Slide 14
Slide 14 text
Membership Inference Attacks
Predict
Membership
Data Set
M
(TPR − FPR)
M1 M2 Mk
A
Expected Training Loss
1
n
n
∑
i=1
ℓ(di
, θ)
Reza Shokri,
Marco Stronati,
Congzheng Song,
Vitaly Shmatikov
(S&P 2017)
Samuel Yeom,
Irene Giacomelli,
Matt Fredrikson,
Somesh Jha
(CSF 2018)
Privacy Leakage