Fetching the paper…
Reading the bibliography…
Empirical auditing has emerged as a means of catching some of the flaws in the implementation of privacy-preserving algorithms.
Differential privacy
Cynthia Dwork · 2006
Earlier work this paper cites.
Resolving individuals contributing trace amounts of dna to highly complex mixtures using high-density snp genotyping microarrays
Nils Homer, Szabolcs Szelinger, Margot Redman, David Duggan, Waibhav Tembe, Jill Muehling, John V Pearson, Dietrich A Stephan, Stanley F Nelson, and David W Craig · 2008
Earlier work this paper cites.
Differentially private empirical risk minimization
Kamalika Chaudhuri, Claire Monteleoni, and Anand D Sarwate · 2011
Earlier work this paper cites.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang · 2016
Earlier work this paper cites.
Sergey Zagoruyko and Nikos Komodakis · 2016
Earlier work this paper cites.
Rényi differential privacy
Ilya Mironov · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Earlier work this paper cites.
Protection against reconstruction and its applications in private federated learning
Abhishek Bhowmick, John Duchi, Julien Freudiger, Gaurav Kapoor, and Ryan Rogers · 2018
Earlier work this paper cites.
Dp-finder: Finding differential privacy violations by sampling and optimization
Benjamin Bichsel, Timon Gehr, Dana Drachsler-Cohen, Petar Tsankov, and Martin Vechev · 2018
Earlier work this paper cites.
Detecting violations of differential privacy
Zeyu Ding, Yuxin Wang, Guanhong Wang, Danfeng Zhang, and Daniel Kifer · 2018
Earlier work this paper cites.
Machine learning with membership privacy using adversarial regularization
Milad Nasr, Reza Shokri, and Amir Houmansadr · 2018
Earlier work this paper cites.
Jinshuo Dong, Aaron Roth, and Weijie J Su · 2019
Earlier work this paper cites.
On the intrinsic privacy of stochastic gradient descent
Stephanie L Hyland and Shruti Tople · 2019
Earlier work this paper cites.
Memguard: Defending against black-box membership inference attacks via adversarial examples
Jinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang, and Neil Zhenqiang Gong · 2019
Earlier work this paper cites.
White-box vs black-box: Bayes optimal strategies for membership inference
Alexandre Sablayrolles, Matthijs Douze, Cordelia Schmid, Yann Ollivier, and Hervé Jégou · 2019
Earlier work this paper cites.
Auditing differentially private machine learning: How private is private sgd?
Matthew Jagielski, Jonathan Ullman, and Alina Oprea · 2020
Earlier work this paper cites.
Stolen memories: Leveraging model memorization for calibrated { \{ White-Box } \} membership inference
Klas Leino and Matt Fredrikson · 2020
Earlier work this paper cites.
Dp-sniper: Black-box discovery of differential privacy violations using classifiers
Benjamin Bichsel, Samuel Steffen, Ilija Bogunovic, and Martin Vechev · 2021
Cited alongside, same era.
Adversary instantiation: Lower bounds for differentially private machine learning
Milad Nasr, Shuang Songi, Abhradeep Thakurta, Nicolas Papernot, and Nicholas Carlin · 2021
Cited alongside, same era.
On the importance of difficulty calibration in membership inference attacks
Lauren Watson, Chuan Guo, Graham Cormode, and Alex Sablayrolles · 2021
Cited alongside, same era.
Reconstructing training data with informed adversaries
Borja Balle, Giovanni Cherubin, and Jamie Hayes · 2022
Cited alongside, same era.
Membership inference attacks from first principles
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer · 2022
Cited alongside, same era.
Zitao Chen and Karthik Pattabiraman · 2023
Later among the works it cites.
Bounding training data reconstruction in dp-sgd
Jamie Hayes, Saeed Mahloujifar, and Borja Balle · 2023
Later among the works it cites.
Georgios Kaissis, Jamie Hayes, Alexander Ziller, and Daniel Rueckert · 2023
Later among the works it cites.
