{"id":"https://openalex.org/W3208549305","doi":"https://doi.org/10.2478/popets-2022-0050","title":"Knowledge Cross-Distillation for Membership Privacy","display_name":"Knowledge Cross-Distillation for Membership Privacy","publication_year":2022,"publication_date":"2022-03-03","ids":{"openalex":"https://openalex.org/W3208549305","doi":"https://doi.org/10.2478/popets-2022-0050","mag":"3208549305"},"language":"en","primary_location":{"id":"doi:10.2478/popets-2022-0050","is_oa":true,"landing_page_url":"https://doi.org/10.2478/popets-2022-0050","pdf_url":"https://petsymposium.org/popets/2022/popets-2022-0050.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://petsymposium.org/popets/2022/popets-2022-0050.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5049298311","display_name":"Rishav Chourasia","orcid":"https://orcid.org/0000-0001-7975-0530"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":true,"raw_author_name":"Rishav Chourasia","raw_affiliation_strings":["National University of Singapore","National University of Singapore,"],"affiliations":[{"raw_affiliation_string":"National University of Singapore","institution_ids":["https://openalex.org/I165932596"]},{"raw_affiliation_string":"National University of Singapore,","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014707393","display_name":"Batnyam Enkhtaivan","orcid":"https://orcid.org/0000-0002-4463-2478"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Batnyam Enkhtaivan","raw_affiliation_strings":["NEC Corporation","National University of Singapore,"],"affiliations":[{"raw_affiliation_string":"NEC Corporation","institution_ids":[]},{"raw_affiliation_string":"National University of Singapore,","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5090320356","display_name":"Kunihiro Ito","orcid":null},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Kunihiro Ito","raw_affiliation_strings":["NEC Corporation","National University of Singapore,"],"affiliations":[{"raw_affiliation_string":"NEC Corporation","institution_ids":[]},{"raw_affiliation_string":"National University of Singapore,","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035060444","display_name":"Junki Mori","orcid":null},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Junki Mori","raw_affiliation_strings":["NEC Corporation","National University of Singapore,"],"affiliations":[{"raw_affiliation_string":"NEC Corporation","institution_ids":[]},{"raw_affiliation_string":"National University of Singapore,","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5035993433","display_name":"Isamu Teranishi","orcid":null},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Isamu Teranishi","raw_affiliation_strings":["NEC Corporation","National University of Singapore,"],"affiliations":[{"raw_affiliation_string":"NEC Corporation","institution_ids":[]},{"raw_affiliation_string":"National University of Singapore,","institution_ids":["https://openalex.org/I165932596"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5013263916","display_name":"Hikaru Tsuchida","orcid":"https://orcid.org/0000-0002-8589-4861"},"institutions":[{"id":"https://openalex.org/I165932596","display_name":"National University of Singapore","ror":"https://ror.org/01tgyzw49","country_code":"SG","type":"education","lineage":["https://openalex.org/I165932596"]}],"countries":["SG"],"is_corresponding":false,"raw_author_name":"Hikaru Tsuchida","raw_affiliation_strings":["NEC Corporation","National University of Singapore,"],"affiliations":[{"raw_affiliation_string":"NEC Corporation","institution_ids":[]},{"raw_affiliation_string":"National University of Singapore,","institution_ids":["https://openalex.org/I165932596"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5049298311"],"corresponding_institution_ids":["https://openalex.org/I165932596"],"apc_list":null,"apc_paid":null,"fwci":1.7939,"has_fulltext":true,"cited_by_count":13,"citation_normalized_percentile":{"value":0.86789464,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":98},"biblio":{"volume":"2022","issue":"2","first_page":"362","last_page":"377"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11636","display_name":"Artificial Intelligence in Healthcare and Education","score":0.9835000038146973,"subfield":{"id":"https://openalex.org/subfields/2718","display_name":"Health Informatics"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7205512523651123},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.6573326587677002},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6351245641708374},{"id":"https://openalex.org/keywords/generative-adversarial-network","display_name":"Generative