{"id":"https://openalex.org/W4409149357","doi":"https://doi.org/10.1145/3690624.3709332","title":"Adaptive Domain Inference Attack with Concept Hierarchy","display_name":"Adaptive Domain Inference Attack with Concept Hierarchy","publication_year":2025,"publication_date":"2025-04-04","ids":{"openalex":"https://openalex.org/W4409149357","doi":"https://doi.org/10.1145/3690624.3709332"},"language":"en","primary_location":{"id":"doi:10.1145/3690624.3709332","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3690624.3709332","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3690624.3709332","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5009417833","display_name":"Yuechun Gu","orcid":null},"institutions":[{"id":"https://openalex.org/I79272384","display_name":"University of Maryland, Baltimore County","ror":"https://ror.org/02qskvh78","country_code":"US","type":"education","lineage":["https://openalex.org/I79272384"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Yuechun Gu","raw_affiliation_strings":["Trustworthy and Intelligent Computing Lab (TAIC), Computer Science and Electrical Engineering, University of Maryland, Baltimore County, Baltimore, Marryland, USA"],"affiliations":[{"raw_affiliation_string":"Trustworthy and Intelligent Computing Lab (TAIC), Computer Science and Electrical Engineering, University of Maryland, Baltimore County, Baltimore, Marryland, USA","institution_ids":["https://openalex.org/I79272384"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101279640","display_name":"Jiajie He","orcid":null},"institutions":[{"id":"https://openalex.org/I79272384","display_name":"University of Maryland, Baltimore County","ror":"https://ror.org/02qskvh78","country_code":"US","type":"education","lineage":["https://openalex.org/I79272384"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jiajie He","raw_affiliation_strings":["Trustworthy and Intelligent Computing Lab (TAIC), Computer Science and Electrical Engineering, University of Maryland, Baltimore County, Baltimore, Maryland, USA"],"affiliations":[{"raw_affiliation_string":"Trustworthy and Intelligent Computing Lab (TAIC), Computer Science and Electrical Engineering, University of Maryland, Baltimore County, Baltimore, Maryland, USA","institution_ids":["https://openalex.org/I79272384"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5002572745","display_name":"Keke Chen","orcid":"https://orcid.org/0000-0002-9996-156X"},"institutions":[{"id":"https://openalex.org/I79272384","display_name":"University of Maryland, Baltimore County","ror":"https://ror.org/02qskvh78","country_code":"US","type":"education","lineage":["https://openalex.org/I79272384"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Keke Chen","raw_affiliation_strings":["Trustworthy and Intelligent Computing Lab (TAIC), Computer Science and Electrical Engineering, University of Maryland, Baltimore County, Baltimore, Maryland, USA"],"affiliations":[{"raw_affiliation_string":"Trustworthy and Intelligent Computing Lab (TAIC), Computer Science and Electrical Engineering, University of Maryland, Baltimore County, Baltimore, Maryland, USA","institution_ids":["https://openalex.org/I79272384"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5009417833"],"corresponding_institution_ids":["https://openalex.org/I79272384"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.06164595,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"413","last_page":"424"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9973000288009644,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9973000288009644,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9958000183105469,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12761","display_name":"Data Stream Mining Techniques","score":0.9937999844551086,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7481037974357605},{"id":"https://openalex.org/keywords/hierarchy","display_name":"Hierarchy","score":0.6532416343688965},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6245639324188232},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.5029317736625671},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.35070082545280457},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3474207818508148},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.1447489857673645}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7481037974357605},{"id":"https://openalex.org/C31170391","wikidata":"https://www.wikidata.org/wiki/Q188619","display_name":"Hierarchy","level":2,"score":0.6532416343688965},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6245639324188232},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.5029317736625671},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.35070082545280457},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3474207818508148},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.1447489857673645},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C34447519","wikidata":"https://www.wikidata.org/wiki/Q179522","display_name":"Market