{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/inference-attack/papers/3","list_of":"/task/inference-attack","task":"Inference Attack","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"repositories listed in the archive (most first), then date (newest first), then slug","page":3,"pages_in_order":3,"rows_per_page":100,"rows":[201,283],"of":283,"counts":{"archive_papers_tagged":283,"with_a_code_link":114,"where_syntology_ran_a_sample":48,"not_listed_spam_title":0,"listed":283,"listed_where_code_ran":48,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":30,"every_run_a_failure_of_syntologys_instrument":18,"listed_with_a_run_with_no_instrument_failure":30,"listed_every_run_a_failure_of_syntologys_instrument":18,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/inference-attack","prev":"/task/inference-attack/papers/2","next":null,"papers":[{"url":null,"slug":"membership-inference-attack-with-relative","title":"Membership inference attack with relative decision boundary distance","date":"2023-06-07","arxiv_id":"2306.04109","repositories_listed":0,"syntology":null},{"url":null,"slug":"does-black-box-attribute-inference-attacks-on","title":"Does Black-box Attribute Inference Attacks on Graph Neural Networks Constitute Privacy Risk?","date":"2023-06-01","arxiv_id":"2306.00578","repositories_listed":0,"syntology":null},{"url":null,"slug":"flocks-of-stochastic-parrots-differentially","title":"Flocks of Stochastic Parrots: Differentially Private Prompt Learning for Large Language Models","date":"2023-05-24","arxiv_id":"2305.15594","repositories_listed":0,"syntology":null},{"url":null,"slug":"recup-fl-reconciling-utility-and-privacy-in","title":"RecUP-FL: Reconciling Utility and Privacy in Federated Learning via User-configurable Privacy Defense","date":"2023-04-11","arxiv_id":"2304.05135","repositories_listed":0,"syntology":null},{"url":null,"slug":"do-backdoors-assist-membership-inference","title":"Do Backdoors Assist Membership Inference Attacks?","date":"2023-03-22","arxiv_id":"2303.12589","repositories_listed":0,"syntology":null},{"url":null,"slug":"membership-inference-attack-for-beluga-whales","title":"Membership Inference Attack for Beluga Whales Discrimination","date":"2023-02-28","arxiv_id":"2302.14769","repositories_listed":0,"syntology":null},{"url":null,"slug":"targeted-attack-on-gpt-neo-for-the-satml","title":"Targeted Attack on GPT-Neo for the SATML Language Model Data Extraction Challenge","date":"2023-02-13","arxiv_id":"2302.07735","repositories_listed":0,"syntology":null},{"url":null,"slug":"privacy-against-agnostic-inference-attack-in","title":"Privacy Against Agnostic Inference Attacks in Vertical Federated Learning","date":"2023-02-10","arxiv_id":"2302.05545","repositories_listed":0,"syntology":null},{"url":null,"slug":"privacy-preserving-representation-learning","title":"Privacy-Preserving Representation Learning for Text-Attributed Networks with Simplicial Complexes","date":"2023-02-09","arxiv_id":"2302.04383","repositories_listed":0,"syntology":null},{"url":null,"slug":"autolycus-exploiting-explainable-ai-xai-for","title":"AUTOLYCUS: Exploiting Explainable AI (XAI) for Model Extraction Attacks against Interpretable Models","date":"2023-02-04","arxiv_id":"2302.02162","repositories_listed":0,"syntology":null},{"url":null,"slug":"privacy-risk-for-anisotropic-langevin","title":"Privacy Risk for anisotropic Langevin dynamics using relative entropy bounds","date":"2023-02-01","arxiv_id":"2302.00766","repositories_listed":0,"syntology":null},{"url":null,"slug":"interaction-level-membership-inference-attack","title":"Interaction-level Membership Inference Attack Against Federated Recommender Systems","date":"2023-01-26","arxiv_id":"2301.10964","repositories_listed":0,"syntology":null},{"url":null,"slug":"ranking-differential-privacy","title":"Ranking Differential Privacy","date":"2023-01-02","arxiv_id":"2301.00841","repositories_listed":0,"syntology":null},{"url":null,"slug":"gan-based-domain-inference-attack","title":"GAN-based Domain Inference