{"id":"https://openalex.org/W4408166050","doi":"https://doi.org/10.1109/tdsc.2025.3548119","title":"Model Inversion Attack Against Transfer Learning: Inverting a Model Without Querying It","display_name":"Model Inversion Attack Against Transfer Learning: Inverting a Model Without Querying It","publication_year":2025,"publication_date":"2025-03-05","ids":{"openalex":"https://openalex.org/W4408166050","doi":"https://doi.org/10.1109/tdsc.2025.3548119"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2025.3548119","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2025.3548119","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5065910481","display_name":"Dayong Ye","orcid":"https://orcid.org/0000-0002-7561-0992"},"institutions":[{"id":"https://openalex.org/I114017466","display_name":"University of Technology Sydney","ror":"https://ror.org/03f0f6041","country_code":"AU","type":"education","lineage":["https://openalex.org/I114017466"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Dayong Ye","raw_affiliation_strings":["School of Computer Science, University of Technology Sydney, Sydney, NSW, Australia","School of Computer Science, University of Technology Sydney, NSW, Australia"],"raw_orcid":"https://orcid.org/0000-0002-7561-0992","affiliations":[{"raw_affiliation_string":"School of Computer Science, University of Technology Sydney, Sydney, NSW, Australia","institution_ids":["https://openalex.org/I114017466"]},{"raw_affiliation_string":"School of Computer Science, University of Technology Sydney, NSW, Australia","institution_ids":["https://openalex.org/I114017466"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5115995603","display_name":"Huiqiang Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I6469544","display_name":"City University of Macau","ror":"https://ror.org/04gpd4q15","country_code":"MO","type":"education","lineage":["https://openalex.org/I6469544"]}],"countries":["MO"],"is_corresponding":false,"raw_author_name":"Huiqiang Chen","raw_affiliation_strings":["Institute of Data Science, City University of Macau, Macau, China","Institute of Data Science, City University of Macau, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Institute of Data Science, City University of Macau, Macau, China","institution_ids":["https://openalex.org/I6469544"]},{"raw_affiliation_string":"Institute of Data Science, City University of Macau, China","institution_ids":["https://openalex.org/I6469544"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081255430","display_name":"Shuai Zhou","orcid":"https://orcid.org/0000-0002-7702-3417"},"institutions":[{"id":"https://openalex.org/I6469544","display_name":"City University of Macau","ror":"https://ror.org/04gpd4q15","country_code":"MO","type":"education","lineage":["https://openalex.org/I6469544"]}],"countries":["MO"],"is_corresponding":false,"raw_author_name":"Shuai Zhou","raw_affiliation_strings":["Faculty of Data Science, City University of Macau, Macau, China","Institute of Data Science, City University of Macau, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Faculty of Data Science, City University of Macau, Macau, China","institution_ids":["https://openalex.org/I6469544"]},{"raw_affiliation_string":"Institute of Data Science, City University of Macau, China","institution_ids":["https://openalex.org/I6469544"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036801346","display_name":"Tianqing Zhu","orcid":"https://orcid.org/0000-0003-3411-7947"},"institutions":[{"id":"https://openalex.org/I6469544","display_name":"City University of Macau","ror":"https://ror.org/04gpd4q15","country_code":"MO","type":"education","lineage":["https://openalex.org/I6469544"]}],"countries":["MO"],"is_corresponding":false,"raw_author_name":"Tianqing Zhu","raw_affiliation_strings":["Institute of Data Science, City University of Macau, Macau, China","Institute of Data Science, City University of Macau, China"],"raw_orcid":"https://orcid.org/0000-0003-3411-7947","affiliations":[{"raw_affiliation_string":"Institute of Data Science, City University of Macau, Macau, China","institution_ids":["https://openalex.org/I6469544"]},{"raw_affiliation_string":"Institute of Data Science, City University of Macau, China","institution_ids":["https://openalex.org/I6469544"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051406984","display_name":"Wanlei Zhou","orcid":"https://orcid.org/0000-0002-1680-2521"},"institutions":[{"id":"https://openalex.org/I6469544","display_name":"City University of Macau","ror":"https://ror.org/04gpd4q15","country_code":"MO","type":"education","lineage":["https://openalex.org/I6469544"]}],"countries":["MO"],"is_corresponding":false,"raw_author_name":"Wanlei Zhou","raw_affiliation_strings":["Institute of Data Science, City University of Macau, Macau, China","Institute of Data Science, City University of Macau, China"],"raw_orcid":"https://orcid.org/0000-0002-1680-2521","affiliations":[{"raw_affiliation_string":"Institute of Data Science, City University of Macau, Macau, China","institution_ids":["https://openalex.org/I6469544"]},{"raw_affiliation_string":"Institute of Data Science, City University of Macau, China","institution_ids":["https://openalex.org/I6469544"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5058611515","display_name":"Shouling Ji","orcid":"https://orcid.org/0000-0003-4268-372X"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shouling Ji","raw_affiliation_strings":["College of Computer Science and Technology, Zhejiang University, Hangzhou, China","College of Computer Science and Technology, Zhejiang