":[6],"of":[7,14,41,55,84,105],"synthetic":[8],"samples":[9],"is":[10,33,44,79],"a":[11,67],"popular":[12],"replacement":[13],"database":[15],"sharing.":[16],"When":[17],"these":[18,42],"are":[20],"built":[21],"using":[22],"sensitive":[23],"data,":[24],"the":[25,30,38,106],"developers":[26],"should":[27],"ensure":[28],"that":[29],"training":[31,98],"dataset":[32],"appropriately":[34],"protected.":[35],"Hence,":[36],"quantifying":[37],"privacy":[39,53],"risk":[40,54],"important.":[45],"In":[46],"this":[47],"paper,":[48],"we":[49,65],"focus":[50],"on":[51],"evaluating":[52],"publishing":[56],"generator":[57,116],"in":[58,113],"adversarial":[60],"network":[61],"(GAN)":[62],"models.":[63,75],"Specially,":[64],"conduct":[66],"white":[68,114],"box":[69,115],"membership":[70],"inference":[71],"attack":[72,78,89,108],"against":[73],"GAN":[74],"The":[76,100],"proposed":[77,107],"applicable":[80],"various":[82,94],"kinds":[83],"GANs.":[85],"We":[86],"evaluate":[87],"our":[88],"accuracy":[90],"with":[91],"respect":[92],"model":[95],"types":[96],"and":[97],"configurations.":[99],"results":[101],"demonstrate":[102],"superior":[103],"performance":[104],"compared":[109],"previous":[111],"attacks":[112],"access.":[117]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1}],"updated_date":"2026-05-07T13:39:58.223016","created_date":"2025-10-10T00:00:00"}
