{"id":"https://openalex.org/W6944454521","doi":"https://doi.org/10.18420/inf2022_106","title":"The Influence of Training Parameters on Neural Networks' Vulnerability to Membership Inference Attacks","display_name":"The Influence of Training Parameters on Neural Networks' Vulnerability to Membership Inference Attacks","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W6944454521","doi":"https://doi.org/10.18420/inf2022_106"},"language":"en","primary_location":{"id":"pmh:oai:publica.fraunhofer.de:publica/447705","is_oa":false,"landing_page_url":"https://publica.fraunhofer.de/handle/publica/447705","pdf_url":null,"source":{"id":"https://openalex.org/S4306400318","display_name":"Fraunhofer-Publica (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"},"type":"article","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.18420/inf2022_106","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Bouanani, Oussama","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Bouanani, Oussama","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":null,"display_name":"Boenisch, Franziska","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Boenisch, Franziska","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.23915539,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":true,"primary_topic":{"id":"https://openalex.org/T13820","display_name":"SAS software applications and methods","score":0.030700000002980232,"subfield":{"id":"https://openalex.org/subfields/2204","display_name":"Biomedical Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T13820","display_name":"SAS software applications and methods","score":0.030700000002980232,"subfield":{"id":"https://openalex.org/subfields/2204","display_name":"Biomedical Engineering"},"field":{"id":"https://openalex.org/fields/22","display_name":"Engineering"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13370","display_name":"Diverse Scientific and Economic Studies","score":0.021900000050663948,"subfield":{"id":"https://openalex.org/subfields/2002","display_name":"Economics and Econometrics"},"field":{"id":"https://openalex.org/fields/20","display_name":"Economics, Econometrics and Finance"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T12330","display_name":"Botanical Research and Applications","score":0.016699999570846558,"subfield":{"id":"https://openalex.org/subfields/1106","display_name":"Food Science"},"field":{"id":"https://openalex.org/fields/11","display_name":"Agricultural and Biological Sciences"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/metric","display_name":"Metric (unit)","score":0.6281999945640564},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6165000200271606},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.6003999710083008},{"id":"https://openalex.org/keywords/normalization","display_name":"Normalization (sociology)","score":0.5557000041007996},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.541100025177002},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.5138000249862671},{"id":"https://openalex.org/keywords/sample","display_name":"Sample (material)","score":0.45170000195503235},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.430400013923645},{"id":"https://openalex.org/keywords/correlation","display_name":"Correlation","score":0.42260000109672546}],"concepts":[{"id":"https://openalex.org/C176217482","wikidata":"https://www.wikidata.org/wiki/Q860554","display_name":"Metric (unit)","level":2,"score":0.6281999945640564},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6165000200271606},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.609000027179718},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6039000153541565},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.6003999710083008},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.578000009059906},{"id":"https://openalex.org/C136886441","wikidata":"https://www.wikidata.org/wiki/Q926129","display_name":"Normalization (sociology)","level":2,"score":0.5557000041007996},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.541100025177002},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.5138000249862671},{"id":"https://openalex.org/C198531522","wikidata":"https://www.wikidata.org/wiki/Q485146","display_name":"Sample (material)","level":2,"score":0.45170000195503235},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.430400013923645},{"id":"https://openalex.org/C117220453","wikidata":"https://www.wikidata.org/wiki/Q5172842","display_name":"Correlation","level":2,"score":0.42260000109672546},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.42260000109672546},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.41940000653266907},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.41620001196861267},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.413100004196167},{"id":"https://openalex.org/C58489278","wikidata":"https://www.wikidata.org/wiki/Q1172284","display_name":"Data set","level":2,"score":0.3853999972343445},{"id":"https://openalex.org/C114289077","wikidata":"https://www.wikidata.org/wiki/Q3284399","display_name":"Statistical