{"id":"https://openalex.org/W4414193599","doi":"https://doi.org/10.1587/transinf.2024icp0005","title":"Quo Vadis Diffusion Model? A Case for Membership Inference Attacks","display_name":"Quo Vadis Diffusion Model? A Case for Membership Inference Attacks","publication_year":2025,"publication_date":"2025-09-15","ids":{"openalex":"https://openalex.org/W4414193599","doi":"https://doi.org/10.1587/transinf.2024icp0005"},"language":"en","primary_location":{"id":"doi:10.1587/transinf.2024icp0005","is_oa":true,"landing_page_url":"https://doi.org/10.1587/transinf.2024icp0005","pdf_url":"https://www.jstage.jst.go.jp/article/transinf/advpub/0/advpub_2024ICP0005/_pdf","source":{"id":"https://openalex.org/S2486202937","display_name":"IEICE Transactions on Information and Systems","issn_l":"0916-8532","issn":["0916-8532","1745-1361"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4320800604","host_organization_name":"Institute of Electronics, Information and Communication Engineers","host_organization_lineage":["https://openalex.org/P4320800604"],"host_organization_lineage_names":["Institute of Electronics, Information and Communication Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEICE Transactions on Information and Systems","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://www.jstage.jst.go.jp/article/transinf/advpub/0/advpub_2024ICP0005/_pdf","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5065918021","display_name":"Tomoya Matsumoto","orcid":"https://orcid.org/0000-0002-1570-2713"},"institutions":[{"id":"https://openalex.org/I98285908","display_name":"The University of Osaka","ror":"https://ror.org/035t8zc32","country_code":"JP","type":"education","lineage":["https://openalex.org/I98285908"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Tomoya MATSUMOTO","raw_affiliation_strings":["Graduate School of Information Science and Technology, Osaka University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graduate School of Information Science and Technology, Osaka University","institution_ids":["https://openalex.org/I98285908"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075912554","display_name":"Takayuki Miura","orcid":"https://orcid.org/0000-0003-1862-1254"},"institutions":[{"id":"https://openalex.org/I98285908","display_name":"The University of Osaka","ror":"https://ror.org/035t8zc32","country_code":"JP","type":"education","lineage":["https://openalex.org/I98285908"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Takayuki MIURA","raw_affiliation_strings":["Graduate School of Information Science and Technology, Osaka University","NTT Social Informatics Laboratories"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graduate School of Information Science and Technology, Osaka University","institution_ids":["https://openalex.org/I98285908"]},{"raw_affiliation_string":"NTT Social Informatics Laboratories","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5071395810","display_name":"Shingo Okamura","orcid":"https://orcid.org/0000-0001-5602-6494"},"institutions":[{"id":"https://openalex.org/I4210140361","display_name":"National Institute of Technology, Nara College","ror":"https://ror.org/034jd0m14","country_code":"JP","type":"education","lineage":["https://openalex.org/I4210120810","https://openalex.org/I4210140361"]},{"id":"https://openalex.org/I98285908","display_name":"The University of Osaka","ror":"https://ror.org/035t8zc32","country_code":"JP","type":"education","lineage":["https://openalex.org/I98285908"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Shingo OKAMURA","raw_affiliation_strings":["Graduate School of Information Science and Technology, Osaka University","National Institute of Technology, Nara College"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graduate School of Information Science and Technology, Osaka University","institution_ids":["https://openalex.org/I98285908"]},{"raw_affiliation_string":"National Institute of Technology, Nara College","institution_ids":["https://openalex.org/I4210140361"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5029096455","display_name":"Behrouz Zolfaghari","orcid":"https://orcid.org/0000-0001-6691-0988"},"institutions":[{"id":"https://openalex.org/I83328450","display_name":"Miami University","ror":"https://ror.org/05nbqxr67","country_code":"US","type":"education","lineage":["https://openalex.org/I83328450"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Behrouz ZOLFAGHARI","raw_affiliation_strings":["Miami University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Miami University","institution_ids":["https://openalex.org/I83328450"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5048334268","display_name":"Naoto Yanai","orcid":"https://orcid.org/0000-0002-0817-6188"},"institutions":[{"id":"https://openalex.org/I98285908","display_name":"The University of