{"id":"https://openalex.org/W2897830718","doi":"https://doi.org/10.1145/3243734.3243834","title":"Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant Representations","display_name":"Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant Representations","publication_year":2018,"publication_date":"2018-10-15","ids":{"openalex":"https://openalex.org/W2897830718","doi":"https://doi.org/10.1145/3243734.3243834","mag":"2897830718"},"language":"en","primary_location":{"id":"doi:10.1145/3243734.3243834","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3243734.3243834","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3243734.3243834","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3243734.3243834","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5066827571","display_name":"Karan Ganju","orcid":null},"institutions":[{"id":"https://openalex.org/I157725225","display_name":"University of Illinois Urbana-Champaign","ror":"https://ror.org/047426m28","country_code":"US","type":"education","lineage":["https://openalex.org/I157725225"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Karan Ganju","raw_affiliation_strings":["University of Illinois at Urbana-Champaign, Urbana, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Illinois at Urbana-Champaign, Urbana, IL, USA","institution_ids":["https://openalex.org/I157725225"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100341321","display_name":"Qi Wang","orcid":"https://orcid.org/0000-0002-7028-4956"},"institutions":[{"id":"https://openalex.org/I157725225","display_name":"University of Illinois Urbana-Champaign","ror":"https://ror.org/047426m28","country_code":"US","type":"education","lineage":["https://openalex.org/I157725225"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Qi Wang","raw_affiliation_strings":["University of Illinois at Urbana-Champaign, Urbana, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Illinois at Urbana-Champaign, Urbana, IL, USA","institution_ids":["https://openalex.org/I157725225"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100613522","display_name":"Wei Yang","orcid":"https://orcid.org/0000-0001-8460-3121"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wei Yang","raw_affiliation_strings":["University of Texas at Dallas, Dallas, TX, USA"],"affiliations":[{"raw_affiliation_string":"University of Texas at Dallas, Dallas, TX, USA","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031954035","display_name":"Carl A. Gunter","orcid":"https://orcid.org/0009-0006-6943-0684"},"institutions":[{"id":"https://openalex.org/I157725225","display_name":"University of Illinois Urbana-Champaign","ror":"https://ror.org/047426m28","country_code":"US","type":"education","lineage":["https://openalex.org/I157725225"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Carl A. Gunter","raw_affiliation_strings":["University of Illinois at Urbana-Champaign, Urbana, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Illinois at Urbana-Champaign, Urbana, IL, USA","institution_ids":["https://openalex.org/I157725225"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5024942018","display_name":"Nikita Borisov","orcid":"https://orcid.org/0000-0002-7769-4931"},"institutions":[{"id":"https://openalex.org/I157725225","display_name":"University of Illinois Urbana-Champaign","ror":"https://ror.org/047426m28","country_code":"US","type":"education","lineage":["https://openalex.org/I157725225"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nikita Borisov","raw_affiliation_strings":["University of Illinois at Urbana-Champaign, Urbana, IL, USA"],"affiliations":[{"raw_affiliation_string":"University of Illinois at Urbana-Champaign, Urbana, IL, USA","institution_ids":["https://openalex.org/I157725225"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5066827571"],"corresponding_institution_ids":["https://openalex.org/I157725225"],"apc_list":null,"apc_paid":null,"fwci":24.7089,"has_fulltext":true,"cited_by_count":446,"citation_normalized_percentile":{"value":0.99538727,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"619","last_page":"633"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11612","display_name":"Stochastic Gradient Optimization Techniques","score":0.9954000115394592,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7841602563858032},{"id":"https://openalex.org/keywords/classifier","display_name":"Classifier (UML)","score":0.6720383167266846},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5830579996109009},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5706035494804382},{"id":"https://openalex.org/keywords/invariant","display_name":"Invariant (physics)","score":0.5354414582252502},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.531672477722168},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4875189960002899},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.455200731754303},{"id":"https://openalex.org/keywords/permutation","display_name":"Permutation (music)","score":0.44831612706184387},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3382190465927124},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.11098712682723999}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7841602563858032},{"id":"https://openalex.org/C95623464","wikidata":"https://www.wikidata.org/wiki/Q1096149","display_name":"Classifier (UML)","level":2,"score":0.6720383167266846},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5830579996109009},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5706035494804382},{"id":"https://openalex.org/C190470478","wikidata":"https://www.wikidata.org/wiki/Q2370229","display_name":"Invariant (physics)","level":2,"score":0.5354414582252502},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.531672477722168},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4875189960002899},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.455200731754303},{"id":"https://openalex.org/C21308566","wikidata":"https://www.wikidata.org/wiki/Q7169365","display_name":"Permutation (music)","level":2,"score":0.44831612706184387},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3382190465927124},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.11098712682723999},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C37914503","wikidata":"https://www.wikidata.org/wiki/Q156495","display_name":"Mathematical