Fetching the paper…
Reading the bibliography…
Membership inference attacks are one of the simplest forms of privacy leakage for machine learning models: given a data point and model, determine whether the point was used to train the model.
The sybil attack
Douceur, J. R · 2002
Earlier work this paper cites.
A systematic literature review of automated clinical coding and classification systems
Stanfill, M. H., Williams, M., Fenton, S. H., Jenders, R. A., and Hersh, W. R · 2010
Earlier work this paper cites.
The application of data mining techniques in financial fraud detection: A classification framework and an academic review of literature
Ngai, E. W., Hu, Y., Wong, Y. H., Chen, Y., and Sun, X · 2011
Earlier work this paper cites.
Machine Learning: A Probabilistic Perspective
Murphy, K. P · 2012
Earlier work this paper cites.
Rectifier nonlinearities improve neural network acoustic models
Maas, A. L., Hannun, A. Y., and Ng, A. Y · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples, 2014
Goodfellow, I. J., Shlens, J., and Szegedy, C · 2014
Earlier work this paper cites.
Understanding machine learning: From theory to algorithms
Shalev-Shwartz, S. and Ben-David, S · 2014
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
Srivastava, N., Hinton, G., Krizhevsky, A., Sutskever, I., and Salakhutdinov, R · 2014
Earlier work this paper cites.
Data augmentation for deep neural network acoustic modeling
Cui, X., Goel, V., and Kingsbury, B · 2015
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Fredrikson, M., Jha, S., and Ristenpart, T · 2015
Earlier work this paper cites.
Deep residual learning for image recognition, 2015
He, K., Zhang, X., Ren, S., and Sun, J · 2015
Earlier work this paper cites.
Character-level convolutional networks for text classification
Zhang, X., Zhao, J., and LeCun, Y · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Earlier work this paper cites.
Uncertainty in deep learning
Gal, Y · 2016
Earlier work this paper cites.
Membership inference attacks against machine learning models, 2016
Shokri, R., Stronati, M., Song, C., and Shmatikov, V · 2016
Earlier work this paper cites.
A boundary tilting persepective on the phenomenon of adversarial examples
Tanay, T. and Griffin, L · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction apis
Tramèr, F., Zhang, F., Juels, A., Reiter, M. K., and Ristenpart, T · 2016
Earlier work this paper cites.
Understanding deep learning requires rethinking generalization
Zhang, C., Bengio, S., Hardt, M., Recht, B., and Vinyals, O · 2016
Earlier work this paper cites.
Deep learning , volume 1
Bengio, Y., Goodfellow, I., and Courville, A · 2017
Cited alongside, same era.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Brendel, W., Rauber, J., and Bethge, M · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Carlini, N. and Wagner, D · 2017
Cited alongside, same era.
Improved regularization of convolutional neural networks with cutout
DeVries, T. and Taylor, G. W · 2017
Cited alongside, same era.
Towards measuring membership privacy
Long, Y., Bindschaedler, V., and Gunter, C. A · 2017
Cited alongside, same era.
Towards demystifying membership inference attacks
Truex, S., Liu, L., Gursoy, M. E., Yu, L., and Wei, W · 2018
Later among the works it cites.
Stealing hyperparameters in machine learning
Wang, B. and Gong, N. Z · 2018
Later among the works it cites.
Privacy risk in machine learning: Analyzing the connection to overfitting
Yeom, S., Giacomelli, I., Fredrikson, M., and Jha, S · 2018
Later among the works it cites.
The secret sharer: Evaluating and testing unintended memorization in neural networks
Carlini, N., Liu, C., Erlingsson, Ú., Kos, J., and Song, D · 2019
Later among the works it cites.
Hopskipjumpattack: A query-efficient decision-based attack, 2019
Chen, J., Jordan, M. I., and Wainwright, M. J · 2019
Later among the works it cites.
Adversarial examples are a natural consequence of test error in noise
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Practical black-box attacks against machine learning
Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z. B., and Swami, A · 2017
Cited alongside, same era.
The effectiveness of data augmentation in image classification using deep learning, 2017
Perez, L. and Wang, J · 2017
Cited alongside, same era.
Knock knock, who’s there? membership inference on aggregate location data
Pyrgelis, A., Troncoso, C., and De Cristofaro, E · 2017
Cited alongside, same era.
Audio adversarial examples: Targeted attacks on speech-to-text
Carlini, N. and Wagner, D · 2018
Cited alongside, same era.
Autoaugment: Learning augmentation policies from data, 2018
Cubuk, E. D., Zoph, B., Mane, D., Vasudevan, V., and Le, Q. V · 2018
Cited alongside, same era.
Bert: Pre-training of deep bidirectional transformers for language understanding, 2018
Devlin, J., Chang, M.-W., Lee, K., and Toutanova, K · 2018
Cited alongside, same era.
Understanding membership inferences on well-generalized learning models
Long, Y., Bindschaedler, V., Wang, L., Bu, D., Wang, X., Tang, H., Gunter, C. A., and Chen, K · 2018
Cited alongside, same era.
Ford, N., Gilmer, J., Carlini, N., and Cubuk, D · 2019
Later among the works it cites.
Logan: Membership inference attacks against generative models
Hayes, J., Melis, L., Danezis, G., and Cristofaro, E. D · 2019
Later among the works it cites.
A new defense against adversarial images: Turning a weakness into a strength
Hu, S., Yu, T., Guo, C., Chao, W.-L., and Weinberger, K. Q · 2019
Later among the works it cites.
Memguard: Defending against black-box membership inference attacks via adversarial examples
Jia, J., Salem, A., Backes, M., Zhang, Y., and Gong, N. Z · 2019
Later among the works it cites.
Stolen memories: Leveraging model memorization for calibrated white-box membership inference
Leino, K. and Fredrikson, M · 2019
Later among the works it cites.
White-box vs black-box: Bayes optimal strategies for membership inference
Sablayrolles, A., Douze, M., Schmid, C., Ollivier, Y., and Jégou, H · 2019
Later among the works it cites.
Multi-grade brain tumor classification using deep cnn with extensive data augmentation
Sajjad, M., Khan, S., Muhammad, K., Wu, W., Ullah, A., and Baik, S. W · 2019
Later among the works it cites.
A survey on image data augmentation for deep learning
Shorten, C. and Khoshgoftaar, T. M · 2019
Later among the works it cites.
Privacy risks of securing machine learning models against adversarial examples
Song, L., Shokri, R., and Mittal, P · 2019
Later among the works it cites.
Revisiting membership inference under realistic assumptions
Jayaraman, B., Wang, L., Evans, D., and Gu, Q · 2020
Closest in time.
Fixmatch: Simplifying semi-supervised learning with consistency and confidence, 2020
Sohn, K., Berthelot, D., Li, C.-L., Zhang, Z., Carlini, N., Cubuk, E. D., Kurakin, A., Zhang, H., and Raffel, C · 2020
Closest in time.
Defending model inversion and membership inference attacks via prediction purification, 2020
Yang, Z., Shao, B., Xuan, B., Chang, E.-C., and Zhang, F · 2020
Closest in time.
Data augmentation for low-resource neural machine translation
Fadaee, M., Bisazza, A., and Monz, C · 2090
Closest in time.