Attack","date":"2022-12-22","arxiv_id":"2212.11810","repositories_listed":0,"syntology":null},{"url":null,"slug":"holistic-risk-assessment-of-inference-attacks","title":"Holistic risk assessment of inference attacks in machine learning","date":"2022-12-15","arxiv_id":"2212.10628","repositories_listed":0,"syntology":null},{"url":null,"slug":"white-box-inference-attacks-against","title":"White-box Inference Attacks against Centralized Machine Learning and Federated Learning","date":"2022-12-15","arxiv_id":"2301.03595","repositories_listed":0,"syntology":null},{"url":null,"slug":"privacy-preserving-collaborative-learning-1","title":"Privacy-Preserving Collaborative Learning through Feature Extraction","date":"2022-12-13","arxiv_id":"2212.06322","repositories_listed":0,"syntology":null},{"url":null,"slug":"purifier-defending-data-inference-attacks-via","title":"Purifier: Defending Data Inference Attacks via Transforming Confidence Scores","date":"2022-12-01","arxiv_id":"2212.00612","repositories_listed":0,"syntology":null},{"url":null,"slug":"leveraging-algorithmic-fairness-to-mitigate","title":"On the Alignment of Group Fairness with Attribute Privacy","date":"2022-11-18","arxiv_id":"2211.10209","repositories_listed":0,"syntology":null},{"url":null,"slug":"inferring-class-label-distribution-of","title":"Inferring Class Label Distribution of Training Data from Classifiers: An Accuracy-Augmented Meta-Classifier Attack","date":"2022-11-08","arxiv_id":"2211.04157","repositories_listed":0,"syntology":null},{"url":null,"slug":"local-model-reconstruction-attacks-in","title":"Local Model Reconstruction Attacks in Federated Learning and their Uses","date":"2022-10-28","arxiv_id":"2210.16205","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-novel-membership-inference-attack-against","title":"A Novel Membership Inference Attack against Dynamic Neural Networks by Utilizing Policy Networks Information","date":"2022-10-17","arxiv_id":"2210.08956","repositories_listed":0,"syntology":null},{"url":null,"slug":"privacy-attacks-against-biometric-models-with","title":"Privacy Attacks Against Biometric Models with Fewer Samples: Incorporating the Output of Multiple Models","date":"2022-09-22","arxiv_id":"2209.11020","repositories_listed":0,"syntology":null},{"url":null,"slug":"property-inference-attack-graph-neural","title":"Property inference attack; Graph neural networks; Privacy attacks and defense; Trustworthy machine learning","date":"2022-09-02","arxiv_id":"2209.01100","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-machine-learning-based","title":"Adversarial Machine Learning-Based Anticipation of Threats Against Vehicle-to-Microgrid Services","date":"2022-08-09","arxiv_id":"2208.05073","repositories_listed":0,"syntology":null},{"url":null,"slug":"on-the-evaluation-of-user-privacy-in-deep","title":"On the Evaluation of User Privacy in Deep Neural Networks using Timing Side Channel","date":"2022-08-01","arxiv_id":"2208.01113","repositories_listed":0,"syntology":null},{"url":null,"slug":"label-only-membership-inference-attack","title":"Label-Only Membership Inference Attack against Node-Level Graph Neural Networks","date":"2022-07-27","arxiv_id":"2207.13766","repositories_listed":0,"syntology":null},{"url":null,"slug":"technical-report-assisting-backdoor-federated","title":"Technical Report: Assisting Backdoor Federated Learning with Whole Population Knowledge Alignment","date":"2022-07-25","arxiv_id":"2207.12327","repositories_listed":0,"syntology":null},{"url":null,"slug":"privacy-against-inference-attacks-in-vertical","title":"Privacy Against Inference Attacks in Vertical Federated Learning","date":"2022-07-24","arxiv_id":"2207.11788","repositories_listed":0,"syntology":null},{"url":null,"slug":"white-box-membership-attack-against-machine","title":"White-box Membership Attack Against Machine Learning Based Retinopathy Classification","date":"2022-05-30","arxiv_id":"2206.03584","repositories_listed":0,"syntology":null},{"url":null,"slug":"benign-overparameterization-in-membership","title":"A Blessing of Dimensionality in Membership Inference through