Fetching the paper…
Reading the bibliography…
Given access to a machine learning model, can an adversary reconstruct the model's training data? This work studies this question from the lens of a powerful informed adversary who knows all the training data points except one.
R. W. Wedderburn, “On the existence and uniqueness of the maximum likelihood estimates for certain generalized linear models,” Biometrika , 1976
1976
Earlier work this paper cites.
Y. Lecun, L. Bottou, Y. Bengio, and P. Haffner, “Gradient-based learning applied to document recognition,” Proceedings of the IEEE , 1998
1998
Earlier work this paper cites.
I. Dinur and K. Nissim, “Revealing information while preserving privacy,” in ACM Symposium on Principles of Database Systems (PODS) , 2003
2003
Earlier work this paper cites.
S. Dasgupta and A. Gupta, “An elementary proof of a theorem of johnson and lindenstrauss,” Random Struct. Algorithms , 2003
2003
Earlier work this paper cites.
A. Blum, C. Dwork, F. McSherry, and K. Nissim, “Practical privacy: the SuLQ framework,” in ACM Symposium on Principles of Database Systems (PODS) , 2005
2005
Earlier work this paper cites.
C. Dwork, F. McSherry, K. Nissim, and A. D. Smith, “Calibrating noise to sensitivity in private data analysis,” in Theory of Cryptography Conference (TCC) , 2006
2006
Earlier work this paper cites.
C. Dwork, K. Kenthapadi, F. McSherry, I. Mironov, and M. Naor, “Our data, ourselves: Privacy via distributed noise generation,” in International Conference on the Theory and Applications of Cryptographic Techniques (EUROCRYPT) , 2006
2006
Earlier work this paper cites.
C. Dwork, F. McSherry, and K. Talwar, “The price of privacy and the limits of LP decoding,” in ACM Symposium on Theory of Computing (STOC) , 2007
2007
Earlier work this paper cites.
M. Shaked and J. G. Shanthikumar, Stochastic orders . Springer Science & Business Media, 2007
2007
Earlier work this paper cites.
Y. Duan, “Privacy without noise,” in ACM Conference on Information and Knowledge Management (CIKM) , 2009
2009
Earlier work this paper cites.
R. Shokri, J. Freudiger, M. Jadliwala, and J. Hubaux, “A distortion-based metric for location privacy,” in ACM Workshop on Privacy in the Electronic Society (WPES) , 2009
2009
Earlier work this paper cites.
G. Smith, “On the foundations of quantitative information flow,” in International Conference on Foundations of Software Science and Computational Structures (FOSSACS) , 2009
2009
Earlier work this paper cites.
L. Wasserman and S. Zhou, “A statistical framework for differential privacy,” Journal of the American Statistical Association , 2010
2010
Earlier work this paper cites.
R. Bhaskar, A. Bhowmick, V. Goyal, S. Laxman, and A. Thakurta, “Noiseless database privacy,” in International Conference on the Theory and Application of Cryptology and Information Security (ASIACRYPT) , 2011
2011
Earlier work this paper cites.
R. Shokri, G. Theodorakopoulos, J. L. Boudec, and J. Hubaux, “Quantifying location privacy,” in IEEE Symposium on Security and Privacy (SP) , 2011
2011
Earlier work this paper cites.
R. Bassily, A. Groce, J. Katz, and A. D. Smith, “Coupled-worlds privacy: Exploiting adversarial uncertainty in statistical data privacy,” in IEEE Symposium on Foundations of Computer Science (FOCS) , 2013
2013
Earlier work this paper cites.
M. Fredrikson, E. Lantz, S. Jha, S. Lin, D. Page, and T. Ristenpart, “Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing,” in USENIX Security Symposium , 2014
2014
Earlier work this paper cites.
D. Kifer and A. Machanavajjhala, “Pufferfish: A framework for mathematical privacy definitions,” ACM Trans. Database Syst. , 2014
2014
Earlier work this paper cites.