Osaka","ror":"https://ror.org/035t8zc32","country_code":"JP","type":"education","lineage":["https://openalex.org/I98285908"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Naoto YANAI","raw_affiliation_strings":["Graduate School of Information Science and Technology, Osaka University"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graduate School of Information Science and Technology, Osaka University","institution_ids":["https://openalex.org/I98285908"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":true,"cited_by_count":0,"citation_normalized_percentile":{"value":0.30453424,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"E108.D","issue":"12","first_page":"1496","last_page":"1506"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.6747999787330627,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.6747999787330627,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11719","display_name":"Data Quality and Management","score":0.628600001335144,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.626800000667572,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6995000243186951},{"id":"https://openalex.org/keywords/hyperparameter","display_name":"Hyperparameter","score":0.5339999794960022},{"id":"https://openalex.org/keywords/sampling","display_name":"Sampling (signal processing)","score":0.5134000182151794},{"id":"https://openalex.org/keywords/noise","display_name":"Noise (video)","score":0.4934999942779541},{"id":"https://openalex.org/keywords/diffusion","display_name":"Diffusion","score":0.44119998812675476},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4269999861717224},{"id":"https://openalex.org/keywords/importance-sampling","display_name":"Importance sampling","score":0.39399999380111694},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.390500009059906}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7900000214576721},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6995000243186951},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5763000249862671},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5717999935150146},{"id":"https://openalex.org/C8642999","wikidata":"https://www.wikidata.org/wiki/Q4171168","display_name":"Hyperparameter","level":2,"score":0.5339999794960022},{"id":"https://openalex.org/C140779682","wikidata":"https://www.wikidata.org/wiki/Q210868","display_name":"Sampling (signal processing)","level":3,"score":0.5134000182151794},{"id":"https://openalex.org/C99498987","wikidata":"https://www.wikidata.org/wiki/Q2210247","display_name":"Noise (video)","level":3,"score":0.4934999942779541},{"id":"https://openalex.org/C69357855","wikidata":"https://www.wikidata.org/wiki/Q163214","display_name":"Diffusion","level":2,"score":0.44119998812675476},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4269999861717224},{"id":"https://openalex.org/C52740198","wikidata":"https://www.wikidata.org/wiki/Q1539564","display_name":"Importance sampling","level":3,"score":0.39399999380111694},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.390500009059906},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.3734999895095825},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.35260000824928284},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.3449000120162964},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.32019999623298645},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.31349998712539673},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3077999949455261},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.30410000681877136},{"id":"https://openalex.org/C2988773926","wikidata":"https://www.wikidata.org/wiki/Q25104379","display_name":"Generative adversarial network","level":3,"score":0.30000001192092896},{"id":"https://openalex.org/C163294075","wikidata":"https://www.wikidata.org/wiki/Q581861","display_name":"Noise reduction","level":2,"score":0.2736999988555908},{"id":"https://openalex.org/C2777472644","wikidata":"https://www.wikidata.org/wiki/Q16968992","display_name":"Approximate inference","level":3,"score":0.2500999867916107}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1587/transinf.2024icp0005","is_oa":true,"landing_page_url":"https://doi.org/10.1587/transinf.2024icp0005","pdf_url":"https://www.jstage.jst.go.jp/article/transinf/advpub/0/advpub_2024ICP0005/_pdf","source":{"id":"https://openalex.org/S2486202937","display_name":"IEICE Transactions on Information and Systems","issn_l":"0916-8532","issn":["0916-8532","1745-1361"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4320800604","host_organization_name":"Institute of Electronics, Information and Communication Engineers","host_organization_lineage":["https://openalex.org/P4320800604"],"host_organization_lineage_names":["Institute of Electronics, Information and Communication Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEICE Transactions on Information and