adversarial network","score":0.5667136907577515},{"id":"https://openalex.org/keywords/privacy-protection","display_name":"Privacy protection","score":0.5605510473251343},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.5220451354980469},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5011358261108398},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.49967217445373535},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.46039125323295593},{"id":"https://openalex.org/keywords/generative-model","display_name":"Generative model","score":0.45038747787475586},{"id":"https://openalex.org/keywords/private-information-retrieval","display_name":"Private information retrieval","score":0.4226028323173523},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3970714211463928},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.39445221424102783},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.36352401971817017},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.24828565120697021}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7205512523651123},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.6573326587677002},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6351245641708374},{"id":"https://openalex.org/C2988773926","wikidata":"https://www.wikidata.org/wiki/Q25104379","display_name":"Generative adversarial network","level":3,"score":0.5667136907577515},{"id":"https://openalex.org/C3017597292","wikidata":"https://www.wikidata.org/wiki/Q25052250","display_name":"Privacy protection","level":2,"score":0.5605510473251343},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.5220451354980469},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5011358261108398},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.49967217445373535},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.46039125323295593},{"id":"https://openalex.org/C167966045","wikidata":"https://www.wikidata.org/wiki/Q5532625","display_name":"Generative model","level":3,"score":0.45038747787475586},{"id":"https://openalex.org/C99221444","wikidata":"https://www.wikidata.org/wiki/Q1532069","display_name":"Private information retrieval","level":2,"score":0.4226028323173523},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3970714211463928},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.39445221424102783},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.36352401971817017},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.24828565120697021},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.2478/popets-2022-0050","is_oa":true,"landing_page_url":"https://doi.org/10.2478/popets-2022-0050","pdf_url":"https://petsymposium.org/popets/2022/popets-2022-0050.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},{"id":"pmh:oai:arXiv.org:2111.01363","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2111.01363","pdf_url":"https://arxiv.org/pdf/2111.01363","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"doi:10.2478/popets-2022-0050","is_oa":true,"landing_page_url":"https://doi.org/10.2478/popets-2022-0050","pdf_url":"https://petsymposium.org/popets/2022/popets-2022-0050.pdf","source":{"id":"https://openalex.org/S4210183172","display_name":"Proceedings on Privacy Enhancing Technologies","issn_l":"2299-0984","issn":["2299-0984"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320322","host_organization_name":"De Gruyter Open","host_organization_lineage":["https://openalex.org/P4310320322","https://openalex.org/P4310313990"],"host_organization_lineage_names":["De Gruyter Open","De Gruyter"],"type":"journal"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings on Privacy Enhancing Technologies","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.46000000834465027}],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3208549305.pdf","grobid_xml":"https://content.openalex.org/works/W3208549305.grobid-xml"},"referenced_works_count":80,"referenced_works":["https://openalex.org/W1473189865","https://openalex.org/W1557833142","https://openalex.org/W1673923490","https://openalex.org/W1821462560","https://openalex.org/W1959608418","https://openalex.org/W1992926795","https://openalex.org/W2040228409","https://openalex.org/W2051267297","https://openalex.org/W2095272373","https://openalex.org/W2095705004","https://openalex.org/W2099471712","https://openalex.org/W2119874464","https://openalex.org/W2167433878","https://openalex.org/W2173520492","https://openalex.org/W2198253679","https://openalex.org/W2473418344","https://openalex.org/W2532781556","https