{"id":"https://openalex.org/W7138354150","doi":"https://doi.org/10.1609/aaai.v40i14.38134","title":"Dual-View Inference Attack: Machine Unlearning Amplifies Privacy Exposure","display_name":"Dual-View Inference Attack: Machine Unlearning Amplifies Privacy Exposure","publication_year":2026,"publication_date":"2026-03-14","ids":{"openalex":"https://openalex.org/W7138354150","doi":"https://doi.org/10.1609/aaai.v40i14.38134"},"language":null,"primary_location":{"id":"doi:10.1609/aaai.v40i14.38134","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i14.38134","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"diamond","oa_url":"https://doi.org/10.1609/aaai.v40i14.38134","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5129724072","display_name":"Lulu Xue","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Lulu Xue","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129651795","display_name":"Shengshan Hu","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Shengshan Hu","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5125726998","display_name":"Linqiang Qian","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Linqiang Qian","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017175888","display_name":"Peijin Guo","orcid":"https://orcid.org/0000-0003-3820-6269"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Peijin Guo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129729443","display_name":"Yechao Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yechao Zhang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129674611","display_name":"Minghui Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Minghui Li","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129751994","display_name":"Yanjun Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Yanjun Zhang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5129752559","display_name":"Dayong Ye","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Dayong Ye","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5129648929","display_name":"Leo Yu Zhang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Leo Yu Zhang","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5129724072"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":20.3204,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.97944551,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":98},"biblio":{"volume":"40","issue":"14","first_page":"11514","last_page":"11522"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.6970999836921692,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.6970999836921692,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.23839999735355377,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11719","display_name":"Data Quality and Management","score":0.012000000104308128,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.7813000082969666},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7537999749183655},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.6884999871253967},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.5895000100135803},{"id":"https://openalex.org/keywords/information-sensitivity","display_name":"Information sensitivity","score":0.5090000033378601},{"id":"https://openalex.org/keywords/privacy-protection","display_name":"Privacy protection","score":0.4115999937057495},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.3783999979496002}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8328999876976013},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.7813000082969666},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7537999749183655},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.6884999871253967},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.5895000100135803},{"id":"https://openalex.org/C137822555","wikidata":"https://www.wikidata.org/wiki/Q2587068","display_name":"Information sensitivity","level":2,"score":0.5090000033378601},{"id":"https://openalex.org/C3017597292","wikidata":"https://www.wikidata.org/wiki/Q25052250","display_name":"Privacy protection","level":2,"score":0.4115999937057495},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.38659998774528503},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.3783999979496002},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.35249999165534973},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.3467999994754791},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.33809998631477356},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3149000108242035},{"id":"https://openalex.org/C169093310","wikidata":"https://www.wikidata.org/wiki/Q3702971","display_name":"Personally identifiable information","level":2,"score":0.2815999984741211},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.2720000147819519},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.26989999413490295},{"id":"https://openalex.org/C509729295","wikidata":"https://www.wikidata.org/wiki/Q7246032","display_name":"Privacy software","level":3,"score":0.26170000433921814},{"id":"https://openalex.org/C2988416141","wikidata":"https://www.wikidata.org/wiki/Q6031139","display_name":"Information loss","level":2,"score":0.2590999901294708},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.25839999318122864}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1609/aaai.v40i14.38134","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i14.38134","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1609/aaai.v40i14.38134","is_oa":true,"landing_page_url":"https://doi.org/10.1609/aaai.v40i14.38134","pdf_url":null,"source":{"id":"https://openalex.org/S4210191458","display_name":"Proceedings of the AAAI Conference on Artificial Intelligence","issn_l":"2159-5399","issn":["2159-5399","2374-3468"],"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/P4310320058","host_organization_name":"Association for the Advancement of Artificial Intelligence","host_organization_lineage":["https://openalex.org/P4310320058"],"host_organization_lineage_names":["Association for the Advancement of Artificial Intelligence"],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the AAAI Conference on Artificial Intelligence","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.8025802373886108,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Machine":[0],"unlearning":[1,86],"is":[2],"a":[3,13,144,172],"newly":[4],"popularized":[5],"technique":[6],"for":[7,76,178],"removing":[8],"specific":[9],"training":[10],"data":[11,21,48,58,74,154],"from":[12],"trained":[14],"model,":[15],"enabling":[16],"it":[17,25,33],"to":[18,56,123,158,165],"comply":[19],"with":[20],"deletion":[22],"requests.":[23],"While":[24],"protects":[26],"the":[27,45,54,69,77,81,88,97,100,109,118,163,189,195,200],"rights":[28],"of":[29,47,72,111,191],"users":[30],"requesting":[31],"unlearning,":[32],"also":[34],"introduces":[35],"new":[36],"privacy":[37,46,70,112,134,196],"risks.":[38],"Prior":[39],"works":[40],"have":[41],"primarily":[42],"focused":[43],"on":[44,68,152],"that":[49,117],"has":[50],"been":[51],"unlearned,":[52],"while":[53],"risks":[55,71,197],"retained":[57,73,153],"remain":[59],"largely":[60],"unexplored.":[61],"To":[62,136],"address":[63],"this":[64,139],"gap,":[65],"we":[66,107,141],"focus":[67],"and,":[75],"first":[78],"time,":[79],"reveal":[80],"vulnerabilities":[82],"introduced":[83],"by":[84],"machine":[85],"under":[87],"dual-view":[89,119,201],"setting,":[90],"where":[91],"an":[92,104,167],"adversary":[93],"can":[94],"query":[95],"both":[96,159],"original":[98],"and":[99,115,170,185,193],"unlearned":[101],"models.":[102,160],"From":[103],"information-theoretic":[105],"perspective,":[106],"introduce":[108],"concept":[110],"knowledge":[113],"gain":[114],"demonstrate":[116,138],"setting":[120],"allows":[121],"adversaries":[122],"obtain":[124],"more":[125],"information":[126,151],"than":[127],"querying":[128],"either":[129],"model":[130,169,186],"alone,":[131],"thereby":[132],"amplifying":[133],"leakage.":[135],"effectively":[137],"threat,":[140],"propose":[142],"DVIA,":[143],"Dual-View":[145],"Inference":[146],"Attack,":[147],"which":[148],"extracts":[149],"membership":[150],"using":[155],"black-box":[156],"queries":[157],"DVIA":[161,192],"eliminates":[162],"need":[164],"train":[166],"attack":[168],"employs":[171],"lightweight":[173],"likelihood":[174],"ratio":[175],"inference":[176],"module":[177],"efficient":[179],"inference.":[180],"Experiments":[181],"across":[182],"different":[183],"datasets":[184],"architectures":[187],"validate":[188],"effectiveness":[190],"highlight":[194],"inherent":[198],"in":[199],"setting.":[202]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2026-03-18T00:00:00"}