Regularization","date":"2022-05-27","arxiv_id":"2205.14055","repositories_listed":0,"syntology":null},{"url":null,"slug":"comprehensive-privacy-analysis-on-federated","title":"Comprehensive Privacy Analysis on Federated Recommender System against Attribute Inference Attacks","date":"2022-05-24","arxiv_id":"2205.11857","repositories_listed":0,"syntology":null},{"url":null,"slug":"residue-based-label-protection-mechanisms-in","title":"Residue-based Label Protection Mechanisms in Vertical Logistic Regression","date":"2022-05-09","arxiv_id":"2205.04166","repositories_listed":0,"syntology":null},{"url":null,"slug":"i-can-read-your-mind-control-mechanism","title":"I Can Read Your Mind: Control Mechanism Secrecy of Networked Dynamical Systems under Inference Attacks","date":"2022-05-07","arxiv_id":"2205.03556","repositories_listed":0,"syntology":null},{"url":null,"slug":"clustering-label-inference-attack-against","title":"Similarity-based Label Inference Attack against Training and Inference of Split Learning","date":"2022-03-10","arxiv_id":"2203.05222","repositories_listed":0,"syntology":null},{"url":null,"slug":"membership-privacy-protection-for-image","title":"Membership Privacy Protection for Image Translation Models via Adversarial Knowledge Distillation","date":"2022-03-10","arxiv_id":"2203.05212","repositories_listed":0,"syntology":null},{"url":null,"slug":"quantifying-privacy-risks-of-masked-language","title":"Quantifying Privacy Risks of Masked Language Models Using Membership Inference Attacks","date":"2022-03-08","arxiv_id":"2203.03929","repositories_listed":0,"syntology":null},{"url":null,"slug":"an-efficient-subpopulation-based-membership","title":"An Efficient Subpopulation-based Membership Inference Attack","date":"2022-03-04","arxiv_id":"2203.02080","repositories_listed":0,"syntology":null},{"url":null,"slug":"user-level-membership-inference-attack","title":"User-Level Membership Inference Attack against Metric Embedding Learning","date":"2022-03-04","arxiv_id":"2203.02077","repositories_listed":0,"syntology":null},{"url":null,"slug":"ppa-preference-profiling-attack-against","title":"PPA: Preference Profiling Attack Against Federated Learning","date":"2022-02-10","arxiv_id":"2202.04856","repositories_listed":0,"syntology":null},{"url":null,"slug":"dikaios-privacy-auditing-of-algorithmic","title":"Dikaios: Privacy Auditing of Algorithmic Fairness via Attribute Inference Attacks","date":"2022-02-04","arxiv_id":"2202.02242","repositories_listed":0,"syntology":null},{"url":null,"slug":"are-your-sensitive-attributes-private-novel","title":"Are Your Sensitive Attributes Private? Novel Model Inversion Attribute Inference Attacks on Classification Models","date":"2022-01-23","arxiv_id":"2201.09370","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-privacy-preserving-unsupervised-domain","title":"A Privacy-Preserving Unsupervised Domain Adaptation Framework for Clinical Text Analysis","date":"2022-01-18","arxiv_id":"2201.07317","repositories_listed":0,"syntology":null},{"url":null,"slug":"defending-label-inference-and-backdoor","title":"Batch Label Inference and Replacement Attacks in Black-Boxed Vertical Federated Learning","date":"2021-12-10","arxiv_id":"2112.05409","repositories_listed":0,"syntology":null},{"url":null,"slug":"machine-unlearning-via-gan","title":"Machine unlearning via GAN","date":"2021-11-22","arxiv_id":"2111.11869","repositories_listed":0,"syntology":null},{"url":null,"slug":"knowledge-cross-distillation-for-membership","title":"Knowledge Cross-Distillation for Membership Privacy","date":"2021-11-02","arxiv_id":"2111.01363","repositories_listed":0,"syntology":null},{"url":null,"slug":"membership-inference-attack-in-face-of-data","title":"Membership Inference Attack in Face of Data Transformations","date":"2021-09-29","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"mixnn-protection-of-federated-learning","title":"MixNN: Protection of Federated Learning Against Inference Attacks by Mixing Neural Network Layers","date":"2021-09-26","arxiv_id":"2109.12550","repositories_listed":0,"syntology":null},{"url":null,"slug":"where-did-you-learn-that-from-surprising","title":"Membership Inference