DSAK: Distillation of Self-Adaptive Knowledge for Membership Privacy Protection
Abstract
1. Introduction
- We put forward a defense mechanism aimed at thwarting black-box membership inference attacks, called Distillation of Self-Adaptive Knowledge (DSAK), which innovatively introduces noise generative models that enable the high-quality privacy training of machine learning models without introducing additional data.
- We introduce a special type of data noise, called self-adaptive noise, which can provide additional data features to the training process of the machine learning model and circumvent its excessive memory of the membership data.
- We perform a detailed examination of DSAK to evidence its contemporary balance of data privacy with model correctness. For example, when considering an increased level of membership privacy, DSAK achieves significantly higher classification task accuracies, ranging from 30% to 65.3%, compared to state-of-the-art defense mechanisms across various classification tasks.

2. Related Work
2.1. Membership Inference Attack
2.1.1. Label Information-Based Methods
2.1.2. Partial Output Information-Based Methods
2.1.3. Total Output Information-Based Methods
2.2. Defenses Against Membership Inference Attack
2.2.1. Noise Disturbance-Based Methods
2.2.2. Suppressing Overfitting-Based Methods
2.2.3. Knowledge Distillation-Based Methods
3. Preliminaries
3.1. Membership Data and Membership Inference Attack
3.2. Machine Learning Classification
3.3. Machine Learning Generativation
4. Our New Method
| Algorithm 1 Distillation of Self-Adaptive Knowledge |
|
4.1. Pre-Training of Self-Adaptive Noise Generation Model
4.2. Training of Teacher Model
4.3. Training of Self-Adaptive Noise-Generative Model
4.4. Self-Knowledge Distillation
4.5. Datasets
Dataset Partition
5. Experimental Design and Implementation
5.1. Models
5.2. Attack Methods
5.3. Settings of DSAK
5.4. Methods of Comparison
5.4.1. Noise-Based Methods
5.4.2. Suppressing Overfitting Methods
5.4.3. Methods in Knowledge Distillation
6. Results and Discussion
6.1. Privacy Training Effectiveness of DSAK
6.2. Comparative Analysis of the Noise-Based Methods
6.3. Comparative Analysis of the Suppressing Overfitting Methods
6.4. Comparative Analysis of the Knowledge Distillation Methods
7. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Wang, R.; Guo, Z.; Pan, W.; Ma, J.; Zhang, Y.; Yang, N.; Liu, Q.; Wei, L.; Zhang, H.; Liu, C.; et al. Pygmtools: A python graph matching toolkit. J. Mach. Learn. Res. 2024, 25, 1–7. [Google Scholar]
- Kheddar, H.; Hemis, M.; Himeur, Y. Automatic speech recognition using advanced deep learning approaches: A survey. Inf. Fusion 2024, 104, 102422. [Google Scholar] [CrossRef] [Scilit]
- Yang, J.; Shang, F.; Liao, Y.; Chen, Y. Toward High Capacity and Robust JPEG Steganography Based on Adversarial Training. Secur. Commun. Netw. 2023, 2023, 3813977. [Google Scholar] [CrossRef] [Scilit]
- Oyewole, A.T.; Adeoye, O.B.; Addy, W.A.; Okoye, C.C.; Ofodile, O.C.; Ugochukwu, C.E. Automating financial reporting with natural language processing: A review and case analysis. World J. Adv. Res. Rev. 2024, 21, 575–589. [Google Scholar] [CrossRef] [Scilit]
