Fetching the paper…
Reading the bibliography…
Neural networks are susceptible to data inference attacks such as the model inversion attack and the membership inference attack, where the attacker could infer the reconstruction and the membership of a data sample from the confidence scores predicted by the target classifier.
P. Sollich and A. Krogh, “Learning with ensembles: How overfitting can be useful,” in Advances in neural information processing systems , 1996, pp. 190–196
1996
Earlier work this paper cites.
D. Opitz and R. Maclin, “Popular ensemble methods: An empirical study,” J. Artif. Int. Res. , vol. 11, no. 1, pp. 169–198, Jul. 1999
1999
Earlier work this paper cites.
R. Caruana, S. Lawrence, and C. L. Giles, “Overfitting in neural nets: Backpropagation, conjugate gradient, and early stopping,” in Advances in neural information processing systems , 2001, pp. 402–408
2001
Earlier work this paper cites.
C. Dwork, F. McSherry, K. Nissim, and A. Smith, “Calibrating Noise to Sensitivity in Private Data Analysis,” in Theory of Cryptography , ser. Lecture Notes in Computer Science, S. Halevi and T. Rabin, Eds. Berlin, Heidelberg: Springer, 2006, pp. 265–284
2006
Earlier work this paper cites.
R. Polikar, “Ensemble based systems in decision making,” IEEE Circuits and Systems Magazine , vol. 6, no. 3, pp. 21–45, Third 2006, conference Name: IEEE Circuits and Systems Magazine
2006
Earlier work this paper cites.
N. Homer, S. Szelinger, M. Redman, D. Duggan, W. Tembe, J. Muehling, J. V. Pearson, D. A. Stephan, S. F. Nelson, and D. W. Craig, “Resolving Individuals Contributing Trace Amounts of DNA to Highly Complex Mixtures Using High-Density SNP Genotyping Microarrays,” PLOS Genetics , vol. 4, no. 8, p. e1000167, Aug. 2008
2008
Earlier work this paper cites.
L. v. d. Maaten and G. Hinton, “Visualizing data using t-sne,” Journal of machine learning research , vol. 9, no. Nov, pp. 2579–2605, 2008
2008
Earlier work this paper cites.
K. Chaudhuri, C. Monteleoni, and A. D. Sarwate, “Differentially private empirical risk minimization,” Journal of Machine Learning Research , vol. 12, no. Mar, pp. 1069–1109, 2011
2011
Earlier work this paper cites.
P. Baldi, “Autoencoders, Unsupervised Learning, and Deep Architectures,” in Proceedings of ICML Workshop on Unsupervised and Transfer Learning , Jun. 2012, pp. 37–49
2012
Earlier work this paper cites.
D. Kifer, A. Smith, and A. Thakurta, “Private Convex Empirical Risk Minimization and High-dimensional Regression,” in Conference on Learning Theory , Jun. 2012, pp. 25.1–25.40
2012
Earlier work this paper cites.
S. Song, K. Chaudhuri, and A. D. Sarwate, “Stochastic gradient descent with differentially private updates,” in 2013 IEEE Global Conference on Signal and Information Processing , Dec. 2013, pp. 245–248
2013
Earlier work this paper cites.
R. Bassily, A. Smith, and A. Thakurta, “Private empirical risk minimization: Efficient algorithms and tight error bounds,” in Proceedings - Annual IEEE Symposium on Foundations of Computer Science, FOCS , ser. Proceedings - Annual IEEE Symposium on Foundations of Computer Science, FOCS. United States: IEEE Computer Society, Dec. 2014, pp. 464–473
2014
Earlier work this paper cites.
M. Fredrikson, E. Lantz, S. Jha, S. Lin, D. Page, and T. Ristenpart, “Privacy in Pharmacogenetics: An End-to-End Case Study of Personalized Warfarin Dosing,” Proceedings of the 23rd USENIX Security Symposium , pp. 17–32, 2014
2014
Earlier work this paper cites.
I. J. Goodfellow, J. Pouget-Abadie, M. Mirza, B. Xu, D. Warde-Farley, S. Ozair, A. C. Courville, and Y. Bengio, “Generative Adversarial Nets,” in Advances in Neural Information Processing Systems 27: Annual Conference on Neural Information Processing Systems 2014, December 8-13 2014, Montreal, Quebec, Canada , 2014, pp. 2672–2680
2014
Earlier work this paper cites.
2014
Earlier work this paper cites.
N. Srivastava, G. Hinton, A. Krizhevsky, I. Sutskever, and R. Salakhutdinov, “Dropout: A Simple Way to Prevent Neural Networks from Overfitting,” Journal of Machine Learning Research , vol. 15, no. 56, pp. 1929–1958, 2014
2014
Earlier work this paper cites.