Attacks Against Temporally Correlated Data in Deep Reinforcement Learning","date":"2021-09-08","arxiv_id":"2109.03975","repositories_listed":0,"syntology":null},{"url":null,"slug":"membership-inference-attack-and-defense-for","title":"Membership Inference Attack and Defense for Wireless Signal Classifiers with Deep Learning","date":"2021-07-22","arxiv_id":"2107.12173","repositories_listed":0,"syntology":null},{"url":null,"slug":"membership-inference-on-word-embedding-and","title":"Membership Inference on Word Embedding and Beyond","date":"2021-06-21","arxiv_id":"2106.11384","repositories_listed":0,"syntology":null},{"url":null,"slug":"privacy-preserving-eye-tracking-using-deep","title":"Privacy-Preserving Eye-tracking Using Deep Learning","date":"2021-06-17","arxiv_id":"2106.09621","repositories_listed":0,"syntology":null},{"url":null,"slug":"killing-two-birds-with-one-stone-stealing","title":"Killing One Bird with Two Stones: Model Extraction and Attribute Inference Attacks against BERT-based APIs","date":"2021-05-23","arxiv_id":"2105.10909","repositories_listed":0,"syntology":null},{"url":null,"slug":"bounding-information-leakage-in-machine","title":"Bounding Information Leakage in Machine Learning","date":"2021-05-09","arxiv_id":"2105.03875","repositories_listed":0,"syntology":null},{"url":null,"slug":"membership-inference-attack-susceptibility-of","title":"Membership Inference Attack Susceptibility of Clinical Language Models","date":"2021-04-16","arxiv_id":"2104.08305","repositories_listed":0,"syntology":null},{"url":null,"slug":"membership-inference-attacks-on-knowledge","title":"Membership Inference Attacks on Knowledge Graphs","date":"2021-04-16","arxiv_id":"2104.08273","repositories_listed":0,"syntology":null},{"url":null,"slug":"on-the-in-feasibility-of-attribute-inference","title":"On the (In)Feasibility of Attribute Inference Attacks on Machine Learning Models","date":"2021-03-12","arxiv_id":"2103.07101","repositories_listed":0,"syntology":null},{"url":null,"slug":"an-analysis-of-protected-health-information","title":"An Analysis Of Protected Health Information Leakage In Deep-Learning Based De-Identification Algorithms","date":"2021-01-28","arxiv_id":"2101.12099","repositories_listed":0,"syntology":null},{"url":null,"slug":"exploring-vulnerabilities-of-bert-based-apis","title":"EXPLORING VULNERABILITIES OF BERT-BASED APIS","date":"2021-01-01","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"evaluation-of-inference-attack-models-for","title":"Evaluation of Inference Attack Models for Deep Learning on Medical Data","date":"2020-10-31","arxiv_id":"2011.00177","repositories_listed":0,"syntology":null},{"url":null,"slug":"an-extension-of-fano-s-inequality-for","title":"An Extension of Fano's Inequality for Characterizing Model Susceptibility to Membership Inference Attacks","date":"2020-09-17","arxiv_id":"2009.08097","repositories_listed":0,"syntology":null},{"url":null,"slug":"quantifying-membership-inference","title":"Quantifying Membership Inference Vulnerability via Generalization Gap and Other Model Metrics","date":"2020-09-11","arxiv_id":"2009.05669","repositories_listed":0,"syntology":null},{"url":null,"slug":"sampling-attacks-amplification-of-membership","title":"Sampling Attacks: Amplification of Membership Inference Attacks by Repeated Queries","date":"2020-09-01","arxiv_id":"2009.00395","repositories_listed":0,"syntology":null},{"url":null,"slug":"mcmia-model-compression-against-membership","title":"Against Membership Inference Attack: Pruning is All You Need","date":"2020-08-28","arxiv_id":"2008.13578","repositories_listed":0,"syntology":null},{"url":null,"slug":"sharing-models-or-coresets-a-study-based-on","title":"Sharing Models or Coresets: A Study based on Membership Inference Attack","date":"2020-07-06","arxiv_id":"2007.02977","repositories_listed":0,"syntology":null},{"url":null,"slug":"over-the-air-membership-inference-attacks-as","title":"Over-the-Air Membership Inference Attacks as Privacy Threats for Deep Learning-based Wireless Signal