Fetching the paper…
Reading the bibliography…
Differentially private training offers a protection which is usually interpreted as a guarantee against membership inference attacks.
Asymptotic minimax character of the sample distribution function and of the classical multinomial estimator
Dvoretzky, A., Kiefer, J., and Wolfowitz, J · 1956
Earlier work this paper cites.
Testing statistical hypotheses
Lehmann, E. L. and Romano, J. P · 2005
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Dwork, C., McSherry, F., Nissim, K., and Smith, A. D · 2006
Earlier work this paper cites.
Resolving individuals contributing trace amounts of dna to highly complex mixtures using high-density snp genotyping microarrays
Homer, N., Szelinger, S., Redman, M., Duggan, D., Tembe, W., Muehling, J., Pearson, J. V., Stephan, D. A., Nelson, S. F., and Craig, D. W · 2008
Earlier work this paper cites.
Stochastic gradient descent with differentially private updates
Song, S., Chaudhuri, K., and Sarwate, A. D · 2013
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Fredrikson, M., Jha, S., and Ristenpart, T · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Earlier work this paper cites.
Wide residual networks
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Accuracy first: Selecting a differential privacy level for accuracy constrained erm
Ligett, K., Neel, S., Roth, A., Waggoner, B., and Wu, S. Z · 2017
Earlier work this paper cites.
Rényi differential privacy
Mironov, I · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
Shokri, R., Stronati, M., Song, C., and Shmatikov, V · 2017
Earlier work this paper cites.
Protection against reconstruction and its applications in private federated learning
Bhowmick, A., Duchi, J., Freudiger, J., Kapoor, G., and Rogers, R · 2018
Earlier work this paper cites.
Privacy risk in machine learning: Analyzing the connection to overfitting
Yeom, S., Giacomelli, I., Fredrikson, M., and Jha, S · 2018
Earlier work this paper cites.
The secret sharer: Evaluating and testing unintended memorization in neural networks
Carlini, N., Liu, C., Erlingsson, Ú., Kos, J., and Song, D · 2019
Earlier work this paper cites.
Dong, J., Roth, A., and Su, W. J · 2019
Earlier work this paper cites.
White-box vs black-box: Bayes optimal strategies for membership inference
Sablayrolles, A., Douze, M., Schmid, C., Ollivier, Y., and Jégou, H · 2019
Earlier work this paper cites.
Overlearning reveals sensitive attributes
Song, C. and Shmatikov, V · 2019
Earlier work this paper cites.
Beyond inferring class representatives: User-level privacy leakage from federated learning
Wang, Z., Song, M., Zhang, Z., Song, Y., Wang, Q., and Qi, H · 2019
Cited alongside, same era.
Deep leakage from gradients
Zhu, L., Liu, Z., and Han, S · 2019
Cited alongside, same era.
Inverting gradients - how easy is it to break privacy in federated learning?
Geiping, J., Bauermeister, H., Dröge, H., and Moeller, M · 2020
Cited alongside, same era.
idlg: Improved deep leakage from gradients
Zhao, B., Mopuri, K. R., and Bilen, H · 2020
Cited alongside, same era.
Extracting training data from large language models
Carlini, N., Tramer, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, U., et al · 2021
Cited alongside, same era.
Individual privacy accounting via a renyi filter
Fine-tuning with differential privacy necessitates an additional hyperparameter search
Cattan, Y., Choquette-Choo, C. A., Papernot, N., and Thakurta, A · 2022
Later among the works it cites.
Unlocking high-accuracy differentially private image classification through scale
De, S., Berrada, L., Hayes, J., Smith, S. L., and Balle, B · 2022
Later among the works it cites.
Privacy loss distributions
Google DP Team · 2022
Later among the works it cites.
Reconstructing training data from trained neural networks
Haim, N., Vardi, G., Yehudai, G., Shamir, O., and Irani, M · 2022
Later among the works it cites.
Preventing verbatim memorization in language models gives a false sense of privacy
Ippolito, D., Tramèr, F., Nasr, M., Zhang, C., Jagielski, M., Lee, K., Choquette-Choo, C. A., and Carlini, N · 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Feldman, V. and Zrnic, T · 2021
Cited alongside, same era.
Numerical composition of differential privacy
Gopi, S., Lee, Y. T., and Wutschitz, L · 2021
Cited alongside, same era.
Evaluating gradient inversion attacks and defenses in federated learning
Huang, Y., Gupta, S., Song, Z., Li, K., and Arora, S · 2021
Cited alongside, same era.
Gradient inversion with generative image prior
Jeon, J., Lee, K., Oh, S., Ok, J., et al · 2021
Cited alongside, same era.
Cafe: Catastrophic data leakage in vertical federated learning
Jin, X., Chen, P.-Y., Hsu, C.-Y., Yu, C.-M., and Chen, T · 2021
Cited alongside, same era.
Adversary instantiation: Lower bounds for differentially private machine learning
Nasr, M., Song, S., Thakurta, A., Papemoti, N., and Carlini, N · 2021
Cited alongside, same era.
Privately publishable per-instance privacy
Redberg, R. and Wang, Y.-X · 2021
Cited alongside, same era.
Later among the works it cites.
Deduplicating training data mitigates privacy risks in language models
Kandpal, N., Wallace, E., and Raffel, C · 2022
Later among the works it cites.
Optimal membership inference bounds for adaptive composition of sampled gaussian mechanisms
Mahloujifar, S., Sablayrolles, A., Cormode, G., and Jha, S · 2022
Later among the works it cites.
Large scale transfer learning for differentially private image classification
Mehta, H., Thakurta, A., Kurakin, A., and Cutkosky, A · 2022
Later among the works it cites.
Quantifying privacy risks of masked language models using membership inference attacks
Mireshghallah, F., Goyal, K., Uniyal, A., Berg-Kirkpatrick, T., and Shokri, R · 2022
Later among the works it cites.
Diffusion art or digital forgery? investigating data replication in diffusion models
Somepalli, G., Singla, V., Goldblum, M., Geiping, J., and Goldstein, T · 2022
Later among the works it cites.
Defending against reconstruction attacks with rényi differential privacy
Stock, P., Shilov, I., Mironov, I., and Sablayrolles, A · 2022
Later among the works it cites.
Memorization without overfitting: Analyzing the training dynamics of large language models
Tirumala, K., Markosyan, A. H., Zettlemoyer, L., and Aghajanyan, A · 2022
Later among the works it cites.
Debugging differential privacy: A case study for privacy auditing
Tramèr, F., Terzis, A., Steinke, T., Song, S., Jagielski, M., and Carlini, N · 2022
Later among the works it cites.
Differentially private learning needs hidden state (or much faster convergence)
Ye, J. and Shokri, R · 2022
Later among the works it cites.
Per-instance privacy accounting for differentially private stochastic gradient descent
Yu, D., Kamath, G., Kulkarni, J., Yin, J., Liu, T.-Y., and Zhang, H · 2022
Later among the works it cites.
Optimal accounting of differential privacy via characteristic function
Zhu, Y., Dong, J., and Wang, Y.-X · 2022
Later among the works it cites.
Extracting training data from diffusion models
Carlini, N., Hayes, J., Nasr, M., Jagielski, M., Sehwag, V., Tramèr, F., Balle, B., Ippolito, D., and Wallace, E · 2023
Closest in time.