- Huang, R.; Li, M.; Yang, D.; Shi, J.; Chang, X.; Ye, Z.; Wu, Y.; Hong, Z.; Huang, J.; Liu, J.; et al. Audiogpt: Understanding and generating speech, music, sound, and talking head. In Proceedings of the AAAI Conference on Artificial Intelligence, Vancouver, Canada, 20–27 February 2024; Volume 38, pp. 23802–23804. [Google Scholar]
- Li, X.; Zhao, H.; Deng, W. BFOD: Blockchain-based privacy protection and security sharing scheme of flight operation data. IEEE Internet Things J. 2023, 10, 21386–21397. [Google Scholar] [CrossRef] [Scilit]
- Chen, S.; Liu, Y.; Zhang, Q.; Shao, Z.; Wang, Z. Multi-Distance Spatial-Temporal Graph Neural Network for Anomaly Detection in Blockchain Transactions. Adv. Intell. Syst. 2025, 7, 2400898. [Google Scholar] [CrossRef] [Scilit]
- Li, Z.; Liu, F.; Yang, W.; Peng, S.; Zhou, J. A survey of convolutional neural networks: Analysis, applications, and prospects. IEEE Trans. Neural Netw. Learn. Syst. 2021, 33, 6999–7019. [Google Scholar] [CrossRef] [Scilit]
- Wang, M.; Deng, W. Deep face recognition: A survey. Neurocomputing 2021, 429, 215–244. [Google Scholar] [CrossRef] [Scilit]
- Ghaleb, B.; Ahmad, J.; Buchanan, W.J.; Jan, S.U.; Tneth, A. Privacy-Preserving Credit Card Approval Using Homomorphic SVM: Toward Secure Inference in FinTech Applications. arXiv 2025, arXiv:2505.05920. [Google Scholar]
- Rigaki, M.; Garcia, S. A survey of privacy attacks in machine learning. Acm Comput. Surv. 2023, 56, 1–34. [Google Scholar] [CrossRef] [Scilit]
- Hu, C.; Zhang, C.; Lei, D.; Wu, T.; Liu, X.; Zhu, L. Achieving privacy-preserving and verifiable support vector machine training in the cloud. IEEE Trans. Inf. Forensics Secur. 2023, 18, 3476–3491. [Google Scholar] [CrossRef] [Scilit]
- Salem, A.M.G.; Bhattacharyya, A.; Backes, M.; Fritz, M.; Zhang, Y. Updates-leak: Data set inference and reconstruction attacks in online learning. In Proceedings of the 29th USENIX Security Symposium. USENIX, Boston, MA, USA, 12–14 August 2020; pp. 1291–1308. [Google Scholar]
- Jayaraman, B.; Evans, D. Are attribute inference attacks just imputation? In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, Los Angeles, CA, USA, 7–11 November 2022; pp. 1569–1582. [Google Scholar]
- Das, D.; Zhang, J.; Tramèr, F. Blind Baselines Beat Membership Inference Attacks for Foundation Models. arXiv 2024, arXiv:2406.16201. [Google Scholar] [CrossRef] [Scilit]
- Shokri, R.; Stronati, M.; Song, C.; Shmatikov, V. Membership inference attacks against machine learning models. In Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA, 22–26 May 2017; IEEE: Piscataway, NJ, USA; pp. 3–18. [Google Scholar]
- Yeom, S.; Giacomelli, I.; Menaged, A.; Fredrikson, M.; Jha, S. Overfitting, robustness, and malicious algorithms: A study of potential causes of privacy risk in machine learning. J. Comput. Secur. 2020, 28, 35–70. [Google Scholar] [CrossRef] [Scilit]
- Ko, M.; Jin, M.; Wang, C.; Jia, R. Practical membership inference attacks against large-scale multi-modal models: A pilot study. In Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV), Paris, France, 1–6 October 2023; pp. 4871–4881. [Google Scholar]
- Song, L.; Mittal, P. Systematic Evaluation of Privacy Risks of Machine Learning Models. In Proceedings of the 30th USENIX Security Symposium, Vancouver, BC, Canada, 11–13 August 2021; Volume 1, pp. 1–18. [Google Scholar]