G. Ateniese, L. V. Mancini, A. Spognardi, A. Villani, D. Vitali, and G. Felici, “Hacking Smart Machines with Smarter Ones: How to Extract Meaningful Data from Machine Learning Classifiers,” International Journal of Security and Networks , vol. 10, no. 3, pp. 137–150, Sep. 2015
2015
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures,” in Proceedings of the 22nd { }
2015
Earlier work this paper cites.
Y. LeCun, Y. Bengio, and G. Hinton, “Deep learning,” nature , vol. 521, no. 7553, pp. 436–444, 2015
2015
Earlier work this paper cites.
R. Shokri and V. Shmatikov, “Privacy-preserving deep learning,” in Proceedings of the 22Nd ACM SIGSAC Conference on Computer and Communications Security , 2015, pp. 1310–1321
2015
Earlier work this paper cites.
M. Abadi, A. Chu, I. J. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep Learning with Differential Privacy,” in Proceedings of the 2016 { }
2016
Earlier work this paper cites.
M. Backes, P. Berrang, M. Humbert, and P. Manoharan, “Membership Privacy in MicroRNA-based Studies,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’16. Vienna, Austria: Association for Computing Machinery, Oct. 2016, pp. 319–330
2016
Earlier work this paper cites.
N. Dowlin, R. Gilad-Bachrach, K. Laine, K. Lauter, M. Naehrig, and J. Wernsing, “CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy,” in Proceedings of the 33rd International Conference on International Conference on Machine Learning - Volume 48 , ser. ICML’16. New York, NY, USA: JMLR.org, Jun. 2016, pp. 201–210
2016
Earlier work this paper cites.
O. Ohrimenko, F. Schuster, C. Fournet, A. Mehta, S. Nowozin, K. Vaswani, and M. Costa, “Oblivious Multi-Party Machine Learning on Trusted Processors,” in 25th { }
2016
Cited alongside, same era.
2016
Cited alongside, same era.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing Machine Learning Models via Prediction APIs,” in 25th { }
2016
Cited alongside, same era.
X. Wu, M. Fredrikson, S. Jha, and J. F. Naughton, “A Methodology for Formalizing Model-Inversion Attacks,” in 2016 IEEE 29th Computer Security Foundations Symposium (CSF) , Jun. 2016, pp. 355–370
2016
Cited alongside, same era.
A. Pyrgelis, C. Troncoso, and E. D. Cristofaro, “Knock Knock, Who’s There? Membership Inference on Aggregate Location Data,” in Proceedings 2018 Network and Distributed System Security Symposium . San Diego, CA: Internet Society, 2018
2018
Later among the works it cites.
A. Salem, Y. Zhang, M. Humbert, M. Fritz, and M. Backes, “ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models,” in Proceedings of the 26th Annual Network and Distributed System Security Symposium ( { }
2018
Later among the works it cites.
B. Wang and N. Z. Gong, “Stealing Hyperparameters in Machine Learning,” in 2018 IEEE Symposium on Security and Privacy (SP) , May 2018, pp. 36–52
2018
Later among the works it cites.
L. Wei, B. Luo, Y. Li, Y. Liu, and Q. Xu, “I Know What You See: Power Side-Channel Attack on Convolutional Neural Network Accelerators,” in Proceedings of the 34th Annual Computer Security Applications Conference , ser. ACSAC ’18. San Juan, PR, USA: Association for Computing Machinery, Dec. 2018, pp. 393–406
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
K. Bonawitz, V. Ivanov, B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth, “Practical Secure Aggregation for Privacy-Preserving Machine Learning,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security - CCS ’17 , 2017, pp. 1175–1191
2017
Cited alongside, same era.
V. Dumoulin, I. Belghazi, B. Poole, A. Lamb, M. Arjovsky, O. Mastropietro, and A. C. Courville, “Adversarially Learned Inference,” in ICLR 2017 , vol. abs/1606.0, 2017
2017
Cited alongside, same era.
S. Hidano, T. Murakami, S. Katsumata, S. Kiyomoto, and G. Hanaoka, “Model Inversion Attacks for Prediction Systems : Without Knowledge of Non-Sensitive Attributes,” in 2017 15th Annual Conference on Privacy, Security and Trust (PST) , 2017
2017
Cited alongside, same era.
B. Hitaj, G. Ateniese, and F. Perez-Cruz, “Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security , vol. 1, 2017, pp. 603–618
2017
Cited alongside, same era.
G. Huang, Z. Liu, L. Van Der Maaten, and K. Q. Weinberger, “Densely Connected Convolutional Networks,” in 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , Jul. 2017, pp. 2261–2269
2017
Cited alongside, same era.