Systems","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1587/transinf.2024icp0005","is_oa":true,"landing_page_url":"https://doi.org/10.1587/transinf.2024icp0005","pdf_url":"https://www.jstage.jst.go.jp/article/transinf/advpub/0/advpub_2024ICP0005/_pdf","source":{"id":"https://openalex.org/S2486202937","display_name":"IEICE Transactions on Information and Systems","issn_l":"0916-8532","issn":["0916-8532","1745-1361"],"is_oa":true,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4320800604","host_organization_name":"Institute of Electronics, Information and Communication Engineers","host_organization_lineage":["https://openalex.org/P4320800604"],"host_organization_lineage_names":["Institute of Electronics, Information and Communication Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEICE Transactions on Information and Systems","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G8159118636","display_name":null,"funder_award_id":"JPMJCR21M5","funder_id":"https://openalex.org/F4320338075","funder_display_name":"Core Research for Evolutional Science and Technology"}],"funders":[{"id":"https://openalex.org/F4320338075","display_name":"Core Research for Evolutional Science and Technology","ror":"https://ror.org/00097mb19"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4414193599.pdf","grobid_xml":"https://content.openalex.org/works/W4414193599.grobid-xml"},"referenced_works_count":31,"referenced_works":["https://openalex.org/W1861492603","https://openalex.org/W2473418344","https://openalex.org/W2535690855","https://openalex.org/W2795435272","https://openalex.org/W2887995258","https://openalex.org/W2890139949","https://openalex.org/W2899461894","https://openalex.org/W2911978475","https://openalex.org/W2952604841","https://openalex.org/W2962770929","https://openalex.org/W2963378725","https://openalex.org/W2965527189","https://openalex.org/W2972359262","https://openalex.org/W2973232880","https://openalex.org/W3071470454","https://openalex.org/W3122816307","https://openalex.org/W3159069780","https://openalex.org/W3212516020","https://openalex.org/W4285605725","https://openalex.org/W4288057780","https://openalex.org/W4300991139","https://openalex.org/W4307964254","https://openalex.org/W4308361270","https://openalex.org/W4308410483","https://openalex.org/W4308643663","https://openalex.org/W4312933868","https://openalex.org/W4377695098","https://openalex.org/W4385269969","https://openalex.org/W4389195517","https://openalex.org/W4394625755","https://openalex.org/W4394625871"],"related_works":[],"abstract_inverted_index":{"Diffusion":[0],"models":[1,4],"are":[2,203],"generative":[3,59],"that":[5,121,140,148,174],"generate":[6],"images,":[7],"videos,":[8],"and":[9,14,67,79,97,109,115,118,147],"audio":[10],"through":[11,168],"learning":[12,44],"samples":[13,186],"have":[15],"attracted":[16],"attention":[17],"in":[18,112,129,152,201],"recent":[19],"years.":[20],"In":[21],"this":[22],"paper,":[23],"we":[24,138,172],"investigate":[25],"whether":[26],"a":[27,42,58,64,94,104,153],"diffusion":[28,50,72,89,95,123],"model":[29,51,66,91,96,124],"is":[30,125,145,176,216],"resistant":[31],"to":[32,70,127,133,159,179,207],"membership":[33,134],"inference":[34,135],"attacks,":[35],"which":[36],"evaluate":[37],"the":[38,49,53,71,87,98,107,122,141,149,156,160,180,208,211],"privacy":[39],"leakage":[40],"of":[41,55,131,143,213],"machine":[43],"model.":[45],"We":[46,82,162],"primarily":[47],"discuss":[48],"from":[52],"standpoints":[54],"comparison":[56],"with":[57,86,184],"adversarial":[60],"network":[61],"(GAN)":[62],"as":[63,75,93,103],"conventional":[65],"hyperparameters":[68,202],"unique":[69],"model,":[73],"such":[74],"timesteps,":[76],"sampling":[77,80,199,214],"steps,":[78],"variances.":[81],"conduct":[83],"extensive":[84],"experiments":[85],"denoising":[88],"implicit":[90],"(DDIM)":[92],"deep":[99],"convolutional":[100],"GAN":[101,105,128],"(DCGAN)":[102],"on":[106],"CelebA":[108],"CIFAR-10":[110],"datasets":[111],"both":[113],"white-box":[114],"black-box":[116],"settings":[117],"then":[119],"show":[120],"comparable":[126],"terms":[130],"resistance":[132,206],"attacks.":[136],"Next,":[137],"demonstrate":[139],"impact":[142,212],"timesteps":[144],"significant":[146],"intermediate":[150],"steps":[151,200],"noise":[154],"schedule":[155],"most":[157],"vulnerable":[158,178],"attack.":[161],"also":[163],"found":[164],"two":[165],"key":[166],"insights":[167],"further":[169],"analysis.":[170],"First,":[171],"identify":[173],"DDIM":[175],"more":[177],"attack":[181],"when":[182],"trained":[183],"fewer":[185],"even":[187],"though":[188],"it":[189],"achieves":[190],"lower":[191],"Frechet":[192],"inception":[193],"distance":[194],"scores":[195],"than":[196],"DCGAN.":[197],"Second,":[198],"important":[204],"for":[205],"attack,":[209],"whereas":[210],"variances":[215],"negligible.":[217]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
