Fetching the paper…
Reading the bibliography…
Empirical defenses for machine learning privacy forgo the provable guarantees of differential privacy in the hope of achieving higher utility while resisting realistic adversaries.
Membership inference attacks from first principles. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 1897–1914
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. 2022a · 1914
Earlier work this paper cites.
Label-only membership inference attacks. In International Conference on Machine Learning . PMLR, 1964–1974
Christopher A Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021 · 1974
Earlier work this paper cites.
Defending Model Inversion and Membership Inference Attacks via Prediction Purification
Ziqi Yang, Bin Shao, Bohan Xuan, Ee-Chien Chang, and Fan Zhang. 2020 · 2005
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography: Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7, 2006. Proceedings 3 . Springer, 265–284
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006 · 2006
Earlier work this paper cites.
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton, et al · 2009
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures. In ACM SIGSAC Conference on Computer and Communications Security . 1322–1333
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015 · 2015
Earlier work this paper cites.
The composition theorem for differential privacy. In International conference on machine learning . PMLR, 1376–1385
Peter Kairouz, Sewoong Oh, and Pramod Viswanath. 2015 · 2015
Earlier work this paper cites.
Deep Learning with Differential Privacy. In ACM SIGSAC Conference on Computer and Communications Security . ACM, 308–318
Martin Abadi, Andy Chu, Ian Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016 · 2016
Earlier work this paper cites.
Deep Residual Learning for Image Recognition. In IEEE Conference on Computer Vision and Pattern Recognition (CVPR) . 770–778
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016 · 2016
Earlier work this paper cites.
Wide Residual Networks. In BMVC
Sergey Zagoruyko and Nikos Komodakis. 2016 · 2016
Earlier work this paper cites.
Data-free knowledge distillation for deep neural networks
Raphael Gontijo Lopes, Stefano Fenu, and Thad Starner. 2017 · 2017
Earlier work this paper cites.
Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data. In International Conference on Learning Representations
Nicolas Papernot, Martín Abadi, Úlfar Erlingsson, Ian Goodfellow, and Kunal Talwar. 2017 · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models. In IEEE Symposium on Security and Privacy . IEEE, 3–18
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017 · 2017
Earlier work this paper cites.
An Improved Method of Identifying Mislabeled Data and the Mislabeled Data in MNIST and CIFAR-10
Xinbin Zhang. 2017 · 2017
Earlier work this paper cites.
Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. In International conference on machine learning . PMLR, 274–283
Anish Athalye, Nicholas Carlini, and David Wagner. 2018 · 2018
Earlier work this paper cites.
Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018 · 2018
Earlier work this paper cites.
Machine learning with membership privacy using adversarial regularization. In ACM SIGSAC Conference on Computer and Communications Security . 634–646
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2018 · 2018
Earlier work this paper cites.
Ensemble Adversarial Training: Attacks and Defenses. In International Conference on Learning Representations
Florian Tramèr, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2018 · 2018
Earlier work this paper cites.
Privacy risk in machine learning: Analyzing the connection to overfitting. In 2018 IEEE 31st computer security foundations symposium (CSF) . IEEE, 268–282
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018 · 2018
Earlier work this paper cites.
The secret sharer: Evaluating and testing unintended memorization in neural networks. In USENIX Security Symposium . 267–284
Nicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos, and Dawn Song. 2019 · 2019
Earlier work this paper cites.
Data-free learning of student networks. In Proceedings of the IEEE/CVF international conference on computer vision . 3514–3522
Hanting Chen, Yunhe Wang, Chang Xu, Zhaohui Yang, Chuanjian Liu, Boxin Shi, Chunjing Xu, Chao Xu, and Qi Tian. 2019 · 2019
Earlier work this paper cites.
MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples. In ACM SIGSAC Conference on Computer and Communications Security . 259–274
Jinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang, and Neil Zhenqiang Gong. 2019 · 2019
Earlier work this paper cites.
Identifying Mislabeled Instances in Classification Datasets. In 2019 International Joint Conference on Neural Networks (IJCNN) . 1–8
Nicolas M. Müller and Karla Markert. 2019 · 2019
Earlier work this paper cites.
Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In IEEE Symposium on Security and Privacy . IEEE, 739–753
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019 · 2019
Earlier work this paper cites.
White-box vs black-box: Bayes optimal strategies for membership inference. In International Conference on Machine Learning . PMLR, 5558–5567
Alexandre Sablayrolles, Matthijs Douze, Cordelia Schmid, Yann Ollivier, and Hervé Jégou. 2019 · 2019
Earlier work this paper cites.
ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models
Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2019 · 2019
Cited alongside, same era.
A simple framework for contrastive learning of visual representations. In International conference on machine learning . 1597–1607
Ting Chen, Simon Kornblith, Mohammad Norouzi, and Geoffrey Hinton. 2020 · 2020
Cited alongside, same era.
Does learning require memorization? A short tale about a long tail. In ACM SIGACT Symposium on Theory of Computing . 954–959
Vitaly Feldman. 2020 · 2020
Cited alongside, same era.
Momentum contrast for unsupervised visual representation learning. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition . 9729–9738
Kaiming He, Haoqi Fan, Yuxin Wu, Saining Xie, and Ross Girshick. 2020 · 2020
Cited alongside, same era.
Auditing differentially private machine learning: How private is private sgd?
Measuring Forgetting of Memorized Training Examples. In The Eleventh International Conference on Learning Representations
Matthew Jagielski, Om Thakkar, Florian Tramer, Daphne Ippolito, Katherine Lee, Nicholas Carlini, Eric Wallace, Shuang Song, Abhradeep Guha Thakurta, Nicolas Papernot, and Chiyuan Zhang. 2022 · 2022
Later among the works it cites.
{ \{ ML-Doctor } \} : Holistic risk assessment of inference attacks against machine learning models. In 31st USENIX Security Symposium (USENIX Security 22) . 4525–4542
Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2022 · 2022
Later among the works it cites.
Mitigating Membership Inference Attacks by Self-Distillation Through a Novel Ensemble Architecture. In USENIX Security Symposium . 1433–1450
Xinyu Tang, Saeed Mahloujifar, Liwei Song, Virat Shejwalkar, Milad Nasr, Amir Houmansadr, and Prateek Mittal. 2022 · 2022
Later among the works it cites.
Truth Serum: Poisoning Machine Learning Models to Reveal Their Secrets. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security . 2779–2792
Florian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le, Matthew Jagielski, Sanghyun Hong, and Nicholas Carlini. 2022 · 2022
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Matthew Jagielski, Jonathan Ullman, and Alina Oprea. 2020 · 2020
Cited alongside, same era.
A Pragmatic Approach to Membership Inferences on Machine Learning Models. In 2020 IEEE European Symposium on Security and Privacy (EuroS&P) . 521–534
Yunhui Long, Lei Wang, Diyue Bu, Vincent Bindschaedler, Xiaofeng Wang, Haixu Tang, Carl A. Gunter, and Kai Chen. 2020 · 2020
Cited alongside, same era.
Lectures 9 and 10
Adam D. Smith. 2020 · 2020
Cited alongside, same era.
The Pitfalls of Average-Case Differential Privacy
Thomas Steinke and Jonathan Ullman. 2020 · 2020
Cited alongside, same era.
Differentially Private Learning Needs Better Features (or Much More Data). In International Conference on Learning Representations
Florian Tramer and Dan Boneh. 2020 · 2020
Cited alongside, same era.
On adaptive attacks to adversarial example defenses
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020 · 2020
Cited alongside, same era.
Dreaming to distill: Data-free knowledge transfer via deepinversion. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 8715–8724
Hongxu Yin, Pavlo Molchanov, Jose M Alvarez, Zhizhong Li, Arun Mallya, Derek Hoiem, Niraj K Jha, and Jan Kautz. 2020 · 2020
Cited alongside, same era.
Extracting training data from large language models. In USENIX Security Symposium
Nicholas Carlini, Florian Tramer, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, Ulfar Erlingsson, et al · 2021
Cited alongside, same era.
Later among the works it cites.
Debugging differential privacy: A case study for privacy auditing
Florian Tramer, Andreas Terzis, Thomas Steinke, Shuang Song, Matthew Jagielski, and Nicholas Carlini. 2022 · 2022
Later among the works it cites.
Canary in a Coalmine: Better Membership Inference with Ensembled Adversarial Queries. In The Eleventh International Conference on Learning Representations
Yuxin Wen, Arpit Bansal, Hamid Kazemi, Eitan Borgnia, Micah Goldblum, Jonas Geiping, and Tom Goldstein. 2022 · 2022
Later among the works it cites.
Enhanced membership inference attacks against machine learning models. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security . 3093–3106
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, and Reza Shokri. 2022 · 2022
Later among the works it cites.
