{"id":"https://openalex.org/W3212600502","doi":"https://doi.org/10.1145/3460120.3484749","title":"EncoderMI: Membership Inference against Pre-trained Encoders in Contrastive Learning","display_name":"EncoderMI: Membership Inference against Pre-trained Encoders in Contrastive Learning","publication_year":2021,"publication_date":"2021-11-12","ids":{"openalex":"https://openalex.org/W3212600502","doi":"https://doi.org/10.1145/3460120.3484749","mag":"3212600502"},"language":"en","primary_location":{"id":"doi:10.1145/3460120.3484749","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3460120.3484749","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3460120.3484749","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3460120.3484749","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100408245","display_name":"Hongbin Liu","orcid":null},"institutions":[{"id":"https://openalex.org/I170897317","display_name":"Duke University","ror":"https://ror.org/00py81415","country_code":"US","type":"education","lineage":["https://openalex.org/I170897317"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Hongbin Liu","raw_affiliation_strings":["Duke University, Durham, NC, USA"],"affiliations":[{"raw_affiliation_string":"Duke University, Durham, NC, USA","institution_ids":["https://openalex.org/I170897317"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101997385","display_name":"Jinyuan Jia","orcid":"https://orcid.org/0000-0003-4452-1396"},"institutions":[{"id":"https://openalex.org/I170897317","display_name":"Duke University","ror":"https://ror.org/00py81415","country_code":"US","type":"education","lineage":["https://openalex.org/I170897317"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jinyuan Jia","raw_affiliation_strings":["Duke University, Durham, NC, USA"],"affiliations":[{"raw_affiliation_string":"Duke University, Durham, NC, USA","institution_ids":["https://openalex.org/I170897317"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109420698","display_name":"Wenjie Qu","orcid":"https://orcid.org/0009-0006-2907-008X"},"institutions":[{"id":"https://openalex.org/I47720641","display_name":"Huazhong University of Science and Technology","ror":"https://ror.org/00p991c53","country_code":"CN","type":"education","lineage":["https://openalex.org/I47720641"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenjie Qu","raw_affiliation_strings":["Huazhong University of Science and Technology, Wuhan, China"],"affiliations":[{"raw_affiliation_string":"Huazhong University of Science and Technology, Wuhan, China","institution_ids":["https://openalex.org/I47720641"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5009102659","display_name":"Neil Zhenqiang Gong","orcid":"https://orcid.org/0000-0002-9900-9309"},"institutions":[{"id":"https://openalex.org/I170897317","display_name":"Duke University","ror":"https://ror.org/00py81415","country_code":"US","type":"education","lineage":["https://openalex.org/I170897317"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Neil Zhenqiang Gong","raw_affiliation_strings":["Duke University, Durham, NC, USA"],"affiliations":[{"raw_affiliation_string":"Duke University, Durham, NC, USA","institution_ids":["https://openalex.org/I170897317"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5100408245"],"corresponding_institution_ids":["https://openalex.org/I170897317"],"apc_list":null,"apc_paid":null,"fwci":6.7081,"has_fulltext":true,"cited_by_count":63,"citation_normalized_percentile":{"value":0.97306461,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":93,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"2081","last_page":"2095"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9142000079154968,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/overfitting","display_name":"Overfitting","score":0.792941153049469},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7740582227706909},{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.7182283997535706},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6358113288879395},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5063494443893433},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.45950764417648315},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.42312559485435486},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.4172241687774658},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.4169679880142212},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.3586313724517822},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.16219913959503174}],"concepts":[{"id":"https://openalex.org/C22019652","wikidata":"https://www.wikidata.org/wiki/Q331309","display_name":"Overfitting","level":3,"score":0.792941153049469},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7740582227706909},{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.7182283997535706},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6358113288879395},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5063494443893433},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.45950764417648315},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.42312559485435486},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4172241687774658},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.4169679880142212},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