Fetching the paper…
Reading the bibliography…
Leakage of data from publicly available Machine Learning (ML) models is an area of growing significance as commercial and government applications of ML can draw on multiple sources of data, potentially including users' and clients' sensitive data.
Data Protection Directive , https://eur-lex.europa.eu/, European Parliament and Council, 1995
1995
Earlier work this paper cites.
Data Protection Act , Parliament of the UK, 1998
1998
Earlier work this paper cites.
T. G. Dietterich, “Ensemble methods in machine learning,” in First International Workshop on Multiple Classifier Systems . Springer, 2000
2000
Earlier work this paper cites.
C. Dwork, K. Kenthapadi, F. McSherry, I. Mironov, and M. Naor, “Our data, ourselves: Privacy via distributed noise generation,” in EUROCRYPT . Springer, 2006, pp. 486–503
2006
Earlier work this paper cites.
K. Nissim, “Smooth sensitivity and sampling in private data analysis,” in STOC . ACM, 2007, pp. 75–84
2007
Earlier work this paper cites.
C. Dwork, “Differential privacy: A survey of results,” in Theory and Applications of Models of Computation . Springer, 2008
2008
Earlier work this paper cites.
A. B. Tsybakov, Introduction to Nonparametric Estimation . Springer, 2008
2008
Earlier work this paper cites.
Statistical Disclosure Control Protocol , NHS National Services Scotland, 2009
2009
Earlier work this paper cites.
C. Gentry, “A fully homomorphic encryption scheme,” Ph.D. dissertation, Stanford University, 2009, crypto.stanford.edu/craig
2009
Earlier work this paper cites.
K. Chaudhuri, C. Monteleoni, and A. D. Sarwate, “Differentially private empirical risk minimization,” J. Mach. Learn. Res. , vol. 12, pp. 1069–1109, 2011
2011
Earlier work this paper cites.
M. Naehrig, K. Lauter, and V. Vaikuntanathan, “Can homomorphic encryption be practical?” ACM, 2011
2011
Earlier work this paper cites.
P. Jain, P. Kothari, and A. Thakurta, “Differentially private online learning,” in COLT , 2012
2012
Earlier work this paper cites.
Anonymisation: managing data protection risk code of practice , https://ico.org.uk, ICO: Information Commissioner’s Office, 2012
2012
Earlier work this paper cites.
G. Ateniese, G. Felici, L. Mancini, A. Spognardi, A. Villani, and D. Vitali, “Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers,” International Journal of Security and Networks , vol. 10, 06 2013
2013
Earlier work this paper cites.
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus, “Intriguing properties of neural networks,” ArXiv , 2013
2013
Earlier work this paper cites.
A. Thakurta and A. D. Smith, “(Nearly) Optimal Algorithms for Private Online Learning in Full-information and Bandit Settings,” in NeurIPS , 2013
2013
Earlier work this paper cites.
S. Song, K. Chaudhuri, and A. D. Sarwate, “Stochastic gradient descent with differentially private updates,” in IEEE GlobalSIP . IEEE, 2013, pp. 245–248
2013
Earlier work this paper cites.
R. Johnson and T. Zhang, “Accelerating stochastic gradient descent using predictive variance reduction,” 2013
2013
Earlier work this paper cites.
M. Fredrikson, E. Lantz, S. Jha, S. M. Lin, D. Page, and T. Ristenpart, “Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing,” in USENIX , 2014, pp. 17–32
2014
Earlier work this paper cites.
C. Dwork and A. Roth, “The algorithmic foundations of differential privacy,” Found. Trends Theor. Comput. Sci. , vol. 9, pp. 211–407, 2014
2014
Earlier work this paper cites.
Z. Ji, Z. C. Lipton, and C. Elkan, “Differential privacy and machine learning: a survey and review,” ArXiv , 2014
2014
Earlier work this paper cites.
R. Bassily, A. D. Smith, and A. Thakurta, “Private empirical risk minimization: Efficient algorithms and tight error bounds,” in IEEE Symposium on Foundations of Computer Science, FOCS . IEEE, 2014, pp. 464–473
2014
Earlier work this paper cites.
