{"id":"https://openalex.org/W4405181963","doi":"https://doi.org/10.1145/3658644.3690202","title":"A Unified Membership Inference Method for Visual Self-supervised Encoder via Part-aware Capability","display_name":"A Unified Membership Inference Method for Visual Self-supervised Encoder via Part-aware Capability","publication_year":2024,"publication_date":"2024-12-02","ids":{"openalex":"https://openalex.org/W4405181963","doi":"https://doi.org/10.1145/3658644.3690202"},"language":"en","primary_location":{"id":"doi:10.1145/3658644.3690202","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3658644.3690202","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3658644.3690202","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3658644.3690202","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101599150","display_name":"Jie Zhu","orcid":"https://orcid.org/0000-0003-3490-4131"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Jie Zhu","raw_affiliation_strings":["Key Lab of High Confidence Software Technologies (Peking University), Ministry of Education &amp; School of Computer Science, Peking University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Key Lab of High Confidence Software Technologies (Peking University), Ministry of Education &amp; School of Computer Science, Peking University, Beijing, China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5108014814","display_name":"Jirong Zha","orcid":"https://orcid.org/0009-0006-4824-6976"},"institutions":[{"id":"https://openalex.org/I4210114105","display_name":"Tsinghua\u2013Berkeley Shenzhen Institute","ror":"https://ror.org/02hhwwz98","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210114105","https://openalex.org/I95457486","https://openalex.org/I99065089"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jirong Zha","raw_affiliation_strings":["Tsinghua-Berkeley Shenzhen Institute, Tsinghua University, Shenzhen, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua-Berkeley Shenzhen Institute, Tsinghua University, Shenzhen, China","institution_ids":["https://openalex.org/I4210114105","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5039182822","display_name":"Ding Li","orcid":"https://orcid.org/0000-0001-7558-9137"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ding Li","raw_affiliation_strings":["Key Lab of High Confidence Software Technologies (Peking University), Ministry of Education &amp; School of Computer Science, Peking University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Key Lab of High Confidence Software Technologies (Peking University), Ministry of Education &amp; School of Computer Science, Peking University, Beijing, China","institution_ids":["https://openalex.org/I20231570"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5055087680","display_name":"Leye Wang","orcid":"https://orcid.org/0000-0002-7627-8485"},"institutions":[{"id":"https://openalex.org/I20231570","display_name":"Peking University","ror":"https://ror.org/02v51f717","country_code":"CN","type":"education","lineage":["https://openalex.org/I20231570"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Leye Wang","raw_affiliation_strings":["Key Lab of High Confidence Software Technologies (Peking University), Ministry of Education &amp; School of Computer Science, Peking University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Key Lab of High Confidence Software Technologies (Peking University), Ministry of Education &amp; School of Computer Science, Peking University, Beijing, China","institution_ids":["https://openalex.org/I20231570"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5101599150"],"corresponding_institution_ids":["https://openalex.org/I20231570"],"apc_list":null,"apc_paid":null,"fwci":1.3627,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.85012601,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"1241","last_page":"1255"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9984999895095825,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.989799976348877,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8146384954452515},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6875835061073303},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6336578130722046},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.6234525442123413},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.6206202507019043},{"id":"https://openalex.org/keywords/representation","display_name":"Representation (politics)","score":0.510852038860321},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.48739200830459595},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.47675830125808716},{"id":"https://openalex.org/keywords/supervised-learning","display_name":"Supervised learning","score":0.4648854434490204},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.4535534977912903},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.4517842233181},{"id":"https://openalex.org/keywords/encoder","display_name":"Encoder","score":0.4425085186958313},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.32893073558807373},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.1193457841873169}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8146384954452515},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6875835061073303},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6336578130722046},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.6234525442123413},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.6206202507019043},{"id":"https://openalex.org/C2776359362","wikidata":"https://www.wikidata.org/wiki/Q2145286","display_name":"Representation (politics)","level":3,"score":0.510852038860321},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.48739200830459595},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.47675830125808716},{"id":"https://openalex.org/C136389625","wikidata":"https://www.wikidata.org/wiki/Q334384","display_name":"Supervised