physics","level":1,"score":0.0},{"id":"https://openalex.org/C24890656","wikidata":"https://www.wikidata.org/wiki/Q82811","display_name":"Acoustics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3243734.3243834","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3243734.3243834","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3243734.3243834","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3243734.3243834","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3243734.3243834","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3243734.3243834","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G4025903539","display_name":null,"funder_award_id":"DE-OE0000780","funder_id":"https://openalex.org/F4320337674","funder_display_name":"Wind Energy Technologies Office"},{"id":"https://openalex.org/G8458631977","display_name":null,"funder_award_id":"CNS 13-30491","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320306084","display_name":"U.S. Department of Energy","ror":"https://ror.org/01bj3aw27"},{"id":"https://openalex.org/F4320337674","display_name":"Wind Energy Technologies Office","ror":null}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2897830718.pdf","grobid_xml":"https://content.openalex.org/works/W2897830718.grobid-xml"},"referenced_works_count":38,"referenced_works":["https://openalex.org/W1473189865","https://openalex.org/W1994616650","https://openalex.org/W2040870580","https://openalex.org/W2051267297","https://openalex.org/W2071289869","https://openalex.org/W2080592089","https://openalex.org/W2096733369","https://openalex.org/W2132862423","https://openalex.org/W2145287260","https://openalex.org/W2166844173","https://openalex.org/W2243397390","https://openalex.org/W2273440736","https://openalex.org/W2350778671","https://openalex.org/W2461943168","https://openalex.org/W2473418344","https://openalex.org/W2504609973","https://openalex.org/W2522718524","https://openalex.org/W2535690855","https://openalex.org/W2543927648","https://openalex.org/W2603766943","https://openalex.org/W2607255160","https://openalex.org/W2618098489","https://openalex.org/W2741933435","https://openalex.org/W2747329762","https://openalex.org/W2753783305","https://openalex.org/W2753798143","https://openalex.org/W2753840555","https://openalex.org/W2757528734","https://openalex.org/W2763172007","https://openalex.org/W2787698406","https://openalex.org/W2788481061","https://openalex.org/W2883613460","https://openalex.org/W2951055356","https://openalex.org/W2962835266","https://openalex.org/W3007346474","https://openalex.org/W3088268709","https://openalex.org/W3099206234","https://openalex.org/W3137695714"],"related_works":["https://openalex.org/W2055243143","https://openalex.org/W2594778474","https://openalex.org/W2944183083","https://openalex.org/W1986418932","https://openalex.org/W2357796999","https://openalex.org/W4321636575","https://openalex.org/W2741131631","https://openalex.org/W2045526782","https://openalex.org/W3104453097","https://openalex.org/W2156919374"],"abstract_inverted_index":{"With":[0],"the":[1,18,21,33,41,44,58,64,69,73,78,81,119,161,196,202,219,223,230,251,263],"growing":[2],"adoption":[3],"of":[4,8,40,60,63,80,99,110,144,198,222],"machine":[5],"learning,":[6],"sharing":[7],"learned":[9],"models":[10],"is":[11,28],"becoming":[12],"popular.":[13],"However,":[14],"in":[15,71,146,225],"addition":[16],"to":[17,25,50,91,194],"prediction":[19],"properties":[20,39,62],"model":[22,34,45],"producer":[23,46],"aims":[24],"share,":[26],"there":[27],"also":[29,189,215,246],"a":[30,86,106,209,237],"risk":[31,109],"that":[32,83,132,138,155,178,208,211,236,239,259],"consumer":[35],"can":[36],"infer":[37],"other":[38],"training":[42,65,116,227],"data":[43,74,82,186],"did":[47],"not":[48],"intend":[49],"share.":[51],"In":[52,201,229],"this":[53,122,126,134,157],"paper,":[54],"we":[55,206,234],"focus":[56],"on":[57,169,255],"inference":[59],"global":[61],"data,":[66],"such":[67],"as":[68,89],"environment":[70],"which":[72],"was":[75,253],"produced,":[76],"or":[77],"fraction":[79],"comes":[84],"from":[85,243,257],"certain":[87],"class,":[88],"applied":[90],"white-box":[92],"Fully":[93],"Connected":[94],"Neural":[95],"Networks":[96],"(FCNNs).":[97],"Because":[98],"their":[100,115],"complexity":[101,123,135],"and":[102,159,172,176,265],"inscrutability,":[103],"FCNNs":[104,139],"have":[105],"particularly":[107],"high":[108],"leaking":[111],"unexpected":[112],"information":[113,127,162,217,248],"about":[114,218,249],"sets;":[117],"at":[118,183],"same":[120],"time,":[121],"makes":[124],"extracting":[125],"challenging.":[128],"We":[129,149,165,188],"develop":[130,150],"techniques":[131,152,168],"reduce":[133],"by":[136],"noting":[137],"are":[140,180],"invariant":[141],"under":[142],"permutation":[143],"nodes":[145],"each":[147],"layer.":[148],"our":[151,167,199],"using":[153],"representations":[154],"capture":[156],"invariance":[158],"simplify":[160],"extraction":[163],"task.":[164],"evaluate":[166],"several":[170],"synthetic":[171],"standard":[173],"benchmark":[174],"datasets":[175],"show":[177,207,235],"they":[179],"very":[181],"effective":[182],"inferring":[184],"various":[185],"properties.":[187],"perform":[190],"two":[191],"case":[192,204,232],"studies":[193],"demonstrate":[195],"impact":[197],"attack.":[200],"first":[203],"study":[205,233],"classifier":[210,238,252],"recognizes":[212,240],"smiling":[213],"faces":[214],"leaks":[216,247],"relative":[220],"attractiveness":[221],"individuals":[224],"its":[226],"set.":[228],"second":[231],"Bitcoin":[241],"mining":[242],"performance":[244],"counters":[245],"whether":[250],"trained":[254],"logs":[256],"machines":[258],"were":[260],"patched":[261],"for":[262],"Meltdown":[264],"Spectre":[266],"attacks.":[267]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":50},{"year":2024,"cited_by_count":82},{"year":2023,"cited_by_count":94},{"year":2022,"cited_by_count":71},{"year":2021,"cited_by_count":78},{"year":2020,"cited_by_count":44},{"year":2019,"cited_by_count":21},{"year":2018,"cited_by_count":3}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