R. Balu, T. Furon, and S. Gambs, “Challenging differential privacy:the case of non-interactive mechanisms,” in ESORICS . Springer, 2014, pp. 146–164
2014
Earlier work this paper cites.
F. Schroff, D. Kalenichenko, and J. Philbin, “FaceNet: A unified embedding for face recognition and clustering,” in IEEE/CVF CVPR . IEEE, 2015, pp. 815–823
2015
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in SIGSAC . ACM, 2015
2015
Earlier work this paper cites.
G. Hinton, O. Vinyals, and J. Dean, “Distilling the knowledge in a neural network,” in NIPS Deep Learning and Representation Learning Workshop , 2015
2015
Earlier work this paper cites.
Y. Cao and J. Yang, “Towards making systems forget with machine unlearning,” in IEEE SSP . IEEE, 2015
2015
Earlier work this paper cites.
M. Abadi, A. Agarwal, P. Barham, E. Brevdo, Z. Chen, C. Citro, G. Corrado, and A. D. et al., “Tensorflow: Large-scale machine learning on heterogeneous distributed systems,” 2015. [Online]. Available: http://download.tensorflow.org/
2015
Earlier work this paper cites.
A. Neelakantan, L. Vilnis, Q. V. Le, I. Sutskever, L. Kaiser, K. Kurach, and J. Martens, “Adding gradient noise improves learning for very deep networks,” CoRR , 2015
2015
Earlier work this paper cites.
R. Shokri and V. Shmatikov, “Privacy-preserving deep learning,” in 53rd Annual Allerton Conference on Communication, Control, and Computing . IEEE, 2015
2015
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction APIs,” in USENIX , 2016, pp. 601–618
2016
Earlier work this paper cites.
X. Wu, M. Fredrikson, S. Jha, and J. F. Naughton, “A methodology for formalizing model-inversion attacks,” in IEEE CSF , 2016, pp. 355–370
2016
Earlier work this paper cites.
P. Tambe and D. Vora, “Data sanitization for privacy preservation on social network,” ICACDOT , pp. 972–976, 2016
2016
Earlier work this paper cites.
N. Papernot, P. McDaniel, X. Wu, S. Jha, and A. Swami, “Distillation as a defense to adversarial perturbations against deep neural networks,” in IEEE SSP . IEEE, 2016, pp. 582–597
2016
Earlier work this paper cites.
N. Papernot and P. McDaniel, “On the effectiveness of defensive distillation,” ArXiv , 2016
2016
Earlier work this paper cites.
C. Dwork and G. N. Rothblum, “Concentrated differential privacy,” CoRR , 2016
2016
Earlier work this paper cites.
M. Bun and T. Steinke, “Concentrated differential privacy: Simplifications, extensions, and lower bounds,” ArXiv , 2016
2016
Earlier work this paper cites.
M. Abadi, A. Chu, I. J. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” SIGSAC , 2016
2016
Earlier work this paper cites.
J. Hamm, Y. Cao, and M. Belkin, “Learning privately from multiparty data,” in ICML , ser. JMLR Workshop and Conference Proceedings, vol. 48. JMLR, 2016
2016
Earlier work this paper cites.
C. Dwork, F. McSherry, K. Nissim, and A. D. Smith, “Calibrating noise to sensitivity in private data analysis,” J. Priv. Confidentiality , vol. 7, 2016
2016
Earlier work this paper cites.
J. Konecný, H. B. McMahan, D. Ramage, and P. Richtárik, “Federated optimization: Distributed machine learning for on-device intelligence,” CoRR , 2016
2016
Earlier work this paper cites.
J. Konecný, H. B. McMahan, F. X. Yu, P. Richtárik, A. T. Suresh, and D. Bacon, “Federated learning: Strategies for improving communication efficiency,” CoRR , 2016
2016
Earlier work this paper cites.
H. B. McMahan, E. Moore, D. Ramage, and B. A. Arcas, “Federated learning of deep networks using model averaging,” CoRR , 2016
2016
Earlier work this paper cites.
The EU General Data Protection Regulation 2016/679 (GDPR): Recital 26 , Parliament of the EU, 2016
2016
Earlier work this paper cites.
