{"id":"https://openalex.org/W4411203640","doi":"https://doi.org/10.1109/tifs.2025.3578931","title":"On the Impact of Uncertainty and Calibration on Likelihood-Ratio Membership Inference Attacks","display_name":"On the Impact of Uncertainty and Calibration on Likelihood-Ratio Membership Inference Attacks","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4411203640","doi":"https://doi.org/10.1109/tifs.2025.3578931"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2025.3578931","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3578931","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5072881181","display_name":"Meiyi Zhu","orcid":"https://orcid.org/0000-0001-9695-6880"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Meiyi Zhu","raw_affiliation_strings":["Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-9695-6880","affiliations":[{"raw_affiliation_string":"Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058648594","display_name":"Caili Guo","orcid":"https://orcid.org/0000-0001-8892-4520"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Caili Guo","raw_affiliation_strings":["Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-8892-4520","affiliations":[{"raw_affiliation_string":"Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5050046664","display_name":"Chunyan Feng","orcid":"https://orcid.org/0000-0002-4277-6857"},"institutions":[{"id":"https://openalex.org/I139759216","display_name":"Beijing University of Posts and Telecommunications","ror":"https://ror.org/04w9fbh59","country_code":"CN","type":"education","lineage":["https://openalex.org/I139759216"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chunyan Feng","raw_affiliation_strings":["Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0002-4277-6857","affiliations":[{"raw_affiliation_string":"Beijing Key Laboratory of Network System Architecture and Convergence, School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China","institution_ids":["https://openalex.org/I139759216"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5017736224","display_name":"Osvaldo Simeone","orcid":"https://orcid.org/0000-0001-9898-3209"},"institutions":[{"id":"https://openalex.org/I183935753","display_name":"King's College London","ror":"https://ror.org/0220mzb33","country_code":"GB","type":"education","lineage":["https://openalex.org/I124357947","https://openalex.org/I183935753"]},{"id":"https://openalex.org/I4210119896","display_name":"King's College School","ror":"https://ror.org/02bbqcn27","country_code":"GB","type":"education","lineage":["https://openalex.org/I4210119896"]}],"countries":["GB"],"is_corresponding":false,"raw_author_name":"Osvaldo Simeone","raw_affiliation_strings":["Department of Engineering, King&#x2019;s Communications, Learning and Information Processing (KCLIP) Laboratory, King&#x2019;s College London, London, U.K"],"raw_orcid":"https://orcid.org/0000-0001-9898-3209","affiliations":[{"raw_affiliation_string":"Department of Engineering, King&#x2019;s Communications, Learning and Information Processing (KCLIP) Laboratory, King&#x2019;s College London, London, U.K","institution_ids":["https://openalex.org/I4210119896","https://openalex.org/I183935753"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5072881181"],"corresponding_institution_ids":["https://openalex.org/I139759216"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.06121365,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"20","issue":null,"first_page":"6292","last_page":"6307"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9926000237464905,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7122726440429688},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.679816484451294},{"id":"https://openalex.org/keywords/calibration","display_name":"Calibration","score":0.6406518220901489},{"id":"https://openalex.org/keywords/likelihood-ratio-test","display_name":"Likelihood-ratio test","score":0.44552081823349},{"id":"https://openalex.org/keywords/econometrics","display_name":"Econometrics","score":0.3645252585411072},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3574133515357971},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3554665446281433},{"id":"https://openalex.org/keywords/statistics","display_name":"Statistics","score":0.34211379289627075},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.15434938669204712}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7122726440429688},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.679816484451294},{"id":"https://openalex.org/C165838908","wikidata":"https://www.wikidata.org/wiki/Q736777","display_name":"Calibration","level":2,"score":0.6406518220901489},{"id":"https://openalex.org/C9483764","wikidata":"https://www.wikidata.org/wiki/Q585740","display_name":"Likelihood-ratio test","level":2,"score":0.44552081823349},{"id":"https://openalex.org/C149782125","wikidata":"https://www.wikidata.org/wiki/Q160039","display_name":"Econometrics","level":1,"score":0.3645252585411072},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3574133515357971},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3554665446281433},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.34211379289627075},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.15434938669204712}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2025.3578931","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3578931","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2914057848","display_name":null,"funder_award_id":"2021XD-A01-1","funder_id":"https://openalex.org/F4320335787","funder_display_name":"Fundamental Research Funds for the Central