S. P. Kasiviswanathan and A. D. Smith, “On the ’semantics’ of differential privacy: A bayesian formulation,” J. Priv. Confidentiality , 2014
2014
Earlier work this paper cites.
E. ElSalamouny, K. Chatzikokolakis, and C. Palamidessi, “Generalized differential privacy: Regions of priors that admit robust optimal mechanisms,” in Horizons of the Mind. A Tribute to Prakash Panangaden - Essays Dedicated to Prakash Panangaden on the Occasion of His 60th Birthday , 2014
2014
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in ACM Conference on Computer and Communications Security (CCS) , 2015
2015
Earlier work this paper cites.
P. Kairouz, S. Oh, and P. Viswanath, “The composition theorem for differential privacy,” in International Conference on Machine Learning (ICML) , 2015
2015
Earlier work this paper cites.
M. Abadi, A. Chu, I. J. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in ACM Conference on Computer and Communications Security (CCS) , 2016
2016
Earlier work this paper cites.
S. Zagoruyko and N. Komodakis, “Wide residual networks,” in British Machine Vision Conference (BMVC) , 2016
2016
Earlier work this paper cites.
M. Bun and T. Steinke, “Concentrated differential privacy: Simplifications, extensions, and lower bounds,” in Theory of Cryptography Conference (TCC) , 2016
2016
Cited alongside, same era.
C. Zhang, S. Bengio, M. Hardt, B. Recht, and O. Vinyals, “Understanding deep learning requires rethinking generalization,” in International Conference on Learning Representations (ICLR) , 2017
2017
Cited alongside, same era.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in IEEE Symposium on Security and Privacy (SP) , 2017
2017
Cited alongside, same era.
B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. Agüera y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in International Conference on Artificial Intelligence and Statistics (AISTATS) , 2017
2017
Cited alongside, same era.
V. Feldman, “Does learning require memorization? a short tale about a long tail,” in ACM Symposium on Theory of Computing (STOC) , 2020
2020
Later among the works it cites.
V. Feldman and C. Zhang, “What neural networks memorize and why: Discovering the long tail via influence estimation,” in Conference on Neural Information Processing Systems (NeurIPS) , 2020
2020
Later among the works it cites.
Y. Zhang, R. Jia, H. Pei, W. Wang, B. Li, and D. Song, “The secret revealer: Generative model-inversion attacks against deep neural networks,” in IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , 2020
2020
Later among the works it cites.
J. Geiping, H. Bauermeister, H. Dröge, and M. Moeller, “Inverting gradients - how easy is it to break privacy in federated learning?” in Conference on Neural Information Processing Systems (NeurIPS) , 2020
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
P. Isola, J.-Y. Zhu, T. Zhou, and A. A. Efros, “Image-to-image translation with conditional adversarial networks,” in IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , 2017
2017
Cited alongside, same era.
X. Mao, Q. Li, H. Xie, R. Y. Lau, Z. Wang, and S. Paul Smolley, “Least squares generative adversarial networks,” in IEEE International Conference on Computer Vision (ICCV) , 2017
2017
Cited alongside, same era.
I. Mironov, “Rényi differential privacy,” in IEEE Computer Security Foundations Symposium (CSF) , 2017
2017
Cited alongside, same era.
A. Ghosh and R. Kleinberg, “Inferential privacy guarantees for differentially private mechanisms,” in Innovations in Theoretical Computer Science Conference (ITCS) , 2017
2017
Cited alongside, same era.
C. Dwork, A. Smith, T. Steinke, and J. Ullman, “Exposed! A survey of attacks on private data,” Annual Review of Statistics and Its Application , 2017
2017
Cited alongside, same era.
K. Ganju, Q. Wang, W. Yang, C. A. Gunter, and N. Borisov, “Property inference attacks on fully connected neural networks using permutation invariant representations,” in ACM Conference on Computer and Communications Security (CCS) , 2018
2018
Cited alongside, same era.
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy risk in machine learning: Analyzing the connection to overfitting,” in IEEE Computer Security Foundations Symposium (CSF) , 2018
2018
Cited alongside, same era.
