{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2018:KFBV36WRSMTVXBMDTA3D2AJ4VR","short_pith_number":"pith:KFBV36WR","schema_version":"1.0","canonical_sha256":"51435dfad193275b858398363d013cac660a4a14c3b8900a185061b5ab4191b7","source":{"kind":"arxiv","id":"1802.04889","version":1},"attestation_state":"computed","paper":{"title":"Understanding Membership Inferences on Well-Generalized Learning Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"Carl A. Gunter, Diyue Bu, Haixu Tang, Kai Chen, Lei Wang, Vincent Bindschaedler, Xiaofeng Wang, Yunhui Long","submitted_at":"2018-02-13T23:05:05Z","abstract_excerpt":"Membership Inference Attack (MIA) determines the presence of a record in a machine learning model's training data by querying the model. Prior work has shown that the attack is feasible when the model is overfitted to its training data or when the adversary controls the training algorithm. However, when the model is not overfitted and the adversary does not control the training algorithm, the threat is not well understood. In this paper, we report a study that discovers overfitting to be a sufficient but not a necessary condition for an MIA to succeed. More specifically, we demonstrate that ev"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1802.04889","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2018-02-13T23:05:05Z","cross_cats_sorted":["cs.LG","stat.ML"],"title_canon_sha256":"16fd61de20f8cd5fb05c0fca9564fec1b77c0a46f844e8df19865d761b73550f","abstract_canon_sha256":"ba38643b09dcf143201efc9192ac8aa4bd27e590a98d240c88d8a1655f05cb63"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-18T00:23:22.306511Z","signature_b64":"kPQgQ5dTv8ry1stNEWE/4QzsANS1XdlaxJlSPqouex9bbCzS2ezOq0TJPKVUm792NO8C5Ko78jeS2KNdomt8Cw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"51435dfad193275b858398363d013cac660a4a14c3b8900a185061b5ab4191b7","last_reissued_at":"2026-05-18T00:23:22.305780Z","signature_status":"signed_v1","first_computed_at":"2026-05-18T00:23:22.305780Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Understanding Membership Inferences on Well-Generalized Learning Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG","stat.ML"],"primary_cat":"cs.CR","authors_text":"Carl A. Gunter, Diyue Bu, Haixu Tang, Kai Chen, Lei Wang, Vincent Bindschaedler, Xiaofeng Wang, Yunhui Long","submitted_at":"2018-02-13T23:05:05Z","abstract_excerpt":"Membership Inference Attack (MIA) determines the presence of a record in a machine learning model's training data by querying the model. Prior work has shown that the attack is feasible when the model is overfitted to its training data or when the adversary controls the training algorithm. However, when the model is not overfitted and the adversary does not control the training algorithm, the threat is not well understood. In this paper, we report a study that discovers overfitting to be a sufficient but not a necessary condition for an MIA to succeed. More specifically, we demonstrate that ev"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1802.04889","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1802.04889","created_at":"2026-05-18T00:23:22.305894+00:00"},{"alias_kind":"arxiv_version","alias_value":"1802.04889v1","created_at":"2026-05-18T00:23:22.305894+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1802.04889","created_at":"2026-05-18T00:23:22.305894+00:00"},{"alias_kind":"pith_short_12","alias_value":"KFBV36WRSMTV","created_at":"2026-05-18T12:32:33.847187+00:00"},{"alias_kind":"pith_short_16","alias_value":"KFBV36WRSMTVXBMD","created_at":"2026-05-18T12:32:33.847187+00:00"},{"alias_kind":"pith_short_8","alias_value":"KFBV36WR","created_at":"2026-05-18T12:32:33.847187+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":4,"sample":[{"citing_arxiv_id":"2605.17341","citing_title":"Single-Sample Black-Box Membership Inference Attack against Vision-Language Models via Cross-modal Semantic Alignment","ref_index":34,"is_internal_anchor":true},{"citing_arxiv_id":"2305.15717","citing_title":"The False Promise of Imitating Proprietary LLMs","ref_index":18,"is_internal_anchor":true},{"citing_arxiv_id":"2510.21783","citing_title":"Noise Aggregation Analysis Driven by Small-Noise Injection: Efficient Membership Inference for Diffusion Models","ref_index":12,"is_internal_anchor":true},{"citing_arxiv_id":"2310.16789","citing_title":"Detecting Pretraining Data from Large Language Models","ref_index":87,"is_internal_anchor":true},{"citing_arxiv_id":"2605.01129","citing_title":"Revisiting Privacy Leakage in Machine Unlearning: Membership Inference Beyond the Forgotten Set","ref_index":25,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR","json":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR.json","graph_json":"https://pith.science/api/pith-number/KFBV36WRSMTVXBMDTA3D2AJ4VR/graph.json","events_json":"https://pith.science/api/pith-number/KFBV36WRSMTVXBMDTA3D2AJ4VR/events.json","paper":"https://pith.science/paper/KFBV36WR"},"agent_actions":{"view_html":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR","download_json":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR.json","view_paper":"https://pith.science/paper/KFBV36WR","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1802.04889&json=true","fetch_graph":"https://pith.science/api/pith-number/KFBV36WRSMTVXBMDTA3D2AJ4VR/graph.json","fetch_events":"https://pith.science/api/pith-number/KFBV36WRSMTVXBMDTA3D2AJ4VR/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/action/timestamp_anchor","attest_storage":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/action/storage_attestation","attest_author":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/action/author_attestation","sign_citation":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/action/citation_signature","submit_replication":"https://pith.science/pith/KFBV36WRSMTVXBMDTA3D2AJ4VR/action/replication_record"}},"created_at":"2026-05-18T00:23:22.305894+00:00","updated_at":"2026-05-18T00:23:22.305894+00:00"}