C. Zhang, S. Bengio, M. Hardt, B. Recht, and O. Vinyals, “Understanding deep learning requires rethinking generalization,” in ICLR , 2017
2017
Earlier work this paper cites.
S. Yeom, M. Fredrikson, and S. Jha, “The unintended consequences of overfitting: Training data inference attacks,” CoRR , 2017
2017
Earlier work this paper cites.
C. Song, T. Ristenpart, and V. Shmatikov, “Machine learning models that remember too much,” in SIGSAC . ACM, 2017, pp. 587–601
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership Inference Attacks Against Machine Learning Models,” in IEEE SSP , 2017, pp. 3–18
2017
Earlier work this paper cites.
B. Hitaj, G. Ateniese, and F. Pérez-Cruz, “Deep models under the GAN: information leakage from collaborative deep learning,” in SIGSAC . ACM, 2017
2017
Earlier work this paper cites.
J. Hayes, L. Melis, G. Danezis, and E. De Cristofaro, “LOGAN: evaluating privacy leakage of generative models using generative adversarial networks,” 2017
2017
Earlier work this paper cites.
Y. Long, V. Bindschaedler, and C. A. Gunter, “Towards measuring membership privacy,” ArXiv , 2017
2017
Earlier work this paper cites.
A. Pyrgelis, C. Troncoso, and E. D. Cristofaro, “Knock knock, who’s there? Membership inference on aggregate location data,” CoRR , 2017
2017
Earlier work this paper cites.
P. Voigt and A. v. d. Bussche, The EU General Data Protection Regulation: A Practical Guide . Springer, 2017
2017
Earlier work this paper cites.
F. Yang, A. Kale, Y. Bubnov, L. Stein, Q. Wang, H. Kiapour, and R. Piramuthu, “Visual search at ebay,” ser. KDD ’17. ACM, 2017, p. 2101–2110
2017
Earlier work this paper cites.
G. Litjens, T. Kooi, B. E. Bejnordi, A. A. A. Setio, F. Ciompi, M. Ghafoorian, J. A. van der Laak, B. van Ginneken, and C. I. Sánchez, “A survey on deep learning in medical image analysis,” Medical Image Analysis , vol. 42, pp. 60–88, 2017
2017
Earlier work this paper cites.
N. Papernot, P. McDaniel, I. J. Goodfellow, S. Jha, Z. Y. Celik, and A. Swami, “Practical black-box attacks against machine learning,” ACM on Asia Conference on Computer and Communications Security , 2017
2017
Earlier work this paper cites.
S. Hidano, T. Murakami, S. Katsumata, S. Kiyomoto, and G. Hanaoka, “Model inversion attacks for prediction systems: Without knowledge of non-sensitive attributes,” in Conference on Privacy, Security and Trust (PST) , 2017
2017
Earlier work this paper cites.
D. Dua and C. Graff, “UCI machine learning repository,” 2017. [Online]. Available: http://archive.ics.uci.edu/ml
2017
Earlier work this paper cites.
M. Zaheer, S. Kottur, S. Ravanbakhsh, B. Póczos, R. R. Salakhutdinov, and A. J. Smola, “Deep sets,” in NIPS , 2017
2017
Earlier work this paper cites.
A. K. Zaman, C. Obimbo, and R. A. Dara, “An improved data sanitization algorithm for privacy preserving medical data publishing,” in Canadian Conference on AI , 2017
2017
Earlier work this paper cites.
B. Mirzasoleiman, A. Karbasi, and A. Krause, “Deletion-robust submodular maximization: Data summarization with ”the right to be forgotten”,” in ICML , vol. 70. PMLR, 2017, pp. 2449–2458
2017
Earlier work this paper cites.
P. W. Koh and P. Liang, “Understanding black-box predictions via influence functions,” CoRR , 2017
2017
Earlier work this paper cites.
J. Liu, M. Juuti, Y. Lu, and N. Asokan, “Oblivious neural network predictions via MiniONN transformations,” SIGSAC , 2017
2017
Earlier work this paper cites.
N. Carlini and D. Wagner, “Towards evaluating the robustness of neural networks,” in IEEE SSP , 2017
2017
Earlier work this paper cites.
I. Mironov, “Rényi differential privacy,” IEEE CSF , pp. 263–275, 2017
2017
Earlier work this paper cites.