Classifiers","date":"2020-06-25","arxiv_id":"2006.14576","repositories_listed":0,"syntology":null},{"url":null,"slug":"on-the-effectiveness-of-regularization","title":"On the Effectiveness of Regularization Against Membership Inference Attacks","date":"2020-06-09","arxiv_id":"2006.05336","repositories_listed":0,"syntology":null},{"url":null,"slug":"damia-leveraging-domain-adaptation-as-a","title":"DAMIA: Leveraging Domain Adaptation as a Defense against Membership Inference Attacks","date":"2020-05-16","arxiv_id":"2005.08016","repositories_listed":0,"syntology":null},{"url":null,"slug":"defending-model-inversion-and-membership","title":"Defending Model Inversion and Membership Inference Attacks via Prediction Purification","date":"2020-05-08","arxiv_id":"2005.03915","repositories_listed":0,"syntology":null},{"url":null,"slug":"differentially-private-k-means-clustering","title":"Differentially Private k-Means Clustering with Guaranteed Convergence","date":"2020-02-03","arxiv_id":"2002.01043","repositories_listed":0,"syntology":null},{"url":null,"slug":"effects-of-differential-privacy-and-data","title":"Effects of Differential Privacy and Data Skewness on Membership Inference Vulnerability","date":"2019-11-21","arxiv_id":"1911.09777","repositories_listed":0,"syntology":null},{"url":null,"slug":"quantifying-hyper-parameter-leakage-in","title":"Quantifying (Hyper) Parameter Leakage in Machine Learning","date":"2019-10-31","arxiv_id":"1910.14409","repositories_listed":0,"syntology":null},{"url":null,"slug":"reducing-audio-membership-inference-attack","title":"Reducing audio membership inference attack accuracy to chance: 4 defenses","date":"2019-10-31","arxiv_id":"1911.01888","repositories_listed":0,"syntology":null},{"url":null,"slug":"eavesdrop-the-composition-proportion-of","title":"Eavesdrop the Composition Proportion of Training Labels in Federated Learning","date":"2019-10-14","arxiv_id":"1910.06044","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-privacy-preservation-under","title":"Adversarial Privacy Preservation under Attribute Inference Attack","date":"2019-09-25","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"defending-against-machine-learning-based","title":"Defending against Machine Learning based Inference Attacks via Adversarial Examples: Opportunities and Challenges","date":"2019-09-17","arxiv_id":"1909.08526","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-task-specific-privacy","title":"Trade-offs and Guarantees of Adversarial Representation Learning for Information Obfuscation","date":"2019-06-19","arxiv_id":"1906.07902","repositories_listed":0,"syntology":null},{"url":null,"slug":"reconciling-utility-and-membership-privacy","title":"Membership Privacy for Machine Learning Models Through Knowledge Transfer","date":"2019-06-15","arxiv_id":"1906.06589","repositories_listed":0,"syntology":null},{"url":null,"slug":"ultimate-power-of-inference-attacks-privacy","title":"Quantifying the Privacy Risks of Learning High-Dimensional Graphical Models","date":"2019-05-29","arxiv_id":"1905.12774","repositories_listed":0,"syntology":null},{"url":null,"slug":"generative-adversarial-networks-for-black-box","title":"Generative Adversarial Networks for Black-Box API Attacks with Limited Training Data","date":"2019-01-25","arxiv_id":"1901.09113","repositories_listed":0,"syntology":null},{"url":null,"slug":"differentially-private-data-generative-models","title":"Differentially Private Data Generative Models","date":"2018-12-06","arxiv_id":"1812.02274","repositories_listed":0,"syntology":null},{"url":null,"slug":"active-deep-learning-attacks-under-strict","title":"Active Deep Learning Attacks under Strict Rate Limitations for Online API Calls","date":"2018-11-05","arxiv_id":"1811.01811","repositories_listed":0,"syntology":null},{"url":null,"slug":"isa4ml-training-data-unaware-imperceptible","title":"TrISec: Training Data-Unaware Imperceptible Security Attacks on Deep Neural Networks","date":"2018-11-02","arxiv_id":"1811.01031","repositories_listed":0,"syntology":null}],"record_sha256":"a6de029432103209eff54c017dced92d63605f059176fdd43d23580241f80bf1","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}