Fetching the paper…
Reading the bibliography…
Understanding to what extent neural networks memorize training data is an intriguing question with practical and theoretical implications.
Fast normalized cross-correlation
J. P. Lewis · 1995
Earlier work this paper cites.
Image quality assessment: from error visibility to structural similarity
Z. Wang, A. C. Bovik, H. R. Sheikh, and E. P. Simoncelli · 2004
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
C. Dwork, F. McSherry, K. Nissim, and A. Smith · 2006
Earlier work this paper cites.
Visualizing higher-layer features of a deep network
D. Erhan, Y. Bengio, A. Courville, and P. Vincent · 2009
Earlier work this paper cites.
Learning multiple layers of features from tiny images
A. Krizhevsky, G. Hinton, et al · 2009
Earlier work this paper cites.
Mnist handwritten digit database
Y. LeCun, C. Cortes, and C. Burges · 2010
Earlier work this paper cites.
Is private learning possible with instance encoding?
N. Carlini, S. Deng, S. Garg, S. Jha, S. Mahloujifar, M. Mahmoody, S. Song, A. Thakurta, and F. Tramer · 2011
Earlier work this paper cites.
Differentially private empirical risk minimization
K. Chaudhuri, C. Monteleoni, and A. D. Sarwate · 2011
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2013
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
M. Fredrikson, S. Jha, and T. Ristenpart · 2015
Earlier work this paper cites.
Delving deep into rectifiers: Surpassing human-level performance on imagenet classification
K. He, X. Zhang, S. Ren, and J. Sun · 2015
Earlier work this paper cites.
Understanding deep image representations by inverting them
A. Mahendran and A. Vedaldi · 2015
Earlier work this paper cites.
Inceptionism: Going deeper into neural networks
A. Mordvintsev, C. Olah, and M. Tyka · 2015
Earlier work this paper cites.
Understanding neural networks through deep visualization
J. Yosinski, J. Clune, A. Nguyen, T. Fuchs, and H. Lipson · 2015
Earlier work this paper cites.
Deep learning with differential privacy
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction { \{ APIs } \}
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart · 2016
Earlier work this paper cites.
Deep models under the gan: information leakage from collaborative deep learning
B. Hitaj, G. Ateniese, and F. Perez-Cruz · 2017
Earlier work this paper cites.
Exploring generalization in deep learning
B. Neyshabur, S. Bhojanapalli, D. McAllester, and N. Srebro · 2017
Earlier work this paper cites.
Plug & play generative networks: Conditional iterative generation of images in latent space
A. Nguyen, J. Clune, Y. Bengio, A. Dosovitskiy, and J. Yosinski · 2017
Earlier work this paper cites.
Feature visualization
C. Olah, A. Mordvintsev, and L. Schubert · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
R. Shokri, M. Stronati, C. Song, and V. Shmatikov · 2017
Earlier work this paper cites.
Gradient descent aligns the layers of deep linear networks
Z. Ji and M. Telgarsky · 2018
Earlier work this paper cites.
Understanding membership inferences on well-generalized learning models
Y. Long, V. Bindschaedler, L. Wang, D. Bu, X. Wang, H. Tang, C. A. Gunter, and K. Chen · 2018
Earlier work this paper cites.
A. Salem, Y. Zhang, M. Humbert, P. Berrang, M. Fritz, and M. Backes · 2018
Earlier work this paper cites.
The implicit bias of gradient descent on separable data
D. Soudry, E. Hoffer, M. S. Nacson, S. Gunasekar, and N. Srebro · 2018
Cited alongside, same era.
Robustness may be at odds with accuracy
D. Tsipras, S. Santurkar, L. Engstrom, A. Turner, and A. Madry · 2018
Cited alongside, same era.
Stealing hyperparameters in machine learning
B. Wang and N. Z. Gong · 2018
Cited alongside, same era.
Privacy risk in machine learning: Analyzing the connection to overfitting
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha · 2018
Cited alongside, same era.
Implicit regularization in deep matrix factorization
S. Arora, N. Cohen, W. Hu, and Y. Luo · 2019
Cited alongside, same era.
The secret sharer: Evaluating and testing unintended memorization in neural networks
Towards resolving the implicit bias of gradient descent for matrix factorization: Greedy low-rank learning
Z. Li, Y. Luo, and K. Lyu · 2020
Later among the works it cites.
Implicit bias in deep linear classification: Initialization scale vs training accuracy
E. Moroshko, B. E. Woodworth, S. Gunasekar, J. D. Lee, N. Srebro, and D. Soudry · 2020
Later among the works it cites.
Zoom in: An introduction to circuits
C. Olah, N. Cammarata, L. Schubert, G. Goh, M. Petrov, and S. Carter · 2020
Later among the works it cites.
