{"id":"https://openalex.org/W4385679801","doi":"https://doi.org/10.1109/sp46215.2023.10179463","title":"Accuracy-Privacy Trade-off in Deep Ensemble: A Membership Inference Perspective","display_name":"Accuracy-Privacy Trade-off in Deep Ensemble: A Membership Inference Perspective","publication_year":2023,"publication_date":"2023-05-01","ids":{"openalex":"https://openalex.org/W4385679801","doi":"https://doi.org/10.1109/sp46215.2023.10179463"},"language":"en","primary_location":{"id":"doi:10.1109/sp46215.2023.10179463","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46215.2023.10179463","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5048444456","display_name":"Shahbaz Rezaei","orcid":"https://orcid.org/0000-0003-1583-0114"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Shahbaz Rezaei","raw_affiliation_strings":["University of California,Davis,CA,USA","University of California, Davis, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California,Davis,CA,USA","institution_ids":["https://openalex.org/I84218800"]},{"raw_affiliation_string":"University of California, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5011499718","display_name":"Zubair Shafiq","orcid":"https://orcid.org/0000-0002-4500-9354"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Zubair Shafiq","raw_affiliation_strings":["University of California,Davis,CA,USA","University of California, Davis, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California,Davis,CA,USA","institution_ids":["https://openalex.org/I84218800"]},{"raw_affiliation_string":"University of California, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100352241","display_name":"Xin Liu","orcid":"https://orcid.org/0000-0002-5379-8269"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xin Liu","raw_affiliation_strings":["University of California,Davis,CA,USA","University of California, Davis, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California,Davis,CA,USA","institution_ids":["https://openalex.org/I84218800"]},{"raw_affiliation_string":"University of California, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5048444456"],"corresponding_institution_ids":["https://openalex.org/I84218800"],"apc_list":null,"apc_paid":null,"fwci":1.049,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.81152584,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"364","last_page":"381"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11636","display_name":"Artificial Intelligence in Healthcare and Education","score":0.9616000056266785,"subfield":{"id":"https://openalex.org/subfields/2718","display_name":"Health Informatics"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.8740674257278442},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7673509120941162},{"id":"https://openalex.org/keywords/snapshot","display_name":"Snapshot (computer storage)","score":0.6696562767028809},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6575493812561035},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6366044282913208},{"id":"https://openalex.org/keywords/deep-neural-networks","display_name":"Deep neural networks","score":0.565349817276001},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5631870031356812},{"id":"https://openalex.org/keywords/differential-privacy","display_name":"Differential privacy","score":0.5250146985054016},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.5024411678314209},{"id":"https://openalex.org/keywords/ensemble-learning","display_name":"Ensemble learning","score":0.47416961193084717},{"id":"https://openalex.org/keywords/regularization","display_name":"Regularization (linguistics)","score":0.4660915434360504},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.43703097105026245}],"concepts":[{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.8740674257278442},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7673509120941162},{"id":"https://openalex.org/C55282118","wikidata":"https://www.wikidata.org/wiki/Q252683","display_name":"Snapshot (computer storage)","level":2,"score":0.6696562767028809},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6575493812561035},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6366044282913208},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.565349817276001},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5631870031356812},{"id":"https://openalex.org/C23130292","wikidata":"https://www.wikidata.org/wiki/Q5275358","display_name":"Differential privacy","level":2,"score":0.5250146985054016},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.5024411678314209},{"id":"https://openalex.org/C45942800","wikidata":"https://www.wikidata.org/wiki/Q245652","display_name":"Ensemble learning","level":2,"score":0.47416961193084717},{"id":"https://openalex.org/C2776135515","wikidata":"https://www.wikidata.org/wiki/Q17143721","display_name":"Regularization (linguistics)","level":2,"score":0.4660915434360504},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.43703097105026245},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/sp46215.2023.10179463","is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp46215.2023.10179463","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE Symposium on Security and Privacy (SP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.5600000023841858,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":79,"referenced_works":["https://openalex.org/W2051267297","https://openalex.org/W2109426455","https://openalex.org/W2112796928","https://openalex.org/W2115629999","https://openalex.org/W2117539524","https://openalex.org/W2172734211","https://openalex.org/W2194775991","https://openalex.org/W2535690855","https://openalex.org/W2750384547","https://openalex.org/W2778284298","https://openalex.org/W2786233556","https://openalex.org/W2789758093","https://openalex.org/W2795435272","https://openalex.org/W2884943453","https://openalex.org/W2897830718","https://openalex.org/W2912023992","https://openalex.org/W2912083425","https://openalex.org/W2930926105","https://openalex.org/W2946363484","https://openalex.org/W2948030332","https://openalex.org/W2951696358","https://openalex.org/W2962835266","https://openalex.org/W2963378725","https://openalex.org/W2983140679","https://openalex.org/W2989885118","https://openalex.org/W2992525328","https://openalex.org/W3015625436","https://openalex.org/W3021166038","https://openalex.org/W3023716276","https://openalex.org/W3024386862","https://openalex.org/W3035261884","https://openalex.org/W3039588859","https://openalex.org/W3042806674","https://openalex.org/W3046102592","https://openalex.org/W3046208783","https://openalex.org/W3081096564","https://openalex.org/W3081595899","https://openalex.org/W3084357355","https://openalex.org/W3103245149","https://openalex.org/W3104224589","https://openalex.org/W3105637493","https://openalex.org/W3110164654","https://openalex.org/W3110515436","https://openalex.org/W3118608800","https://openalex.org/W3155551741","https://openalex.org/W3170237968","https://openalex.org/W3170901302","https://openalex.org/W3190398575","https://openalex.org/W4221140056","https://openalex.org/W4226445324","https://openalex.org/W4246193833","https://openalex.org/W4288057780","https://openalex.org/W6685500198","https://openalex.org/W6703116779","https://openalex.org/W6730042731","https://openalex.org/W6737496325","https://openalex.org/W6743688258","https://openalex.org/W6746849571","https://openalex.org/W6747553010","https://openalex.org/W6752346538","https://openalex.org/W6763077247","https://openalex.org/W6765055791","https://openalex.org/W6771378952","https://openalex.org/W6776455625","https://openalex.org/W6776993083","https://openalex.org/W6777717587","https://openalex.org/W6780505285","https://openalex.org/W6780820450","https://openalex.org/W6781508659","https://openalex.org/W6781511523","https://openalex.org/W6782331252","https://openalex.org/W6782733353","https://openalex.org/W6786706431","https://openalex.org/W6786823094","https://openalex.org/W6786871979","https://openalex.org/W6787972765","https://openalex.org/W6799846784","https://openalex.org/W6803256842","https://openalex.org/W6810782223"],"related_works":["https://openalex.org/W4380075502","https://openalex.org/W4223943233","https://openalex.org/W4312200629","https://openalex.org/W4360585206","https://openalex.org/W4364306694","https://openalex.org/W2810053714","https://openalex.org/W3136979370","https://openalex.org/W2791691546","https://openalex.org/W3202860343","https://openalex.org/W4378505913"],"abstract_inverted_index":{"Deep":[0],"ensemble":[1,131,150],"learning":[2,19],"has":[3,20],"been":[4,22],"shown":[5],"to":[6,24,163],"improve":[7,169],"accuracy":[8,46,171],"by":[9],"training":[10],"multiple":[11],"neural":[12],"networks":[13],"and":[14,47,64,91,111,140,148,172],"averaging":[15],"their":[16],"outputs.":[17],"Ensemble":[18],"also":[21],"suggested":[23],"defend":[25],"against":[26,104],"membership":[27,52,73,105,125],"inference":[28,53,74,106,126],"attacks":[29,75,107],"that":[30,69,116],"undermine":[31],"privacy.":[32,113],"In":[33],"this":[34],"paper,":[35],"we":[36,67,100,153],"empirically":[37],"demonstrate":[38,92],"a":[39,59,155],"trade-off":[40,136,166],"between":[41],"these":[42,118],"two":[43],"goals,":[44],"namely":[45],"privacy":[48],"(in":[49],"terms":[50],"of":[51,62,72,85,96,124],"attacks),":[54],"in":[55,88,137],"deep":[56,89,161],"ensembles.":[57],"Using":[58],"wide":[60],"range":[61],"datasets":[63],"model":[65],"architectures,":[66],"show":[68,115],"the":[70,83,93,97,122,165,170],"effectiveness":[71,123],"increases":[76],"when":[77],"ensembling":[78,142],"improves":[79],"accuracy.":[80,132],"We":[81,114,133],"analyze":[82],"impact":[84],"various":[86],"factors":[87],"ensembles":[90,147,162],"root":[94],"cause":[95],"trade-off.":[98],"Then,":[99],"evaluate":[101],"common":[102],"defenses":[103,119],"based":[108],"on":[109],"regularization":[110],"differential":[112],"while":[117],"can":[120],"mitigate":[121],"attacks,":[127],"they":[128],"simultaneously":[129],"degrade":[130],"illustrate":[134],"similar":[135],"more":[138],"advanced":[139],"state-of-the-art":[141],"techniques,":[143],"such":[144],"as":[145],"snapshot":[146],"diversified":[149],"networks.":[151],"Finally,":[152],"propose":[154],"simple":[156],"yet":[157],"effective":[158],"defense":[159],"for":[160],"break":[164],"and,":[167],"consequently,":[168],"privacy,":[173],"simultaneously.":[174]},"counts_by_year":[{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