Students parrot their teachers: Membership inference on model distillation
Jagielski Matthew, Nasr Milad, Choquette-Choo Christopher, Lee Katherine, and Carlini Nicholas · 2023
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Bounding training data reconstruction in private (deep) learning
Chuan Guo, Brian Karrer, Kamalika Chaudhuri, and Laurens van der Maaten · 2022
Cited alongside, same era.
Membership inference attacks on machine learning: A survey
Hongsheng Hu, Zoran Salcic, Lichao Sun, Gillian Dobbie, Philip S Yu, and Xuyun Zhang · 2022
Cited alongside, same era.
A general framework for auditing differentially private machine learning
Fred Lu, Joseph Munoz, Maya Fuchs, Tyler LeBlond, Elliott Zaresky-Williams, Edward Raff, Francis Ferraro, and Brian Testa · 2022
Cited alongside, same era.
Optimal membership inference bounds for adaptive composition of sampled gaussian mechanisms
Saeed Mahloujifar, Alexandre Sablayrolles, Graham Cormode, and Somesh Jha · 2022
Cited alongside, same era.
Defending against reconstruction attacks with r \ \backslash ’enyi differential privacy
Pierre Stock, Igor Shilov, Ilya Mironov, and Alexandre Sablayrolles · 2022
Cited alongside, same era.
Mitigating membership inference attacks by { \{ Self-Distillation } \} through a novel ensemble architecture
Xinyu Tang, Saeed Mahloujifar, Liwei Song, Virat Shejwalkar, Milad Nasr, Amir Houmansadr, and Prateek Mittal · 2022
Cited alongside, same era.
Debugging differential privacy: A case study for privacy auditing
Florian Tramer, Andreas Terzis, Thomas Steinke, Shuang Song, Matthew Jagielski, and Nicholas Carlini · 2022
Cited alongside, same era.
Milad Nasr, Jamie Hayes, Thomas Steinke, Borja Balle, Florian Tramèr, Matthew Jagielski, Nicholas Carlini, and Andreas Terzis · 2023
Later among the works it cites.
Tan without a burn: Scaling laws of dp-sgd
Tom Sander, Pierre Stock, and Alexandre Sablayrolles · 2023
Later among the works it cites.
Privacy auditing with one (1) training run
Thomas Steinke, Milad Nasr, and Matthew Jagielski · 2023
Later among the works it cites.
A randomized approach for tight privacy accounting
Jiachen T Wang, Saeed Mahloujifar, Tong Wu, Ruoxi Jia, and Prateek Mittal · 2023
Later among the works it cites.
Low-cost high-power membership inference by boosting relativity
Sajjad Zarifzadeh, Philippe Cheng-Jie Marc Liu, and Reza Shokri · 2023
Later among the works it cites.
Scalable membership inference attacks via quantile regression
Martin Bertran, Shuai Tang, Aaron Roth, Michael Kearns, Jamie H Morgenstern, and Steven Z Wu · 2024
Closest in time.
Tighter privacy auditing of dp-sgd in the hidden state threat model
Tudor Cebere, Aurélien Bellet, and Nicolas Papernot · 2024
Closest in time.
Karan Chadha, Matthew Jagielski, Nicolas Papernot, Christopher Choquette-Choo, and Milad Nasr · 2024
Closest in time.
Do membership inference attacks work on large language models?
Michael Duan, Anshuman Suri, Niloofar Mireshghallah, Sewon Min, Weijia Shi, Luke Zettlemoyer, Yulia Tsvetkov, Yejin Choi, David Evans, and Hannaneh Hajishirzi · 2024
Closest in time.
Optimal privacy guarantees for a relaxed threat model: Addressing sub-optimal adversaries in differentially private machine learning
Georgios Kaissis, Alexander Ziller, Stefan Kolek, Anneliese Riess, and Daniel Rueckert · 2024
Closest in time.
{ \{ MIST } \} : Defending against membership inference attacks through { \{ Membership-Invariant } \} subspace training
Jiacheng Li, Ninghui Li, and Bruno Ribeiro · 2024
Closest in time.
Unleashing the power of randomization in auditing differentially private ml
Krishna Pillutla, Galen Andrew, Peter Kairouz, H Brendan McMahan, Alina Oprea, and Sewoong Oh · 2024
Closest in time.