Fetching the paper…
Reading the bibliography…
This paper introduces a novel approach to membership inference attacks (MIA) targeting stable diffusion computer vision models, specifically focusing on the highly sophisticated Stable Diffusion V2 by StabilityAI.
N. Carlini, S. Chien, M. Nasr, S. Song, A. Terzis, and F. Tramer, “Membership inference attacks from first principles,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 1897–1914
1914
Earlier work this paper cites.
C. A. Choquette-Choo, F. Tramer, N. Carlini, and N. Papernot, “Label-only membership inference attacks,” in Proceedings of the 38th International Conference on Machine Learning , ser. Proceedings of Machine Learning Research, M. Meila and T. Zhang, Eds., vol. 139. PMLR, 18–24 Jul 2021, pp. 1964–1974. [Online]. Available: https://proceedings.mlr.press/v139/choquette-choo21a.html
1974
Earlier work this paper cites.
T. C. Rindfleisch, “Privacy, information technology, and health care,” Communications of the ACM , vol. 40, no. 8, pp. 92–100, 1997
1997
Earlier work this paper cites.
R. J. Bolton and D. J. Hand, “Statistical fraud detection: A review,” Statistical science , vol. 17, no. 3, pp. 235–255, 2002
2002
Earlier work this paper cites.
N. Homer, S. Szelinger, M. Redman, D. Duggan, W. Tembe, J. Muehling, J. V. Pearson, D. A. Stephan, S. F. Nelson, and D. W. Craig, “Resolving individuals contributing trace amounts of dna to highly complex mixtures using high-density snp genotyping microarrays,” PLOS Genetics , vol. 4, no. 8, pp. 1–9, 08 2008. [Online]. Available: https://doi.org/10.1371/journal.pgen.1000167
2008
Earlier work this paper cites.
S. Sankararaman, G. Obozinski, M. I. Jordan, and E. Halperin, “Genomic privacy and limits of individual detection in a pool,” Nature genetics , vol. 41, no. 9, pp. 965–967, 2009
2009
Earlier work this paper cites.
S. Song, K. Chaudhuri, and A. D. Sarwate, “Stochastic gradient descent with differentially private updates,” in 2013 IEEE Global Conference on Signal and Information Processing , 2013, pp. 245–248
2013
Earlier work this paper cites.
C. Dwork and A. Roth, “The algorithmic foundations of differential privacy,” Foundations and Trends® in Theoretical Computer Science , vol. 9, no. 3–4, pp. 211–407, 2014. [Online]. Available: http://dx.doi.org/10.1561/0400000042
2014
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in Proceedings of the 22nd ACM SIGSAC conference on computer and communications security , 2015, pp. 1322–1333
2015
Earlier work this paper cites.
R. Shokri and V. Shmatikov, “Privacy-preserving deep learning,” in Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’15. New York, NY, USA: Association for Computing Machinery, 2015, p. 1310–1321. [Online]. Available: https://doi.org/10.1145/2810103.2813687
2015
Earlier work this paper cites.
C. Dwork, A. Smith, T. Steinke, J. Ullman, and S. Vadhan, “Robust traceability from trace amounts,” in 2015 IEEE 56th Annual Symposium on Foundations of Computer Science , 2015, pp. 650–669
2015
Earlier work this paper cites.
J. Sohl-Dickstein, E. Weiss, N. Maheswaranathan, and S. Ganguli, “Deep unsupervised learning using nonequilibrium thermodynamics,” in International conference on machine learning . PMLR, 2015, pp. 2256–2265
2015
Earlier work this paper cites.
2016
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction apis,” in Proceedings of the 25th USENIX Conference on Security Symposium , ser. SEC’16. USA: USENIX Association, 2016, p. 601–618
2016
Earlier work this paper cites.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’16. New York, NY, USA: Association for Computing Machinery, 2016, p. 308–318. [Online]. Available: https://doi.org/10.1145/2976749.2978318
2016
Earlier work this paper cites.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’16. New York, NY, USA: Association for Computing Machinery, 2016, p. 308–318. [Online]. Available: https://doi.org/10.1145/2976749.2978318
2016
Earlier work this paper cites.
