Fetching the paper…
Reading the bibliography…
A membership inference attack allows an adversary to query a trained machine learning model to predict whether or not a particular example was contained in the model's training dataset.
On the problem of the most efficient tests of statistical hypotheses
Jerzy Neyman and Egon Sharpe Pearson · 1933
Earlier work this paper cites.
Increased rates of convergence through learning rate adaptation
Robert A Jacobs · 1988
Earlier work this paper cites.
A simple weight decay can improve generalization
Anders Krogh and John A Hertz · 1992
Earlier work this paper cites.
Gradient-based learning applied to document recognition
Yann LeCun, Léon Bottou, Yoshua Bengio, and Patrick Haffner · 1998
Earlier work this paper cites.
SpamCop: A spam classification & organization program
Patrick Pantel and Dekang Lin · 1998
Earlier work this paper cites.
The art of data augmentation
David A Van Dyk and Xiao-Li Meng · 2001
Earlier work this paper cites.
A comparative study of anomaly detection schemes in network intrusion detection
Aleksandar Lazarevic, Levent Ertoz, Vipin Kumar, Aysel Ozgur, and Jaideep Srivastava · 2003
Earlier work this paper cites.
Learning to detect and classify malicious executables in the wild
Zico Kolter and Marcus A Maloof · 2006
Earlier work this paper cites.
Spam filtering with naive Bayes–which naive Bayes?
Vangelis Metsis, Ion Androutsopoulos, and Georgios Paliouras · 2006
Earlier work this paper cites.
Resolving individuals contributing trace amounts of dna to highly complex mixtures using high-density snp genotyping microarrays
Nils Homer, Szabolcs Szelinger, Margot Redman, David Duggan, Waibhav Tembe, Jill Muehling, John V Pearson, Dietrich A Stephan, Stanley F Nelson, and David W Craig · 2008
Earlier work this paper cites.
ImageNet: A large-scale hierarchical image database
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images, 2009
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
Genomic privacy and limits of individual detection in a pool
Sriram Sankararaman, Guillaume Obozinski, Michael I Jordan, and Eran Halperin · 2009
Earlier work this paper cites.
Stochastic gradient descent with differentially private updates
Shuang Song, Kamalika Chaudhuri, and Anand D Sarwate · 2013
Earlier work this paper cites.
The algorithmic foundations of differential privacy
Cynthia Dwork and Aaron Roth · 2014
Earlier work this paper cites.
Robust traceability from trace amounts
Cynthia Dwork, Adam Smith, Thomas Steinke, Jonathan Ullman, and Salil Vadhan · 2015
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart · 2015
Earlier work this paper cites.
Deep residual learning for image recognition, 2015
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2015
Earlier work this paper cites.
Better malware ground truth: Techniques for weighting anti-virus vendor labels
Alex Kantchelian, Michael Carl Tschantz, Sadia Afroz, Brad Miller, Vaishaal Shankar, Rekha Bachwani, Anthony D Joseph, and J Doug Tygar · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang · 2016
Earlier work this paper cites.
SGDR: Stochastic gradient descent with warm restarts
Ilya Loshchilov and Frank Hutter · 2016
Earlier work this paper cites.
Pointer sentinel mixture models
Stephen Merity, Caiming Xiong, James Bradbury, and Richard Socher · 2016
Earlier work this paper cites.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Exposed! a survey of attacks on private data
Cynthia Dwork, Adam Smith, Thomas Steinke, and Jonathan Ullman · 2017
Earlier work this paper cites.
Dermatologist-level classification of skin cancer with deep neural networks
Andre Esteva, Brett Kuprel, Roberto A Novoa, Justin Ko, Susan M Swetter, Helen M Blau, and Sebastian Thrun · 2017
Cited alongside, same era.
Detecting credential spearphishing in enterprise settings
Grant Ho, Aashish Sharma, Mobin Javed, Vern Paxson, and David Wagner · 2017
Cited alongside, same era.
Towards measuring membership privacy
Yunhui Long, Vincent Bindschaedler, and Carl A Gunter · 2017
Cited alongside, same era.
Knock knock, who’s there? membership inference on aggregate location data
Apostolos Pyrgelis, Carmela Troncoso, and Emiliano De Cristofaro · 2017
Cited alongside, same era.
Autoaugment: Learning augmentation policies from data, 2018
Ekin D. Cubuk, Barret Zoph, Dandelion Mane, Vijay Vasudevan, and Quoc V. Le · 2018
Cited alongside, same era.
Does learning require memorization? a short tale about a long tail
Vitaly Feldman · 2020
Later among the works it cites.