- Choquette-Choo, C.A.; Tramèr, F.; Carlini, N.; Papernot, N. Label-only membership inference attacks. In Proceedings of the 38th International Conference on Machine Learning (ICML), Virtual Event, 18–24 July 2021; pp. 1964–1974. [Google Scholar]
- Yeom, S.; Giacomelli, I.; Fredrikson, M.; Jha, S. Privacy risk in machine learning: Analyzing the connection to overfitting. In Proceedings of the IEEE 31st Computer Security Foundations Symposium (CSF), Oxford, UK, 9–12 July 2018; IEEE: Piscataway, NJ, USA, 2018; pp. 268–282. [Google Scholar]
- Huang, S.; Liu, Z.; Yu, J.; Tang, Y.; Luo, Z.; Rao, Y. MKD: Mutual Knowledge Distillation for Membership Privacy Protection. In Proceedings of the Artificial Intelligence Security and Privacy, Abu Dhabi, United Arab Emirates, 4–6 December 2024; Vaidya, J., Gabbouj, M., Li, J., Eds.; Springer: Singapore, 2024; pp. 483–498. [Google Scholar]
- Vasa, J.; Thakkar, A. Deep learning: Differential privacy preservation in the era of big data. J. Comput. Inf. Syst. 2023, 63, 608–631. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Y.; Xu, Q.; Tang, N.; Qu, A. Differentially Private Data Release for Mixed-type Data via Latent Factor Models. J. Mach. Learn. Res. 2024, 25, 1–37. [Google Scholar]
- Chen, D.; Yu, N.; Fritz, M. RelaxLoss: Defending membership inference attacks without losing utility. arXiv 2022, arXiv:2207.05801. [Google Scholar] [CrossRef] [Scilit]
- Bukharin, A.; Li, Y.; Yu, Y.; Zhang, Q.; Chen, Z.; Zuo, S.; Zhang, C.; Zhang, S.; Zhao, T. Robust multi-agent reinforcement learning via adversarial regularization: Theoretical foundation and stable algorithms. Adv. Neural Inf. Process. Syst. 2024, 36. [Google Scholar]
- Wang, B.; Mendez, J.A.; Shui, C.; Zhou, F.; Wu, D.; Xu, G.; Gagné, C.; Eaton, E. Gap minimization for knowledge sharing and transfer. J. Mach. Learn. Res. 2023, 24, 1–57. [Google Scholar]
- Liang, J.; Huang, T.; Luo, Z.; Li, D.; Li, Y.; Ding, Z. GanNoise: Defending against black-box membership inference attacks by countering noise generation. In Proceedings of the 2023 International Conference on Data Security and Privacy Protection (DSPP), Tianjin, China, 21–23 July 2023; pp. 32–40. [Google Scholar] [CrossRef] [Scilit]
- Niu, J.; Liu, P.; Zhu, X.; Shen, K.; Wang, Y.; Chi, H.; Shen, Y.; Jiang, X.; Ma, J.; Zhang, Y. A survey on membership inference attacks and defenses in Machine Learning. J. Inf. Intell. 2024, 2, 100014. [Google Scholar] [CrossRef] [Scilit]
- Shejwalkar, V.; Houmansadr, A. Membership privacy for machine learning models through knowledge transfer. In Proceedings of the AAAI Conference on Artificial Intelligence, Virtual Event, 2–9 February 2021; Volume 35, pp. 9549–9557. [Google Scholar]
- Papernot, N.; Song, S.; Mironov, I.; Raghunathan, A.; Talwar, K.; Erlingsson, Ú. Scalable private learning with PATE. arXiv 2018, arXiv:1802.08908. [Google Scholar] [CrossRef] [Scilit]
- Zarifzadeh, S.; Liu, P.; Shokri, R. Low-Cost High-Power Membership Inference Attacks. In Proceedings of the 41st International Conference on Machine Learning, Vienna, Austria, 21–27 July 2024. [Google Scholar]