://openalex.org/W2535690855","https://openalex.org/W2595056910","https://openalex.org/W2757528734","https://openalex.org/W2786233556","https://openalex.org/W2795435272","https://openalex.org/W2798657499","https://openalex.org/W2811973125","https://openalex.org/W2884943453","https://openalex.org/W2887995258","https://openalex.org/W2897830718","https://openalex.org/W2912023992","https://openalex.org/W2923095117","https://openalex.org/W2925799800","https://openalex.org/W2930926105","https://openalex.org/W2945237470","https://openalex.org/W2946363484","https://openalex.org/W2946930197","https://openalex.org/W2947411064","https://openalex.org/W2952604841","https://openalex.org/W2956128647","https://openalex.org/W2962835266","https://openalex.org/W2963374540","https://openalex.org/W2963378725","https://openalex.org/W2963399829","https://openalex.org/W2963456518","https://openalex.org/W2963844355","https://openalex.org/W2963857521","https://openalex.org/W2964151798","https://openalex.org/W2964153729","https://openalex.org/W2964318098","https://openalex.org/W2965527189","https://openalex.org/W2967985550","https://openalex.org/W2973232880","https://openalex.org/W2976822050","https://openalex.org/W2979099362","https://openalex.org/W2983140679","https://openalex.org/W2998183189","https://openalex.org/W2998732348","https://openalex.org/W3004170295","https://openalex.org/W3010177353","https://openalex.org/W3015625436","https://openalex.org/W3035422456","https://openalex.org/W3046102592","https://openalex.org/W3046208783","https://openalex.org/W3048775464","https://openalex.org/W3071470454","https://openalex.org/W3096692244","https://openalex.org/W3096738375","https://openalex.org/W3103245149","https://openalex.org/W3104216513","https://openalex.org/W3104224589","https://openalex.org/W3106051020","https://openalex.org/W3110470025","https://openalex.org/W3115042282","https://openalex.org/W3118608800","https://openalex.org/W3137695714","https://openalex.org/W3138758728","https://openalex.org/W3138815606","https://openalex.org/W3155551741","https://openalex.org/W3164762628","https://openalex.org/W3176193152","https://openalex.org/W3189843092","https://openalex.org/W3205533264"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W4246396837","https://openalex.org/W2482350142","https://openalex.org/W3176240006","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4385421777","https://openalex.org/W2971552217","https://openalex.org/W3132610544"],"abstract_inverted_index":{"Abstract":[0],"A":[1],"membership":[2,42],"inference":[3],"attack":[4],"(MIA)":[5],"poses":[6],"privacy":[7,43,127],"risks":[8],"for":[9,41,50,82,140,174],"the":[10,25,32,70,93,99,126,141,164,175],"training":[11,33],"data":[12,27,49,74,85,173],"of":[13,31,56,72,101,131,138,163],"a":[14,29,53,79,109,156],"machine":[15],"learning":[16],"model.":[17],"With":[18],"an":[19,21],"MIA,":[20],"attacker":[22],"guesses":[23],"if":[24],"target":[26],"are":[28,134],"member":[30],"dataset.":[34],"The":[35],"state-of-the-art":[36],"defense":[37,111,133,154],"against":[38,112],"MIAs,":[39],"distillation":[40,117],"(DMP),":[44],"requires":[45],"not":[46,76,170],"only":[47],"private":[48],"protection":[51,128],"but":[52],"large":[54],"amount":[55],"unlabeled":[57],"public":[58,73,84,120,172],"data.":[59,121],"However,":[60],"in":[61,146],"certain":[62],"privacy-sensitive":[63],"domains,":[64],"such":[65],"as":[66,96],"medicine":[67],"and":[68,129,150,152],"finance,":[69],"availability":[71],"is":[75],"guaranteed.":[77],"Moreover,":[78],"trivial":[80],"method":[81],"generating":[83],"by":[86,98],"using":[87],"generative":[88],"adversarial":[89],"networks":[90],"significantly":[91],"decreases":[92],"model":[94],"accuracy,":[95],"reported":[97],"authors":[100],"DMP.":[102],"To":[103],"overcome":[104],"this":[105],"problem,":[106],"we":[107],"propose":[108],"novel":[110],"MIAs":[113],"that":[114,125,167],"uses":[115],"knowledge":[116],"without":[118],"requiring":[119],"Our":[122],"experiments":[123],"show":[124],"accuracy":[130],"our":[132,153],"comparable":[135],"to":[136],"those":[137,162],"DMP":[139],"benchmark":[142],"tabular":[143],"datasets":[144],"used":[145],"MIA":[147],"research,":[148],"Purchase100":[149],"Texas100,":[151],"has":[155],"much":[157],"better":[158],"privacy-utility":[159],"trade-off":[160],"than":[161],"existing":[165],"defenses":[166],"also":[168],"do":[169],"use":[171],"image":[176],"dataset":[177],"CIFAR10.":[178]},"counts_by_year":[{"year":2025,"cited_by_count":2},{"year":2024,"cited_by_count":6},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