What neural networks memorize and why: Discovering the long tail via influence estimation
Vitaly Feldman and Chiyuan Zhang · 2020
Later among the works it cites.
Auditing differentially private machine learning: How private is private SGD?
Matthew Jagielski, Jonathan Ullman, and Alina Oprea · 2020
Later among the works it cites.
Membership leakage in label-only exposures
Zheng Li and Yang Zhang · 2020
Later among the works it cites.
A pragmatic approach to membership inferences on machine learning models
Yunhui Long, Lei Wang, Diyue Bu, Vincent Bindschaedler, Xiaofeng Wang, Haixu Tang, Carl A Gunter, and Kai Chen · 2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
CINIC-10 is not Imagenet or CIFAR-10
Luke N Darlow, Elliot J Crowley, Antreas Antoniou, and Amos J Storkey · 2018
Cited alongside, same era.
Property inference attacks on fully connected neural networks using permutation invariant representations
Karan Ganju, Qi Wang, Wei Yang, Carl A Gunter, and Nikita Borisov · 2018
Cited alongside, same era.
Machine learning with membership privacy using adversarial regularization
Milad Nasr, Reza Shokri, and Amir Houmansadr · 2018
Cited alongside, same era.
Scalable private learning with PATE
Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Úlfar Erlingsson · 2018
Cited alongside, same era.
Membership inference attack against differentially private deep learning model
Md Atiqur Rahman, Tanzila Rahman, Robert Laganière, Noman Mohammed, and Yang Wang · 2018
Cited alongside, same era.
ML-Leaks: Model and data independent membership inference attacks and defenses on machine learning models, 2018
Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes · 2018
Cited alongside, same era.
Towards demystifying membership inference attacks
Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Lei Yu, and Wenqi Wei · 2018
Cited alongside, same era.
ML Privacy Meter: Aiding regulatory compliance by quantifying the privacy risks of machine learning
Sasi Kumar Murakonda and Reza Shokri · 2020
Later among the works it cites.
Sampling attacks: Amplification of membership inference attacks by repeated queries
Shadi Rahimian, Tribhuvanesh Orekondy, and Mario Fritz · 2020
Later among the works it cites.
Updates-leak: Data set inference and reconstruction attacks in online learning
Ahmed Salem, Apratim Bhattacharya, Michael Backes, Mario Fritz, and Yang Zhang · 2020
Later among the works it cites.
Introducing a new privacy testing library in tensorflow
Shuang Song and David Marn · 2020
Later among the works it cites.
The pitfalls of average-case differential privacy
Thomas Steinke and Jonathan Ullman · 2020
Later among the works it cites.
Random erasing data augmentation
Zhun Zhong, Liang Zheng, Guoliang Kang, Shaozi Li, and Yi Yang · 2020
Later among the works it cites.
When is memorization of irrelevant training data necessary for high-accuracy learning?
Gavin Brown, Mark Bun, Vitaly Feldman, Adam Smith, and Kunal Talwar · 2021
Closest in time.
Extracting training data from large language models
Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al · 2021
Closest in time.
Label-only membership inference attacks
Christopher A Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot · 2021
Closest in time.
Stealing links from graph neural networks
Xinlei He, Jinyuan Jia, Michael Backes, Neil Zhenqiang Gong, and Yang Zhang · 2021
Closest in time.
Revisiting membership inference under realistic assumptions
Bargav Jayaraman, Lingxiao Wang, David Evans, and Quanquan Gu · 2021
Closest in time.
ML-Doctor: Holistic risk assessment of inference attacks against machine learning models
Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang · 2021
Closest in time.
Quantifying the privacy risks of learning high-dimensional graphical models
Sasi Kumar Murakonda, Reza Shokri, and George Theodorakopoulos · 2021
Closest in time.
Adversary instantiation: Lower bounds for differentially private machine learning
Milad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot, and Nicholas Carlini · 2021
Closest in time.
huyvnphan/pytorch_cifar10, January 2021
Huy Phan · 2021
Closest in time.
Systematic evaluation of privacy risks of machine learning models
Liwei Song and Prateek Mittal · 2021
Closest in time.
On the importance of difficulty calibration in membership inference attacks
Lauren Watson, Chuan Guo, Graham Cormode, and Alex Sablayrolles · 2021
Closest in time.
Enhanced membership inference attacks against machine learning models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, and Reza Shokri · 2021
Closest in time.
Understanding deep learning (still) requires rethinking generalization
Chiyuan Zhang, Samy Bengio, Moritz Hardt, Benjamin Recht, and Oriol Vinyals · 2021
Closest in time.