- Li, Z.; Zhang, Y. Label-leaks: Membership Inference Attack with Label. arXiv 2020, arXiv:2007.15528. [Google Scholar]
- Salem, A.; Zhang, Y.; Humbert, M.; Berrang, P.; Fritz, M.; Backes, M. ML-leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. arXiv 2018, arXiv:1806.01246. [Google Scholar] [CrossRef] [Scilit]
- Abadi, M.; Chu, A.; Goodfellow, I.; McMahan, H.B.; Mironov, I.; Talwar, K.; Zhang, L. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS), Vienna, Austria, 24–28 October 2016; pp. 308–318. [Google Scholar]
- Giraldo, J.; Cardenas, A.; Kantarcioglu, M.; Katz, J. Adversarial classification under differential privacy. In Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 23–26 February 2020. [Google Scholar]
- Jia, J.; Salem, A.; Backes, M.; Zhang, Y.; Gong, N.Z. MemGuard: Defending against black-box membership inference attacks via adversarial examples. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS), London, UK, 11–15 November 2019; pp. 259–274. [Google Scholar]
- Xue, M.; Yuan, C.; He, C.; Wu, Y.; Wu, Z.; Zhang, Y.; Liu, Z.; Liu, W. Use the Spear as a Shield: An Adversarial Example Based Privacy-Preserving Technique Against Membership Inference Attacks. IEEE Trans. Emerg. Top. Comput. 2022, 11, 153–169. [Google Scholar] [CrossRef] [Scilit]
- Kaya, Y.; Hong, S.; Dumitras, T. On the Effectiveness of Regularization Against Membership Inference Attacks. arXiv 2020, arXiv:2006.05336. [Google Scholar] [CrossRef] [Scilit]
- Kong, L.; Qi, Y.; Liu, H.; Meng, C. Sneak Path-Aware Reliability-Based Iterative Majority-Logic Decoding Algorithms for LDPC Codes in ReRAM Systems. IEEE Commun. Lett. 2025, 29, 2018–2022. [Google Scholar] [CrossRef] [Scilit]
- Hu, H.; Salcic, Z.; Dobbie, G.; Chen, Y.; Zhang, X. EAR: An enhanced adversarial regularization approach against membership inference attacks. In Proceedings of the 2021 International Joint Conference on Neural Networks (IJCNN), Shenzhen, China, 18–22 July 2021; IEEE: Piscataway, NJ, USA, 2021; pp. 1–8. [Google Scholar]
- Chen, J.; Wang, W.H.; Shi, X. Differential privacy protection against membership inference attack on machine learning for genomic data. In Proceedings of the Pacific Symposium on Biocomputing (PSB 2021), Virtual Event, 4–8 January 2021; World Scientific: Singapore, 2021; pp. 26–37. [Google Scholar]
- Zhang, Z.; Lin, G.; Ke, L.; Peng, S.; Hu, L.; Yan, H. KD-GAN: An effective membership inference attacks defence framework. Int. J. Intell. Syst. 2022, 37, 9921–9935. [Google Scholar] [CrossRef] [Scilit]
- Shen, X.; Chen, C.; Han, D.; Xu, Y.; Wang, X.; Zhou, H. A triple-branch hybrid dynamic-static alignment strategy for vision-language tasks. Neural Netw. 2025, 178, 107871. [Google Scholar] [CrossRef] [Scilit]
- Deng, J.; Guo, J.; Xue, N.; Zafeiriou, S. Arcface: Additive angular margin loss for deep face recognition. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, Long Beach, CA, USA, 15–20 June 2019; pp. 4690–4699. [Google Scholar]
- Caron, M.; Touvron, H.; Misra, I.; Jégou, H.; Mairal, J.; Bojanowski, P.; Joulin, A. Emerging properties in self-supervised vision transformers. In Proceedings of the IEEE/CVF International Conference on Computer Vision, Montreal, QC, Canada, 11–17 October 2021; pp. 9650–9660. [Google Scholar]