N. Agarwal and K. Singh, “The price of differential privacy for online learning,” in ICML . PMLR, 2017
2017
Earlier work this paper cites.
D. Wang, M. Ye, and J. Xu, “Differentially private empirical risk minimization revisited: Faster and more general,” in NeurIPS , 2017, pp. 2722–2731
2017
Earlier work this paper cites.
H. B. McMahan, D. Ramage, K. Talwar, and L. Zhang, “Learning differentially private language models without losing accuracy,” CoRR , 2017
2017
Earlier work this paper cites.
M. Abadi, Ú. Erlingsson, I. J. Goodfellow, H. B. McMahan, I. Mironov, N. Papernot, K. Talwar, and L. Zhang, “On the protection of private information in machine learning systems: Two recent approaches,” in IEEE Computer Security Foundations Symposium . IEEE, 2017
2017
Earlier work this paper cites.
N. Papernot, M. Abadi, Ú. Erlingsson, I. J. Goodfellow, and K. Talwar, “Semi-supervised knowledge transfer for deep learning from private training data,” ArXiv , 2017
2017
Earlier work this paper cites.
J. Jälkö, A. Honkela, and O. Dikmen, “Differentially private variational inference for non-conjugate models,” in Conference on Uncertainty in Artificial Intelligence . AUAI Press, 2017
2017
Earlier work this paper cites.
X. Wu, F. Li, A. Kumar, K. Chaudhuri, S. Jha, and J. F. Naughton, “Bolt-on differential privacy for scalable stochastic gradient descent-based analytics,” in SIGMOD . ACM, 2017, pp. 1307–1322
2017
Earlier work this paper cites.
J. Lee, “Differentially private variance reduced stochastic gradient descent,” International Conference on New Trends in Computing Sciences , pp. 161–166, 2017
2017
Earlier work this paper cites.
N. Papernot, M. Abadi, Ú. Erlingsson, I. J. Goodfellow, and K. Talwar, “Semi-supervised knowledge transfer for deep learning from private training data,” in ICLR , 2017
2017
Earlier work this paper cites.
A. Bellet, R. Guerraoui, M. Taziki, and M. Tommasi, “Fast and differentially private algorithms for decentralized collaborative machine learning,” CoRR , 2017
2017
Earlier work this paper cites.
M. A. Heikkilä, E. Lagerspetz, S. Kaski, K. Shimizu, S. Tarkoma, and A. Honkela, “Differentially private bayesian learning on distributed data,” in NeurIPS , 2017, pp. 3226–3235
2017
Earlier work this paper cites.
K. Bonawitz, V. Ivanov, B. Kreuter, A. Marcedone, H. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth, “Practical secure aggregation for privacy-preserving machine learning,” SIGSAC , 2017
2017
Cited alongside, same era.
R. Berk, H. Heidari, S. Jabbari, M. Joseph, M. Kearns, J. Morgenstern, S. Neel, and A. Roth, “A convex framework for fair regression,” ArXiv , 2017
2017
Cited alongside, same era.
V. Bindschaedler, R. Shokri, and C. A. Gunter, “Plausible deniability for privacy-preserving data synthesis,” Proc. VLDB Endow. , vol. 10, p. 481–492, 2017
2017
Cited alongside, same era.
B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning,” Pattern Recognit. , vol. 84, pp. 317–331, 2018
2018
Cited alongside, same era.
N. Papernot, P. McDaniel, A. Sinha, and M. P. Wellman, “SoK: Security and privacy in machine learning,” in IEEE EuroSP , 2018, pp. 399–414
R. Giordano, W. T. Stephenson, R. Liu, M. I. Jordan, and T. Broderick, “A Swiss Army Infinitesimal Jackknife,” in AISTATS , vol. 89. PMLR, 2019, pp. 1139–47
2019
Later among the works it cites.
C. Guo, T. Goldstein, A. Y. Hannun, and L. van der Maaten, “Certified data removal from machine learning models,” CoRR , 2019
2019
Later among the works it cites.
A. Golatkar, A. Achille, and S. Soatto, “Eternal Sunshine of the Spotless Net: Selective Forgetting in Deep Networks,” ArXiv , 2019
2019
Later among the works it cites.