Implicit regularization in deep learning may not be explainable by norms
N. Razin and N. Cohen · 2020
Later among the works it cites.
Reverse-engineering deep relu networks
D. Rolnick and K. Kording · 2020
Later among the works it cites.
Kernel and rich regimes in overparametrized models
B. Woodworth, S. Gunasekar, J. D. Lee, E. Moroshko, P. Savarese, I. Golan, D. Soudry, and N. Srebro · 2020
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
N. Carlini, C. Liu, Ú. Erlingsson, J. Kos, and D. Song · 2019
Cited alongside, same era.
Adversarial robustness as a prior for learned representations
L. Engstrom, A. Ilyas, S. Santurkar, D. Tsipras, B. Tran, and A. Madry · 2019
Cited alongside, same era.
Model inversion attacks against collaborative inference
Z. He, T. Zhang, and R. B. Lee · 2019
Cited alongside, same era.
Gradient descent maximizes the margin of homogeneous neural networks
K. Lyu and J. Li · 2019
Cited alongside, same era.
Robust or private? adversarial training makes models more vulnerable to privacy attacks
F. A. Mejia, P. Gamble, Z. Hampel-Arias, M. Lomnitz, N. Lopatina, L. Tindall, and M. A. Barrios · 2019
Cited alongside, same era.
Exploiting unintended feature leakage in collaborative learning
L. Melis, C. Song, E. De Cristofaro, and V. Shmatikov · 2019
Cited alongside, same era.
Model reconstruction from model explanations
S. Milli, L. Schmidt, A. D. Dragan, and M. Hardt · 2019
Cited alongside, same era.
Later among the works it cites.
Dreaming to distill: Data-free knowledge transfer via deepinversion
H. Yin, P. Molchanov, J. M. Alvarez, Z. Li, A. Mallya, D. Hoiem, N. K. Jha, and J. Kautz · 2020
Later among the works it cites.
A unifying view on implicit bias in training linear neural networks
C. Yun, S. Krishnan, and H. Mobahi · 2020
Later among the works it cites.
The secret revealer: Generative model-inversion attacks against deep neural networks
Y. Zhang, R. Jia, H. Pei, W. Wang, B. Li, and D. Song · 2020
Later among the works it cites.
On the implicit bias of initialization shape: Beyond infinitesimal mirror descent
S. Azulay, E. Moroshko, M. S. Nacson, B. Woodworth, N. Srebro, A. Globerson, and D. Soudry · 2021
Later among the works it cites.
When is memorization of irrelevant training data necessary for high-accuracy learning?
G. Brown, M. Bun, V. Feldman, A. Smith, and K. Talwar · 2021
Later among the works it cites.
Extracting training data from large language models
N. Carlini, F. Tramer, E. Wallace, M. Jagielski, A. Herbert-Voss, K. Lee, A. Roberts, T. Brown, D. Song, U. Erlingsson, et al · 2021
Later among the works it cites.
Efficiently learning one hidden layer relu networks from queries
S. Chen, A. Klivans, and R. Meka · 2021
Later among the works it cites.
Evaluating gradient inversion attacks and defenses in federated learning
Y. Huang, S. Gupta, Z. Song, K. Li, and S. Arora · 2021
Later among the works it cites.
Survey: Leakage and privacy at inference time
M. Jegorova, C. Kaul, C. Mayor, A. Q. O’Neil, A. Weir, R. Murray-Smith, and S. A. Tsaftaris · 2021
Later among the works it cites.
When machine learning meets privacy: A survey and outlook
B. Liu, M. Ding, S. Shaham, W. Rahayu, F. Farokhi, and Z. Lin · 2021
Later among the works it cites.
Systematic evaluation of privacy risks of machine learning models
L. Song and P. Mittal · 2021
Later among the works it cites.
Implicit regularization in relu networks with the square loss
G. Vardi and O. Shamir · 2021
Later among the works it cites.
On margin maximization in linear and relu networks
G. Vardi, O. Shamir, and N. Srebro · 2021
Later among the works it cites.
See through gradients: Image batch recovery via gradinversion
H. Yin, A. Mallya, A. Vahdat, J. M. Alvarez, J. Kautz, and P. Molchanov · 2021
Later among the works it cites.
Understanding deep learning (still) requires rethinking generalization
C. Zhang, S. Bengio, M. Hardt, B. Recht, and O. Vinyals · 2021
Later among the works it cites.
Reconstructing training data with informed adversaries
B. Balle, G. Cherubin, and J. Hayes · 2022
Closest in time.
Implicit regularization towards rank minimization in relu networks
N. Timor, G. Vardi, and O. Shamir · 2022
Closest in time.
On the implicit bias in deep-learning algorithms
G. Vardi · 2022
Closest in time.