learning","level":3,"score":0.4648854434490204},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.4535534977912903},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.4517842233181},{"id":"https://openalex.org/C118505674","wikidata":"https://www.wikidata.org/wiki/Q42586063","display_name":"Encoder","level":2,"score":0.4425085186958313},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.32893073558807373},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.1193457841873169},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.0},{"id":"https://openalex.org/C94625758","wikidata":"https://www.wikidata.org/wiki/Q7163","display_name":"Politics","level":2,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3658644.3690202","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3658644.3690202","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3658644.3690202","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3658644.3690202","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3658644.3690202","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3658644.3690202","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2525199997","display_name":null,"funder_award_id":"2022ZD0119103","funder_id":"https://openalex.org/F4320329860","funder_display_name":"National Science and Technology Major Project"}],"funders":[{"id":"https://openalex.org/F4320329860","display_name":"National Science and Technology Major Project","ror":null}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4405181963.pdf","grobid_xml":"https://content.openalex.org/works/W4405181963.grobid-xml"},"referenced_works_count":47,"referenced_works":["https://openalex.org/W1861492603","https://openalex.org/W2053801139","https://openalex.org/W2194775991","https://openalex.org/W2473418344","https://openalex.org/W2535690855","https://openalex.org/W2752929869","https://openalex.org/W2795435272","https://openalex.org/W2884943453","https://openalex.org/W2887995258","https://openalex.org/W2930926105","https://openalex.org/W2932329902","https://openalex.org/W2983140679","https://openalex.org/W3034318565","https://openalex.org/W3035524453","https://openalex.org/W3036224891","https://openalex.org/W3036982689","https://openalex.org/W3091473186","https://openalex.org/W3096609285","https://openalex.org/W3096738375","https://openalex.org/W3100859887","https://openalex.org/W3103245149","https://openalex.org/W3115042282","https://openalex.org/W3138815606","https://openalex.org/W3145450063","https://openalex.org/W3153405813","https://openalex.org/W3159481202","https://openalex.org/W3188079459","https://openalex.org/W3189551349","https://openalex.org/W3189812816","https://openalex.org/W3212600502","https://openalex.org/W4212774754","https://openalex.org/W4232172926","https://openalex.org/W4295362399","https://openalex.org/W4296564842","https://openalex.org/W4308391439","https://openalex.org/W4308643089","https://openalex.org/W4312768002","https://openalex.org/W4312804044","https://openalex.org/W4313156423","https://openalex.org/W4382460372","https://openalex.org/W4386065386","https://openalex.org/W4386066015","https://openalex.org/W4386076509","https://openalex.org/W4390874575","https://openalex.org/W6745136726","https://openalex.org/W6779630795","https://openalex.org/W6842301077"],"related_works":["https://openalex.org/W4388150944","https://openalex.org/W4242235492","https://openalex.org/W4237162029","https://openalex.org/W2367268135","https://openalex.org/W3162204513","https://openalex.org/W2385701518","https://openalex.org/W4237464767","https://openalex.org/W4390516098","https://openalex.org/W2371138613","https://openalex.org/W2068562251"],"abstract_inverted_index":{"Self-supervised":[0],"learning":[1],"shows":[2],"promise":[3],"in":[4,17,32,56,117,126],"harnessing":[5],"extensive":[6,131],"unlabeled":[7],"data,":[8],"but":[9],"it":[10],"also":[11],"confronts":[12],"significant":[13],"privacy":[14],"concerns,":[15],"especially":[16],"vision.":[18],"In":[19,58],"this":[20,59],"paper,":[21],"we":[22,84,162],"aim":[23],"to":[24,120,158],"perform":[25],"membership":[26,88],"inference":[27,89],"on":[28,107,133],"visual":[29],"self-supervised":[30,37,63,71,134],"models":[31,102,135],"a":[33,53,86,175],"more":[34],"realistic":[35],"setting:":[36],"training":[38,82,109,138],"method":[39,90,177],"and":[40,77,103,140,153,170,173],"details":[41],"are":[42,191],"unknown":[43],"for":[44],"an":[45,118],"adversary":[46],"when":[47],"attacking":[48],"as":[49],"he":[50],"usually":[51],"faces":[52],"black-box":[54],"system":[55],"practice.":[57],"setting,":[60],"considering":[61],"that":[62,187],"model":[64],"could":[65],"be":[66],"trained":[67],"by":[68,96],"completely":[69],"different":[70,137],"paradigms,":[72],"e.g.,":[73],"masked":[74],"image":[75,119,125,146],"modeling":[76],"contrastive":[78],"learning,":[79],"with":[80,123,136],"complex":[81],"details,":[83],"propose":[85,174],"unified":[87],"called":[91,178],"PartCrop.":[92,156],"It":[93],"is":[94,195],"motivated":[95],"the":[97,108,124,151],"shared":[98],"part-aware":[99],"capability":[100],"among":[101],"stronger":[104],"part":[105],"response":[106],"data.":[110],"Specifically,":[111],"PartCrop":[112],"crops":[113],"parts":[114],"of":[115,155,189],"objects":[116],"query":[121],"responses":[122],"representation":[127],"space.":[128],"We":[129],"conduct":[130],"attacks":[132],"protocols":[139],"structures":[141],"using":[142],"three":[143],"widely":[144],"used":[145],"datasets.":[147],"The":[148,183],"results":[149],"verify":[150],"effectiveness":[152],"generalization":[154],"Moreover,":[157],"defend":[159],"against":[160],"PartCrop,":[161],"evaluate":[163],"two":[164],"common":[165],"approaches,":[166],"i.e.,":[167],"early":[168],"stop":[169],"differential":[171],"privacy,":[172],"tailored":[176],"shrinking":[179],"crop":[180],"scale":[181],"range.":[182],"defense":[184],"experiments":[185],"indicate":[186],"all":[188],"them":[190],"effective.":[192],"Our":[193],"code":[194],"available":[196],"at":[197],"https://github.com/JiePKU/PartCrop.":[198]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":1}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
