Pith. sign in

REVIEW 2 cited by

Revisiting Membership Inference Under Realistic Assumptions

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2005.10881 v5 pith:7MFU4YXP submitted 2020-05-21 cs.CR cs.LGstat.ML

classification cs.CRcs.LGstat.ML
keywords inferencesettingattackattacksdevelopassumptionsconsiderloss
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We study membership inference in settings where some of the assumptions typically used in previous research are relaxed. First, we consider skewed priors, to cover cases such as when only a small fraction of the candidate pool targeted by the adversary are actually members and develop a PPV-based metric suitable for this setting. This setting is more realistic than the balanced prior setting typically considered by researchers. Second, we consider adversaries that select inference thresholds according to their attack goals and develop a threshold selection procedure that improves inference attacks. Since previous inference attacks fail in imbalanced prior setting, we develop a new inference attack based on the intuition that inputs corresponding to training set members will be near a local minimum in the loss function, and show that an attack that combines this with thresholds on the per-instance loss can achieve high PPV even in settings where other attacks appear to be ineffective. Code for our experiments can be found here: https://github.com/bargavj/EvaluatingDPML.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Cascading and Proxy Membership Inference Attacks

    cs.CR 2025-07 conditional novelty 7.0 of 10

    CMIA cascades conditional shadow training to exploit membership dependencies, and PMIA uses proxy data to approximate Bayesian membership odds, both substantially outperforming prior MIAs in low false-positive regimes.

  2. Evaluating the Dynamics of Membership Privacy in Deep Learning

    cs.LG 2025-07 conditional novelty 6.0 of 10

    Per-sample membership vulnerability is established early in training, especially for hard-to-learn examples, and can be tracked on an FPR-TPR plane.

Pith tools