Fetching the paper…
Reading the bibliography…
We present PANORAMIA, a privacy leakage measurement framework for machine learning models that relies on membership inference attacks using generated data as non-members.
Membership inference attacks from first principles
Carlini, N., Chien, S., Nasr, M., Song, S., Terzis, A., and Tramer, F · 1914
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Dwork, C., McSherry, F., Nissim, K., and Smith, A · 2006
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Krizhevsky, A · 2009
Earlier work this paper cites.
An image is worth 16x16 words: Transformers for image recognition at scale, 2021
Dosovitskiy, A., Beyer, L., Kolesnikov, A., Weissenborn, D., Zhai, X., Unterthiner, T., Dehghani, M., Minderer, M., Heigold, G., Gelly, S., Uszkoreit, J., and Houlsby, N · 2010
Earlier work this paper cites.
A statistical framework for differential privacy
Wasserman, L. and Zhou, S · 2010
Earlier work this paper cites.
Deep residual learning for image recognition, 2015
He, K., Zhang, X., Ren, S., and Sun, J · 2015
Earlier work this paper cites.
The composition theorem for differential privacy
Kairouz, P., Oh, S., and Viswanath, P · 2015
Earlier work this paper cites.
Deep learning face attributes in the wild
Liu, Z., Luo, P., Wang, X., and Tang, X · 2015
Earlier work this paper cites.
An introduction to convolutional neural networks, 2015
O’Shea, K. and Nash, R · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L · 2016
Earlier work this paper cites.
Pointer sentinel mixture models
Merity, S., Xiong, C., Bradbury, J., and Socher, R · 2016
Earlier work this paper cites.
Privacy risk in machine learning: Analyzing the connection to overfitting
Yeom, S., Giacomelli, I., Fredrikson, M., and Jha, S · 2018
Earlier work this paper cites.
The secret sharer: Evaluating and testing unintended memorization in neural networks
Carlini, N., Liu, C., Erlingsson, Ú., Kos, J., and Song, D · 2019
Earlier work this paper cites.
Dong, J., Roth, A., and Su, W. J · 2019
Cited alongside, same era.
The curious case of neural text degeneration
Holtzman, A., Buys, J., Du, L., Forbes, M., and Choi, Y · 2019
Cited alongside, same era.
Evaluating differentially private machine learning in practice
Jayaraman, B. and Evans, D. E · 2019
Cited alongside, same era.
Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning
Nasr, M., Shokri, R., and Houmansadr, A · 2019
Cited alongside, same era.
Language models are unsupervised multitask learners
Radford, A., Wu, J., Child, R., Luan, D., Amodei, D., Sutskever, I., et al · 2019
Cited alongside, same era.
Bayesian estimation of differential privacy, 2022
Zanella-Béguelin, S., Wutschitz, L., Tople, S., Salem, A., Rühle, V., Paverd, A., Naseri, M., Köpf, B., and Jones, D · 2022
Later among the works it cites.
One-shot empirical privacy estimation for federated learning, 2023
Andrew, G., Kairouz, P., Oh, S., Oprea, A., McMahan, H. B., and Suriyakumar, V · 2023
Later among the works it cites.
A general framework for auditing differentially private machine learning, 2023
Lu, F., Munoz, J., Fuchs, M., LeBlond, T., Zaresky-Williams, E., Raff, E., Ferraro, F., and Testa, B · 2023
Later among the works it cites.
Canife: Crafting canaries for empirical privacy measurement in federated learning, 2023
Maddock, S., Sablayrolles, A., and Stock, P · 2023
Later among the works it cites.
Tight auditing of differentially private machine learning, 2023
Nasr, M., Hayes, J., Steinke, T., Balle, B., Tramèr, F., Jagielski, M., Carlini, N., and Terzis, A · 2023
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Auditing differentially private machine learning: How private is private sgd?
Jagielski, M., Ullman, J., and Oprea, A · 2020
Cited alongside, same era.
Training generative adversarial networks with limited data, 2020
Karras, T., Aittala, M., Hellsten, J., Laine, S., Lehtinen, J., and Aila, T · 2020
Cited alongside, same era.
Extracting training data from large language models
Carlini, N., Tramer, F., Wallace, E., Jagielski, M., Herbert-Voss, A., Lee, K., Roberts, A., Brown, T., Song, D., Erlingsson, U., et al · 2021
Cited alongside, same era.
Large language models can be strong differentially private learners
Li, X., Tramer, F., Liang, P., and Hashimoto, T · 2021
Cited alongside, same era.
Winning the nist contest: A scalable and general approach to differentially private synthetic data
McKenna, R., Miklau, G., and Sheldon, D · 2021
Cited alongside, same era.
Adversary instantiation: Lower bounds for differentially private machine learning
Nasr, M., Songi, S., Thakurta, A., Papernot, N., and Carlin, N · 2021
Cited alongside, same era.
Opacus: User-friendly differential privacy library in PyTorch
Yousefpour, A., Shilov, I., Sablayrolles, A., Testuggine, D., Prasad, K., Malek, M., Nguyen, J., Ghosh, S., Bharadwaj, A., Zhao, J., Cormode, G., and Mironov, I · 2021
Cited alongside, same era.
Negoescu, D. M., Gonzalez, H., Orjany, S. E. A., Yang, J., Lut, Y., Tandra, R., Zhang, X., Zheng, X., Douglas, Z., Nolkha, V., et al · 2023
Later among the works it cites.
Privacy auditing with one (1) training run
Steinke, T., Nasr, M., and Jagielski, M · 2023
Later among the works it cites.
Low-cost high-power membership inference by boosting relativity
Zarifzadeh, S., Liu, P. C.-J. M., and Shokri, R · 2023
Later among the works it cites.
Blind baselines beat membership inference attacks for foundation models
Das, D., Zhang, J., and Tramèr, F · 2024
Closest in time.
Do membership inference attacks work on large language models?
Duan, M., Suri, A., Mireshghallah, N., Min, S., Shi, W., Zettlemoyer, L., Tsvetkov, Y., Choi, Y., Evans, D., and Hajishirzi, H · 2024
Closest in time.
Inherent challenges of post-hoc membership inference for large language models
Meeus, M., Jain, S., Rei, M., and de Montjoye, Y.-A · 2024
Closest in time.
Do parameters reveal more than loss for membership inference?
Suri, A., Zhang, X., and Evans, D · 2024
Closest in time.