- Krizhevsky, A.; Hinton, G. Learning Multiple Layers of Features from Tiny Images; Technical Report; University of Toronto: Toronto, ON, Canada, 2009. [Google Scholar]
- Hinton, G.E.; Krizhevsky, A.; Sutskever, I. Imagenet classification with deep convolutional neural networks. Adv. Neural Inf. Process. Syst. 2012, 25, 1. [Google Scholar]
- Huang, G.; Liu, Z.; Van Der Maaten, L.; Weinberger, K.Q. Densely connected convolutional networks. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA, 21–26 July 2017; pp. 4700–4708. [Google Scholar]
- He, K.; Zhang, X.; Ren, S.; Sun, J. Deep residual learning for image recognition. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA, 27–30 June 2016; pp. 770–778. [Google Scholar]
- Leino, K.; Fredrikson, M. Stolen memories: Leveraging model memorization for calibrated white-box membership inference. In Proceedings of the 29th USENIX Security Symposium, Boston, MA, USA, 12–14 August 2020. [Google Scholar]
- Carlini, N.; Chien, S.; Nasr, M.; Song, S.; Terzis, A.; Tramer, F. Membership inference attacks from first principles. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 22–26 May 2022; IEEE: Piscataway, NJ, USA, 2022; pp. 1897–1914. [Google Scholar]
- Nasr, M.; Shokri, R.; Houmansadr, A. Machine learning with membership privacy using adversarial regularization. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada, 15–19 October 2018; pp. 634–646. [Google Scholar]



| Notations | Description | Notations | Description |
|---|---|---|---|
| Membership Data Samples | Non-Membership Data Samples | ||
| D | Private Membership Dataset | Shadow Membership Dataset | |
| Private Non-Membership Dataset | Shadow Non-Membership Dataset | ||
| f | Target Classifier Model | B | Batch Size of Data Samples |
| t | Teacher classifier Model | C | Number of Output Classes |
| g | Self-adaptive Noise Generative Model | K | Number of Iterations |
| Label Weights of TSG in DSAK | Distant Weights of TSG in DSAK | ||
| Probability of Member Data Application of SKD in DSAK | ∇ | Amount of Variation of Model Parameters | |
| Training Epochs of PTG in DSAK | Parameter Transfer Epochs of TTM in DSAK | ||
| , , | Parameters of Model f, t and g | , , | Learning Rates of Model f, t and g |
| Dataset | Private Data | Shadow Data | ||
|---|---|---|---|---|
| CIFAR100 | ||||
| Texas100 | ||||
| Purchase100 | ||||
| Dataset | Model | |||||||
|---|---|---|---|---|---|---|---|---|
| CIFAR100 | AlexNet | 4 | 1 | 10 | 0 | |||
| DenseNet | 1 | 1 | 50 | 0 | ||||
| Texas100 | NN | 5 | 1 | 1 | ||||
| Purchase100 | NN | 16 | 1 | 1 |
| Dataset | Model | Defense | Task Accuracy (%) ↑ | Membership Inference Attack Accuracy ↓ | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| Train | Test | Avg. | ||||||||
| CIFAR100 | AlexNet | w/o | 99.3 | 32.7 | 81.3 | 83.3 | 80.2 | 80.3 | 71.4 | 91.2 |
| w | 46.5 | 33.4 | 52.1–29.2 | 56.6 | 50.0 | 50.1 | 50.8 | 53.1 | ||
| DenseNet | w/o | 98.9 | 53.7 | 75.3 | 72.6 | 73.2 | 73.1 | 77.4 | 80.4 | |
| w | 69.7 | 54.1 | 55.7–19.6 | 57.8 | 54.4 | 54.2 | 56.7 | 55.2 | ||
| Texas100 | NN Net | w/o | 82.2 | 53.2 | 62.0 | 64.5 | 56.9 | 55.6 | 62.8 | 70.2 |
| w | 63.2 | 53.9 | 52.7–9.3 | 54.6 | 52.0 | 52.1 | 52.5 | 52.1 | ||