P. Voigt and A. Von dem Bussche, “The eu general data protection regulation (gdpr),” A Practical Guide, 1st Ed., Cham: Springer International Publishing , vol. 10, no. 3152676, pp. 10–5555, 2017
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in 2017 IEEE symposium on security and privacy (SP) . IEEE, 2017, pp. 3–18
2017
Earlier work this paper cites.
C. Dwork, A. Smith, T. Steinke, and J. Ullman, “Exposed! a survey of attacks on private data,” Annual Review of Statistics and Its Application , vol. 4, no. 1, pp. 61–84, 2017. [Online]. Available: https://doi.org/10.1146/annurev-statistics-060116-054123
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
S. Yeom, I. Giacomelli, M. Fredrikson, and S. Jha, “Privacy risk in machine learning: Analyzing the connection to overfitting,” in 2018 IEEE 31st computer security foundations symposium (CSF) . IEEE, 2018, pp. 268–282
2018
Earlier work this paper cites.
K. Ganju, Q. Wang, W. Yang, C. A. Gunter, and N. Borisov, “Property inference attacks on fully connected neural networks using permutation invariant representations,” in Proceedings of the 2018 ACM SIGSAC conference on computer and communications security , 2018, pp. 619–633
2018
Earlier work this paper cites.
K. Ganju, Q. Wang, W. Yang, C. A. Gunter, and N. Borisov, “Property inference attacks on fully connected neural networks using permutation invariant representations,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’18. New York, NY, USA: Association for Computing Machinery, 2018, p. 619–633. [Online]. Available: https://doi.org/10.1145/3243734.3243834
2018
Earlier work this paper cites.
M. Nasr, R. Shokri, and A. Houmansadr, “Machine learning with membership privacy using adversarial regularization,” in Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’18. New York, NY, USA: Association for Computing Machinery, 2018, p. 634–646. [Online]. Available: https://doi.org/10.1145/3243734.3243855
2018
Cited alongside, same era.
N. Papernot, S. Song, I. Mironov, A. Raghunathan, K. Talwar, and U. Erlingsson, “Scalable private learning with PATE,” in International Conference on Learning Representations , 2018. [Online]. Available: https://openreview.net/forum?id=rkZB1XbRZ
2018
Cited alongside, same era.
Z. Yang and L. Wang, “Learning relationships for multi-view 3d object recognition,” in Proceedings of the IEEE/CVF international conference on computer vision , 2019, pp. 7505–7514
2019
Cited alongside, same era.
J. D. M.-W. C. Kenton and L. K. Toutanova, “Bert: Pre-training of deep bidirectional transformers for language understanding,” in Proceedings of naacL-HLT , vol. 1, 2019, p. 2
G. Brown, M. Bun, V. Feldman, A. Smith, and K. Talwar, “When is memorization of irrelevant training data necessary for high-accuracy learning?” in Proceedings of the 53rd Annual ACM SIGACT Symposium on Theory of Computing , ser. STOC 2021. New York, NY, USA: Association for Computing Machinery, 2021, p. 123–132. [Online]. Available: https://doi.org/10.1145/3406325.3451131
2021
Later among the works it cites.
L. Song and P. Mittal, “Systematic evaluation of privacy risks of machine learning models,” in 30th USENIX Security Symposium (USENIX Security 21) . USENIX Association, Aug. 2021, pp. 2615–2632. [Online]. Available: https://www.usenix.org/conference/usenixsecurity21/presentation/song
2021
Later among the works it cites.
B. Jayaraman, L. Wang, K. Knipmeyer, Q. Gu, and D. Evans, “Revisiting membership inference under realistic assumptions,” Proceedings on Privacy Enhancing Technologies , vol. 2021, no. 2, 2021
2021
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2019
Cited alongside, same era.