Dense: Data-free one-shot federated learning
Jie Zhang, Chen Chen, Bo Li, Lingjuan Lyu, Shuang Wu, Shouhong Ding, Chunhua Shen, and Chao Wu. 2022 · 2022
Later among the works it cites.
Scalable Membership Inference Attacks via Quantile Regression. In Advances in Neural Information Processing Systems
Martin Bertran, Shuai Tang, Michael Kearns, Jamie Morgenstern, Aaron Roth, and Zhiwei Steven Wu. 2023 · 2023
Later among the works it cites.
Practical Membership Inference Attacks Against Large-Scale Multi-Modal Models: A Pilot Study. In Proceedings of the IEEE/CVF International Conference on Computer Vision . 4871–4881
Myeongseob Ko, Ming Jin, Chenguang Wang, and Ruoxi Jia. 2023 · 2023
Later among the works it cites.
Tight Auditing of Differentially Private Machine Learning. In USENIX Security Symposium . 1631–1648
Milad Nasr, Jamie Hayes, Thomas Steinke, Borja Balle, Florian Tramèr, Matthew Jagielski, Nicholas Carlini, and Andreas Terzis. 2023 · 2023
Later among the works it cites.
Unleashing the Power of Randomization in Auditing Differentially Private ML. In Advances in Neural Information Processing Systems . 66201–66238
Krishna Pillutla, Galen Andrew, Peter Kairouz, H. Brendan McMahan, Alina Oprea, and Sewoong Oh. 2023 · 2023
Later among the works it cites.
TAN without a Burn: Scaling Laws of DP-SGD. In Proceedings of the International Conference on Machine Learning , Vol. 202. 29937–29949
Tom Sander, Pierre Stock, and Alexandre Sablayrolles. 2023 · 2023
Later among the works it cites.
Privacy Auditing with One (1) Training Run. In Advances in Neural Information Processing Systems . 49268–49280
Thomas Steinke, Milad Nasr, and Matthew Jagielski. 2023 · 2023
Later among the works it cites.
Leave-One-out Distinguishability in Machine Learning. In International Conference on Learning Representations
Jiayuan Ye, Anastasia Borovykh, Soufiane Hayou, and Reza Shokri. 2023 · 2023
Later among the works it cites.
IDEAL: Query-Efficient Data-Free Learning from Black-Box Models. In The Eleventh International Conference on Learning Representations
Jie Zhang, Chen Chen, and Lingjuan Lyu. 2023 · 2023
Later among the works it cites.
Overconfidence Is a Dangerous Thing: Mitigating Membership Inference Attacks by Enforcing Less Confident Prediction. In NDSS Symposium
Zitao Chen and Karthik Pattabiraman. 2024 · 2024
Closest in time.
Privacy Backdoors: Stealing Data with Corrupted Pretrained Models
Shanglun Feng and Florian Tramèr. 2024 · 2024
Closest in time.
A Cautionary Tale: On the Role of Reference Data in Empirical Privacy Defenses. In Proceedings on Privacy Enhancing Technologies . 525–548
Caelin Kaplan, Chuan Xu, Othmane Marfoq, Giovanni Neglia, and Anderson Santana de Oliveira. 2024 · 2024
Closest in time.
On the Privacy Effect of Data Enhancement via the Lens of Memorization
Xiao Li, Qiongxiu Li, Zhanhao Hu, and Xiaolin Hu. 2024 · 2024
Closest in time.
PILLAR: How to Make Semi-Private Learning More Effective. In 2nd IEEE Conference on Secure and Trustworthy Machine Learning
Francesco Pinto, Yaxi Hu, Fanny Yang, and Amartya Sanyal. 2024 · 2024
Closest in time.
Memorization in Self-Supervised Learning Improves Downstream Generalization. In The Twelfth International Conference on Learning Representations
Wenhao Wang, Muhammad Ahmad Kaleem, Adam Dziedzic, Michael Backes, Nicolas Papernot, and Franziska Boenisch. 2024 · 2024
Closest in time.
Low-Cost High-Power Membership Inference Attacks
Sajjad Zarifzadeh, Philippe Liu, and Reza Shokri. 2024 · 2024
Closest in time.
EncoderMI: Membership inference against pre-trained encoders in contrastive learning. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . 2081–2095
Hongbin Liu, Jinyuan Jia, Wenjie Qu, and Neil Zhenqiang Gong. 2021 · 2095
Closest in time.