Under a Gibbs posterior assumption, the Bayes-optimal membership inference attack depends only on the model's loss, and simple loss-threshold attacks outperform shadow models.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
stat.ML 1years
2019 1verdicts
CONDITIONAL 1representative citing papers
citing papers explorer
-
White-box vs Black-box: Bayes Optimal Strategies for Membership Inference
Under a Gibbs posterior assumption, the Bayes-optimal membership inference attack depends only on the model's loss, and simple loss-threshold attacks outperform shadow models.