.3586313724517822},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.16219913959503174},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3460120.3484749","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3460120.3484749","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3460120.3484749","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3460120.3484749","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3460120.3484749","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3460120.3484749","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.5600000023841858}],"awards":[{"id":"https://openalex.org/G6117838619","display_name":null,"funder_award_id":"1937786","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3212600502.pdf","grobid_xml":"https://content.openalex.org/works/W3212600502.grobid-xml"},"referenced_works_count":33,"referenced_works":["https://openalex.org/W1873763122","https://openalex.org/W2025768430","https://openalex.org/W2053801139","https://openalex.org/W2118858186","https://openalex.org/W2138621090","https://openalex.org/W2194775991","https://openalex.org/W2337093093","https://openalex.org/W2473418344","https://openalex.org/W2535690855","https://openalex.org/W2795435272","https://openalex.org/W2884943453","https://openalex.org/W2923095117","https://openalex.org/W2930926105","https://openalex.org/W2932329902","https://openalex.org/W2946363484","https://openalex.org/W2962835968","https://openalex.org/W2963844355","https://openalex.org/W2983140679","https://openalex.org/W3005680577","https://openalex.org/W3035009277","https://openalex.org/W3035524453","https://openalex.org/W3096738375","https://openalex.org/W3104224589","https://openalex.org/W3112689365","https://openalex.org/W3155551741","https://openalex.org/W3170901302","https://openalex.org/W3186482562","https://openalex.org/W3189812816","https://openalex.org/W3202500832","https://openalex.org/W3214437258","https://openalex.org/W4287391919","https://openalex.org/W4299301436","https://openalex.org/W4299337115"],"related_works":["https://openalex.org/W4362597605","https://openalex.org/W1574414179","https://openalex.org/W4297676672","https://openalex.org/W3009056573","https://openalex.org/W2922073769","https://openalex.org/W4281702477","https://openalex.org/W2490526372","https://openalex.org/W4376166922","https://openalex.org/W4378510483","https://openalex.org/W4221142204"],"abstract_inverted_index":{"Given":[0],"a":[1,23,54,83,216],"set":[2],"of":[3,73,110,123,152,235,239,249,258],"unlabeled":[4],"images":[5],"or":[6,102],"(image,":[7,190],"text)":[8,191],"pairs,":[9],"contrastive":[10,46],"learning":[11],"aims":[12,62],"to":[13,57,63,86,94,107,140],"pre-train":[14,95],"an":[15,51,58,96,105,133,153],"image":[16,42,59,75,97,125,135,166,182,241,266],"encoder":[17,98,126,136],"that":[18,204,229],"can":[19,78,206,245],"be":[20,79],"used":[21,80,93],"as":[22,174,176],"feature":[24,146],"extractor":[25],"for":[26,148],"many":[27],"downstream":[28,260],"tasks.":[29],"In":[30,48,131],"this":[31],"work,":[32],"we":[33],"propose":[34],"EncoderMI,":[35,250],"the":[36,66,70,74,111,121,124,177,195,240,247,259,265],"first":[37],"membership":[38],"inference":[39],"method":[40],"against":[41,218],"encoders":[43,167],"pre-trained":[44,168,186],"by":[45,82,104,172,199],"learning.":[47],"particular,":[49,132],"given":[50],"input":[52,67,154],"and":[53,197,211,237],"black-box":[55],"access":[56],"encoder,":[60,183,242],"EncoderMI":[61,77,119,164,205,219,236],"infer":[64],"whether":[65,88],"is":[68,116,137,185],"in":[69,155],"training":[71,112,129,160],"dataset":[72],"encoder.":[76,267],"1)":[81],"data":[84,91,113],"owner":[85],"audit":[87],"its":[89,100,128,159],"(public)":[90],"was":[92],"without":[99],"authorization":[101],"2)":[103],"attacker":[106],"compromise":[108],"privacy":[109],"when":[114],"it":[115,230,244,252],"private/sensitive.":[117],"Our":[118,201,226],"exploits":[120],"overfitting":[122,222],"towards":[127],"data.":[130],"overfitted":[134],"more":[138,142],"likely":[139],"output":[141],"(or":[143,156],"less)":[144],"similar":[145],"vectors":[147],"two":[149],"augmented":[150],"versions":[151],"not":[157],"in)":[158],"dataset.":[161],"We":[162,213],"evaluate":[163],"on":[165,169,187,264],"multiple":[170],"datasets":[171],"ourselves":[173],"well":[175],"Contrastive":[178],"Language-Image":[179],"Pre-training":[180],"(CLIP)":[181],"which":[184],"400":[188],"million":[189],"pairs":[192],"collected":[193],"from":[194],"Internet":[196],"released":[198],"OpenAI.":[200],"results":[202,227],"show":[203,228],"achieve":[207],"high":[208],"accuracy,":[209],"precision,":[210],"recall.":[212],"also":[214,253],"explore":[215],"countermeasure":[217],"via":[220],"preventing":[221],"through":[223],"early":[224],"stopping.":[225],"achieves":[231],"trade-offs":[232],"between":[233],"accuracy":[234,248,256],"utility":[238],"i.e.,":[243],"reduce":[246],"but":[251],"incurs":[254],"classification":[255],"loss":[257],"classifiers":[261],"built":[262],"based":[263]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":14},{"year":2024,"cited_by_count":20},{"year":2023,"cited_by_count":13},{"year":2022,"cited_by_count":13},{"year":2021,"cited_by_count":2}],"updated_date":"2026-03-17T09:09:15.849793","created_date":"2025-10-10T00:00:00"}
