{"id":"https://openalex.org/W4407638390","doi":"https://doi.org/10.1109/tdsc.2025.3543093","title":"On the Vulnerability of Data Points Under Multiple Membership Inference Attacks and Target Models","display_name":"On the Vulnerability of Data Points Under Multiple Membership Inference Attacks and Target Models","publication_year":2025,"publication_date":"2025-02-17","ids":{"openalex":"https://openalex.org/W4407638390","doi":"https://doi.org/10.1109/tdsc.2025.3543093"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2025.3543093","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2025.3543093","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://repository.ubn.ru.nl//bitstream/handle/2066/321274/321274.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5063847107","display_name":"Mauro Conti","orcid":"https://orcid.org/0000-0002-3612-1934"},"institutions":[{"id":"https://openalex.org/I138689650","display_name":"University of Padua","ror":"https://ror.org/00240q980","country_code":"IT","type":"education","lineage":["https://openalex.org/I138689650"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Mauro Conti","raw_affiliation_strings":["Department of Mathematics, University of Padua, Padua, Italy"],"raw_orcid":"https://orcid.org/0000-0002-3612-1934","affiliations":[{"raw_affiliation_string":"Department of Mathematics, University of Padua, Padua, Italy","institution_ids":["https://openalex.org/I138689650"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100343424","display_name":"Jiaxin Li","orcid":"https://orcid.org/0000-0002-5366-843X"},"institutions":[{"id":"https://openalex.org/I138689650","display_name":"University of Padua","ror":"https://ror.org/00240q980","country_code":"IT","type":"education","lineage":["https://openalex.org/I138689650"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Jiaxin Li","raw_affiliation_strings":["Department of Mathematics, University of Padua, Padua, Italy"],"raw_orcid":"https://orcid.org/0000-0002-5366-843X","affiliations":[{"raw_affiliation_string":"Department of Mathematics, University of Padua, Padua, Italy","institution_ids":["https://openalex.org/I138689650"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5024072796","display_name":"Stjepan Picek","orcid":"https://orcid.org/0000-0001-7509-4337"},"institutions":[{"id":"https://openalex.org/I145872427","display_name":"Radboud University Nijmegen","ror":"https://ror.org/016xsfp80","country_code":"NL","type":"education","lineage":["https://openalex.org/I145872427"]}],"countries":["NL"],"is_corresponding":false,"raw_author_name":"Stjepan Picek","raw_affiliation_strings":["Institute for Computing and Information Sciences, Radboud University, Nijmegen, The Netherlands"],"raw_orcid":"https://orcid.org/0000-0001-7509-4337","affiliations":[{"raw_affiliation_string":"Institute for Computing and Information Sciences, Radboud University, Nijmegen, The Netherlands","institution_ids":["https://openalex.org/I145872427"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5063847107"],"corresponding_institution_ids":["https://openalex.org/I138689650"],"apc_list":null,"apc_paid":null,"fwci":2.1733,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.87193892,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":"22","issue":"4","first_page":"4022","last_page":"4039"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9930999875068665,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7354134917259216},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5953755974769592},{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5809226036071777},{"id":"https://openalex.org/keywords/data-modeling","display_name":"Data modeling","score":0.5509065389633179},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4363192319869995},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4119536280632019},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.27171629667282104}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7354134917259216},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5953755974769592},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5809226036071777},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.5509065389633179},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4363192319869995},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4119536280632019},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.27171629667282104},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tdsc.2025.3543093","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2025.3543093","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},{"id":"pmh:oai:repository.ubn.ru.nl:2066/321274","is_oa":true,"landing_page_url":"https://hdl.handle.net/2066/321274","pdf_url":"https://repository.ubn.ru.nl//bitstream/handle/2066/321274/321274.pdf","source":{"id":"https://openalex.org/S4306401067","display_name":"Radboud Repository (Radboud University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I145872427","host_organization_name":"Radboud University Nijmegen","host_organization_lineage":["https://openalex.org/I145872427"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Article / Letter to editor"}],"best_oa_location":{"id":"pmh:oai:repository.ubn.ru.nl:2066/321274","is_oa":true,"landing_page_url":"https://hdl.handle.net/2066/321274","pdf_url":"https://repository.ubn.ru.nl//bitstream/handle/2066/321274/321274.pdf","source":{"id":"https://openalex.org/S4306401067","display_name":"Radboud Repository (Radboud University)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I145872427","host_organization_name":"Radboud University Nijmegen","host_organization_lineage":["https://openalex.org/I145872427"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"Article / Letter to editor"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320322725","display_name":"China Scholarship Council","ror":"https://ror.org/04atp4p48"}],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4407638390.pdf"},"referenced_works_count":54,"referenced_works":["https://openalex.org/W1964940342","https://openalex.org/W2095705004","https://openalex.org/W2100805904","https://openalex.org/W2101549186","https://openalex.org/W2295598076","https://openalex.org/W2295797531","https://openalex.org/W2473418344","https://openalex.org/W2535690855","https://openalex.org/W2795435272","https://openalex.org/W2884943453","https://openalex.org/W2887995258","https://openalex.org/W2912023992","https://openalex.org/W2930926105","https://openalex.org/W2963178695","https://openalex.org/W2963378725","https://openalex.org/W2963456518","https://openalex.org/W2963844355","https://openalex.org/W2983140679","https://openalex.org/W3004854517","https://openalex.org/W3042943646","https://openalex.org/W3071470454","https://openalex.org/W3081096564","https://openalex.org/W3096692244","https://openalex.org/W3103245149","https://openalex.org/W3106873467","https://openalex.org/W3115042282","https://openalex.org/W3125963848","https://openalex.org/W3126787694","https://openalex.org/W3150395569","https://openalex.org/W3155551741","https://openalex.org/W3181414820","https://openalex.org/W3206855510","https://openalex.org/W3211490561","https://openalex.org/W3213187311","https://openalex.org/W3214437258","https://openalex.org/W3214968384","https://openalex.org/W4288057780","https://openalex.org/W4299551239","https://openalex.org/W4308410483","https://openalex.org/W4315706478","https://openalex.org/W4320086218","https://openalex.org/W6640425456","https://openalex.org/W6674330103","https://openalex.org/W6737100851","https://openalex.org/W6763077247","https://openalex.org/W6773738116","https://openalex.org/W6775482175","https://openalex.org/W6781475444","https://openalex.org/W6781511523","https://openalex.org/W6789723219","https://openalex.org/W6789917881","https://openalex.org/W6801935883","https://openalex.org/W6804464829","https://openalex.org/W6850102650"],"related_works":["https://openalex.org/W2055243143","https://openalex.org/W2095999892","https://openalex.org/W2018764758","https://openalex.org/W2383689843","https://openalex.org/W1550668881","https://openalex.org/W617913288","https://openalex.org/W2062873522","https://openalex.org/W2319323865","https://openalex.org/W2951745010","https://openalex.org/W1986418932"],"abstract_inverted_index":{"Membership":[0,122],"Inference":[1,123],"Attacks":[2,124],"(MIAs)":[3],"infer":[4],"whether":[5],"a":[6,15,71,144],"data":[7,13,24,32,41,47,62,80,86,141,157,182],"point":[8],"is":[9],"in":[10,45],"the":[11,46,59,129,168,179],"training":[12],"of":[14,48,61,170,181],"machine":[16],"learning":[17],"model,":[18],"posing":[19],"privacy":[20],"risks":[21],"to":[22,54,109,111,139],"sensitive":[23],"like":[25],"medical":[26],"records":[27],"or":[28],"financial":[29],"data.":[30],"Intuitively,":[31],"points":[33,42,63,87,142,158],"that":[34,133],"MIA":[35,134],"accurately":[36],"detects":[37],"are":[38,152],"vulnerable.":[39],"Those":[40],"may":[43],"exist":[44],"different":[49],"target":[50,68,92,104,163],"models,":[51],"each":[52],"susceptible":[53],"multiple":[55,65,89,160],"MIAs.":[56],"As":[57],"such,":[58],"vulnerability":[60,82,180],"under":[64,88,159],"MIAs":[66,90,161],"and":[67,83,91,118,162,174],"models":[69,105,176],"represents":[70],"significant":[72],"challenge.":[73],"This":[74],"article":[75],"defines":[76],"several":[77],"metrics":[78],"reflecting":[79],"points\u2019":[81],"capturing":[84],"vulnerable":[85,156],"models.":[93,164],"We":[94],"implement":[95],"77":[96],"MIAs,":[97],"with":[98,115],"an":[99,136],"average":[100],"attack":[101,175],"accuracy":[102],"over":[103],"ranging":[106],"from":[107],"0.5":[108],"0.9,":[110],"support":[112],"our":[113,116],"analysis":[114],"scalable":[117],"flexible":[119],"platform,":[120],"Various":[121],"Platform":[125],"(VMIAP).":[126],"Based":[127],"on":[128,178],"results,":[130],"we":[131,166],"observe":[132],"has":[135],"inference":[137,147],"tendency":[138],"some":[140],"despite":[143],"low":[145],"overall":[146],"performance.":[148],"Furthermore,":[149],"previous":[150],"approaches":[151],"unsuitable":[153],"for":[154],"finding":[155],"Finally,":[165],"explore":[167],"impact":[169],"retraining":[171],"target,":[172],"shadow,":[173],"separately":[177],"points.":[183]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