M. Ellers, M. Cochez, T. Schumacher, M. Strohmaier, and F. Lemmerich, “Privacy attacks on network embeddings,” CoRR , 2019
2019
Later among the works it cites.
C. Song and V. Shmatikov, “Auditing data provenance in text-generation models,” ser. KDD ’19. ACM, 2019
2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
S. Chang and C. Li, “Privacy in neural network learning: Threats and countermeasures,” IEEE Network , vol. 32, pp. 61–67, 2018
2018
Cited alongside, same era.
M. Ozdag, “Adversarial attacks and defenses against deep neural networks: A survey,” Procedia Computer Science , vol. 140, pp. 152–161, 2018
2018
Cited alongside, same era.
A. Chakraborty, M. Alam, V. Dey, A. Chattopadhyay, and D. Mukhopadhyay, “Adversarial attacks and defences: A survey,” CoRR , 2018
2018
Cited alongside, same era.
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy risk in machine learning: Analyzing the connection to overfitting,” in IEEE Computer Security Foundations Symposium . IEEE, 2018, pp. 268–282
2018
Cited alongside, same era.
Y. Long, V. Bindschaedler, L. Wang, D. Bu, X. Wang, H. Tang, C. A. Gunter, and K. Chen, “Understanding membership inferences on well-generalized learning models,” arXiv , 2018
2018
Cited alongside, same era.
A. Sablayrolles, M. Douze, C. Schmid, and H. Jégou, “Déjà Vu: an empirical evaluation of the memorization properties of ConvNets,” CoRR , 2018
2018
Cited alongside, same era.
Y. Kim, M. Kim, and G. Kim, “Memorization precedes generation: Learning unsupervised GANs with memory networks,” CoRR , 2018
2018
Cited alongside, same era.
V. Shejwalkar and A. Houmansadr, “Reconciling utility and membership privacy via knowledge distillation,” ArXiv , 2019
2019
Later among the works it cites.
Y. Wang, D. Kifer, and J. Lee, “Differentially private confidence intervals for empirical risk minimization,” J. Priv. Confidentiality , vol. 9, 2019
2019
Later among the works it cites.
D. Wang and J. Xu, “Differentially private empirical risk minimization with smooth non-convex loss functions: A non-stationary view,” in AAAI Conference on Artificial Intelligence . AAAI Press, 2019, pp. 1182–89
2019
Later among the works it cites.
K. S. S. Kumar and M. P. Deisenroth, “Differentially private empirical risk minimization with sparsity-inducing norms,” CoRR , 2019
2019
Later among the works it cites.
B. Jayaraman and D. Evans, “When relaxations go bad: ”differentially-private” machine learning,” ArXiv , 2019
2019
Later among the works it cites.
Y. Long, S. Lin, Z. Yang, C. A. Gunter, and B. Li, “Scalable Differentially Private Generative Student Model via PATE,” ArXiv , 2019
2019
Later among the works it cites.
J. Jordon, J. Yoon, and M. Schaar, “Pate-gan: Generating synthetic data with differential privacy guarantees,” in ICLR , 2019
2019
Later among the works it cites.
Q. Yang, Y. Liu, T. Chen, and Y. Tong, “Federated machine learning: Concept and applications,” arXiv: Artificial Intelligence , 2019
2019
Later among the works it cites.
T. Li, A. K. Sahu, A. Talwalkar, and V. Smith, “Federated learning: Challenges, methods, and future directions,” CoRR , 2019
2019
Later among the works it cites.
P. Kairouz, H. B. McMahan, B. Avent, A. Bellet, and M. Bennis, “Advances and open problems in federated learning,” CoRR , 2019
2019
Later among the works it cites.
Q. Li, Z. Wen, and B. He, “Federated learning systems: Vision, hype and reality for data privacy and protection,” CoRR , 2019
2019
Later among the works it cites.
K. Cheng, T. Fan, Y. Jin, Y. Liu, T. Chen, and Q. Yang, “SecureBoost: A lossless federated learning framework,” CoRR , 2019
2019
Later among the works it cites.