model","level":2,"score":0.34459999203681946},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.3441999852657318},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.3221000134944916},{"id":"https://openalex.org/C2776145597","wikidata":"https://www.wikidata.org/wiki/Q25339462","display_name":"Dropout (neural networks)","level":2,"score":0.2955000102519989},{"id":"https://openalex.org/C2780898871","wikidata":"https://www.wikidata.org/wiki/Q860554","display_name":"Performance metric","level":2,"score":0.2930000126361847},{"id":"https://openalex.org/C2780069185","wikidata":"https://www.wikidata.org/wiki/Q7977945","display_name":"Equivalence (formal languages)","level":2,"score":0.2892000079154968},{"id":"https://openalex.org/C129848803","wikidata":"https://www.wikidata.org/wiki/Q2564360","display_name":"Sample size determination","level":2,"score":0.2856000065803528},{"id":"https://openalex.org/C160234255","wikidata":"https://www.wikidata.org/wiki/Q812535","display_name":"Bayesian inference","level":3,"score":0.2840000092983246},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.28209999203681946},{"id":"https://openalex.org/C2984842247","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep neural networks","level":3,"score":0.28139999508857727},{"id":"https://openalex.org/C134261354","wikidata":"https://www.wikidata.org/wiki/Q938438","display_name":"Statistical inference","level":2,"score":0.2786000072956085},{"id":"https://openalex.org/C49937458","wikidata":"https://www.wikidata.org/wiki/Q2599292","display_name":"Probabilistic logic","level":2,"score":0.27320000529289246},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.27219998836517334},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.26420000195503235}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:publica.fraunhofer.de:publica/447705","is_oa":false,"landing_page_url":"https://publica.fraunhofer.de/handle/publica/447705","pdf_url":null,"source":{"id":"https://openalex.org/S4306400318","display_name":"Fraunhofer-Publica (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"},{"id":"doi:10.18420/inf2022_106","is_oa":true,"landing_page_url":"https://doi.org/10.18420/inf2022_106","pdf_url":null,"source":{"id":"https://openalex.org/S7407052918","display_name":"Gesellschaft f\u00fcr Informatik (GI)","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article-journal"}],"best_oa_location":{"id":"doi:10.18420/inf2022_106","is_oa":true,"landing_page_url":"https://doi.org/10.18420/inf2022_106","pdf_url":null,"source":{"id":"https://openalex.org/S7407052918","display_name":"Gesellschaft f\u00fcr Informatik (GI)","issn_l":null,"issn":[],"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article-journal"},"sustainable_development_goals":[{"score":0.48410844802856445,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"With":[0],"Machine":[1],"Learning":[2],"(ML)":[3],"models":[4,67,183],"being":[5],"increasingly":[6],"applied":[7,135],"in":[8,84,98,168],"sensitive":[9],"domains,":[10],"the":[11,41,63,66,69,92,95,101,108,111,115,125,129,139,166,169,195],"related":[12],"privacy":[13,51],"concerns":[14],"are":[15,20,53],"rising.":[16],"Neural":[17],"networks":[18],"(NN)":[19],"vulnerable":[21],"to,":[22],"so-called,":[23],"membership":[24],"inference":[25],"attacks":[26],"(MIA)":[27],"which":[28],"aim":[29],"at":[30],"determining":[31],"whether":[32],"a":[33,74,144,149,162],"particular":[34],"data":[35,178],"sample":[36],"was":[37,200],"used":[38],"for":[39,207],"training":[40,70,96],"model.":[42],"The":[43,197],"factors":[44,82],"that":[45,62,107,182,188],"render":[46],"NNs":[47,99],"prone":[48],"to":[49,77,89,138,152,164,194],"this":[50],"attack":[52],"not":[54],"yet":[55],"fully":[56],"understood.":[57],"However,":[58],"previous":[59],"work":[60],"suggests":[61],"setup":[64],"of":[65,94,119,131,171],"and":[68,114,117,122,142,155,176,180,209,218],"process":[71],"might":[72],"impact":[73,127],"model's":[75,150],"risk":[76],"MIAs.":[78,132],"To":[79],"investigate":[80],"these":[81],"more":[83,192],"detail,":[85],"we":[86,134],"set":[87],"out":[88],"experimentally":[90],"evaluate":[91],"influence":[93],"choices":[97],"on":[100,128,187,221],"models'":[102],"vulnerability.":[103],"Our":[104],"analyses":[105,137],"highlight":[106],"batch":[109,120],"size,":[110],"activation":[112],"function,":[113],"application":[116],"placement":[118],"normalization":[121],"dropout":[123],"have":[124],"highest":[126],"success":[130],"Additionally,":[133],"statistical":[136],"experiment":[140],"results":[141],"found":[143],"highly":[145],"positive":[146],"correlation":[147],"between":[148,174],"ability":[151],"resist":[153],"MIAs":[154,220],"its":[156],"generalization":[157],"capacity.":[158],"We":[159],"also":[160],"defined":[161],"metric":[163,189],"measure":[165],"difference":[167],"distributions":[170,217],"loss":[172,213],"values":[173,186,214],"member":[175,208],"non-member":[177,210],"samples":[179,211],"observed":[181],"scoring":[184],"higher":[185],"were":[190],"consistently":[191],"exposed":[193],"attack.":[196],"latter":[198],"observation":[199],"further":[201],"confirmed":[202],"by":[203],"manually":[204],"generating":[205],"predictions":[206],"producing":[212],"within":[215],"specific":[216],"launching":[219],"them.":[222]},"counts_by_year":[],"updated_date":"2026-04-26T08:31:28.666265","created_date":"2025-10-10T00:00:00"}