| Purchase100 | NN Net | w/o | 97.7 | 76.5 | 62.1 | 60.6 | 60.3 | 60.3 | 64.0 | 65.4 |
| w | 90.4 | 76.8 | 53.9–8.2 | 56.8 | 52.7 | 51.2 | 53.7 | 55.3 | ||
| Dataset | Model | Defense | Task Accuracy (%) ↑ | Membership Inference Attack Accuracy (%) ↓ | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Train | Test | Avg. | ||||||||||
| CIFAR100 | AlexNet | DP-SGD | 28.1 | 20.2 ± 0.2 | +65.3% | 52.2 ± 0.1 | % | 53.0 | 50.1 | 50.1 | 54.7 | 53.2 |
| MemGuard | 99.3 | 32.7 ± 0.2 | +21% | 57.1 ± 0.1 | +9% | 83.3 | 50.0 | 50.0 | 50.1 | 52.1 | ||
| AdvReg | 76.4 | 32.5 ± 0.8 | +2.8% | 57.2 ± 0.2 | +9% | 71.9 | 50.1 | 50.1 | 54.3 | 59.5 | ||
| Relax Loss | 37.2 | 31.8 ± 0.3 | +5.0% | 52.0 ± 0.1 | +2% | 54.8 | 50.4 | 50.3 | 52.1 | 52.6 | ||
| DMP | 50.4 | 30.4 ± 0.2 | +9.9% | 54.4 ± 0.1 | +4% | 60.0 | 54.2 | 53.2 | 52.4 | 52.4 | ||
| DSAK (ours) | 46.5 | 33.4 ± 0.2 | 52.1 ± 0.1 | 56.6 | 50.0 | 50.1 | 50.8 | 53.1 | ||||
| DenseNet | MemGuard | 98.9 | 53.7 ± 0.1 | +0.7% | 55.7 ± 0.1 | +0% | 72.6 | 50.0 | 50.0 | 51.1 | 54.8 | |
| AdvReg | 71.7 | 40.8 ± 0.6 | +32.6% | 55.3 ± 0.3 | +1% | 65.4 | 51.0 | 51.8 | 52.0 | 56.2 | ||
| Relax Loss | 83.5 | 53.9 ± 0.5 | +0.4% | 58.0 ± 0.3 | +4% | 64.8 | 56.5 | 54.7 | 59.7 | 54.4 | ||
| DMP | 59.5 | 53.1 ± 0.2 | +1.9% | 59.2 ± 0.1 | +6% | 65.1 | 51.2 | 59.6 | 59.8 | 60.2 | ||
| DSAK (ours) | 69.7 | 54.1 ± 0.2 | 55.7 ± 0.1 | 57.8 | 54.4 | 54.2 | 56.7 | 55.2 | ||||
| Texas100 | NN Net | MemGuard | 82.2 | 53.2 ± 0.1 | +1.3% | 53.4 ± 0.1 | +1% | 64.5 | 50.0 | 50.0 | 50.6 | 52.1 |
| AdvReg | 76.0 | 52.8 ± 0.5 | +2.1% | 57.7 ± 0.6 | +9% | 64.6 | 54.4 | 53.8 | 58.3 | 57.2 | ||
| Relax Loss | 62.4 | 52.4 ± 0.5 | +2.9% | 53.3 ± 0.4 | +1% | 55.3 | 51.7 | 52.0 | 52.3 | 55.3 | ||
| DMP | 71.1 | 51.9 ± 0.2 | +3.9% | 57.0 ± 0.2 | +8% | 59.6 | 55.0 | 55.1 | 57.9 | 57.6 | ||
| DSAK (ours) | 63.2 | 53.9 ± 0.2 | 52.7 ± 0.1 | 54.6 | 52.0 | 52.1 | 52.5 | 52.1 | ||||
| Purchase100 | NN Net | MemGuard | 97.7 | 76.5 ± 0.1 | +0.4% | 52.9 ± 0.2 | % | 60.6 | 50.0 | 50.0 | 51.3 | 52.7 |
| AdvReg | 95.3 | 70.3 ± 0.5 | +9.2% | 56.6 ± 0.5 | +5% | 60.9 | 55.1 | 55.2 | 55.2 | 56.8 | ||
| Relax Loss | 90.8 | 73.1 ± 0.4 | +5.1% | 53.6 ± 0.2 | % | 57.6 | 51.5 | 50.4 | 52.7 | 55.9 | ||
| DMP | 87.3 | 72.4 ± 0.3 | +6.1% | 56.2 ± 0.1 | +4% | 57.5 | 55.0 | 54.5 | 57.7 | 56.2 | ||
| DSAK (ours) | 90.4 | 76.8 ± 0.3 | 53.9 ± 0.2 | 56.8 | 52.7 | 51.2 | 53.7 | 55.3 | ||||
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Sheng, Q.; Liang, J.; Li, X.; Huang, Y. DSAK: Distillation of Self-Adaptive Knowledge for Membership Privacy Protection. Mathematics 2026, 14, 1249. https://doi.org/10.3390/math14081249
Sheng Q, Liang J, Li X, Huang Y. DSAK: Distillation of Self-Adaptive Knowledge for Membership Privacy Protection. Mathematics. 2026; 14(8):1249. https://doi.org/10.3390/math14081249
Chicago/Turabian StyleSheng, Qian, Jiaming Liang, Xinyu Li, and Yan Huang. 2026. "DSAK: Distillation of Self-Adaptive Knowledge for Membership Privacy Protection" Mathematics 14, no. 8: 1249. https://doi.org/10.3390/math14081249
APA StyleSheng, Q., Liang, J., Li, X., & Huang, Y. (2026). DSAK: Distillation of Self-Adaptive Knowledge for Membership Privacy Protection. Mathematics, 14(8), 1249. https://doi.org/10.3390/math14081249