A. Jalalirad, M. Scavuzzo, C. Capota, and M. Sprague, “A simple and efficient federated recommender system,” ser. BDCAT ’19. ACM, 2019, p. 53–58
2019
Later among the works it cites.
M. Ammad-ud-din, E. Ivannikova, S. A. Khan, W. Oyomno, Q. Fu, K. E. Tan, and A. Flanagan, “Federated collaborative filtering for privacy-preserving personalized recommendation system,” CoRR , 2019
2019
Later among the works it cites.
L. Phong and T. T. Phuong, “Privacy-preserving deep learning via weight transmission,” IEEE Trans on Information Forensics and Security , vol. 14, 2019
2019
Later among the works it cites.
L. Lyu, J. Yu, K. Nandakumar, Y. Li, X. Ma, and J. Jin, “Towards fair and decentralized privacy-preserving deep learning with blockchain,” ArXiv , 2019
2019
Later among the works it cites.
L. Huang and N. K. Vishnoi, “Stable and fair classification,” arXiv preprint arXiv:1902.07823 , 2019
2019
Later among the works it cites.
Pseudonymisation techniques and best practices , https://www.enisa.europa.eu/, EUAC, 2019
2019
Later among the works it cites.
E. De Cristofaro, “An overview of privacy in machine learning,” arXiv , 05 2020
2020
Later among the works it cites.
M. Rigaki and S. Garcia, “A survey of privacy attacks in machine learning,” arXiv , 07 2020
2020
Later among the works it cites.
J. Zhang, C. Li, J. Ye, and G. Qu, “Privacy threats and protection in machine learning,” 2020 Great Lakes Symposium on VLSI , 2020
2020
Later among the works it cites.
K. Ren, T. Zheng, Z. Qin, and X. Liu, “Adversarial attacks and defenses in deep learning,” Engineering , vol. 6, pp. 346–360, 2020
2020
Later among the works it cites.
C. Song and V. Shmatikov, “Overlearning reveals sensitive attributes,” ArXiv , 2020
2020
Later among the works it cites.
S. Hisamoto, M. Post, and K. Duh, “Membership inference attacks on sequence-to-sequence models: Is my data in your machine translation system?” Trans of the Association for Computational Linguistics , vol. 8, pp. 49–63, 2020
2020
Later among the works it cites.
M. Jagielski, N. Carlini, D. Berthelot, A. Kurakin, and N. Papernot, “High accuracy and high fidelity extraction of neural networks,” in USENIX , 2020
2020
Later among the works it cites.
V. Chandrasekaran, K. Chaudhuri, I. Giacomelli, S. Jha, and S. Yan, “Exploring connections between active learning and model extraction,” in USENIX , 2020, pp. 1309–1326
2020
Later among the works it cites.
K. Krishna, G. S. Tomar, A. P. Parikh, N. Papernot, and M. Iyyer, “Thieves on Sesame Street! model extraction of BERT-based APIs,” ArXiv , 2020
2020
Later among the works it cites.
E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov, “How to backdoor federated learning,” in International Conference on Artificial Intelligence and Statistics . PMLR, 2020, pp. 2938–2948
2020
Later among the works it cites.
F. Suya, S. Mahloujifar, A. Suri, D. Evans, and Y. Tian, “Model-targeted poisoning attacks with provable convergence,” ArXiv , 2020
2020
Later among the works it cites.
Y. Zhang, R. Jia, H. Pei, W. Wang, B. Li, and D. Song, “The secret revealer: Generative model-inversion attacks against deep neural networks,” in IEEE/CVF CVPR , 2020, pp. 250–258
2020
Later among the works it cites.
A. Salem, A. Bhattacharyya, M. Backes, M. Fritz, and Y. Zhang, “Updates-leak: Data set inference and reconstruction attacks in online learning,” ArXiv , 2020
2020
Later among the works it cites.
Z. Yang, B. Shao, B. Xuan, E. Chang, and F. Zhang, “Defending model inversion and membership inference attacks via prediction purification,” CoRR , 2020
2020
Later among the works it cites.
P. Vepakomma, A. Singh, O. Gupta, and R. Raskar, “NoPeek: information leakage reduction to share activations in distributed deep learning,” in ICDM Workshops . IEEE, 2020, pp. 933–942
2020
Later among the works it cites.
