{"id":"https://openalex.org/W4214931017","doi":"https://doi.org/10.1109/tifs.2022.3155921","title":"Your Model Trains on My Data? Protecting Intellectual Property of Training Data via Membership Fingerprint Authentication","display_name":"Your Model Trains on My Data? Protecting Intellectual Property of Training Data via Membership Fingerprint Authentication","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4214931017","doi":"https://doi.org/10.1109/tifs.2022.3155921"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2022.3155921","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3155921","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5104666790","display_name":"Gaoyang Liu","orcid":"https://orcid.org/0000-0003-2566-9360"},"institutions":[{"id":"https://openalex.org/I18014758","display_name":"Simon Fraser University","ror":"https://ror.org/0213rcc28","country_code":"CA","type":"education","lineage":["https://openalex.org/I18014758"]},{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CA","CN"],"is_corresponding":true,"raw_author_name":"Gaoyang Liu","raw_affiliation_strings":["Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China","School of Computing Science, Simon Fraser University, Burnaby, BC, Canada"],"affiliations":[{"raw_affiliation_string":"Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]},{"raw_affiliation_string":"School of Computing Science, Simon Fraser University, Burnaby, BC, Canada","institution_ids":["https://openalex.org/I18014758"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101306543","display_name":"Tianlong Xu","orcid":null},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tianlong Xu","raw_affiliation_strings":["Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101637757","display_name":"Xiaoqiang Ma","orcid":"https://orcid.org/0000-0001-9987-0329"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaoqiang Ma","raw_affiliation_strings":["Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100337659","display_name":"Chen Wang","orcid":"https://orcid.org/0000-0003-1963-4954"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chen Wang","raw_affiliation_strings":["Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Hubei Key Laboratory of Smart Internet Technology, School of Electronic Information and Communications, Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5104666790"],"corresponding_institution_ids":["https://openalex.org/I18014758","https://openalex.org/I47720641"],"apc_list":null,"apc_paid":null,"fwci":4.2732,"has_fulltext":false,"cited_by_count":31,"citation_normalized_percentile":{"value":0.947575,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":100},"biblio":{"volume":"17","issue":null,"first_page":"1024","last_page":"1037"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9987999796867371,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10883","display_name":"Ethics and Social Impacts of AI","score":0.96670001745224,"subfield":{"id":"https://openalex.org/subfields/3311","display_name":"Safety Research"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8109675645828247},{"id":"https://openalex.org/keywords/fingerprint","display_name":"Fingerprint (computing)","score":0.6917054057121277},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.6133611798286438},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5629913210868835},{"id":"https://openalex.org/keywords/property","display_name":"Property (philosophy)","score":0.5152354836463928},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.501331090927124},{"id":"https://openalex.org/keywords/suspect","display_name":"Suspect","score":0.46481236815452576},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.456603080034256},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.44852039217948914},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4472426772117615},{"id":"https://openalex.org/keywords/data-modeling","display_name":"Data modeling","score":0.44383442401885986},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.4251856207847595},{"id":"https://openalex.org/keywords/product","display_name":"Product (mathematics)","score":0.4125867784023285},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.24472454190254211},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.24463462829589844}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8109675645828247},{"id":"https://openalex.org/C2777826928","wikidata":"https://www.wikidata.org/wiki/Q3745713","display_name":"Fingerprint (computing)","level":2,"score":0.6917054057121277},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.6133611798286438},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5629913210868835},{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.5152354836463928},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.501331090927124},{"id":"https://openalex.org/C2778223634","wikidata":"https://www.wikidata.org/wiki/Q224952","display_name":"Suspect","level":2,"score":0.46481236815452576},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.456603080034256},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.44852039217948914},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4472426772117615},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.44383442401885986},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.4251856207847595},{"id":"https://openalex.org/C90673727","wikidata":"https://www.wikidata.org/wiki/Q901718","display_name":"Product (mathematics)","level":2,"score":0.4125867784023285},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.24472454190254211},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.24463462829589844},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2022.3155921","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3155921","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2077566469","display_name":null,"funder_award_id":"61872416","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2616141538","display_name":null,"funder_award_id":"62002104","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2656589067","display_name":null,"funder_award_id":"62071192","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7481879049","display_name":null,"funder_award_id":"62171189","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G781080216","display_name":null,"funder_award_id":"2019kfyXJJS017","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320334202","display_name":"Wuhan Yellow Crane Talents Program","ror":null},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":56,"referenced_works":["https://openalex.org/W1873763122","https://openalex.org/W2051267297","https://openalex.org/W2473418344","https://openalex.org/W2535690855","https://openalex.org/W2573551535","https://openalex.org/W2579318729","https://openalex.org/W2768064608","https://openalex.org/W2795435272","https://openalex.org/W2806082141","https://openalex.org/W2890595448","https://openalex.org/W2899585792","https://openalex.org/W2904945771","https://openalex.org/W2909703150","https://openalex.org/W2911978475","https://openalex.org/W2923599618","https://openalex.org/W2930926105","https://openalex.org/W2935349488","https://openalex.org/W2948030332","https://openalex.org/W2952608669","https://openalex.org/W2963122862","https://openalex.org/W2963378725","https://openalex.org/W2963456518","https://openalex.org/W2964252706","https://openalex.org/W2970408908","https://openalex.org/W2981446616","https://openalex.org/W2990980946","https://openalex.org/W3002731020","https://openalex.org/W3013682536","https://openalex.org/W3023153742","https://openalex.org/W3034256900","https://openalex.org/W3091877649","https://openalex.org/W3094821564","https://openalex.org/W3102733833","https://openalex.org/W3103245149","https://openalex.org/W3135872251","https://openalex.org/W3138758728","https://openalex.org/W3138815606","https://openalex.org/W3155296704","https://openalex.org/W3159754263","https://openalex.org/W3163966458","https://openalex.org/W3164111940","https://openalex.org/W3173531806","https://openalex.org/W3179479348","https://openalex.org/W3180608480","https://openalex.org/W3181414820","https://openalex.org/W3214437258","https://openalex.org/W3216556018","https://openalex.org/W6758359881","https://openalex.org/W6763736615","https://openalex.org/W6772947036","https://openalex.org/W6774150056","https://openalex.org/W6781511523","https://openalex.org/W6788876066","https://openalex.org/W6790534320","https://openalex.org/W6790544463","https://openalex.org/W6804372167"],"related_works":["https://openalex.org/W3197016913","https://openalex.org/W2389153751","https://openalex.org/W4386728183","https://openalex.org/W2185015567","https://openalex.org/W2394191954","https://openalex.org/W2113933481","https://openalex.org/W4292622136","https://openalex.org/W2559305818","https://openalex.org/W4285322112","https://openalex.org/W4292794239"],"abstract_inverted_index":{"In":[0,53],"recent":[1],"years,":[2],"data":[3,22,47,65,90,101,125,132,263],"has":[4,102,150],"become":[5],"the":[6,18,40,45,85,107,127,130,140,145,161,176,191,194,202,207,221,228,232,247,261],"new":[7],"oil":[8,19],"that":[9,97,253],"fuels":[10],"various":[11],"machine":[12],"learning":[13],"(ML)":[14],"applications.":[15],"Just":[16],"as":[17,126,216],"refining,":[20],"providing":[21],"to":[23,38,75,86,122,138,190,219,258],"an":[24,135],"ML":[25,49,80,112,224,244],"model":[26,81,137,163],"is":[27,73,82,96,255,264],"a":[28,59,78,98,103,180,210,217],"product":[29],"of":[30,44,100,110,129,160,179,201,206,223,231,243,249],"massive":[31],"costs":[32],"and":[33,133,183,240,251],"expertise":[34],"efforts.":[35],"However,":[36],"how":[37],"protect":[39],"intellectual":[41],"property":[42,205],"(IP)":[43],"training":[46,64,195,229,262],"in":[48],"remains":[50],"largely":[51],"open.":[52],"this":[54,115],"paper,":[55],"we":[56,172],"present":[57],"MeFA,":[58,250],"novel":[60],"framework":[61],"for":[62,165],"detecting":[63],"IP":[66],"embezzlement":[67],"via":[68],"Membership":[69],"Fingerprint":[70],"Authentication,":[71],"which":[72,171],"able":[74],"determine":[76],"whether":[77],"suspect":[79,162],"trained":[83],"on":[84,106,236],"be":[87],"protected":[88],"target":[89,131],"or":[91,193,267],"not.":[92],"The":[93],"key":[94],"observation":[95],"part":[99],"similar":[104],"influence":[105],"prediction":[108,168,177],"behavior":[109],"different":[111],"models.":[113],"On":[114],"basis,":[116],"MeFA":[117,149,212],"leverages":[118],"membership":[119,147,204,271],"inference":[120,272],"techniques":[121],"extract":[123],"these":[124],"fingerprints":[128],"constructs":[134],"authentication":[136],"verify":[139,220],"data\u2019s":[141],"ownership":[142,222],"by":[143],"identifying":[144],"obtained":[146],"fingerprints.":[148],"several":[151],"salient":[152],"features.":[153],"It":[154],"does":[155,185],"not":[156,186],"assume":[157],"any":[158,188],"knowledge":[159],"except":[164],"its":[166],"black-box":[167],"API,":[169],"through":[170],"can":[173,213],"merely":[174],"get":[175],"output":[178],"given":[181],"input,":[182],"also":[184,214,256],"require":[187],"modification":[189],"dataset":[192],"process,":[196],"since":[197],"it":[198,254],"takes":[199],"advantage":[200],"inherent":[203],"data.":[208],"As":[209],"by-product,":[211],"serve":[215],"post-protection":[218],"models,":[225],"without":[226],"modifying":[227],"process":[230],"model.":[233],"Extensive":[234],"experiments":[235],"three":[237],"realistic":[238],"datasets":[239],"seven":[241],"types":[242],"models":[245],"validate":[246],"effectiveness":[248],"demonstrate":[252],"robust":[257],"scenarios":[259],"when":[260],"partially":[265],"used":[266],"preprocessed":[268],"with":[269],"representative":[270],"defenses.":[273]},"counts_by_year":[{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":1}],"updated_date":"2026-03-17T09:09:15.849793","created_date":"2025-10-10T00:00:00"}
