Fetching the paper…
Reading the bibliography…
Membership inference attacks are a key measure to evaluate privacy leakage in machine learning (ML) models.
A simple weight decay can improve generalization
Anders Krogh and John A Hertz · 1992
Earlier work this paper cites.
Overfitting in neural nets: Backpropagation, conjugate gradient, and early stopping
Rich Caruana, Steve Lawrence, and C Lee Giles · 2001
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith · 2006
Earlier work this paper cites.
Differential privacy: A survey of results
Cynthia Dwork · 2008
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky and Geoffrey Hinton · 2009
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Cynthia Dwork, Aaron Roth, et al · 2014
Earlier work this paper cites.
Adam: A method for stochastic optimization
Diederik P Kingma and Jimmy Ba · 2014
Earlier work this paper cites.
Dropout: a simple way to prevent neural networks from overfitting
Nitish Srivastava, Geoffrey Hinton, Alex Krizhevsky, Ilya Sutskever, and Ruslan Salakhutdinov · 2014
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart · 2015
Earlier work this paper cites.
Distilling the knowledge in a neural network
Geoffrey Hinton, Oriol Vinyals, and Jeff Dean · 2015
Earlier work this paper cites.
Very deep convolutional networks for large-scale image recognition
Karen Simonyan and Andrew Zisserman · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction apis
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart · 2016
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Earlier work this paper cites.
Semi-supervised knowledge transfer for deep learning from private training data
Nicolas Papernot, Martín Abadi, Ulfar Erlingsson, Ian Goodfellow, and Kunal Talwar · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Earlier work this paper cites.
Machine learning models that remember too much
Congzheng Song, Thomas Ristenpart, and Vitaly Shmatikov · 2017
Earlier work this paper cites.
Decision-based adversarial attacks: Reliable attacks against black-box machine learning models
Wieland Brendel, Jonas Rauber, and Matthias Bethge · 2018
Earlier work this paper cites.
Property inference attacks on fully connected neural networks using permutation invariant representations
Karan Ganju, Qi Wang, Wei Yang, Carl A Gunter, and Nikita Borisov · 2018
Cited alongside, same era.
Understanding membership inferences on well-generalized learning models
Yunhui Long, Vincent Bindschaedler, Lei Wang, Diyue Bu, Xiaofeng Wang, Haixu Tang, Carl A Gunter, and Kai Chen · 2018
Cited alongside, same era.
Learning differentially private recurrent language models
H Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang · 2018
Cited alongside, same era.
Machine learning with membership privacy using adversarial regularization
Milad Nasr, Reza Shokri, and Amir Houmansadr · 2018
Cited alongside, same era.
Scalable private learning with pate
Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Úlfar Erlingsson · 2018
Cited alongside, same era.
Thieves on sesame street! model extraction of bert-based apis
Kalpesh Krishna, Gaurav Singh Tomar, Ankur P Parikh, Nicolas Papernot, and Mohit Iyyer · 2020
Later among the works it cites.
Stolen memories: Leveraging model memorization for calibrated white-box membership inference
Klas Leino and Matt Fredrikson · 2020
Later among the works it cites.
Improving deep learning with differential privacy using gradient encoding and denoising
Milad Nasr, Reza Shokri, and Amir Houmansadr · 2020
Later among the works it cites.
Updates-leak: Data set inference and reconstruction attacks in online learning
Ahmed Salem, Apratim Bhattacharya, Michael Backes, Mario Fritz, and Yang Zhang · 2020
Later among the works it cites.
Defending model inversion and membership inference attacks via prediction purification
Ziqi Yang, Bin Shao, Bohan Xuan, Ee-Chien Chang, and Fan Zhang · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Membership inference attack against differentially private deep learning model
Md Atiqur Rahman, Tanzila Rahman, Robert Laganière, Noman Mohammed, and Yang Wang · 2018
Cited alongside, same era.
Stealing hyperparameters in machine learning
Binghui Wang and Neil Zhenqiang Gong · 2018
Cited alongside, same era.
Privacy risk in machine learning: Analyzing the connection to overfitting
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha · 2018
Cited alongside, same era.
The secret sharer: Evaluating and testing unintended memorization in neural networks
Nicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos, and Dawn Song · 2019
Cited alongside, same era.
Logan: Membership inference attacks against generative models
Jamie Hayes, Luca Melis, George Danezis, and Emiliano De Cristofaro · 2019
Cited alongside, same era.
Evaluating differentially private machine learning in practice
Bargav Jayaraman and David Evans · 2019
Cited alongside, same era.
Memguard: Defending against black-box membership inference attacks via adversarial examples
Jinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang, and Neil Zhenqiang Gong · 2019
Cited alongside, same era.
Later among the works it cites.
Overfitting, robustness, and malicious algorithms: A study of potential causes of privacy risk in machine learning
Samuel Yeom, Irene Giacomelli, Alan Menaged, Matt Fredrikson, and Somesh Jha · 2020
Later among the works it cites.
Extracting training data from large language models
Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al · 2021
Closest in time.
Label-only membership inference attacks
Christopher A Choquette Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot · 2021
Closest in time.
Stealing links from graph neural networks
Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang · 2021
Closest in time.
Practical blind membership inference attack via differential comparisons
Bo Hui, Yuchen Yang, Haolin Yuan, Philippe Burlina, Neil Zhenqiang Gong, and Yinzhi Cao · 2021
Closest in time.
Revisiting membership inference under realistic assumptions
Bargav Jayaraman, Lingxiao Wang, David Evans, and Quanquan Gu · 2021
Closest in time.
Membership inference attacks and defenses in classification models
Jiacheng Li, Ninghui Li, and Bruno Ribeiro · 2021
Closest in time.
Membership leakage in label-only exposures
Zheng Li and Yang Zhang · 2021
Closest in time.
Adversary instantiation: Lower bounds for differentially private machine learning
Milad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot, and Nicholas Carlini · 2021
Closest in time.
Tempered sigmoid activations for deep learning with differential privacy
Nicolas Papernot, Abhradeep Thakurta, Shuang Song, Steve Chien, and Úlfar Erlingsson · 2021
Closest in time.
Membership privacy for machine learning models through knowledge transfer
Virat Shejwalkar and Amir Houmansadr · 2021
Closest in time.
Systematic evaluation of privacy risks of machine learning models
Liwei Song and Prateek Mittal · 2021
Closest in time.
Differentially private learning needs better features (or much more data)
Florian Tramèr and Dan Boneh · 2021
Closest in time.