Y. Zhang, R. Jia, H. Pei, W. Wang, B. Li, and D. Song, “The secret revealer: Generative model-inversion attacks against deep neural networks,” IEEE/CVF CVPR , pp. 250–258, 2020
2020
Later among the works it cites.
A. Tucker, Z. Wang, Y. Rotalinti, and P. Myles, “Generating high-fidelity synthetic patient data for assessing machine learning healthcare software,” NPJ Digital Medicine , vol. 3, 2020
2020
Later among the works it cites.
T. Stadler, B. Oprisanu, and C. Troncoso, “Synthetic data - A privacy mirage,” CoRR , 2020
2020
Later among the works it cites.
K. Leino and M. Fredrikson, “Stolen memories: Leveraging model memorization for calibrated white-box membership inference,” ArXiv , 2020
2020
Later among the works it cites.
S. Yeom, I. Giacomelli, A. Menaged, M. Fredrikson, and S. Jha, “Overfitting, robustness, and malicious algorithms: A study of potential causes of privacy risk in machine learning,” J. Comput. Secur. , vol. 28, 2020
2020
Later among the works it cites.
M. Chen, Z. Zhang, T. Wang, M. Backes, M. Humbert, and Y. Zhang, “When machine unlearning jeopardizes privacy,” CoRR , 2020
2020
Later among the works it cites.
J. W. Bentley, D. Gibney, G. Hoppenworth, and S. K. Jha, “Quantifying Membership Inference Vulnerability via Generalization Gap and Other Model Metrics,” 2020
2020
Later among the works it cites.
C. Wang, G. Liu, H. Huang, W. Feng, K. Peng, and L. Wang, “MIASec: Enabling data indistinguishability against membership inference attacks in MLaaS,” IEEE Trans on Sustainable Computing , vol. 5, pp. 365–376, 2020
2020
Later among the works it cites.
Z. Yang, B. Shao, B. Xuan, E.-C. Chang, and F. Zhang, “Defending model inversion and membership inference attacks via prediction purification,” ArXiv , 2020
2020
Later among the works it cites.
Z. Izzo, M. A. Smart, K. Chaudhuri, and J. Y. Zou, “Approximate data deletion from machine learning models: Algorithms and evaluations,” CoRR , 2020
2020
Later among the works it cites.
T. Baumhauer, P. Schöttle, and M. Zeppelzauer, “Machine unlearning: Linear filtration for logit-based classifiers,” CoRR , 2020
2020
Later among the works it cites.
A. Golatkar, A. Achille, and S. Soatto, “Forgetting outside the box: Scrubbing deep networks of information accessible from input-output observations,” ECCV , vol. 12374, pp. 383–398, 2020
2020
Later among the works it cites.
S. Garg, S. Goldwasser, and P. N. Vasudevan, “Formalizing data deletion in the context of the right to be forgotten,” in EUROCRYPT . Springer, 2020
2020
Later among the works it cites.
X. Liu and S. A. Tsaftaris, “Have you forgotten? A method to assess if machine learning models have forgotten data,” MICCAI , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
G. Kaissis, M. Makowski, D. Rückert, and R. Braren, “Secure, privacy-preserving and federated machine learning in medical imaging,” Nature Machine Intelligence , vol. 2, pp. 305–311, 2020
2020
Later among the works it cites.
S. Smith, E. Elsen, and S. De, “On the generalization benefit of noise in stochastic gradient descent,” in ICML , vol. 119, 2020, pp. 9058–9067
2020
Later among the works it cites.
L. Lyu, H. Yu, and Q. Yang, “Threats to federated learning: A survey,” CoRR , 2020
2020
Later among the works it cites.
M. Song, Z. Wang, Z. Zhang, Y. Song, Q. Wang, J. Ren, and H. Qi, “Analyzing user-level privacy attack against federated learning,” IEEE Journal on Selected Areas in Communications , vol. 38, pp. 2430–2444, 2020
2020
Later among the works it cites.
Y. Liu, Y. Kang, C. Xing, T. Chen, and Q. Yang, “A secure federated transfer learning framework,” IEEE Intelligent Systems , vol. 35, pp. 70–82, 2020
2020
Later among the works it cites.