University, China"],"raw_orcid":"https://orcid.org/0000-0003-4268-372X","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I168879160"]},{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, China","institution_ids":["https://openalex.org/I168879160"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5065910481"],"corresponding_institution_ids":["https://openalex.org/I114017466"],"apc_list":null,"apc_paid":null,"fwci":4.3465,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.93295291,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"22","issue":"4","first_page":"4472","last_page":"4487"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9945999979972839,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9945999979972839,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7503121495246887},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.554142951965332},{"id":"https://openalex.org/keywords/transfer-of-learning","display_name":"Transfer of learning","score":0.4566362202167511},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3420603275299072},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.272885262966156},{"id":"https://openalex.org/keywords/geology","display_name":"Geology","score":0.12716665863990784}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7503121495246887},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.554142951965332},{"id":"https://openalex.org/C150899416","wikidata":"https://www.wikidata.org/wiki/Q1820378","display_name":"Transfer of learning","level":2,"score":0.4566362202167511},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3420603275299072},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.272885262966156},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.12716665863990784},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tdsc.2025.3548119","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2025.3548119","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Reduced inequalities","score":0.4399999976158142,"id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":51,"referenced_works":["https://openalex.org/W1834627138","https://openalex.org/W2024922353","https://openalex.org/W2051267297","https://openalex.org/W2295107390","https://openalex.org/W2535690855","https://openalex.org/W2606462007","https://openalex.org/W2767566874","https://openalex.org/W2894906112","https://openalex.org/W2897865027","https://openalex.org/W2904008038","https://openalex.org/W2949736877","https://openalex.org/W2954996726","https://openalex.org/W2962770929","https://openalex.org/W2963465221","https://openalex.org/W2963542245","https://openalex.org/W2963845150","https://openalex.org/W2985580374","https://openalex.org/W2985913519","https://openalex.org/W2992308087","https://openalex.org/W2999321020","https://openalex.org/W3023371261","https://openalex.org/W3035616549","https://openalex.org/W3035682985","https://openalex.org/W3035725276","https://openalex.org/W3041133507","https://openalex.org/W3113374047","https://openalex.org/W3175192640","https://openalex.org/W3176913662","https://openalex.org/W3197312262","https://openalex.org/W3200264958","https://openalex.org/W3202500832","https://openalex.org/W4214567027","https://openalex.org/W4226136925","https://openalex.org/W4242986078","https://openalex.org/W4312307529","https://openalex.org/W4313547874","https://openalex.org/W6628547770","https://openalex.org/W6637373629","https://openalex.org/W6638484148","https://openalex.org/W6754279747","https://openalex.org/W6760759230","https://openalex.org/W6761076018","https://openalex.org/W6775563089","https://openalex.org/W6778883912","https://openalex.org/W6780245538","https://openalex.org/W6782733353","https://openalex.org/W6787335730","https://openalex.org/W6789034737","https://openalex.org/W6791544697","https://openalex.org/W6798190327","https://openalex.org/W6810738896"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"Transfer":[0],"learning":[1,26,49,63,118],"is":[2,31,43,50,65,79,203],"an":[3],"important":[4],"approach":[5],"that":[6,29,131,152,179,198],"produces":[7],"pre-trained":[8],"teacher":[9,163],"models":[10],"which":[11],"can":[12,184,209],"be":[13,185,211],"used":[14],"to":[15,33,52,83,137,213],"quickly":[16],"build":[17],"specialized":[18],"student":[19,71,90,140],"models.":[20],"However,":[21,41],"recent":[22],"research":[23,111,193],"on":[24,101,135],"transfer":[25,48,62,117],"has":[27,148],"found":[28],"it":[30,42,78,208],"vulnerable":[32,51],"various":[34],"attacks,":[35,127],"e.g.,":[36],"misclassification":[37],"and":[38],"backdoor":[39],"attacks.":[40,55,216],"still":[44,210],"not":[45,81,133,172],"clear":[46],"whether":[47],"model":[53,58,72,93,113,202,214],"inversion":[54,59,94,114,215],"Launching":[56],"a":[57,89,201],"attack":[60,122],"against":[61,116],"scheme":[64],"challenging.":[66],"Not":[67],"only":[68],"does":[69,171],"the":[70,84,103,138,143,146,149,154,158,162,166,169,195],"hide":[73],"its":[74],"structural":[75],"parameters,":[76],"but":[77],"also":[80],"queried":[82],"adversary.":[85],"Hence,":[86],"when":[87,200],"targeting":[88],"model,":[91],"existing":[92],"attacks":[95,115],"fail,":[96],"as":[97,157],"they":[98],"typically":[99],"rely":[100,134],"querying":[102],"target":[104,139],"model.":[105,141,164],"In":[106,142,165],"this":[107],"paper,":[108],"we":[109],"initiate":[110],"into":[112],"with":[119,187],"two":[120],"novel":[121],"methods.":[123,191],"Both":[124],"are":[125],"black-box":[126],"suiting":[128],"different":[129],"situations,":[130],"do":[132],"queries":[136],"first":[144],"method,":[145,168],"adversary":[147,170],"data":[150,182],"samples":[151],"share":[153],"same":[155],"distribution":[156],"training":[159],"set":[160],"of":[161,189],"second":[167],"have":[173],"any":[174],"such":[175],"samples.":[176],"Experiments":[177],"show":[178],"highly":[180],"recognizable":[181],"records":[183],"inverted":[186],"both":[188],"these":[190],"This":[192],"underscores":[194],"critical":[196],"insight":[197],"even":[199],"shielded":[204],"from":[205],"public":[206],"queries,":[207],"susceptible":[212]},"counts_by_year":[{"year":2026,"cited_by_count":2}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
