Fetching the paper…
Reading the bibliography…
Model distillation is frequently proposed as a technique to reduce the privacy leakage of machine learning.
Membership inference attacks from first principles
Carlini, N., Chien, S., Nasr, M., Song, S., Terzis, A., and Tramer, F · 1914
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Dwork, C., McSherry, F., Nissim, K., and Smith, A · 2006
Earlier work this paper cites.
Do deep nets really need to be deep?
Ba, J. and Caruana, R · 2014
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Fredrikson, M., Jha, S., and Ristenpart, T · 2015
Earlier work this paper cites.
Distilling the knowledge in a neural network
Hinton, G., Vinyals, O., Dean, J., et al · 2015
Earlier work this paper cites.
Semi-supervised knowledge transfer for deep learning from private training data
Papernot, N., Abadi, M., Erlingsson, U., Goodfellow, I., and Talwar, K · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction { \{ APIs } \}
Tramèr, F., Zhang, F., Juels, A., Reiter, M. K., and Ristenpart, T · 2016
Earlier work this paper cites.
Zagoruyko, S. and Komodakis, N · 2016
Earlier work this paper cites.
Dawnbench: An end-to-end deep learning benchmark and competition
Coleman, C., Narayanan, D., Kang, D., Zhao, T., Zhang, J., Nardi, L., Bailis, P., Olukotun, K., Ré, C., and Zaharia, M · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
Shokri, R., Stronati, M., Song, C., and Shmatikov, V · 2017
Earlier work this paper cites.
Born again neural networks
Furlanello, T., Lipton, Z., Tschannen, M., Itti, L., and Anandkumar, A · 2018
Earlier work this paper cites.
Property inference attacks on fully connected neural networks using permutation invariant representations
Ganju, K., Wang, Q., Yang, W., Gunter, C. A., and Borisov, N · 2018
Earlier work this paper cites.
Paraphrasing complex network: Network compression via factor transfer
Kim, J., Park, S., and Kwak, N · 2018
Earlier work this paper cites.
Understanding membership inferences on well-generalized learning models
Long, Y., Bindschaedler, V., Wang, L., Bu, D., Wang, X., Tang, H., Gunter, C. A., and Chen, K · 2018
Cited alongside, same era.
Model compression via distillation and quantization
Polino, A., Pascanu, R., and Alistarh, D · 2018
Cited alongside, same era.
Privacy risk in machine learning: Analyzing the connection to overfitting
Yeom, S., Giacomelli, I., Fredrikson, M., and Jha, S · 2018
Cited alongside, same era.
Imagededup
Jain, T., Lennan, C., John, Z., and Tran, D · 2019
Cited alongside, same era.
Knockoff nets: Stealing functionality of black-box models
Orekondy, T., Schiele, B., and Fritz, M · 2019
Cited alongside, same era.
Label-only membership inference attacks
Choquette-Choo, C. A., Tramer, F., Carlini, N., and Papernot, N · 2021
Later among the works it cites.
Membership leakage in label-only exposures
Li, Z. and Zhang, Y · 2021
Later among the works it cites.
Membership privacy for machine learning models through knowledge transfer
Shejwalkar, V. and Houmansadr, A · 2021
Later among the works it cites.
On the importance of difficulty calibration in membership inference attacks
Watson, L., Guo, C., Cormode, G., and Sablayrolles, A · 2021
Later among the works it cites.
Resisting membership inference attacks through knowledge distillation
Zheng, J., Cao, Y., and Wang, H · 2021
Later among the works it cites.
Amplifying membership exposure via data poisoning
Chen, Y., Shen, C., Shen, Y., Wang, C., and Zhang, Y · 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Sablayrolles, A., Douze, M., Schmid, C., Ollivier, Y., and Jégou, H · 2019
Cited alongside, same era.
Patient knowledge distillation for bert model compression
Sun, S., Cheng, Y., Gan, Z., and Liu, J · 2019
Cited alongside, same era.
High accuracy and high fidelity extraction of neural networks
Jagielski, M., Carlini, N., Berthelot, D., Kurakin, A., and Papernot, N · 2020
Cited alongside, same era.
Revisiting membership inference under realistic assumptions
Jayaraman, B., Wang, L., Knipmeyer, K., Gu, Q., and Evans, D · 2020
Cited alongside, same era.
Activethief: Model extraction using active learning and unannotated public data
Pal, S., Gupta, Y., Shukla, A., Kanade, A., Shevade, S., and Ganapathy, V · 2020
Cited alongside, same era.
Self-training with noisy student improves imagenet classification
Xie, Q., Luong, M.-T., Hovy, E., and Le, Q. V · 2020
Cited alongside, same era.
Extracting training data from large language models
Carlini, N., Tramer, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, U., et al · 2021
Cited alongside, same era.
Later among the works it cites.
Less is more: Task-aware layer-wise distillation for language model compression
Liang, C., Zuo, S., Zhang, Q., He, P., Chen, W., and Zhao, T · 2022
Later among the works it cites.
Repeated knowledge distillation with confidence masking to mitigate membership inference attacks
Mazzone, F., van den Heuvel, L., Huber, M., Verdecchia, C., Everts, M., Hahn, F., and Peter, A · 2022
Later among the works it cites.
Differentially private model compression
Mireshghallah, F., Backurs, A., Inan, H. A., Wutschitz, L., and Kulkarni, J · 2022
Later among the works it cites.
Mitigating membership inference attacks by { \{ Self-Distillation } \} through a novel ensemble architecture
Tang, X., Mahloujifar, S., Song, L., Shejwalkar, V., Nasr, M., Houmansadr, A., and Mittal, P · 2022
Later among the works it cites.
Truth serum: Poisoning machine learning models to reveal their secrets
Tramèr, F., Shokri, R., San Joaquin, A., Le, H., Jagielski, M., Hong, S., and Carlini, N · 2022
Later among the works it cites.
Canary in a coalmine: Better membership inference with ensembled adversarial queries
Wen, Y., Bansal, A., Kazemi, H., Borgnia, E., Goldblum, M., Geiping, J., and Goldstein, T · 2022
Later among the works it cites.