C. Zhang, S. Li, J. Xia, W. Wang, F. Yan, Y. Liu, and et al., “BatchCrypt: Efficient homomorphic encryption for cross-silo federated learning,” in USENIX , 2020
2020
Later among the works it cites.
N. Kaaniche, M. Laurent, and S. Belguith, “Privacy enhancing technologies for solving the privacy-personalization paradox: Taxonomy and survey,” J. of Network and Comp. App. , vol. 171, 2020
2020
Later among the works it cites.
M. Park, J. R. Foulds, K. Chaudhuri, and M. Welling, “Variational Bayes In Private Settings (VIPS),” J. Artif. Intell. Res. , vol. 68, pp. 109–157, 2020
2020
Later among the works it cites.
M. Finck and F. Pallas, “They who must not be identified—distinguishing personal from non-personal data under the GDPR,” International Data Privacy Law , vol. 10, pp. 11–36, 2020
2020
Later among the works it cites.
M. Chase, E. Ghosh, and S. Mahloujifar, “Property inference from poisoning,” ArXiv , 2021
2021
Closest in time.
T. Titcombe, A. J. Hall, P. Papadopoulos, and D. Romanini, “Practical defences against model inversion attacks for split neural networks,” ArXiv , 2021
2021
Closest in time.
G. Kaissis, A. Ziller, J. Passerat-Palmbach, T. Ryffel, D. Usynin, A. Trask, I. Lima, J. Mancuso, F. Jungmann, M.-M. Steinborn, A. Saleh, M. Makowski, D. Rueckert, and R. Braren, “End-to-end privacy preserving deep learning on multi-institutional medical imaging,” Nature Machine Intelligence , 2021
2021
Closest in time.
R. Shokri, M. Strobel, and Y. Zick, “On the privacy risks of model explanations,” in AIES ’21: AAAI/ACM , M. Fourcade, B. Kuipers, S. Lazar, and D. K. Mulligan, Eds. ACM, 2021, pp. 231–241
2021
Closest in time.
L. Song and P. Mittal, “Systematic evaluation of privacy risks of machine learning models,” in USENIX Security Symposium , M. Bailey and R. Greenstadt, Eds., 2021, pp. 2615–2632
2021
Closest in time.
H. Hu, Z. Salcic, G. Dobbie, and X. Zhang, “Membership inference attacks on machine learning: A survey,” 2021
2021
Closest in time.
S. Mukherjee, Y. Xu, A. Trivedi, N. Patowary, and J. L. Ferres, “privGAN: Protecting GANs from membership inference attacks at low cost to utility,” Proc. Priv. Enhancing Technol. , 2021
2021
Closest in time.
J. Li, N. Li, and B. Ribeiro, “Membership inference attacks and defenses in classification models,” in CODASPY , A. Joshi, B. Carminati, and R. M. Verma, Eds. ACM, 2021, pp. 5–16
2021
Closest in time.
L. Hanzlik, Y. Zhang, K. Grosse, A. Salem, M. Augustin, M. Backes, and M. Fritz, “Mlcapsule: Guarded offline deployment of machine learning as a service,” in IEEE CVPR , 2021
2021
Closest in time.
R. Izmailov, P. Lin, C. Mesterharm, and S. Basu, “Privacy leakage avoidance with switching ensembles,” in IEEE MILCOM , 2021, pp. 981–986
2021
Closest in time.
H. Harutyunyan, A. Achille, G. Paolini, O. Majumder, A. Ravichandran, R. Bhotika, and S. Soatto, “Estimating informativeness of samples with smooth unique information,” in ICLR , 2021
2021
Closest in time.
Y.-Y. Yang and K. Chaudhuri, “Understanding rare spurious correlations in neural networks,” arXiv , 2022
2022
Closest in time.
J. Hartley and S. A. Tsaftaris, “Measuring unintended memorisation of unique private features in neural networks,” arXiv , 2022
2022
Closest in time.
Y. Yin, K. Chen, L. Shou, and G. Chen, “Defending privacy against more knowledgeable membership inference attackers,” in SIGKDD , F. Zhu, B. C. Ooi, and C. Miao, Eds. ACM, 2021, pp. 2026–2036
2036
Closest in time.