N. Carlini, C. Liu, Ú. Erlingsson, J. Kos, and D. Song, “The secret sharer: Evaluating and testing unintended memorization in neural networks,” in 28th USENIX Security Symposium (USENIX Security 19) . Santa Clara, CA: USENIX Association, Aug. 2019, pp. 267–284. [Online]. Available: https://www.usenix.org/conference/usenixsecurity19/presentation/carlini
2019
Cited alongside, same era.
J. Jia, A. Salem, M. Backes, Y. Zhang, and N. Z. Gong, “Memguard: Defending against black-box membership inference attacks via adversarial examples,” in Proceedings of the 2019 ACM SIGSAC conference on computer and communications security , 2019, pp. 259–274
2019
Cited alongside, same era.
J. Jia, A. Salem, M. Backes, Y. Zhang, and N. Z. Gong, “Memguard: Defending against black-box membership inference attacks via adversarial examples,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , ser. CCS ’19. New York, NY, USA: Association for Computing Machinery, 2019, p. 259–274. [Online]. Available: https://doi.org/10.1145/3319535.3363201
2019
Cited alongside, same era.
Y. Song and S. Ermon, “Generative modeling by estimating gradients of the data distribution,” Advances in neural information processing systems , vol. 32, 2019
2019
Cited alongside, same era.
A. Waheed, M. Goyal, D. Gupta, A. Khanna, F. Al-Turjman, and P. R. Pinheiro, “Covidgan: data augmentation using auxiliary classifier gan for improved covid-19 detection,” Ieee Access , vol. 8, pp. 91 916–91 923, 2020
2020
Cited alongside, same era.
S. Natale and A. Ballatore, “Imagining the thinking machine: Technological myths and the rise of artificial intelligence,” Convergence , vol. 26, no. 1, pp. 3–18, 2020. [Online]. Available: https://doi.org/10.1177/1354856517715164
2020
Cited alongside, same era.
S. Shan, E. Wenger, J. Zhang, H. Li, H. Zheng, and B. Y. Zhao, “Fawkes: Protecting privacy against unauthorized deep learning models,” in 29th USENIX security symposium (USENIX Security 20) , 2020, pp. 1589–1604
2020
Cited alongside, same era.
F. Mo, A. S. Shamsabadi, K. Katevas, S. Demetriou, I. Leontiadis, A. Cavallaro, and H. Haddadi, “Darknetz: towards model privacy at the edge using trusted execution environments,” in Proceedings of the 18th International Conference on Mobile Systems, Applications, and Services , 2020, pp. 161–174
2020
Cited alongside, same era.
Y. Song, J. Sohl-Dickstein, D. P. Kingma, A. Kumar, S. Ermon, and B. Poole, “Score-based generative modeling through stochastic differential equations,” in International Conference on Learning Representations , 2021. [Online]. Available: https://openreview.net/forum?id=PxTIG12RRHS
2021
Later among the works it cites.
2021
Later among the works it cites.
R. S. Zimmermann, L. Schott, Y. Song, B. A. Dunn, and D. A. Klindt, “Score-based generative classifiers,” in NeurIPS 2021 Workshop on Deep Generative Models and Downstream Applications , 2021. [Online]. Available: https://openreview.net/forum?id=usdN2qgg0L
2021
Later among the works it cites.
T. Cilloni, W. Wang, C. Walter, and C. Fleming, “Ulixes: Facial recognition privacy with adversarial machine learning,” Proceedings on Privacy Enhancing Technologies , vol. 1, pp. 148–165, 2022
2022
Later among the works it cites.
R. Shokri, “Auditing data privacy for machine learning,” in Enigma 2022 . Santa Clara, CA: USENIX Association, Feb. 2022
2022
Later among the works it cites.