R. Zhang, P. Isola, A. A. Efros, E. Shechtman, and O. Wang, “The unreasonable effectiveness of deep features as a perceptual metric,” in IEEE Conference on Computer Vision and Pattern Recognition (CVPR) , 2018
2018
Cited alongside, same era.
S. Z. Béguelin, L. Wutschitz, S. Tople, V. Rühle, A. Paverd, O. Ohrimenko, B. Köpf, and M. Brockschmidt, “Analyzing information leakage of updates to natural language models,” in ACM Conference on Computer and Communications Security (CCS) , 2020
2020
Later among the works it cites.
A. Salem, A. Bhattacharya, M. Backes, M. Fritz, and Y. Zhang, “Updates-leak: Data set inference and reconstruction attacks in online learning,” in USENIX Security Symposium , 2020
2020
Later among the works it cites.
T. Hennigan, T. Cai, T. Norman, and I. Babuschkin, “Haiku: Sonnet for JAX,” 2020. [Online]. Available: http://github.com/deepmind/dm-haiku
2020
Later among the works it cites.
M. Jagielski, J. Ullman, and A. Oprea, “Auditing differentially private machine learning: How private is private sgd?” Advances in Neural Information Processing Systems , 2020
2020
Later among the works it cites.
B. Balle, G. Barthe, M. Gaboardi, J. Hsu, and T. Sato, “Hypothesis testing interpretations and renyi differential privacy,” in International Conference on Artificial Intelligence and Statistics (AISTATS) , 2020
2020
Later among the works it cites.
A. Cohen and K. Nissim, “Linear program reconstruction in practice,” J. Priv. Confidentiality , 2020
2020
Later among the works it cites.
A. Cohen, S. Nikolov, Z. Schutzman, and J. Ullman, “Reconstruction attacks in practice,” 2020. [Online]. Available: https://differentialprivacy.org/diffix-attack/
2020
Later among the works it cites.
M. S. Alvim, K. Chatzikokolakis, A. McIver, C. Morgan, C. Palamidessi, and G. Smith, The Science of Quantitative Information Flow . Springer, 2020
2020
Later among the works it cites.
M. Johnson, “add gpu determinism note,” Nov 2020. [Online]. Available: https://github.com/google/jax/pull/4824
2020
Later among the works it cites.
V. Feldman and T. Zrnic, “Individual privacy accounting via a renyi filter,” arXiv:2008.11193 , 2020
2020
Later among the works it cites.
S. Song and D. Marn, “Introducing a New Privacy Testing Library in TensorFlow.” June 2020. [Online]. Available: https://blog.tensorflow.org/2020/06/introducing-new-privacy-testing-library.html
2020
Later among the works it cites.
G. Brown, M. Bun, V. Feldman, A. D. Smith, and K. Talwar, “When is memorization of irrelevant training data necessary for high-accuracy learning?” in ACM Symposium on Theory of Computing (STOC) , 2021
2021
Later among the works it cites.
N. Carlini, F. Tramèr, E. Wallace, M. Jagielski, A. Herbert-Voss, K. Lee, A. Roberts, T. B. Brown, D. Song, Ú. Erlingsson, A. Oprea, and C. Raffel, “Extracting training data from large language models,” in USENIX Security Symposium , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
M. Nasr, S. Song, A. Thakurta, N. Papernot, and N. Carlini, “Adversary instantiation: Lower bounds for differentially private machine learning,” in IEEE Symposium on Security and Privacy (SP) , 2021
2021
Later among the works it cites.
2021
Later among the works it cites.
2021
Later among the works it cites.
F. McSherry, “I suspect the ”Discovery” had a different feel for the various involved people. I personally spent a lot of time trying to remove explicit references to adversaries and assumptions about them.” Jan 2021. [Online]. Available: https://twitter.com/frankmcsherry/status/1354789417727234049
2021
Later among the works it cites.
“JAX activations,” https://jax.readthedocs.io/en/latest/jax.nn.html , accessed: 2022-03-25
2022
Closest in time.