Universities"},{"id":"https://openalex.org/G5448899510","display_name":null,"funder_award_id":"62371070","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335787","display_name":"Fundamental Research Funds for the Central Universities","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":65,"referenced_works":["https://openalex.org/W1553101044","https://openalex.org/W1565315670","https://openalex.org/W2000359198","https://openalex.org/W2027595342","https://openalex.org/W2065638573","https://openalex.org/W2487122920","https://openalex.org/W2535690855","https://openalex.org/W2786233556","https://openalex.org/W2795435272","https://openalex.org/W2884943453","https://openalex.org/W2912023992","https://openalex.org/W2963122862","https://openalex.org/W2963378725","https://openalex.org/W2963844355","https://openalex.org/W2983140679","https://openalex.org/W3014596384","https://openalex.org/W3045700442","https://openalex.org/W3111192549","https://openalex.org/W3130294315","https://openalex.org/W3134774296","https://openalex.org/W3150395569","https://openalex.org/W3162883552","https://openalex.org/W3188079459","https://openalex.org/W3214437258","https://openalex.org/W3214968384","https://openalex.org/W4212863985","https://openalex.org/W4212996651","https://openalex.org/W4236474156","https://openalex.org/W4285230500","https://openalex.org/W4287075774","https://openalex.org/W4287760010","https://openalex.org/W4287867418","https://openalex.org/W4288057780","https://openalex.org/W4292828881","https://openalex.org/W4293253127","https://openalex.org/W4308410483","https://openalex.org/W4308410741","https://openalex.org/W4381713069","https://openalex.org/W4382202942","https://openalex.org/W4384112166","https://openalex.org/W4387010331","https://openalex.org/W4387928556","https://openalex.org/W4387950911","https://openalex.org/W4391725330","https://openalex.org/W4401692036","https://openalex.org/W4410341587","https://openalex.org/W6739651123","https://openalex.org/W6747553010","https://openalex.org/W6752346538","https://openalex.org/W6763736615","https://openalex.org/W6773676928","https://openalex.org/W6775482175","https://openalex.org/W6779414803","https://openalex.org/W6781511523","https://openalex.org/W6790790599","https://openalex.org/W6794076919","https://openalex.org/W6798067434","https://openalex.org/W6842397358","https://openalex.org/W6853261327","https://openalex.org/W6853539036","https://openalex.org/W6853919943","https://openalex.org/W6857469753","https://openalex.org/W6858290023","https://openalex.org/W6864050950","https://openalex.org/W6967027720"],"related_works":["https://openalex.org/W2055243143","https://openalex.org/W1986418932","https://openalex.org/W2357796999","https://openalex.org/W4321636575","https://openalex.org/W2741131631","https://openalex.org/W2045526782","https://openalex.org/W2156919374","https://openalex.org/W1483472507","https://openalex.org/W1984019423","https://openalex.org/W4280588203"],"abstract_inverted_index":{"In":[0,33],"a":[1,22,30,79],"<italic":[2,42,61,73,87,112,126,150],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[3,43,62,74,88,113,127,151],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">membership":[4],"inference":[5],"attack</i>":[6,46],"(MIA),":[7],"an":[8,49,158,175],"attacker":[9,103],"exploits":[10],"the":[11,38,41,54,57,60,66,72,86,92,102,109,120,136,140,147,172,179,185,192,200,206],"overconfidence":[12],"exhibited":[13],"by":[14,78,146],"typical":[15],"machine":[16],"learning":[17],"models":[18],"to":[19,28,139],"determine":[20],"whether":[21],"specific":[23],"data":[24,68,82],"point":[25],"was":[26],"used":[27],"train":[29],"target":[31,93,110],"model.":[32,94],"this":[34],"paper,":[35],"we":[36],"analyze":[37],"performance":[39],"of":[40,56,59,71,85,91,174,181,187,194,208],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">likelihood":[44],"ratio":[45],"(LiRA)":[47],"within":[48],"information-theoretical":[50],"framework":[51],"that":[52,199],"allows":[53],"investigation":[55],"impact":[58,186],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">aleatoric":[63],"uncertainty</i>":[64,76],"in":[65,100,118,133,156,165],"true":[67,141],"generation":[69],"process,":[70],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">epistemic":[75],"caused":[77],"limited":[80],"training":[81],"set,":[83],"and":[84,149,189],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">calibration":[89],"level</i>":[90],"We":[95,168],"compare":[96],"three":[97],"different":[98],"settings,":[99],"which":[101,119,134,157],"receives":[104],"decreasingly":[105],"informative":[106],"feedback":[107],"from":[108],"model:":[111],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">confidence":[114],"vector</i>":[115],"(CV)":[116],"disclosure,":[117,132,155],"output":[121],"probability":[122,137],"vector":[123],"is":[124,143,162],"released;":[125],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">true":[128],"label":[129,142],"confidence</i>":[130],"(TLC)":[131],"only":[135],"assigned":[138],"made":[144],"available":[145],"model;":[148],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">decision":[152],"set</i>":[153],"(DS)":[154],"adaptive":[159],"prediction":[160],"set":[161],"produced":[163],"as":[164],"conformal":[166],"prediction.":[167],"derive":[169],"bounds":[170,203],"on":[171,191],"advantage":[173],"MIA":[176],"adversary":[177],"with":[178],"aim":[180],"offering":[182],"insights":[183],"into":[184],"uncertainty":[188],"calibration":[190],"effectiveness":[193,207],"MIAs.":[195,209],"Simulation":[196],"results":[197],"demonstrate":[198],"derived":[201],"analytical":[202],"predict":[204],"well":[205]},"counts_by_year":[],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
