{"id":"https://openalex.org/W4367047222","doi":"https://doi.org/10.1145/3543507.3583224","title":"NetGuard: Protecting Commercial Web APIs from Model Inversion Attacks using GAN-generated Fake Samples","display_name":"NetGuard: Protecting Commercial Web APIs from Model Inversion Attacks using GAN-generated Fake Samples","publication_year":2023,"publication_date":"2023-04-26","ids":{"openalex":"https://openalex.org/W4367047222","doi":"https://doi.org/10.1145/3543507.3583224"},"language":"en","primary_location":{"id":"doi:10.1145/3543507.3583224","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3543507.3583224","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2023","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5046712504","display_name":"Xueluan Gong","orcid":"https://orcid.org/0000-0003-2190-8117"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xueluan Gong","raw_affiliation_strings":["Wuhan University, China"],"affiliations":[{"raw_affiliation_string":"Wuhan University, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5054424294","display_name":"Ziyao Wang","orcid":"https://orcid.org/0000-0002-1394-9587"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ziyao Wang","raw_affiliation_strings":["Wuhan University, China"],"affiliations":[{"raw_affiliation_string":"Wuhan University, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015275781","display_name":"Yanjiao Chen","orcid":"https://orcid.org/0000-0002-1382-0679"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"education","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yanjiao Chen","raw_affiliation_strings":["Zhejiang University, China"],"affiliations":[{"raw_affiliation_string":"Zhejiang University, China","institution_ids":["https://openalex.org/I76130692"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100391116","display_name":"Qian Wang","orcid":"https://orcid.org/0000-0002-8967-8525"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"education","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qian Wang","raw_affiliation_strings":["Wuhan University, China"],"affiliations":[{"raw_affiliation_string":"Wuhan University, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100390514","display_name":"Cong Wang","orcid":"https://orcid.org/0000-0003-0547-315X"},"institutions":[{"id":"https://openalex.org/I168719708","display_name":"City University of Hong Kong","ror":"https://ror.org/03q8dnn23","country_code":"HK","type":"education","lineage":["https://openalex.org/I168719708"]}],"countries":["HK"],"is_corresponding":false,"raw_author_name":"Cong Wang","raw_affiliation_strings":["City University of Hong Kong, China"],"affiliations":[{"raw_affiliation_string":"City University of Hong Kong, China","institution_ids":["https://openalex.org/I168719708"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101843177","display_name":"Chao Shen","orcid":"https://orcid.org/0000-0003-2783-5529"},"institutions":[{"id":"https://openalex.org/I87445476","display_name":"Xi'an Jiaotong University","ror":"https://ror.org/017zhmm22","country_code":"CN","type":"education","lineage":["https://openalex.org/I87445476"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chao Shen","raw_affiliation_strings":["Xi'an Jiaotong University, China"],"affiliations":[{"raw_affiliation_string":"Xi'an Jiaotong University, China","institution_ids":["https://openalex.org/I87445476"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5046712504"],"corresponding_institution_ids":["https://openalex.org/I37461747"],"apc_list":null,"apc_paid":null,"fwci":0.6959,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.74606243,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"2045","last_page":"2053"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9847999811172485,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.983299970626831,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7778968811035156},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.6284928917884827},{"id":"https://openalex.org/keywords/cloud-computing","display_name":"Cloud computing","score":0.6262942552566528},{"id":"https://openalex.org/keywords/generative-adversarial-network","display_name":"Generative adversarial network","score":0.5270942449569702},{"id":"https://openalex.org/keywords/high-fidelity","display_name":"High fidelity","score":0.5125553607940674},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5041557550430298},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.46864503622055054},{"id":"https://openalex.org/keywords/fidelity","display_name":"Fidelity","score":0.43708354234695435},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4350036084651947},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3776249587535858},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.11295214295387268},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.09926137328147888}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7778968811035156},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.6284928917884827},{"id":"https://openalex.org/C79974875","wikidata":"https://www.wikidata.org/wiki/Q483639","display_name":"Cloud