{"id":"https://openalex.org/W4285262889","doi":"https://doi.org/10.1109/tetc.2022.3179980","title":"An Approximate Memory Based Defense Against Model Inversion Attacks to Neural Networks","display_name":"An Approximate Memory Based Defense Against Model Inversion Attacks to Neural Networks","publication_year":2022,"publication_date":"2022-06-09","ids":{"openalex":"https://openalex.org/W4285262889","doi":"https://doi.org/10.1109/tetc.2022.3179980"},"language":"en","primary_location":{"id":"doi:10.1109/tetc.2022.3179980","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tetc.2022.3179980","pdf_url":null,"source":{"id":"https://openalex.org/S2496326734","display_name":"IEEE Transactions on Emerging Topics in Computing","issn_l":"2168-6750","issn":["2168-6750","2376-4562"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Emerging Topics in Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5015070751","display_name":"Qian Xu","orcid":"https://orcid.org/0000-0001-6143-9787"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Qian Xu","raw_affiliation_strings":["Electrical and Computer Engineering Department, University of Maryland, College Park, MD, USA"],"affiliations":[{"raw_affiliation_string":"Electrical and Computer Engineering Department, University of Maryland, College Park, MD, USA","institution_ids":["https://openalex.org/I66946132"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077280198","display_name":"Md Tanvir Arafin","orcid":"https://orcid.org/0000-0002-5179-5216"},"institutions":[{"id":"https://openalex.org/I83909951","display_name":"Morgan State University","ror":"https://ror.org/017d8gk22","country_code":"US","type":"education","lineage":["https://openalex.org/I83909951"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Md Tanvir Arafin","raw_affiliation_strings":["ECE Department, Morgan State University, Baltimore, MD, USA"],"affiliations":[{"raw_affiliation_string":"ECE Department, Morgan State University, Baltimore, MD, USA","institution_ids":["https://openalex.org/I83909951"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012474783","display_name":"Gang Qu","orcid":"https://orcid.org/0000-0001-6759-8949"},"institutions":[{"id":"https://openalex.org/I66946132","display_name":"University of Maryland, College Park","ror":"https://ror.org/047s2c258","country_code":"US","type":"education","lineage":["https://openalex.org/I66946132"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Gang Qu","raw_affiliation_strings":["ECE and ISR, University of Maryland, College Park, MD, USA"],"affiliations":[{"raw_affiliation_string":"ECE and ISR, University of Maryland, College Park, MD, USA","institution_ids":["https://openalex.org/I66946132"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5015070751"],"corresponding_institution_ids":["https://openalex.org/I66946132"],"apc_list":null,"apc_paid":null,"fwci":0.3979,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.66184263,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":96},"biblio":{"volume":"10","issue":"4","first_page":"1733","last_page":"1745"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12122","display_name":"Physical Unclonable Functions (PUFs) and Hardware Security","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10502","display_name":"Advanced Memory and Neural Computing","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/2208","display_name":"Electrical and Electronic Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8313387632369995},{"id":"https://openalex.org/keywords/dram","display_name":"Dram","score":0.7224205136299133},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.6479935646057129},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.49892115592956543},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.4683743417263031},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.44118532538414},{"id":"https://openalex.org/keywords/computer-engineering","display_name":"Computer engineering","score":0.3978758156299591},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3592478036880493},{"id":"https://openalex.org/keywords/embedded-system","display_name":"Embedded system","score":0.3249180316925049},{"id":"https://openalex.org/keywords/computer-hardware","display_name":"Computer hardware","score":0.1657385230064392}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8313387632369995},{"id":"https://openalex.org/C7366592","wikidata":"https://www.wikidata.org/wiki/Q1255620","display_name":"Dram","level":2,"score":0.7224205136299133},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.6479935646057129},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.49892115592956543},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.4683743417263031},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.44118532538414},{"id":"https://openalex.org/C113775141","wikidata":"https://www.wikidata.org/wiki/Q428691","display_name":"Computer