G. Li, S. Rezaei, and X. Liu, “User-level membership inference attack against metric embedding learning,” in ICLR 2022 Workshop on PAIR^2Struct: Privacy, Accountability, Interpretability, Robustness, Reasoning on Structured Data , 2022. [Online]. Available: https://openreview.net/forum?id=H__g7vTqIx9
2022
Later among the works it cites.
R. Rombach, A. Blattmann, D. Lorenz, P. Esser, and B. Ommer, “High-resolution image synthesis with latent diffusion models,” in Proceedings of the IEEE/CVF conference on computer vision and pattern recognition , 2022, pp. 10 684–10 695
2022
Later among the works it cites.
C. Saharia, J. Ho, W. Chan, T. Salimans, D. J. Fleet, and M. Norouzi, “Image super-resolution via iterative refinement,” IEEE Transactions on Pattern Analysis and Machine Intelligence , vol. 45, no. 4, pp. 4713–4726, 2022
2022
Later among the works it cites.
O. Avrahami, D. Lischinski, and O. Fried, “Blended diffusion for text-driven editing of natural images,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , 2022, pp. 18 208–18 218
2022
Later among the works it cites.
D. Baranchuk, A. Voynov, I. Rubachev, V. Khrulkov, and A. Babenko, “Label-efficient semantic segmentation with diffusion models,” in International Conference on Learning Representations , 2022. [Online]. Available: https://openreview.net/forum?id=SlxSY2UZQT
2022
Later among the works it cites.
A. Graikos, N. Malkin, N. Jojic, and D. Samaras, “Diffusion models as plug-and-play priors,” Advances in Neural Information Processing Systems , vol. 35, pp. 14 715–14 728, 2022
2022
Later among the works it cites.
W. H. Pinaya, M. S. Graham, R. Gray, P. F. Da Costa, P.-D. Tudosiu, P. Wright, Y. H. Mah, A. D. MacKinnon, J. T. Teo, R. Jager et al. , “Fast unsupervised brain anomaly detection and segmentation with diffusion models,” in International Conference on Medical Image Computing and Computer-Assisted Intervention . Springer, 2022, pp. 705–714
2022
Later among the works it cites.
J. Wolleb, F. Bieder, R. Sandkühler, and P. C. Cattin, “Diffusion models for medical anomaly detection,” in International Conference on Medical image computing and computer-assisted intervention . Springer, 2022, pp. 35–45
2022
Later among the works it cites.
R. Rombach, A. Blattmann, D. Lorenz, P. Esser, and B. Ommer, “High-resolution image synthesis with latent diffusion models,” in 2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) , 2022, pp. 10 674–10 685
2022
Later among the works it cites.
C. Schuhmann, R. Beaumont, R. Vencu, C. Gordon, R. Wightman, M. Cherti, T. Coombes, A. Katta, C. Mullis, M. Wortsman et al. , “Laion-5b: An open large-scale dataset for training next generation image-text models,” Advances in Neural Information Processing Systems , vol. 35, pp. 25 278–25 294, 2022
2022
Later among the works it cites.
A. Oprea and A. Vassilev, “Adversarial machine learning: A taxonomy and terminology of attacks and mitigations,” National Institute of Standards and Technology – Computer Security Resource Center, Tech. Rep. NIST AI 100-2 E2023, 3 2023
2023
Closest in time.
N. Carlini, J. Hayes, M. Nasr, M. Jagielski, V. Sehwag, F. Tramer, B. Balle, D. Ippolito, and E. Wallace, “Extracting training data from diffusion models,” in 32nd USENIX Security Symposium (USENIX Security 23) , 2023, pp. 5253–5270
2023
Closest in time.
J. Duan, F. Kong, S. Wang, X. Shi, and K. Xu, “Are diffusion models vulnerable to membership inference attacks?” in Proceedings of the 40th International Conference on Machine Learning , ser. ICML’23. JMLR.org, 2023
2023
Closest in time.
2023
Closest in time.