computing","level":2,"score":0.6262942552566528},{"id":"https://openalex.org/C2988773926","wikidata":"https://www.wikidata.org/wiki/Q25104379","display_name":"Generative adversarial network","level":3,"score":0.5270942449569702},{"id":"https://openalex.org/C113364801","wikidata":"https://www.wikidata.org/wiki/Q26674","display_name":"High fidelity","level":2,"score":0.5125553607940674},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5041557550430298},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.46864503622055054},{"id":"https://openalex.org/C2776459999","wikidata":"https://www.wikidata.org/wiki/Q2119376","display_name":"Fidelity","level":2,"score":0.43708354234695435},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4350036084651947},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3776249587535858},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.11295214295387268},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.09926137328147888},{"id":"https://openalex.org/C76155785","wikidata":"https://www.wikidata.org/wiki/Q418","display_name":"Telecommunications","level":1,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3543507.3583224","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3543507.3583224","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2023","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.800000011920929,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G2838469879","display_name":null,"funder_award_id":"61972296","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":23,"referenced_works":["https://openalex.org/W1834627138","https://openalex.org/W2051267297","https://openalex.org/W2325939864","https://openalex.org/W2350778671","https://openalex.org/W2473418344","https://openalex.org/W2560647685","https://openalex.org/W2795435272","https://openalex.org/W2884282566","https://openalex.org/W2946697723","https://openalex.org/W2962770929","https://openalex.org/W2963037989","https://openalex.org/W2963839617","https://openalex.org/W2985580374","https://openalex.org/W3010216907","https://openalex.org/W3030364939","https://openalex.org/W3034957837","https://openalex.org/W3035616549","https://openalex.org/W3091787298","https://openalex.org/W3177170788","https://openalex.org/W3197399603","https://openalex.org/W4214567027","https://openalex.org/W4226117300","https://openalex.org/W4285292458"],"related_works":["https://openalex.org/W4313443006","https://openalex.org/W2945374968","https://openalex.org/W4293777179","https://openalex.org/W4385452045","https://openalex.org/W2164070813","https://openalex.org/W2135608140","https://openalex.org/W2895525995","https://openalex.org/W2332512904","https://openalex.org/W4224231624","https://openalex.org/W2319626700"],"abstract_inverted_index":{"Recently":[0],"more":[1,3,70],"and":[2,10,66,164,178,193],"cloud":[4],"service":[5],"providers":[6],"(e.g.,":[7],"Microsoft,":[8],"Google,":[9],"Amazon)":[11],"have":[12],"commercialized":[13],"their":[14],"well-trained":[15],"deep":[16],"learning":[17,149],"models":[18],"by":[19,110],"providing":[20],"limited":[21],"access":[22],"via":[23],"web":[24],"API":[25],"interfaces.":[26],"However,":[27],"it":[28],"is":[29,124,170],"shown":[30],"that":[31,95,168],"these":[32],"APIs":[33],"are":[34,67],"susceptible":[35],"to":[36,105,127,132,150,172],"model":[37,58,64,88,136,183],"inversion":[38,59,89,184],"attacks,":[39,60,72,185],"where":[40],"attackers":[41],"can":[42],"recover":[43],"the":[44,63,100,107,116,134,139,142,153,156],"training":[45,117,130],"data":[46],"with":[47],"high":[48],"fidelity,":[49],"which":[50],"may":[51],"cause":[52],"serious":[53],"privacy":[54],"leakage.Existing":[55],"defenses":[56],"against":[57,87],"however,":[61],"hinder":[62],"performance":[65,140],"ineffective":[68],"for":[69],"advanced":[71],"e.g.,":[73],"Mirror":[74,189],"[4].":[75],"In":[76],"this":[77],"paper,":[78],"we":[79,103,146],"proposed":[80],"NetGuard,":[81],"a":[82],"novel":[83],"utility-aware":[84],"defense":[85],"methodology":[86],"attacks":[90],"(MIAs).":[91],"Unlike":[92],"previous":[93],"works":[94],"perturb":[96],"prediction":[97],"outputs":[98],"of":[99,141,155],"victim":[101,143,157],"model,":[102],"propose":[104],"mislead":[106,133],"MIA":[108],"effort":[109],"inserting":[111],"engineered":[112],"fake":[113,129],"samples":[114,131],"during":[115],"process.":[118],"A":[119],"generative":[120],"adversarial":[121],"network":[122],"(GAN)":[123],"carefully":[125],"built":[126],"construct":[128],"attack":[135],"without":[137],"degrading":[138],"model.":[144,158],"Besides,":[145],"adopt":[147],"continual":[148],"further":[151],"improve":[152],"utility":[154],"Extensive":[159],"experiments":[160],"on":[161,181],"CelebA,":[162],"VGG-Face,":[163],"VGG-Face2":[165],"datasets":[166],"show":[167],"NetGuard":[169],"superior":[171],"existing":[173],"defenses,":[174],"including":[175],"DP":[176],"[37]":[177],"Ad-mi":[179],"[32]":[180],"state-of-the-art":[182],"i.e.,":[186],"DMI":[187],"[8],":[188],"[4],":[190],"Privacy":[191],"[12],":[192],"Alignment":[194],"[34].":[195]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":2},{"year":2023,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
