1. R. Shokri, M. Stronati, C. Song, V. Shmatikov, Membership inference attacks against machine learning models, in: 2017 IEEE Symposium on Security and Privacy, IEEE Computer Society, San Jose, CA, USA, 2017, pp. 3–18.
2. Membership leakage in label-only exposures;Li,2021
3. M. Fredrikson, S. Jha, T. Ristenpart, Model inversion attacks that exploit confidence information and basic countermeasures, in: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA, 2015, pp. 1322–1333.
4. M. Fredrikson, E. Lantz, S. Jha, S.M. Lin, D. Page, T. Ristenpart, Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing, in: Proceedings of the 23rd USENIX Security Symposium, San Diego, CA, USA, 2014, pp. 17–32.
5. Secure aggregation is insecure: Category inference attack on federated learning;Gao;IEEE Transactions on Dependable and Secure Computing,2021