J. Liu, M. Juuti, Y. Lu, and N. Asokan, “Oblivious Neural Network Predictions via MiniONN Transformations,” Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security - CCS ’17 , no. 2017/452, pp. 619–631, 2017
2017
Cited alongside, same era.
2017
Cited alongside, same era.
P. Mohassel and Y. Zhang, “SecureML: { }
2017
Cited alongside, same era.
2018
Later among the works it cites.
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting,” 2018 IEEE 31st Computer Security Foundations Symposium (CSF) , pp. 268–282, 2018
2018
Later among the works it cites.
A. Demontis, M. Melis, M. Pintor, M. Jagielski, B. Biggio, A. Oprea, C. Nita-Rotaru, and F. Roli, “Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks,” in Proceedings of the 28th USENIX Conference on Security Symposium , ser. SEC’19. USA: USENIX Association, 2019, pp. 321–338
2019
Later among the works it cites.
I. Hagestedt, Y. Zhang, M. Humbert, P. Berrang, H. Tang, X. Wang, and M. Backes, “MBeacon: Privacy-Preserving Beacons for DNA Methylation Data,” in Proceedings 2019 Network and Distributed System Security Symposium . San Diego, CA: Internet Society, 2019
2019
Later among the works it cites.
J. Hayes, L. Melis, G. Danezis, and E. De Cristofaro, “LOGAN: Membership inference attacks against generative models,” Proceedings on Privacy Enhancing Technologies , vol. 2019, no. 1, pp. 133–152, 2019
2019
Later among the works it cites.
R. Iyengar, J. P. Near, D. Song, O. Thakkar, A. Thakurta, and L. Wang, “Towards practical differentially private convex optimization,” in 2019 IEEE Symposium on Security and Privacy (SP) , 2019, pp. 299–316
2019
Later among the works it cites.
J. Jia, A. Salem, M. Backes, Y. Zhang, and N. Z. Gong, “MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security - CCS ’19 . London, United Kingdom: ACM Press, 2019, pp. 259–274
2019
Later among the works it cites.
L. Melis, C. Song, E. D. Cristofaro, and V. Shmatikov, “Exploiting Unintended Feature Leakage in Collaborative Learning,” in 2019 2019 IEEE Symposium on Security and Privacy (SP) . Los Alamitos, CA, USA: IEEE Computer Society, May 2019, pp. 497–512
2019
Later among the works it cites.
T. Miyato, S.-I. Maeda, M. Koyama, and S. Ishii, “Virtual Adversarial Training: A Regularization Method for Supervised and Semi-Supervised Learning,” IEEE Transactions on Pattern Analysis and Machine Intelligence , vol. 41, no. 8, pp. 1979–1993, Aug. 2019, conference Name: IEEE Transactions on Pattern Analysis and Machine Intelligence
2019
Later among the works it cites.
M. Nasr, R. Shokri, and A. Houmansadr, “Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning,” in 2019 2019 IEEE Symposium on Security and Privacy (SP) . Los Alamitos, CA, USA: IEEE Computer Society, May 2019, pp. 1021–1035
2019
Later among the works it cites.
T. Orekondy, B. Schiele, and M. Fritz, “Knockoff Nets: Stealing Functionality of Black-Box Models,” in 2019 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , Jun. 2019, pp. 4949–4958
2019
Later among the works it cites.
A. Pyrgelis, C. Troncoso, and E. De Cristofaro, “Under the Hood of Membership Inference Attacks on Aggregate Location Time-Series,” Feb. 2019
2019
Later among the works it cites.
2019
Later among the works it cites.
Z. Yang, J. Zhang, E.-C. Chang, and Z. Liang, “Neural network inversion in adversarial setting via background knowledge alignment,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’19. New York, NY, USA: Association for Computing Machinery, 2019, pp. 225–240
2019
Later among the works it cites.
L. Yu, L. Liu, C. Pu, M. Gursoy, and S. Truex, “Differentially Private Model Publishing for Deep Learning,” in 2019 2019 IEEE Symposium on Security and Privacy (SP) . Los Alamitos, CA, USA: IEEE Computer Society, May 2019, pp. 326–343
2019
Later among the works it cites.
2019
Later among the works it cites.
K. Leino and M. Fredrikson, “Stolen memories: Leveraging model memorization for calibrated white-box membership inference,” in 29th USENIX Security Symposium (USENIX Security 20) . USENIX Association, Aug. 2020
2020
Closest in time.
2020
Closest in time.
A. Salem, A. Bhattacharya, M. Backes, M. Fritz, and Y. Zhang, “Updates-leak: Data set inference and reconstruction attacks in online learning,” in 29th USENIX Security Symposium (USENIX Security 20) . Boston, MA: USENIX Association, Aug. 2020
2020
Closest in time.