economy","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3690624.3709332","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3690624.3709332","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1","raw_type":"proceedings-article"},{"id":"pmh:doi:10.13016/m2sxuc-qtvo","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3690624.3709332.","pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Text"}],"best_oa_location":{"id":"doi:10.1145/3690624.3709332","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3690624.3709332","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":29,"referenced_works":["https://openalex.org/W1526236503","https://openalex.org/W2007339694","https://openalex.org/W2051267297","https://openalex.org/W2108598243","https://openalex.org/W2194775991","https://openalex.org/W2310347995","https://openalex.org/W2471768434","https://openalex.org/W2535690855","https://openalex.org/W2550447077","https://openalex.org/W2605449204","https://openalex.org/W2750384547","https://openalex.org/W2798334860","https://openalex.org/W2897830718","https://openalex.org/W3005343217","https://openalex.org/W3035616549","https://openalex.org/W3040473534","https://openalex.org/W3048051147","https://openalex.org/W3109161889","https://openalex.org/W3118635493","https://openalex.org/W3131760363","https://openalex.org/W3133843004","https://openalex.org/W3138815606","https://openalex.org/W4200561106","https://openalex.org/W4229936741","https://openalex.org/W4287869765","https://openalex.org/W4288057780","https://openalex.org/W4382318179","https://openalex.org/W4385269969","https://openalex.org/W4386075570"],"related_works":["https://openalex.org/W2365264209","https://openalex.org/W962203960","https://openalex.org/W2026999166","https://openalex.org/W1996802783","https://openalex.org/W2509431957","https://openalex.org/W4211007821","https://openalex.org/W2802395037","https://openalex.org/W4389565704","https://openalex.org/W1976216854","https://openalex.org/W3207031006"],"abstract_inverted_index":{"With":[0],"increasingly":[1],"deployed":[2],"deep":[3],"neural":[4],"networks":[5],"in":[6,155,160],"sensitive":[7,22],"application":[8,39],"domains,":[9],"such":[10],"as":[11,77],"healthcare":[12],"and":[13,87,134,142,193],"security,":[14],"it's":[15],"essential":[16],"to":[17,45,147],"understand":[18],"what":[19],"kind":[20],"of":[21,85,102,119,152],"information":[23,53],"can":[24,96,112,140],"be":[25],"inferred":[26],"from":[27,54,59,131],"these":[28,60],"models.":[29],"Most":[30],"known":[31],"model-targeted":[32],"attacks":[33],"assume":[34],"attackers":[35],"have":[36],"learned":[37],"the":[38,51,75,83,89,108,117,123,127,132,138,150,156,161,186,195],"domain":[40,52,92],"or":[41],"training":[42,103,163,183],"data":[43,111,184],"distribution":[44],"ensure":[46],"successful":[47],"attacks.":[48,121],"Can":[49],"removing":[50],"model":[55,76],"APIs":[56],"protect":[57],"models":[58],"attacks?":[61],"This":[62],"paper":[63],"studies":[64],"this":[65],"critical":[66],"problem.":[67],"Unfortunately,":[68],"even":[69],"with":[70],"minimal":[71],"knowledge,":[72],"i.e.,":[73],"accessing":[74],"an":[78],"unnamed":[79],"function":[80],"without":[81],"leaking":[82],"meaning":[84],"input":[86],"output,":[88],"proposed":[90],"adaptive":[91],"inference":[93],"attack":[94,173,178],"(ADI)":[95],"still":[97],"successfully":[98],"estimate":[99],"relevant":[100,110],"subsets":[101],"data.":[104,164],"We":[105],"show":[106],"that":[107,137],"extracted":[109,130],"significantly":[113],"improve,":[114],"for":[115],"instance,":[116],"performance":[118],"model-inversion":[120],"Specifically,":[122],"ADI":[124,177],"method":[125],"utilizes":[126],"concept":[128,187],"hierarchy":[129,157],"public":[133],"private":[135],"datasets":[136],"attacker":[139],"access":[141],"applies":[143],"a":[144,170],"novel":[145],"algorithm":[146],"adaptively":[148],"tune":[149],"likelihood":[151],"leaf":[153],"concepts":[154],"showing":[158],"up":[159],"unseen":[162],"For":[165],"comparison,":[166],"we":[167],"also":[168,190],"designed":[169],"straightforward":[171],"hypothesis-testing-based":[172],"--":[174],"LDI.":[175],"The":[176],"not":[179],"only":[180],"extracts":[181],"partial":[182],"at":[185,207],"level":[188],"but":[189],"converges":[191],"fastest":[192],"requires":[194],"fewest":[196],"target-model":[197],"accesses":[198],"among":[199],"all":[200],"candidate":[201],"methods.":[202],"Our":[203],"code":[204],"is":[205],"available":[206],"https://anonymous.4open.science/r/KDD-362D.":[208]},"counts_by_year":[],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