engineering","level":1,"score":0.3978758156299591},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3592478036880493},{"id":"https://openalex.org/C149635348","wikidata":"https://www.wikidata.org/wiki/Q193040","display_name":"Embedded system","level":1,"score":0.3249180316925049},{"id":"https://openalex.org/C9390403","wikidata":"https://www.wikidata.org/wiki/Q3966","display_name":"Computer hardware","level":1,"score":0.1657385230064392},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tetc.2022.3179980","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tetc.2022.3179980","pdf_url":null,"source":{"id":"https://openalex.org/S2496326734","display_name":"IEEE Transactions on Emerging Topics in Computing","issn_l":"2168-6750","issn":["2168-6750","2376-4562"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Emerging Topics in Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320332180","display_name":"Defense Advanced Research Projects Agency","ror":"https://ror.org/02caytj08"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":42,"referenced_works":["https://openalex.org/W124944822","https://openalex.org/W1473189865","https://openalex.org/W1480376833","https://openalex.org/W1834627138","https://openalex.org/W1915485278","https://openalex.org/W1963998358","https://openalex.org/W2001041320","https://openalex.org/W2024922353","https://openalex.org/W2032820948","https://openalex.org/W2051267297","https://openalex.org/W2105216798","https://openalex.org/W2105407012","https://openalex.org/W2116374153","https://openalex.org/W2190008860","https://openalex.org/W2330864775","https://openalex.org/W2401836885","https://openalex.org/W2565435739","https://openalex.org/W2565960208","https://openalex.org/W2588907924","https://openalex.org/W2612315906","https://openalex.org/W2615368515","https://openalex.org/W2794842046","https://openalex.org/W2811364593","https://openalex.org/W2946697723","https://openalex.org/W2949493305","https://openalex.org/W2953044030","https://openalex.org/W2965470910","https://openalex.org/W2979754840","https://openalex.org/W2985580374","https://openalex.org/W2997613220","https://openalex.org/W2998041822","https://openalex.org/W3020870837","https://openalex.org/W3035616549","https://openalex.org/W3129330586","https://openalex.org/W3136120147","https://openalex.org/W3156573592","https://openalex.org/W4252290681","https://openalex.org/W4297752781","https://openalex.org/W6628547770","https://openalex.org/W6717255582","https://openalex.org/W6766568290","https://openalex.org/W6794124026"],"related_works":["https://openalex.org/W3120961607","https://openalex.org/W3148568549","https://openalex.org/W2098207691","https://openalex.org/W1648516568","https://openalex.org/W361036515","https://openalex.org/W4211178602","https://openalex.org/W2269474412","https://openalex.org/W4386903460","https://openalex.org/W2537599394","https://openalex.org/W4390846322"],"abstract_inverted_index":{"Diverse":[0],"and":[1,39,97,129,141],"comprehensive":[2],"training":[3,31,47,110,132],"data":[4,48,111],"is":[5],"critical":[6],"in":[7],"building":[8],"robust":[9],"machine":[10],"learning":[11],"(ML)":[12],"models.":[13],"However,":[14],"model":[15,24,89],"inversion":[16],"attacks":[17],"(MIA)":[18],"have":[19],"demonstrated":[20],"that":[21,105],"an":[22,61],"ML":[23,77],"can":[25,107],"leak":[26],"important":[27],"information":[28],"about":[29],"its":[30],"dataset.":[32],"This":[33],"work":[34],"examines":[35],"the":[36,46,75,86,94,119,127,130,136],"existing":[37],"MIAs":[38],"proposes":[40],"a":[41],"hardware-oriented":[42],"solution":[43,54],"to":[44,70,84],"protect":[45,109],"from":[49,112],"such":[50],"attacks.":[51,115],"Our":[52,102],"proposed":[53,100],"\u2013":[55,65],"MIDAS:":[56],"Model":[57],"Inversion":[58],"Defenses":[59],"with":[60,90],"Approximate":[62],"memory":[63,68],"System":[64],"intentionally":[66],"introduces":[67],"faults":[69],"thwart":[71],"MIA":[72],"without":[73],"compromising":[74],"original":[76,128],"model.":[78],"We":[79],"use":[80],"detailed":[81],"SPICE":[82],"simulations":[83],"build":[85],"DRAM":[87],"fault":[88],"voltage":[91],"overscaling,":[92],"implement":[93],"state-of-the-art":[95],"MIAs,":[96],"evaluate":[98],"our":[99],"solution.":[101],"experiments":[103],"demonstrate":[104],"MIDAS":[106,134],"effectively":[108],"run-time":[113],"adversarial":[114],"In":[116],"terms":[117],"of":[118],"Pearson":[120],"Correlation":[121],"Coefficient":[122],"(PCC)":[123],"similarity":[124],"measure":[125],"(between":[126],"recovered":[131],"data),":[133],"reduces":[135],"PCC":[137],"value":[138],"for":[139],"shallow":[140],"deep":[142],"neural":[143],"networks.":[144]},"counts_by_year":[{"year":2024,"cited_by_count":2},{"year":2022,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
